Viewing File: /var/cache/yum/x86_64/7/updates/gen/other_db.sqlite

SQLite format 3@  O
-)
M2@YindexpkgIdpackagesM.CREATE INDEX pkgId ON packages (pkgId)KeindexkeychangechangelogJCREATE INDEX keychange ON changelog (pkgKey) /triggerremove_changelogspackagesCREATE TRIGGER remove_changelogs AFTER DELETE ON packages  BEGIN    DELETE FROM changelog WHERE pkgKey = old.pkgKey;  ENDv;tablechangelogchangelogCREATE TABLE changelog (  pkgKey INTEGER,  author TEXT,  date INTEGER,  changelog TEXT)^tablepackagespackagesCREATE TABLE packages (  pkgKey INTEGER PRIMARY KEY,  pkgId TEXT)Q{tabledb_infodb_infoCREATE TABLE db_info (dbversion INTEGER, checksum TEXT)
E
e075c2b40e525d4aa752b17e8fbb11f11068a185fa08d55c4fe9ebf0db3508ef='
֗x
ՋF77plicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
8;8	oCMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skew	oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testsb	o[Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS:	oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5Re
5lD	oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsF	o#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterH	o'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
B
	q!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load		oSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server	oKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
`Go#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterI
o'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissionsoCMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skewoMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV tests
x8xoSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the serveroKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationEoMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
mvamoCMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skewXoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12o9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNq!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
4jEoMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsGo#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterIo'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
@q!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadoSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the serveroKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
uuoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleXoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12o9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
4jE!oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsG o#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterIo'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
@$q!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load#oSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server"oKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
uu'oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleX&oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12%o9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
))E*oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsG)o#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterB(oThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)
@-q!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load,oSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server+oKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
uu0oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleX/oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12.o9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
2o?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchB1oThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)
x8x5oSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server4oKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationE3oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
vaX8oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-127o9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN6q!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
B:oThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)9oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
o<osThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database;o?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search
@?q!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load>oSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server=oKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
uuBoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleXAoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12@o9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
Do?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchBCoThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)
\\:Go	Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-5^=Q@- Bump version to 1.3.10.1-5
- Resolves: Bug 1744623 - DB Deadlock on modrdn appears to corrupt database and entry cache(cont)rFqwMark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_reploEosThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database
j;JoMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5Re-IooMark Reynolds <mreynolds@redhat.com> - 1.3.10.1-7^\A- Bump version to 1.3.10.1-7
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind (fix regression)cHo[Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-6^\@- Bump version to 1.3.10.1-6
- Resolves: Bug 1801694 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1803052 - Memory leak in ACI using IP subject
- Resolves: Bug 1801703 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1809160 - Entry cache contention during base searchplicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
..INo'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissionsMoCMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skewLoMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testscKo[Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS
n6nEPoMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsGOo#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilter
j;So	Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5Re#-Roo	Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-7^\A- Bump version to 1.3.10.1-7
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind (fix regression)cQo[	Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-6^\@- Bump version to 1.3.10.1-6
- Resolves: Bug 1801694 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1803052 - Memory leak in ACI using IP subject
- Resolves: Bug 1801703 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1809160 - Entry cache contention during base searchplicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
..IWo'	Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissionsVoC	Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skewUo	Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testscTo[	Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS
P6nPZoK	Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationEYo	Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsGXo#	Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilter
P$^o
Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testsc]o[
Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS;\o
Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5Re'-[oo
Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-7^\@- Bump version to 1.3.10.1-7
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind (fix regression)plicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
fGao#
Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterI`o'
Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions_oC
Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skew
x8xdoS
Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-8
- Resolves: Bug 1905450 - Internal unindexed search crashes the servercoK
Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationEbo
Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
e^eXhoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12go9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNfq!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadeoSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server
BjoThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)ioGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
olosThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the databaseko?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search
==oq!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadAnoSimon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU usermqwMark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
uuroGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleXqoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12po9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
to?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchBsoThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)
rvqwMark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_replouosThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database
 XzoG
Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12yo9
Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNxoGMark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringAwoSimon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU use
B|o
Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular){oG
Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
o~os
Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database}o?
Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search
6)6XoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12o=
Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-3d@- Bump version to 1.3.11.1-3
- Resolves: rhbz#2224507 - Paged search impacts performanceoG
Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringAo
Simon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU userqw
Mark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
BoThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
oosThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the databaseo?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search

(o=Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-3d@- Bump version to 1.3.11.1-3
- Resolves: rhbz#2224507 - Paged search impacts performance
oGMark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringA	oSimon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU userqwMark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
IfI
oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rulemCThierry Bordaz <tbordaz@redhat.com> - 1.3.11.1-4ey- Bump version to 1.3.11.1-4
- Resolves: RHEL-17332 - ns-slapd crash in slapi_attr_basetype
,t.\Dr,D
a746522986b0afca052c56bfe30e019392742f4feb4722768d2eb43b4babeac8D

231493e830d00be6017e14f2838a22163835ecea8facf688b9769eed88f3c9b2D
d3229cfb18563fc8a24139a13a8b266e417258f43d36a4a4ac3b372af35d59f8D
187145d7bfd310c612f73b86a31e75562cbe69306dca7362841fcb038b52fa3bD

2952ebf67510a8da5c648a66cb72fb82d02a871b1b805e3fa5d9a1ab8d1377d2D	
6af757b1f83a00f0551ab69c27a637b1a7fcd95125d64c9146be9158ec4964c4D
69b46c2053c4fbaa163f2390003a89acba1e45f20c75c06337f18474970f4943D
8185f310e186803f0af31262808f321254090fced72ee96c77a5b4ecea2ab08cD
5d1951ec0080791e7902a50f19ea2eab2f07b5ce3efea78f024eb1a197abfb77D
a4b372b0da7c95c62540dcfd5049d2b4cd05abf59cb373d2a9a94bcdce3472c3D
8638584ccb7fcde8b4799f13f6a58ef2c129baba95c41aeb504453c5262416a1D
25d8cb3d83565ead22c4bfc3963acaa10f44a28286e88bfd60ce16ec510a113bD
47174964aa424317b7623852dab6eb134838bc81b1ecc6687a16e8461523c3c8D
a6a35e6ed55e101d96fd0ed48dd8267a7e8e10917230172a9de28a796d39490e
,t.\Dr,D
66236b68ae255104741eb03ff98c372f45d1070837fd9f390037488468b9dd1dD
6c8904697fe6c2ee66e07070d91ead8cd93c7f2b07461f411e7fbb303c278589D
5d56166abb7686fc795b62a2d6600a144699caccdbc3ea53b082d1535c2834b0D
709e283813b0f0f0fdef0e1af87059ea4abce1a31640b490109436fad941d2dbD
1315433f5602796463c98742b5395f6bc95f0716a4d9322f2131b5bd23a0bcdcD
e3f5a839e2e8acc1d26bf39b94c2d5f01d99b4c9f59926532da730dd0cc33feaD
6777f22d398c85f89da0f1efaa40c7fb3d16e1d72eeb8ae99d1e2dc818769d0dD
2cfc157959dd7203260a2f727d8590878e5ebaf061e1f17210e36684e46916d4D
18552d6d05e89198db7ddef073bf9f88ff81556cc037c82a133b0eba4e12c71aD
f8c005d77b5c2074f8f5ecf019407c406d423acd0fddbce4ac8b4efa1be0f808D
26f9837529ec8886d1314252f193f695e2df988f21ba6cbdef62da935e15848fD
7f2bca34d66595ea71392f8a9fe4f631679313d883bbc5d48d3d49e1ceb88d8bD
53bef7d8f496ce93d095af2f28cf9ea690f7d61117266073c87080d1457a56e3D
27db2cd3bba9e5240c46f94fcd95f8d419bad9f865a7b32e02a98759ed918be2
o?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchBoThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)

rqwMark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_reploosThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database
mCThierry Bordaz <tbordaz@redhat.com> - 1.3.11.1-4ey- Bump version to 1.3.11.1-4
- Resolves: RHEL-17332 - ns-slapd crash in slapi_attr_basetypeo=Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-3d@- Bump version to 1.3.11.1-3
- Resolves: rhbz#2224507 - Paged search impacts performanceoGMark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringAoSimon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU use
oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleMm1James Chapman <jachapma@redhat.com> - 1.3.11.1-5f(@- Bump version to 1.3.11.1-5
- Resolves: RHEL-33337 - redhat-ds:11/389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request
- Resolves: RHEL-34817 - redhat-ds:11/389-ds-base: Malformed userPassword may cause crash at do_modify in slapd/modify.c
o?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchBoThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)

rqwMark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_reploosThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database
mCThierry Bordaz <tbordaz@redhat.com> - 1.3.11.1-4ey- Bump version to 1.3.11.1-4
- Resolves: RHEL-17332 - ns-slapd crash in slapi_attr_basetypeo=Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-3d@- Bump version to 1.3.11.1-3
- Resolves: rhbz#2224507 - Paged search impacts performanceoGMark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringAoSimon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU use
c"o[Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS;!oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5ReCM m1James Chapman <jachapma@redhat.com> - 1.3.11.1-5f(@- Bump version to 1.3.11.1-5
- Resolves: RHEL-33337 - redhat-ds:11/389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request
- Resolves: RHEL-34817 - redhat-ds:11/389-ds-base: Malformed userPassword may cause crash at do_modify in slapd/modify.cplicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
^G&o#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterI%o'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions$oCMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skew#oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV tests
u7u)oSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server(oKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationE'oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
un,oCMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skew+oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV tests*q!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
3hE/oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsG.o#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterI-o'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
>2q!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load1oSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server0oKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
\'\G7o#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterI6o'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions5oCMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skewX4oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-123o9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
u7u:oSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server9oKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationE8oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
u_X=oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12<o9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN;q!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
KKG@o#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterI?o'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions>oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
u7uCoSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the serverBoKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationEAoMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
u_XFoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12Eo9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNDq!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
BHoThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)GoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
M5lMKoKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationEJoMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsGIo#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilter
a]aXOoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12No9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNMq!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadLoSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server
BQoThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)PoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
ESoMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsRo?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search
>Vq!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadUoSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the serverToKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
rrYoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleXXoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12Wo9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
[o?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchBZoThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)
K
K^oSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server]oKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationo\osThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database
u_XaoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12`o9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN_q!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
BcoThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)boGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
oeosThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the databasedo?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search
e
Lecho[Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-6^\@- Bump version to 1.3.10.1-6
- Resolves: Bug 1801694 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1803052 - Memory leak in ACI using IP subject
- Resolves: Bug 1801703 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1809160 - Entry cache contention during base search:go	Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-5^=Q@- Bump version to 1.3.10.1-5
- Resolves: Bug 1744623 - DB Deadlock on modrdn appears to corrupt database and entry cache(cont)rfqwMark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
O!loMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testscko[Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS;joMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5Re]-iooMark Reynolds <mreynolds@redhat.com> - 1.3.10.1-7^\A- Bump version to 1.3.10.1-7
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind (fix regression)plicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
eGoo#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterIno'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissionsmoCMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skew
P7Pcqo[Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-6^\@- Bump version to 1.3.10.1-6
- Resolves: Bug 1801694 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1803052 - Memory leak in ACI using IP subject
- Resolves: Bug 1801703 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1809160 - Entry cache contention during base searchEpoMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
O!uoMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testscto[Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS;soMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5Rea-rooMark Reynolds <mreynolds@redhat.com> - 1.3.10.1-7^\A- Bump version to 1.3.10.1-7
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind (fix regression)plicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
eGxo#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterIwo'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissionsvoCMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skew
g7g-{ooMark Reynolds <mreynolds@redhat.com> - 1.3.10.1-7^\@- Bump version to 1.3.10.1-7
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind (fix regression)zoKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationEyoMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsplicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
090oCMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skew~oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testsc}o[Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS;|oMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5Red
3hEoMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsGo#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterIo'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
>q!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadoSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the serveroSMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-8
- Resolves: Bug 1905450 - Internal unindexed search crashes the serveroKMark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
rr	oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleXoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12o9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
o?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchB
oThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)

r
qwMark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_reploosThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database
0o9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNq!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadAoSimon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU use
BBBoThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleXoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12
oosThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the databaseo?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search

(o9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNoGMark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringAoSimon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU userqwMark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
,t.\Dr,D*
bff0a6adc60eba913218bcccc836d732221469cd7650eb27d199e3f7780373a7D)
29d3baca7632def182f6a6250f76f26476b491b66dfe819eb6d94008003dfc3dD(
f9a690e8aa496786b4e27818af37b20bb17b3805bd626de662a2647c04ea6bb1D'
808bc13d124b864d8dd90f80437bc5d919d6dcdca1ebbd9efcd56e575fbfb500D&
b957705e340403c636b68ab6ee9c49dd1552eb20220d0175dbbf84f042ac62c4D%
210a76b6e2c83684ac3c106fff35849b22269be89a5b895625ac4ca5bf489796D$
9e9a8ce7cbf019108675746a5f67d8ff853fb0b97c72cbd0f4d38b6dad0c96b7D#
ca73e4d1c2e57869c6e300075fa3bdd65118ee30910c0ed450532b3fd0d7976bD"
c10b86b4a5c3b1385c04eab748fa24507011e241349fb530ab4df3fbb719f26eD!
bb1ab36dd4c499189f1a463cc83793aa1e996879aa0fc39e43580add7837b7c9D 
cf900656ad664e99d27fd815261164678b178f186d6fbadf440dbc7ab48fbbfeD
0f6b2d20fc79acfdc5f930788c81abbec7863d8a4d373229f80a9f4d126d1db8D
aa0fe451ab8753df55722f121169c9aca26ca19a8b763c4d7f831af3bf826a26D
e5c8dac0c01ec10e911180046ed350bf3dafcb9bd06121d746055d20b4d55586
BBBoThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleXoGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12
oosThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the databaseo?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search
5
(5X#oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12"o=Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-3d@- Bump version to 1.3.11.1-3
- Resolves: rhbz#2224507 - Paged search impacts performance!oGMark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringA oSimon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU userqwMark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
B%oThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)$oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
o'osThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database&o?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search

(+o=Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-3d@- Bump version to 1.3.11.1-3
- Resolves: rhbz#2224507 - Paged search impacts performance*oGMark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringA)oSimon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU user(qwMark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
IfI-oGThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule,mCThierry Bordaz <tbordaz@redhat.com> - 1.3.11.1-4ey- Bump version to 1.3.11.1-4
- Resolves: RHEL-17332 - ns-slapd crash in slapi_attr_basetype
/o?Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchB.oThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)

r1qwMark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_replo0osThierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database
5mCThierry Bordaz <tbordaz@redhat.com> - 1.3.11.1-4ey- Bump version to 1.3.11.1-4
- Resolves: RHEL-17332 - ns-slapd crash in slapi_attr_basetype4o=Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-3d@- Bump version to 1.3.11.1-3
- Resolves: rhbz#2224507 - Paged search impacts performance3oGMark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringA2oSimon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU use
c8o[ Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS;7o Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5Re{M6m1James Chapman <jachapma@redhat.com> - 1.3.11.1-5f(@- Bump version to 1.3.11.1-5
- Resolves: RHEL-33337 - redhat-ds:11/389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request
- Resolves: RHEL-34817 - redhat-ds:11/389-ds-base: Malformed userPassword may cause crash at do_modify in slapd/modify.cplicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
^G<o# Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterI;o' Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions:oC Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skew9o Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV tests
u7u?oS Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server>oK Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationE=o Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
unBoC!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skewAo!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV tests@q! Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
3hEEo!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsGDo#!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterICo'!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
>Hq!!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadGoS!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the serverFoK!Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
\'\GMo#"Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterILo'"Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissionsKoC"Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skewXJoG!Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12Io9!Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
u7uPoS"Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the serverOoK"Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationENo"Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
u_XSoG"Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12Ro9"Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNQq!"Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
KKGVo##Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterIUo'#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissionsToG"Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
u7uYoS#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the serverXoK#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationEWo#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
u_X\oG#Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12[o9#Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNZq!#Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
B^o#Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)]oG#Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
M5lMaoK$Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationE`o$Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsG_o#$Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilter
a]aXeoG$Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12do9$Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNcq!$Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadboS$Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server
Bgo$Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)foG$Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
Eio%Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsho?$Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search
>lq!%Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadkoS%Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the serverjoK%Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
rrooG%Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleXnoG%Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12mo9%Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
qo?%Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchBpo%Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)
K
KtoS&Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the serversoK&Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationoros%Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database
u_XwoG&Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12vo9&Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNuq!&Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
Byo&Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)xoG&Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
o{os&Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the databasezo?&Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search
e
Lec~o['Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-6^\@- Bump version to 1.3.10.1-6
- Resolves: Bug 1801694 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1803052 - Memory leak in ACI using IP subject
- Resolves: Bug 1801703 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1809160 - Entry cache contention during base search:}o	'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-5^=Q@- Bump version to 1.3.10.1-5
- Resolves: Bug 1744623 - DB Deadlock on modrdn appears to corrupt database and entry cache(cont)r|qw&Mark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
O!o'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testsco['Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS;o'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5Re-oo'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-7^\A- Bump version to 1.3.10.1-7
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind (fix regression)plicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
eGo#'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterIo''Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissionsoC'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skewtssx}	"',16;@EJPV\bhntz
"(.4:@FLRX^djpv|
	

!$'*-0258:<?BDGJ N!P"S$W%Z&^(a)d*h+j,l-o.r/t0v1z2|3~45678
;<=>?@AB"D&E)F,G/H2I7J:K=L@MCNFOHPKQORQSSTVUYV[W^XaYcZe[h\l^o_q`ubxc{efgh	ij
klmnpqr#s%t'u+v-w/x1y5z8|<}?~BEHMPSVofflrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|\^aegiloqtwy{~!#&)+/249;=ACEGKNRUX[^cfilortƒwÃ{ă}ŃƄDŽȄɄ
ʄ
˄̄̈́΄Єф҄!Ԅ$Մ'ׄ+؄.ل2ۄ5܄7݄9ބ<߄?AEHJOQSWY[]agpy'1:CLU^gq{

P7Pco[(Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-6^\@- Bump version to 1.3.10.1-6
- Resolves: Bug 1801694 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1803052 - Memory leak in ACI using IP subject
- Resolves: Bug 1801703 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1809160 - Entry cache contention during base searchEo'Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
O!o(Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testsc
o[(Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS;	o(Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5Re-oo(Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-7^\A- Bump version to 1.3.10.1-7
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind (fix regression)plicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
eGo#(Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterI
o'(Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissionsoC(Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skew
g7g-oo)Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-7^\@- Bump version to 1.3.10.1-7
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind (fix regression)oK(Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationEo(Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsplicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
090oC)Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skewo)Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testsco[)Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS;o)Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5Re
3hEo)Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsGo#)Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterIo')Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
>q!*Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadoS*Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the serveroS)Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-8
- Resolves: Bug 1905450 - Internal unindexed search crashes the serveroK)Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
rroG*Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleXoG*Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12o9*Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
!o?*Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchB o*Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)

r#qw*Mark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_replo"os*Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database
0&o9+Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN%q!+Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadA$o*Simon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU use
,t.\Dr,D8
7f3bdd324d9659e15f12b5165027a55a0cea71990ff77d978912c84bebe83633D7
81e77a0ae807ac0a5e4579c4ac44dde54b30b6b5c6ab31d335b8c1bd1836ecb2D6
af4f36c81584781e9a0b5038c6d887f8d9a95020701f12f3688519038ca47c15D5
8ad876dd83b3d0a6435b5decb5ebce5c58c33e7d6fe1fd43a96a9f7e6afcb562D4
fe65f8c1104a49b25deba3a5dd771fe3ef37e4b8efeb398644007101e18a4473D3
fe57c2235944b61957f96287d962dc8a6f63af33aa9a45b6bff9fc30a34862f5D2
528e29a03538329527c3f4082c917cb49d0bf14f6f4b401f793a6ea83f341395D1
373ae4c777d075890ed70569cf89dd0563fc99e76ace4281502f4aed12d4dcf6D0
30212ff031337cd6d1555e594dd9bb0d28c9a5c7c25257cfe0770146ed77d187D/
37244afa6bebe0e93a5dcd0ef3ea1ac9a76f734e116ce8c087a5f791ad1136d3D.
65debf30e942beaf68eeeebb661030f709a1c53b1981536c005e8dddf29b7da6D-
eef2f7ac436c0d23750d0d428880ec5d58260342fcb7de2587122eea70893429D,
99549f1842c7801ff61d826ce12f1351ce7f60f836b2dcf51fb46da34c4b3d1eD+
6471268f8ca47b59f93b0c5a8b8bbf5e9a7d6cfb337f2a89a19b76d82ac5bde2
BBB)o+Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)(oG+Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleX'oG+Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12
o+os+Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database*o?+Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search

(/o9,Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN.oG+Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringA-o+Simon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU user,qw+Mark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
BBB2o,Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)1oG,Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleX0oG,Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12
o4os,Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database3o?,Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search
5
(5X9oG-Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-128o=,Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-3d@- Bump version to 1.3.11.1-3
- Resolves: rhbz#2224507 - Paged search impacts performance7oG,Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringA6o,Simon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU user5qw,Mark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
B;o-Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular):oG-Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
o=os-Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database<o?-Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search

(Ao=-Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-3d@- Bump version to 1.3.11.1-3
- Resolves: rhbz#2224507 - Paged search impacts performance@oG-Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringA?o-Simon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU user>qw-Mark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
IfICoG.Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleBmC-Thierry Bordaz <tbordaz@redhat.com> - 1.3.11.1-4ey- Bump version to 1.3.11.1-4
- Resolves: RHEL-17332 - ns-slapd crash in slapi_attr_basetype
Eo?.Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchBDo.Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)

rGqw.Mark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_reploFos.Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database
KmC.Thierry Bordaz <tbordaz@redhat.com> - 1.3.11.1-4ey- Bump version to 1.3.11.1-4
- Resolves: RHEL-17332 - ns-slapd crash in slapi_attr_basetypeJo=.Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-3d@- Bump version to 1.3.11.1-3
- Resolves: rhbz#2224507 - Paged search impacts performanceIoG.Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringAHo.Simon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU use
cNo[/Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS;Mo/Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5ReMLm1.James Chapman <jachapma@redhat.com> - 1.3.11.1-5f(@- Bump version to 1.3.11.1-5
- Resolves: RHEL-33337 - redhat-ds:11/389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request
- Resolves: RHEL-34817 - redhat-ds:11/389-ds-base: Malformed userPassword may cause crash at do_modify in slapd/modify.cplicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
^GRo#/Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterIQo'/Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissionsPoC/Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skewOo/Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV tests
u7uUoS/Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the serverToK/Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationESo/Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
unXoC0Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skewWo0Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testsVq!/Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
3hE[o0Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsGZo#0Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterIYo'0Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
>^q!0Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load]oS0Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server\oK0Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
\'\Gco#1Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterIbo'1Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissionsaoC1Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skewX`oG0Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12_o90Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
u7ufoS1Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the servereoK1Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationEdo1Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
u_XioG1Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12ho91Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNgq!1Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
KKGlo#2Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterIko'2Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissionsjoG1Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
u7uooS2Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the servernoK2Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationEmo2Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
u_XroG2Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12qo92Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNpq!2Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
Bto2Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)soG2Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
M5lMwoK3Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationEvo3Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsGuo#3Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilter
a]aX{oG3Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12zo93Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNyq!3Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadxoS3Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server
B}o3Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)|oG3Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
Eo4Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars~o?3Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search
>q!4Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadoS4Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the serveroK4Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
rroG4Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleXoG4Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12o94Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
o?4Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchBo4Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)
K
K
oS5Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server	oK5Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationoos4Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database
u_X
oG5Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12o95Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNq!5Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load
Bo5Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)oG5Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
oos5Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the databaseo?5Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search
e
Leco[6Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-6^\@- Bump version to 1.3.10.1-6
- Resolves: Bug 1801694 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1803052 - Memory leak in ACI using IP subject
- Resolves: Bug 1801703 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1809160 - Entry cache contention during base search:o	6Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-5^=Q@- Bump version to 1.3.10.1-5
- Resolves: Bug 1744623 - DB Deadlock on modrdn appears to corrupt database and entry cache(cont)rqw5Mark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
O!o6Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testsco[6Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS;o6Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5Reρ-oo6Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-7^\A- Bump version to 1.3.10.1-7
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind (fix regression)plicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
eGo#6Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterIo'6Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissionsoC6Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skew
P7Pco[7Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-6^\@- Bump version to 1.3.10.1-6
- Resolves: Bug 1801694 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1803052 - Memory leak in ACI using IP subject
- Resolves: Bug 1801703 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1809160 - Entry cache contention during base searchEo6Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped chars
O!!o7Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testsc o[7Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS;o7Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5ReӁ-oo7Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-7^\A- Bump version to 1.3.10.1-7
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind (fix regression)plicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
eG$o#7Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterI#o'7Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions"oC7Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skew
g7g-'oo8Mark Reynolds <mreynolds@redhat.com> - 1.3.10.1-7^\@- Bump version to 1.3.10.1-7
- Resolves: Bug 1803023 - Several memory leaks reported by Valgrind (fix regression)&oK7Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replicationE%o7Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsplicaId cant be set to the old value it had before
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
- Resolves: Bug 1762901 - cenotaph errors on modrdn operations
- Resolves: Bug 1772616 - Typo in the replication debug message "error 0 for oparation 561" 
- Resolves: Bug 1781276 - Regression: NSS has interop problems as server when using limited cipher list
- Resolves: Bug 1787921 - Crash on startup: Bus error in __env_faultmem.isra.1.part.2
- Resolves: Bug 1759142 - No error returned when adding an entry matching filters for a non existing automember group
- Resolves: Bug 1763365 - ns-slapd is crashing while restarting ipactl
- Resolves: Bug 1769418 - Several memory leaks reported by Valgrind for 389-ds 1.3.9.1-10
- Resolves: Bug 1775165 - ldclt core dumped when run with -e genldif option
- Resolves: Bug 1796558 - Memory leak in ACI using IP subject
- Resolves: Bug 1769296 - cl-dump exit code is 0 even if command fails with invalid arguments
090+oC8Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-4^@- Bump version to 1.3.10.2-4
- Resolves: Bug 1837105 - Check for clock errors and time skew*o8Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-3^@- Bump version to 1.3.10.2-3
- Resolves: Bug 1824930 - ipa ns-slapd 3 threads deadlock, db pages, state_change lock, write vattr lock
- Resolves: Bug 1837477 - ns-slapd hangs during CleanAllRUV testsc)o[8Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-2^@- Bump version to  1.3.10.2-2
- Resolves: Bug 1820433 - Invalid defaults.inf, missing key db_home_dir
- Resolves: Bug 1801327 - intermittent SSL hang with rhds
- Resolves: Bug 1807537 - wildcards in rootdn-allow-ip attribute are not accepted
- Resolves: Bug 1827284 - Memory leak in indirect COS;(o8Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-1^oj@- Bump version to  1.3.10.2-1
- Resolves: Bug 1724761 - Entry cache contention during base search
- Resolves: Bug 1515319 - nsDS5Re
3hE.o8Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-7_"- Bump version to 1.3.10.2-7
- Resolves: Bug 1870624 - RHDS - allow more than 1 empty AttributeDescription for ldapsearch, without the risk of denial of service
- Resolves: Bug 1876028 - errors log with incorrectly formatted message parent_update_on_childchange on PARENTUPDATE_DEL
- Resolves: Bug 1860008 - On ADD replication URP issue internal searches with filter containing unescaped charsG-o#8Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-6^@- Bump version to 1.3.10.2-6
- Resolves: Bug 1839085 - IPA: Winsync not honoring parameters winSyncDirectoryFilter and winSyncWindowsFilterI,o'8Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-5^?@- Bump version to 1.3.10.2-5
- Resolves: Bug 1700987 - 389-base-ds expected file permissions in package don't match final runtime permissions
>2q!9Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high load1oS9Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-9
- Resolves: Bug 1905450 - Internal unindexed search crashes the server0oS8Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-9_- Bump version to 1.3.10.2-8
- Resolves: Bug 1905450 - Internal unindexed search crashes the server/oK8Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-8_@- Bump version to 1.3.10.2-8
- Resolves: Bug 1904145 - group rdn with leading space char and add fails error 21 invalid syntax and delete fails error 32
- Resolves: Bug 1902042 - Entries conflict not resolved by replication
,t.\Dr,DF
b15c5bd5d17c47937d82efe2f0ce115cd380671ef484581d4184399c840e2c35DE
a7b0d2e78f9226d952fd5d798225620b853fb2b0edd6abeda0fcca3095856f7aDD
cf312b0640aa93a5701862f262416738887b1618922b58eaadfe16d281c1fa7dDC
d10825f54b07b6022f065b39a4e37c8c89bfdc877a230746fbbc048f9659348aDB
ef9ae19900dd432de99370f4bb886c82cc0f4b68367dc2be63113d3f3cbd48d1DA
8b82511897f48ce484e303fe650c32ea1191e71ee0cbd9aff580743fa4f9067cD@
49941263a7a0309c58b3d3e00ab81c56b1ee1a70b49b873188cc23686f5d3d9bD?
cae6bd3ac4c68910abe44b5f1d6e48b99b76914d3a6223b9511bde08f8a3e1cdD>
d98a7567aa18df65a4b612f107387d6f50362fcef232a4c1fe5a246e2d477764D=
fce742e752f83c91c4d9e2dc4fad5ff1b7affb7363270b752a793df36c00754fD<
4cae2658d6c984132e253fc1cb8af035251a3acc79acc7957fc3c92111b0f643D;
6858631f1ec62fd357122548e9196427a27ee3daeb8bc9decbb2919eedf39730D:
40080eb44ef8aa6b4771bc9e085e56264b9e562822c2bbfbd713b6887b64b41fD9
7f6f935600e1b0c0b16538a2e5c86c076209ebb973e4d33e6f98c66d85973c9e
rr5oG9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleX4oG9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-123o99Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN
7o?9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchB6o9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)

r9qw9Mark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_replo8os9Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database
0<o9:Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DN;q!:Mark Reynolds <mreynolds@redhat.com> - 1.3.10.2-10`7@- Bump version to 1.3.10.2-10
- Resolves: Bug 1909342 - DS crash in deref plugin while dereferencing an entry that exists but that is not returned by internal search
- Resolves: Bug 1921856 - “write” permission of ACI changes ns-slapd’s behavior on search operation 
- Resolves: Bug 1881968 - Replication Lag under high loadA:o9Simon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU use
BBB?o:Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)>oG:Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleX=oG:Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12
oAos:Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database@o?:Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search

(Eo9;Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-11`- Bump version to 1.3.10.2-11
- Resolves: Bug 1953673 - Add new access log keywords for time spent in work queue and actual operation time
- Resolves: Bug 1931182 - information disclosure during the binding of a DNDoG:Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringACo:Simon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU userBqw:Mark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
BBBHo;Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)GoG;Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleXFoG;Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12
oJos;Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the databaseIo?;Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search
5
(5XOoG<Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-12`+- Bump version to 1.3.10.2-12No=;Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-3d@- Bump version to 1.3.11.1-3
- Resolves: rhbz#2224507 - Paged search impacts performanceMoG;Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringALo;Simon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU userKqw;Mark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
BQo<Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)PoG<Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule
oSos<Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the databaseRo?<Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent search

(Wo=<Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-3d@- Bump version to 1.3.11.1-3
- Resolves: rhbz#2224507 - Paged search impacts performanceVoG<Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringAUo<Simon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU userTqw<Mark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_repl
IfIYoG=Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-13aHw- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind ruleXmC<Thierry Bordaz <tbordaz@redhat.com> - 1.3.11.1-4ey- Bump version to 1.3.11.1-4
- Resolves: RHEL-17332 - ns-slapd crash in slapi_attr_basetype
[o?=Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-15a- Bump version to 1.3.10.2-15
- Resolves: Bug 2049812 - Fix csn generator to limit time skew drift
- Resolves: Bug 2048530 - CVE-2021-4091 389-ds-base: double-free of the virtual attribute context in persistent searchBZo=Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-14a{@- Bump version to 1.3.10.2-14
- Resolves: Bug 2018257 - hang because of incorrect accounting of readers in vattr rwlock
- Resolves: Bug 2010976 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular)

r]qw=Mark Reynolds <mreynolds@redhat.com> - 1.3.10-2-17c6@- Bump version to 1.3.10.2-17
- Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created
- Resolves: Bug 2131083 - SIGSEGV in sync_replo\os=Thierry Bordaz <tbordaz@redhat.com> - 1.3.10.2-16b=- Bump version to 1.3.10.2-16
- Resolves: Bug 2077395 - CVE-2022-0918 389-ds:1.4/389-ds-base: sending crafted message could result in DoS
- Resolves: Bug 2014768 - Log the Auto Member invalid regex rules in the LDAP errors log
- Resolves: Bug 2018153 - RFE - Provide an option to abort an Auto Member rebuild task
- Resolves: Bug 2093294 - CVE-2022-0996 389-ds:1.4/389-ds-base: expired password was still allowed to access the database
amC=Thierry Bordaz <tbordaz@redhat.com> - 1.3.11.1-4ey- Bump version to 1.3.11.1-4
- Resolves: RHEL-17332 - ns-slapd crash in slapi_attr_basetype`o==Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-3d@- Bump version to 1.3.11.1-3
- Resolves: rhbz#2224507 - Paged search impacts performance_oG=Mark Reynolds <mreynolds@redhat.com> - 1.3.11.1-2dl- Bump version to 1.3.11.1-2
- Resolves: Bug 2170224 - Fix upgrade scripts and version stringA^o=Simon Pichugin <spichugi@redhat.com> - 1.3.11.1-1c@- Bump version to 1.3.11.1-1
- Resolves: Bug 2170224 - Backport Rust password storage PBKDF2 schemes
- Resolves: Bug 2170221 - Boolean attributes should be case insensitive
- Resolves: Bug 2170218 - Slow memberof fixup task for large static groups, high CPU use
JA"JYgaW>Jan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yfa>Jan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)eaY>Jan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}da>Jan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717kca{>Jan Horak <jhorak@redhat.com> - 6.7.8.9-11V@- Fixed crash when processing .exr files (rhbz#1303227)Mbm1=James Chapman <jachapma@redhat.com> - 1.3.11.1-5f(@- Bump version to 1.3.11.1-5
- Resolves: RHEL-33337 - redhat-ds:11/389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request
- Resolves: RHEL-34817 - redhat-ds:11/389-ds-base: Malformed userPassword may cause crash at do_modify in slapd/modify.c
	%h.@%ypa?Jan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)oaY?Jan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}na?Jan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717kma{?Jan Horak <jhorak@redhat.com> - 6.7.8.9-11V@- Fixed crash when processing .exr files (rhbz#1303227)elcm>Jan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdkck>Jan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hjcs>Jan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJic7>Jan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Hha5>Jan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white images
	7Y:R7yya@Jan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)xaY@Jan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}wa@Jan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717evcm?Jan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againduck?Jan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''htcs?Jan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJsc7?Jan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Hra5?Jan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYqaW?Jan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)
	`Y:`aYAJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}aAJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717PcC@Jan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixecm@Jan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againd~ck@Jan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''h}cs@Jan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ|c7@Jan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68H{a5@Jan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYzaW@Jan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)
	d(%VdaYBJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553P
cCAJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixe	cmAJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdckAJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hcsAJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJc7AJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Ha5AJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYaWAJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yaAJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)
	(%VQcEBJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800PcCBJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixecmBJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdckBJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hcsBJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJc7BJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Ha5BJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesY
aWBJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yaBJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)
	da>dPcCCJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixecmCJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdckCJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hcsCJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJc7CJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Ha5CJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYaWCJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yaCJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)aYCJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553

[0<j[Q'cEDJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800P&cCDJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixe%cmDJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againd$ckDJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''h#csDJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ"c7DJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68H!a5DJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesY aWDJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yaDJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)QcECJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800

Y.:hYQ1cEEJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800P0cCEJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixe/cmEJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againd.ckEJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''h-csEJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ,c7EJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68H+a5EJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesY*aWEJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)y)aEJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)S(cIDJan Horak <jhorak@redhat.com> - 6.9.10.68-7e;- Added fix for CVE-2021-40211
	B<EBh:csFJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ9c7FJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68H8a5FJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesY7aWFJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)y6aFJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)5aYFJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}4aFJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717k3a{FJan Horak <jhorak@redhat.com> - 6.7.8.9-11V@- Fixed crash when processing .exr files (rhbz#1303227)S2cIEJan Horak <jhorak@redhat.com> - 6.9.10.68-7e;- Added fix for CVE-2021-40211
	41C(4JCc7GJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68HBa5GJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYAaWGJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)y@aGJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)?aYGJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}>aGJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717k=a{GJan Horak <jhorak@redhat.com> - 6.7.8.9-11V@- Fixed crash when processing .exr files (rhbz#1303227)e<cmFJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againd;ckFJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''
,t.\Dr,DT
e614cee98b3c2a67c0a489a233ca9a7a574ea6bc8dd166f835f26bca8d3d5f7cDS
6d4f5821c8a6634679262138e6c634828699fef39bbd22f409c545e572e816bcDR
572d9ccefce27e99905ba8c221c2216b7ba572949a397e457aeaf3e65ce8b4e4DQ
fb00ca97e06f7da066e8d05cafb17b9f9680e39f50979090e489d8a1720bb4d4DP
3fb72ac0367e9afd39874f48b9a0b356b9cbb0b86d41265538358ef72583d32dDO
5fa6b764fa4d36de1e4b14029d52584b86f65e0020290798aecbd853fb5b4ab5DN
96954d570d0d25ab837bbc471057f6a90d46ffff9195b1391abb3cbc708c7684DM
f6a237d150654379162b6b0cb9396c65ec4227bf24e4b01d1dbb5180dc3b28beDL
342100bd7ce3ca8e951285697781ddb9192c0a02dd56cad55d48bdf20a74bec2DK
54773bd4792a30ed2a90d50d65778c4d34f672bedec6da03981162ca13109417DJ
3694e0f350aab4369f5eda09dba8aaf0c4d0128990509c2eab7a69e8a99c5400DI
208142489b5b939b70a9d0d5242ac84ad700f6bc7f8549c1b26d447993c66b86DH
3d1f2217dd6b5ed505a6858933c562175be86840b5c6c7328291ec8c31333a56DG
365ab6c383dd555fe42283836abe7f7014bf20c41b0828d72f1c13ab138cc1d1
	7.F+7JLc7HJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68HKa5HJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYJaWHJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yIaHJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)HaYHJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}GaHJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717eFcmGJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdEckGJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hDcsGJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflicts
	1.sT|1HUa5IJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYTaWIJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)ySaIJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)RaYIJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}QaIJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717PPcCHJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixeOcmHJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdNckHJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hMcsHJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflicts
	dHy&dH^a5JJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesY]aWJJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)y\aJJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)[aYJJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553PZcCIJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixeYcmIJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdXckIJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hWcsIJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJVc7IJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68
	[Hy&3[YgaWKJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yfaKJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)eaYKJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553QdcEJJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800PccCJJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixebcmJJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdackJJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''h`csJJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ_c7JJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68

dh.dHqa5LJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYpaWLJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yoaLJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)QncEKJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800PmcCKJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixelcmKJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdkckKJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hjcsKJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJic7KJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Hha5KJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white images

YHy&|YH{a5MJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYzaWMJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yyaMJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)SxcILJan Horak <jhorak@redhat.com> - 6.9.10.68-7e;- Added fix for CVE-2021-40211QwcELJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800PvcCLJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixeucmLJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdtckLJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hscsLJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJrc7LJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68
	Hy&|}aNJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717ka{NJan Horak <jhorak@redhat.com> - 6.7.8.9-11V@- Fixed crash when processing .exr files (rhbz#1303227)ScIMJan Horak <jhorak@redhat.com> - 6.9.10.68-7e;- Added fix for CVE-2021-40211QcEMJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800PcCMJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixecmMJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againd~ckMJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''h}csMJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ|c7MJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68
	Ia>Ik
a{OJan Horak <jhorak@redhat.com> - 6.7.8.9-11V@- Fixed crash when processing .exr files (rhbz#1303227)ecmNJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdckNJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''h
csNJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ	c7NJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Ha5NJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYaWNJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yaNJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)aYNJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553
	7e	q7ecmOJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdckOJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hcsOJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJc7OJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Ha5OJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYaWOJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yaOJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)aYOJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}aOJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717
	7e	q7ecmPJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdckPJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hcsPJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJc7PJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Ha5PJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYaWPJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yaPJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)aYPJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}aPJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717
	L-kLd(ckQJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''h'csQJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ&c7QJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68H%a5QJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesY$aWQJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)y#aQJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)"aYQJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}!aQJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717P cCPJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fix
	dE*6dd1ckRJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''h0csRJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ/c7RJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68H.a5RJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesY-aWRJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)y,aRJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)+aYRJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553P*cCQJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixe)cmQJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 again
	wERz/wh:csSJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ9c7SJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68H8a5SJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesY7aWSJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)y6aSJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)5aYSJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553Q4cERJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800P3cCRJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixe2cmRJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 again

H1gHdDckTJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hCcsTJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJBc7TJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68HAa5TJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesY@aWTJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)y?aTJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)Q>cESJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800P=cCSJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixe<cmSJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againd;ckSJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''

YEx+YdNckUJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hMcsUJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJLc7UJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68HKa5UJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYJaWUJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yIaUJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)SHcITJan Horak <jhorak@redhat.com> - 6.9.10.68-7e;- Added fix for CVE-2021-40211QGcETJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800PFcCTJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixeEcmTJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 again
,t.\Dr,Db
c7663ee5f2439075ade107aa7f0383f301032506d3673446ac4c84d046337418Da
f27e3d167e8d7cfb2c448d400f034b7443c2e076e94b38a67fddd951a9bf745eD`
bb05359bb91eb56f0684f800012c621df3fb69caa61349ed4d20292998b1cb0bD_
4c39fd8baa3677dd6ae1debc1bc8f2bcb012f024717dc7b97179d39ba6e3853fD^
177ecfa448785c1fa6fae690a5662325ebe3e141bf45117920f280b5a8880a0aD]
0df91ae3f7e140e17025cfcac0a1bbb8507f665cf4f2ae6e8e6951f0fbc667e5D\
49ac1322f5ed8d216331f29c35eab930dc5be738f27bf00fca63036fbce5de80D[
3fa609f1cadb881d127a3eed1c7b8f2fa2ba4efc32cb2e34e025b3d4215af9d1DZ
e56a5b95dac0bbc46dff9f5743926a4f4bf4883bf7b515cdcd6310771c36a4a8DY
b095f7fcbb5d718e30c01471ddebc9eca7b0315ab21ba2c286f3e4c44b8bf2b1DX
d45776ea070dd01bfa5681b3d5be4cd2fdb7fe2baac5c1720ab216221ef7ddf8DW
c119aff62d5c0644926253cc760d84d4a8fbbb2124668b95f93468f578a85b04DV
a1ac854d8e90e02d163b93f8f41c02c3b799b35db98f425c835e937468ad058bDU
f613394ac503882a78ac261fc0ddce0cd6b033530342f31d88f080b4b99f51b0
	6E-6YWaWVJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yVaVJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)UaYVJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}TaVJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717kSa{VJan Horak <jhorak@redhat.com> - 6.7.8.9-11V@- Fixed crash when processing .exr files (rhbz#1303227)SRcIUJan Horak <jhorak@redhat.com> - 6.9.10.68-7e;- Added fix for CVE-2021-40211QQcEUJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800PPcCUJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixeOcmUJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 again
	%h.@%y`aWJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)_aYWJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}^aWJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717k]a{WJan Horak <jhorak@redhat.com> - 6.7.8.9-11V@- Fixed crash when processing .exr files (rhbz#1303227)e\cmVJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againd[ckVJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hZcsVJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJYc7VJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68HXa5VJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white images
	7Y:R7yiaXJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)haYXJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}gaXJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717efcmWJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdeckWJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hdcsWJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJcc7WJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Hba5WJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYaaWWJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)
	`Y:`raYYJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}qaYJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717PpcCXJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixeocmXJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdnckXJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hmcsXJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJlc7XJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Hka5XJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYjaWXJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)
	d(%Vd{aYZJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553PzcCYJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixeycmYJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdxckYJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hwcsYJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJvc7YJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Hua5YJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYtaWYJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)ysaYJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)
	(%VQcEZJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800PcCZJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixecmZJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdckZJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hcsZJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJc7ZJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68H~a5ZJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesY}aWZJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)y|aZJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)
	da>dP
cC[Jan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixecm[Jan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdck[Jan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''h
cs[Jan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ	c7[Jan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Ha5[Jan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYaW[Jan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)ya[Jan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)aY[Jan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553

[0<j[QcE\Jan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800PcC\Jan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixecm\Jan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdck\Jan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hcs\Jan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJc7\Jan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Ha5\Jan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYaW\Jan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)ya\Jan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)QcE[Jan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800

Y.:hYQ!cE]Jan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800P cC]Jan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixecm]Jan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdck]Jan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hcs]Jan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJc7]Jan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Ha5]Jan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYaW]Jan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)ya]Jan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)ScI\Jan Horak <jhorak@redhat.com> - 6.9.10.68-7e;- Added fix for CVE-2021-40211
	B<EBh*cs^Jan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ)c7^Jan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68H(a5^Jan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesY'aW^Jan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)y&a^Jan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)%aY^Jan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}$a^Jan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717k#a{^Jan Horak <jhorak@redhat.com> - 6.7.8.9-11V@- Fixed crash when processing .exr files (rhbz#1303227)S"cI]Jan Horak <jhorak@redhat.com> - 6.9.10.68-7e;- Added fix for CVE-2021-40211
	71:7h3cs_Jan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ2c7_Jan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68H1a5_Jan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesY0aW_Jan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)y/a_Jan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602).aY_Jan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}-a_Jan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717e,cm^Jan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againd+ck^Jan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''
	d1?gdh<cs`Jan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJ;c7`Jan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68H:a5`Jan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesY9aW`Jan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)y8a`Jan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)7aY`Jan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553P6cC_Jan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixe5cm_Jan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againd4ck_Jan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''

H1gHdFckaJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hEcsaJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJDc7aJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68HCa5aJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYBaWaJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yAaaJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)Q@cE`Jan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800P?cC`Jan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixe>cm`Jan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againd=ck`Jan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''
	6E-6YOaWbJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yNabJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)MaYbJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}LabJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717kKa{bJan Horak <jhorak@redhat.com> - 6.7.8.9-11V@- Fixed crash when processing .exr files (rhbz#1303227)SJcIaJan Horak <jhorak@redhat.com> - 6.9.10.68-7e;- Added fix for CVE-2021-40211QIcEaJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800PHcCaJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixeGcmaJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 again
	7h.7YXaWcJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yWacJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)VaYcJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553}UacJan Horak <jhorak@redhat.com> - 6.7.8.9-13W+5- Add fix for CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717eTcmbJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdSckbJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hRcsbJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJQc7bJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68HPa5bJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white images
,t.\Dr,Dp
21113ab4dcd135895d98e51d9d540e8be477abdc44e185a460a9a835e382a7c1Do
a3a98ff12318616c1641d6e0d2dadf6e2f268b6bbc34e65924fe720f0ed2b498Dn
b59dc7ffbf0ef066ff9a1cf076ed8bff6d49817bed656cf03853d4c14c19563fDm
c7c905b4d230c3305d7223c1efb2e2c29d90ee0fe667ec5973b84522b52f1b7cDl
d309a7bec2af466981338b2729711aca0aac30101fc7b53822baf4eca6bf3bf3Dk
d85c7c7044bb25d459d1d3377a16e6bc25cd16ea3a67985795886527085aca81Dj
da671c2234ad85d7898dc39cf7cbbe3f81c92f9de8153ed656a948fe022cc14bDi
b73a625e6724b514380e5393dc8ac1ff68137ee32e63057c82c80eb5439701baDh
82770f241e9bdc035784ea9189503fbe592d5c29147b6f0860949963afbefbe1Dg
20385107dd6a4623cd7aaccc57b216a7fd04a22b8f56bf7e874d9fbe49095bf1Df
53cb4b1814b006d5822769285fafe984c2312ad59f2a1efd65a648bf4d1f6df1De
af07229f94ef571d7d7fa63fd7b1e5c4feaf193b6302b4faf6e64302611433ceDd
62f87a828471cada41da0e65515893c663ffb4843c97b49a68ce916292d1f8b2Dc
4dc1a1327e468460b517ab53ed5f213f2ea0b15a999fc2c3f80d7d5b477118cd
	dh.<dYaaWdJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)y`adJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)_aYdJan Horak <jhorak@redhat.com> - 6.7.8.9-15WP- Added fix for CVE-2016-5118, CVE-2016-5240, rhbz#1269562,
  rhbz#1326834, rhbz#1334188, rhbz#1269553P^cCcJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixe]cmcJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againd\ckcJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''h[cscJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJZc7cJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68HYa5cJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white images

dh.dHka5eJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white imagesYjaWeJan Horak <jhorak@redhat.com> - 6.7.8.9-17\4- Enable lcms2 support (rhbz#1585291)yiaeJan Horak <jhorak@redhat.com> - 6.7.8.9-16[^- Added fix for long convert under some circumstances (rhbz#1633602)QhcEdJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800PgcCdJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixefcmdJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdeckdJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hdcsdJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJcc7dJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68Hba5dJan Horak <jhorak@redhat.com> - 6.7.8.9-18\,@- Fixed white images

aHy&|aLu_?fDaniel Mach <dmach@redhat.com> - 0.14.8-3Rk- Mass rebuild 2013-12-27hteqfJon Ciesla <limburgher@gmail.com> - 0.14.8-2Q- Patch for double free, CVE-2013-2126, BZ 968387.^se]fJon Ciesla <limburgher@gmail.com> - 0.14.8-1Q- Latest upstream, fixes gcc 4.8 issues.SrcIeJan Horak <jhorak@redhat.com> - 6.9.10.68-7e;- Added fix for CVE-2021-40211QqcEeJan Horak <jhorak@redhat.com> - 6.9.10.68-6aK- Added fix for rhbz#2005800PpcCeJan Horak <jhorak@redhat.com> - 6.9.10.68-5_ܙ- Adding CTV-2020-29599 fixeocmeJan Horak <jhorak@redhat.com> - 6.9.10.68-4_X@- Build with openjpeg2 to support JPEG2000 againdnckeJan Horak <jhorak@redhat.com> - 6.9.10.68-3]M@- Fixing freeze when svg file contains class=''hmcseJan Horak <jhorak@redhat.com> - 6.9.10.68-2]@- Fixed ghostscript fonts, fixed multilib conflictsJlc7eJan Horak <jhorak@redhat.com> - 6.9.10.68-1]@- Rebase to 6.9.10.68
	/s-c/h~eqgJon Ciesla <limburgher@gmail.com> - 0.14.8-2Q- Patch for double free, CVE-2013-2126, BZ 968387.^}e]gJon Ciesla <limburgher@gmail.com> - 0.14.8-1Q- Latest upstream, fixes gcc 4.8 issues.e|oafDebarshi Ray <rishi@fedoraproject.org> - 0.19.4-2e6`@- Fix CVE-2021-32142
- Resolves: RHEL-9524b{o[fDebarshi Ray <rishi@fedoraproject.org> - 0.19.4-1]S- Update to 0.19.4
- Resolves: #1741274bzo[fDebarshi Ray <rishi@fedoraproject.org> - 0.19.2-1\,- Update to 0.19.2
- Resolves: #1543597|yo
fDebarshi Ray <rishi@fedoraproject.org> - 0.19.1-2\,- Remove the samples subpackage from RHEL 7
- Resolves: #1543597bxo[fDebarshi Ray <rishi@fedoraproject.org> - 0.19.1-1\- Update to 0.19.1
- Resolves: #1543597_w?fDaniel Mach <dmach@redhat.com> - 0.14.8-5.20120830git98d925RU- Mass rebuild 2014-01-24	vfDebarshi Ray <rishi@fedoraproject.org> - 0.14.8-4.20120830git98d925R=- Fix CVE-2013-1438 and CVE-2013-1439
- Resolves: #1002718
	K$]yK^e]hJon Ciesla <limburgher@gmail.com> - 0.14.8-1Q- Latest upstream, fixes gcc 4.8 issues.eoagDebarshi Ray <rishi@fedoraproject.org> - 0.19.4-2e6`@- Fix CVE-2021-32142
- Resolves: RHEL-9524bo[gDebarshi Ray <rishi@fedoraproject.org> - 0.19.4-1]S- Update to 0.19.4
- Resolves: #1741274bo[gDebarshi Ray <rishi@fedoraproject.org> - 0.19.2-1\,- Update to 0.19.2
- Resolves: #1543597|o
gDebarshi Ray <rishi@fedoraproject.org> - 0.19.1-2\,- Remove the samples subpackage from RHEL 7
- Resolves: #1543597bo[gDebarshi Ray <rishi@fedoraproject.org> - 0.19.1-1\- Update to 0.19.1
- Resolves: #1543597_?gDaniel Mach <dmach@redhat.com> - 0.14.8-5.20120830git98d925RU- Mass rebuild 2014-01-24	gDebarshi Ray <rishi@fedoraproject.org> - 0.14.8-4.20120830git98d925R=- Fix CVE-2013-1438 and CVE-2013-1439
- Resolves: #1002718L_?gDaniel Mach <dmach@redhat.com> - 0.14.8-3Rk- Mass rebuild 2013-12-27
	AFWsAeoahDebarshi Ray <rishi@fedoraproject.org> - 0.19.4-2e6`@- Fix CVE-2021-32142
- Resolves: RHEL-9524bo[hDebarshi Ray <rishi@fedoraproject.org> - 0.19.4-1]S- Update to 0.19.4
- Resolves: #1741274bo[hDebarshi Ray <rishi@fedoraproject.org> - 0.19.2-1\,- Update to 0.19.2
- Resolves: #1543597|
o
hDebarshi Ray <rishi@fedoraproject.org> - 0.19.1-2\,- Remove the samples subpackage from RHEL 7
- Resolves: #1543597bo[hDebarshi Ray <rishi@fedoraproject.org> - 0.19.1-1\- Update to 0.19.1
- Resolves: #1543597_?hDaniel Mach <dmach@redhat.com> - 0.14.8-5.20120830git98d925RU- Mass rebuild 2014-01-24	
hDebarshi Ray <rishi@fedoraproject.org> - 0.14.8-4.20120830git98d925R=- Fix CVE-2013-1438 and CVE-2013-1439
- Resolves: #1002718L	_?hDaniel Mach <dmach@redhat.com> - 0.14.8-3Rk- Mass rebuild 2013-12-27heqhJon Ciesla <limburgher@gmail.com> - 0.14.8-2Q- Patch for double free, CVE-2013-2126, BZ 968387.
	H4XHbo[iDebarshi Ray <rishi@fedoraproject.org> - 0.19.4-1]S- Update to 0.19.4
- Resolves: #1741274bo[iDebarshi Ray <rishi@fedoraproject.org> - 0.19.2-1\,- Update to 0.19.2
- Resolves: #1543597|o
iDebarshi Ray <rishi@fedoraproject.org> - 0.19.1-2\,- Remove the samples subpackage from RHEL 7
- Resolves: #1543597bo[iDebarshi Ray <rishi@fedoraproject.org> - 0.19.1-1\- Update to 0.19.1
- Resolves: #1543597_?iDaniel Mach <dmach@redhat.com> - 0.14.8-5.20120830git98d925RU- Mass rebuild 2014-01-24	iDebarshi Ray <rishi@fedoraproject.org> - 0.14.8-4.20120830git98d925R=- Fix CVE-2013-1438 and CVE-2013-1439
- Resolves: #1002718L_?iDaniel Mach <dmach@redhat.com> - 0.14.8-3Rk- Mass rebuild 2013-12-27heqiJon Ciesla <limburgher@gmail.com> - 0.14.8-2Q- Patch for double free, CVE-2013-2126, BZ 968387.^e]iJon Ciesla <limburgher@gmail.com> - 0.14.8-1Q- Latest upstream, fixes gcc 4.8 issues.
	E7})Eb"o[jDebarshi Ray <rishi@fedoraproject.org> - 0.19.2-1\,- Update to 0.19.2
- Resolves: #1543597|!o
jDebarshi Ray <rishi@fedoraproject.org> - 0.19.1-2\,- Remove the samples subpackage from RHEL 7
- Resolves: #1543597b o[jDebarshi Ray <rishi@fedoraproject.org> - 0.19.1-1\- Update to 0.19.1
- Resolves: #1543597_?jDaniel Mach <dmach@redhat.com> - 0.14.8-5.20120830git98d925RU- Mass rebuild 2014-01-24	jDebarshi Ray <rishi@fedoraproject.org> - 0.14.8-4.20120830git98d925R=- Fix CVE-2013-1438 and CVE-2013-1439
- Resolves: #1002718L_?jDaniel Mach <dmach@redhat.com> - 0.14.8-3Rk- Mass rebuild 2013-12-27heqjJon Ciesla <limburgher@gmail.com> - 0.14.8-2Q- Patch for double free, CVE-2013-2126, BZ 968387.^e]jJon Ciesla <limburgher@gmail.com> - 0.14.8-1Q- Latest upstream, fixes gcc 4.8 issues.eoaiDebarshi Ray <rishi@fedoraproject.org> - 0.19.4-2e6`@- Fix CVE-2021-32142
- Resolves: RHEL-9524
	E3g)E|+o
kDebarshi Ray <rishi@fedoraproject.org> - 0.19.1-2\,- Remove the samples subpackage from RHEL 7
- Resolves: #1543597b*o[kDebarshi Ray <rishi@fedoraproject.org> - 0.19.1-1\- Update to 0.19.1
- Resolves: #1543597_)?kDaniel Mach <dmach@redhat.com> - 0.14.8-5.20120830git98d925RU- Mass rebuild 2014-01-24	(kDebarshi Ray <rishi@fedoraproject.org> - 0.14.8-4.20120830git98d925R=- Fix CVE-2013-1438 and CVE-2013-1439
- Resolves: #1002718L'_?kDaniel Mach <dmach@redhat.com> - 0.14.8-3Rk- Mass rebuild 2013-12-27h&eqkJon Ciesla <limburgher@gmail.com> - 0.14.8-2Q- Patch for double free, CVE-2013-2126, BZ 968387.^%e]kJon Ciesla <limburgher@gmail.com> - 0.14.8-1Q- Latest upstream, fixes gcc 4.8 issues.e$oajDebarshi Ray <rishi@fedoraproject.org> - 0.19.4-2e6`@- Fix CVE-2021-32142
- Resolves: RHEL-9524b#o[jDebarshi Ray <rishi@fedoraproject.org> - 0.19.4-1]S- Update to 0.19.4
- Resolves: #1741274
A6A	/u!lBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)e.oakDebarshi Ray <rishi@fedoraproject.org> - 0.19.4-2e6`@- Fix CVE-2021-32142
- Resolves: RHEL-9524b-o[kDebarshi Ray <rishi@fedoraproject.org> - 0.19.4-1]S- Update to 0.19.4
- Resolves: #1741274b,o[kDebarshi Ray <rishi@fedoraproject.org> - 0.19.2-1\,- Update to 0.19.2
- Resolves: #1543597
 r 2ulBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)B1ulBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
0k-lThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)ofwflrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|(1:DNW	`
ir{

!*3<FOXaku~" +!/"2$7%9&<'A(C)F*K+M,P-U.W/Z0_1a3d4i5k6n7s8u9x:};<=>	?@ABCDE F%G'H*I/J1K4L9M;N>OCPEQHRMSOTRUWVYW\XaYcZf[k\m^r_w`~abcd&e0f:gDhNiXjbkllsnyopqrst u'v,
..I7k+lThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.6u-lBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)a5uSlBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-4kslThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)Y3uAlBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	9u!mBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)c8k_lThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r <umBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)B;umBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
:k-mThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..IAk+mThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.@u-mBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)a?uSmBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)->ksmThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)Y=uAmBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	Cu!nBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)cBk_mThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r FunBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)BEunBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
Dk-nThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..IKk+nThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.Ju-nBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)aIuSnBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-HksnThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)YGuAnBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	Mu!oBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)cLk_nThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r PuoBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)BOuoBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
Nk-oThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..IUk+oThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.Tu-oBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)aSuSoBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-RksoThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)YQuAoBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	Wu!pBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)cVk_oThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r ZupBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)BYupBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
Xk-pThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..I_k+pThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.^u-pBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)a]uSpBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-\kspThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)Y[uApBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	au!qBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)c`k_pThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
,t.\Dr,D~
8376cfa512fe6b2ff76656a962eb9991e84736e4a697d521ce94ef01b76d8224D}
96e5936275322903cfbb6baf53a0c7b17d256a8f32f01311f863e027c6f7d955D|
1eae80c524fc2bc5a90ced35062890a40b5625b866e658c984d2c21a6b84fbdaD{
0d7ee838bc95b1ca0f6653c7bb6bf7f82fd91bddf5008eb108ab46da2a4a15a4Dz
bcf2e159d49fe0cc5b342fc05255f862141272c22ce694e38e0133129e1ca198Dy
6a1e8e996df86eab01a9069d9b5a346d8a727e6c633a9f89b1adef59b208e01dDx
cbb13427dedac5cf271bc5a5113b736a34f96516510eb972cb3320ae396950fbDw
80bdac5815e2cb87ffd8f9a1347f373f9a9ced0b8d2fe36ed814bd54f4ef39faDv
366db37e736f288688e2f7de25a2589d720f57d0ee9d9147989b609d9dfea648Du
9b6de03afb9e2ed1eb1fe326e14a90ed08a67cee15e148db6d1d484cd4022e4cDt
d7b21ff17ce56f83ff2000fca6f369f4160b7c039d960862da62ff6aab5c8df3Ds
3cbf76c62b3dabd78db73ad0e95a34d50022e61f36e7a967aabcc7f9c3f4c6ccDr
2020ae44e6c85c50fdf7fbfec19d2bbaf6f8395f641b1b48c4743285b9fd8bdcDq
121ed67b550b9b757c921a1f6eba668e72a8d28d183054b14f8e1d37b81b602b
 r duqBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)BcuqBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
bk-qThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..Iik+qThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.hu-qBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)aguSqBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-fksqThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)YeuAqBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	ku!rBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)cjk_qThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r nurBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)BmurBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
lk-rThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..Isk+rThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.ru-rBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)aquSrBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-pksrThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)YouArBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	uu!sBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)ctk_rThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r xusBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)BwusBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
vk-sThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..I}k+sThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.|u-sBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)a{uSsBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-zkssThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)YyuAsBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	u!tBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)c~k_sThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r utBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)ButBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
k-tThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..Ik+tThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.u-tBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)auStBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-kstThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)YuAtBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
		u!uBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)ck_tThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r uuBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)BuuBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)

k-uThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..Ik+uThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.u-uBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)auSuBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-ksuThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)Y
uAuBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	u!vBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)ck_uThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r uvBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)BuvBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
k-vThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..Ik+vThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.u-vBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)auSvBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-ksvThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)YuAvBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	u!wBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)ck_vThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r  uwBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)BuwBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
k-wThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..I%k+wThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.$u-wBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)a#uSwBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-"kswThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)Y!uAwBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	'u!xBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)c&k_wThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r *uxBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)B)uxBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
(k-xThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..I/k+xThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties..u-xBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)a-uSxBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-,ksxThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)Y+uAxBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	1u!yBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)c0k_xThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r 4uyBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)B3uyBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
2k-yThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..I9k+yThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.8u-yBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)a7uSyBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-6ksyThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)Y5uAyBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	;u!zBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)c:k_yThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r >uzBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)B=uzBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
<k-zThomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..ICk+zThomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.Bu-zBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)aAuSzBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-@kszThomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)Y?uAzBeniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	Eu!{Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)cDk_zThomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r Hu{Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)BGu{Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
Fk-{Thomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..IMk+{Thomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.Lu-{Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)aKuS{Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-Jks{Thomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)YIuA{Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	Ou!|Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)cNk_{Thomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r Ru|Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)BQu|Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
Pk-|Thomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..IWk+|Thomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.Vu-|Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)aUuS|Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-Tks|Thomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)YSuA|Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	Yu!}Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)cXk_|Thomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r \u}Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)B[u}Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
Zk-}Thomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..Iak+}Thomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.`u-}Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)a_uS}Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-^ks}Thomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)Y]uA}Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
	cu!~Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.0-6]B@- core: fix activation of ovs slaves after a service restart (rh #1733709)cbk_}Thomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)
 r fu~Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-3^[- ovs: allow changing mac address of bridges and interfaces (rh #1740557)Beu~Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.4-2]@- dhcp: include conditionals from existing dhclient configuration (rh #1758550)
- core: fix sending ARP announcements (rh #1767681)
dk-~Thomas Haller <thaller@redhat.com> - 1:1.18.4-1]- Update to 1.18.4 release
- cli: fix bash completion for slave-types (rh #1654062)
- core: improve handling of policy routing rules when restarting daemon (rh #1696881)
- ifcfg-rh: preserve existance of ethernet setting in profile (rh #1703960)
- tui: only add bond options to profile that are supported by tui (rh #1715720)
- cli: fix resetting default value for properties (rh #1715887)
- core: fix detecting parent device by connection's UUID (rh #1716438)
- core: fix setting IPv6 route options and destination (rh #1727193)
- core: support more "arp_validate" bond options (rh #1730793)
..Ikk+~Thomas Haller <thaller@redhat.com> - 1:1.18.8-1^@- Update to 1.18.8 relase
- ifcfg-rh: handle "802-1x.{,phase2-}ca-path" (rh #1841397, CVE-2020-10754)
- ifcfg-rh: handle 802-1x.pin properties.ju-~Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-4^@- ip-tunnel: set cloned-mac-address only for layer2 tunnel devices (rh #1832170)aiuS~Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-3^- Update translations (rh #1796852)-hks~Thomas Haller <thaller@redhat.com> - 1:1.18.6-2^- vpn: gracefully handle invalid routes from VPN plugins
- workaround g_strtoll() failing with EAGAIN (rh #1797915)YguA~Beniamino Galvani <bgalvani@redhat.com> - 1:1.18.6-1^- Update to 1.18.6 release
- cli: unset "ipv[46].never-default" when setting "ipv[46].gateway" (rh #1785039)
- core: keep MTU of MACsec and MAC-VLAN interfaces in sync with parent (rh #1723690)
- core: forbid autoactivation of parent when it is blocked by user request (rh #1765566)
`m[iSumit Bose <sbose@redhat.com> - 0.8.1-8\@- Various updates for RHEL-7.7
- many adcli-krb5-????? directories are created /tmp [#1588596]
- adcli exports kerberos ticket with old kvno [#1642546]
- [RFE] Have `adcli join` work without FQDN in `hostname` output [#1595911]
- Improve handling of service principals [#1644311]
- [RFE] adcli command with --unix-* options doesn't update
  values in UnixAttributes Tab for user [#1337489]
- [RFE] adcli join should preserve SPN added by adcli preset-computer [#1630187]
- [RFE] Need an option for adcli command which will show domain join status. [#1622583]clk_~Thomas Haller <thaller@redhat.com> - 1:1.18.8-2_ts@- Backport OVS related fixes (rh #1871935)
- ovs: support changing the MTU of ovs interfaces (rh #1820052)
- ovs: fix race condition in setting MAC address (rh #1852106)

fs,W;fD
3d9697b9d1df6afe1e6f7753c817927e77aab45d8ae4e6b00aab690614c170a3D

27b3a6d5e1c664607297b18087e7b61c8f79281dcd08b501d6a4a98d0f06ccc1D	
2eebe28ab1f164eeb8573869c86de47b750d8a043f1b3897566fe0753003f2a4D
43e5f421e8e3c2fe23f7a93bd002c12ec11faf3194b342d07ee3a9f9fb37a875D
dc1ec1c4e74af368428ce982615f87d7121b8baea33bec02313d1f3b501a036eD
892fa4df2150169a5c8680af75e4e63f2ffbf5ca0f9dafb19d1928769a5769b9D
e291f44f4466940d2b21380d3d68e50016685dad9868bd9563a304233da7eca0D
da160f160c233fe77d6e2113aad1a189ed766c41fc8254b49f764306d9538dc9D
b8b4286c072a6e2914a35c1f9d77c2d2f6fc910361424e0fd362363d7d5d74a7D
82e901dcdc6ecc6088013e726925ea0a208b449014b09f844465ad5d7b305805D
f7e3acc601ed8b9698fbc58cf297b2ad5a49ead168e515f329e2d95f3cd8083dD
e00e4e27e76a7ce874a947e6df6282be03c80787552e9101d00197dc467c0182D
db29a04632a66bb63dd0b015dea1aadce0cd2e22371225ebfeec0ec5dec16c02
-OV-r]ESumit Bose <sbose@redhat.com> - 0.8.1-13^@- adcli should be able to Force LDAPS over 636 with AD Access Provider w.r.t sssd [#1786776]q]KSumit Bose <sbose@redhat.com> - 0.8.1-12]o@- adcli info should send netlogin pings to all domain controllers, not only a subset [#1685138]up]Sumit Bose <sbose@redhat.com> - 0.8.1-11]e@- Fixes and improvements for RHEL-7.8
- Issue is that with arcfour-hmac as first encryption type in the config ... [#1683745]
- adcli update --add-samba-data does not work as expected [#1738573]#o]mSumit Bose <sbose@redhat.com> - 0.8.1-10]QT- adcli is failing with "Couldn't add keytab entries: FILE:/etc/krb5.keytab:
  Cannot allocate memory" [1665162]n[5Sumit Bose <sbose@redhat.com> - 0.8.1-9\- Fixes for RHEL-7.7 updates
- additional patch for [RFE] adcli join should preserve SPN added by adcli
  preset-computer [#1630187]
- new patches for many adcli-krb5-????? directories are created /tmp [#1588596]
(wFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.15.1-5Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildVvaQSumit Bose <sbose@redhat.com> - 0.8.1-16.1_A- add missing patch for [#1871436]u]+Sumit Bose <sbose@redhat.com> - 0.8.1-16_@- adcli: couldn't connect to KEYRING:persistent:0:krb_ccache_jgrrBI8 [#1871436]t]5Sumit Bose <sbose@redhat.com> - 0.8.1-15^(@- More fixes for RHEL-7.9
- No longer able to delete computer from AD using adcli [#1840752]
- adcli: presetting $computer in $domain domain failed: Cannot set computer
  password: Authentication error [#1762633]js]{Sumit Bose <sbose@redhat.com> - 0.8.1-14^=@- Fixes for RHEL-7.9
- Update' adcli update --add-samba-data ' info under correct section in man adcli [#1774622]
- [abrt] [faf] adcli: raise(): /usr/sbin/adcli killed by 6 [#1802258]
sQesc~gcRadovan Sroka <rsroka@redhat.com> - 0.15.1-12X- RHEL 7.4 ERRATUM
  Resolves: rhbz#1377215}m%Daniel Kopecek <dkopecek@redhat.com> - 0.15.1-11W@- Corrected typos in the default configuration file
  Resolves: rhbz#1304334)|mgDaniel Kopecek <dkopecek@redhat.com> - 0.15.1-10Wm - Updated the default configuration file. New defaults contributed
  by Steve Grubb.
  Resolves: rhbz#1304334{kMDaniel Kopecek <dkopecek@redhat.com> - 0.15.1-9Su- Don't require prelink on aarch64 and ppc64le
  Resolves: rhbz#1078555
  Resolves: rhbz#1125462Mz_?Daniel Mach <dmach@redhat.com> - 0.15.1-8RU- Mass rebuild 2014-01-24My_?Daniel Mach <dmach@redhat.com> - 0.15.1-7Rk- Mass rebuild 2013-12-27+xkmDaniel Kopecek <dkopecek@redhat.com> - 0.15.1-6R|@- warn if processing prelinked binary objects and the prelink binary
  is not available
  Resolves: rbhz#1004826

T#msTb_iHonza Horak <hhorak@redhat.com> - 1.5.2-5Rx@- Rebuild for mariadb-libs
  Related: #1045013L]?Daniel Mach <dmach@redhat.com> - 1.5.2-4Rk- Mass rebuild 2013-12-27h_uJan Kaluza <jkaluza@redhat.com> - 1.5.2-3Q- do not build with freetds when it is not availableF[5Joe Orton <jorton@redhat.com> - 1.5.2-2Qd- update for aarch64C[/Joe Orton <jorton@redhat.com> - 1.5.2-1Qd- update to 1.5.2hcqJon Ciesla <limburgher@gmail.com> - 1.4.1-8Q@- Apply private patch from Merge Review BZ 225254.^_aJan Kaluza <jkaluza@redhat.com> - 1.4.1-7PM@- ensure we use latest libdb5 (not libdb4)R[MJoe Orton <jorton@redhat.com> - 1.4.1-6P@- use -lldap_r instead of -lldapteRadovan Sroka <rsroka@redhat.com> - 0.15.1.1a@- backported fix for CVE-2021-45417
  resolves: rhbz#2041952cgcRadovan Sroka <rsroka@redhat.com> - 0.15.1-13X@- RHEL 7.4 ERRATUM
  Resolves: rhbz#1400548

IbhIb_iHonza Horak <hhorak@redhat.com> - 1.5.2-5Rx@- Rebuild for mariadb-libs
  Related: #1045013L]?Daniel Mach <dmach@redhat.com> - 1.5.2-4Rk- Mass rebuild 2013-12-27h_uJan Kaluza <jkaluza@redhat.com> - 1.5.2-3Q- do not build with freetds when it is not availableF[5Joe Orton <jorton@redhat.com> - 1.5.2-2Qd- update for aarch64C[/Joe Orton <jorton@redhat.com> - 1.5.2-1Qd- update to 1.5.2h
cqJon Ciesla <limburgher@gmail.com> - 1.4.1-8Q@- Apply private patch from Merge Review BZ 225254.^_aJan Kaluza <jkaluza@redhat.com> - 1.4.1-7PM@- ensure we use latest libdb5 (not libdb4)R[MJoe Orton <jorton@redhat.com> - 1.4.1-6P@- use -lldap_r instead of -lldap
o=Luboš Uhliarik <luhliari@redhat.com> - 1.5.2-6.1dZ5- Resolves: #2196120 - CVE-2022-25147 apr-util: out-of-bounds writes
  in the apr_base64L	]?Daniel Mach <dmach@redhat.com> - 1.5.2-6RU- Mass rebuild 2014-01-24

IbhIb_iHonza Horak <hhorak@redhat.com> - 1.5.2-5Rx@- Rebuild for mariadb-libs
  Related: #1045013L]?Daniel Mach <dmach@redhat.com> - 1.5.2-4Rk- Mass rebuild 2013-12-27h_uJan Kaluza <jkaluza@redhat.com> - 1.5.2-3Q- do not build with freetds when it is not availableF[5Joe Orton <jorton@redhat.com> - 1.5.2-2Qd- update for aarch64C[/Joe Orton <jorton@redhat.com> - 1.5.2-1Qd- update to 1.5.2hcqJon Ciesla <limburgher@gmail.com> - 1.4.1-8Q@- Apply private patch from Merge Review BZ 225254.^_aJan Kaluza <jkaluza@redhat.com> - 1.4.1-7PM@- ensure we use latest libdb5 (not libdb4)R[MJoe Orton <jorton@redhat.com> - 1.4.1-6P@- use -lldap_r instead of -lldapo=Luboš Uhliarik <luhliari@redhat.com> - 1.5.2-6.1dZ5- Resolves: #2196120 - CVE-2022-25147 apr-util: out-of-bounds writes
  in the apr_base64L]?Daniel Mach <dmach@redhat.com> - 1.5.2-6RU- Mass rebuild 2014-01-24

IbhIb&_iHonza Horak <hhorak@redhat.com> - 1.5.2-5Rx@- Rebuild for mariadb-libs
  Related: #1045013L%]?Daniel Mach <dmach@redhat.com> - 1.5.2-4Rk- Mass rebuild 2013-12-27h$_uJan Kaluza <jkaluza@redhat.com> - 1.5.2-3Q- do not build with freetds when it is not availableF#[5Joe Orton <jorton@redhat.com> - 1.5.2-2Qd- update for aarch64C"[/Joe Orton <jorton@redhat.com> - 1.5.2-1Qd- update to 1.5.2h!cqJon Ciesla <limburgher@gmail.com> - 1.4.1-8Q@- Apply private patch from Merge Review BZ 225254.^ _aJan Kaluza <jkaluza@redhat.com> - 1.4.1-7PM@- ensure we use latest libdb5 (not libdb4)R[MJoe Orton <jorton@redhat.com> - 1.4.1-6P@- use -lldap_r instead of -lldapo=Luboš Uhliarik <luhliari@redhat.com> - 1.5.2-6.1dZ5- Resolves: #2196120 - CVE-2022-25147 apr-util: out-of-bounds writes
  in the apr_base64L]?Daniel Mach <dmach@redhat.com> - 1.5.2-6RU- Mass rebuild 2014-01-24

IbhIb0_iHonza Horak <hhorak@redhat.com> - 1.5.2-5Rx@- Rebuild for mariadb-libs
  Related: #1045013L/]?Daniel Mach <dmach@redhat.com> - 1.5.2-4Rk- Mass rebuild 2013-12-27h._uJan Kaluza <jkaluza@redhat.com> - 1.5.2-3Q- do not build with freetds when it is not availableF-[5Joe Orton <jorton@redhat.com> - 1.5.2-2Qd- update for aarch64C,[/Joe Orton <jorton@redhat.com> - 1.5.2-1Qd- update to 1.5.2h+cqJon Ciesla <limburgher@gmail.com> - 1.4.1-8Q@- Apply private patch from Merge Review BZ 225254.^*_aJan Kaluza <jkaluza@redhat.com> - 1.4.1-7PM@- ensure we use latest libdb5 (not libdb4)R)[MJoe Orton <jorton@redhat.com> - 1.4.1-6P@- use -lldap_r instead of -lldap(o=Luboš Uhliarik <luhliari@redhat.com> - 1.5.2-6.1dZ5- Resolves: #2196120 - CVE-2022-25147 apr-util: out-of-bounds writes
  in the apr_base64L']?Daniel Mach <dmach@redhat.com> - 1.5.2-6RU- Mass rebuild 2014-01-24

IbhIb:_iHonza Horak <hhorak@redhat.com> - 1.5.2-5Rx@- Rebuild for mariadb-libs
  Related: #1045013L9]?Daniel Mach <dmach@redhat.com> - 1.5.2-4Rk- Mass rebuild 2013-12-27h8_uJan Kaluza <jkaluza@redhat.com> - 1.5.2-3Q- do not build with freetds when it is not availableF7[5Joe Orton <jorton@redhat.com> - 1.5.2-2Qd- update for aarch64C6[/Joe Orton <jorton@redhat.com> - 1.5.2-1Qd- update to 1.5.2h5cqJon Ciesla <limburgher@gmail.com> - 1.4.1-8Q@- Apply private patch from Merge Review BZ 225254.^4_aJan Kaluza <jkaluza@redhat.com> - 1.4.1-7PM@- ensure we use latest libdb5 (not libdb4)R3[MJoe Orton <jorton@redhat.com> - 1.4.1-6P@- use -lldap_r instead of -lldap2o=Luboš Uhliarik <luhliari@redhat.com> - 1.5.2-6.1dZ5- Resolves: #2196120 - CVE-2022-25147 apr-util: out-of-bounds writes
  in the apr_base64L1]?Daniel Mach <dmach@redhat.com> - 1.5.2-6RU- Mass rebuild 2014-01-24

IbhIbD_iHonza Horak <hhorak@redhat.com> - 1.5.2-5Rx@- Rebuild for mariadb-libs
  Related: #1045013LC]?Daniel Mach <dmach@redhat.com> - 1.5.2-4Rk- Mass rebuild 2013-12-27hB_uJan Kaluza <jkaluza@redhat.com> - 1.5.2-3Q- do not build with freetds when it is not availableFA[5Joe Orton <jorton@redhat.com> - 1.5.2-2Qd- update for aarch64C@[/Joe Orton <jorton@redhat.com> - 1.5.2-1Qd- update to 1.5.2h?cqJon Ciesla <limburgher@gmail.com> - 1.4.1-8Q@- Apply private patch from Merge Review BZ 225254.^>_aJan Kaluza <jkaluza@redhat.com> - 1.4.1-7PM@- ensure we use latest libdb5 (not libdb4)R=[MJoe Orton <jorton@redhat.com> - 1.4.1-6P@- use -lldap_r instead of -lldap<o=Luboš Uhliarik <luhliari@redhat.com> - 1.5.2-6.1dZ5- Resolves: #2196120 - CVE-2022-25147 apr-util: out-of-bounds writes
  in the apr_base64L;]?Daniel Mach <dmach@redhat.com> - 1.5.2-6RU- Mass rebuild 2014-01-24

IbhIbN_iHonza Horak <hhorak@redhat.com> - 1.5.2-5Rx@- Rebuild for mariadb-libs
  Related: #1045013LM]?Daniel Mach <dmach@redhat.com> - 1.5.2-4Rk- Mass rebuild 2013-12-27hL_uJan Kaluza <jkaluza@redhat.com> - 1.5.2-3Q- do not build with freetds when it is not availableFK[5Joe Orton <jorton@redhat.com> - 1.5.2-2Qd- update for aarch64CJ[/Joe Orton <jorton@redhat.com> - 1.5.2-1Qd- update to 1.5.2hIcqJon Ciesla <limburgher@gmail.com> - 1.4.1-8Q@- Apply private patch from Merge Review BZ 225254.^H_aJan Kaluza <jkaluza@redhat.com> - 1.4.1-7PM@- ensure we use latest libdb5 (not libdb4)RG[MJoe Orton <jorton@redhat.com> - 1.4.1-6P@- use -lldap_r instead of -lldapFo=Luboš Uhliarik <luhliari@redhat.com> - 1.5.2-6.1dZ5- Resolves: #2196120 - CVE-2022-25147 apr-util: out-of-bounds writes
  in the apr_base64LE]?Daniel Mach <dmach@redhat.com> - 1.5.2-6RU- Mass rebuild 2014-01-24

IbhIbX_iHonza Horak <hhorak@redhat.com> - 1.5.2-5Rx@- Rebuild for mariadb-libs
  Related: #1045013LW]?Daniel Mach <dmach@redhat.com> - 1.5.2-4Rk- Mass rebuild 2013-12-27hV_uJan Kaluza <jkaluza@redhat.com> - 1.5.2-3Q- do not build with freetds when it is not availableFU[5Joe Orton <jorton@redhat.com> - 1.5.2-2Qd- update for aarch64CT[/Joe Orton <jorton@redhat.com> - 1.5.2-1Qd- update to 1.5.2hScqJon Ciesla <limburgher@gmail.com> - 1.4.1-8Q@- Apply private patch from Merge Review BZ 225254.^R_aJan Kaluza <jkaluza@redhat.com> - 1.4.1-7PM@- ensure we use latest libdb5 (not libdb4)RQ[MJoe Orton <jorton@redhat.com> - 1.4.1-6P@- use -lldap_r instead of -lldapPo=Luboš Uhliarik <luhliari@redhat.com> - 1.5.2-6.1dZ5- Resolves: #2196120 - CVE-2022-25147 apr-util: out-of-bounds writes
  in the apr_base64LO]?Daniel Mach <dmach@redhat.com> - 1.5.2-6RU- Mass rebuild 2014-01-24

IbhIbb_iHonza Horak <hhorak@redhat.com> - 1.5.2-5Rx@- Rebuild for mariadb-libs
  Related: #1045013La]?Daniel Mach <dmach@redhat.com> - 1.5.2-4Rk- Mass rebuild 2013-12-27h`_uJan Kaluza <jkaluza@redhat.com> - 1.5.2-3Q- do not build with freetds when it is not availableF_[5Joe Orton <jorton@redhat.com> - 1.5.2-2Qd- update for aarch64C^[/Joe Orton <jorton@redhat.com> - 1.5.2-1Qd- update to 1.5.2h]cqJon Ciesla <limburgher@gmail.com> - 1.4.1-8Q@- Apply private patch from Merge Review BZ 225254.^\_aJan Kaluza <jkaluza@redhat.com> - 1.4.1-7PM@- ensure we use latest libdb5 (not libdb4)R[[MJoe Orton <jorton@redhat.com> - 1.4.1-6P@- use -lldap_r instead of -lldapZo=Luboš Uhliarik <luhliari@redhat.com> - 1.5.2-6.1dZ5- Resolves: #2196120 - CVE-2022-25147 apr-util: out-of-bounds writes
  in the apr_base64LY]?Daniel Mach <dmach@redhat.com> - 1.5.2-6RU- Mass rebuild 2014-01-24

IbhIbl_iHonza Horak <hhorak@redhat.com> - 1.5.2-5Rx@- Rebuild for mariadb-libs
  Related: #1045013Lk]?Daniel Mach <dmach@redhat.com> - 1.5.2-4Rk- Mass rebuild 2013-12-27hj_uJan Kaluza <jkaluza@redhat.com> - 1.5.2-3Q- do not build with freetds when it is not availableFi[5Joe Orton <jorton@redhat.com> - 1.5.2-2Qd- update for aarch64Ch[/Joe Orton <jorton@redhat.com> - 1.5.2-1Qd- update to 1.5.2hgcqJon Ciesla <limburgher@gmail.com> - 1.4.1-8Q@- Apply private patch from Merge Review BZ 225254.^f_aJan Kaluza <jkaluza@redhat.com> - 1.4.1-7PM@- ensure we use latest libdb5 (not libdb4)Re[MJoe Orton <jorton@redhat.com> - 1.4.1-6P@- use -lldap_r instead of -lldapdo=Luboš Uhliarik <luhliari@redhat.com> - 1.5.2-6.1dZ5- Resolves: #2196120 - CVE-2022-25147 apr-util: out-of-bounds writes
  in the apr_base64Lc]?Daniel Mach <dmach@redhat.com> - 1.5.2-6RU- Mass rebuild 2014-01-24
nrseTomáš Mráz <tmraz@redhat.com> - 3.1.13-20U- build the package with hardening flags (PIE, full RELRO)sreTomáš Mráz <tmraz@redhat.com> - 3.1.13-18T.- filter environment variables not acceptable in bash inputNqa?Daniel Mach <dmach@redhat.com> - 3.1.13-17RU- Mass rebuild 2014-01-24@p{Marcela Mašláňová <mmaslano@redhat.com> - 3.1.13-16RΏ@- the correct solution is remove smp_flags, they don't work properly on ppc with
  the option mpower7
- Related: rhbz#1048745o{)Marcela Mašláňová <mmaslano@redhat.com> - 3.1.13-15Rʚ- remove old changelogs
- ppc fail to rebuild package
- Resolves: rhbz#1048745no=Luboš Uhliarik <luhliari@redhat.com> - 1.5.2-6.1dZ5- Resolves: #2196120 - CVE-2022-25147 apr-util: out-of-bounds writes
  in the apr_base64Lm]?Daniel Mach <dmach@redhat.com> - 1.5.2-6RU- Mass rebuild 2014-01-24

er+V:eD
552aefa94572e48c27a350e1ef2936db101b0d78eba2ef8d8369a651e1bbd1dfD
bb6e90b56d4b253121d4d970d8427ccc31a51594a6631e598efd9c3a3c659156D
cb5931215d156696cbe58219e39202ac72b87128adece13396ffa94ab6dad395D
586962e501bdd67c2893b8019c9cdcd07d6767b123c3fe8e93e64e94439c832bD
b05cbfb8155501322d2372a41219a106a3f361ad36d86f1e9fcf2f235dd2e63cD
328461666a24e217d010ef9c4a1fa1802b6a66e769d41f06e0f36ef5390ce3b5D
0a712b8f1eda25e3f9a256fe884b8e622404b2f830abfa7cb7a720a164b44109D
7d5e6120ec65accb2c5c369568085687a5c6a5b1b8a72db4eab223aeff60b971D
b1fc5ae8c9c372eb9d1971e1612aa3947e2c1b7fb9700813c9c66f35908dd4b3D
d7f65f5f9fa39de94807feafc132da13d35ac5d5d8864bf8bb7af2099bd8163eD
56771785cffde9bcf2a1b33447024e6a12a3805c64a69be7e940a45fda1e2824D

73839ad166f5daa6f4e5a2a9b08686fda05962283302afa1963df3b66c4b53e0D
f9a5378694573063ecf61c516d27731ba3a515cc1b91bfced9a7057634a8d54c
]U]y{)Marcela Mašláňová <mmaslano@redhat.com> - 3.1.13-15Rʚ- remove old changelogs
- ppc fail to rebuild package
- Resolves: rhbz#1048745`xe_Jan Staněk <jstanek@redhat.com> - 3.1.13-25b- re-import selinux support from upstreamOwe=Tomáš Mráz <tmraz@redhat.com> - 3.1.13-24[W- log the jobs being runveTomáš Mráz <tmraz@redhat.com> - 3.1.13-23Yo@- fix the ownership of the spool directory (#1414228)
- document the -n option of atd (#739870)
- fix handling of the aborted jobs (due to possibly
  temporary conditions) and avoid flooding the sysloghueoTomáš Mráz <tmraz@redhat.com> - 3.1.13-22WB- SIGPIPE should not be ignored in atd (#1338039)etegTomáš Mráz <tmraz@redhat.com> - 3.1.13-21Wo@- correct the DST correction when using UTC time specification (#1328832)
- clear non-job files from at dir and test for write error on fclose
  to fix bogus syslog messages
<uheoTomáš Mráz <tmraz@redhat.com> - 3.1.13-22WB- SIGPIPE should not be ignored in atd (#1338039)e~egTomáš Mráz <tmraz@redhat.com> - 3.1.13-21Wo@- correct the DST correction when using UTC time specification (#1328832)
- clear non-job files from at dir and test for write error on fclose
  to fix bogus syslog messagesr}eTomáš Mráz <tmraz@redhat.com> - 3.1.13-20U- build the package with hardening flags (PIE, full RELRO)s|eTomáš Mráz <tmraz@redhat.com> - 3.1.13-18T.- filter environment variables not acceptable in bash inputN{a?Daniel Mach <dmach@redhat.com> - 3.1.13-17RU- Mass rebuild 2014-01-24@z{Marcela Mašláňová <mmaslano@redhat.com> - 3.1.13-16RΏ@- the correct solution is remove smp_flags, they don't work properly on ppc with
  the option mpower7
- Related: rhbz#1048745
bFbtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode`e_Jan Staněk <jstanek@redhat.com> - 3.1.13-25b- re-import selinux support from upstreamOe=Tomáš Mráz <tmraz@redhat.com> - 3.1.13-24[W- log the jobs being runeTomáš Mráz <tmraz@redhat.com> - 3.1.13-23Yo@- fix the ownership of the spool directory (#1414228)
- document the -n option of atd (#739870)
- fix handling of the aborted jobs (due to possibly
  temporary conditions) and avoid flooding the syslog
x~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
	u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPS
1'(H1uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU
w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`Uw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~ wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1'uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
&u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t%uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf$u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858#uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt"uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU!w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`U,w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog+u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode*gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~)wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm(uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~4wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm3uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black2uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
1u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t0uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf/u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858.uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt-uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1;uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
:u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t9uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf8u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168587uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt6uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU5w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`U@w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog?u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode>gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~=wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm<uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~HwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormGuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackFuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Eu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tDuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfCu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858BuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStAuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1OuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Nu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tMuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfLu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858KuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStJuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUIw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`UTw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogSu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeRgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~QwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormPuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~\wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm[uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackZuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Yu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tXuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfWu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858VuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStUuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1cuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
bu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tauwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf`u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858_uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt^uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU]w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`Uhw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialoggu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modefgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~ewStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormduiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~pwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormouiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blacknuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
mu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tluwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfku[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858juCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStiuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor

er+V:eD%
81673643543357b7e306b0565d82bcd642537fefb2eb0244c2dc8b1dbe481c2bD$
7a7b265708dca056a11cfae6ae29db41405f54311ecc3a62636751d2e8044546D#
5530c892f1f2952996a03043005582fd05142b2402c3d3ba2d871149e6f6b902D"
cb353d5c74471de09be7e0fd09fe8cc300e96b28268cedc2c0c08e286daf5f95D!
a1015ebe13614d40e027fbd95e9c012b121af65537d9fa42d84ae37bd4b3f77aD 
8ce3c00b5ddec20bc2e8b9298da33c7143687fe46bc2765f98f31a35a820ac4dD
da01a171c185a98e0fc00bd31c919dcde123a4f0d7b42379acae4b7bd481a35aD
275d7c54ef8b97dfca3a0aeae434bcf2bc9cc690357c78c2944a06043dd90fbeD
d20149409ae526dab742784b326a5dd70b37681effe645a6221fdfc0adcaf401D
fdff2f1a1756e0f2d41cfa80f3b32907c40bd0172a470e140d1cb91e3b1dbecaD
b0fbae2e0eb181380b19d158478bf7d42c9f4424384f6f24d8b1d95b7a9954b9D
8a6f4b746d5edf5cd1a9c83d8f03ddbe3050f70230be328aa88328d12100ea4bD
43797987bd1c6a7789711b4d44fcbdd981073b3086621718cadbafddd9a64625
1'(H1wuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
vu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresftu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858suCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStruwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUqw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`U|w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog{u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modezgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~ywStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormxuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858~uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt}uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t	uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`Uw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~
wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`U$w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog#u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode"gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~!wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~,wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm+uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
)u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t(uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf'u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858&uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt%uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H13uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
2u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t1uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf0u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858/uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt.uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU-w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`U8w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog7u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode6gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~5wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm4uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~@wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm?uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black>uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
=u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t<uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf;u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858:uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt9uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1GuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Fu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tEuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfDu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858CuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStBuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUAw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`ULw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogKu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeJgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~IwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormHuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~TwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormSuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackRuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Qu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tPuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfOu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858NuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStMuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1[uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Zu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tYuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfXu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858WuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStVuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`U`w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog_u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode^gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~]wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm\uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~hwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormguiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackfuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
eu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tduwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfcu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858buCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStauwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1ouCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
nu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tmuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresflu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858kuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStjuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUiw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`Utw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogsu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modergIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~qwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormpuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black

er+V:eD2
40e08209c8de5003d4423a0ad7ed9c6b0f8180f4ac00c11d42d96a7a5069ebdbD1
0dafa08f6f467ecca9fd5fafad09fcd5cac9b1f2f050f88329a90f3434c52078D0
cfeadf715a776582bc168121a31f85069becc17f2556be2c3ea11c7d6040209dD/
6d1d56332454173cddc2595690e7c56c35decdfd2263853829c0fd32e430c247D.
3525be93a809d42aa8d6b8563d5762f4fd6f25a1b228b65589656a65c2bbba4aD-
e638dd51d9159ae8157653edb26aaf106eb560ae53f15fb80efa319e41e729b6D,
29938eb53cc7e9d2d0198a3a51f899d7a6d63659353fc78aac0dd24310a2cd39D+
dd33037be3199f5576c54b56155a6558f0ffc24162964a2a3f1e2dd0be0681c8D*
a1186ec734eb9834a2715c84b38c55a5efc049d49063deb03d006c6cbc9dd48cD)
0ddc672fbbf22b385a04e5922c34037d8950a75fb1cd0527f909bcc1783abb9fD(
46604e7e63c82851d300be853fd43bec9f863d6c14a9a404185a9c0fe6b88932D'
cfeef0c73c66033047dc4cf15b633dace6008e084cb069e2c95d1c60abffd496D&
04c1cb44a333186da972033dd6cf11d36780a1631c165568ae8099544c2c1543
!
~|wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm{uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackzuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
yu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849txuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfwu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858vuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt~uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU}w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`Uw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck

u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858
uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt	uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`Uw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~$wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm#uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black"uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
!u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1+uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
*u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t)uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf(u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858'uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt&uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU%w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`U0w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog/u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode.gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~-wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm,uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~8wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm7uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black6uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
5u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t4uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf3u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168582uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt1uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1?uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
>u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t=uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf<u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858;uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt:uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU9w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`UDw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeBgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~AwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm@uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~LwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormKuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackJuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Iu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tHuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfGu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858FuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStEuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1SuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Ru'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tQuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfPu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858OuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStNuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUMw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`UXw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogWu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeVgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~UwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormTuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~`wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm_uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black^uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
]u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t\uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf[u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858ZuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStYuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1guCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
fu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849teuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfdu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858cuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStbuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUaw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogofflrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|x;y@zH{O|T}\~chpw|$,38@GLT[`hot|$+08?DLSX`glt{#(07<DKPX_dlsxÏďŏƏ Ǐ(ȏ/ɏ4ʏ<ˏC̏H͏PΏWϏ\ЏdяkҏpӏxՏ֐אِؐېܐ ݐ%ߐ(-4:AHNU\bipv}

`Ulw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogku-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modejgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~iwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormhuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~twStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormsuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackruCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
qu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tpuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfou[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858nuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStmuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor

er+V:eD?
53cf10100297e3ee9624975cc473fc78d64bd6ad2a0106e1e5fd695e76c2ce9cD>
334cdf2e5acff8ba4421fc51d46210b1cc6cca7070a3a55c0b71135ea842a3c7D=
cda41b361d863ac2471e67f30a37dfa1d776eb1ecdfd24b6d620d454ea726cf4D<
e55f24cd7b3be8300c44b260f1159a66b99a1775ff2fe6134024d8c234f14559D;
0184b3c53d99c0d7a743fc2eefaec2158d3ccddc254688d6b5fed77bcdaf78d0D:
39ac208f2aaeedee724d09ffc9d779294a7721cd83807bbda081d0114bd94acdD9
fad6c8c1ae7000eeba2040a8163e5cc4920ac0d48ff08d1634dbe24df69b112dD8
5b0b31c3c4aa723f9a677d0ccaea58da6ec37710d6177cb930b490c716240bf8D7
be0ce9e4ff4bdfae6a6868243b708bb09deb84a5401d6d59e749b0aa376ff432D6
5d2375f20cc25e073efba76f4aeff505ebc4d30019f64ff6c16696cf30c075d2D5
11d3ec6a7cbf0f5ab4a611abed3a8e577bdb9e6c35243dff95e929892554069cD4
64701408bd6314de93c364f1b1a6d1f58f607d97f62aed713456040f9a7d6a21D3
7b8ac8b33b435a9814ec099de17eab143568599d591c4426da4cffcce26808a6
1'(H1{uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
zu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tyuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfxu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858wuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStvuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUuw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`Uw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode~gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~}wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm|uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t
uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt
uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU	w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`Uw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1#uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
"u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t!uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`U(w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog'u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode&gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~%wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm$uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~0wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm/uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black.uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
-u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t,uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf+u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt)uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H17uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
6u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t5uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf4u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168583uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt2uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU1w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`U<w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog;u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode:gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~9wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm8uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~DwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormCuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackBuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Au'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t@uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf?u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858>uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt=uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1KuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Ju'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tIuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfHu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858GuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStFuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUEw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`UPw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogOu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeNgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~MwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormLuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~XwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormWuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackVuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Uu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tTuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfSu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858RuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStQuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1_uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
^u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t]uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf\u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858[uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStZuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUYw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`Udw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogcu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modebgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~awStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm`uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~lwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormkuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackjuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
iu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849thuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfgu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858fuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSteuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1suCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
ru'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tquwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfpu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858ouCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStnuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUmw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`Uxw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogwu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modevgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~uwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormtuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black

er+V:eDL
fdb3d033e3ca54175fbc3432d0eaabe73a06e7062247eadf1c8f79411c315081DK
9888e1c7e5a6ba68fcb281294fab022f976b2e122801da77461f2029f281517bDJ
b5a2b6df0e41a71f9cfd396eaf57386bb3c21a06e22de723d7391c558e82402fDI
327a16cb84103e242030ecfe69ccf4a3d6b745ebcaa6a416efaf9fd6b57dbb18DH
cb993c6b41619d0b739c98a53cc2ca52430d470822dc5d7f74a0f2761581971bDG
497675cb6d7517ba23fea71659d07fd3761c557cdf9fd151aa544223dbc11237DF
ffe6c8fe6239af5ba9b802d1110485c57c37832e367d2ff85fa1252c920e1193DE
89c58d30f7f1b409bf2172a4eb140ffdd938bbe72118610420ec4abc9c64eff6DD
03a8c1b34a6e0348a56c5f5c1e6d5f586c514da1b01b442feaf2c7dfec629173DC
fb0edda86631e065ab929a5645c3c5c9573ef194bf8813617457f152c46177e3DB
6814c1585ec14edaecfb3a1c411a60fa17aa216d2f668964f68de8ee908ba367DA
bf547b98a8486311d474acce3d85c5eab20067359561488db6243baf1f10d389D@
31678e32384951f2d0803f480a17916c8967a20bfa4c0a7b627436b112c717fd
!
~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black~uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
}u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t|uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf{u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858zuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStyuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`Uw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode
gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~	wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt
uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`U w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~(wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm'uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black&uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
%u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t$uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf#u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858"uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt!uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1/uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
.u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t-uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf,u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858+uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt*uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU)w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`U4w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog3u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode2gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~1wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm0uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~<wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm;uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black:uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
9u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t8uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf7u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168586uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt5uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1CuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Bu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tAuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf@u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858?uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt>uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU=w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`UHw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogGu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeFgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~EwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormDuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~PwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormOuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackNuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Mu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tLuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfKu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858JuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStIuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1WuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Vu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tUuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfTu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858SuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStRuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUQw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`U\w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog[u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeZgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~YwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormXuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~dwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormcuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackbuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
au'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t`uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf_u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858^uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt]uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1kuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
ju'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tiuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfhu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858guCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStfuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUew5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`Upw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogou-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modengIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~mwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormluiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~xwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormwuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackvuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
uu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849ttuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfsu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858ruCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStquwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor

er+V:eDY
98c4c14b7a0910ce624cb7b36dfb871441e4dc7f083e2dc7b39b52dfce97238fDX
f023965895ca396ee7837ef741c80807f3fcd4e941fe9b021ef6476083832b31DW
2a3e32785639d588761d6bf2e56e7121d3b1a72e11b62d59b95a594bbfe19836DV
ac61f136dfa8ec37083c4218f10c4b90438fde96c223895a6e3d08660c0652f3DU
7cf9167bef9413a9b392bca9faff3196f5c05d3ec73a6d3e2429936ca11db4a3DT
9fe95cd53733c5ac4fb1ee1e907acf53ce9a1661cc2b2e83a473ca67ae9bfc46DS
5c57f76aba32a986317ac294945a789bd49f7cd09491d4a66c8c259b336a13dbDR
fbae91cfe9ae73876a8eeb3b715dacaef2f15103aae6c0a6040a7aec6578cc0dDQ
3ec6e9340959cede8f65ef85eb65d48800aad8e51db71b9f3bd47bed04cd9c3aDP
33aa69d7f9394b9a6d1d03cca5e79975ae42fc6d8a6d1794ebe7bfcf8d3bf01aDO
fb3f399c2cd3a00d11861039ba16df58c2d041ebce64824acdef0563df4d8ed8DN
a27a74e92715fbe40b9a7d67bedad0e62952307a43ea09eecd25aa1667294bd5DM
a93df30801aba8cea190c36d5bfa44f375fde46284080e1a7e93e5873bc75bb9
1'(H1uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
~u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t}uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf|u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858{uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStzuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUyw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
`Uw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
!
~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
	u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursor
1'(H1uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU
w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
h[wIan Kent <ikent@redhat.com> - 5.0.7-109][- bz1728914 - getmntent returns additional "-hosts" entries when
  automounter is used with "hosts" map
  - fix missing initialization of autofs_point flags.
- Related: rhbz#1728914d[oIan Kent <ikent@redhat.com> - 5.0.7-108]M`@- bz1728914 - getmntent returns additional "-hosts" eڂgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackntries when
  automounter is used with "hosts" map
  - remove unused function has_fstab_option().
  - remove unused function reverse_mnt_list().
  - remove a couple of old debug messages.
  - fix amd entry memory leak.
  - fix unlink_mount_tree() not umounting mounts.
  - add ignore mount option.
  - use ignore option for offset mounts as well.
  - add config option for "ignore" mount option
  - use bit flags for autofs mount types in mnt_list.
  - use mp instead of path in mnt_list entries.
  - always use PROC_MOUNTS to make mount lists.
  - add glibc getmntent_r().
  - use local getmntent_r in table_is_mounted().
  - refactor unlink_active_mounts() in direct.c.
  - don't use tree_is_mounted() for mounted checks.
  - use single unlink_umount_tree() for both direct and indirect mounts.
  - move unlink_mount_tree() to lib/mounts.c.
  - use local_getmntent_r() for unlink_mount_tree().
  - use local getmntent_r() in get_mnt_list().
  - use local getmntent_r() in tree_make_mnt_list().
- Resolves: rhbz#1728914
NQ9[Ian Kent <ikent@redhat.com> - 5.0.7-114^@- bz1847762 - automount program crashes with "malloc(): invalid next size
  (unsorted)
  - initialize struct addrinfo for getaddrinfo() calls.
  - fix quoted string length calc in expandsunent().
  - fix autofs mount options construction.
-Resolves: rhbz#1847762[7Ian Kent <ikent@redhat.com> - 5.0.7-113^A- Fix changelog revision for previous 2 commits.
- Related: rhbz#1806514 rhbz#1818664H[7Ian Kent <ikent@redhat.com> - 5.0.7-112^@- bz1818664 - autofs cannot mount samba/cifs shares that end with a dollar sign
  - fix trailing dollar sun entry expansion.
- Resolves: rhbz#1818664![iIan Kent <ikent@redhat.com> - 5.0.7-111^{G- bz1806514 - strictexpire option not set for offset mounts
  - fix patch not applied.
- Related: rhbz#1806514.[Ian Kent <ikent@redhat.com> - 5.0.7-110^{G- bz1806514 - strictexpire option not set for offset mounts
  - also use strictexpire for offsets.
- Resolves: rhbz#1806514
q=Pq[ iOIan Kent <ikent@redhat.com> - 5.0.7-116el7_9.1c- bz2107752 - autofs: send FAIL cmd/ioctl mess when encountering problems
  with mount trigger
  - fix kernel mount status notification.
- Resolves: rhbz#2107752i[yIan Kent <ikent@redhat.com> - 5.0.7-116_A- bz1885511 - automount force unlink option (-F) does not work as expected
  on autofs-5.0.7-109.el7
  - fix incorrect logical compare in unlink_mount_tree().
- Related: rhbz#1885511?[%Ian Kent <ikent@redhat.com> - 5.0.7-115_@- bz1885511 - automount force unlink option (-F) does not work as expected
  on autofs-5.0.7-109.el7
  - fix direct mount unlink_mount_tree() path.
  - fix unlink mounts umount order.
- bz1858586 - autofs share doesn't mount when using nobind over RDMA where
  nfs-server and nfs-client are the same systems
  - mount_nfs.c fix local rdma share not mounting.
- Resolves: rhbz#1885511 rhbz#1858586
3%!%[iIan Kent <ikent@redhat.com> - 5.0.7-111^{G- bz1806514 - strictexpire option not set for offset mounts
  - fix patch not applied.
- Related: rhbz#1806514.$[Ian Kent <ikent@redhat.com> - 5.0.7-110^{G- bz1806514 - strictexpire option not set for offset mounts
  - also use strictexpire for offsets.
- Resolves: rhbz#1806514h#[wIan Kent <ikent@redhat.com> - 5.0.7-109][- bz1728914 - getmntent returns additional "-hosts" entries when
  automounter is used with "hosts" map
  - fix missing initialization of autofs_point flags.
- Related: rhbz#1728914d"[oIan Kent <ikent@redhat.com> - 5.0.7-108]M`@- bz1728914 - getmntent returns additional "-hosts" eށI![9Ian Kent <ikent@redhat.com> - 5.0.7-107]@1@- bz1734057 - automount segfaults if a bad hosts entry is added
  in /etc/auto.master
  - fix reset flex scan buffer on init.
- Resolves: rhbz#1734057ntries when
  automounter is used with "hosts" map
  - remove unused function has_fstab_option().
  - remove unused function reverse_mnt_list().
  - remove a couple of old debug messages.
  - fix amd entry memory leak.
  - fix unlink_mount_tree() not umounting mounts.
  - add ignore mount option.
  - use ignore option for offset mounts as well.
  - add config option for "ignore" mount option
  - use bit flags for autofs mount types in mnt_list.
  - use mp instead of path in mnt_list entries.
  - always use PROC_MOUNTS to make mount lists.
  - add glibc getmntent_r().
  - use local getmntent_r in table_is_mounted().
  - refactor unlink_active_mounts() in direct.c.
  - don't use tree_is_mounted() for mounted checks.
  - use single unlink_umount_tree() for both direct and indirect mounts.
  - move unlink_mount_tree() to lib/mounts.c.
  - use local_getmntent_r() for unlink_mount_tree().
  - use local getmntent_r() in get_mnt_list().
  - use local getmntent_r() in tree_make_mnt_list().
- Resolves: rhbz#1728914
k4k9([Ian Kent <ikent@redhat.com> - 5.0.7-114^@- bz1847762 - automount program crashes with "malloc(): invalid next size
  (unsorted)
  - initialize struct addrinfo for getaddrinfo() calls.
  - fix quoted string length calc in expandsunent().
  - fix autofs mount options construction.
-Resolves: rhbz#1847762'[7Ian Kent <ikent@redhat.com> - 5.0.7-113^A- Fix changelog revision for previous 2 commits.
- Related: rhbz#1806514 rhbz#1818664H&[7Ian Kent <ikent@redhat.com> - 5.0.7-112^@- bz1818664 - autofs cannot mount samba/cifs shares that end with a dollar sign
  - fix trailing dollar sun entry expansion.
- Resolves: rhbz#1818664
4=P4]-5Fabio Alessandro Locati <fale@fedoraproject.org> - 1.11.109-1YJ_- Update to 1.11.109[,3Fabio Alessandro Locati <fale@fedoraproject.org> - 1.11.90-1Y$$@- Update to 1.11.90[+3Fabio Alessandro Locati <fale@fedoraproject.org> - 1.11.63-1X,- Update to 1.11.63i*[yIan Kent <ikent@redhat.com> - 5.0.7-116_A- bz1885511 - automount force unlink option (-F) does not work as expected
  on autofs-5.0.7-109.el7
  - fix incorrect logical compare in unlink_mount_tree().
- Related: rhbz#1885511?)[%Ian Kent <ikent@redhat.com> - 5.0.7-115_@- bz1885511 - automount force unlink option (-F) does not work as expected
  on autofs-5.0.7-109.el7
  - fix direct mount unlink_mount_tree() path.
  - fix unlink mounts umount order.
- bz1858586 - autofs share doesn't mount when using nobind over RDMA where
  nfs-server and nfs-client are the same systems
  - mount_nfs.c fix local rdma share not mounting.
- Resolves: rhbz#1885511 rhbz#1858586
QQ
4u'Oyvind Albrigtsen <oalbrigt@redhat.com> - 1.23.2-1.1bq@- Rebase to 1.23.2 to fix issues with upgraded libs

  Resolves: rhbz#207397953syOyvind Albrigtsen <oalbrigt@redhat.com> - 1.14.28-5Z- Append python-botocore and python-jmespath bundled directory to
  search path where needed

  Resolves: rhbz#1509434p2sqOyvind Albrigtsen <oalbrigt@redhat.com> - 1.14.28-4Zz@- Bundle python-colorama

  Resolves: rhbz#15094341sCOyvind Albrigtsen <oalbrigt@redhat.com> - 1.14.28-1Za- Update to 1.14.28
- Replace python-rsa with python-cryptography

  Resolves: rhbz#1509434]05Fabio Alessandro Locati <fale@fedoraproject.org> - 1.11.133-1Y?@- Update to 1.11.133/Fedora Release Engineering <releng@fedoraproject.org> - 1.11.109-3Yx@- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild[.1Fabio Alessandro Locati <fale@fedoraproject.org> - 1.11.109-2YJ_- Forgot to update
^.":wSiteshwar Vashisht <svashisht@redhat.com> - 4.2.46-31[@- Append '/' while tab completing directory names
  Resolves: #14953989wSiteshwar Vashisht <svashisht@redhat.com> - 4.2.46-30Y- Check for multibyte characters in commands
  Resolves: #14876158wSiteshwar Vashisht <svashisht@redhat.com> - 4.2.46-29Y@- Fix a pipe fd leak in process substitution
  Resolves: #14732457aAKamil Dudka <kdudka@redhat.com - 4.2.46-28X- CVE-2016-9401 - Fix crash when '-' is passed as second sign to popd
  Resolves: #14298386aQKamil Dudka <kdudka@redhat.com - 4.2.46-27X @- CVE-2016-7543: Fix for arbitrary code execution via SHELLOPTS+PS4 variables
  Resolves: #14260265wGSiteshwar Vashisht <svashisht@redhat.com> - 4.2.46-26XY- CVE-2016-0634: Fix for arbitrary code execution via malicious hostname
  Resolves: #1379237
i[LAaAKamil Dudka <kdudka@redhat.com - 4.2.46-28X- CVE-2016-9401 - Fix crash when '-' is passed as second sign to popd
  Resolves: #1429838@aQKamil Dudka <kdudka@redhat.com - 4.2.46-27X @- CVE-2016-7543: Fix for arbitrary code execution via SHELLOPTS+PS4 variables
  Resolves: #1426026?wGSiteshwar Vashisht <svashisht@redhat.com> - 4.2.46-26XY- CVE-2016-0634: Fix for arbitrary code execution via malicious hostname
  Resolves: #1379237j>waSiteshwar Vashisht <svashisht@redhat.com> - 4.2.46-35an@- Bump version number
  Resolves: #2015565=w!Siteshwar Vashisht <svashisht@redhat.com> - 4.2.46-34]V- BASH_CMD should not be writable in restricted shell
  Resolves: #1693181|<wSiteshwar Vashisht <svashisht@redhat.com> - 4.2.46-33\- Add support for bracketed paste mode
  Resolves: #1573901;w1Siteshwar Vashisht <svashisht@redhat.com> - 4.2.46-32\@- Add configuration option for logging bash history to syslog
  Resolves: #1160482
WziSWjHwaSiteshwar Vashisht <svashisht@redhat.com> - 4.2.46-35an@- Bump version number
  Resolves: #2015565Gw!Siteshwar Vashisht <svashisht@redhat.com> - 4.2.46-34]V- BASH_CMD should not be writable in restricted shell
  Resolves: #1693181|FwSiteshwar Vashisht <svashisht@redhat.com> - 4.2.46-33\- Add support for bracketed paste mode
  Resolves: #1573901Ew1Siteshwar Vashisht <svashisht@redhat.com> - 4.2.46-32\@- Add configuration option for logging bash history to syslog
  Resolves: #1160482DwSiteshwar Vashisht <svashisht@redhat.com> - 4.2.46-31[@- Append '/' while tab completing directory names
  Resolves: #1495398CwSiteshwar Vashisht <svashisht@redhat.com> - 4.2.46-30Y- Check for multibyte characters in commands
  Resolves: #1487615BwSiteshwar Vashisht <svashisht@redhat.com> - 4.2.46-29Y@- Fix a pipe fd leak in process substitution
  Resolves: #1473245
p?M]pNFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0:5.2-15Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildOMm5Tom Callaway <spot@fedoraproject.org> - 0:5.2-14P6@- Package NOTICE.txtlL]}Andy Grimm <agrimm@gmail.com> - 0:5.2-13P3x@- This package should not own _mavendepmapfragdir (RHBZ#850005)
- Build with maven, and clean up deprecated spec constructs
- Fix pom file (See http://jira.codehaus.org/browse/MEV-592)KFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0:5.2-12P@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildTJq;Gerard Ryan <galileo@fedoraproject.org> - 0:5.2-11O@- Inject OSGI Manifest.=IiVille Skyttä <ville.skytta@iki.fi> - 0:5.2-10O
y- Specify explicit source encoding to fix build with Java 7.
- Install jar and javadocs unversioned.
- Crosslink with JDK javadocs.
If;IUFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0:5.2-12P@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildTTq;Gerard Ryan <galileo@fedoraproject.org> - 0:5.2-11O@- Inject OSGI Manifest.=SiVille Skyttä <ville.skytta@iki.fi> - 0:5.2-10O
y- Specify explicit source encoding to fix build with Java 7.
- Install jar and javadocs unversioned.
- Crosslink with JDK javadocs.Ro9Mikolaj Izdebski <mizdebsk@redhat.com> - 0:5.2-19c@- Fix arbitrary bytecode produced via out-of-bounds writing
- Resolves: CVE-2022-42920LQ]?Daniel Mach <dmach@redhat.com> - 05.2-18Rk- Mass rebuild 2013-12-27PoMikolaj Izdebski <mizdebsk@redhat.com> - 0:5.2-17Qz- Rebuild to regenerate API documentation
- Resolves: CVE-2013-1571Oo?Mikolaj Izdebski <mizdebsk@redhat.com> - 0:5.2-16Q- Complete spec file rewrite
- Build with Maven instead of Ant
- Remove manual subpackage
#\o9Mikolaj Izdebski <mizdebsk@redhat.com> - 0:5.2-19c@- Fix arbitrary bytecode produced via out-of-bounds writing
- Resolves: CVE-2022-42920L[]?Daniel Mach <dmach@redhat.com> - 05.2-18Rk- Mass rebuild 2013-12-27ZoMikolaj Izdebski <mizdebsk@redhat.com> - 0:5.2-17Qz- Rebuild to regenerate API documentation
- Resolves: CVE-2013-1571Yo?Mikolaj Izdebski <mizdebsk@redhat.com> - 0:5.2-16Q- Complete spec file rewrite
- Build with Maven instead of Ant
- Remove manual subpackageXFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0:5.2-15Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildOWm5Tom Callaway <spot@fedoraproject.org> - 0:5.2-14P6@- Package NOTICE.txtlV]}Andy Grimm <agrimm@gmail.com> - 0:5.2-13P3x@- This package should not own _mavendepmapfragdir (RHBZ#850005)
- Build with maven, and clean up deprecated spec constructs
- Fix pom file (See http://jira.codehaus.org/browse/MEV-592)
$b{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)a{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)`{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d_wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t^wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z]{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
5i{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)h{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)g{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?f}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)e{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)md{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qc{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
p}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)po}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)n}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?m}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)l{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mk{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qj{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrf?v}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)u{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mt{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qs{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistaker{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)q{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
bb]Fbm}{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q|{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)zqStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)y}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)px}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)w}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)

er+V:eDf
664e7cfa4c02ab9121f80adbb03b0b47bb258e1ff0c45161da3208d48bf6750aDe
d6069d49f727f500878d2326ae170486edd57be2ead8d6aa3454e528b9d0cad7Dd
efe7ae6b25e582508f3ba41e0017ca4b0ffbec80692919abd79c1b54bbb43465Dc
18b2663b932253d1cd4199938857bde269a7f2c90665ff7782c334d88b68f7b7Db
42b68ad1d87236d5de03de1b7d591b6a993c1067b4bb54558ceaa48a68fff9e1Da
ecbe95651dc59d12d773005ad0f00df91c1b689c1ad0402467603a9ab799c2fbD`
7200ad28455e7f8044a9521a187ff712e7d782e9a38db84d1c18e9b54e7a9a28D_
1e67462d537e085a22099169bfc37a18a1e6f210a61839b9e0b229fcde3add6eD^
1edd338d1d20b130c1a107ea59652842ef0a8167393745468301105b2a59ca6dD]
76f7044e7f7cf0b257e3f983a0bb8457ed7e60c7c386096fd844e8a43f3614acD\
10a06eabffcd2d73d1de3fa1821108cbfe10fb4977603c9f495854984a91542bD[
958d635feece68e98a7942fb734aa2b1c79c887db56e57df5884c0a90afa291fDZ
e6f4e61f30e26ae0718f9ae0753c408d47f937201175fa1753774f9139b55f1c
xdxsStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)~{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
r/p
}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)	}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)
nZxw}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)HsStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers

s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)
~zy~g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
bb,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
V2Vr#wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)d"wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t!wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z {{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase
{ty{z){{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g({WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
'{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[&wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,%wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){$wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)
}"l}
0{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[/wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,.wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){-wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201),{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d+wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t*wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
L!2L[7wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase6{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)5{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d4wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t3wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z2{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g1{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
o)>{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)={Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d<wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t;wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z:{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g9{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
8{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
#ni#dEwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tDwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zC{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gB{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
A{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)q@{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake?{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
x^zgK{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversmJ{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qI{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeH{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)G{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)F{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
$Q{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)P{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)O{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dNwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tMwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zL{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
X{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dWwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tVwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zU{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)T{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mS{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qR{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrf_{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?^}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)]{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m\{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q[{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeZ{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)Y{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
xrf?e}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)d{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mc{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qb{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakea{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)`{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
_b]C_ml{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qk{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakej{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)i{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)h}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pg}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)f}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
ydyrqStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)q}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pp}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)o}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?n}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)m{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
n+py}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)x}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?w}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)v{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mu{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qt{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakes{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
nZv?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m~{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q}{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
|s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341){sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)z}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)

er+V:eDs
01af8dbfbd06ab846b1473d9c0c02a8f51af1a47c8d92957ff4e5508b3d647daDr
334b38af49e56e5f0435be05785e022ac744d9fb66965fc0b8baeec1fbc47653Dq
d1092d59f303a24817bad40a23bbaac2dcc1d56beef54c5d1c3d42e225090212Dp
12356c5566012c75f7cff8722dced224c1aa54d1c80a99482b0c3ec180432929Do
4b10b467e7f7d3c03d65a1978142de23e7d3b60c9c6729496eac6cd915d2e83cDn
42ff9328e94163ac1555369afb66d510954eee171420041d8a4d8bcf504fe3f8Dm
89bf5b84dc71e5ad5f0d9d9867283539d89d67b1aa0c88f54a59c8766c3d2351Dl
ae6ecf30bc0a1b8e2c0c2d8702e3eaf7db4864987e02a301446311ff1594d050Dk
58d55e76b88d088f5d397d7b1d908c6ffc3f06ec1ee82d97c1383fb167104aabDj
1a87cf953d16581b70a51f9c131f6f714e364e0a57dee8b2856b43aad7d89104Di
87690efabf1c1904d1640276e18c4a1568f33f6688bfde4c8352defdd62b25d4Dh
3f9569f5e76f2c85ea0b8843abaa2fe4d295bef235b8e3c6c65588c40bfbaad2Dg
badfc32e957614210eda392b71e458da964b3e66c2b8b1d7b457703c93fb8070
Ib]I
s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
9>{
wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r	wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)xw}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)HsStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
PatwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers

{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
~zy~g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
#$1#[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
#o)#{%wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)${Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d#wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t"wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z!{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g {WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
Pad,wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t+wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z*{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g){WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
({!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)['wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,&wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
"x"t3wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z2{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g1{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
0{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[/wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase.{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)-{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
g:{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
9{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)q8{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake7{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)6{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)5{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d4wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
$@{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)?{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)>{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d=wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t<wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z;{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
N=NG{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dFwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tEwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zD{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gC{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversmB{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qA{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
hxrfhzM{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)L{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mK{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qJ{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeI{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)H{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
"mT{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qS{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeR{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)Q{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)P{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dOwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tNwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
=d,=Z{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dYwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tXwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zW{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)?V}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)U{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
xrfa{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?`}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)_{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m^{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q]{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake\{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)[{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
xrf?g}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)f{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)me{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qd{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakec{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)b{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
Gb]MGqn{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakem{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)l{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)k{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)j}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pi}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)h}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
1 t}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)ps}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)r}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?q}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)p{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mo{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)
xrf?z}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)y{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mx{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qw{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakev{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)u{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
Jb]PJq{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)~qStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p|}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220){}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)

er+V:eD
9c36a1622791ce03d6ac94ea9fa499f523998938199fdd4b31677374da4a1118D
c19e37c8595f0a36840e5ffde24ba2022e36425cc814639db070930027e078abD~
5bc7e489f2286aea26973b124918a70b6f8f29e9936508ee68e5fa89b453002bD}
ee52c09ab7dca8a8e11fe87c0855b1ce38df1fdaef899e8ce50d80b72009b62bD|
5ea154c824570a42b00ec0dd66ecba1eb3ba53a7d8875b374a32bfc093aea76fD{
e27571469712e3c2e9c26aebde7261eee92c600cc19e6d3f6b1bc172f0234ab4Dz
5171be56dca06ca1e7da429b0b918c643f00522f432cfaa4d67aeea0ee796306Dy
f82ec6b5a321f21916898763958f2f66aa27af989f717611ee77da7475cd01dbDx
9440248086b43cdef2b59af7d4689cf4358b9549a0e882439813dcc84f72e359Dw
5d5eaf30c36d5edff16d10d59883fcd24b4d915f4f6a332fd0a4498d47a9abe2Dv
f41e3da0ff09a0dfcee4669524a544896ae845227cd61f6da9cf4fac362b2c63Du
e69d6d87e87eca926adc10baf1eeb4125ba0103b79977c638b305b870f7d2110Dt
fd7c147bd421d47e6afa077b39fee3edde95b7c1ad7a4371b4271f0aaea8ca13
1 }!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)
{ui?
}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q
{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake	{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)qStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)
Cb]ICq{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
1 }!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)
zxl? }Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)
Ib]I
%s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)$sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)#}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p"}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)!}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
q@4q?*}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m({cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q'{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeH&sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
Ib]I
/s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341).sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)-}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p,}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)+}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
9>{4wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r3wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)2wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)x1w}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)H0sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headersoffflrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|#)07>EKQX_elry
%	,
3:@
GMTZagntz
 %*/ 4":#A$G%N&U'\(c)i*p+w,~-/
012 3&4-53697?8F9L:R;Y<`=f>m?s@yABDEFGH$I)J.K4L;MANHOOPVQ]RcSjTqUxVWY
Z[\ ]'^-_3`:a@bFcMdTe[
Pat:wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z9{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g8{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
7{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[6wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,5wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
m\m
A{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[@wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,?wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){>wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r=wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)<wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)x;w}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)
!&{GwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rFwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)EwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)tDwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zC{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gB{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
PadNwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tMwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zL{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gK{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
J{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[IwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,HwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
~zy~gU{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
T{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[SwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,RwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){QwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rPwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)OwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
#$1#[\wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,[wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){ZwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rYwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)dXwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tWwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zV{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
,o),rcwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)b{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dawUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t`wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z_{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g^{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
]{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
{ty{zi{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gh{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
g{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[fwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,ewcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){dwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)
}"l}
p{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[owCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,nwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){mwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)l{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dkwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tjwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
,!2,{wwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)v{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)u{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dtwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tswuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zr{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gq{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
Pad~wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t}wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z|{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
z{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[ywCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,xwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
"x"twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)

er+V:eD

af6f8cc2f0f6c25b367a6731610bc84784ff7ff2b8355c606556d449c930b965D
a09beb8f5ef98b4539f6e145b9e6318297e4159b1e5234b77768dd9c5b344039D
13955770f0ef1cb7ca5e13e21afb4cd0cce8b0b1d8181ffddb7f3fd4fad797e1D

2eeaafbd3cb22d15a16eddd840a62f042636325ea6009b82fbb72f520fc834b2D	
ad66c6e64486ef32978fa8bc2e30651674507fed936596d70705e9e334965f98D
7a8a2950c90f28d4e41ed775b9ba97a61e78927e387a936edd2bb1ccadd3bdc7D
e024eb4fe098b64e9e4de794efbaffc32240faa47afbd2335907c1f6f78cb52bD
7e64442436c5c1978be36615d69bc4f59a79cef4c9a5819e922bc16f290cdc13D
1039cd93e11117af53816432e691fa32ce9f5c6aef8a37f44ed3c7b1291ba097D
b7454eacf95c0a09d97a1463029b82bc777116a9ed468c5edd4c0e8ec75006e6D
1cd733c69fed61cd28bbf528bf31510db3dbaaa4cbc45ab7ed8a654264b298aaD
337b3b492087333d675bf644cd7cab27fad998fd2eb5f3f1064b766e5fbf85c1D
dfe4993ac8d4d097c4e5e97fc006d27039a6a3d4cc79f87f4d56c9e79afd3a86
*%*g
{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebaseq
{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake	{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
${#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
--{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrqg {WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$&{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)%{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)${Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d#wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t"wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z!{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
N=N-{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d,wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t+wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z*{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g){WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversm({cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q'{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrfg3{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers2{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m1{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q0{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake/{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214).{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$9{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)8{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)7{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d6wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t5wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z4{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
2z2D?a)Tomas Krizek <tkrizek@redhat.com> - 11.1-1X,- update to letest upstream version
- resolves: #1393889 Rebase to bind-dyndb-ldap 11+
- resolves: #1165796 bind-dyndb-ldap crashes if server is shutting down and connection to LDAP is down
- resolves: #1413805 bind-dyndb-ldap default schema is shipped with syntax error>_)Petr Spacek <pspacek@redhat.com> - 10.0-5Wv@- resolves: #1376851 Unable to set named_write_master_zones boolean on upgrade|=_Petr Spacek <pspacek@redhat.com> - 10.0-4W@- resolves: #1366565 Deletion of DNS root zone breaks global forwarding<{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m;{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q:{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
H]H|F_Stepan Broz <sbroz@redhat.com> - 11.1-7.1fM@- Rebuild required for BIND changes for KeyTrap change (CVE-2023-50387)Em9Alexander Bokovoy <abokovoy@redhat.com> - 11.1-7]o@- Fix attribute templating in case of a missing default value
- Resolves: rhbz#1748904=DePetr Menšík <pemensik@redhat.com> - 11.1-6\b@- Bump BIND version and fix library dependecies
- Rebuild for bind 9.11.3. Minor tweaks to compile.
- Support for bind 9.11.5 headersnCe{Petr Menšík <pemensik@redhat.com> - 11.1-5[@- Resolves: #1580389 depend on bind with writeable homeBa#Tomas Krizek <tkrizek@redhat.com> - 11.1-4Yf@- Resolves: #1469563 required bind version doesn't have the dyndb interface
Aa;Tomas Krizek <tkrizek@redhat.com> - 11.1-3Y- resolves: #1436268 crash when server_id is not present in named.conf
- coverity fixesX@aSTomas Krizek <tkrizek@redhat.com> - 11.1-2X,- bump NVR to fix bind dependencies
$L{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)K{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)J{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dIwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tHwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zG{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
HHtRwu	Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zQ{{	Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)?P}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)O{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mN{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qM{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
wwY{7	Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mX{c	Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qW{k	Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeV{#	Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)U{	Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)T{	Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dSwU	Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
=-'`{7
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m_{c
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q^{k
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake]{#
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)\{
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)[{
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?Z}	Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)
=,f{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)e{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d}!
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pc}g
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)b}9
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?a}
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)
n+pm}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)l}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?k}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)j{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mi{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qh{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeg{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
nTps{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mr{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qq{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakep{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)o{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)n}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)
=,y{
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)xqStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)w}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pv}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)u}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?t}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)
n+p}g
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?~}
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)}{7
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m|{c
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{{k
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakez{#
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
nWs{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)q
Stepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!
Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)

er+V:eD
620e6945f7639eacc1508005775c37d66e64ae3f5ec915e87d132a17a45d3999D
84515e054cf47fee3e466382e25e19eb92f6f9947741105ea5f6071f7fe18185D
b7958e30f90b1219e2202114385b2a92aa2271e3064f4b5e46ba9f99c2beeef9D
a9b560ad84f4c4da2302f2f1c1581df4d699c0e0f9cf0754e125b2bab6ea4795D
28d32718cac59baf9c4162573d291af2345e664d16de912661fa18de7157ca63D
e0386a64a095ddfdf29e498080b5d77f7bb681d49c55cf461188e3263c1ab429D
94b92924f85680ecbc45ab163f775966e4511c2f9885c4c80f5e90d414a6b7edD
92aef4b8e3ee011c2535abd3662b5231c16dfc9b45c3e7649a1a6b3355518f1bD
7a15e89049ae929f16d7970980522d53b696c61a5d5ce15d47c614ac40e4e05cD
69c9b42984d2a52a135360b34ce4482f7f1f7c83bcdc685dbc6cc7db28136840D
472dfbe984defab2da4d391865a8dad49409470d075bba14d4c3b8ed3ece9e0dD
43e92b9290406137c9b3c56768f3269a089b338a410de4e2879c249fd794ac2bD
330b8ae0aa3720eeebeb9d9321a83a407e356101f5d7cb524b333e0a138ceb96
=,
s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)
}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p	}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)
n+p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
nZv?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)
Ib]I
s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
q@4q?$}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)#{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m"{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q!{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeH sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
Ib]I
)s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)(sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)'}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p&}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)%}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
9>{.wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r-wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589),wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)x+w}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)H*sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
Pat4wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z3{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g2{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
1{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[0wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,/wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
m\m
;{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[:wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,9wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){8wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r7wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)6wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)x5w}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)
!&{AwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r@wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)?wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)t>wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z={{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g<{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
PadHwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tGwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zF{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gE{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
D{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[CwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,BwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
~zy~gO{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
N{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[MwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,LwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){KwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rJwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)IwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
#$1#[VwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,UwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){TwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rSwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)dRwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tQwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zP{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
,o),r]wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)\{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d[wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tZwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zY{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gX{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
W{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
{ty{zc{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gb{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
a{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[`wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,_wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){^wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)
}"l}
j{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[iwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,hwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){gwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)f{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dewUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tdwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
,!2,{qwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)p{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)o{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dnwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tmwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zl{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gk{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
PadxwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zv{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gu{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
t{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[swCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,rwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
"x"twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z~{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g}{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
|{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[{wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebasez{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)y{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
*%*g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebaseq{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)

er+V:eD'
9a5fa14360c626a157114ece6ad7b3186a9d13ffe35b54f68fab1678618a929dD&
b822a9890f5063ab0234ba6cf91bd64b1adc0c4e2f854176b9b00a76b414ca7eD%
5b81f0de16b9e09141c5ea31f902a18f54277c2e168b86007146e71b8f29b163D$
36ae65670b57a81f320f0e21426f30d359715f401c51ab27568393a36e6d75aaD#
60b33a8a989840613908660e2204def7a4fe9b0d9cbcdf16e46b65bfc1c9bb2cD"
f3e24a8285c55480cfef6e63c976be0f143c1010b3511cdb0c8f2bc86dd82ef4D!
b9d806c4557aff349da1d626e32967c4202becbc72147a2c93ba8a440c08995cD 
ef26f87d833891a36ec1eeac1cbd5de9be6729295a8243544f11a26a7e28373aD
bd09bb37e73e22a5b20339a2eafaa7a10698dd1ebf5a8bf4c187d59b68d06a60D
56cdf3051f5fd87ff809ab1843192abe235c6093bc0a83213f73bb7ebe2a0f2aD
e87be7552176482fd5e981021e62d2dab6c7950108f44af47af3d68b9fa442a8D
e8843e39d98b4c77a9cab62b23793b825c2c78175ae84da344250acedf05778eD
ddbc53b44a7ec6dd175840df4ba96e8440a167aca06195e38f9ce8e768f82f30
$
{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d
wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t	wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
--{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrqg{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$ {#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
N=N'{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d&wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t%wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z${{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g#{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversm"{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q!{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrfg-{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers,{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m+{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q*{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake){#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)({Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$3{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)2{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)1{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d0wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t/wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z.{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
:{ Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d9wU Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t8wu Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z7{{ Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)6{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m5{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q4{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrf?@} Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)?{7 Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m>{c Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q={k Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake<{# Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214);{ Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$F{#!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)E{!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)D{!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dCwU!Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tBwu!Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zA{{!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
5M{#"Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)L{"Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)K{"Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?J}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)I{7!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mH{c!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qG{k!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
T}!"Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pS}g"Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)R}9"Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?Q}"Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)P{7"Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mO{c"Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qN{k"Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
x^z?[}#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)Z{7#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mY{c#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qX{k#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeW{##Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)V{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)U{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
_b]C_mb{c$Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qa{k$Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake`{#$Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)_{$Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)^}!#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p]}g#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)\}9#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
ydyhq$Stepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)g}!$Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pf}g$Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)e}9$Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?d}$Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)c{7$Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
xrf?n}%Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)m{7%Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)ml{c%Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qk{k%Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakej{#%Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)i{%Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
bb]Fbmu{c&Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qt{k&Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakes{#&Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)rq%Stepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)q}!%Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pp}g%Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)o}9%Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
xdx{s&Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)z}!&Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)py}g&Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)x}9&Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?w}&Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)v{7&Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
rl`?}'Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7'Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{c'Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q~{k'Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake}{#'Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
|s#&Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)
eb]Iem{c(Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{k(Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
s#'Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)s'Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!'Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}g'Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9'Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)

er+V:eD4
e08149c8f4894437d1cb9d2b60f6771c7922cc3b83c5f92705e75f509b048115D3
5af6b82a47585513d5a6a8ccc974d524ebc2a67fba642652aa75b566045b004cD2
d1270ff691bc97bc9a737c8556081408a04f2a325ffb0db2fb561a7add15d0e6D1
64c82c743b0aa34d2ad89724607562e8cf196bdaec58dcfd940a8f728ce9c754D0
e9c3f41aecb56447424691a9aedff1c7449cb17f5a1e759c6f7c7c089b2d1adfD/
6df17149302a2cb98a128880ea6df6fe1092d0cd169dda5bd470cf1dc5c73494D.
f23ad28777ef3020a0b4c72141bc0d367c9a60a8eca144eafcef471df349d126D-
0f6bed5732bc76bfe3e0c85d59ade8d7716ebb9113974ea0d93511212d1907dfD,
f9112352a12b79f2772b0d357f993f93cfbadb96eb79b1c1b7ea2072dad1e32aD+
80e8a702983be224224c674404dfed4b8a89aa2c699a0bb3c32dc8c20f0219c9D*
6cb04e523ff2e6b8d60ef0c4e8df263d8d56af10fd076b4510daa749d0d1b65dD)
28f3f06dbb75d2a2fd58b0494a47a36def1dde4acad9dde4faf9ec2d6f7c9321D(
fbdf0d211089d0219b49949e4bac45457c7c0de563ac494e01584ec1c65eb69d
xdxs(Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)
}!(Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}g(Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9(Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?
}(Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)	{7(Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
r&B{7)Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{c)Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{k)Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeHs(Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
s#(Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)
=,
s#)Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)s)Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!)Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}g)Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9)Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?})Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)
9>{w*Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rwq*Petr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)w*Petr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)xw}*Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)Hs)Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
Pat$wu*Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z#{{*Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g"{W*Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
!{!*Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[ wC*Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wc*Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
m\m
+{!+Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[*wC+Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,)wc+Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){(w+Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r'wq+Petr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)&w+Petr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)x%w}+Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)
!&{1w,Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r0wq,Petr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)/w,Petr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)t.wu+Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z-{{+Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g,{W+Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
Pad8wU,Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t7wu,Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z6{{,Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g5{W,Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
4{!,Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[3wC,Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,2wc,Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
~zy~g?{W-Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
>{!-Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[=wC-Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,<wc-Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){;w-Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r:wq-Petr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)9w-Petr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
#$1#[FwC.Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,Ewc.Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){Dw.Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rCwq.Petr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)dBwU-Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tAwu-Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z@{{-Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
,o),rMwq/Petr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)L{.Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dKwU.Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tJwu.Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zI{{.Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gH{W.Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
G{!.Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
{ty{zS{{/Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gR{W/Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
Q{!/Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[PwC/Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,Owc/Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){Nw/Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)
}"l}
Z{!0Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[YwC0Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,Xwc0Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){Ww0Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)V{/Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dUwU/Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tTwu/Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
,!2,{aw1Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)`{0Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)_{0Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d^wU0Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t]wu0Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z\{{0Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g[{W0Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
PadhwU1Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tgwu1Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zf{{1Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)ge{W1Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
d{!1Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[cwC1Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,bwc1Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
"x"towu2Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zn{{2Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gm{W2Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
l{!2Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[kwC2Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebasej{1Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)i{1Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
*%*gw{W3Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
v{!3Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[uwC3Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebaseqt{k2Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakes{#2Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)r{2Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)q{2Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dpwU2Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
$}{#3Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)|{3Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){{3Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dzwU3Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tywu3Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zx{{3Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
--{4Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwU4Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twu4Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{4Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{W4Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!4Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)q~{k3Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrqg
{W5Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
	{!5Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)m{c4Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{k4Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#4Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){4Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)

er+V:eDA
911c67bf8be2e9d6a8d64cffde6ace72707962e5ee3df52066dc91049cea2aa1D@
d3c2e1e27a400829f10a9833f70edf0886d63ded954c2aca900c1d63fd6cb984D?
0304822e8138a928f86fc2b725ede94f0fe7ad348c85d005729fc71bac0ba3b2D>
4dc25e03c0a0a30babb3b4e2d1e9e2f11733686d656dc393fa7d1a62fc9f6fc3D=
05e34813e9daef9255f5e02eb2c3753c5308d070ffe9608abf8367fedeff8e2dD<
1aa586cd752451a887e64054c0eda881403fbc6b7e9c6079ce1e356a839fd225D;
defc20ca4fb42304e9222b189cd76864191e45eb95df7eb3cb3ba3efd335419fD:
f292ac03827b0d517e0873201d36bd5f7899da820fe99fba7955de328d3e2773D9
6335456bae4a6531a1e5a588c09b5fa47d70ef61f6374951aca147a452b4eb02D8
b3204ebd71ad924147ec931e26a4e2b1126596abc3c240218c3fa6304427d289D7
33233f04e60e9c664a7bf40da5737db125bcf521206e43d06261d80d1b4babe3D6
ebf8758838f5dc246c98cc6f76706eafa07a5083df17f4fbfa2489df5db98458D5
9840fc5d69627a908ae29e24dc640f83ad9be6b88a9779079293c46cd56d1fa5
${#5Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){5Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){5Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d
wU5Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twu5Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{5Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
N=N{6Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwU6Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twu6Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{6Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{W6Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversm{c5Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{k5Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrfg{W7Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers{76Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{c6Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{k6Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#6Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){6Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$#{#7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)"{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)!{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d wU7Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twu7Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
*{8Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d)wU8Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t(wu8Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z'{{8Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)&{77Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m%{c7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q${k7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrf?0}8Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)/{78Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m.{c8Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q-{k8Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake,{#8Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)+{8Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$6{#9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)5{9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)4{9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d3wU9Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t2wu9Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z1{{9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
5={#:Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)<{:Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215);{:Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?:}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)9{79Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m8{c9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q7{k9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
D}!:Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pC}g:Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)B}9:Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?A}:Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)@{7:Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m?{c:Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q>{k:Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
x^z?K};Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)J{7;Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mI{c;Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qH{k;Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeG{#;Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)F{;Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)E{;Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
_b]C_mR{c<Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qQ{k<Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeP{#<Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)O{<Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)N}!;Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pM}g;Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)L}9;Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
ydyXq<Stepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)W}!<Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pV}g<Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)U}9<Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?T}<Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)S{7<Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
xrf?^}=Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)]{7=Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m\{c=Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q[{k=Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeZ{#=Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)Y{=Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
bb]Fbme{c>Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qd{k>Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakec{#>Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)bq=Stepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)a}!=Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p`}g=Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)_}9=Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
xdxks>Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)j}!>Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pi}g>Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)h}9>Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?g}>Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)f{7>Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
rl`?q}?Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)p{7?Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mo{c?Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qn{k?Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakem{#?Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
ls#>Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)
eb]Iemx{c@Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qw{k@Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
vs#?Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)us?Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)t}!?Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)ps}g?Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)r}9?Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
xdx~s@Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}}!@Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p|}g@Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220){}9@Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?z}@Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)y{7@Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
r&B{7APetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cAPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kAPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeHs@Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
s#@Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)
=,
	s#AStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)sAStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!APetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gAPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9APetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?}APetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)offlrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|ghhniuj{klnopqr$s+t1u8v?wFxMySzZ{a|h}o~w}
#*06=DKRX^ekqx~	!(/6=CJQX_gmtz
 &-4;BHNU[ahnsy~›ěśƛ&Ǜ-ț3ɛ:ʛA˛H̛O͛WΛ]ϛdЛjћpқwӛ}Ԝ՜
֜؜ٜڜ$ۜ+ܜ2
9>{wBPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r
wqBPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)wBPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)xw}BPetr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)H
sAStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers

er+V:eDN
dca184c57d0913cdde1f9f39c446f2cad1f8daa197d290e0f0ee296dc3b345daDM
3c96054de3771395180ce2ef6da4dfcd565ee2d14573da0adad58ff76b63d77aDL
31deb0ef8475cdf1766d7273df81d1e80842c260ddc7eac34364361b4b00b974DK
2c72fd0a8014e13440ebde0c0ae037cea29cc8aa567b3723619486dc2040f9e5DJ
fc93fa73ee589349b26030b1fd56173975859786d624ddeaf826606e99c8b4f3DI
0f79393bd746c2a784972b1db928fdca74d0c0324e00a1859ceede81d1af8b93DH
8e85466eac6dba299f3f8211333d50827e103a67a8296884c3d1d1a87ce8a828DG
43570d8e293bd93001cb8c4cac3e4b2045b3024b7f3e08f4449735bfb9d206c6DF
c779ed4a8b7cd8df613f47c214050d61ac25927ab97381ffb59944fb998585ffDE
c9392783583e0597ccdfaf17dae6fee1b00c3d8da0cb91842328276045fb62a5DD
7b3d8994d78928ac66011137e013e2d788ecc7712d592ce7c08306cfd1728489DC
90290c5f2092315060a14a82b7d692c91c1f7a1b307ffd574420dbe3936b6177DB
df8d2506c03d24e1a590d6879a32d25fc08c64674c5b3363908407344377e1dd
PatwuBTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{BPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WBArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!BArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCBPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcBPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
m\m
{!CArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rwqCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)xw}CPetr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)
!&{!wDPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r wqDPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)wDPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)twuCTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{CPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WCArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
Pad(wUDTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t'wuDTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z&{{DPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g%{WDArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
${!DArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[#wCDPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,"wcDPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
~zy~g/{WEArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
.{!EArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[-wCEPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,,wcEPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){+wEPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r*wqEPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589))wEPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
#$1#[6wCFPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,5wcFPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){4wFPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r3wqFPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)d2wUETomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t1wuETomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z0{{EPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
,o),r=wqGPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)<{FPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d;wUFTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t:wuFTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z9{{FPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g8{WFArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
7{!FArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
{ty{zC{{GPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gB{WGArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
A{!GArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[@wCGPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,?wcGPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){>wGPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)
}"l}
J{!HArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[IwCHPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,HwcHPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){GwHPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)F{GPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dEwUGTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tDwuGTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
,!2,{QwIPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)P{HPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)O{HPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dNwUHTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tMwuHTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zL{{HPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gK{WHArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
PadXwUITomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tWwuITomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zV{{IPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gU{WIArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
T{!IArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[SwCIPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,RwcIPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
"x"t_wuJTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z^{{JPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g]{WJArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
\{!JArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[[wCJPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebaseZ{IPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)Y{IPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
*%*gg{WKArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
f{!KArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[ewCKPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebaseqd{kJPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakec{#JPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)b{JPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)a{JPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d`wUJTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
$m{#KPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)l{KPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)k{KPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)djwUKTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tiwuKTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zh{{KPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
--t{LPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dswULTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)trwuLTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zq{{LPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gp{WLArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
o{!LArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)qn{kKPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrqgz{WMArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
y{!MArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)mx{cLPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qw{kLPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakev{#LPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)u{LPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
${#MPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){MPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)~{MPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d}wUMTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t|wuMTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{{MPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
N=N{NPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUNTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuNTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{NPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WNArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversm{cMPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kMPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrfg
{WOArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers{7NPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cNPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q
{kNPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake	{#NPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){NPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)

er+V:eD[
6164453fc73f06d895ca8df581d46682883daa8322bdf6c511c25bd367caea15DZ
808073e5962f5fd81e0f89ce66bccad77dea549a509cf522580257f973f2dbe4DY
f5d02c79227db8a83ef923f005bb223131cc21a7d230cd462aa73916b2da8a5aDX
0ce460c4fec36484894f526d04090272961a86fa1cadfc07b79bf7eb7f0095f6DW
e72e7e5054cec7dd0b5f52acc7183ddfcb107875c50ad6ef52f07a3785689966DV
1c21a4bf7dd0a9330e1d0f9859575f2ab5436413cea65a4a73f0b1991f3dd1ceDU
72ab9b204a4a984bb758843741ab139089f24553cac0336f08a7b1d1029030aeDT
9339fa8d6974fa8dfc8e28dbe75760c7c49d355183c0f71b2e5d7d7ea2db67dcDS
f48ce4d917bdd2d6d5ec5a6aa18216b99e980b86d7308d6e535eafb38aa0fbfcDR
f13d76a0cbcea5bf7f05f28bbb2ad0ca59d71e977f1c3f3c544f403d4f947794DQ
a1b74be1d5a4cc7822e76a9f4d891bbacc535194cb8b1f766c6b04f42b2e443aDP
e7ad03734c0fc0d4d420d177cc82478f12f8c7fcb1b49294d3f686e186915e9bDO
3d75be4567f3055d6aa45834620c4fdab40240d0eac958aa3b5401832cf284bb
${#OPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){OPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){OPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUOTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuOTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{OPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
{PPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUPTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuPTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{PPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624){7OPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cOPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kOPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrf? }PPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7PPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#PPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){PPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$&{#QPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)%{QPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)${QPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d#wUQTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t"wuQTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z!{{QPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
5-{#RPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214),{RPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)+{RPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?*}QPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)){7QPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m({cQPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q'{kQPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
4}!RPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p3}gRPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)2}9RPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?1}RPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)0{7RPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m/{cRPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q.{kRPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
x^z?;}SPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178):{7SPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m9{cSPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q8{kSPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake7{#SPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)6{SPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)5{SPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
_b]C_mB{cTPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qA{kTPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake@{#TPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)?{TPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)>}!SPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p=}gSPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)<}9SPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
ydyHqTStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)G}!TPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pF}gTPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)E}9TPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?D}TPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)C{7TPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
xrf?N}UPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)M{7UPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mL{cUPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qK{kUPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeJ{#UPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)I{UPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
bb]FbmU{cVPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qT{kVPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeS{#VPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)RqUStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)Q}!UPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pP}gUPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)O}9UPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
xdx[sVStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)Z}!VPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pY}gVPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)X}9VPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?W}VPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)V{7VPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
rl`?a}WPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)`{7WPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m_{cWPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q^{kWPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake]{#WPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
\s#VStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)
eb]Iemh{cXPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qg{kXPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
fs#WStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)esWStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)d}!WPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pc}gWPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)b}9WPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
xdxnsXStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)m}!XPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pl}gXPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)k}9XPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?j}XPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)i{7XPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
r&Bs{7YPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mr{cYPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qq{kYPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeHpsXStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
os#XStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)
=,
ys#YStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)xsYStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)w}!YPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pv}gYPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)u}9YPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?t}YPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)
9>{~wZPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r}wqZPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)|wZPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)x{w}ZPetr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)HzsYStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
PatwuZTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{ZPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WZArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!ZArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCZPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcZPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
m\m
{![Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[
wC[Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,	wc[Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){w[Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rwq[Petr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)w[Petr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)xw}[Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)
!&{w\Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rwq\Petr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)w\Petr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)twu[Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z
{{[Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{W[Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers

er+V:eDh
c5debfa2df24c434430b601b89c524d821308d5207f350610e556a17360391b5Dg
46f776adf7f88106a8e818889463dd616d261bb3462ec68346857a126aee742eDf
5105577688287233ec925ee639d92524c00f6f7490e2c5501c49eeb0f07cd511De
802a7e88deb752607d0e6f0f44f099a1dfee4747bd86101389d25eccf2a9ebe8Dd
7d49e6164c17d7539dfdc7b2354026cb06b6ee0a32b0c9218ac3d8960f348534Dc
f9e741d7af4fbcb102cf759697c858701bf8839ced08a5f62c9415ac5de9dda3Db
23886775cbbf0f0b980d7e700a1fa3cce9ae8149522a191554e770fe0acf1813Da
0d291da8585bc5dc3d72a81e494c64767eb04ba5a938f0847121edded2bcbdecD`
2974a1f35f8a1dbd3f46361c76fee7876402f098199e8208407a59471c892340D_
5380ad090ba99c100379b2fc1cf54a62f85cdfe390b04b6e5e0fe4c213aa4661D^
43a8791d748c2ca3cb5e8c1b6682319313b8373bb0e84e9e545ba09dc9e093bbD]
012bfa8eacdc2cdef0742df38d48737a13ab8171afc5020ef127dc81084a68b5D\
ffa04ef798ab2e5815f659306b1ff16a316bf5e5501788e7e0bdda2800e8afd0
PadwU\Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twu\Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{\Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{W\Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!\Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wC\Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wc\Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
~zy~g{W]Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!]Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wC]Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wc]Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){w]Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rwq]Petr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)w]Petr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
#$1#[&wC^Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,%wc^Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){$w^Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r#wq^Petr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)d"wU]Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t!wu]Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z {{]Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
,o),r-wq_Petr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589),{^Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d+wU^Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t*wu^Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z){{^Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g({W^Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
'{!^Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
{ty{z3{{_Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g2{W_Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
1{!_Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[0wC_Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,/wc_Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){.w_Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)
}"l}
:{!`Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[9wC`Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,8wc`Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){7w`Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)6{_Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d5wU_Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t4wu_Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
,!2,{AwaPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)@{`Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)?{`Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d>wU`Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t=wu`Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z<{{`Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g;{W`Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
PadHwUaTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tGwuaTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zF{{aPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gE{WaArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
D{!aArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[CwCaPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,BwcaPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
"x"tOwubTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zN{{bPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gM{WbArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
L{!bArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[KwCbPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebaseJ{aPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)I{aPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
*%*gW{WcArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
V{!cArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[UwCcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebaseqT{kbPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeS{#bPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)R{bPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)Q{bPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dPwUbTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
$]{#cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)\{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)[{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dZwUcTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tYwucTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zX{{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
--d{dPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dcwUdTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tbwudTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)za{{dPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g`{WdArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
_{!dArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)q^{kcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrqgj{WeArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
i{!eArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)mh{cdPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qg{kdPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakef{#dPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)e{dPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$p{#ePetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)o{ePetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)n{ePetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dmwUeTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tlwueTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zk{{ePetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
N=Nw{fPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dvwUfTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tuwufTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zt{{fPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gs{WfArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversmr{cePetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qq{kePetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrfg}{WgArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers|{7fPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{{cfPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qz{kfPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakey{#fPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)x{fPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
${#gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUgTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twugTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z~{{gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)

{hPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d	wUhTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuhTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{hPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624){7gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cgPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kgPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrf{iPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?}hPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7hPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{chPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q
{khPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#hPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){hPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)

er+V:eDu
7266766000b531cf157295f474f17dcfde3f6c02dca1c64d75e027774c33560fDt
5b90034629bafae7fc40e3688bcd096834f9ce5de48a7f47ccb507c4f1c06c93Ds
ef23d81c590cbf657f32525eaf60a72a65cac4272b7cfa37677546ee5204deb1Dr
44e365718f57aa02dbc0e6c0f884b3e6dd15e03acd28ab5154d917184b1d05ceDq
417df6c01f4373a219da10ea1df04e2565b5b27e4710818aa6718065c174f25fDp
fad06e13ad887025495d47068294bf443e6c6209bbb16324fa1b3eb9ef5a885eDo
4cfa5141393a1004bc9d7885fee9a606293ee21216066238700f933afd5e4598Dn
9339296f633515808554bf8032f56569d2f34d4c9a34b1d71f968cd560dfc9e2Dm
64d39cb55589918f3c7cc7eebfd7ff6020fe1f126e87eb124bd3399e6a321938Dl
d39ddef78717bb9c60b1a73d0b5bd7070471daf3610288379a07921135392492Dk
ed2d48ef1a3e3a6e64fd20780277157eee5875df3e41cf640f9569e3437be284Dj
8f9c62b62ee309f73ecbf3c62a51cb3d3b553a7505e51047083926355d41e0cdDi
898a882b2bfc15fc532825fa940804005432ab222c1efaacec472c1c18aa8c66
xrf?}iPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7iPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{ciPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kiPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#iPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){iPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
_b]C_m{cjPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kjPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#jPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){jPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)}!iPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}giPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9iPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
ydy$qjStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)#}!jPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p"}gjPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)!}9jPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)? }jPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7jPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
n+p+}gkPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)*}9kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?)}kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)({7kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m'{ckPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q&{kkPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake%{#kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
nZv?2}lPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)1{7lPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m0{clPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q/{klPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
.s#kStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)-skStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828),}!kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)
Ib]I
7s#lStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)6slStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)5}!lPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p4}glPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)3}9lPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
9>{<wmPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r;wqmPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589):wmPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)x9w}mPetr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)H8slStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
PatBwumTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zA{{mPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g@{WmArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
?{!mArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[>wCmPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,=wcmPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
~zy~gI{WnArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
H{!nArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[GwCnPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,FwcnPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){EwnPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rDwqnPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)CwnPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
#$1#[PwCoPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,OwcoPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){NwoPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rMwqoPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)dLwUnTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tKwunTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zJ{{nPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
#o)#{WwpPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)V{oPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dUwUoTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tTwuoTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zS{{oPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gR{WoArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
Q{!oArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
Pad^wUpTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t]wupTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z\{{pPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g[{WpArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
Z{!pArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[YwCpPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,XwcpPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
"x"tewuqTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zd{{qPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gc{WqArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
b{!qArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[awCqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase`{pPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)_{pPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
gl{WrArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
k{!rArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)qj{kqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakei{#qPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)h{qPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)g{qPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dfwUqTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
$r{#rPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)q{rPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)p{rPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dowUrTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tnwurTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zm{{rPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
N=Ny{sPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dxwUsTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twwusTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zv{{sPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gu{WsArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversmt{crPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qs{krPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
hxrfhz{{tPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)~{7sPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m}{csPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q|{ksPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{{#sPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)z{sPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
"m{ctPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{ktPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#tPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){tPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){tPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUtTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twutTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
=d,={uPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t
wuuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z	{{uPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)?}tPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7tPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
xrf{vPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?}uPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7uPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cuPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kuPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#uPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
{uPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)

er+V:eD
d97cd106cf9572dc73237ecabf174c9e7fd63f1831ecd180582edfe2ee993409D
29afed10faa9e050e9b84ade3202f51f3836b8d12289ddbf91099a716ea0838cD
8b2f892532b5441db04bb9a1d3ad5ae901202de8ca4725355c38b6ac842c3f60D
1a86cce369d4fa519dc82e79409e0ff8f027575c7dd5f588f2c3ca8ed78e840bD~
ec694ed3c68742fc4ff18e183f1eb03790bcac0cf47880b2b25ad5ac15c207f6D}
b1c8c2c11e1df4cb77d96713a2285d4a6059f60b0d4baf4e2122da1910d62f6fD|
6277ccdddce2fa5ee1ecc12615c107ef3a280e1716b89c5bb60d515fecf84416D{
f985f476bdedc2f9a31dcd4fddfea63520d50b7d0201272e1df3ec06366409a3Dz
cbc4ea12d67dbb0aec7f99363fd0094c3b67059cbe632d6140c54b02128a4520Dy
014f5bd144904dc6d27a7fe4b1819401d5f70ea084c8f04cf734fc30dd3fcfacDx
68dca12ceecda33b2f945d88f466ab32954ff89b462395ef6346d95a47ea375eDw
3f67c1b26c1f278f9f7675269681e617b83498e50e541a04d9a936a563d20506Dv
4ff754e3b0277c5062fbf7116cde18b1ff4c39ef530dd4fecc189d221739fe28
xrf?}vPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7vPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cvPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kvPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#vPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){vPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
Gb]MGq {kwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)}!vPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gvPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9vPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
1 &}!wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p%}gwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)$}9wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?#}wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)"{7wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m!{cwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)
xrf?,}xPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)+{7xPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m*{cxPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q){kxPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake({#xPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)'{xPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
Jb]PJq3{kyPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake2{#yPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)1{yPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)0qxStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)/}!xPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p.}gxPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)-}9xPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
1 9}!yPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p8}gyPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)7}9yPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?6}yPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)5{7yPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m4{cyPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)
{ui??}zPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)>{7zPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m={czPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q<{kzPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake;{#zPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214):qyStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)
Cb]ICqF{k{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeE{#{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
Ds#zStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)CszStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)B}!zPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pA}gzPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)@}9zPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
1 L}!{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pK}g{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)J}9{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?I}{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)H{7{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mG{c{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)
zxl?R}|Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)Q{7|Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mP{c|Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qO{k|Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
Ns#{Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)Ms{Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)
Ib]I
Ws#|Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)Vs|Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)U}!|Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pT}g|Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)S}9|Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
q@4q?\}}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)[{7}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mZ{c}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qY{k}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeHXs|Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
Ib]I
as#}Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)`s}Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)_}!}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p^}g}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)]}9}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
9>{fw~Petr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rewq~Petr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)dw~Petr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)xcw}~Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)Hbs}Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
Patlwu~Tomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zk{{~Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gj{W~Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
i{!~Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[hwC~Petr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,gwc~Petr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
m\m
s{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[rwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,qwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){pwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rowqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)nwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)xmw}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)
!&{ywPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rxwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)wwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)tvwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zu{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gt{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
PadwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z~{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g}{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
|{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[{wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,zwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
~zy~g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
#$1#[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,
wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)d
wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t	wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
,o),rwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)

er+V:eD
61925baba4d4105a8e0a3e4da4f567f21fe8f341492cc4f0d809f774ead1a48bD
5acc0609a41df6553c86c09d5b59189c6442930ac603ef8674a29954ae4a3fd3D

d6562a8f4c336171a1c63516de07f7e1ff14168c67b6aa0b7065c624836896f7D
8e8d874e43fcfca807986a24918c2f7b0c82f04d8a0ca32bc0d9523000380ae8D
f59dc733e2e61cc262d571504ef9b62561aab27935f5cc432e2109e165936dacD

3997f8bf7bec69e2b9fc0ff0a33790347a77cd30140b40f7b9a36ae91591d36eD	
f9eddb4d96fec5e873cef47d5028d8ef2534235e25948f0010a17f3da79f7835D
b2b7af7c6537a7e10965b0b999532c5684afc0b6d255efc2b50da0c38e3f168aD
9744361dc7129978289b5a40fcacd9f52369b57774ec2256bc3c078d4d6e8f03D
f0c0b3f210497c3d560f42df97307f09afe0cd687c2e08ebc1cb7b03e28b8319D
54904b5dad92e58cb221e767835398cc72621bab301b2d3964a854595d9e6d60D
f4a5bde79d6cee985d2f0ff8727b2428ec15fbdd03adaa9733b09f7b173c01c7D
87c1a04fd7037d13c6be98a8a975ef7a41eec66aa9031b781b61eabe9107ce9b
{ty{z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)
}"l}
"{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[!wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase, wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
,!2,{)wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)({Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)'{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d&wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t%wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z${{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g#{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
Pad0wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t/wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z.{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g-{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
,{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[+wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,*wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
"x"t7wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z6{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g5{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
4{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[3wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase2{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)1{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
*%*g?{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
>{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[=wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebaseq<{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake;{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214):{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)9{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d8wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
$E{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)D{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)C{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dBwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tAwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z@{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
--L{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dKwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tJwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zI{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gH{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
G{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)qF{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrqgR{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
Q{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)mP{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qO{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeN{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)M{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$X{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)W{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)V{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dUwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tTwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zS{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
N=N_{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d^wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t]wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z\{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g[{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversmZ{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qY{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeofSflrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|ޜ<ߜBIPW^elry &,39?FLRW\aflsy")07?	E
LRX
_ekry$*18?F M!T"Z#a$g%n&t'{()*+,.!/'0.142:3?4D5I6N7T8[9a:h;o<v=}>?
@ABD'E-F4G:H@IGJMKSLZM`NfOmPtQ{R
xrfge{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversd{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mc{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qb{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakea{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)`{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$k{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)j{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)i{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dhwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tgwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zf{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
r{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dqwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tpwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zo{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)n{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mm{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)ql{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrfy{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?x}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)w{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mv{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qu{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistaket{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)s{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
xrf?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)~{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m}{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q|{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)z{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
_b]C_m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
ydyqStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p
}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)	}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
n+p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
nZv?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)

er+V:eD
5cbb74a2688de09192fd42f0956329cbe2c77efa2ec5ed4d5dd90ffcdd07f898D
5fe18b0b420aaf810ed5edcf1e1fd4fa93b6639632315bdd9348ecd11d6dac60D
4f490fc935e1622edd8f29833cff99546eda921facd62b71d30c95acefada869D
e9c57b29838349dee4d11ec1d130cd0d7b3fb5df669721f178440fd42a507752D
5272f52e8e18d2702e48f4c1ff860fc6d052acf1543d9556f54efa55bbe31535D
913377ddeda7e9a87688016fb775cfe7ac678ed7b17cab277996497a766e6c67D
bd2c5200554793773e752c3edacd8567d9f6db98bf2bc3399bb18086f6b771e8D
4d2dbd65fa67b8c23648a188f830340cc1da72b5dbc71795229022de0ff9720dD
b524427963041d0c49036598caa6da026b76085863c14fdbec1466146a3b137aD
8df89d78d785928efa5b8d059e96ce33ffe0c9356663c9acb50ce3ec8c660d92D
0a8d2dafb528818f6b019015fbaf8cdd2fe3b6535d85da90f6a1db984b828e8eD
9e6c9b4224affd5105ee5ffe4355eb2e09681fde2148ce946769e1c4583a360bD
bd0b8c4bd642bf2ddec4f60168cf63044086bf8e861160721a1ffb61a553229a
Ib]I
s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
9>{$wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r#wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)"wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)x!w}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)H sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
Pat*wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z){{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g({WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
'{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[&wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,%wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
~zy~g1{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
0{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[/wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,.wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){-wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r,wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)+wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
#$1#[8wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,7wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){6wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r5wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)d4wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t3wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z2{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
#o)#{?wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)>{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d=wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t<wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z;{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g:{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
9{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
PadFwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tEwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zD{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gC{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
B{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[AwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,@wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
"x"tMwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zL{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gK{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
J{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[IwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebaseH{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)G{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
gT{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
S{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)qR{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeQ{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)P{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)O{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dNwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
$Z{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)Y{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)X{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dWwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tVwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zU{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
N=Na{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d`wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t_wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z^{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g]{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversm\{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q[{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
hxrfhzg{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)f{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)me{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qd{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakec{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)b{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
"mn{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qm{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakel{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)k{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)j{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)diwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)thwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
=d,=t{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dswUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)trwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zq{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)?p}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)o{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
xrf{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?z}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)y{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mx{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qw{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakev{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)u{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
xrf?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q~{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake}{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)|{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
Gb]MGq{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
1 }!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p
}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)
{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m	{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)
xrf?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
Jb]PJq{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)qStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)

er+V:eD)
afda0e4a1bc46470df4a4993f659a23e39c688752ccd5958b18e448a2d51f8d1D(
2eb85e9cbd29bebc8ce3cd107af06c6ae0f59fcc9a1056aa9226b8201c309a26D'
1612a4f04271f95f905580cfc4cc94695b1a11ade17803d000750d518bc0e3acD&
f5a544c1c54d159d63ecf02b66555411db8230d7164937c969ee12412a7b3426D%
3f11637118683c18d64ab08e86467d90916b689368a1c29e9b095c9b7c8e2633D$
26e0a18b1adcde25239343e4537dc1023fada0ed64e1d72e8b7a98ac795d90deD#
1b0d419b8d0ecbbebdaf88198d39462c8f0babefb9b711f46865cfaaf19e8ad2D"
ffc1d3cbc957771182427d3972e83824283b43b4272f105619d32ec0195171ceD!
b1efb67b99edebdc9042e5a1fc8376aaaf9c18620d6efda4ea95ea1b1ebc91c5D 
3059b560a681189650e415ad7288004812bfd2e3c70a86249b7a9650f86f646eD
e9972fdb7ca4cc3ff44e4f3ed37bfc724bfa5d7006592b775660808adeaacd37D
02e583fec180896fabf3422f69975545e3bd8d8460665b7044a186d0d5a4f817D
c9ec93a5f3a15917b5ceeb7e19b67519e6e4ed8b7b2df39dc7999cf6d9f4c5e5
1 !}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p }gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)
{ui?'}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)&{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m%{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q${kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake#{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)"qStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)
Cb]ICq.{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake-{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
,s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)+sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)*}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p)}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)(}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
1 4}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p3}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)2}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?1}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)0{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m/{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)
zxl?:}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)9{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m8{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q7{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
6s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)5sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)
Ib]I
?s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)>sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)=}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p<}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220);}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
q@4q?D}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)C{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mB{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qA{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeH@sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
Ib]I
Is#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)HsStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)G}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pF}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)E}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
9>{NwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rMwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)LwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)xKw}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)HJsStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
PatTwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zS{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gR{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
Q{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[PwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,OwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
m\m
[{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[ZwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,YwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){XwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rWwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)VwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)xUw}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)
!&{awPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r`wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)_wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)t^wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z]{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g\{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
PadhwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tgwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zf{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)ge{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
d{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[cwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,bwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
~zy~go{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
n{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[mwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,lwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){kwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rjwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)iwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
#$1#[vwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,uwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){twPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rswqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)drwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tqwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zp{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
,o),r}wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)|{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d{wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tzwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zy{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gx{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
w{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
{ty{z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){~wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)
}"l}
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[	wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
,!2,{wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t
wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
PadwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
"x"twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)

er+V:eD6
05ba725d5c869c501d11a5e7d8127d0ad80d328b3e6147d560401baf1810497bD5
516201be4c2a553028eb1f983417912a1b05f800b8989fcd30a55f89623a57b6D4
1f800a61ea4b98c012916d84ad280573560d18bf31af0e459b43494dbf907a0dD3
edfa799d5c426dea0808d52912a4ed39b1534c8e7a5d3dc0a96937be66990f1cD2
9ed16457c6de56bbd64bcca2285bd78861c098822395446cc3a1c693ffb69c77D1
bc1b8404e2707eba59addc78201595f614f7350f97cf87e924e6f6dbac90b3c3D0
2953e2a9ba9042a9c5ebb93523d595d91f7367d8b83dc5b40a473e85572478b2D/
0f0f20e5079748f9103ff3e0068108043ec9079822de5e46263c2c1f09b6dc0dD.
c0a3bcd41e5beba5e539861177a8ed67f9626d4b21b11ab1b621770a53bf3137D-
43e8db14504b7b1b92c33224717880dd9e4ea6101787efd5f0da89bc9bf2d7a0D,
ebbfadfcdd945e3b5ae40adb51fb4d444facc09bdd9f9cc989542bfed2cdee60D+
5ca5234e59243cc5ced75e11bc9ad434a82d86c5fa5eab71a130bd3c3ae49334D*
d4718c0bcf9365bfcd07e9c307952a12ae32802cbc6bde5707222c30c90cbb85
*%*g'{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
&{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[%wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebaseq${kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake#{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)"{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)!{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
$-{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214),{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)+{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d*wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t)wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z({{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
--4{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d3wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t2wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z1{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g0{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
/{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)q.{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrqg:{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
9{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)m8{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q7{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake6{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)5{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$@{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)?{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)>{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d=wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t<wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z;{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
N=NG{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dFwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tEwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zD{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gC{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversmB{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qA{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrfgM{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversL{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mK{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qJ{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeI{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)H{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$S{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)R{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)Q{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dPwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tOwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zN{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
Z{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dYwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tXwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zW{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)V{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mU{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qT{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrf?`}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)_{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m^{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q]{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake\{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)[{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$f{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)e{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)d{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dcwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tbwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)za{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
5m{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)l{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)k{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?j}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)i{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mh{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qg{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
t}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)ps}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)r}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?q}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)p{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mo{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qn{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
x^z?{}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)z{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)my{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qx{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakew{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)v{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)u{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
_b]C_m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)~}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)|}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
ydyqStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
xrf?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)
{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)	{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
bb]Fbm{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)qStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
xdxsStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
rl`?!}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178) {7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)

er+V:eDC
32f0185e8d6a9ab586922827519f1f38fb921fcaff260385904d3e61dd029d44DB
3d4d0d965fc073d950dd63507c1b1287648ef59c103d02cf09891c04bd99e930DA
d0428b24d84b75519bce64c115f13b151f065712ac094dcd035dc9b63bbdc664D@
0d953611a4ac63b86ca9bbf1ca0f35e9ef53094123f9e581e16919ed0393c690D?
40ceb41cf108321fdafc40bff1168cbc4f3e85a9ec271d6b55e946ed83697fb7D>
86d0b148abfa317696a046ac187cb479b242ea3f9ec769e6891130395ea172a9D=
b3e23051f12c034b848268c08321e17a519c484640546a3ae90e7f99b36e7174D<
9ea26fb857c06b7e275a794a125b7880359b3911861019696cd35074ee1063d3D;
ba3bba99a83841a7ef214b159627a5734756196a37510565d94c55e374ab6dc9D:
6c557f44383a709d2f0b400c2b77b432a965e5b7d4507ed1ecaf15fd92b55760D9
932e0ad4e24e0525ba464544c1e8e10938e5fe172b6f926e51a12e6e2874b3edD8
98cb7a80b5609722e12d6cd1a4562d0177f0672359013887fde3560ec9647c8fD7
83e71037aa03cb56d8e5d9d0d2f0e410673cb723d0cf4f81dff15ea65830fd59
eb]Iem({cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q'{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
&s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)%sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)$}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p#}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)"}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
xdx.sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)-}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p,}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)+}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?*}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)){7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
r&B3{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m2{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q1{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeH0sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
/s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)
=,
9s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)8sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)7}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p6}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)5}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?4}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)
9>{>wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r=wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)<wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)x;w}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)H:sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
PatDwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zC{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gB{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
A{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[@wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,?wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
m\m
K{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[JwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,IwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){HwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rGwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)FwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)xEw}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)
!&{QwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rPwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)OwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)tNwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zM{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gL{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
PadXwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tWwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zV{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gU{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
T{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[SwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,RwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
~zy~g_{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
^{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[]wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,\wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){[wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rZwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)YwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
#$1#[fwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,ewcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){dwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rcwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)dbwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tawuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z`{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
,o),rmwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)l{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dkwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tjwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zi{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gh{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
g{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
{ty{zs{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gr{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
q{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[pwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,owcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){nwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)
}"l}
z{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[ywCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,xwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)v{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)duwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)ttwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
,!2,{wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d~wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t}wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z|{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
PadwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
"x"twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g
{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase
{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)	{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
*%*g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebaseq{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
${#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
--${Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d#wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t"wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z!{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g {WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake

er+V:eDP
566646f7e600ab8480640215904fa6db201c8d068ab3d6f8b7e348bf1ad1fd34DO
b97a0e1f72d3fb43f706975f8e02ff0c130ef35fc6b4763eb18db88980fcde25DN
922e0899bd8cf38bf10d752a0549435a450f968969520194880a2484c23f16dfDM
61a1892c950bfc4a208064a4e1d8a4d65876ca4891cc730ee2b045f0f37f7794DL
9a717dd3b5eb02f5b812a44d5dde08db1964e2500b23bb7518df5c5083372f36DK
72e5967a31cc0ef1edc116fd15578c5e906edd2f9c5485a13dfaf37b191efb7cDJ
07ef29e54e22c90b43aa4eb7133046f805b01fd91030eafee283ca4db4b35173DI
b09f1f08469f4eb7a40b74f2e3cd25fa408b93d9213c6bdbc7ef21b1ee1ac8a9DH
1a1a8ca0b3ee1af1eea431740811a8a48d9564e81093de7dc250d46e47d3383fDG
1c0761e63af4f982fec4bf5ddbda7da44c1f6472883839db48386eaaac902785DF
9e951fe6f09cc5cf1402211e1232a2a92d029d66404daf66003bfc285052a41dDE
27e369dd165f3e4ff6b99227422febe5eb07cd10c6962ce831eade5566e16b91DD
22eb2233053a534b388c3ed8e39dfa1b4901d5e8b1e278a8c843c301c9db2488
xrqg*{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
){!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)m({cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q'{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake&{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)%{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$0{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)/{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215).{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d-wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t,wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z+{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
N=N7{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d6wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t5wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z4{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g3{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversm2{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q1{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrfg={WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers<{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m;{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q:{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake9{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)8{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
$C{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)B{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)A{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d@wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t?wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z>{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
J{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dIwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tHwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zG{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)F{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mE{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qD{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrfQ{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?P}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)O{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mN{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qM{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeL{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)K{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
xrf?W}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)V{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mU{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qT{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeS{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)R{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
_b]C_m^{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q]{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake\{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)[{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)Z}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pY}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)X}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
ydydqStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)c}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pb}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)a}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?`}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)_{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
n+pk}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)j}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?i}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)h{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mg{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qf{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakee{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
nZv?r}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)q{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mp{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qo{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
ns#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)msStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)l}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)
Ib]I
ws#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)vsStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)u}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pt}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)s}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
9>{|wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r{wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)zwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)xyw}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)HxsStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
PatwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[~wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,}wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
~zy~g	{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
#$1#[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r
wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z
{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
#o)#{wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
PadwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
"x"t%wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z${{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g#{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
"{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[!wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase {Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)

er+V:eD]
ca5ee1ff2a858d3eaf6bbed3a7c0421519183d99018689b9d2bfb4f8b2bdb122D\
02b9f36207f55eecbaed6219e76bf38881875be99f49e0eca71ec75e6d3a7aa3D[
235100bdba26a1af51c7f66f533d9318837d01dafa0c5e822245c8e0e5469978DZ
1efc77004111254487934c32f189a3b3fc8b1baf00a6e8350558183281f3855dDY
f6274f5c3cd73beb54d94229fd5b93b99b525f50921dae06b852ca0ada18b5b9DX
955704fe8de0bbcec645e44f2b204e4b12ce8b7bd2c8bfaba5e8968ee76f0568DW
74f4bb31b79790aa5a646612520c06cdd181b6e3e39b90a65dfc2634c1821260DV
cf810cc7447c597839d02d5738646b8afcdb25edddcbd9cfbd3173d5a01cf3a3DU
089b94f213c170e875e90bb476e333d4b7d2491e323f4692f8e1513f78b4203eDT
8724fc26052010a537fbffaecee3413ede14b44646e26a456c4c8695f5f259c0DS
11e7a9eb9ad854ce3901deb76ff9ab3e462f87d56766b9cda133c1fbcc89d812DR
1a7fc39e7d481badbe2fe10dd40d290dcdefdeb4f572a8affee7880a751d5805DQ
f7789c32ac34827df4b6c180e845361bb70aa1fcbc165a6c2a533559f2bc3f76
g,{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
+{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)q*{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake){#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)({Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)'{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d&wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
$2{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)1{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)0{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d/wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t.wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z-{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)offlrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|TUVW!Y(Z.[3\9]>^D_K`QaXb_cfdmesfzghijkl$n*o0p7q=rCsJtQuWv^wdxkyrzw{||}	~%,29?FMSZ`fmsy!(/6<CJPW]dipv}
%+29?FLSZ_djqx
!(§.ç4ħ:ŧAƧHǧOȧVɧZ
N=N9{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d8wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t7wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z6{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g5{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversm4{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q3{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
hxrfhz?{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)>{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m={cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q<{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake;{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214):{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
"mF{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qE{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeD{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)C{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)B{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dAwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t@wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
dmM{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qL{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeK{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)J{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)I{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?H}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)G{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
vdvS{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)R}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pQ}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)P}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?O}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)N{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
n+pZ}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)Y}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?X}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)W{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mV{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qU{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeT{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
nWs`{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m_{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q^{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake]{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)\qStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)[}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)
=,
fs#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)esStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)d}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pc}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)b}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?a}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)
m}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pl}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)k}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?j}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)i{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mh{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qg{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
*z%*rswqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)rwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)xqw}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)HpsStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
os#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)nsStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)
{ty{zy{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gx{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
w{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[vwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,uwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){twPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)
q`q
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,~wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){}wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)r|wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)tzwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
!E,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
C2C{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d
wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g
{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
	{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase
{ty{z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)
"#g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
$!{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214) {Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
--({Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d'wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t&wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z%{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g${WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
#{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)q"{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake

er+V:eDj
32af5400af5619a7e1f0c43f574170ae98cfd7cdc7e831f572b8d05530bd8913Di
850be6d438290af4b3c31805a40c2f8a88e4e751bafa1bb02b6b884736f80ef2Dh
8317594c4733bc6fd9c13e0001d962d14e7bffb83ed66e6337f6b8a490067ea9Dg
a191bcc40fb33d21a6109e116756d8999e60adb5535583f65d05f51ff3047463Df
f43e7c1792d357cd5fb1ac5a13e744a5ba50e7309444d7ab7d0149227755b575De
f6c854fef6008f3f063c3ed1c4f6a2e51821b5fe057282702dfcd15b7783bd41Dd
87d3a6a27aa6179e43d778cec0765e166b68510a391d6eea5236b2e70d6d746bDc
fdb600cfe62d10fb9b78089a4daae03dd3010232a321c952510faa95723d5a60Db
dd3bfb74354db34116d2bb2b298b233f3d005acdb7709c1ea17dd9dede2e0566Da
d1870d7298e93c62411f7b0b728df981e13f75ca9fdac1fb117b0e2d50d3b71fD`
2924951f311fafa5d17831ab4e1bd85bee2bd6d9ed591445149b5fd70152d077D_
4552c0e9031fc5f990a165feb17e2cd243461f760cb80e75769c837d1052f193D^
8908f58fb71fd39056da9b792dd69e358735856d43352a085ffea8b4b8f2039e
#xr#t/wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z.{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g-{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversm,{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q+{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake*{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
ww6{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m5{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q4{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake3{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)2{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)1{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d0wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
$<{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214);{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215):{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d9wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t8wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z7{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
5C{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)B{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)A{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?@}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)?{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m>{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q={kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
J}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pI}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)H}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?G}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)F{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mE{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qD{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrf?P}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)O{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mN{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qM{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeL{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)K{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
bb]FbmW{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qV{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeU{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)TqStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)S}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pR}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)Q}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
xdx]sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)\}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p[}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)Z}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?Y}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)X{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
r/pd}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)c}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?b}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)a{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m`{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q_{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
^s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)
nZxiw}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)HhsStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
gs#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)fsStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)e}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)
~zy~gp{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
o{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[nwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,mwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){lwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rkwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)jwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
bb,vwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){uwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rtwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)swPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)trwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zq{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
V2Vr}wqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)d|wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t{wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zz{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gy{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
x{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase
{ty{z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){~wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)
}"l}
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[	wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)
L!2L[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t
wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
o){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
#ni#dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
x^zg%{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversm${cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q#{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake"{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)!{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215) {Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)

er+V:eDw
ad525efce24792177db9c59af54a5822206dc0ec6f5b18770062ca07e51ac4caDv
f2cbc4c0d7d808554f9689174450c43f80db727c186bd3a1980494886a25212aDu
0834c02bc349eaabe64a4015d07ee7cbcf7776a68766e81cd93be0a58c7d5465Dt
43f50cb7c44309253c847a258d592992e250678cda19887c482849bd67b447e3Ds
461bf2c4280e37fa28f8577583cf56315e10dc6a8898497da766b5dffbdb1a56Dr
797abce4232e5ed3353b7d0733cce5d5aea1134edf9acaa37b6028ef6bcfbc3dDq
6c2a1f394c23865716bd975554c638950ef8bb2b3efd23074290f41ebd724f20Dp
2c9324974a8a0cabc911ea21fe71581d404b5d397c0c010f06880df10520bbf3Do
a6c934448f1ad13c105abb9c4606317935bd853ff0ba1a80735013b194ee0643Dn
41923a544cdeeda959457ff656dfdd7e871d90f2d4f234055c2bb0f1f3996609Dm
4f2f74c8de47efbfeea14ccb4e01899a829a67121a6963532b82205d11eaea8bDl
f59ceed71d088a420b5ecc67bc4a13df798f7d3d12556a27285fb4dfd594850eDk
74038c223561306541466c5407569dcc8055567f3cc9a56e7ec106015d2df942
$+{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)*{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d(wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t'wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z&{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
2{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d1wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t0wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z/{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624).{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m-{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q,{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
xrf9{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)?8}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)7{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m6{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q5{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake4{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)3{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
xrf??}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)>{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m={cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q<{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake;{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214):{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)
_b]C_mF{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qE{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeD{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)C{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)B}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pA}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)@}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
ydyLqStepan Broz <sbroz@redhat.com> - 2:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)K}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)pJ}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)I}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?H}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)G{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)
n+pS}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)R}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)?Q}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)P{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mO{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qN{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistakeM{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)
nZv?Z}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.10c,N@- Fix memory leak in ECDSA verify processing (CVE-2022-38177)
- Fix memory leak in EdDSA verify processing (CVE-2022-38178)Y{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)mX{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)qW{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
Vs#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)UsStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)T}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)
Ib]I
_s#Stepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.15ev@- Limit the amount of recursion possible in control channel (CVE-2023-3341)^sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.14d@- Prevent the cache going over the configured limit (CVE-2023-2828)]}!Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.13c- Tighten cache protection against record from forwarders (CVE-2021-25220)p\}gPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.12c- Include test of forwarders (CVE-2021-25220)[}9Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.11c5- Prevent excessive resource use while processing large delegations.
  (CVE-2022-2795)
9>{dwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rcwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)bwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)xaw}Petr Menšík <pemensik@redhat.com> - 32:9.11.4-19.P2^h- Allow conflicting zone files with a warning (#1744081)H`sStepan Broz <sbroz@redhat.com> - 32:9.11.4-26.P2.16fh@- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Add missing design by contract tests to dns_catz*
- Speed up parsing of DNS messages with many different names (CVE-2023-4408)
- Do not use header_prev in expire_lru_headers
PatjwuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zi{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gh{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
g{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[fwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,ewcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
~zy~gq{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
p{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[owCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,nwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){mwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)rlwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)kwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-20.P2^ku- Do not crash when nsupdate with GSS terminated early (#1300636)
#$1#[xwCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wwcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617){vwPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)ruwqPetr Menšík <pemensik@redhat.com> - 32:9.11.4-21.P2^oj@- Disable atomic operations also on ppc (#1779589)dtwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)tswuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)zr{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
#o)#{wPetr Menšík <pemensik@redhat.com> - 32:9.11.4-22.P2^r
@- Solve often priming queries on some forwarder (#1756201)~{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d}wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)t|wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)gz{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
y{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)
PadwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase,wcPetr Menšík <pemensik@redhat.com> - 32:9.11.4-23.P2^x- Limit number of queries triggered by a request (CVE-2020-8616)
- Fix invalid tsig request (CVE-2020-8617)
"x"t
wuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)[	wCPetr Menšík <pemensik@redhat.com> - 32:9.11.4-24.P2^Ǿ- Add CVE tests to codebase{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken servers
{!Artem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-25.P2^- rebinding protection for forwarding DNS server upstream patch (#1832812)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)
${#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215){Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)dwUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
N=N!{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.4`*b@- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)d wUTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.3_:- Fix inline re-signing (#rh1889902)twuTomas Korbar <tkorbar@redhat.com> - 32:9.11.4-26.P2.2_w@- Fix unsupported algorithms validation (#rh1769876)z{{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.1_FN- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624)g{WArtem Egorenkov <aegorenk@redhat.com> - 32:9.11.4-26.P2^@- Fix EDNS512 loops on broken serversm{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q{kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake
UxrfU(g9Nick Clifton  <nickc@redhat.com> 2.27-36.base\4- Prevent resource exhaustion attacks on libiberty's name demangling code.  (#1598561){'gNick Clifton  <nickc@redhat.com> 2.27-35.base\4- Stop strip crashing when removing .comment sections.  (#1644632)&{7Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.9a- Fix possible assertion failure isc_refcount_current == 0 in free_rbtdb
  (#1935152)m%{cPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.8ah- Prevent a race after zone load (#2011220)q${kPetr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.7`@- Apply again patch 172, got removed by mistake#{#Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.6`Z- Insufficient IXFR checks could lead to assertion failure (CVE-2021-25214)"{Petr Menšík <pemensik@redhat.com> - 32:9.11.4-26.P2.5`- Possible assertion failure on DNAME processing (CVE-2021-25215)

er+V:eD
8e35267d29e2ee8a7d9678927b89dd4a07137e32a7f920844428b1f94aaf2c97D
0f2b2ab9e05c1447b23d28c2912f8057c494168f4eed17e7d868e5970436722dD
580edd83e305e9b58fb0cceca959a21a8c59ccd3bc075f075211019108f73863D
ebf604edce00a3a3778207eeaac06a3de226dbf62bfb987ed00584aa8d736ea1D
d9c97d1412cfdb3b24b2aca08bec9bed63be4db9461f19ba0eef840ad48dc19eD
9e472e05a5fca129f0efc2c81b7fc14f5daa96935b5c693cead447474422f17fD~
6f1a8e6e9202d70c194d4aaed3c034d719a85eb53ac63f8c6235756a9646a2faD}
e51d2de57b856312d8eb1bbf6ee6b7ac8f910ebf5d7e0b516012d5d9c31c7853D|
64ec5a21e706505bd67ed2ff5da8b90fcfb71ea07550d90a777323f49c8ee5d9D{
f17b58dd383483f1592c8c3c0bf814ed80d208d19a254620ec541a14c9f5f144Dz
20887cda88d458e236a1d13d68fb01b10056907594d573f0342d40b9bd677d37Dy
b88c8339f9ad90d0855cda0072a67860549759e8870cc9abc61555e4d4ef4f61Dx
db4dac1347f0a7c37ce54b990ae4be455c6c016e54d0a315f1e2cbefcefd3073
zy.gWNick Clifton  <nickc@redhat.com> 2.27-42.base]w@- Stop the BFD library from complaining about sections with multiple sets of relocations.  (#1749085)-g?Nick Clifton  <nickc@redhat.com> 2.27-41.base\r@- Fix up some linker tests that fail because of the R_x86_64_GOTPCRELX patch.  (#1699745)h,gmNick Clifton  <nickc@redhat.com> 2.27-40.base\N- Enable gold for PowerPC and s390x.  (#1670014)+g7Nick Clifton  <nickc@redhat.com> 2.27-39.base\<y- Fix a potential illegal memory access triggered by an integer overflow.  (#1665884)s*gNick Clifton  <nickc@redhat.com> 2.27-38.base\4- Disable optimizations of x06_64 PLT entries.  (#1624779){)gNick Clifton  <nickc@redhat.com> 2.27-37.base\4- Add the .attach-to-group pseudo-op to the assembler.  (#1652587)
	vs4gNick Clifton  <nickc@redhat.com> 2.27-38.base\4- Disable optimizations of x06_64 PLT entries.  (#1624779){3gNick Clifton  <nickc@redhat.com> 2.27-37.base\4- Add the .attach-to-group pseudo-op to the assembler.  (#1652587)2g9Nick Clifton  <nickc@redhat.com> 2.27-36.base\4- Prevent resource exhaustion attacks on libiberty's name demangling code.  (#1598561){1gNick Clifton  <nickc@redhat.com> 2.27-35.base\4- Stop strip crashing when removing .comment sections.  (#1644632)0oNick Clifton  <nickc@redhat.com> - 2.27-44.base.1ar- Add ability to control the display of unicode characters.  (#2009168)m/guNick Clifton  <nickc@redhat.com> 2.27-44.base^E:@- Allow the BFD library to handle the copying of files which contain secondary reloc sections.  (#1785294)
- Implement assembler workaround for Intel JCC microcode bug.  (#1778892)
RnmR:oNick Clifton  <nickc@redhat.com> - 2.27-44.base.1ar- Add ability to control the display of unicode characters.  (#2009168)m9guNick Clifton  <nickc@redhat.com> 2.27-44.base^E:@- Allow the BFD library to handle the copying of files which contain secondary reloc sections.  (#1785294)
- Implement assembler workaround for Intel JCC microcode bug.  (#1778892)8gWNick Clifton  <nickc@redhat.com> 2.27-42.base]w@- Stop the BFD library from complaining about sections with multiple sets of relocations.  (#1749085)7g?Nick Clifton  <nickc@redhat.com> 2.27-41.base\r@- Fix up some linker tests that fail because of the R_x86_64_GOTPCRELX patch.  (#1699745)h6gmNick Clifton  <nickc@redhat.com> 2.27-40.base\N- Enable gold for PowerPC and s390x.  (#1670014)5g7Nick Clifton  <nickc@redhat.com> 2.27-39.base\<y- Fix a potential illegal memory access triggered by an integer overflow.  (#1665884)
hqihAg?Nick Clifton  <nickc@redhat.com> 2.27-41.base\r@- Fix up some linker tests that fail because of the R_x86_64_GOTPCRELX patch.  (#1699745)h@gmNick Clifton  <nickc@redhat.com> 2.27-40.base\N- Enable gold for PowerPC and s390x.  (#1670014)?g7Nick Clifton  <nickc@redhat.com> 2.27-39.base\<y- Fix a potential illegal memory access triggered by an integer overflow.  (#1665884)s>gNick Clifton  <nickc@redhat.com> 2.27-38.base\4- Disable optimizations of x06_64 PLT entries.  (#1624779){=gNick Clifton  <nickc@redhat.com> 2.27-37.base\4- Add the .attach-to-group pseudo-op to the assembler.  (#1652587)<g9Nick Clifton  <nickc@redhat.com> 2.27-36.base\4- Prevent resource exhaustion attacks on libiberty's name demangling code.  (#1598561){;gNick Clifton  <nickc@redhat.com> 2.27-35.base\4- Stop strip crashing when removing .comment sections.  (#1644632)
+^m.+WHeMJosef Ridky <jridky@redhat.com> - 0:1.8.18-4X+- Fix RPMDiff issues and rebuild%GegJosef Ridky <jridky@redhat.com> - 0:1.8.18-3X@- Fix issues with warning: dereferencing type-punned pointer 
  will break strict-aliasing rules from RPMDiffRFeCJosef Ridky <jridky@redhat.com> - 0:1.8.18-2X- Fix issue in file sources_Ee]Josef Ridky <jridky@redhat.com> - 0:1.8.18-1X@- New upstream release 1.8.18 (#1398658)DoNick Clifton  <nickc@redhat.com> - 2.27-44.base.1ar- Add ability to control the display of unicode characters.  (#2009168)mCguNick Clifton  <nickc@redhat.com> 2.27-44.base^E:@- Allow the BFD library to handle the copying of files which contain secondary reloc sections.  (#1785294)
- Implement assembler workaround for Intel JCC microcode bug.  (#1778892)BgWNick Clifton  <nickc@redhat.com> 2.27-42.base]w@- Stop the BFD library from complaining about sections with multiple sets of relocations.  (#1749085)
D'DROeCJosef Ridky <jridky@redhat.com> - 0:1.8.18-2X- Fix issue in file sourcesNkSPavel Cahyna <pcahyna@redhat.com> - 0:1.8.18-10a{- Protect against negative values to memmove that caused
  "ipmitool sol activate" to crash against an IBM DataPower appliance
  (#1951480) and IP-131 Dayton blades in a SGI ICE-X (#2025519)
  Cherry-picked from upstream PR#78.iMscVáclav Doležal <vdolezal@redhat.com> - 0:1.8.18-9^_@- Disable -fstrict-aliasing (RPMDiff issue)^LsMVáclav Doležal <vdolezal@redhat.com> - 0:1.8.18-8^^F- Backport fix for CVE-2020-5208oKe}Josef Ridky <jridky@redhat.com> - 0:1.8.18-7Zy- Remove debug prints shown without -v option (#1483163)Je=Josef Ridky <jridky@redhat.com> - 0:1.8.18-6Y{- Hide unrequested verbose output (#1483163)
- Fix doc for check input values (#1495098)oIe}Josef Ridky <jridky@redhat.com> - 0:1.8.18-5Xs- Remove RPMDiff fix file (#1439269) related to #1398658
W$iVscVáclav Doležal <vdolezal@redhat.com> - 0:1.8.18-9^_@- Disable -fstrict-aliasing (RPMDiff issue)^UsMVáclav Doležal <vdolezal@redhat.com> - 0:1.8.18-8^^F- Backport fix for CVE-2020-5208oTe}Josef Ridky <jridky@redhat.com> - 0:1.8.18-7Zy- Remove debug prints shown without -v option (#1483163)Se=Josef Ridky <jridky@redhat.com> - 0:1.8.18-6Y{- Hide unrequested verbose output (#1483163)
- Fix doc for check input values (#1495098)oRe}Josef Ridky <jridky@redhat.com> - 0:1.8.18-5Xs- Remove RPMDiff fix file (#1439269) related to #1398658WQeMJosef Ridky <jridky@redhat.com> - 0:1.8.18-4X+- Fix RPMDiff issues and rebuild%PegJosef Ridky <jridky@redhat.com> - 0:1.8.18-3X@- Fix issues with warning: dereferencing type-punned pointer 
  will break strict-aliasing rules from RPMDiff
<ZwRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}Y
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]wXg	Pavel Cahyna <pcahyna@redhat.com> - 1.8.18-11d- Add upstream ipmievd patch to check received msg id against expectation
  Fixes problem where SEL response is not recognized correctly
  when SEL request times out
  Resolves: rhbz#2224569WkSPavel Cahyna <pcahyna@redhat.com> - 0:1.8.18-10a{- Protect against negative values to memmove that caused
  "ipmitool sol activate" to crash against an IBM DataPower appliance
  (#1951480) and IP-131 Dayton blades in a SGI ICE-X (#2025519)
  Cherry-picked from upstream PR#78.
IK\}Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3[eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]
t^gRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i]QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
-`WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M_Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
??Kc}Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]b9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]LaRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]
tegRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]idQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
-gWRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]MfRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
i9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]LhRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
2k1Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fԃJjRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
=MmRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}?l{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
OLoRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}-nWRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]
r1Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_f؃JqRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)p9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
==?s{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
dtERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
r-r7vkRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]OuRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
PxAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol݅^w9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
;;9zoAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powtyeAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commanderpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
{{|7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: HanX{-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
f}IAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
pp~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}


oYAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]
q]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
dERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
r-rr|uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]7kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Z}wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]BRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]
##?
{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.2.el7]ef@- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}4	eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
ZB
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]|uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]
}wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]
4eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~yRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
(o("ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens
}wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]BRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}
4eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~yRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
o+	MRadomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ensdle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han
f IAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
pp!Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}


o"YAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]
q#]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
//R%Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE^$7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
--O&Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]
((1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.2.el7]`	l- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]T'#Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]

er+V:eD
6652fd59e1328ff5e8f2141d6e091685a4e2cb80366a0f729537fb40a17779b8D
168cb87176ec6a7a6805dcccc50c34a22945c1ebfd027164ff0028a1a140a637D
388ece9ac8d1f44fa207868af7af9df39a1479ce72301c159bfb9ed3f436fd61D
f2dc09932d5afec99bdc35c39f858385a06e600f3b989133d348ed00959ba429D

19575eb2feb5e29ed339c078e462e2a4ac7a44f0888328185fc248a30681b82eD
5b19e42e03ab5ffdc24e71ec6c71dd0d4c8a557e482b142cb58bd7eaf529174aD
e07580dc20cee29ddae2c26b7d4782a6e7671477d7f4ae210d2cef6cc71555cbD

8b60c6a9194e57ad101ad2a28015f644b915aa5c958a5f8b0e68def14394fa13D	
479b38bee7280885a7df789a1472c2d43e1a0103f8607f0e6d3fb26c2ae13423D
bfe191b783a11c70daf05fb86e81e2e36d80b7dec5eb2243fa223700ce330824D
a6119606e76fc09a37585914c2063026064b1b979d9cffcf71712c2218b4c3c2D
d8f18b1da519f3d475ad00269e3908ecb8abedc91f0754a3a8a6aa8b624b04ddD
f1ba2741b87027c8c0f29b9262bb396c142986c3ad3c68f88e90f34cb028b6de
CC*sJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check J)s#Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
E
ED,sJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o+smJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
ehej/scJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840].s1Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []-s7Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
61+Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]F0sJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
3sJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check ^29Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]ofUflrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|̧^ͧ`ΧcЧeѧgҧiӧkէm֧oקr٧sڧtۧvܧxߧz|}~

 !"#%&(*,/13	5
8:;
=?ABCDEFHIJKLM O!Q#R$S%T&U(V)X*Y+Z,\-]._/a0b1c2d3e4f5g6h8j9l:n<p=r>s?t@uAwByCzD{E|F}GHIJKL	M
OP
QRTto gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
E
ED5sJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o4smJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
ehej8scJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]7s1Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []6s7Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
6:+Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]F9sJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
^;9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]
yy^=7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]!<?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.2.el7]_- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
O?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]R>Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE
A(A[A1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797T@#Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bB?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4CcAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
22JDAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
22JEAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
FAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
A(A[H1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797TG#Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bI?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4JcAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
22JKAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
22JLAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
MAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
MM/OYAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|NsAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
bIb[Q1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797"3PaAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bR?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4Sc	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
22JT	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
22JU	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
V	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend'
MM/XY	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|Ws	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
II3Ya	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
BB:Zo	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
MM/\Y
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|[s
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
II3]a
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
6B6_
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.26.1.el7]`~@- selinux: fix deadlock in security_set_bools() (Ondrej Mosnacek) [1939091]
- md: fix md io stats accounting broken (Ming Lei) [1927106]
- redhat: Fix realtime_check for -private (Juri Lelli):^o
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
11a	
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]@`{
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.27.1.el7]`N@- video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (Mohammed Gamal) [1941841]
- Drivers: hv: vmbus: enable VMBus protocol version 5.0 (Mohammed Gamal) [1941841]
- redhat: Add git suffix to realtime_check merge_tree (Juri Lelli)
>>>bw
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
c#
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
//Md
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]
uue	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]
>>>fwAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
g#Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
//MhAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
,j'Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}HiAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 7
U{U"l?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]k}Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
..n-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.2.el7]`A- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]1m]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
,p'Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}HoAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP ;
U{U"r?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]q}Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
1s]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
tAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
uAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
002w_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]v'Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
]y}
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]x9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
"z?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
1{]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
|
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
}
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
002_
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]~'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
]9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
002_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]'Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
]	9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
33I

Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
nnRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348N
pp
9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]iQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
Z9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]
33I
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
nnRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348S
iQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
EE7mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
  !ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
nnRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348Y
iQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
EE7mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
  !ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]
rfrp_Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]+Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}
"!+Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}n [Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igaZ3Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]bet() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush cif write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error rdeform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
.n$[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igfZ#3Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]p"_Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]get() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush hif write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error rieform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
d}d
&Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060k%}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
@(Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<'wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
&S&,s1Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []+s7Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]%*IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609])Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}

er+V:eD
766b6de38798e8e6035b4c0b18df36607cccc2e988be356ea2d9eb9c21de9b6cD
ce3a408dfe9ac91c4e9fefe4168ef2cbd9d6d18a92f2dfd2e36b2b7af8c8b103D
e2dd1e90386216ad54e0f6e9509f96a4314819f96abc9b8ea88ffbb03f05dd03D
a8d4bf67c5aec05b8881b57f4ec80fbc832c77a1fabb65bb68b376c269b759d3D
85de1b747c97e7d16a742f3f0789c4d8761e3b44c28ff437bc8b47499a9132adD
61a258f5eb7c2c013c4eeb36791fdc7dc8b813c04b4ae5b0d1a31faa435a58acD
04b4fe240bbb7def555afa21959f623f37179a6993d0e6a57f592f05ab3f531bD
66cc35a05dd83f4129f6b3bb4f774d59fc607704c381b660b909ab3e3776ab96D
7284d6fec357299a1772944305ca58f5d48637a3031733bcdd30849ec50f7a98D
e9db6345b34c115b15bd297bcda0f0680ee1a37cf51adeb1477e16e232d6f289D
81df5804e78ba7e49ce4ceb11f4b7c514d4f06d0ad146b950993c6cb77e58dfaD
0dac2946a3cac243477b0ac6573b491a15bcd751bbfaa32b92535f850f10cf3fD
2d58b75f307b928bfae35e0818fe5449c542ed611f46c2ba4663d50f304c0295
F.sJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]j-scJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]
/+Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]
P1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_holr^09Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
;;93oAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powut2eAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commandserpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
55n5[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igwX4-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}xet() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush yif write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error rzeform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
d}d
7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060|6}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
@9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<8wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
SS%;IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]:Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\<7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT
QQ+=URado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
))S>%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
vr%AIRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]@Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}?Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\B7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT
QQ+CURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
))SD%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
sDsMGRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%FIRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}ERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
88DHRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
))SI%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
sDsMLRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%KIRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
88DMRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
'w'LORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]N	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
e
RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]Q)Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]P-Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
'w'LTRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]S	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
e&XKRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]V)Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]U-Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
zzZ#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lYWRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T['Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
7_Q'7l_WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&^KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]\9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
jj`#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
Ta'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
I_Ic#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]b9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
Q*BfRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825+dURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
PPi#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lhWRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&gKRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]offlrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|VWXZ[\]^_`!e$j&l(m,o.p/q1t3v5{7}9~;<=>ABCDGHILMORTXZ[_`acfijloqrtwxy{}~ªêĪŪ	ƪȪɪʪ˪ͪΪЪѪ!Ҫ$Ӫ'Ԫ)֪+ת.ܪ0ު2ߪ5<FPZdnv{
 #&)*+-.1	2
3567>Dcpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
Tj'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
I_Il#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]k9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
Q*BoRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825+mURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
q#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]LpRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
Tr'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
I_It#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]s9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
Q*BwRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825+uURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
LxRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]
''Uy)Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825zRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
jjL}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]B|Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
''U~)Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
iQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
<<@Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
c7mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc1Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
yyLRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]3eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
''U)Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
iQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
<<@	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
c7mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitcDž
1Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
H+H_=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]
3Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
iQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
<<@Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
c7mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc̅1Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
+H7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
YY1Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
=h_=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]7mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc
`VK<!wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233} 
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]
If$7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_#=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3"eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
++<'wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}&
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]
IK)}Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3(eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]
t+gRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i*QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
.sJan Stancek <jstancek@redhat.com> [3.10.0-1152.el7]^- [nvmem] nvmem: properly handle returned value nvmem_reg_read (Vladis Dronoڊ	-s!Jan Stancek <jstancek@redhat.com> [3.10.0-1151.el7]^W@- [netdrv] qede: Fix multicast mac configuration (Michal Schmidt) [1740064]
- [scsi] sd_dif: avoid incorrect ref_tag errors on 4K devices larger than 2TB (Ewan Milne) [1833528]
- [hid] HID: hiddev: do cleanقM,Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}

er+V:eD+
d56f208cb0a3f9404c7aa65a34d04ff637f76d4517d2f68c4c63ec940a0806a5D*
04dce9028a87d078c3036031ae186db04fd35a585bd35d7aa2fcc7c8300830edD)
a99bb11d5187d473fbf1ceddf45f95459a860863d190605924743cdb4f34261bD(
7c67eafa7cee5c39a41ff1aeb7d5cd4d764c1967ad0cc0795ad34e1d63727f0eD'
58d8a7b6d0fdb9777df76fd29a92c1c249ab8fe602e217d454e4b89dd8a82452D&
d30f35b56aec811e1b348312a8f58d2e793a4c89f8e25ac9155a5e74a0d04b90D%
1b927fc58d94ad45dc78d0926b1fb83cae72958110a6ebfa24f75a5d5a9a4b4dD$
37c1fc32da75405bdcca093c9fce198c021c7868450f7b272aed38def708857dD#
518ebaac264e510836e723892b0b9982787bf6b242d9843e5ab09ecc5c9f642aD"
4857df90d4f9aa3520255aef6c5bdbe887f7cdaae0d006c15b15db7c418b372fD!
ad182b2b1a28f50e4030294d1ad1de624300da1440a08ecc9180070cc3c2b076D 
149c020747f7a669eb88245d5064fa806ac7462e9cdd3a6c05414ff08bdd43e7D
86101a94927cf01319d801575aa4ea26e63efa577a5431856e0329f06a994596up in failure of opening a device (Torez Smith) [1814257] {CVE-2019-19527}
- [hid] HID: hiddev: avoid opening a disconnected device (Torez Smith) [1814257] {CVE-2019-19527}
- [x86] x86: make mul_u64_u64_div_u64() "static inline" (Oleg Nesterov) [1845864]
- [mm] mm: page_isolation: fix potential warning from user (Rafael Aquini) [1845620]
- [s390] s390/mm: correct return value of pmd_pfn (Claudio Imbrenda) [1841106]
- [fs] fs/proc/vmcore.c:mmap_vmcore: skip non-ram pages reported by hypervisors (Lianbo Jiang) [1790799]
- [kernel] kernel/sysctl.c: ignore out-of-range taint bits introduced via kernel.tainted (Rafael Aquini) [1845356]
- [documentation] kernel: add panic_on_taint (Rafael Aquini) [1845356]
- [fs] ext4: Remove unwanted ext4_bread() from ext4_quota_write() (Lukas Czerner) [1845379]
- [scsi] scsi: sg: add sg_remove_request in sg_write ("Ewan D. Milne") [1840699] {CVE-2020-12770}
- [fs] fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (Donghai Qiao) [1832062] {CVE-2020-10732}v) [1844409]
- [mailbox] PCC: fix dereference of ERR_PTR (Vladis Dronov) [1844409]
- [kernel] futex: Unlock hb->lock in futex_wait_requeue_pi() error path (Vladis Dronov) [1844409]
- [fs] aio: fix inconsistent ring state (Jeff Moyer) [1845326]
- [vfio] vfio/mdev: make create attribute static (Vladis Dronov) [1837549]
- [vfio] treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Synchronize device create/remove with parent removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid creating sysfs remove file on stale device removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Improve the create/remove sequence (Vladis Dronov) [1837549]
- [vfio] treewide: Add SPDX license identifier - Makefile/Kconfig (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid inline get and put parent helpers (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Fix aborting mdev child device removal if one fails (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Follow correct remove sequence (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid masking error code to EBUSY (Vladis Dronov) [1837549]
- [include] vfio/mdev: Drop redundant extern for exported symbols (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Removed unused kref (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid release parent reference during error path (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Add iommu related member in mdev_device (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: add static modifier to add_mdev_supported_type (Vladis Dronov) [1837549]
- [vfio] vfio: mdev: make a couple of functions and structure vfio_mdev_driver static (Vladis Dronov) [1837549]
- [char] tpm/tpm_tis: Free IRQ if probing fails (David Arcari) [1774698]
- [kernel] audit: fix a memleak caused by auditing load module (Richard Guy Briggs) [1843370]
- [kernel] audit: fix potential null dereference 'context->module.name' (Richard Guy Briggs) [1843370]
- [nvme] nvme: limit number of IO queues on Dell/Samsung config (David Milburn) [1837617]
CC0sJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check ݆J/s#Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
E
ED2sJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o1smJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
ehej5scJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]4s1Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []3s7Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
6w(vZ<iO Peter Robinson <pbrobinson@redhat.com> 3.8.0-8S- Fix dependencies on own libraryL;]? Daniel Mach <dmach@redhat.com> - 3.8.0-7RU- Mass rebuild 2014-01-24`:_e Zeeshan Ali <zeenix@redhat.com> - 3.8.0-6R@- Add dep on own library (related: #1045140)L9]? Daniel Mach <dmach@redhat.com> - 3.8.0-5Rk- Mass rebuild 2013-12-27_8_c Zeeshan Ali <zeenix@redhat.com> - 3.8.0-4Rj- Complete translations (related: #1030319)Z7_Y Zeeshan Ali <zeenix@redhat.com> - 3.8.0-3R{- Fix ISRC handling (related: #861191)F6sJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]

f?&ufZFiO!Peter Robinson <pbrobinson@redhat.com> 3.8.0-8S- Fix dependencies on own libraryLE]?!Daniel Mach <dmach@redhat.com> - 3.8.0-7RU- Mass rebuild 2014-01-24`D_e!Zeeshan Ali <zeenix@redhat.com> - 3.8.0-6R@- Add dep on own library (related: #1045140)LC]?!Daniel Mach <dmach@redhat.com> - 3.8.0-5Rk- Mass rebuild 2013-12-27_B_c!Zeeshan Ali <zeenix@redhat.com> - 3.8.0-4Rj- Complete translations (related: #1030319)ZA_Y!Zeeshan Ali <zeenix@redhat.com> - 3.8.0-3R{- Fix ISRC handling (related: #861191)V@aO David King <dking@redhat.com> - 3.12.2-5.1aTU@- Fix BD-R media flags (#2053594)`?i[ Richard Hughes <rhughes@redhat.com> - 3.12.2-5[)- Update to 3.12.2
- Resolves: #1569810[>]] David King <dking@redhat.com> - 3.12.1-2U[%- Rebuild for totem-pl-parser (#1222884)`=i[ Richard Hughes <rhughes@redhat.com> - 3.12.1-1UG_@- Update to 3.12.1
- Resolves: #1174577

f?&ufZPiO"Peter Robinson <pbrobinson@redhat.com> 3.8.0-8S- Fix dependencies on own libraryLO]?"Daniel Mach <dmach@redhat.com> - 3.8.0-7RU- Mass rebuild 2014-01-24`N_e"Zeeshan Ali <zeenix@redhat.com> - 3.8.0-6R@- Add dep on own library (related: #1045140)LM]?"Daniel Mach <dmach@redhat.com> - 3.8.0-5Rk- Mass rebuild 2013-12-27_L_c"Zeeshan Ali <zeenix@redhat.com> - 3.8.0-4Rj- Complete translations (related: #1030319)ZK_Y"Zeeshan Ali <zeenix@redhat.com> - 3.8.0-3R{- Fix ISRC handling (related: #861191)VJaO!David King <dking@redhat.com> - 3.12.2-5.1aTU@- Fix BD-R media flags (#2053594)`Ii[!Richard Hughes <rhughes@redhat.com> - 3.12.2-5[)- Update to 3.12.2
- Resolves: #1569810[H]]!David King <dking@redhat.com> - 3.12.1-2U[%- Rebuild for totem-pl-parser (#1222884)`Gi[!Richard Hughes <rhughes@redhat.com> - 3.12.1-1UG_@- Update to 3.12.1
- Resolves: #1174577

f?&ufZZiO#Peter Robinson <pbrobinson@redhat.com> 3.8.0-8S- Fix dependencies on own libraryLY]?#Daniel Mach <dmach@redhat.com> - 3.8.0-7RU- Mass rebuild 2014-01-24`X_e#Zeeshan Ali <zeenix@redhat.com> - 3.8.0-6R@- Add dep on own library (related: #1045140)LW]?#Daniel Mach <dmach@redhat.com> - 3.8.0-5Rk- Mass rebuild 2013-12-27_V_c#Zeeshan Ali <zeenix@redhat.com> - 3.8.0-4Rj- Complete translations (related: #1030319)ZU_Y#Zeeshan Ali <zeenix@redhat.com> - 3.8.0-3R{- Fix ISRC handling (related: #861191)VTaO"David King <dking@redhat.com> - 3.12.2-5.1aTU@- Fix BD-R media flags (#2053594)`Si["Richard Hughes <rhughes@redhat.com> - 3.12.2-5[)- Update to 3.12.2
- Resolves: #1569810[R]]"David King <dking@redhat.com> - 3.12.1-2U[%- Rebuild for totem-pl-parser (#1222884)`Qi["Richard Hughes <rhughes@redhat.com> - 3.12.1-1UG_@- Update to 3.12.1
- Resolves: #1174577

f?&ufZdiO$Peter Robinson <pbrobinson@redhat.com> 3.8.0-8S- Fix dependencies on own libraryLc]?$Daniel Mach <dmach@redhat.com> - 3.8.0-7RU- Mass rebuild 2014-01-24`b_e$Zeeshan Ali <zeenix@redhat.com> - 3.8.0-6R@- Add dep on own library (related: #1045140)La]?$Daniel Mach <dmach@redhat.com> - 3.8.0-5Rk- Mass rebuild 2013-12-27_`_c$Zeeshan Ali <zeenix@redhat.com> - 3.8.0-4Rj- Complete translations (related: #1030319)Z__Y$Zeeshan Ali <zeenix@redhat.com> - 3.8.0-3R{- Fix ISRC handling (related: #861191)V^aO#David King <dking@redhat.com> - 3.12.2-5.1aTU@- Fix BD-R media flags (#2053594)`]i[#Richard Hughes <rhughes@redhat.com> - 3.12.2-5[)- Update to 3.12.2
- Resolves: #1569810[\]]#David King <dking@redhat.com> - 3.12.1-2U[%- Rebuild for totem-pl-parser (#1222884)`[i[#Richard Hughes <rhughes@redhat.com> - 3.12.1-1UG_@- Update to 3.12.1
- Resolves: #1174577

f?&ufZniO%Peter Robinson <pbrobinson@redhat.com> 3.8.0-8S- Fix dependencies on own libraryLm]?%Daniel Mach <dmach@redhat.com> - 3.8.0-7RU- Mass rebuild 2014-01-24`l_e%Zeeshan Ali <zeenix@redhat.com> - 3.8.0-6R@- Add dep on own library (related: #1045140)Lk]?%Daniel Mach <dmach@redhat.com> - 3.8.0-5Rk- Mass rebuild 2013-12-27_j_c%Zeeshan Ali <zeenix@redhat.com> - 3.8.0-4Rj- Complete translations (related: #1030319)Zi_Y%Zeeshan Ali <zeenix@redhat.com> - 3.8.0-3R{- Fix ISRC handling (related: #861191)VhaO$David King <dking@redhat.com> - 3.12.2-5.1aTU@- Fix BD-R media flags (#2053594)`gi[$Richard Hughes <rhughes@redhat.com> - 3.12.2-5[)- Update to 3.12.2
- Resolves: #1569810[f]]$David King <dking@redhat.com> - 3.12.1-2U[%- Rebuild for totem-pl-parser (#1222884)`ei[$Richard Hughes <rhughes@redhat.com> - 3.12.1-1UG_@- Update to 3.12.1
- Resolves: #1174577
?5Av&Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.9.1-4Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildWucO&Jakub Hrozek <jhrozek@redhat.com> - 1.9.1-3P"T- Include URL to the license textt&Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.9.1-2P@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildKsk/&Tom Callaway <spot@fedoraproject.org> - 1.9.1-1OR- update to 1.9.1VraO%David King <dking@redhat.com> - 3.12.2-5.1aTU@- Fix BD-R media flags (#2053594)`qi[%Richard Hughes <rhughes@redhat.com> - 3.12.2-5[)- Update to 3.12.2
- Resolves: #1569810[p]]%David King <dking@redhat.com> - 3.12.1-2U[%- Rebuild for totem-pl-parser (#1222884)`oi[%Richard Hughes <rhughes@redhat.com> - 3.12.1-1UG_@- Update to 3.12.1
- Resolves: #1174577
F&M{_?&Daniel Mach <dmach@redhat.com> - 1.10.0-3RU- Mass rebuild 2014-01-24Mz_?&Daniel Mach <dmach@redhat.com> - 1.10.0-2Rk- Mass rebuild 2013-12-27yeU&Jakub Hrozek <jhrozek@redhat.com> - 1.10.1-1Q- New upstream release 1.10
- Obsolete upstreamed patches
- Amend the multilib patch, there's no need to patch configure since we
  are running autoreconf anyways
- https://raw.github.com/bagder/c-ares/cares-1_10_0/RELEASE-NOTESxc%&Jakub Hrozek <jhrozek@redhat.com> - 1.9.1-6Qf- Apply an upstream patch to override AC_CONFIG_MACRO_DIR only conditionally/wc}&Jakub Hrozek <jhrozek@redhat.com> - 1.9.1-5Qf- Apply a patch by Stephen Gallagher to patch autoconf, not configure to
  allow optflags to be passed in by build environment
- Run autoreconf before configure
- git rm obsolete patches
- Apply upstream patch to stop overriding AC_CONFIG_MACRO_DIR
L[
sL/c}'Jakub Hrozek <jhrozek@redhat.com> - 1.9.1-5Qf- Apply a patch by Stephen Gallagher to patch autoconf, not configure to
  allow optflags to be passed in by build environment
- Run autoreconf before configure
- git rm obsolete patches
- Apply upstream patch to stop overriding AC_CONFIG_MACRO_DIR'Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.9.1-4Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildWcO'Jakub Hrozek <jhrozek@redhat.com> - 1.9.1-3P"T- Include URL to the license text~'Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.9.1-2P@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildK}k/'Tom Callaway <spot@fedoraproject.org> - 1.9.1-1OR- update to 1.9.1!|qS&Alexey Tikhonov <atikhono@redhat.com> - 1.10.0-3.1d@- Resolves: rhbz#2209503 - CVE-2023-32067 c-ares: 0-byte UDP payload Denial of Service [rhel-7.9.z]
,yY	,(Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.9.1-2P@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildKk/(Tom Callaway <spot@fedoraproject.org> - 1.9.1-1OR- update to 1.9.1!qS'Alexey Tikhonov <atikhono@redhat.com> - 1.10.0-3.1d@- Resolves: rhbz#2209503 - CVE-2023-32067 c-ares: 0-byte UDP payload Denial of Service [rhel-7.9.z]M_?'Daniel Mach <dmach@redhat.com> - 1.10.0-3RU- Mass rebuild 2014-01-24M_?'Daniel Mach <dmach@redhat.com> - 1.10.0-2Rk- Mass rebuild 2013-12-27eU'Jakub Hrozek <jhrozek@redhat.com> - 1.10.1-1Q- New upstream release 1.10
- Obsolete upstreamed patches
- Amend the multilib patch, there's no need to patch configure since we
  are running autoreconf anyways
- https://raw.github.com/bagder/c-ares/cares-1_10_0/RELEASE-NOTESc%'Jakub Hrozek <jhrozek@redhat.com> - 1.9.1-6Qf- Apply an upstream patch to override AC_CONFIG_MACRO_DIR only conditionally
2R2
eU(Jakub Hrozek <jhrozek@redhat.com> - 1.10.1-1Q- New upstream release 1.10
- Obsolete upstreamed patches
- Amend the multilib patch, there's no need to patch configure since we
  are running autoreconf anyways
- https://raw.github.com/bagder/c-ares/cares-1_10_0/RELEASE-NOTESc%(Jakub Hrozek <jhrozek@redhat.com> - 1.9.1-6Qf- Apply an upstream patch to override AC_CONFIG_MACRO_DIR only conditionally/c}(Jakub Hrozek <jhrozek@redhat.com> - 1.9.1-5Qf- Apply a patch by Stephen Gallagher to patch autoconf, not configure to
  allow optflags to be passed in by build environment
- Run autoreconf before configure
- git rm obsolete patches
- Apply upstream patch to stop overriding AC_CONFIG_MACRO_DIR
(Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.9.1-4Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildW	cO(Jakub Hrozek <jhrozek@redhat.com> - 1.9.1-3P"T- Include URL to the license text
`my)Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.9.1-4Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildWcO)Jakub Hrozek <jhrozek@redhat.com> - 1.9.1-3P"T- Include URL to the license text)Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.9.1-2P@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildKk/)Tom Callaway <spot@fedoraproject.org> - 1.9.1-1OR- update to 1.9.1!qS(Alexey Tikhonov <atikhono@redhat.com> - 1.10.0-3.1d@- Resolves: rhbz#2209503 - CVE-2023-32067 c-ares: 0-byte UDP payload Denial of Service [rhel-7.9.z]M_?(Daniel Mach <dmach@redhat.com> - 1.10.0-3RU- Mass rebuild 2014-01-24M_?(Daniel Mach <dmach@redhat.com> - 1.10.0-2Rk- Mass rebuild 2013-12-27
F&M_?)Daniel Mach <dmach@redhat.com> - 1.10.0-3RU- Mass rebuild 2014-01-24M_?)Daniel Mach <dmach@redhat.com> - 1.10.0-2Rk- Mass rebuild 2013-12-27eU)Jakub Hrozek <jhrozek@redhat.com> - 1.10.1-1Q- New upstream release 1.10
- Obsolete upstreamed patches
- Amend the multilib patch, there's no need to patch configure since we
  are running autoreconf anyways
- https://raw.github.com/bagder/c-ares/cares-1_10_0/RELEASE-NOTESc%)Jakub Hrozek <jhrozek@redhat.com> - 1.9.1-6Qf- Apply an upstream patch to override AC_CONFIG_MACRO_DIR only conditionally/c})Jakub Hrozek <jhrozek@redhat.com> - 1.9.1-5Qf- Apply a patch by Stephen Gallagher to patch autoconf, not configure to
  allow optflags to be passed in by build environment
- Run autoreconf before configure
- git rm obsolete patches
- Apply upstream patch to stop overriding AC_CONFIG_MACRO_DIR
z[:wz i?*Bob Relyea <rrelyea@redhat.com> - 2019.2.32-76]- Update to CKBI 2.32 from NSS 3.44
-   Removing:
-   # Certificate "Visa eCommerce Root"
-  [gS*Kai Engert <kaie@redhat.com> - 2018.2.22-70.0Z- Update to CKBI 2.22 from NSS 3.35[cW*Kai Engert <kaie@redhat.com> - 2017.2.20-71Z@- Update to CKBI 2.20 from NSS 3.34.1bce*Kai Engert <kaie@redhat.com> - 2017.2.18-71Y@- Update to CKBI 2.18 (pre-release snapshot)?c*Kai Engert <kaie@redhat.com> - 2017.2.16-71YA@- Update to CKBI 2.16 from NSS 3.32. In addition to removals/additions,
  Mozilla removed code signing trust from all CAs (rhbz#1472933)[cW*Kai Engert <kaie@redhat.com> - 2017.2.14-71Y.- Update to CKBI 2.14 from NSS 3.30.2!qS)Alexey Tikhonov <atikhono@redhat.com> - 1.10.0-3.1d@- Resolves: rhbz#2209503 - CVE-2023-32067 c-ares: 0-byte UDP payload Denial of Service [rhel-7.9.z] # Certificate "AC Raiz Certicamara S.A."
-   # Certificate "TC TrustCenter Class 3 CA II"
-   # Certificate "ComSign CA"
-   # Certificate "S-TRUST Universal Root CA"
-   # Certificate "TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı H5"
-   # Certificate "Certplus Root CA G1"
-   # Certificate "Certplus Root CA G2"
-   # Certificate "OpenTrust Root CA G1"
-   # Certificate "OpenTrust Root CA G2"
-   # Certificate "OpenTrust Root CA G3"
-  Adding:
-   # Certificate "GlobalSign Root CA - R6"
-   # Certificate "OISTE WISeKey Global Root GC CA"
-   # Certificate "GTS Root R1"
-   # Certificate "GTS Root R2"
-   # Certificate "GTS Root R3"
-   # Certificate "GTS Root R4"
-   # Certificate "UCA Global G2 Root"
-   # Certificate "UCA Extended Validation Root"
-   # Certificate "Certigna Root CA"
-   # Certificate "emSign Root CA - G1"
-   # Certificate "emSign ECC Root CA - G3"
-   # Certificate "emSign Root CA - C1"
-   # Certificate "emSign ECC Root CA - C3"
-   # Certificate "Hongkong Post Root CA 3"
99}#i*Bob Relyea <rrelyea@redhat.com> - 2021.2.50-71`- Update to CKBI 2.50 from NSS 3.67
   - version number update onlyN"i5*Bob Relyea <rrelyea@redhat.com> - 2021.2.48-71`P@- Update to CKBI 2.48 from NSS 3.66
-    Removing:
-     # Certificate "Verisign Class 3 Public Primary Certification Authority - G3"
-     # Certificate "Ge!ic*Bob Relyea <rrelyea@redhat.com> - 2020.2.41-79^y- Update to CKBI 2.41 from NSS 3.53.0
-    Removing:
-     # Certificate "AddTrust Low-Value Services Root"
-     # Certificate "AddTrust External Root"
-     # Certificate "UTN USERFirst Email Root CA"
-     # Certificate "Certplus Class 2 Primary CA"
-     # Certificate "Deutsche Telekom Root CA 2"
-     # Certificate "Staat der Nederlanden Root CA - G2"
-     # Certificate "Swisscom Root CA 2"
-     # Certificate "Certinomis - Root CA"
-    Adding:
-     # Certificate "Entrust Root Certification Authority - G4"
- fix permissions on ghosted files.eoTrust Global CA"
-     # Certificate "GeoTrust Universal CA"
-     # Certificate "GeoTrust Universal CA 2"
-     # Certificate "QuoVadis Root CA"
-     # Certificate "Sonera Class 2 Root CA"
-     # Certificate "Taiwan GRCA"
-     # Certificate "GeoTrust Primary Certification Authority"
-     # Certificate "thawte Primary Root CA"
-     # Certificate "VeriSign Class 3 Public Primary Certification Authority - G5"
-     # Certificate "GeoTrust Primary Certification Authority - G3"
-     # Certificate "thawte Primary Root CA - G2"
-     # Certificate "thawte Primary Root CA - G3"
-     # Certificate "GeoTrust Primary Certification Authority - G2"
-     # Certificate "VeriSign Universal Root Certification Authority"
-     # Certificate "VeriSign Class 3 Public Primary Certification Authority - G4"
-     # Certificate "Trustis FPS Root CA"
-     # Certificate "EE Certification Centre Root CA"
-     # Certificate "LuxTrust Global Root 2"
-     # Certificate "Symantec Class 1 Public Primary Certification Authority - G4"
-     # Certificate "Symantec Class 2 Public Primary Certification Authority - G4"
-    Adding:
-     # Certificate "Microsoft ECC Root Certificate Authority 2017"
-     # Certificate "Microsoft RSA Root Certificate Authority 2017"
-     # Certificate "e-Szigno Root CA 2017"
-     # Certificate "certSIGN Root CA G2"
-     # Certificate "Trustwave Global Certification Authority"
-     # Certificate "Trustwave Global ECC P256 Certification Authority"
-     # Certificate "Trustwave Global ECC P384 Certification Authority"
-     # Certificate "NAVER Global Root Certification Authority"
-     # Certificate "AC RAIZ FNMT-RCM SERVIDORES SEGUROS"
-     # Certificate "GlobalSign Secure Mail Root R45"
-     # Certificate "GlobalSign Secure Mail Root E45"
-     # Certificate "GlobalSign Root R46"
-     # Certificate "GlobalSign Root E46"
-     # Certificate "GLOBALTRUST 2020"
-     # Certificate "ANF Secure Server Root CA"
-     # Certificate "Certum EC-384 CA"
-     # Certificate "Certum Trusted Root CA"
wtw&i?+Bob Relyea <rrelyea@redhat.com> - 2019.2.32-76]- Update to CKBI 2.32 from NSS 3.44
-   Removing:
-   # Certificate "Visa eCommerce Root"
-  [%gS+Kai Engert <kaie@redhat.com> - 2018.2.22-70.0Z- Update to CKBI 2.22 from NSS 3.35$i)*Bob Relyea <rrelyea@redhat.com> - 2021.2.50-72a@- Fix expired certificate.
-    Removing:
-     # Certificate "DST Root CA X3" # Certificate "AC Raiz Certicamara S.A."
-   # Certificate "TC TrustCenter Class 3 CA II"
-   # Certificate "ComSign CA"
-   # Certificate "S-TRUST Universal Root CA"
-   # Certificate "TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı H5"
-   # Certificate "Certplus Root CA G1"
-   # Certificate "Certplus Root CA G2"
-   # Certificate "OpenTrust Root CA G1"
-   # Certificate "OpenTrust Root CA G2"
-   # Certificate "OpenTrust Root CA G3"
-  Adding:
-   # Certificate "GlobalSign Root CA - R6"
-   # Certificate "OISTE WISeKey Global Root GC CA"
-   # Certificate "GTS Root R1"
-   # Certificate "GTS Root R2"
-   # Certificate "GTS Root R3"
-   # Certificate "GTS Root R4"
-   # Certificate "UCA Global G2 Root"
-   # Certificate "UCA Extended Validation Root"
-   # Certificate "Certigna Root CA"
-   # Certificate "emSign Root CA - G1"
-   # Certificate "emSign ECC Root CA - G3"
-   # Certificate "emSign Root CA - C1"
-   # Certificate "emSign ECC Root CA - C3"
-   # Certificate "Hongkong Post Root CA 3"
99})i+Bob Relyea <rrelyea@redhat.com> - 2021.2.50-71`- Update to CKBI 2.50 from NSS 3.67
   - version number update onlyN(i5+Bob Relyea <rrelyea@redhat.com> - 2021.2.48-71`P@- Update to CKBI 2.48 from NSS 3.66
-    Removing:
-     # Certificate "Verisign Class 3 Public Primary Certification Authority - G3"
-     # Certificate "Ge'ic+Bob Relyea <rrelyea@redhat.com> - 2020.2.41-79^y- Update to CKBI 2.41 from NSS 3.53.0
-    Removing:
-     # Certificate "AddTrust Low-Value Services Root"
-     # Certificate "AddTrust External Root"
-     # Certificate "UTN USERFirst Email Root CA"
-     # Certificate "Certplus Class 2 Primary CA"
-     # Certificate "Deutsche Telekom Root CA 2"
-     # Certificate "Staat der Nederlanden Root CA - G2"
-     # Certificate "Swisscom Root CA 2"
-     # Certificate "Certinomis - Root CA"
-    Adding:
-     # Certificate "Entrust Root Certification Authority - G4"
- fix permissions on ghosted files.eoTrust Global CA"
-     # Certificate "GeoTrust Universal CA"
-     # Certificate "GeoTrust Universal CA 2"
-     # Certificate "QuoVadis Root CA"
-     # Certificate "Sonera Class 2 Root CA"
-     # Certificate "Taiwan GRCA"
-     # Certificate "GeoTrust Primary Certification Authority"
-     # Certificate "thawte Primary Root CA"
-     # Certificate "VeriSign Class 3 Public Primary Certification Authority - G5"
-     # Certificate "GeoTrust Primary Certification Authority - G3"
-     # Certificate "thawte Primary Root CA - G2"
-     # Certificate "thawte Primary Root CA - G3"
-     # Certificate "GeoTrust Primary Certification Authority - G2"
-     # Certificate "VeriSign Universal Root Certification Authority"
-     # Certificate "VeriSign Class 3 Public Primary Certification Authority - G4"
-     # Certificate "Trustis FPS Root CA"
-     # Certificate "EE Certification Centre Root CA"
-     # Certificate "LuxTrust Global Root 2"
-     # Certificate "Symantec Class 1 Public Primary Certification Authority - G4"
-     # Certificate "Symantec Class 2 Public Primary Certification Authority - G4"
-    Adding:
-     # Certificate "Microsoft ECC Root Certificate Authority 2017"
-     # Certificate "Microsoft RSA Root Certificate Authority 2017"
-     # Certificate "e-Szigno Root CA 2017"
-     # Certificate "certSIGN Root CA G2"
-     # Certificate "Trustwave Global Certification Authority"
-     # Certificate "Trustwave Global ECC P256 Certification Authority"
-     # Certificate "Trustwave Global ECC P384 Certification Authority"
-     # Certificate "NAVER Global Root Certification Authority"
-     # Certificate "AC RAIZ FNMT-RCM SERVIDORES SEGUROS"
-     # Certificate "GlobalSign Secure Mail Root R45"
-     # Certificate "GlobalSign Secure Mail Root E45"
-     # Certificate "GlobalSign Root R46"
-     # Certificate "GlobalSign Root E46"
-     # Certificate "GLOBALTRUST 2020"
-     # Certificate "ANF Secure Server Root CA"
-     # Certificate "Certum EC-384 CA"
-     # Certificate "Certum Trusted Root CA"
tt*i)+Bob Relyea <rrelyea@redhat.com> - 2021.2.50-72a@- Fix expired certificate.
-    Removing:
-     # Certificate "DST Root CA X3"
}+i+Bob Relyea <rrelyea@redhat.com> - 2022.2.54-71b- Update to CKBI 2.54 from NSS 3.79
-    Removing:
-     # Certificate "GlobalSign Root CA - R2"
-     # Certificate "Cybertrust Global Root"
-     # Certificate "Explicitly Distrusted DigiNotar PKIoverheid G2"
-    Adding:
-     # Certificate "TunTrust Root CA"
-     # Certificate "HARICA TLS RSA Root CA 2021"
-     # Certificate "HARICA TLS ECC Root CA 2021"
-     # Certificate "HARICA Client RSA Root CA 2021"
-     # Certificate "HARICA Client ECC Root CA 2021"
-     # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
-     # Certificate "vTrus ECC Root CA"
-     # Certificate "vTrus Root CA"
-     # Certificate "ISRG Root X2"
-     # Certificate "HiPKI Root CA - G1"
-     # Certificate "Telia Root CA v2"
-     # Certificate "D-TRUST BR Root CA 1 2020"
-     # Certificate "D-TRUST EV Root CA 1 2020"t Root CA G2"
-     # Certificate "OpenTrust Root CA G3"
-     # Certificate "Certplus Root CA G1"
-     # Certificate "Certplus Root CA G2"
-     # Certificate "Government Root Certification Authority"
-     # Certificate "A-Trust-Qual-02"
-     # Certificate "Thailand National Root Certification Authority - G1"
-     # Certificate "TrustCor ECA-1"
-     # Certificate "TrustCor RootCert CA-2"
-     # Certificate "TrustCor RootCert CA-1"
-     # Certificate "Certification Authority of WoSign"
-     # Certificate "CA 沃通根证书"
-     # Certificate "SSC GDL CA Root B"
-     # Certificate "SAPO Class 2 Root CA"
-     # Certificate "SAPO Class 3 Root CA"
-     # Certificate "SAPO Class 4 Root CA"
-     # Certificate "CA Disig Root R1"
-     # Certificate "Autoridad Certificadora Raíz Nacional de Uruguay"
-     # Certificate "ApplicationCA2 Root"
-     # Certificate "GlobalSign"
-     # Certificate "Symantec Class 3 Public Primary Certification Authority - G6"
-     # Certificate "Symantec Class 3 Public Primary Certification Authority - G4"
-     # Certificate "Halcom Root CA"
-     # Certificate "Swisscom Root EV CA 2"
-     # Certificate "CFCA GT CA"
-     # Certificate "Digidentity L3 Root CA - G2"
-     # Certificate "SITHS Root CA v1"
-     # Certificate "Macao Post eSignTrust Root Certification Authority (G02)"
-     # Certificate "Autoridade Certificadora Raiz Brasileira v2"
-     # Certificate "Swisscom Root CA 2"
-     # Certificate "IGC/A AC racine Etat francais"
-     # Certificate "PersonalID Trustworthy RootCA 2011"
-     # Certificate "Swedish Government Root Authority v1"
-     # Certificate "Swiss Government Root CA II"
-     # Certificate "Swiss Government Root CA I"
-     # Certificate "Network Solutions Certificate Authority"
-     # Certificate "COMODO Certification Authority"
-     # Certificate "LuxTrust Global Root"
-     # Certificate "AC1 RAIZ MTIN"
-     # Certificate "Microsoft Root Certificate Authority 2011"
-     # Certificate "CCA India 2011"
-     # Certificate "ANCERT Certificados Notariales V2"
-     # Certificate "ANCERT Certificados CGN V2"
-     # Certificate "EE Certification Centre Root CA"
-     # Certificate "DigiNotar Root CA G2"
-     # Certificate "Federal Common Policy CA"
-     # Certificate "Autoridad de Certificacion Raiz del Estado Venezolano"
-     # Certificate "Autoridad de Certificacion Raiz del Estado Venezolano"
-     # Certificate "China Internet Network Information Center EV Certificates Root"
-     # Certificate "Verizon Global Root CA"
-     # Certificate "SwissSign Silver Root CA - G3"
-     # Certificate "SwissSign Platinum Root CA - G3"
-     # Certificate "SwissSign Gold Root CA - G3"
-     # Certificate "Microsec e-Szigno Root CA 2009"
-     # Certificate "SITHS CA v3"
-     # Certificate "Certinomis - Autorité Racine"
-     # Certificate "ANF Server CA"
-     # Certificate "Thawte Premium Server CA"
-     # Certificate "Thawte Server CA"
-     # Certificate "TC TrustCenter Universal CA III"
-     # Certificate "KEYNECTIS ROOT CA"
-     # Certificate "I.CA - Standard Certification Authority, 09/2009"
-     # Certificate "I.CA - Qualified Certification Authority, 09/2009"
-     # Certificate "VI Registru Centras RCSC (RootCA)"
-     # Certificate "CCA India 2007"
-     # Certificate "Autoridade Certificadora Raiz Brasileira v1"
-     # Certificate "ipsCA Global CA Root"
-     # Certificate "ipsCA Main CA Root"
-     # Certificate "Actalis Authentication CA G1"
-     # Certificate "A-Trust-Qual-03"
-     # Certificate "AddTrust External CA Root"
-     # Certificate "ECRaizEstado"
-     # Certificate "Configuration"
-     # Certificate "FNMT-RCM"
-     # Certificate "StartCom Certification Authority"
-     # Certificate "TWCA Root Certification Authority"
-     # Certificate "VeriSign Class 3 Public Primary Certification Authority - G4"
-     # Certificate "thawte Primary Root CA - G2"
-     # Certificate "GeoTrust Primary Certification Authority - G2"
-     # Certificate "VeriSign Universal Root Certification Authority"
-     # Certificate "thawte Primary Root CA - G3"
-     # Certificate "GeoTrust Primary Certification Authority - G3"
-     # Certificate "E-ME SSI (RCA)"
-     # Certificate "ACEDICOM Root"
-     # Certificate "Autoridad Certificadora Raiz de la Secretaria de Economia"
-     # Certificate "Correo Uruguayo - Root CA"
-     # Certificate "CNNIC ROOT"
-     # Certificate "Common Policy"
-     # Certificate "Macao Post eSignTrust Root Certification Authority"
-     # Certificate "Staat der Nederlanden Root CA - G2"
-     # Certificate "NetLock Platina (Class Platinum) Főtanúsítvány"
-     # Certificate "AC Raíz Certicámara S.A."
-     # Certificate "Cisco Root CA 2048"
-     # Certificate "CA Disig"
-     # Certificate "InfoNotary CSP Root"
-     # Certificate "UCA Global Root"
-     # Certificate "UCA Root"
-     # Certificate "DigiNotar Root CA"
-     # Certificate "Starfield Services Root Certificate Authority"
-     # Certificate "I.CA - Qualified root certificate"
-     # Certificate "I.CA - Standard root certificate"
-     # Certificate "e-Guven Kok Elektronik Sertifika Hizmet Saglayicisi"
-     # Certificate "Japanese Government"
-     # Certificate "AdminCA-CD-T01"
-     # Certificate "Admin-Root-CA"
-     # Certificate "Izenpe.com"
-     # Certificate "TÜBİTAK UEKAE Kök Sertifika Hizmet Sağlayıcısı - Sürüm 3"
-     # Certificate "Halcom CA FO"
-     # Certificate "Halcom CA PO 2"
-     # Certificate "Root CA"
-     # Certificate "GPKIRootCA"
-     # Certificate "ACNLB"
-     # Certificate "state-institutions"
-     # Certificate "state-institutions"
-     # Certificate "SECOM Trust Systems CO.,LTD."
-     # Certificate "D-TRUST Qualified Root CA 1 2007:PN"
-     # Certificate "D-TRUST Root Class 2 CA 2007"
-     # Certificate "D-TRUST Root Class 3 CA 2007"
-     # Certificate "SSC Root CA A"
-     # Certificate "SSC Root CA B"
-     # Certificate "SSC Root CA C"
-     # Certificate "Autoridad de Certificacion de la Abogacia"
-     # Certificate "Root CA Generalitat Valenciana"
-     # Certificate "VAS Latvijas Pasts SSI(RCA)"
-     # Certificate "ANCERT Certificados CGN"
-     # Certificate "ANCERT Certificados Notariales"
-     # Certificate "ANCERT Corporaciones de Derecho Publico"
-     # Certificate "GLOBALTRUST"
-     # Certificate "Certipost E-Trust TOP Root CA"
-     # Certificate "Certipost E-Trust Primary Qualified CA"
-     # Certificate "Certipost E-Trust Primary Normalised CA"
-     # Certificate "Cybertrust Global Root"
-     # Certificate "GlobalSign"
-     # Certificate "IGC/A"
-     # Certificate "S-TRUST Authentication and Encryption Root CA 2005:PN"
-     # Certificate "TC TrustCenter Universal CA I"
-     # Certificate "TC TrustCenter Universal CA II"
-     # Certificate "TC TrustCenter Class 2 CA II"
-     # Certificate "TC TrustCenter Class 4 CA II"
-     # Certificate "Swisscom Root CA 1"
-     # Certificate "Microsec e-Szigno Root CA"
-     # Certificate "LGPKI"
-     # Certificate "AC RAIZ DNIE"
-     # Certificate "Common Policy"
-     # Certificate "TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı"
-     # Certificate "A-Trust-nQual-03"
-     # Certificate "A-Trust-nQual-03"
-     # Certificate "CertRSA01"
-     # Certificate "KISA RootCA 1"
-     # Certificate "KISA RootCA 3"
-     # Certificate "NetLock Minositett Kozjegyzoi (Class QA) Tanusitvanykiado"
-     # Certificate "A-CERT ADVANCED"
-     # Certificate "A-Trust-Qual-01"
-     # Certificate "A-Trust-nQual-01"
-     # Certificate "A-Trust-Qual-02"
-     # Certificate "Staat der Nederlanden Root CA"
-     # Certificate "Serasa Certificate Authority II"
-     # Certificate "TDC Internet"
-     # Certificate "America Online Root Certification Authority 2"
-     # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
-     # Certificate "Government Root Certification Authority"
-     # Certificate "RSA Security Inc"
-     # Certificate "Public Notary Root"
-     # Certificate "GeoTrust Global CA"
-     # Certificate "GeoTrust Global CA 2"
-     # Certificate "GeoTrust Universal CA"
-     # Certificate "GeoTrust Universal CA 2"
-     # Certificate "QuoVadis Root Certification Authority"
-     # Certificate "Autoridade Certificadora Raiz Brasileira"
-     # Certificate "Post.Trust Root CA"
-     # Certificate "Microsoft Root Authority"
-     # Certificate "Microsoft Root Certificate Authority"
-     # Certificate "Microsoft Root Certificate Authority 2010"
-     # Certificate "Entrust.net Secure Server Certification Authority"
-     # Certificate "UTN-USERFirst-Object"
-     # Certificate "BYTE Root Certification Authority 001"
-     # Certificate "CISRCA1"
-     # Certificate "ePKI Root Certification Authority - G2"
-     # Certificate "ePKI EV SSL Certification Authority - G1"
-     # Certificate "AC Raíz Certicámara S.A."
-     # Certificate "SSL.com EV Root Certification Authority RSA"
-     # Certificate "LuxTrust Global Root 2"
-     # Certificate "ACA ROOT"
-     # Certificate "Security Communication ECC RootCA1"
-     # Certificate "Security Communication RootCA3"
-     # Certificate "CHAMBERS OF COMMERCE ROOT - 2016"
-     # Certificate "Network Solutions RSA Certificate Authority"
-     # Certificate "Network Solutions ECC Certificate Authority"
-     # Certificate "Australian Defence Public Root CA"
-     # Certificate "SI-TRUST Root"
-     # Certificate "Halcom Root Certificate Authority"
-     # Certificate "Application CA G3 Root"
-     # Certificate "GLOBALTRUST 2015"
-     # Certificate "Microsoft ECC Product Root Certificate Authority 2018"
-     # Certificate "emSign Root CA - G2"
-     # Certificate "emSign Root CA - C2"
-     # Certificate "Microsoft ECC TS Root Certificate Authority 2018"
-     # Certificate "DigiCert CS ECC P384 Root G5"
-     # Certificate "DigiCert CS RSA4096 Root G5"
-     # Certificate "DigiCert RSA4096 Root G5"
-     # Certificate "DigiCert ECC P384 Root G5"
-     # Certificate "HARICA Code Signing RSA Root CA 2021"
-     # Certificate "HARICA Code Signing ECC Root CA 2021"
-     # Certificate "Microsoft Identity Verification Root Certificate Authority 2020"
o\-iS+Bob Relyea <rrelyea@redhat.com> - 2022.2.54-73b(- Update to CKBI 2.54 from NSS 3.79a,iY+Bob Relyea <rrelyea@redhat.com> - 2022.2.54-72bV- Update to CKBI 2.54 from NSS 3.79
-    Adding:
-     # Certificate "CAEDICOM Root"
-     # Certificate "I.CA Root CA/RSA"
-     # Certificate "MULTICERT Root Certification Authority 01"
-     # Certificate "Certification Authority of WoSign G2"
-     # Certificate "CA WoSign ECC Root"
-     # Certificate "CCA India 2015 SPL"
-     # Certificate "Swedish Government Root Authority v3"
-     # Certificate "Swedish Government Root Authority v2"
-     # Certificate "Tunisian Root Certificate Authority - TunRootCA2"
-     # Certificate "OpenTrust Root CA G1"
-     # Certificate "OpenTrus
JJ2.i}+Bob Relyea <rrelyea@redhat.com> - 2022.2.54-74bz@- Update to CKBI 2.54 from NSS 3.79
-    Removing:
-     # Certificate "TrustCor ECA-1"
-     # Certificate "TrustCor RootCert CA-2"
-     # Certificate "TrustCor RootCert CA-1"
-     # Certificate "Network Solutions Certificate Authority"
-     # Certificate "COMODO Certification Authority"
-     # Certificate "Autoridad de Certificacion Raiz del Estado Venezolano"
-     # Certificate "Microsec e-Szigno Root CA 2009"
-     # Certificate "TWCA Root Certification Authority"
-     # Certificate "Izenpe.com"
-     # Certificate "state-institutions"
-     # Certificate "GlobalSign"
-     # Certificate "Common Policy"
-     # Certificate "A-Trust-nQual-03"
-     # Certificate "A-Trust-Qual-02"
-     # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
-     # Certificate "Government Root Certification Authority"
-     # Certificate "AC Raíz Certicámara S.A."

er+V:eD8
71f20a3e8a0bfe010564d4b6ff77d4b2647ba8383e62e64a557c131359fff889D7
78f9c4332b1d2f19135c616b66d43dfc85165cfc47974524516f8cfde4bb9665D6
bbe893457383d81228467a2e58df9d5f1d18cbfd30d4cd35b2c717dc660133b7D5
744a4dba649fc88cac73b711d32a121916093d5d15e77ef286faaedeb4a66167D4
a0771a63bfd2ad4fc5390775761741924acb2e2a6d6fea5e21306d97e0c18190D3
24f07a4fe7e067974796688aef2936d4d3134d870c6f53a7327a664da0d20893D2
dc1bf06608a791a1bc05682c7a5dd37ff4776553816b5359923260fb02f0c9e2D1
71f02e63578770de15752f8dd63988ac82d645cc84914639679034beaf9f4136D0
cad56706d665a1639372b33e26f5e8b2d45d262ba181a414599688a30272bffdD/
2b5152401ce98d5b3a93e430dbe5819aed3a19a15ef5104214f16d8171c990feD.
aa50cc92809002bfd1b3255057b176376353bd9a36274c4d200209a0ec0861d3D-
b1b4503ca199a88ac8a81a7fa75f6487ef746fd58e4bf8d079e879b4ad3596cbD,
e3a24b7d3f533aea4ed0f3d9388b2f7d72febbb435d58e7be4020cdbc47107e6
99}1i,Bob Relyea <rrelyea@redhat.com> - 2021.2.50-71`- Update to CKBI 2.50 from NSS 3.67
   - version number update onlyN0i5,Bob Relyea <rrelyea@redhat.com> - 2021.2.48-71`P@- Update to CKBI 2.48 from NSS 3.66
-    Removing:
-     # Certificate "Verisign Class 3 Public Primary Certification Authority - G3"
-     # Certificate "Ge/ic,Bob Relyea <rrelyea@redhat.com> - 2020.2.41-79^y- Update to CKBI 2.41 from NSS 3.53.0
-    Removing:
-     # Certificate "AddTrust Low-Value Services Root"
-     # Certificate "AddTrust External Root"
-     # Certificate "UTN USERFirst Email Root CA"
-     # Certificate "Certplus Class 2 Primary CA"
-     # Certificate "Deutsche Telekom Root CA 2"
-     # Certificate "Staat der Nederlanden Root CA - G2"
-     # Certificate "Swisscom Root CA 2"
-     # Certificate "Certinomis - Root CA"
-    Adding:
-     # Certificate "Entrust Root Certification Authority - G4"
- fix permissions on ghosted files.eoTrust Global CA"
-     # Certificate "GeoTrust Universal CA"
-     # Certificate "GeoTrust Universal CA 2"
-     # Certificate "QuoVadis Root CA"
-     # Certificate "Sonera Class 2 Root CA"
-     # Certificate "Taiwan GRCA"
-     # Certificate "GeoTrust Primary Certification Authority"
-     # Certificate "thawte Primary Root CA"
-     # Certificate "VeriSign Class 3 Public Primary Certification Authority - G5"
-     # Certificate "GeoTrust Primary Certification Authority - G3"
-     # Certificate "thawte Primary Root CA - G2"
-     # Certificate "thawte Primary Root CA - G3"
-     # Certificate "GeoTrust Primary Certification Authority - G2"
-     # Certificate "VeriSign Universal Root Certification Authority"
-     # Certificate "VeriSign Class 3 Public Primary Certification Authority - G4"
-     # Certificate "Trustis FPS Root CA"
-     # Certificate "EE Certification Centre Root CA"
-     # Certificate "LuxTrust Global Root 2"
-     # Certificate "Symantec Class 1 Public Primary Certification Authority - G4"
-     # Certificate "Symantec Class 2 Public Primary Certification Authority - G4"
-    Adding:
-     # Certificate "Microsoft ECC Root Certificate Authority 2017"
-     # Certificate "Microsoft RSA Root Certificate Authority 2017"
-     # Certificate "e-Szigno Root CA 2017"
-     # Certificate "certSIGN Root CA G2"
-     # Certificate "Trustwave Global Certification Authority"
-     # Certificate "Trustwave Global ECC P256 Certification Authority"
-     # Certificate "Trustwave Global ECC P384 Certification Authority"
-     # Certificate "NAVER Global Root Certification Authority"
-     # Certificate "AC RAIZ FNMT-RCM SERVIDORES SEGUROS"
-     # Certificate "GlobalSign Secure Mail Root R45"
-     # Certificate "GlobalSign Secure Mail Root E45"
-     # Certificate "GlobalSign Root R46"
-     # Certificate "GlobalSign Root E46"
-     # Certificate "GLOBALTRUST 2020"
-     # Certificate "ANF Secure Server Root CA"
-     # Certificate "Certum EC-384 CA"
-     # Certificate "Certum Trusted Root CA"
tt2i),Bob Relyea <rrelyea@redhat.com> - 2021.2.50-72a@- Fix expired certificate.
-    Removing:
-     # Certificate "DST Root CA X3"
}3i,Bob Relyea <rrelyea@redhat.com> - 2022.2.54-71b- Update to CKBI 2.54 from NSS 3.79
-    Removing:
-     # Certificate "GlobalSign Root CA - R2"
-     # Certificate "Cybertrust Global Root"
-     # Certificate "Explicitly Distrusted DigiNotar PKIoverheid G2"
-    Adding:
-     # Certificate "TunTrust Root CA"
-     # Certificate "HARICA TLS RSA Root CA 2021"
-     # Certificate "HARICA TLS ECC Root CA 2021"
-     # Certificate "HARICA Client RSA Root CA 2021"
-     # Certificate "HARICA Client ECC Root CA 2021"
-     # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
-     # Certificate "vTrus ECC Root CA"
-     # Certificate "vTrus Root CA"
-     # Certificate "ISRG Root X2"
-     # Certificate "HiPKI Root CA - G1"
-     # Certificate "Telia Root CA v2"
-     # Certificate "D-TRUST BR Root CA 1 2020"
-     # Certificate "D-TRUST EV Root CA 1 2020"t Root CA G2"
-     # Certificate "OpenTrust Root CA G3"
-     # Certificate "Certplus Root CA G1"
-     # Certificate "Certplus Root CA G2"
-     # Certificate "Government Root Certification Authority"
-     # Certificate "A-Trust-Qual-02"
-     # Certificate "Thailand National Root Certification Authority - G1"
-     # Certificate "TrustCor ECA-1"
-     # Certificate "TrustCor RootCert CA-2"
-     # Certificate "TrustCor RootCert CA-1"
-     # Certificate "Certification Authority of WoSign"
-     # Certificate "CA 沃通根证书"
-     # Certificate "SSC GDL CA Root B"
-     # Certificate "SAPO Class 2 Root CA"
-     # Certificate "SAPO Class 3 Root CA"
-     # Certificate "SAPO Class 4 Root CA"
-     # Certificate "CA Disig Root R1"
-     # Certificate "Autoridad Certificadora Raíz Nacional de Uruguay"
-     # Certificate "ApplicationCA2 Root"
-     # Certificate "GlobalSign"
-     # Certificate "Symantec Class 3 Public Primary Certification Authority - G6"
-     # Certificate "Symantec Class 3 Publi
c Primary Certification Authority - G4"
-     # Certificate "Halcom Root CA"
-     # Certificate "Swisscom Root EV CA 2"
-     # Certificate "CFCA GT CA"
-     # Certificate "Digidentity L3 Root CA - G2"
-     # Certificate "SITHS Root CA v1"
-     # Certificate "Macao Post eSignTrust Root Certification Authority (G02)"
-     # Certificate "Autoridade Certificadora Raiz Brasileira v2"
-     # Certificate "Swisscom Root CA 2"
-     # Certificate "IGC/A AC racine Etat francais"
-     # Certificate "PersonalID Trustworthy RootCA 2011"
-     # Certificate "Swedish Government Root Authority v1"
-     # Certificate "Swiss Government Root CA II"
-     # Certificate "Swiss Government Root CA I"
-     # Certificate "Network Solutions Certificate Authority"
-     # Certificate "COMODO Certification Authority"
-     # Certificate "LuxTrust Global Root"
-     # Certificate "AC1 RAIZ MTIN"
-     # Certificate "Microsoft Root Certificate Authority 2011"
-     # Certificate "CCA India 2011"
-     # Certificate "ANCERT Certificados Notariales V2"
-     # Certificate "ANCERT Certificados CGN V2"
-     # Certificate "EE Certification Centre Root CA"
-     # Certificate "DigiNotar Root CA G2"
-     # Certificate "Federal Common Policy CA"
-     # Certificate "Autoridad de Certificacion Raiz del Estado Venezolano"
-     # Certificate "Autoridad de Certificacion Raiz del Estado Venezolano"
-     # Certificate "China Internet Network Information Center EV Certificates Root"
-     # Certificate "Verizon Global Root CA"
-     # Certificate "SwissSign Silver Root CA - G3"
-     # Certificate "SwissSign Platinum Root CA - G3"
-     # Certificate "SwissSign Gold Root CA - G3"
-     # Certificate "Microsec e-Szigno Root CA 2009"
-     # Certificate "SITHS CA v3"
-     # Certificate "Certinomis - Autorité Racine"
-     # Certificate "ANF Server CA"
-     # Certificate "Thawte Premium Server CA"
-     # Certificate "Thawte Server CA"
-     # Certificate "TC TrustCenter Universal CA III"
-     # Certificate "KEYNECTIS ROOT CA"
-     # Certificate "I.CA - Standard Certification Authority, 09/2009"
-     # Certificate "I.CA - Qualified Certification Authority, 09/2009"
-     # Certificate "VI Registru Centras RCSC (RootCA)"
-     # Certificate "CCA India 2007"
-     # Certificate "Autoridade Certificadora Raiz Brasileira v1"
-     # Certificate "ipsCA Global CA Root"
-     # Certificate "ipsCA Main CA Root"
-     # Certificate "Actalis Authentication CA G1"
-     # Certificate "A-Trust-Qual-03"
-     # Certificate "AddTrust External CA Root"
-     # Certificate "ECRaizEstado"
-     # Certificate "Configuration"
-     # Certificate "FNMT-RCM"
-     # Certificate "StartCom Certification Authority"
-     # Certificate "TWCA Root Certification Authority"
-     # Certificate "VeriSign Class 3 Public Primary Certification Authority - G4"
-     # Certificate "thawte Primary Root CA - G2"
-     # Certificate "GeoTrust Primary Certification Authority - G2"
-     # Certificate "VeriSign Universal Root Certification Authority"
-     # Certificate "thawte Primary Root CA - G3"
-     # Certificate "GeoTrust Primary Certification Authority - G3"
-     # Certificate "E-ME SSI (RCA)"
-     # Certificate "ACEDICOM Root"
-     # Certificate "Autoridad Certificadora Raiz de la Secretaria de Economia"
-     # Certificate "Correo Uruguayo - Root CA"
-     # Certificate "CNNIC ROOT"
-     # Certificate "Common Policy"
-     # Certificate "Macao Post eSignTrust Root Certification Authority"
-     # Certificate "Staat der Nederlanden Root CA - G2"
-     # Certificate "NetLock Platina (Class Platinum) Főtanúsítvány"
-     # Certificate "AC Raíz Certicámara S.A."
-     # Certificate "Cisco Root CA 2048"
-     # Certificate "CA Disig"
-     # Certificate "InfoNotary CSP Root"
-     # Certificate "UCA Global Root"
-     # Certificate "UCA Root"
-     # Certificate "DigiNotar Root CA"
-     # Certificate "Starfield Services Root Certificate Authority"
-     # Certificate "I.CA - Qualified root certificate"
-     # Certificate "I.CA - Standard root certificate"
-     # Certificate "e-Guven Kok Elektronik Sertifika Hizmet Saglayicisi"
-     # Certificate "Japanese Government"
-     # Certificate "AdminCA-CD-T01"
-     # Certificate "Admin-Root-CA"
-     # Certificate "Izenpe.com"
-     # Certificate "TÜBİTAK UEKAE Kök Sertifika Hizmet Sağlayıcısı - Sürüm 3"
-     # Certificate "Halcom CA FO"
-     # Certificate "Halcom CA PO 2"
-     # Certificate "Root CA"
-     # Certificate "GPKIRootCA"
-     # Certificate "ACNLB"
-     # Certificate "state-institutions"
-     # Certificate "state-institutions"
-     # Certificate "SECOM Trust Systems CO.,LTD."
-     # Certificate "D-TRUST Qualified Root CA 1 2007:PN"
-     # Certificate "D-TRUST Root Class 2 CA 2007"
-     # Certificate "D-TRUST Root Class 3 CA 2007"
-     # Certificate "SSC Root CA A"
-     # Certificate "SSC Root CA B"
-     # Certificate "SSC Root CA C"
-     # Certificate "Autoridad de Certificacion de la Abogacia"
-     # Certificate "Root CA Generalitat Valenciana"
-     # Certificate "VAS Latvijas Pasts SSI(RCA)"
-     # Certificate "ANCERT Certificados CGN"
-     # Certificate "ANCERT Certificados Notariales"
-     # Certificate "ANCERT Corporaciones de Derecho Publico"
-     # Certificate "GLOBALTRUST"
-     # Certificate "Certipost E-Trust TOP Root CA"
-     # Certificate "Certipost E-Trust Primary Qualified CA"
-     # Certificate "Certipost E-Trust Primary Normalised CA"
-     # Certificate "Cybertrust Global Root"
-     # Certificate "GlobalSign"
-     # Certificate "IGC/A"
-     # Certificate "S-TRUST Authentication and Encryption Root CA 2005:PN"
-     # Certificate "TC TrustCenter Universal CA I"
-     # Certificate "TC TrustCenter Universal CA II"
-     # Certificate "TC TrustCenter Class 2 CA II"
-     # Certificate "TC TrustCenter Class 4 CA II"
-     # Certificate "Swisscom Root CA 1"
-     # Certificate "Microsec e-Szigno Root CA"
-     # Certificate "LGPKI"
-     # Certificate "AC RAIZ DNIE"
-     # Certificate "Common Policy"
-     # Certificate "TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı"
-     # Certificate "A-Trust-nQual-03"
-     # Certificate "A-Trust-nQual-03"
-     # Certificate "CertRSA01"
-     # Certificate "KISA RootCA 1"
-     # Certificate "KISA RootCA 3"
-     # Certificate "NetLock Minositett Kozjegyzoi (Class QA) Tanusitvanykiado"
-     # Certificate "A-CERT ADVANCED"
-     # Certificate "A-Trust-Qual-01"
-     # Certificate "A-Trust-nQual-01"
-     # Certificate "A-Trust-Qual-02"
-     # Certificate "Staat der Nederlanden Root CA"
-     # Certificate "Serasa Certificate Authority II"
-     # Certificate "TDC Internet"
-     # Certificate "America Online Root Certification Authority 2"
-     # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
-     # Certificate "Government Root Certification Authority"
-     # Certificate "RSA Security Inc"
-     # Certificate "Public Notary Root"
-     # Certificate "GeoTrust Global CA"
-     # Certificate "GeoTrust Global CA 2"
-     # Certificate "GeoTrust Universal CA"
-     # Certificate "GeoTrust Universal CA 2"
-     # Certificate "QuoVadis Root Certification Authority"
-     # Certificate "Autoridade Certificadora Raiz Brasileira"
-     # Certificate "Post.Trust Root CA"
-     # Certificate "Microsoft Root Authority"
-     # Certificate "Microsoft Root Certificate Authority"
-     # Certificate "Microsoft Root Certificate Authority 2010"
-     # Certificate "Entrust.net Secure Server Certification Authority"
-     # Certificate "UTN-USERFirst-Object"
-     # Certificate "BYTE Root Certification Authority 001"
-     # Certificate "CISRCA1"
-     # Certificate "ePKI Root Certification Authority - G2"
-     # Certificate "ePKI EV SSL Certification Authority - G1"
-     # Certificate "AC Raíz Certicámara S.A."
-     # Certificate "SSL.com EV Root Certification Authority RSA"
-     # Certificate "LuxTrust Global Root 2"
-     # Certificate "ACA ROOT"
-     # Certificate "Security Communication ECC RootCA1"
-     # Certificate "Security Communication RootCA3"
-     # Certificate "CHAMBERS OF COMMERCE ROOT - 2016"
-     # Certificate "Network Solutions RSA Certificate Authority"
-     # Certificate "Network Solutions ECC Certificate Authority"
-     # Certificate "Australian Defence Public Root CA"
-     # Certificate "SI-TRUST Root"
-     # Certificate "Halcom Root Certificate Authority"
-     # Certificate "Application CA G3 Root"
-     # Certificate "GLOBALTRUST 2015"
-     # Certificate "Microsoft ECC Product Root Certificate Authority 2018"
-     # Certificate "emSign Root CA - G2"
-     # Certificate "emSign Root CA - C2"
-     # Certificate "Microsoft ECC TS Root Certificate Authority 2018"
-     # Certificate "DigiCert CS ECC P384 Root G5"
-     # Certificate "DigiCert CS RSA4096 Root G5"
-     # Certificate "DigiCert RSA4096 Root G5"
-     # Certificate "DigiCert ECC P384 Root G5"
-     # Certificate "HARICA Code Signing RSA Root CA 2021"
-     # Certificate "HARICA Code Signing ECC Root CA 2021"
-     # Certificate "Microsoft Identity Verification Root Certificate Authority 2020"
o\5iS,Bob Relyea <rrelyea@redhat.com> - 2022.2.54-73b(- Update to CKBI 2.54 from NSS 3.79a4iY,Bob Relyea <rrelyea@redhat.com> - 2022.2.54-72bV- Update to CKBI 2.54 from NSS 3.79
-    Adding:
-     # Certificate "CAEDICOM Root"
-     # Certificate "I.CA Root CA/RSA"
-     # Certificate "MULTICERT Root Certification Authority 01"
-     # Certificate "Certification Authority of WoSign G2"
-     # Certificate "CA WoSign ECC Root"
-     # Certificate "CCA India 2015 SPL"
-     # Certificate "Swedish Government Root Authority v3"
-     # Certificate "Swedish Government Root Authority v2"
-     # Certificate "Tunisian Root Certificate Authority - TunRootCA2"
-     # Certificate "OpenTrust Root CA G1"
-     # Certificate "OpenTrus
JJ26i},Bob Relyea <rrelyea@redhat.com> - 2022.2.54-74bz@- Update to CKBI 2.54 from NSS 3.79
-    Removing:
-     # Certificate "TrustCor ECA-1"
-     # Certificate "TrustCor RootCert CA-2"
-     # Certificate "TrustCor RootCert CA-1"
-     # Certificate "Network Solutions Certificate Authority"
-     # Certificate "COMODO Certification Authority"
-     # Certificate "Autoridad de Certificacion Raiz del Estado Venezolano"
-     # Certificate "Microsec e-Szigno Root CA 2009"
-     # Certificate "TWCA Root Certification Authority"
-     # Certificate "Izenpe.com"
-     # Certificate "state-institutions"
-     # Certificate "GlobalSign"
-     # Certificate "Common Policy"
-     # Certificate "A-Trust-nQual-03"
-     # Certificate "A-Trust-Qual-02"
-     # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
-     # Certificate "Government Root Certification Authority"
-     # Certificate "AC Raíz Certicámara S.A.""
-     # Certificate "GPKIRootCA"
-     # Certificate "D-TRUST Qualified Root CA 1 2007:PN"
-     # Certificate "TC TrustCenter Universal CA I"
-     # Certificate "TC TrustCenter Universal CA II"
-     # Certificate "TC TrustCenter Class 2 CA II"
-     # Certificate "TC TrustCenter Class 4 CA II"
-     # Certificate "TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı"
-     # Certificate "CertRSA01"
-     # Certificate "KISA RootCA 3"
-     # Certificate "A-CERT ADVANCED"
-     # Certificate "A-Trust-Qual-01"
-     # Certificate "A-Trust-nQual-01"
-     # Certificate "Serasa Certificate Authority II"
-     # Certificate "TDC Internet"
-     # Certificate "America Online Root Certification Authority 2"
-     # Certificate "RSA Security Inc"
-     # Certificate "Public Notary Root"
-     # Certificate "Autoridade Certificadora Raiz Brasileira"
-     # Certificate "Post.Trust Root CA"
-     # Certificate "Entrust.net Secure Server Certification Authority"
-     # Certificate "ePKI EV SSL Certification Authority - G1"
-    Adding:
-     # Certificate "DigiCert TLS ECC P384 Root G5"
-     # Certificate "DigiCert TLS RSA4096 Root G5"
-     # Certificate "DigiCert SMIME ECC P384 Root G5"
-     # Certificate "DigiCert SMIME RSA4096 Root G5"
-     # Certificate "Certainly Root R1"
-     # Certificate "Certainly Root E1"
-     # Certificate "E-Tugra Global Root CA RSA v3"
-     # Certificate "E-Tugra Global Root CA ECC v3"
-     # Certificate "DIGITALSIGN GLOBAL ROOT RSA CA"
-     # Certificate "DIGITALSIGN GLOBAL ROOT ECDSA CA"
-     # Certificate "BJCA Global Root CA1"
-     # Certificate "BJCA Global Root CA2"
-     # Certificate "Symantec Enterprise Mobile Root for Microsoft"
-     # Certificate "A-Trust-Root-05"
-     # Certificate "ADOCA02"
-     # Certificate "StartCom Certification Authority G2"
-     # Certificate "ATHEX Root CA"
-     # Certificate "EBG Elektronik Sertifika Hizmet Sağlayıcısı"
-     # Certificate "GeoTrust Primary Certification Authority"
-     # Certificate "thawte Primary Root CA"
-     # Certificate "VeriSign Class 3 Public Primary Certification Authority - G5"
-     # Certificate "America Online Root Certification Authority 1"
-     # Certificate "Juur-SK"
-     # Certificate "ComSign CA"
-     # Certificate "ComSign Secured CA"
-     # Certificate "ComSign Advanced Security CA"
-     # Certificate "Global Chambersign Root"
-     # Certificate "Sonera Class2 CA"
-     # Certificate "VeriSign Class 3 Public Primary Certification Authority - G3"
-     # Certificate "VeriSign, Inc."
-     # Certificate "GTE CyberTrust Global Root"
-     # Certificate "Equifax Secure Global eBusiness CA-1"
-     # Certificate "Equifax"
-     # Certificate "Class 1 Primary CA"
-     # Certificate "Swiss Government Root CA III"
-     # Certificate "Application CA G4 Root"
-     # Certificate "SSC GDL CA Root A"
-     # Certificate "GlobalSign Code Signing Root E45"
-     # Certificate "GlobalSign Code Signing Root R45"
-     # Certificate "Entrust Code Signing Root Certification Authority - CSBR1"

7,Robert Relyea <rrelyea@redhat.com> - 2023.2.60_v7.0.306-71d- Update to CKBI 2.60_v7.0.306 from NSS 3.91
-    Removing:
-     # Certificate "Camerfirma Global Chambersign Root"
-     # Certificate "Staat der Nederlanden EV Root CA"
-     # Certificate "OpenTrust Root CA G1"
-     # Certificate "Swedish Government Root Authority v1"
-     # Certificate "DigiNotar Root CA G2"
-     # Certificate "Federal Common Policy CA"
-     # Certificate "TC TrustCenter Universal CA III"
-     # Certificate "CCA India 2007"
-     # Certificate "ipsCA Global CA Root"
-     # Certificate "ipsCA Main CA Root"
-     # Certificate "Macao Post eSignTrust Root Certification Authority"
-     # Certificate "InfoNotary CSP Root"
-     # Certificate "DigiNotar Root CA"
-     # Certificate "Root CA
"[]P>UO-Pablo Greco <pablo@fliagreco.com.ar>[- Update to 7.6
- Fix vault reposp=]-Anssi Johansson <avij@centosproject.org>[@- Point AltArch URLs to mirrorlist.c.o instead of mirror.c.o~<U)-Pablo Greco <pablo@fliagreco.com.ar>[l,- Enable ostree-remount in presets
- Include power9 as a separate ppc64le archz;U!-Pablo Greco <pablo@fliagreco.com.ar>[dC- Unified tarball for all arches, so it can be built from the same src.rpmz:U!-Pablo Greco <pablo@fliagreco.com.ar>[bA- Sync version and fixes with centos-release
- Unified spec for all archesG9OC-Johnny Hughes <johnny@centos.org>[b@- Post Trans for contentdirZ83,Robert Relyea <rrelyea@redhat.com> - 2023.2.60_v7.0.306-72di- hand merge the two 'GlobalSign ECC Root CA R4' certs together and the two 'AC RAIZ FNMT-RCM' certs together to keep p11kit from getting confused.
o4oGDOC.Johnny Hughes <johnny@centos.org>[b@- Post Trans for contentdirxCU.Pablo Greco <pablo@fliagreco.com.ar>ZK@- armhfp: Require extlinux-bootloader now that update-boot was obsoletedPBYK-Pablo Greco <pgreco@centosproject.org>_@- Fix reference to 7.8 upstream@AY+-Pablo Greco <pgreco@centosproject.org>_@- Update to 7.9>@Y%-Pablo Greco <pgreco@centosproject.org>^- Add rootfs-expand to aarch64
- Create generic kvariant in aarch64 if it doesn't exist (for new kernel repos)
- Own kvariant var in armhfp and aarch64
- Backport move of /etc/os-release to /usr/lib/os-release (ngompa)
- Spec file cleanup (carlwgeorge)
- Update to 7.8p?Y	-Pablo Greco <pgreco@centosproject.org>]m@- Own yum vars
- Generate yum vars at build time
- Remove dist_suffix
- Fix autorelabel preset
- Fix tuned profile in system-release-cpe
- Set aarch64 tuned profile to server
- Update to 7.7
pJY	.Pablo Greco <pgreco@centosproject.org>]m@- Own yum vars
- Generate yum vars at build time
- Remove dist_suffix
- Fix autorelabel preset
- Fix tuned profile in system-release-cpe
- Set aarch64 tuned profile to server
- Update to 7.7PIUO.Pablo Greco <pablo@fliagreco.com.ar>[- Update to 7.6
- Fix vault repospH].Anssi Johansson <avij@centosproject.org>[@- Point AltArch URLs to mirrorlist.c.o instead of mirror.c.o~GU).Pablo Greco <pablo@fliagreco.com.ar>[l,- Enable ostree-remount in presets
- Include power9 as a separate ppc64le archzFU!.Pablo Greco <pablo@fliagreco.com.ar>[dC- Unified tarball for all arches, so it can be built from the same src.rpmzEU!.Pablo Greco <pablo@fliagreco.com.ar>[bA- Sync version and fixes with centos-release
- Unified spec for all arches
\l$Ok_/Rob Crittenden <rcritten@redhat.com> - 0.78.4-8[MA- Disable iterate-10 test which fails intermitently (#1596161)
- Add BuildRequires for running autoreconf
Nk1/Rob Crittenden <rcritten@redhat.com> - 0.78.4-7[M@- Pass _PROXY, _proxy, LANG and LC_* environment variables to
  helpers (#1596161)\MkQ/Rob Crittenden <rcritten@redhat.com> - 0.78.4-6[
@- Remove reference to unused patch_LOs.Johnny Hughes <johnny@centos.org>dcp@- Update for 7.9.2009 and EOL
- EOL is 30 June 2024>KY%.Pablo Greco <pgreco@centosproject.org>^- Add rootfs-expand to aarch64
- Create generic kvariant in aarch64 if it doesn't exist (for new kernel repos)
- Own kvariant var in armhfp and aarch64
- Backport move of /etc/os-release to /usr/lib/os-release (ngompa)
- Spec file cleanup (carlwgeorge)
- Update to 7.8
>
{Tm/Rob Crittenden <rcritten@redhat.com> - 0.78.4-13^@- Ensure that files read in have a trailing new-line (#1814976)xSm/Rob Crittenden <rcritten@redhat.com> - 0.78.4-12]A- Add documentation for the '-N' option to the dogtag-ipa-renew-agent-submit
  man page (#1651368)
- SCEP: Don't set message=<ca ident> with GetCaps and GetCACert (#1608781)
- SCEP operation GetCAChain is not valid. Should be GetCACertChain (#1590727)
- Document owner and permission parameters to getcert (#1549585)Rm9/Rob Crittenden <rcritten@redhat.com> - 0.78.4-11\b@- Increase SCEP spec compliance, set more secure default cipher and hash.
  (#1533216)QmC/Rob Crittenden <rcritten@redhat.com> - 0.78.4-10[@- Backport patches to add support for the MS Certificate Template V2
  extension (#1622184)>Pk/Rob Crittenden <rcritten@redhat.com> - 0.78.4-9[qr- Remove patch to pass _PROXY, _proxy, LANG and LC_* environment
  variables to helpers. The root cause was a bug in IPA (#1596161)
Wx\WZmC0Rob Crittenden <rcritten@redhat.com> - 0.78.4-10[@- Backport patches to add support for the MS Certificate Template V2
  extension (#1622184)>Yk0Rob Crittenden <rcritten@redhat.com> - 0.78.4-9[qr- Remove patch to pass _PROXY, _proxy, LANG and LC_* environment
  variables to helpers. The root cause was a bug in IPA (#1596161)$Xk_0Rob Crittenden <rcritten@redhat.com> - 0.78.4-8[MA- Disable iterate-10 test which fails intermitently (#1596161)
- Add BuildRequires for running autoreconf
Wk10Rob Crittenden <rcritten@redhat.com> - 0.78.4-7[M@- Pass _PROXY, _proxy, LANG and LC_* environment variables to
  helpers (#1596161)Vm#/Rob Crittenden <rcritten@redhat.com> - 0.78.4-15`@- Don't report spurious error if no SCEP pkiMessage is ready yet (#1969854)Um/Rob Crittenden <rcritten@redhat.com> - 0.78.4-14^Ǿ- Include &message=CA-IDENT with GetCACaps/GetCACert requests (#1839181)
]jp]_m#0Rob Crittenden <rcritten@redhat.com> - 0.78.4-15`@- Don't report spurious error if no SCEP pkiMessage is ready yet (#1969854)^m0Rob Crittenden <rcritten@redhat.com> - 0.78.4-14^Ǿ- Include &message=CA-IDENT with GetCACaps/GetCACert requests (#1839181){]m0Rob Crittenden <rcritten@redhat.com> - 0.78.4-13^@- Ensure that files read in have a trailing new-line (#1814976)x\m0Rob Crittenden <rcritten@redhat.com> - 0.78.4-12]A- Add documentation for the '-N' option to the dogtag-ipa-renew-agent-submit
  man page (#1651368)
- SCEP: Don't set message=<ca ident> with GetCaps and GetCACert (#1608781)
- SCEP operation GetCAChain is not valid. Should be GetCACertChain (#1590727)
- Document owner and permission parameters to getcert (#1549585)[m90Rob Crittenden <rcritten@redhat.com> - 0.78.4-11\b@- Increase SCEP spec compliance, set more secure default cipher and hash.
  (#1533216)
}dm91Rob Crittenden <rcritten@redhat.com> - 0.78.4-11\b@- Increase SCEP spec compliance, set more secure default cipher and hash.
  (#1533216)cmC1Rob Crittenden <rcritten@redhat.com> - 0.78.4-10[@- Backport patches to add support for the MS Certificate Template V2
  extension (#1622184)>bk1Rob Crittenden <rcritten@redhat.com> - 0.78.4-9[qr- Remove patch to pass _PROXY, _proxy, LANG and LC_* environment
  variables to helpers. The root cause was a bug in IPA (#1596161)$ak_1Rob Crittenden <rcritten@redhat.com> - 0.78.4-8[M@- Disable iterate-10 test which fails intermitently (#1596161)
- Add BuildRequires for running autoreconf{`m0Rob Crittenden <rcritten@redhat.com> - 0.78.4-16aHw- Fix file descriptor leak when executing CA helpers (#1992439)
u~u{im1Rob Crittenden <rcritten@redhat.com> - 0.78.4-16aHw- Fix file descriptor leak when executing CA helpers (#1992439)hm#1Rob Crittenden <rcritten@redhat.com> - 0.78.4-15`@- Don't report spurious error if no SCEP pkiMessage is ready yet (#1969854)gm1Rob Crittenden <rcritten@redhat.com> - 0.78.4-14^Ǿ- Include &message=CA-IDENT with GetCACaps/GetCACert requests (#1839181){fm1Rob Crittenden <rcritten@redhat.com> - 0.78.4-13^@- Ensure that files read in have a trailing new-line (#1814976)xem1Rob Crittenden <rcritten@redhat.com> - 0.78.4-12]A- Add documentation for the '-N' option to the dogtag-ipa-renew-agent-submit
  man page (#1651368)
- SCEP: Don't set message=<ca ident> with GetCaps and GetCACert (#1608781)
- SCEP operation GetCAChain is not valid. Should be GetCACertChain (#1590727)
- Document owner and permission parameters to getcert (#1549585)
XXWhXznu2Miroslav Rezanina <mrezanin@redhat.com> - 19.4-2.el7^s^- ci-Removing-cloud-user-from-wheel.pat%muG2Miroslav Rezanina <mrezanin@redhat.com> - 19.4-1.el7^p- Rebase to 19.4 [bz#1803094]
- Resolves: bz#1803094
  ([RHEL-7.9] cloud-init rebase to 19.4)kluc2Miroslav Rezanina <mrezanin@redhat.com> - 18.5-6.el7]@- ci-util-json.dumps-on-python-2.7-will-handle-UnicodeDec.patch [bz#1744526]
- Resolves: bz#1744526
  ([cloud-init][OpenStack] cloud-init can't persist instance-data.json)}ku2Miroslav Rezanina <mrezanin@redhat.com> - 18.5-5.el7]w@- ci-Fix-for-network-configuration-not-persisting-after-r.patch [bz#1593010]
- Resolves: bz#1593010
  ([cloud-init][RHVM]cloud-init network configuration does not persist reboot [RHEL 7.8])$jm]1Rob Crittenden <rcritten@redhat.com> - 0.78.4-17an@- certmonger creates CSRs with invalid DER syntax for X509v3 extensions
  with critical=FALSE (#2015511)ch [bz#1549638]
- ci-Remove-race-condition-between-cloud-init-and-Network.patch [bz#1748015]
- ci-cc_set_password-increase-random-pwlength-from-9-to-2.patch [bz#1812170]
- ci-utils-use-SystemRandom-when-generating-random-passwo.patch [bz#1812173]
- ci-Enable-ssh_deletekeys-by-default.patch [bz#1574338]
- Resolves: bz#1549638
  ([RHEL7]cloud-user added to wheel group and sudoers.d causes 'sudo -v' prompts for passphrase)
- Resolves: bz#1574338
  (CVE-2018-10896 cloud-init: SSH host keys are not regenerated for the new instances [rhel-7])
- Resolves: bz#1748015
  ([cloud-init][RHEL7] /etc/resolv.conf lose config after reboot (initial instance is ok))
- Resolves: bz#1812170
  (CVE-2020-8632 cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py [rhel-7])
- Resolves: bz#1812173
  (CVE-2020-8631 cloud-init: Use of random.choice when generating random password [rhel-7])
++@qu
2Miroslav Rezanina <mrezanin@redhat.com> - 19.4-5.el7^@- ci-Remove-race-condition-between-cloud-init-and-Network-v2.patch [bz#1748015]
- ci-cc_mounts-fix-incorrect-format-specifiers-316.patch [bz#1772505]
- Resolves: bz#1748015
  ([cloud-init][RHEL7] /etc/resolv.conf lose config after reboot (initial instance is ok))
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)pu2Miroslav Rezanina <mrezanin@redhat.com> - 19.4-4.el7^@- ci-swap-file-size-being-used-before-checked-if-str-315.patch [bz#1772505]
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)ou2Miroslav Rezanina <mrezanin@redhat.com> - 19.4-3.el7^@- ci-Do-not-use-fallocate-in-swap-file-creation-on-xfs.-7.patch [bz#1772505]
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)
qYqdsuU2Miroslav Rezanina <mrezanin@redhat.com> - 19.4-7.el7^- ci-ec2-only-redact-token-request-headers-in-logs-avoid-.patch [bz#1821999]
- Resolves: bz#1821999
  ([RHEL7.9] Do not log IMDSv2 token values into cloud-init.log)#ruS2Miroslav Rezanina <mrezanin@redhat.com> - 19.4-6.el7^>@- ci-Use-reload-or-try-restart-instead-of-try-reload-or-r.patch [bz#1748015]
- ci-ec2-Do-not-log-IMDSv2-token-values-instead-use-REDAC.patch [bz#1821999]
- Resolves: bz#1748015
  ([cloud-init][RHEL7] /etc/resolv.conf lose config after reboot (initial instance is ok))
- Resolves: bz#1821999
  ([RHEL7.9] Do not log IMDSv2 token values into cloud-init.log)
Wzvu3Miroslav Rezanina <mrezanin@redhat.com> - 19.4-2.el7^s^- ci-Removing-cloud-user-from-wheel.pat)uuG3Miroslav Rezanina <mrezanin@redhat.com> - 19.4-1.el7^p- Rebase to 19.4 [bz#1803094]
- Resolves: bz#1803094
  ([RHEL-7.9] cloud-init rebase to 19.4)ti!2Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.2_- ci-When-tools.conf-does-not-exist-running-cmd-vmware-to.patch [bz#1839619]
- ci-Changing-notation-of-subp-call.patch [bz#1839619]
- ci-DHCP-sandboxing-failing-on-noexec-mounted-var-tmp-52.patch [bz#1871916]
- Resolves: bz#1839619
  ([ESXi][RHEL7.9][cloud-init]ERROR log in cloud-init.log after clone VM on ESXi platform [rhel-7.9.z])
- Resolves: bz#1871916
  ([Azure][RHEL 7.9] cloud-init Permission denied with the use of mount option noexec [rhel-7.9.z])ch [bz#1549638]
- ci-Remove-race-condition-between-cloud-init-and-Network.patch [bz#1748015]
- ci-cc_set_password-increase-random-pwlength-from-9-to-2.patch [bz#1812170]
- ci-utils-use-SystemRandom-when-generating-random-passwo.patch [bz#1812173]
- ci-Enable-ssh_deletekeys-by-default.patch [bz#1574338]
- Resolves: bz#1549638
  ([RHEL7]cloud-user added to wheel group and sudoers.d causes 'sudo -v' prompts for passphrase)
- Resolves: bz#1574338
  (CVE-2018-10896 cloud-init: SSH host keys are not regenerated for the new instances [rhel-7])
- Resolves: bz#1748015
  ([cloud-init][RHEL7] /etc/resolv.conf lose config after reboot (initial instance is ok))
- Resolves: bz#1812170
  (CVE-2020-8632 cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py [rhel-7])
- Resolves: bz#1812173
  (CVE-2020-8631 cloud-init: Use of random.choice when generating random password [rhel-7])
++@yu
3Miroslav Rezanina <mrezanin@redhat.com> - 19.4-5.el7^@- ci-Remove-race-condition-between-cloud-init-and-Network-v2.patch [bz#1748015]
- ci-cc_mounts-fix-incorrect-format-specifiers-316.patch [bz#1772505]
- Resolves: bz#1748015
  ([cloud-init][RHEL7] /etc/resolv.conf lose config after reboot (initial instance is ok))
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)xu3Miroslav Rezanina <mrezanin@redhat.com> - 19.4-4.el7^@- ci-swap-file-size-being-used-before-checked-if-str-315.patch [bz#1772505]
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)wu3Miroslav Rezanina <mrezanin@redhat.com> - 19.4-3.el7^@- ci-Do-not-use-fallocate-in-swap-file-creation-on-xfs.-7.patch [bz#1772505]
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)
qYqd{uU3Miroslav Rezanina <mrezanin@redhat.com> - 19.4-7.el7^- ci-ec2-only-redact-token-request-headers-in-logs-avoid-.patch [bz#1821999]
- Resolves: bz#1821999
  ([RHEL7.9] Do not log IMDSv2 token values into cloud-init.log)#zuS3Miroslav Rezanina <mrezanin@redhat.com> - 19.4-6.el7^>@- ci-Use-reload-or-try-restart-instead-of-try-reload-or-r.patch [bz#1748015]
- ci-ec2-Do-not-log-IMDSv2-token-values-instead-use-REDAC.patch [bz#1821999]
- Resolves: bz#1748015
  ([cloud-init][RHEL7] /etc/resolv.conf lose config after reboot (initial instance is ok))
- Resolves: bz#1821999
  ([RHEL7.9] Do not log IMDSv2 token values into cloud-init.log)
#}i_3Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.3_- ci-network-Fix-type-and-respect-name-when-rendering-vla.patch [bz#1861871]
- Resolves: bz#1861871
- ([rhel7][cloud-init] ifup bond0.504 Error: Connection activation failed: No suitable device found for this connection [rhel-7.9.z])|i!3Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.2_- ci-When-tools.conf-does-not-exist-running-cmd-vmware-to.patch [bz#1839619]
- ci-Changing-notation-of-subp-call.patch [bz#1839619]
- ci-DHCP-sandboxing-failing-on-noexec-mounted-var-tmp-52.patch [bz#1871916]
- Resolves: bz#1839619
  ([ESXi][RHEL7.9][cloud-init]ERROR log in cloud-init.log after clone VM on ESXi platform [rhel-7.9.z])
- Resolves: bz#1871916
  ([Azure][RHEL 7.9] cloud-init Permission denied with the use of mount option noexec [rhel-7.9.z])
YjaYu4Miroslav Rezanina <mrezanin@redhat.com> - 19.4-4.el7^@- ci-swap-file-size-being-used-before-checked-if-str-315.patch [bz#1772505]
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)u4Miroslav Rezanina <mrezanin@redhat.com> - 19.4-3.el7^@- ci-Do-not-use-fallocate-in-swap-file-creation-on-xfs.-7.patch [bz#1772505]
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)zu4Miroslav Rezanina <mrezanin@redhat.com> - 19.4-2.el7^s^- ci-Removing-cloud-user-from-wheel.pat.#~i_3Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.3_- ci-network-Fix-type-and-respect-name-when-rendering-vla.patch [bz#1861871]
- Resolves: bz#1861871
  ([rhel7][cloud-init] ifup bond0.504 Error: Connection activation failed: No suitable device found for this connection [rhel-7.9.z])ch [bz#1549638]
- ci-Remove-race-condition-between-cloud-init-and-Network.patch [bz#1748015]
- ci-cc_set_password-increase-random-pwlength-from-9-to-2.patch [bz#1812170]
- ci-utils-use-SystemRandom-when-generating-random-passwo.patch [bz#1812173]
- ci-Enable-ssh_deletekeys-by-default.patch [bz#1574338]
- Resolves: bz#1549638
  ([RHEL7]cloud-user added to wheel group and sudoers.d causes 'sudo -v' prompts for passphrase)
- Resolves: bz#1574338
  (CVE-2018-10896 cloud-init: SSH host keys are not regenerated for the new instances [rhel-7])
- Resolves: bz#1748015
  ([cloud-init][RHEL7] /etc/resolv.conf lose config after reboot (initial instance is ok))
- Resolves: bz#1812170
  (CVE-2020-8632 cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py [rhel-7])
- Resolves: bz#1812173
  (CVE-2020-8631 cloud-init: Use of random.choice when generating random password [rhel-7])
<#uS4Miroslav Rezanina <mrezanin@redhat.com> - 19.4-6.el7^>@- ci-Use-reload-or-try-restart-instead-of-try-reload-or-r.patch [bz#1748015]
- ci-ec2-Do-not-log-IMDSv2-token-values-instead-use-REDAC.patch [bz#1821999]
- Resolves: bz#1748015
  ([cloud-init][RHEL7] /etc/resolv.conf lose config after reboot (initial instance is ok))
- Resolves: bz#1821999
  ([RHEL7.9] Do not log IMDSv2 token values into cloud-init.log)@u
4Miroslav Rezanina <mrezanin@redhat.com> - 19.4-5.el7^@- ci-Remove-race-condition-between-cloud-init-and-Network-v2.patch [bz#1748015]
- ci-cc_mounts-fix-incorrect-format-specifiers-316.patch [bz#1772505]
- Resolves: bz#1748015
  ([cloud-init][RHEL7] /etc/resolv.conf lose config after reboot (initial instance is ok))
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)
i!4Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.2_- ci-When-tools.conf-does-not-exist-running-cmd-vmware-to.patch [bz#1839619]
- ci-Changing-notation-of-subp-call.patch [bz#1839619]
- ci-DHCP-sandboxing-failing-on-noexec-mounted-var-tmp-52.patch [bz#1871916]
- Resolves: bz#1839619
  ([ESXi][RHEL7.9][cloud-init]ERROR log in cloud-init.log after clone VM on ESXi platform [rhel-7.9.z])
- Resolves: bz#1871916
  ([Azure][RHEL 7.9] cloud-init Permission denied with the use of mount option noexec [rhel-7.9.z])duU4Miroslav Rezanina <mrezanin@redhat.com> - 19.4-7.el7^- ci-ec2-only-redact-token-request-headers-in-logs-avoid-.patch [bz#1821999]
- Resolves: bz#1821999
  ([RHEL7.9] Do not log IMDSv2 token values into cloud-init.log)
Fi%4Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.4`+- ci-DataSourceAzure-update-password-for-defuser-if-exist.patch [bz#1900807]
- Resolves: bz#1900807
  (Update existing user password RHEL7x)#i_4Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.3_- ci-network-Fix-type-and-respect-name-when-rendering-vla.patch [bz#1861871]
- Resolves: bz#1861871
  ([rhel7][cloud-init] ifup bond0.504 Error: Connection activation failed: No suitable device found for this connection [rhel-7.9.z])#i_4Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.3_- ci-network-Fix-type-and-respect-name-when-rendering-vla.patch [bz#1861871]
- Resolves: bz#1861871
- ([rhel7][cloud-init] ifup bond0.504 Error: Connection activation failed: No suitable device found for this connection [rhel-7.9.z])
++@u
5Miroslav Rezanina <mrezanin@redhat.com> - 19.4-5.el7^@- ci-Remove-race-condition-between-cloud-init-and-Network-v2.patch [bz#1748015]
- ci-cc_mounts-fix-incorrect-format-specifiers-316.patch [bz#1772505]
- Resolves: bz#1748015
  ([cloud-init][RHEL7] /etc/resolv.conf lose config after reboot (initial instance is ok))
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)
u5Miroslav Rezanina <mrezanin@redhat.com> - 19.4-4.el7^@- ci-swap-file-size-being-used-before-checked-if-str-315.patch [bz#1772505]
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)	u5Miroslav Rezanina <mrezanin@redhat.com> - 19.4-3.el7^@- ci-Do-not-use-fallocate-in-swap-file-creation-on-xfs.-7.patch [bz#1772505]
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)
qYqd
uU5Miroslav Rezanina <mrezanin@redhat.com> - 19.4-7.el7^- ci-ec2-only-redact-token-request-headers-in-logs-avoid-.patch [bz#1821999]
- Resolves: bz#1821999
  ([RHEL7.9] Do not log IMDSv2 token values into cloud-init.log)#uS5Miroslav Rezanina <mrezanin@redhat.com> - 19.4-6.el7^>@- ci-Use-reload-or-try-restart-instead-of-try-reload-or-r.patch [bz#1748015]
- ci-ec2-Do-not-log-IMDSv2-token-values-instead-use-REDAC.patch [bz#1821999]
- Resolves: bz#1748015
  ([cloud-init][RHEL7] /etc/resolv.conf lose config after reboot (initial instance is ok))
- Resolves: bz#1821999
  ([RHEL7.9] Do not log IMDSv2 token values into cloud-init.log)
#i_5Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.3_- ci-network-Fix-type-and-respect-name-when-rendering-vla.patch [bz#1861871]
- Resolves: bz#1861871
- ([rhel7][cloud-init] ifup bond0.504 Error: Connection activation failed: No suitable device found for this connection [rhel-7.9.z])i!5Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.2_- ci-When-tools.conf-does-not-exist-running-cmd-vmware-to.patch [bz#1839619]
- ci-Changing-notation-of-subp-call.patch [bz#1839619]
- ci-DHCP-sandboxing-failing-on-noexec-mounted-var-tmp-52.patch [bz#1871916]
- Resolves: bz#1839619
  ([ESXi][RHEL7.9][cloud-init]ERROR log in cloud-init.log after clone VM on ESXi platform [rhel-7.9.z])
- Resolves: bz#1871916
  ([Azure][RHEL 7.9] cloud-init Permission denied with the use of mount option noexec [rhel-7.9.z])
u6Miroslav Rezanina <mrezanin@redhat.com> - 19.4-4.el7^@- ci-swap-file-size-being-used-before-checked-if-str-315.patch [bz#1772505]
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)n}a5Miroslav Rezanina <mrezanin@redhat.com> - 19.4-7.el7_9.5`@- ci-Fix-unit-failure-of-cloud-final.service-if-NetworkMa.patch [bz#1897616]
- Resolves: bz#1897616
  ([rhel-7]cloud-final.service fails if NetworkManager not installed.)Fi%5Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.4`+- ci-DataSourceAzure-update-password-for-defuser-if-exist.patch [bz#1900807]
- Resolves: bz#1900807
  (Update existing user password RHEL7x)#i_5Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.3_- ci-network-Fix-type-and-respect-name-when-rendering-vla.patch [bz#1861871]
- Resolves: bz#1861871
  ([rhel7][cloud-init] ifup bond0.504 Error: Connection activation failed: No suitable device found for this connection [rhel-7.9.z])
<#uS6Miroslav Rezanina <mrezanin@redhat.com> - 19.4-6.el7^>@- ci-Use-reload-or-try-restart-instead-of-try-reload-or-r.patch [bz#1748015]
- ci-ec2-Do-not-log-IMDSv2-token-values-instead-use-REDAC.patch [bz#1821999]
- Resolves: bz#1748015
  ([cloud-init][RHEL7] /etc/resolv.conf lose config after reboot (initial instance is ok))
- Resolves: bz#1821999
  ([RHEL7.9] Do not log IMDSv2 token values into cloud-init.log)@u
6Miroslav Rezanina <mrezanin@redhat.com> - 19.4-5.el7^@- ci-Remove-race-condition-between-cloud-init-and-Network-v2.patch [bz#1748015]
- ci-cc_mounts-fix-incorrect-format-specifiers-316.patch [bz#1772505]
- Resolves: bz#1748015
  ([cloud-init][RHEL7] /etc/resolv.conf lose config after reboot (initial instance is ok))
- Resolves: bz#1772505
  ([RHEL7] swapon fails with "swapfile has holes" when created on a xfs filesystem by cloud-init)
i!6Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.2_- ci-When-tools.conf-does-not-exist-running-cmd-vmware-to.patch [bz#1839619]
- ci-Changing-notation-of-subp-call.patch [bz#1839619]
- ci-DHCP-sandboxing-failing-on-noexec-mounted-var-tmp-52.patch [bz#1871916]
- Resolves: bz#1839619
  ([ESXi][RHEL7.9][cloud-init]ERROR log in cloud-init.log after clone VM on ESXi platform [rhel-7.9.z])
- Resolves: bz#1871916
  ([Azure][RHEL 7.9] cloud-init Permission denied with the use of mount option noexec [rhel-7.9.z])duU6Miroslav Rezanina <mrezanin@redhat.com> - 19.4-7.el7^- ci-ec2-only-redact-token-request-headers-in-logs-avoid-.patch [bz#1821999]
- Resolves: bz#1821999
  ([RHEL7.9] Do not log IMDSv2 token values into cloud-init.log)
Fi%6Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.4`+- ci-DataSourceAzure-update-password-for-defuser-if-exist.patch [bz#1900807]
- Resolves: bz#1900807
  (Update existing user password RHEL7x)#i_6Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.3_- ci-network-Fix-type-and-respect-name-when-rendering-vla.patch [bz#1861871]
- Resolves: bz#1861871
  ([rhel7][cloud-init] ifup bond0.504 Error: Connection activation failed: No suitable device found for this connection [rhel-7.9.z])#i_6Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.3_- ci-network-Fix-type-and-respect-name-when-rendering-vla.patch [bz#1861871]
- Resolves: bz#1861871
- ([rhel7][cloud-init] ifup bond0.504 Error: Connection activation failed: No suitable device found for this connection [rhel-7.9.z])
{{sI7Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rsu7Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.mY7Marian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.	i+6Jon Maloy <jmaloy@redhat.com> - 19.4-7.el7_9.6a- ci-cloudinit-net-handle-two-different-routes-for-the-sa.patch [bz#2003231]
- Resolves: bz#2003231
  (anything above 19.2 of cloud init it fails to assign default route and connect to the meta data service)n}a6Miroslav Rezanina <mrezanin@redhat.com> - 19.4-7.el7_9.5`@- ci-Fix-unit-failure-of-cloud-final.service-if-NetworkMa.patch [bz#1897616]
- Resolves: bz#1897616
  ([rhel-7]cloud-final.service fails if NetworkManager not installed.)
st[Q%7Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.$7Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
#s#7Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c"sW7Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.!s97Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	 s!7Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.
Br\6B
,s#8Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c+sW8Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.*s98Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	)s!8Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.(sI8Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r'su8Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
&7Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.
mum	2s!9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.1sI9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.t0g8Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
/8Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q.8Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.-8Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.

er+V:eDE
298ea0c2efac5573e322e25503e2c30d52bb589fa8ef1cc0df2ba4f2bbbfd3c3DD
c5fc7f37feaeaf11068007f084d0a7046d1674006226de685b890730ee95e3c5DC
5f7f4b24a0e71345d5407d27b3ec2dba93f549f3873d99c73c1a6b6d5527120bDB
69d4fb9319ca5a9e4cae9e47996216cc1f227003389290e9e68c05911af73d15DA
f3f69f58e04b244b740beae57319f782363f8a8bfaacea37bca6ed2cb7d1cd2eD@
1cb1df73a2743fe17a9ccf9a82ba1339ff309d7912d173c10e2a3e8ef400fcffD?
2009ebe5d0c47032c5784190a92c5dfb2abdff45270eabce812d7641915b2fb6D>
88829e504b63e6f7b3b0f74d257ab87d6d2ac4c04e4220a90e33576fdc11d02fD=
6a71d3f89673ae6444441f6f1e25eb47a4347ba95f13345e2fcfcdfda313670bD<
8c4048ad0a30efd78b835e73ee590a52730bf658e4ee011dd963e908a4dbad81D;
6489c51c51e8202231b1a3e24f6328463bbd952da0cbdede7cfd828112422e18D:
c7607cfa2a4a5dcba948ec0c8b744a7f05d5113920dcbe14a16acdc6a14166b7D9
7fe1420aaf46d2b3e38efd53645a2803c75ef85aa2e51400cf062745f1a1e9ca
gs
89Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q79Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.69Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
5s#9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c4sW9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.3s99Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
WFuW
?e7:Kalev Lember <klember@redhat.com> - 3.28.1-4[s- Backport two additional upstream patches for thunderbolt panel
- Resolves: #1594880	>m':Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-3[(@- Remove outdated soft hyphens from Japanese translation
- Resolves: #1519109m=qm:Christian Kellner <ckellner@redhat.com> - 3.28.1-2[d@- Include thunderbolt panel
- Resolves: #1567179^<e[:Kalev Lember <klember@redhat.com> - 3.28.1-1Zn- Update to 3.28.1
- Resolves: #1567179y;m:Carlos Garnacho <cgarnach@redhat.com> - 3.26.2-9Z- Add support for Wacom Pro Pen 3D styli
  Resolves: #1557256C:9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.t9g9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
>y>mGqm;Christian Kellner <ckellner@redhat.com> - 3.28.1-2[d@- Include thunderbolt panel
- Resolves: #1567179^Fe[;Kalev Lember <klember@redhat.com> - 3.28.1-1Zn- Update to 3.28.1
- Resolves: #1567179yEm;Carlos Garnacho <cgarnach@redhat.com> - 3.26.2-9Z- Add support for Wacom Pro Pen 3D styli
  Resolves: #1557256rDyo:Michael Catanzaro <mcatanzaro@redhat.com> - 3.28.1-8.1b@- Remove timezone boundaries
  Resolves: #2098262vCa
:Marek Kasik <mkasik@redhat.com> - 3.28.1-8`KW- Enable Printers panel in all environments
- Resolves: #1559431zBm	:Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7^- Categorize Infiniband devices correctly
  Resolves: #1630154Am;:Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]L- Calculate better extents for the configured displays arrangement
  Resolves: #1591643p@mw:Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]J@- Fix crash in thunderbolt panel
  Resolves: #1672289
mso[mrNyo;Michael Catanzaro <mcatanzaro@redhat.com> - 3.28.1-8.1b@- Remove timezone boundaries
  Resolves: #2098262vMa
;Marek Kasik <mkasik@redhat.com> - 3.28.1-8`KW- Enable Printers panel in all environments
- Resolves: #1559431zLm	;Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7^- Categorize Infiniband devices correctly
  Resolves: #1630154Km;;Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]L- Calculate better extents for the configured displays arrangement
  Resolves: #1591643pJmw;Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]J@- Fix crash in thunderbolt panel
  Resolves: #1672289
Ie7;Kalev Lember <klember@redhat.com> - 3.28.1-4[s- Backport two additional upstream patches for thunderbolt panel
- Resolves: #1594880	Hm';Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-3[(@- Remove outdated soft hyphens from Japanese translation
- Resolves: #1519109
Y7Z]YpUmw<Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]J@- Fix crash in thunderbolt panel
  Resolves: #1672289
Te7<Kalev Lember <klember@redhat.com> - 3.28.1-4[s- Backport two additional upstream patches for thunderbolt panel
- Resolves: #1594880	Sm'<Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-3[(@- Remove outdated soft hyphens from Japanese translation
- Resolves: #1519109mRqm<Christian Kellner <ckellner@redhat.com> - 3.28.1-2[d@- Include thunderbolt panel
- Resolves: #1567179^Qe[<Kalev Lember <klember@redhat.com> - 3.28.1-1Zn- Update to 3.28.1
- Resolves: #1567179yPm<Carlos Garnacho <cgarnach@redhat.com> - 3.26.2-9Z- Add support for Wacom Pro Pen 3D styli
  Resolves: #1557256EOi#<Bastien Nocera <bnocera@redhat.com> - 3.26.2-8Z
+ control-center-3.26.2-8
- Fix Wi-Fi networks not getting updated
- Show "Wi-Fi disabled" page when Wi-Fi is disabled
- Resolves: #1545713
]is.]m\qm=Christian Kellner <ckellner@redhat.com> - 3.28.1-2[d@- Include thunderbolt panel
- Resolves: #1567179^[e[=Kalev Lember <klember@redhat.com> - 3.28.1-1Zn- Update to 3.28.1
- Resolves: #1567179yZm=Carlos Garnacho <cgarnach@redhat.com> - 3.26.2-9Z- Add support for Wacom Pro Pen 3D styli
  Resolves: #1557256EYi#=Bastien Nocera <bnocera@redhat.com> - 3.26.2-8Z
+ control-center-3.26.2-8
- Fix Wi-Fi networks not getting updated
- Show "Wi-Fi disabled" page when Wi-Fi is disabled
- Resolves: #1545713vXa
<Marek Kasik <mkasik@redhat.com> - 3.28.1-8`KW- Enable Printers panel in all environments
- Resolves: #1559431zWm	<Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7^- Categorize Infiniband devices correctly
  Resolves: #1630154Vm;<Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]L- Calculate better extents for the configured displays arrangement
  Resolves: #1591643
fso[fycm>Carlos Garnacho <cgarnach@redhat.com> - 3.26.2-9Z- Add support for Wacom Pro Pen 3D styli
  Resolves: #1557256vba
=Marek Kasik <mkasik@redhat.com> - 3.28.1-8`KW- Enable Printers panel in all environments
- Resolves: #1559431zam	=Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7^- Categorize Infiniband devices correctly
  Resolves: #1630154`m;=Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]L- Calculate better extents for the configured displays arrangement
  Resolves: #1591643p_mw=Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]J@- Fix crash in thunderbolt panel
  Resolves: #1672289
^e7=Kalev Lember <klember@redhat.com> - 3.28.1-4[s- Backport two additional upstream patches for thunderbolt panel
- Resolves: #1594880	]m'=Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-3[(@- Remove outdated soft hyphens from Japanese translation
- Resolves: #1519109
/zjm	>Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7^- Categorize Infiniband devices correctly
  Resolves: #1630154im;>Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]L- Calculate better extents for the configured displays arrangement
  Resolves: #1591643phmw>Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]J@- Fix crash in thunderbolt panel
  Resolves: #1672289
ge7>Kalev Lember <klember@redhat.com> - 3.28.1-4[s- Backport two additional upstream patches for thunderbolt panel
- Resolves: #1594880	fm'>Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-3[(@- Remove outdated soft hyphens from Japanese translation
- Resolves: #1519109meqm>Christian Kellner <ckellner@redhat.com> - 3.28.1-2[d@- Include thunderbolt panel
- Resolves: #1567179^de[>Kalev Lember <klember@redhat.com> - 3.28.1-1Zn- Update to 3.28.1
- Resolves: #1567179
oIlo	qm'?Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-3[(@- Remove outdated soft hyphens from Japanese translation
- Resolves: #1519109mpqm?Christian Kellner <ckellner@redhat.com> - 3.28.1-2[d@- Include thunderbolt panel
- Resolves: #1567179^oe[?Kalev Lember <klember@redhat.com> - 3.28.1-1Zn- Update to 3.28.1
- Resolves: #1567179ynm?Carlos Garnacho <cgarnach@redhat.com> - 3.26.2-9Z- Add support for Wacom Pro Pen 3D styli
  Resolves: #1557256Emi#?Bastien Nocera <bnocera@redhat.com> - 3.26.2-8Z
+ control-center-3.26.2-8
- Fix Wi-Fi networks not getting updated
- Show "Wi-Fi disabled" page when Wi-Fi is disabled
- Resolves: #1545713rlyo>Michael Catanzaro <mcatanzaro@redhat.com> - 3.28.1-8.1b@- Remove timezone boundaries
  Resolves: #2098262vka
>Marek Kasik <mkasik@redhat.com> - 3.28.1-8`KW- Enable Printers panel in all environments
- Resolves: #1559431
LoeoLxxY@Jiri Vanek <jvanek@redhat.com> - 1.2-1W- updated to 1,3 which fixing nss minor issue
- Resolves: rhbz#1296430$wYq@Jiri Vanek <jvanek@redhat.com> - 1.1-5W- posttrans silenced, the error is appearing only in state, when there is nothing to copy
- Resolves: rhbz#1296430vva
?Marek Kasik <mkasik@redhat.com> - 3.28.1-8`KW- Enable Printers panel in all environments
- Resolves: #1559431zum	?Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7^- Categorize Infiniband devices correctly
  Resolves: #1630154tm;?Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]L- Calculate better extents for the configured displays arrangement
  Resolves: #1591643psmw?Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]J@- Fix crash in thunderbolt panel
  Resolves: #1672289
re7?Kalev Lember <klember@redhat.com> - 3.28.1-4[s- Backport two additional upstream patches for thunderbolt panel
- Resolves: #1594880
UqJnU~Y/@Jiri Vanek <jvanek@redhat.com> - 3.3-3Zm- fixes issue when java.security for openjdk7 was erased
- Resolves: rhbz#1571854}YE@Jiri Vanek <jvanek@redhat.com> - 3.3-2YZA- added another subdirs for policies files
- Resolves: rhbz#1503647
- Resolves: rhbz#1503668t|Y@Jiri Vanek <jvanek@redhat.com> - 3.3-1YZ@- updated to 3.3
- Resolves: rhbz#1503647
- Resolves: rhbz#1503668b{Yo@Jiri Vanek <jvanek@redhat.com> - 2.2-3YG- updated to latest head
- Resolves: rhbz#1427463#zYo@Jiri Vanek <jvanek@redhat.com> - 2.2-1Y?- added "jre/lib/security/blacklisted.certs" to cared files
- moved to newest release 2.1
- moved to new upstream at pagure.io
- added new script of copy_jdk_configs_fixFiles.sh 
- copy_jdk_configs.lua  aligned to it
- Resolves: rhbz#1427463yY?@Jiri Vanek <jvanek@redhat.com> - 1.3-1X@- updated to upstream 1.3 (adding jre/lib/security/cacerts file)
- Resolves: rhbz#1399719
1
1gaoAOndrej Vasik <ovasik@redhat.com> - 8.22-18Wv[@- fix xfs build failure in chrooted environment (#1263341)
- update filesystem lists for stat and tail from latest upstream
  (#1327881, #1280357) 
- disable id/setgid.sh test(missing chroot feature), fix 
  cp-a-selinux test (#1266500,#1266501)
- colorls.sh - change detection of interactive shell for ksh
  compatibility (#1321648)
- fix date --date crash with empty or invalid TZ envvar (#1325786)
- df -l: do not hang on a dead autofs mount point (#1309247)
- sort -h: fix functionality of human readable numeric sort for other
  than first field (#1328360)naAOndrej Vasik <ovasik@redhat.com> - 8.22-16VU- cp: prevent potential sparse file corruption (#1284906)~[#@Jiri Vanek <jvanek@redhat.com> - 3.3-11[R@- Fixing deletation ofemtpy dirs via rogue symlink
- Resolves: rhbz#2100617o[@Jiri Vanek <jvanek@redhat.com> - 3.3-10Z@- added javaws.policy and blacklist
- Resolves: rhbz#1571854
>_AKamil Dudka <kdudka@redhat.com> - 8.22-23[#@- update description of the -a/--all option in df.1 man page (#1553212)
- sort -M: fix memory leak when using multibyte locale (#1540059)h_uAKamil Dudka <kdudka@redhat.com> - 8.22-22Zhu@- mv -n: do not overwrite the destination (#1526265)r_AKamil Dudka <kdudka@redhat.com> - 8.22-21Z%8- timeout: revert the last fix for a possible race (#1439465)_%AKamil Dudka <kdudka@redhat.com> - 8.22-20Z@- df: do not stat file systems that do not satisfy the -t/-x args (#1511947)p_AKamil Dudka <kdudka@redhat.com> - 8.22-19Yé- timeout: fix race possibly terminating wrong process (#1439465)
- ls: allow interruption when reading slow directories (#1421802)
- fold: preserve new-lines in mutlibyte text (#1418505)
!d
o]AKamil Dudka <kdudka@redhat.com> - 8.22-24.el7_9.2_- sync: fix open fallback bug (#1850682)r	oyAKamil Dudka <kdudka@redhat.com> - 8.22-24.el7_9.1^- sync: support syncing specified arguments (#1850682)f_oAKamil Dudka <kdudka@redhat.com> - 8.22-24\- doc: improve description of the --kibibytes option of ls (#1527391)
- doc: fix typo in date example (#1620624)
- stat,tail: sync the list of file systems with coreutils-8.31 (#1659530)
- df: avoid stat() for dummy file systems with -l (#1668137)
- df: prioritize mounts nearer the device root (#1042840)
S\S
_YBJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5g_sBJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage _cBJan Friesse <jfriesse@redhat.com> 2.4.3-5\|- Resolves: rhbz#1376819
- Resolves: rhbz#1634710

- configure: add --with-initconfigdir option (rhbz#1376819)
- merge upstream commit c0d8af0c7b247df16a90850b0edab4f978cb8192 (rhbz#1376819)
- Use RuntimeDirectory instead of tmpfiles.d (rhbz#1376819)
- merge upstream commit fde7fa0c6408709ccdd090aa9064e6a78232498a (rhbz#1376819)
- totemcrypto: Fix importing of the private key (rhbz#1634710)
- merge upstream commit 3f3e6b62719a263cb221c19a06d9a2c570234caa (rhbz#1634710)
- qnetd: Check existence of NSS DB dir before fork (rhbz#1376819)
- merge upstream commit eac28dffdf7f060f41f2b2e95bb0f4c6c033425d (rhbz#1376819)
&sjcuBJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/c}BJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definitionV_OBJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)
vvj_wBJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)_SBJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)
a#D;aV_OCJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)_YCJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5g_sCJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage[cUBJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)Y_UBJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)offlrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|OT Z!_"d#i$n&q's(v*y+{,}-/0123
456789:%;,<2>8??@GANBUC\DcEjFqGxH~IJK
L
MNOQRS!T$U&V+W.X2Z5[8\:]?^B_F`IaLbNcPdSeVfXg]h`idjikklnmqntovpxq{r~stuvwxyz{#|)}/~5:?EJPU[afkquy~	
M_SCJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)jcuCJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/c}CJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definition
>>cGCJan Friesse <jfriesse@redhat.com> 2.4.5-7.2av@- Resolves: rhbz#2001969

- totem: Add cancel_hold_on_retransmit config option (rhbz#2001969)[cUCJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)Y_UCJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)j_wCJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)
S\S!_YDJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5g _sDJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage _cDJan Friesse <jfriesse@redhat.com> 2.4.3-5\|- Resolves: rhbz#1376819
- Resolves: rhbz#1634710

- configure: add --with-initconfigdir option (rhbz#1376819)
- merge upstream commit c0d8af0c7b247df16a90850b0edab4f978cb8192 (rhbz#1376819)
- Use RuntimeDirectory instead of tmpfiles.d (rhbz#1376819)
- merge upstream commit fde7fa0c6408709ccdd090aa9064e6a78232498a (rhbz#1376819)
- totemcrypto: Fix importing of the private key (rhbz#1634710)
- merge upstream commit 3f3e6b62719a263cb221c19a06d9a2c570234caa (rhbz#1634710)
- qnetd: Check existence of NSS DB dir before fork (rhbz#1376819)
- merge upstream commit eac28dffdf7f060f41f2b2e95bb0f4c6c033425d (rhbz#1376819)
&sj$cuDJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/#c}DJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definitionV"_ODJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)
vvj&_wDJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)%_SDJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)
a#D;aV+_OEJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)*_YEJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5g)_sEJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage[(cUDJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)Y'_UDJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)
M._SEJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)j-cuEJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/,c}EJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definition
>>2cGEJan Friesse <jfriesse@redhat.com> 2.4.5-7.2av@- Resolves: rhbz#2001969

- totem: Add cancel_hold_on_retransmit config option (rhbz#2001969)[1cUEJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)Y0_UEJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)j/_wEJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)

er+V:eDR
f19ef75ad99fd28a32063032985acd16eed69a49de7940fe80fe25a45d7b20d5DQ
9b1fd6f75c44990182608f11437d29610a09c14eef6cd15e358d8dc204c067a6DP
21cd1d5d48d73a90f3072f23c5e4e21283dbd047dba314b528013a884054068eDO
8a874d1a0c3f0dce30ef48f0095dafcb59e864b2b89528a61ee1b1d0a5dcfb7fDN
68ee3d48388315e955a81bc549710f8201b486ea8413b2e63a516ea8d40e5534DM
d413e9756d3b6aece12ea946151d51900d80c7fc73dbaac617ca6d4212d49e38DL
26c0bf18af70ee3cb9525c40bdea17bad250aa0b3b0200dd8132b995dc4081a9DK
547e7d5fe595fcb6ed9634585475a0cdf56327add42e4ccd74358d8c4a27b140DJ
e5654c00b989b0595c553eaf073114c219aec1d06fb9571ebdcebbdfef5a90d5DI
99812ac04e29b031870c5675a4888ceb7ec75a205bace3fe8e9339e91f0e8109DH
adf023be78972d5813085a5facdbea98c19687e2f35459fa6060b6c2fded31a9DG
c6c5c2f11ff4c5bdd22deb3a88852ae012482664acb196d328e4b290495979edDF
2bf6c6071be41d65c91d31c9399563bd6d9298e9a9911c2cfff1bae35d4209fe
S\S5_YFJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5g4_sFJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage 3_cFJan Friesse <jfriesse@redhat.com> 2.4.3-5\|- Resolves: rhbz#1376819
- Resolves: rhbz#1634710

- configure: add --with-initconfigdir option (rhbz#1376819)
- merge upstream commit c0d8af0c7b247df16a90850b0edab4f978cb8192 (rhbz#1376819)
- Use RuntimeDirectory instead of tmpfiles.d (rhbz#1376819)
- merge upstream commit fde7fa0c6408709ccdd090aa9064e6a78232498a (rhbz#1376819)
- totemcrypto: Fix importing of the private key (rhbz#1634710)
- merge upstream commit 3f3e6b62719a263cb221c19a06d9a2c570234caa (rhbz#1634710)
- qnetd: Check existence of NSS DB dir before fork (rhbz#1376819)
- merge upstream commit eac28dffdf7f060f41f2b2e95bb0f4c6c033425d (rhbz#1376819)
&sj8cuFJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/7c}FJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definitionV6_OFJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)
vvj:_wFJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)9_SFJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)
a#D;aV?_OGJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)>_YGJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5g=_sGJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage[<cUFJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)Y;_UFJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)
MB_SGJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)jAcuGJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/@c}GJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definition
>>FcGGJan Friesse <jfriesse@redhat.com> 2.4.5-7.2av@- Resolves: rhbz#2001969

- totem: Add cancel_hold_on_retransmit config option (rhbz#2001969)[EcUGJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)YD_UGJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)jC_wGJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)
S\SI_YHJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5gH_sHJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage G_cHJan Friesse <jfriesse@redhat.com> 2.4.3-5\|- Resolves: rhbz#1376819
- Resolves: rhbz#1634710

- configure: add --with-initconfigdir option (rhbz#1376819)
- merge upstream commit c0d8af0c7b247df16a90850b0edab4f978cb8192 (rhbz#1376819)
- Use RuntimeDirectory instead of tmpfiles.d (rhbz#1376819)
- merge upstream commit fde7fa0c6408709ccdd090aa9064e6a78232498a (rhbz#1376819)
- totemcrypto: Fix importing of the private key (rhbz#1634710)
- merge upstream commit 3f3e6b62719a263cb221c19a06d9a2c570234caa (rhbz#1634710)
- qnetd: Check existence of NSS DB dir before fork (rhbz#1376819)
- merge upstream commit eac28dffdf7f060f41f2b2e95bb0f4c6c033425d (rhbz#1376819)
&sjLcuHJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/Kc}HJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definitionVJ_OHJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)
vvjN_wHJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)M_SHJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)
D#D[PcUHJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)YO_UHJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)
S\SS_YIJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5gR_sIJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage Q_cIJan Friesse <jfriesse@redhat.com> 2.4.3-5\|- Resolves: rhbz#1376819
- Resolves: rhbz#1634710

- configure: add --with-initconfigdir option (rhbz#1376819)
- merge upstream commit c0d8af0c7b247df16a90850b0edab4f978cb8192 (rhbz#1376819)
- Use RuntimeDirectory instead of tmpfiles.d (rhbz#1376819)
- merge upstream commit fde7fa0c6408709ccdd090aa9064e6a78232498a (rhbz#1376819)
- totemcrypto: Fix importing of the private key (rhbz#1634710)
- merge upstream commit 3f3e6b62719a263cb221c19a06d9a2c570234caa (rhbz#1634710)
- qnetd: Check existence of NSS DB dir before fork (rhbz#1376819)
- merge upstream commit eac28dffdf7f060f41f2b2e95bb0f4c6c033425d (rhbz#1376819)
&sjVcuIJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/Uc}IJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definitionVT_OIJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)
vvjX_wIJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)W_SIJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)
a#D;aV]_OJJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)\_YJJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5g[_sJJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage[ZcUIJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)YY_UIJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)
M`_SJJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)j_cuJJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/^c}JJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definition
>>dcGJJan Friesse <jfriesse@redhat.com> 2.4.5-7.2av@- Resolves: rhbz#2001969

- totem: Add cancel_hold_on_retransmit config option (rhbz#2001969)[ccUJJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)Yb_UJJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)ja_wJJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)
jjicuKJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/hc}KJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definitionVg_OKJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)f_YKJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5ge_sKJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage
vvjk_wKJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)j_SKJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)
#DncGKJan Friesse <jfriesse@redhat.com> 2.4.5-7.2av@- Resolves: rhbz#2001969

- totem: Add cancel_hold_on_retransmit config option (rhbz#2001969)[mcUKJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)Yl_UKJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)
S\Sq_YLJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5gp_sLJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage o_cLJan Friesse <jfriesse@redhat.com> 2.4.3-5\|- Resolves: rhbz#1376819
- Resolves: rhbz#1634710

- configure: add --with-initconfigdir option (rhbz#1376819)
- merge upstream commit c0d8af0c7b247df16a90850b0edab4f978cb8192 (rhbz#1376819)
- Use RuntimeDirectory instead of tmpfiles.d (rhbz#1376819)
- merge upstream commit fde7fa0c6408709ccdd090aa9064e6a78232498a (rhbz#1376819)
- totemcrypto: Fix importing of the private key (rhbz#1634710)
- merge upstream commit 3f3e6b62719a263cb221c19a06d9a2c570234caa (rhbz#1634710)
- qnetd: Check existence of NSS DB dir before fork (rhbz#1376819)
- merge upstream commit eac28dffdf7f060f41f2b2e95bb0f4c6c033425d (rhbz#1376819)
&sjtcuLJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/sc}LJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definitionVr_OLJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)
vvjv_wLJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)u_SLJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)
D#D[xcULJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)Yw_ULJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)
S\S{_YMJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5gz_sMJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage y_cMJan Friesse <jfriesse@redhat.com> 2.4.3-5\|- Resolves: rhbz#1376819
- Resolves: rhbz#1634710

- configure: add --with-initconfigdir option (rhbz#1376819)
- merge upstream commit c0d8af0c7b247df16a90850b0edab4f978cb8192 (rhbz#1376819)
- Use RuntimeDirectory instead of tmpfiles.d (rhbz#1376819)
- merge upstream commit fde7fa0c6408709ccdd090aa9064e6a78232498a (rhbz#1376819)
- totemcrypto: Fix importing of the private key (rhbz#1634710)
- merge upstream commit 3f3e6b62719a263cb221c19a06d9a2c570234caa (rhbz#1634710)
- qnetd: Check existence of NSS DB dir before fork (rhbz#1376819)
- merge upstream commit eac28dffdf7f060f41f2b2e95bb0f4c6c033425d (rhbz#1376819)
&sj~cuMJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/}c}MJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definitionV|_OMJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)
vvj_wMJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)_SMJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)
a#D;aV_ONJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)_YNJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5g_sNJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage[cUMJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)Y_UMJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)
M_SNJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)jcuNJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/c}NJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definition
>>cGNJan Friesse <jfriesse@redhat.com> 2.4.5-7.2av@- Resolves: rhbz#2001969

- totem: Add cancel_hold_on_retransmit config option (rhbz#2001969)[cUNJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)Y
_UNJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)j	_wNJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)
jjcuOJan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/c}OJan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definitionV_OOJan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)_YOJan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5g
_sOJan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage
vvj_wOJan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)_SOJan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)
#D&kgsPDave Anderson <anderson@redhat.com> - 7.2.3-4[5A- Fix bpf.c covscan issues
  Resolves: rhbz#1559758gPDave Anderson <anderson@redhat.com> - 7.2.3-3[5@- Rebase to github commits a6cd8408 to da49e201 
  Resolves: rhbz#1559460cGOJan Friesse <jfriesse@redhat.com> 2.4.5-7.2av@- Resolves: rhbz#2001969

- totem: Add cancel_hold_on_retransmit config option (rhbz#2001969)[cUOJan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)Y_UOJan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)
9D:gPDave Anderson <anderson@redhat.com> - 7.2.3-9\,- Alternate list loop detection option
  Resolves: rhbz#1595389
- Readline library tab completion plugin
  Resolves: rhbz#1656165&ggPDave Anderson <anderson@redhat.com> - 7.2.3-8[@- Fix ppc64 "bt" command failure reporting invalid NIP value for a user-space task. 
  Resolves: rhbz#16179361g}PDave Anderson <anderson@redhat.com> - 7.2.3-7[Q@- Support ppc64 increased VA range
- Fix ppc64 "bt" command failure reporting invalid NIP value
  Resolves: rhbz#1617936g?PDave Anderson <anderson@redhat.com> - 7.2.3-6[?Y- Fix for RHEL7 kernel's eBPF support that uses old IDR facility
  Resolves: rhbz#1559758Cg!PDave Anderson <anderson@redhat.com> - 7.2.3-5[d@- Rebase to github commits b9d76838 to c79a11fa
  Resolves: rhbz#1559460
- Fix ppc64/ppc6le stacksize calculation
  Resolves: rhbz#1589685
|7C|C#g!QDave Anderson <anderson@redhat.com> - 7.2.3-5[d@- Rebase to github commits b9d76838 to c79a11fa
  Resolves: rhbz#1559460
- Fix ppc64/ppc6le stacksize calculation
  Resolves: rhbz#1589685k"gsQDave Anderson <anderson@redhat.com> - 7.2.3-4[5A- Fix bpf.c covscan issues
  Resolves: rhbz#1559758!gQDave Anderson <anderson@redhat.com> - 7.2.3-3[5@- Rebase to github commits a6cd8408 to da49e201 
  Resolves: rhbz#15594608 oPBhupesh Sharma <bhsharma@redhat.com> - 7.2.3-11.1_k8- crash/sadump, kaslr: fix failure of calculating kaslr_offset due to an sadump format restriction
  Resolves: rhbz#1854016i5PDave Anderson <anderson@redhat.com> - 7.2.3-11\- Fix to prevent display of invalid "timer" command entries
  Resolves: rhbz#1818084xi	PDave Anderson <anderson@redhat.com> - 7.2.3-10\4- Restrict command line to 1500 bytes
  Resolves: rhbz#1663792
@jM@)i5QDave Anderson <anderson@redhat.com> - 7.2.3-11\- Fix to prevent display of invalid "timer" command entries
  Resolves: rhbz#1818084x(i	QDave Anderson <anderson@redhat.com> - 7.2.3-10\4- Restrict command line to 1500 bytes
  Resolves: rhbz#1663792:'gQDave Anderson <anderson@redhat.com> - 7.2.3-9\,- Alternate list loop detection option
  Resolves: rhbz#1595389
- Readline library tab completion plugin
  Resolves: rhbz#1656165&&ggQDave Anderson <anderson@redhat.com> - 7.2.3-8[@- Fix ppc64 "bt" command failure reporting invalid NIP value for a user-space task. 
  Resolves: rhbz#16179361%g}QDave Anderson <anderson@redhat.com> - 7.2.3-7[Q@- Support ppc64 increased VA range
- Fix ppc64 "bt" command failure reporting invalid NIP value
  Resolves: rhbz#1617936$g?QDave Anderson <anderson@redhat.com> - 7.2.3-6[?Y- Fix for RHEL7 kernel's eBPF support that uses old IDR facility
  Resolves: rhbz#1559758
>DP>1/g}RDave Anderson <anderson@redhat.com> - 7.2.3-7[Q@- Support ppc64 increased VA range
- Fix ppc64 "bt" command failure reporting invalid NIP value
  Resolves: rhbz#1617936.g?RDave Anderson <anderson@redhat.com> - 7.2.3-6[?Y- Fix for RHEL7 kernel's eBPF support that uses old IDR facility
  Resolves: rhbz#1559758C-g!RDave Anderson <anderson@redhat.com> - 7.2.3-5[d@- Rebase to github commits b9d76838 to c79a11fa
  Resolves: rhbz#1559460
- Fix ppc64/ppc6le stacksize calculation
  Resolves: rhbz#1589685k,gsRDave Anderson <anderson@redhat.com> - 7.2.3-4[5A- Fix bpf.c covscan issues
  Resolves: rhbz#1559758+gRDave Anderson <anderson@redhat.com> - 7.2.3-3[5@- Rebase to github commits a6cd8408 to da49e201 
  Resolves: rhbz#15594608*oQBhupesh Sharma <bhsharma@redhat.com> - 7.2.3-11.1_k8- crash/sadump, kaslr: fix failure of calculating kaslr_offset due to an sadump format restriction
  Resolves: rhbz#1854016
YVYs5eSTomáš Mráz <tmraz@redhat.com> - 1.4.11-15VI- crontab: use temporary filename properly ignored by crond84oRBhupesh Sharma <bhsharma@redhat.com> - 7.2.3-11.1_k8- crash/sadump, kaslr: fix failure of calculating kaslr_offset due to an sadump format restriction
  Resolves: rhbz#18540163i5RDave Anderson <anderson@redhat.com> - 7.2.3-11\- Fix to prevent display of invalid "timer" command entries
  Resolves: rhbz#1818084x2i	RDave Anderson <anderson@redhat.com> - 7.2.3-10\4- Restrict command line to 1500 bytes
  Resolves: rhbz#1663792:1gRDave Anderson <anderson@redhat.com> - 7.2.3-9\,- Alternate list loop detection option
  Resolves: rhbz#1595389
- Readline library tab completion plugin
  Resolves: rhbz#1656165&0ggRDave Anderson <anderson@redhat.com> - 7.2.3-8[@- Fix ppc64 "bt" command failure reporting invalid NIP value for a user-space task. 
  Resolves: rhbz#1617936

er+V:eD_
964701bf20ea9285610ce775b493e6d79bf2f27999d29ccbdc6ac91eb4261ce9D^
801be54b282724d9d09516d698bc641c19471a40f11821cbf51804f40228e59aD]
902507007b4e5ee04bd47f98345b605b7cce177b0569460eb0efb299a91918e5D\
e4bb7031f520b296dbe56b80bca148b9f8409329cef2007dd5a06e4548e780d3D[
9e8882a42b481017ad43c670ac8c75a3a878d804f43f7716f685798813397a3fDZ
44ab9339bd5d854867709f046ee7265cdf470dcab6e44935238e9d85f50a3ffbDY
891dab92096ecafec7121bace38c5d802443f838cef21422beb6a451c0e0892dDX
8c0e209a9b3e465d9d43e1e9e5585d8222d61a73748d1a2e8ce486e8b2b25715DW
d97cce4820b6ef5656963548218f0d4ff9ef7c504f16623dd12d6b73c7cf2e2fDV
93e5893e2543f24cc6076a35548745fc96be00bd8f9960f8645d41100dcf0c3aDU
87818b04247bfad1a3a5ad6b7d4ba90f571e7df0d267da4a66fd5e1e17409c65DT
596130fb4480b497134f1ceee905500a7718c15559963c2786a784a511011077DS
64c5a32d35ccc6312c43d89cfee42872bacebecc43ec10e09f90916daedb80da
sD*s3:aSMarcel Plch <mplch@redhat.com> - 1.4.11-20[
@- Fix race condition when crontab is modified the same second
  before and after reading the crontab
- Resolves: rhbz#1638691i9eqSTomáš Mráz <tmraz@redhat.com> - 1.4.11-19Y@- fix URL and source URL of the package (#1501726)*8eqSTomáš Mráz <tmraz@redhat.com> - 1.4.11-18Y- fix regression - spurious PAM log message from crontab (#1479064)
- allow empty variables in crontabs (#1439217)7e[STomáš Mráz <tmraz@redhat.com> - 1.4.11-17Xۡ- make anacron not to contradict itself in syslog
  (job output does not have to be necessarily mailed)6eGSTomáš Mráz <tmraz@redhat.com> - 1.4.11-16X- disable mail from anacron with empty MAILTO
- crontab: do not block access with PAM when running as root
- improve the crontab man page
- do not hardcode system_u selinux user but use the user from
  the current context
trt?eGTTomáš Mráz <tmraz@redhat.com> - 1.4.11-16X- disable mail from anacron with empty MAILTO
- crontab: do not block access with PAM when running as root
- improve the crontab man page
- do not hardcode system_u selinux user but use the user from
  the current contexta>e_SJan Staněk <jstanek@redhat.com> - 1.4.11-24a- Limit memory allocated for file descriptors
  Backports https://github.com/cronie-crond/cronie/commit/584911514ce6aa2f16e1d79431bac816ea62cb2c
  Resolves: rhbz#2026289n=aSMarcel Plch <mplch@redhat.com> - 1.4.11-23\d- Make cronie restart on failure
- Resolves: rhbz#1651730<aWSMarcel Plch <mplch@redhat.com> - 1.4.11-22\l@- Backport upstream patch to fix cron failing on
  smart card authentication
- Resolves: rhbz#1650314{;aSMarcel Plch <mplch@redhat.com> - 1.4.11-21[- Backport upstream patch to fix -P behavior
- Resolves: rhbz#1536111
o]CoEaWTMarcel Plch <mplch@redhat.com> - 1.4.11-22\l@- Backport upstream patch to fix cron failing on
  smart card authentication
- Resolves: rhbz#1650314{DaTMarcel Plch <mplch@redhat.com> - 1.4.11-21[- Backport upstream patch to fix -P behavior
- Resolves: rhbz#15361113CaTMarcel Plch <mplch@redhat.com> - 1.4.11-20[
@- Fix race condition when crontab is modified the same second
  before and after reading the crontab
- Resolves: rhbz#1638691iBeqTTomáš Mráz <tmraz@redhat.com> - 1.4.11-19Y@- fix URL and source URL of the package (#1501726)*AeqTTomáš Mráz <tmraz@redhat.com> - 1.4.11-18Y- fix regression - spurious PAM log message from crontab (#1479064)
- allow empty variables in crontabs (#1439217)@e[TTomáš Mráz <tmraz@redhat.com> - 1.4.11-17Xۡ- make anacron not to contradict itself in syslog
  (job output does not have to be necessarily mailed)
{
{JeGUTomáš Mráz <tmraz@redhat.com> - 1.4.11-16X- disable mail from anacron with empty MAILTO
- crontab: do not block access with PAM when running as root
- improve the crontab man page
- do not hardcode system_u selinux user but use the user from
  the current contextsIeUTomáš Mráz <tmraz@redhat.com> - 1.4.11-15VI- crontab: use temporary filename properly ignored by crondHyATOndřej Pohořelský <opohorel@redhat.com> - 1.4.11-25d@- Set 'missingok' for /etc/cron.deny to not recreate it on update
- Resolves: rhbz#2059479aGe_TJan Staněk <jstanek@redhat.com> - 1.4.11-24a- Limit memory allocated for file descriptors
  Backports https://github.com/cronie-crond/cronie/commit/584911514ce6aa2f16e1d79431bac816ea62cb2c
  Resolves: rhbz#2026289nFaTMarcel Plch <mplch@redhat.com> - 1.4.11-23\d- Make cronie restart on failure
- Resolves: rhbz#1651730
o]CoPaWUMarcel Plch <mplch@redhat.com> - 1.4.11-22\l@- Backport upstream patch to fix cron failing on
  smart card authentication
- Resolves: rhbz#1650314{OaUMarcel Plch <mplch@redhat.com> - 1.4.11-21[- Backport upstream patch to fix -P behavior
- Resolves: rhbz#15361113NaUMarcel Plch <mplch@redhat.com> - 1.4.11-20[
@- Fix race condition when crontab is modified the same second
  before and after reading the crontab
- Resolves: rhbz#1638691iMeqUTomáš Mráz <tmraz@redhat.com> - 1.4.11-19Y@- fix URL and source URL of the package (#1501726)*LeqUTomáš Mráz <tmraz@redhat.com> - 1.4.11-18Y- fix regression - spurious PAM log message from crontab (#1479064)
- allow empty variables in crontabs (#1439217)Ke[UTomáš Mráz <tmraz@redhat.com> - 1.4.11-17Xۡ- make anacron not to contradict itself in syslog
  (job output does not have to be necessarily mailed)
@@*UeqVTomáš Mráz <tmraz@redhat.com> - 1.4.11-18Y- fix regression - spurious PAM log message from crontab (#1479064)
- allow empty variables in crontabs (#1439217)Te[VTomáš Mráz <tmraz@redhat.com> - 1.4.11-17Xۡ- make anacron not to contradict itself in syslog
  (job output does not have to be necessarily mailed)SeGVTomáš Mráz <tmraz@redhat.com> - 1.4.11-16X- disable mail from anacron with empty MAILTO
- crontab: do not block access with PAM when running as root
- improve the crontab man page
- do not hardcode system_u selinux user but use the user from
  the current contextaRe_UJan Staněk <jstanek@redhat.com> - 1.4.11-24a- Limit memory allocated for file descriptors
  Backports https://github.com/cronie-crond/cronie/commit/584911514ce6aa2f16e1d79431bac816ea62cb2c
  Resolves: rhbz#2026289nQaUMarcel Plch <mplch@redhat.com> - 1.4.11-23\d- Make cronie restart on failure
- Resolves: rhbz#1651730
j_Oja[e_VJan Staněk <jstanek@redhat.com> - 1.4.11-24a- Limit memory allocated for file descriptors
  Backports https://github.com/cronie-crond/cronie/commit/584911514ce6aa2f16e1d79431bac816ea62cb2c
  Resolves: rhbz#2026289nZaVMarcel Plch <mplch@redhat.com> - 1.4.11-23\d- Make cronie restart on failure
- Resolves: rhbz#1651730YaWVMarcel Plch <mplch@redhat.com> - 1.4.11-22\l@- Backport upstream patch to fix cron failing on
  smart card authentication
- Resolves: rhbz#1650314{XaVMarcel Plch <mplch@redhat.com> - 1.4.11-21[- Backport upstream patch to fix -P behavior
- Resolves: rhbz#15361113WaVMarcel Plch <mplch@redhat.com> - 1.4.11-20[
@- Fix race condition when crontab is modified the same second
  before and after reading the crontab
- Resolves: rhbz#1638691iVeqVTomáš Mráz <tmraz@redhat.com> - 1.4.11-19Y@- fix URL and source URL of the package (#1501726)
`.iaeqWTomáš Mráz <tmraz@redhat.com> - 1.4.11-19Y@- fix URL and source URL of the package (#1501726)*`eqWTomáš Mráz <tmraz@redhat.com> - 1.4.11-18Y- fix regression - spurious PAM log message from crontab (#1479064)
- allow empty variables in crontabs (#1439217)_e[WTomáš Mráz <tmraz@redhat.com> - 1.4.11-17Xۡ- make anacron not to contradict itself in syslog
  (job output does not have to be necessarily mailed)^eGWTomáš Mráz <tmraz@redhat.com> - 1.4.11-16X- disable mail from anacron with empty MAILTO
- crontab: do not block access with PAM when running as root
- improve the crontab man page
- do not hardcode system_u selinux user but use the user from
  the current contexts]eWTomáš Mráz <tmraz@redhat.com> - 1.4.11-15VI- crontab: use temporary filename properly ignored by crond\yAVOndřej Pohořelský <opohorel@redhat.com> - 1.4.11-25d@- Set 'missingok' for /etc/cron.deny to not recreate it on update
- Resolves: rhbz#2059479
I,afe_WJan Staněk <jstanek@redhat.com> - 1.4.11-24a- Limit memory allocated for file descriptors
  Backports https://github.com/cronie-crond/cronie/commit/584911514ce6aa2f16e1d79431bac816ea62cb2c
  Resolves: rhbz#2026289neaWMarcel Plch <mplch@redhat.com> - 1.4.11-23\d- Make cronie restart on failure
- Resolves: rhbz#1651730daWWMarcel Plch <mplch@redhat.com> - 1.4.11-22\l@- Backport upstream patch to fix cron failing on
  smart card authentication
- Resolves: rhbz#1650314{caWMarcel Plch <mplch@redhat.com> - 1.4.11-21[- Backport upstream patch to fix -P behavior
- Resolves: rhbz#15361113baWMarcel Plch <mplch@redhat.com> - 1.4.11-20[
@- Fix race condition when crontab is modified the same second
  before and after reading the crontab
- Resolves: rhbz#1638691
sD*s3kaXMarcel Plch <mplch@redhat.com> - 1.4.11-20[
@- Fix race condition when crontab is modified the same second
  before and after reading the crontab
- Resolves: rhbz#1638691ijeqXTomáš Mráz <tmraz@redhat.com> - 1.4.11-19Y@- fix URL and source URL of the package (#1501726)*ieqXTomáš Mráz <tmraz@redhat.com> - 1.4.11-18Y- fix regression - spurious PAM log message from crontab (#1479064)
- allow empty variables in crontabs (#1439217)he[XTomáš Mráz <tmraz@redhat.com> - 1.4.11-17Xۡ- make anacron not to contradict itself in syslog
  (job output does not have to be necessarily mailed)geGXTomáš Mráz <tmraz@redhat.com> - 1.4.11-16X- disable mail from anacron with empty MAILTO
- crontab: do not block access with PAM when running as root
- improve the crontab man page
- do not hardcode system_u selinux user but use the user from
  the current context
rhqikYAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16pyAXOndřej Pohořelský <opohorel@redhat.com> - 1.4.11-25d@- Set 'missingok' for /etc/cron.deny to not recreate it on update
- Resolves: rhbz#2059479aoe_XJan Staněk <jstanek@redhat.com> - 1.4.11-24a- Limit memory allocated for file descriptors
  Backports https://github.com/cronie-crond/cronie/commit/584911514ce6aa2f16e1d79431bac816ea62cb2c
  Resolves: rhbz#2026289nnaXMarcel Plch <mplch@redhat.com> - 1.4.11-23\d- Make cronie restart on failure
- Resolves: rhbz#1651730maWXMarcel Plch <mplch@redhat.com> - 1.4.11-22\l@- Backport upstream patch to fix cron failing on
  smart card authentication
- Resolves: rhbz#1650314{laXMarcel Plch <mplch@redhat.com> - 1.4.11-21[- Backport upstream patch to fix -P behavior
- Resolves: rhbz#1536111
IfwukYIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvtkYIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgsiiYAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3rk}YIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
ykYAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockxk%YAndreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskwiqYAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspviyYAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
*{*p~iyZAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew}kZIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv|kZIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg{iiZAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequireszkYAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
((wk[Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagck_ZAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwZAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskZAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkZAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%ZAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqZAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
	k[Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%[Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiq[Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiy[Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
{!Mzk[Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP
k7[Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_[Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkw[Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
k[Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
k\Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%\Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiq\Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiy\Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
{!Mzk\Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7\Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_\Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkw\Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesk\Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
k]Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockk]Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%]Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiq]Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{k
\Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
VUV{!k
]Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z k]Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7]Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_]Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkw]Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
WG6Wc'k_^Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p&kw^Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services%k^Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock$k^Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock#k%^Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5"k]Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
,q,k{^Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5+k^Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{*k
^Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z)k^Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP(k7^Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
{!Mz1k_Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP0k7_Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc/k__Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p.kw_Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services-k_Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
Hnz6k_Andreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c5k__Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q4k{_Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind53k_Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{2k
_Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142

er+V:eDl
88400b854d053822b230b8e0402132b7559ddccd811a7abcedeb1406f7bd8cbdDk
3f56b1a9c01d9d56c7c61e5e85f89f379f66270b55c609f84ba58194ac11e489Dj
7b215997f9c81095863133061f447c80e870ef64f74f3d78e13b7f9cbe749027Di
efa403ad1b6d2564bce0ec54cef3ee401c15f4282733a928d75bb703119161b5Dh
56345477656cfcf05709f7ed9a7e36814bd7eda39a49f2d5fc436d774aef8e06Dg
b6282c4c1e703d703b92a52a9f3959b4a6412072b5923853674734d4920eb1eeDf
650ecdc0d3c0f2d221347461dc47da74b9aeb8041326a30662c310db8452c289De
d12d34da150d926afed7f5810b9ebdc562f483d0100cdce78091fd464612301dDd
fbcc3e564c6dca446a39edd03f346e88b9881d9d18050e89024d0ff48b46240aDc
030d403b90d83c7791ba3ea26cc659f709c596898fbfbd5d5f6e4b737a1293faDb
4fa63e9cbed9669fb646f612b5c9371ba7bd3f11e6ce5059f28af1cdc7da0780Da
80bfd0e65eafbe59f9079ccbd7a8c303269a333e10aaddfce933c3cc81907c66D`
435acde66414134bd505e6658dda39972f87e643ec0169c1f4c59a938280fa39
VUV{;k
`Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z:k`Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP9k7`Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc8k_`Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p7kw`Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
Gm{vAiaAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesr@k}`Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z?k`Andreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c>k_`Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q=k{`Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5<k`Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
H)M+HvIkaIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgHiiaAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Gk}aIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhFikaAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mEiuaAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiDimaAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUCiEaAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|BkaIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
M.R0MvQkbIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgPiibAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Ok}bIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhNikbAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mMiubAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiLimbAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUKiEbAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wJkaIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
$hUikcAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kTiqbAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspSiybAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewRkbIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
IfwYkcIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvXkcIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgWiicAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Vk}cIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
]kcAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock\k%cAndreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk[iqcAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspZiycAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
*{*pbiydAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewakdIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv`kdIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg_iidAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires^kcAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
((wikeIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagchk_dAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pgkwdAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesfkdAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockekdAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockdk%dAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskciqdAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
mkeAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode locklk%eAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskkiqeAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspjiyeAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
{!MzrkeAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePqk7eAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcpk_eAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pokweAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesnkeAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
vkfAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockuk%fAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesktiqfAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspsiyfAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
{!Mz{kfAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePzk7fAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcyk_fAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pxkwfAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceswkfAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kgAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkgAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock~k%gAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk}iqgAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{|k
fAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
VUV{k
gAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkgAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7gAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_gAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwgAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
WG6Wck_hAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p
kwhAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services	khAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkhAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%hAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5kgAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
,qk{hAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5khAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
hAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z
khAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7hAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
{!MzkiAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7iAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_iAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwiAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskiAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
HnzkiAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023ck_iAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qk{iAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kiAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
iAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
VUV{k
jAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkjAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7jAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_jAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwjAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
Gm{v%ikAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesr$k}jAndreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z#kjAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c"k_jAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q!k{jAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5 kjAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
H)M+Hv-kkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg,iikAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3+k}kIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh*ikkAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m)iukAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi(imkAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU'iEkAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|&kkIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
M.R0Mv5klIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg4iilAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires33k}lIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh2iklAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m1iulAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi0imlAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU/iElAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057w.kkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
$9i/mTomas Korbar <tkorbar@redhat.com> - 1:1.6.3-43]L- 1687571 - cupsd doesn't clean tmp files if client conn is terminated abnormallyk8iqlAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp7iylAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew6klIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag

er+V:eDy
fa6421de2c15921a2e6fedbf4185a77ea6ccb46658a05d2002f389b7e2a8b60eDx
a9a856900d5a29d9cf94b7fdac8c07e41ad87194e1b959095cdaa6019f30d4c6Dw
4613273bfc2c11c9816fb2825af9aeec01ebd5785d69700793afafb364fdfa5bDv
7e50ed884e06e8b99632be1537d095f84b2961978088e061936f9dc699a523b1Du
ae5e89ffdb193ba77fff5f91338b3087497c816b899809d1d303e53d659e4ea3Dt
438a67adb5128df187df7f5745a6afe2d244d1571ecaf4159b03356b32a60436Ds
36577f1cf5cefd40798e73d112856b462b3290fa90abd70553c107f45542a070Dr
589706b3e3179980b4ac5c2328bf6ff3d88a995174ce4fa64d0ad480965e67c2Dq
7ac7d7acc2695d1247889b192c63a490c516efb9b8c1309543008402c549f1ebDp
73fc0c87cb3098d277406335ceeb029508b87e5d4f5c7d1cc89eeffaf0bc4009Do
3da43cb47b5ad18f1ce3f3b8c4d77981a8aeebe7eeafb778c043bdf4d7883d0eDn
50988ba783fc21f380b1867ef9c2f3753fc650d74ce1e24f4f3f94a5284b4dbfDm
34171e7570b3702011ad6135ba344acf87732fde15fa9714876fa317e1cfd747
NbNk?komZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-49^F- more covscan issues raised from the fix 1672212]>kSmZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-48^F- fixing covscan issue from 1672212=k?mZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-47^F- 1672212 - cupsd eats a lot of memory when lots of queue with extensive PPDs are created*<kkmZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-46^B@- 1715907 - CUPS- client: cupsGetPPD3() function tries to load PPD from IPP printer and not from the CUPS queue];kSmZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-45^;- fixing covscan issue from 1774460::kmZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-44^8@- 1774460 - CVE-2019-8696 cups: stack-buffer-overflow in libcups's asn1_get_packed function [rhel-7]
- 1774461 - CVE-2019-8675 cups: stack-buffer-overflow in libcups's asn1_get_type function [rhel-7]
- 1753809 - Settings in ~/.cups/client.conf aren't used
+uX+]EkSnZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-45^;- fixing covscan issue from 1774460:DknZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-44^8@- 1774460 - CVE-2019-8696 cups: stack-buffer-overflow in libcups's asn1_get_packed function [rhel-7]
- 1774461 - CVE-2019-8675 cups: stack-buffer-overflow in libcups's asn1_get_type function [rhel-7]
- 1753809 - Settings in ~/.cups/client.conf aren't usedCi/nTomas Korbar <tkorbar@redhat.com> - 1:1.6.3-43]L- 1687571 - cupsd doesn't clean tmp files if client conn is terminated abnormallyBe#mBryan Mason <bmason@redhat.com> - 1:1.6.3-52dh- CVE-2023-32360 cups: Information leak through Cups-Get-Document operationAk;mZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-51^- 1823758 - CVE-2017-18190 cups: DNS rebinding attacks via incorrect whitelist [rhel-7]@k%mZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-50^{G- 1813413 - [RHEL 7.7] segfault in cupsdSaveJob() caused by no space in /var
DRZaDLe#nBryan Mason <bmason@redhat.com> - 1:1.6.3-52dh- CVE-2023-32360 cups: Information leak through Cups-Get-Document operationKk;nZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-51^- 1823758 - CVE-2017-18190 cups: DNS rebinding attacks via incorrect whitelist [rhel-7]Jk%nZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-50^{G- 1813413 - [RHEL 7.7] segfault in cupsdSaveJob() caused by no space in /varkIkonZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-49^F- more covscan issues raised from the fix 1672212]HkSnZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-48^F- fixing covscan issue from 1672212Gk?nZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-47^F- 1672212 - cupsd eats a lot of memory when lots of queue with extensive PPDs are created*FkknZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-46^B@- 1715907 - CUPS- client: cupsGetPPD3() function tries to load PPD from IPP printer and not from the CUPS queue
-q3%-]RkSoZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-48^F- fixing covscan issue from 1672212Qk?oZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-47^F- 1672212 - cupsd eats a lot of memory when lots of queue with extensive PPDs are created*PkkoZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-46^B@- 1715907 - CUPS- client: cupsGetPPD3() function tries to load PPD from IPP printer and not from the CUPS queue]OkSoZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-45^;- fixing covscan issue from 1774460:NkoZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-44^8@- 1774460 - CVE-2019-8696 cups: stack-buffer-overflow in libcups's asn1_get_packed function [rhel-7]
- 1774461 - CVE-2019-8675 cups: stack-buffer-overflow in libcups's asn1_get_type function [rhel-7]
- 1753809 - Settings in ~/.cups/client.conf aren't usedMi/oTomas Korbar <tkorbar@redhat.com> - 1:1.6.3-43]L- 1687571 - cupsd doesn't clean tmp files if client conn is terminated abnormally
q[:XkpZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-44^8@- 1774460 - CVE-2019-8696 cups: stack-buffer-overflow in libcups's asn1_get_packed function [rhel-7]
- 1774461 - CVE-2019-8675 cups: stack-buffer-overflow in libcups's asn1_get_type function [rhel-7]
- 1753809 - Settings in ~/.cups/client.conf aren't usedWi/pTomas Korbar <tkorbar@redhat.com> - 1:1.6.3-43]L- 1687571 - cupsd doesn't clean tmp files if client conn is terminated abnormallyVe#oBryan Mason <bmason@redhat.com> - 1:1.6.3-52dh- CVE-2023-32360 cups: Information leak through Cups-Get-Document operationUk;oZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-51^- 1823758 - CVE-2017-18190 cups: DNS rebinding attacks via incorrect whitelist [rhel-7]Tk%oZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-50^{G- 1813413 - [RHEL 7.7] segfault in cupsdSaveJob() caused by no space in /varkSkooZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-49^F- more covscan issues raised from the fix 1672212
kZk_k;pZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-51^- 1823758 - CVE-2017-18190 cups: DNS rebinding attacks via incorrect whitelist [rhel-7]^k%pZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-50^{G- 1813413 - [RHEL 7.7] segfault in cupsdSaveJob() caused by no space in /vark]kopZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-49^F- more covscan issues raised from the fix 1672212]\kSpZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-48^F- fixing covscan issue from 1672212[k?pZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-47^F- 1672212 - cupsd eats a lot of memory when lots of queue with extensive PPDs are created*ZkkpZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-46^B@- 1715907 - CUPS- client: cupsGetPPD3() function tries to load PPD from IPP printer and not from the CUPS queue]YkSpZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-45^;- fixing covscan issue from 1774460
yL*dkkqZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-46^B@- 1715907 - CUPS- client: cupsGetPPD3() function tries to load PPD from IPP printer and not from the CUPS queue]ckSqZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-45^;- fixing covscan issue from 1774460:bkqZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-44^8@- 1774460 - CVE-2019-8696 cups: stack-buffer-overflow in libcups's asn1_get_packed function [rhel-7]
- 1774461 - CVE-2019-8675 cups: stack-buffer-overflow in libcups's asn1_get_type function [rhel-7]
- 1753809 - Settings in ~/.cups/client.conf aren't usedai/qTomas Korbar <tkorbar@redhat.com> - 1:1.6.3-43]L- 1687571 - cupsd doesn't clean tmp files if client conn is terminated abnormally`e#pBryan Mason <bmason@redhat.com> - 1:1.6.3-52dh- CVE-2023-32360 cups: Information leak through Cups-Get-Document operation
UhyUk_UrTim Waugh <twaugh@redhat.com> - 1.0.35-21Ub@- Fix heap-based buffer overflow in texttopdf filter (bug #1241242,
  CVE-2015-3258, CVE-2015-3279).je#qBryan Mason <bmason@redhat.com> - 1:1.6.3-52dh- CVE-2023-32360 cups: Information leak through Cups-Get-Document operationik;qZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-51^- 1823758 - CVE-2017-18190 cups: DNS rebinding attacks via incorrect whitelist [rhel-7]hk%qZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-50^{G- 1813413 - [RHEL 7.7] segfault in cupsdSaveJob() caused by no space in /varkgkoqZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-49^F- more covscan issues raised from the fix 1672212]fkSqZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-48^F- fixing covscan issue from 1672212ek?qZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-47^F- 1672212 - cupsd eats a lot of memory when lots of queue with extensive PPDs are created
YwwuY!ri[rZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-28^x- 1816109 - Queues are not cleaned up after stopping cups-browsed
- 1811190 - cups-browsed leaks memorytqirZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-27]@- 1775776 - Updated cups-browsed in RHEL 7.7 leaks socketsopiyrZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-26\@- 1508018 - man pages: wrong links in man cups-browsedoi1rZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-25\@- 1700333 - [abrt] [faf] cups-filters: raise(): /usr/sbin/cups-browsed killed by 6unirZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-24\@- fixing covscan issues, backported from upstream - 1485502mi!rZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-23\mA@- 1485502 - Rebase cups-browsed to latest version in upstream cups-filtersli#rZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-22X	@- 1427690 - /usr/lib/cups/filter/pstopdf: line 17: which: command not found
=VE=yi1sZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-25\@- 1700333 - [abrt] [faf] cups-filters: raise(): /usr/sbin/cups-browsed killed by 6uxisZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-24\@- fixing covscan issues, backported from upstream - 1485502wi!sZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-23\mA@- 1485502 - Rebase cups-browsed to latest version in upstream cups-filtersvi#sZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-22X	@- 1427690 - /usr/lib/cups/filter/pstopdf: line 17: which: command not foundu_UsTim Waugh <twaugh@redhat.com> - 1.0.35-21Ub@- Fix heap-based buffer overflow in texttopdf filter (bug #1241242,
  CVE-2015-3258, CVE-2015-3279).tiCrZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-29b@- 1894301 - cups-browsed segfaults when accessing freed master queue in print queue clusterqsi}rZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-28^y@- 1812635 - RHEL 7.7. cups-browsed segfaults on shutdown
?re?i#tZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-22X	@- 1427690 - /usr/lib/cups/filter/pstopdf: line 17: which: command not found_UtTim Waugh <twaugh@redhat.com> - 1.0.35-21Ub@- Fix heap-based buffer overflow in texttopdf filter (bug #1241242,
  CVE-2015-3258, CVE-2015-3279).~iCsZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-29b@- 1894301 - cups-browsed segfaults when accessing freed master queue in print queue clusterq}i}sZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-28^y@- 1812635 - RHEL 7.7. cups-browsed segfaults on shutdown!|i[sZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-28^x- 1816109 - Queues are not cleaned up after stopping cups-browsed
- 1811190 - cups-browsed leaks memoryt{isZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-27]@- 1775776 - Updated cups-browsed in RHEL 7.7 leaks socketsoziysZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-26\@- 1508018 - man pages: wrong links in man cups-browsed
nxpnqi}tZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-28^y@- 1812635 - RHEL 7.7. cups-browsed segfaults on shutdown!i[tZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-28^x- 1816109 - Queues are not cleaned up after stopping cups-browsed
- 1811190 - cups-browsed leaks memorytitZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-27]@- 1775776 - Updated cups-browsed in RHEL 7.7 leaks socketsoiytZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-26\@- 1508018 - man pages: wrong links in man cups-browsedi1tZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-25\@- 1700333 - [abrt] [faf] cups-filters: raise(): /usr/sbin/cups-browsed killed by 6uitZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-24\@- fixing covscan issues, backported from upstream - 1485502i!tZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-23\mA@- 1485502 - Rebase cups-browsed to latest version in upstream cups-filters
?gAA?oiyuZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-26\@- 1508018 - man pages: wrong links in man cups-browsed
i1uZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-25\@- 1700333 - [abrt] [faf] cups-filters: raise(): /usr/sbin/cups-browsed killed by 6uiuZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-24\@- fixing covscan issues, backported from upstream - 1485502i!uZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-23\mA@- 1485502 - Rebase cups-browsed to latest version in upstream cups-filters
i#uZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-22X	@- 1427690 - /usr/lib/cups/filter/pstopdf: line 17: which: command not found	_UuTim Waugh <twaugh@redhat.com> - 1.0.35-21Ub@- Fix heap-based buffer overflow in texttopdf filter (bug #1241242,
  CVE-2015-3258, CVE-2015-3279).iCtZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-29b@- 1894301 - cups-browsed segfaults when accessing freed master queue in print queue cluster
)p:)i!vZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-23\mA@- 1485502 - Rebase cups-browsed to latest version in upstream cups-filtersi#vZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-22X	@- 1427690 - /usr/lib/cups/filter/pstopdf: line 17: which: command not found_UvTim Waugh <twaugh@redhat.com> - 1.0.35-21Ub@- Fix heap-based buffer overflow in texttopdf filter (bug #1241242,
  CVE-2015-3258, CVE-2015-3279).iCuZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-29b@- 1894301 - cups-browsed segfaults when accessing freed master queue in print queue clusterqi}uZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-28^y@- 1812635 - RHEL 7.7. cups-browsed segfaults on shutdown!i[uZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-28^x- 1816109 - Queues are not cleaned up after stopping cups-browsed
- 1811190 - cups-browsed leaks memorytiuZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-27]@- 1775776 - Updated cups-browsed in RHEL 7.7 leaks sockets
]j]iCvZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-29b@- 1894301 - cups-browsed segfaults when accessing freed master queue in print queue clusterqi}vZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-28^y@- 1812635 - RHEL 7.7. cups-browsed segfaults on shutdown!i[vZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-28^x- 1816109 - Queues are not cleaned up after stopping cups-browsed
- 1811190 - cups-browsed leaks memorytivZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-27]@- 1775776 - Updated cups-browsed in RHEL 7.7 leaks socketsoiyvZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-26\@- 1508018 - man pages: wrong links in man cups-browsedi1vZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-25\@- 1700333 - [abrt] [faf] cups-filters: raise(): /usr/sbin/cups-browsed killed by 6uivZdenek Dohnal <zdohnal@redhat.com> - 1.0.35-24\@- fixing covscan issues, backported from upstream - 1485502
-q3%-]"kSwZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-48^F- fixing covscan issue from 1672212!k?wZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-47^F- 1672212 - cupsd eats a lot of memory when lots of queue with extensive PPDs are created* kkwZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-46^B@- 1715907 - CUPS- client: cupsGetPPD3() function tries to load PPD from IPP printer and not from the CUPS queue]kSwZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-45^;- fixing covscan issue from 1774460:kwZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-44^8@- 1774460 - CVE-2019-8696 cups: stack-buffer-overflow in libcups's asn1_get_packed function [rhel-7]
- 1774461 - CVE-2019-8675 cups: stack-buffer-overflow in libcups's asn1_get_type function [rhel-7]
- 1753809 - Settings in ~/.cups/client.conf aren't usedi/wTomas Korbar <tkorbar@redhat.com> - 1:1.6.3-43]L- 1687571 - cupsd doesn't clean tmp files if client conn is terminated abnormally
q[:(kxZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-44^8@- 1774460 - CVE-2019-8696 cups: stack-buffer-overflow in libcups's asn1_get_packed function [rhel-7]
- 1774461 - CVE-2019-8675 cups: stack-buffer-overflow in libcups's asn1_get_type function [rhel-7]
- 1753809 - Settings in ~/.cups/client.conf aren't used'i/xTomas Korbar <tkorbar@redhat.com> - 1:1.6.3-43]L- 1687571 - cupsd doesn't clean tmp files if client conn is terminated abnormally&e#wBryan Mason <bmason@redhat.com> - 1:1.6.3-52dh- CVE-2023-32360 cups: Information leak through Cups-Get-Document operation%k;wZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-51^- 1823758 - CVE-2017-18190 cups: DNS rebinding attacks via incorrect whitelist [rhel-7]$k%wZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-50^{G- 1813413 - [RHEL 7.7] segfault in cupsdSaveJob() caused by no space in /vark#kowZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-49^F- more covscan issues raised from the fix 1672212
kZk/k;xZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-51^- 1823758 - CVE-2017-18190 cups: DNS rebinding attacks via incorrect whitelist [rhel-7].k%xZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-50^{G- 1813413 - [RHEL 7.7] segfault in cupsdSaveJob() caused by no space in /vark-koxZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-49^F- more covscan issues raised from the fix 1672212],kSxZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-48^F- fixing covscan issue from 1672212+k?xZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-47^F- 1672212 - cupsd eats a lot of memory when lots of queue with extensive PPDs are created**kkxZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-46^B@- 1715907 - CUPS- client: cupsGetPPD3() function tries to load PPD from IPP printer and not from the CUPS queue])kSxZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-45^;- fixing covscan issue from 1774460of
flrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|',16;AIQUY]bimrv{%-59?ELRX_dkry±"ñ(ı/Ʊ4DZ;ɱAʱF˱ṈTͱ[α`ϱeбjѱoұtӱyԱ~ղֲײ
زٲڲ۲!ܲ&ݲ+޲0߲5:?DINSX]bglqv{
#(-28<AEJNTX^bhov|	
yL*4kkyZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-46^B@- 1715907 - CUPS- client: cupsGetPPD3() function tries to load PPD from IPP printer and not from the CUPS queue]3kSyZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-45^;- fixing covscan issue from 1774460:2kyZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-44^8@- 1774460 - CVE-2019-8696 cups: stack-buffer-overflow in libcups's asn1_get_packed function [rhel-7]
- 1774461 - CVE-2019-8675 cups: stack-buffer-overflow in libcups's asn1_get_type function [rhel-7]
- 1753809 - Settings in ~/.cups/client.conf aren't used1i/yTomas Korbar <tkorbar@redhat.com> - 1:1.6.3-43]L- 1687571 - cupsd doesn't clean tmp files if client conn is terminated abnormally0e#xBryan Mason <bmason@redhat.com> - 1:1.6.3-52dh- CVE-2023-32360 cups: Information leak through Cups-Get-Document operation
chyc;i/zTomas Korbar <tkorbar@redhat.com> - 1:1.6.3-43]L- 1687571 - cupsd doesn't clean tmp files if client conn is terminated abnormally:e#yBryan Mason <bmason@redhat.com> - 1:1.6.3-52dh- CVE-2023-32360 cups: Information leak through Cups-Get-Document operation9k;yZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-51^- 1823758 - CVE-2017-18190 cups: DNS rebinding attacks via incorrect whitelist [rhel-7]8k%yZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-50^{G- 1813413 - [RHEL 7.7] segfault in cupsdSaveJob() caused by no space in /vark7koyZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-49^F- more covscan issues raised from the fix 1672212]6kSyZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-48^F- fixing covscan issue from 16722125k?yZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-47^F- 1672212 - cupsd eats a lot of memory when lots of queue with extensive PPDs are created

er+V:eD
4a53adae3dd3a8d933f2ec113b7303ce7d9c782edd612d17b8d3badf4c04167eD
46ac94286722fc2f6f68ec4c0e70152b3d1ff6fac6001d2155f8228d91126574D
816c816facf8421458376b99f244ef91c147063ed4f4955fd0e8dae62eccaeb8D
c75dd0b94b1e1300b04edfbfa5a3739573a6f83dc0737110d2f8cfedfc5ab7a2D
da2b0ffc968803d239f38444842e6792e85494901ff8d0075652f6c2d7aa1800D
46f713cd31041330e2739c5a644e4f598536096f3e39d6c667a6d044eaa87893D
b2e43341cc469f66b5495139b62a419c0c671b19535efcdc79df055cc43686e5D
cf7edef3f54d6a2816515812d2f679ae21bbfb26767bf64e34b73d19a3bce3aeD~
8180d23815951b3c5be397846577728116502dad35bbc2dd67b7c4188244e465D}
5a07757ffcab76dc74eef1e1537c4ea823f723bae2c05ab1dd29679d95478db1D|
a979b1653b72f0551faf8fa54eed42be4d51511d962ed09d02ece63f2402d5f7D{
dfc95bdd8057839d4b45153318acb4e09f4da257afee1c57c07781870a68ecefDz
c9fd3024d128c4accf8a1b5a9b3207e10e714a336f6fe04b88a1d557e2bc7a24
NbNkAkozZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-49^F- more covscan issues raised from the fix 1672212]@kSzZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-48^F- fixing covscan issue from 1672212?k?zZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-47^F- 1672212 - cupsd eats a lot of memory when lots of queue with extensive PPDs are created*>kkzZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-46^B@- 1715907 - CUPS- client: cupsGetPPD3() function tries to load PPD from IPP printer and not from the CUPS queue]=kSzZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-45^;- fixing covscan issue from 1774460:<kzZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-44^8@- 1774460 - CVE-2019-8696 cups: stack-buffer-overflow in libcups's asn1_get_packed function [rhel-7]
- 1774461 - CVE-2019-8675 cups: stack-buffer-overflow in libcups's asn1_get_type function [rhel-7]
- 1753809 - Settings in ~/.cups/client.conf aren't used
AuXA	Fc1{Kamil Dudka <kdudka@redhat.com> - 7.29.0-52\y- prevent curl --rate-limit from hanging on file URLs (#1281969)
- fix NTLM password overflow via integer overflow (CVE-2018-14618)
- fix bad arithmetic when outputting warnings to stderr (CVE-2018-16842)
- backport options to force TLS 1.3 in curl and libcurl (#1672639)
- prevent curl --rate-limit from crashing on https URLs (#1683292)Ec+{Kamil Dudka <kdudka@redhat.com> - 7.29.0-51[j@- require a new enough version of nss-pem to avoid regression in yum (#1610998)De#zBryan Mason <bmason@redhat.com> - 1:1.6.3-52dh- CVE-2023-32360 cups: Information leak through Cups-Get-Document operationCk;zZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-51^- 1823758 - CVE-2017-18190 cups: DNS rebinding attacks via incorrect whitelist [rhel-7]Bk%zZdenek Dohnal <zdohnal@redhat.com> - 1:1.6.3-50^{G- 1813413 - [RHEL 7.7] segfault in cupsdSaveJob() caused by no space in /var
6)76vNs}{Kamil Dudka <kdudka@redhat.com> - 7.29.0-59.el7_9.1_ @- avoid overwriting a local file with -J (CVE-2020-8177)Mc'{Kamil Dudka <kdudka@redhat.com> - 7.29.0-59^?@- http: free protocol-specific struct in setup_connection callback (#1836773)Lc%{Kamil Dudka <kdudka@redhat.com> - 7.29.0-58^x- fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)hKcq{Kamil Dudka <kdudka@redhat.com> - 7.29.0-57]e@- allow curl to POST from a char device (#1769307)|Jc{Kamil Dudka <kdudka@redhat.com> - 7.29.0-56]?- fix auth failure with duplicated WWW-Authenticate header (#1754736)hIcq{Kamil Dudka <kdudka@redhat.com> - 7.29.0-55]Ik- fix TFTP receive buffer overflow (CVE-2019-5436)jHcu{Kamil Dudka <kdudka@redhat.com> - 7.29.0-54\- make `curl --tlsv1` backward compatible (#1672639)}Gc{Kamil Dudka <kdudka@redhat.com> - 7.29.0-53\@- backport the --tls-max option of curl and TLS 1.3 ciphers (#1672639)
1s1hTcq|Kamil Dudka <kdudka@redhat.com> - 7.29.0-57]e@- allow curl to POST from a char device (#1769307)|Sc|Kamil Dudka <kdudka@redhat.com> - 7.29.0-56]?- fix auth failure with duplicated WWW-Authenticate header (#1754736)hRcq|Kamil Dudka <kdudka@redhat.com> - 7.29.0-55]Ik- fix TFTP receive buffer overflow (CVE-2019-5436)jQcu|Kamil Dudka <kdudka@redhat.com> - 7.29.0-54\- make `curl --tlsv1` backward compatible (#1672639)}Pc|Kamil Dudka <kdudka@redhat.com> - 7.29.0-53\@- backport the --tls-max option of curl and TLS 1.3 ciphers (#1672639)	Oc1|Kamil Dudka <kdudka@redhat.com> - 7.29.0-52\y- prevent curl --rate-limit from hanging on file URLs (#1281969)
- fix NTLM password overflow via integer overflow (CVE-2018-14618)
- fix bad arithmetic when outputting warnings to stderr (CVE-2018-16842)
- backport options to force TLS 1.3 in curl and libcurl (#1672639)
- prevent curl --rate-limit from crashing on https URLs (#1683292)
yxjN[a?}Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dZci}Honza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jYio}Petr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)XwE|Jacek Migacz <jmigacz@redhat.com> - 7.29.0-59.el7_9.2eJ&- fix HTTP proxy deny use after free (CVE-2022-43552)
- rebuild certs with 2048-bit RSA keysvWs}|Kamil Dudka <kdudka@redhat.com> - 7.29.0-59.el7_9.1_ @- avoid overwriting a local file with -J (CVE-2020-8177)Vc'|Kamil Dudka <kdudka@redhat.com> - 7.29.0-59^?@- http: free protocol-specific struct in setup_connection callback (#1836773)Uc%|Kamil Dudka <kdudka@redhat.com> - 7.29.0-58^x- fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)
*s*n`c}}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)a_cc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q^_}Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)]c#}Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)\_)}Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_Nea?~Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24ddci~Honza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jcio~Petr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)db]o}Simo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842cacg}Jakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*njc}~Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)aicc~Jakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)qh_~Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)gc#~Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)f_)~Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_Noa?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dnciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jmioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)dl]o~Simo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842ckcg~Jakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*ntc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)asccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)qr_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)qc#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)p_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_Nya?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dxciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jwioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)dv]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842cucgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*n~c}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)a}ccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q|_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017){c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)z_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_Na?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)d]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842ccgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*nc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)accJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_N
a?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)d
]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842c	cgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*nc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)accJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_Na?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)d]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842ccgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*nc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)accJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_N!a?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24d ciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)d]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842ccgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*n&c}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)a%ccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q$_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)#c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)"_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_N+a?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24d*ciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013j)ioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)d(]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842c'cgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*n0c}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)a/ccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q._Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)-c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065),_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_N5a?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24d4ciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013j3ioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)d2]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842c1cgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*n:c}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)a9ccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q8_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)7c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)6_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_N?a?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24d>ciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013j=ioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)d<]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842c;cgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)

er+V:eD
d008be734234764be6a4c1b2f1c97cad53b746ecc9d1086444715833c6eb8450D
9fc8f4ae81c019b16a882823948eff561fe0f6ad38be509f514a5c287a60d121D
b1fa72dca82442418098746eaa9881ac7e92678c41e6786a458c28d77235fd5eD
4fc0e17577976ecf2487198134b9f2656bdc36caf8e27c75efb6aff14204088eD
925078e3fe326e7212b074bf495287d0fafc0395d9657b439a01b27d1539037eD
c960158be24b783ab7fb4a317899b83f806692c1e48426fe46c6bee909357ee5D

5a42bda7621305ca3bcd588a0c84aac743aba372ea8ee558945564b62173e3f3D
995c318e872c57fa7ce17355320c34d3fdd0774343e691cc23d9e9215ad53931D
94d6c80d9b08af719fa8a5e007bf753a3f13406d99bcd8411d914c6115c3b571D

c92bf980488dff6128c5564f2f75712ccb2a9a0f859f4667af435f967eef4c45D	
ffcf7016d990141a16d89aca74ebc89f797e93581bb8c97a08c83f5bf4ae47e4D
e1d065bfaef705d407c6134352d1afc64ecf26a5970a0e5282f6dda745483db8D
4579c7a7925097881dd33b28c72cce227a024a5f071fa4cd0c5bb09cd76d8ec0
*s*nDc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)aCccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)qB_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)Ac#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)@_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_NIa?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dHciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jGioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)dF]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842cEcgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*nNc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)aMccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)qL_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)Kc#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)J_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_NSa?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dRciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jQioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)dP]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842cOcgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*nXc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)aWccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)qV_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)Uc#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)T_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_N]a?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24d\ciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013j[ioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)dZ]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842cYcgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*nbc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)aaccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q`_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)_c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)^_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_Nga?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dfciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jeioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)dd]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842cccgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*nlc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)akccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)qj_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)ic#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)h_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_Nqa?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dpciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013joioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)dn]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842cmcgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*nvc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)auccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)qt_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)sc#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)r_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_N{a?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dzciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jyioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)dx]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842cwcgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*nc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)accJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q~_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)}c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)|_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_Na?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)d]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842ccgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*n
c}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)a	ccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_Na?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013j
ioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)d]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842ccgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*nc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)accJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_Na?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24dciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013jioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)d]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842ccgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*nc}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)accJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_N#a?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24d"ciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013j!ioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)d ]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842ccgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*n(c}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)a'ccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q&_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)%c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)$_)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
3_N-a?Daniel Mach <dmach@redhat.com> - 2.1.26-17RU- Mass rebuild 2014-01-24d,ciHonza Horak <hhorak@redhat.com> - 2.1.26-16Rx@- Rebuild for mariadb-libs
  Related: #1045013j+ioPetr Lautrbach <plautrba@redhat.com> 2.1.26-15R&- compile cyrus-sasl with -O3 on ppc64 (#1051063)d*]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842c)cgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
*s*n2c}Jakub Jelen <jjelen@redhat.com> - 2.1.26-22Yé- Allow cyrus sasl to get the ssf from gssapi (#1431586)a1ccJakub Jelen <jjelen@redhat.com> - 2.1.26-21XO@- support proper SASL GSS-SPNEGO (#1421663)q0_Jakub Jelen <jjelen@redhat.com> 2.1.26-20Va@- GSSAPI: Use per-connection mutex where possible (#1263017)/c#Jakub Jelen <jjelen@redhat.com> 2.1.26-19.2U- Revert tmpfiles.d and use new systemd feature RuntimeDirectory (#1188065)._)Jakub Jelen <jjelen@redhat.com> 2.1.26-18U\w@- Revert updated GSSAPI flags as in RFC 4752 to restore backward compatibility (#1154566)
- Add and document ability to run saslauth as non-root user (#1188065)
- Support AIX SASL GSSAPI (#1174322)
- Update client library to be thread safe (#1147659)
- Fix problem, that parsing short prefix matches the whole mechanism name (#1089267)
- Don't use unnecessary quotes around user description (#1082564)
- Fix confusing message when config file has typo (#1022479)
K3K	8[9Jeff Moyer <jmoyer@redhat.com> - 64.1-2\e- Fix initramfs creating by forcing installation of libnvdimm.ko
- Related: bz#1634348?7[%Jeff Moyer <jmoyer@redhat.com> - 64.1-1\@- Rebase to v64.1 (Jeff Moyer)
  - add security commands
  - fix broken udev rule for dirty shutdown count
- Resolves: bz#1634348 bz#1635441)6W}Jeff Moyer <jmoyer@redhat.com> - 62-1[~- Rebase to v62 (Jeff Moyer)
  - a new monitor command / daemon
  - an ndctl udev rule for recording the unsafe shutdown count
  - smart error injection
  - create-namespace fix for fragmented namespaces
- Resolves: bz#1610649 bz#1611833 bz#1456320h5[yJeff Moyer <jmoyer@redhat.com> - 60.3-4[^- Apply all patches (Jeff Moyer)
- Related: bz#1456320d4]oSimo Sorce <simo@redhat.com> - 2.1.26-24b8- Fix for CVE-2022-24407
- Resolves: rhbz#2055842c3cgJakub Jelen <jjelen@redhat.com> - 2.1.26-23Zf- Avoid undefined symbols on s390x (#1516193)
C^C<_9Jeff Moyer <jmoyer@redhat.com> - 65.4.el7]QT- Add spaces to the add_driver directive in the dracut module
- Resolves: rhbz#17403834;_Jeff Moyer <jmoyer@redhat.com> - 65.3.el7]Ik- modify nvdimm-security.conf touse '&&' instead of ';'
  Without this change, the module doesn't load
- Resolves: rhbz#1725405P:_CJeff Moyer <jmoyer@redhat.com> - 65.2.el7]>- Remove 'daxctl migrate-device-model' command.  We won't
  support hot-plugging device dax into the memory hierarchy
  on RHEL 7.
- Resolves: rhbz#17341539__Jeff Moyer <jmoyer@redhat.com> - 65.1.el7]9- Rebase to v65
  - clear-errors: new command to clear errors on a namespace
  - monitor: remove the requirement of a default config
  - sanitize-dimm: allow a zero-key for secure-erase
  - sanitize-dimm: preserve keys after an overwrite
  - load-keys: fix for non-TPM keys
- Fix test harness to run against the rhel7 test kernel modules
- Related: rhbz#1722481
c?A[%Jeff Moyer <jmoyer@redhat.com> - 64.1-1\@- Rebase to v64.1 (Jeff Moyer)
  - add security commands
  - fix broken udev rule for dirty shutdown count
- Resolves: bz#1634348 bz#1635441)@W}Jeff Moyer <jmoyer@redhat.com> - 62-1[~- Rebase to v62 (Jeff Moyer)
  - a new monitor command / daemon
  - an ndctl udev rule for recording the unsafe shutdown count
  - smart error injection
  - create-namespace fix for fragmented namespaces
- Resolves: bz#1610649 bz#1611833 bz#1456320h?[yJeff Moyer <jmoyer@redhat.com> - 60.3-4[^- Apply all patches (Jeff Moyer)
- Related: bz#1456320>_#Jeff Moyer <jmoyer@redhat.com> - 65.6.el7_ܙ- add space to install_items in dracut config file
- Resolves: rhbz#1909233~=_Jeff Moyer <jmoyer@redhat.com> - 65.5.el7]w@- Once again attempt to fix nvdimm-security.conf
- Resolves: rhbz#1750199

er+V:eD 
917535cc1bccdcfa4383143cc52d13f8fd161a5ec8f1037f606123737f818acfD
39c70285432c56fe5dd79f0d155069d48956d10fcdcac838a4590c4a44b0b521D
88e796afa3934d3cefb09a6a575714bdc8aede8ee6a3c6b7be0bb59a130d5efdD
cab18530e297449d292d630ec6e205013f25a4889616836298778283e58c4646D
e5b4fe58bfeb115113e7edd7fb472941f60801137b90d42e57b06b22865ac47dD
a18e979a837324a9730fc3e5b08e4f228f22d46c20c0a6445f7147444b8449c3D
2ed2fcd8e79d8a62a374c054083792b657cb4d4668e39188deeb1ad3d72c948fD
d7480f6ca0e1f89838274cae938826c82a1a691a1f3fa5dc9b3eda6662d64f7bD
dd427ef9920f27966d5b507f154c88d80a03bc944b494a89f98eae387f25e950D
b063de6c9fdc361af76d98bb3d3b31fd5ee05e120f1dc64f9ddfe77217c012c6D
3f1d1aaf2ad1912b72db538da9e7a824ec1beb3f7eceb8da6ab8b296c810b913D
8c8d68b411cf4b1553f6d61ec9e5e792aab640f1b6ce5645df2f4da01896ad23D
8e01728503e8663cde52ff2eb87bcbcd9a04b60fa17e1729dc2658f1cce309dc
EsE4E_Jeff Moyer <jmoyer@redhat.com> - 65.3.el7]Ik- modify nvdimm-security.conf touse '&&' instead of ';'
  Without this change, the module doesn't load
- Resolves: rhbz#1725405PD_CJeff Moyer <jmoyer@redhat.com> - 65.2.el7]>- Remove 'daxctl migrate-device-model' command.  We won't
  support hot-plugging device dax into the memory hierarchy
  on RHEL 7.
- Resolves: rhbz#1734153C__Jeff Moyer <jmoyer@redhat.com> - 65.1.el7]9- Rebase to v65
  - clear-errors: new command to clear errors on a namespace
  - monitor: remove the requirement of a default config
  - sanitize-dimm: allow a zero-key for secure-erase
  - sanitize-dimm: preserve keys after an overwrite
  - load-keys: fix for non-TPM keys
- Fix test harness to run against the rhel7 test kernel modules
- Related: rhbz#1722481	B[9Jeff Moyer <jmoyer@redhat.com> - 64.1-2\e- Fix initramfs creating by forcing installation of libnvdimm.ko
- Related: bz#1634348
ql)JW}Jeff Moyer <jmoyer@redhat.com> - 62-1[~- Rebase to v62 (Jeff Moyer)
  - a new monitor command / daemon
  - an ndctl udev rule for recording the unsafe shutdown count
  - smart error injection
  - create-namespace fix for fragmented namespaces
- Resolves: bz#1610649 bz#1611833 bz#1456320hI[yJeff Moyer <jmoyer@redhat.com> - 60.3-4[^- Apply all patches (Jeff Moyer)
- Related: bz#1456320H_#Jeff Moyer <jmoyer@redhat.com> - 65.6.el7_ܙ- add space to install_items in dracut config file
- Resolves: rhbz#1909233~G_Jeff Moyer <jmoyer@redhat.com> - 65.5.el7]w@- Once again attempt to fix nvdimm-security.conf
- Resolves: rhbz#1750199F_9Jeff Moyer <jmoyer@redhat.com> - 65.4.el7]QT- Add spaces to the add_driver directive in the dracut module
- Resolves: rhbz#1740383
:=:PN_CJeff Moyer <jmoyer@redhat.com> - 65.2.el7]>- Remove 'daxctl migrate-device-model' command.  We won't
  support hot-plugging device dax into the memory hierarchy
  on RHEL 7.
- Resolves: rhbz#1734153M__Jeff Moyer <jmoyer@redhat.com> - 65.1.el7]9- Rebase to v65
  - clear-errors: new command to clear errors on a namespace
  - monitor: remove the requirement of a default config
  - sanitize-dimm: allow a zero-key for secure-erase
  - sanitize-dimm: preserve keys after an overwrite
  - load-keys: fix for non-TPM keys
- Fix test harness to run against the rhel7 test kernel modules
- Related: rhbz#1722481	L[9Jeff Moyer <jmoyer@redhat.com> - 64.1-2\e- Fix initramfs creating by forcing installation of libnvdimm.ko
- Related: bz#1634348?K[%Jeff Moyer <jmoyer@redhat.com> - 64.1-1\@- Rebase to v64.1 (Jeff Moyer)
  - add security commands
  - fix broken udev rule for dirty shutdown count
- Resolves: bz#1634348 bz#1635441
H8I)TW}Jeff Moyer <jmoyer@redhat.com> - 62-1[~- Rebase to v62 (Jeff Moyer)
  - a new monitor command / daemon
  - an ndctl udev rule for recording the unsafe shutdown count
  - smart error injection
  - create-namespace fix for fragmented namespaces
- Resolves: bz#1610649 bz#1611833 bz#1456320hS[yJeff Moyer <jmoyer@redhat.com> - 60.3-4[^- Apply all patches (Jeff Moyer)
- Related: bz#1456320R_#Jeff Moyer <jmoyer@redhat.com> - 65.6.el7_ܙ- add space to install_items in dracut config file
- Resolves: rhbz#1909233~Q_Jeff Moyer <jmoyer@redhat.com> - 65.5.el7]w@- Once again attempt to fix nvdimm-security.conf
- Resolves: rhbz#1750199P_9Jeff Moyer <jmoyer@redhat.com> - 65.4.el7]QT- Add spaces to the add_driver directive in the dracut module
- Resolves: rhbz#17403834O_Jeff Moyer <jmoyer@redhat.com> - 65.3.el7]Ik- modify nvdimm-security.conf touse '&&' instead of ';'
  Without this change, the module doesn't load
- Resolves: rhbz#1725405
:=:PX_CJeff Moyer <jmoyer@redhat.com> - 65.2.el7]>- Remove 'daxctl migrate-device-model' command.  We won't
  support hot-plugging device dax into the memory hierarchy
  on RHEL 7.
- Resolves: rhbz#1734153W__Jeff Moyer <jmoyer@redhat.com> - 65.1.el7]9- Rebase to v65
  - clear-errors: new command to clear errors on a namespace
  - monitor: remove the requirement of a default config
  - sanitize-dimm: allow a zero-key for secure-erase
  - sanitize-dimm: preserve keys after an overwrite
  - load-keys: fix for non-TPM keys
- Fix test harness to run against the rhel7 test kernel modules
- Related: rhbz#1722481	V[9Jeff Moyer <jmoyer@redhat.com> - 64.1-2\e- Fix initramfs creating by forcing installation of libnvdimm.ko
- Related: bz#1634348?U[%Jeff Moyer <jmoyer@redhat.com> - 64.1-1\@- Rebase to v64.1 (Jeff Moyer)
  - add security commands
  - fix broken udev rule for dirty shutdown count
- Resolves: bz#1634348 bz#1635441
H8I)^W}Jeff Moyer <jmoyer@redhat.com> - 62-1[~- Rebase to v62 (Jeff Moyer)
  - a new monitor command / daemon
  - an ndctl udev rule for recording the unsafe shutdown count
  - smart error injection
  - create-namespace fix for fragmented namespaces
- Resolves: bz#1610649 bz#1611833 bz#1456320h][yJeff Moyer <jmoyer@redhat.com> - 60.3-4[^- Apply all patches (Jeff Moyer)
- Related: bz#1456320\_#Jeff Moyer <jmoyer@redhat.com> - 65.6.el7_ܙ- add space to install_items in dracut config file
- Resolves: rhbz#1909233~[_Jeff Moyer <jmoyer@redhat.com> - 65.5.el7]w@- Once again attempt to fix nvdimm-security.conf
- Resolves: rhbz#1750199Z_9Jeff Moyer <jmoyer@redhat.com> - 65.4.el7]QT- Add spaces to the add_driver directive in the dracut module
- Resolves: rhbz#17403834Y_Jeff Moyer <jmoyer@redhat.com> - 65.3.el7]Ik- modify nvdimm-security.conf touse '&&' instead of ';'
  Without this change, the module doesn't load
- Resolves: rhbz#1725405
:=:Pb_CJeff Moyer <jmoyer@redhat.com> - 65.2.el7]>- Remove 'daxctl migrate-device-model' command.  We won't
  support hot-plugging device dax into the memory hierarchy
  on RHEL 7.
- Resolves: rhbz#1734153a__Jeff Moyer <jmoyer@redhat.com> - 65.1.el7]9- Rebase to v65
  - clear-errors: new command to clear errors on a namespace
  - monitor: remove the requirement of a default config
  - sanitize-dimm: allow a zero-key for secure-erase
  - sanitize-dimm: preserve keys after an overwrite
  - load-keys: fix for non-TPM keys
- Fix test harness to run against the rhel7 test kernel modules
- Related: rhbz#1722481	`[9Jeff Moyer <jmoyer@redhat.com> - 64.1-2\e- Fix initramfs creating by forcing installation of libnvdimm.ko
- Related: bz#1634348?_[%Jeff Moyer <jmoyer@redhat.com> - 64.1-1\@- Rebase to v64.1 (Jeff Moyer)
  - add security commands
  - fix broken udev rule for dirty shutdown count
- Resolves: bz#1634348 bz#1635441
'H8'h{David Kaspar [Dee'Kej] <dkaspar@redhat.com> - 9.49.46-1[@- ifup-post: fix incorrect condition for RESOLV_MODS (bug #1610411)g{David Kaspar [Dee'Kej] <dkaspar@redhat.com> - 9.49.45-1[W- network: parsing of /proc/mounts returned (bug #1572659)
- netconsole: LSB header added (bug #1508489)
- ifdown-eth: no longer needed 'pidof -x dhclient' condition removed (bug #1559384)f_#Jeff Moyer <jmoyer@redhat.com> - 65.6.el7_ܙ- add space to install_items in dracut config file
- Resolves: rhbz#1909233~e_Jeff Moyer <jmoyer@redhat.com> - 65.5.el7]w@- Once again attempt to fix nvdimm-security.conf
- Resolves: rhbz#1750199d_9Jeff Moyer <jmoyer@redhat.com> - 65.4.el7]QT- Add spaces to the add_driver directive in the dracut module
- Resolves: rhbz#17403834c_Jeff Moyer <jmoyer@redhat.com> - 65.3.el7]Ik- modify nvdimm-security.conf touse '&&' instead of ';'
  Without this change, the module doesn't load
- Resolves: rhbz#1725405
+&+coaiJan Macku <jamacku@redhat.com> - 9.49.53-1^Ǿ- rwtab: Add support for chrony (bug #1838260)naCJan Macku <jamacku@redhat.con> - 9.49.52-1^x- ifup-eth: Switch to bc utility, which supports floating point computations (bug #1609687)ZmaWJan Macku <jamacku@redhat.com> - 9.49.51-1^r
@- Fix inline comment - (bug #1773798)laCJan Macku <jamacku@redhat.com> - 9.49.50-1^h- Wait for scope link addresses as well as for scope global addresses - ipv6 (bug #1773798)ka]Jan Macku <jamacku@redhat.com> - 9.49.49-1]Z@- ifup-eth: Check that device name is set (bug #1741830)
- Add option for IPv6 GRE tunnel (bug #1691552)ajacJan Macku <jamacku@redhat.com> - 9.49.48-1]Ik- network: don't fail with IFDOWN_ON_SHUTDOWN (bug #1693977)
- Configure autorelabel service to output to journal and to console if set (bug #1634661)
- Fix changelog typo^ia_Jan Macku <jamacku@redhat.com> - 9.49.47-1\- Fix file permissions for /var/log/dmesg
}	|}cvsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.us9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	ts!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.ssIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rrsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.mqYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.npqoJan Macku <jamacku@redhat.com> - 9.49.53-1.el7_9.1_- rwtab: Allow updating mlocate.db (bug #1880095)
nrn|sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r{suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
zMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QyMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.xMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
ws#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.
st[QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.~s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	}s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.
@rZ4@
	s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.
dudmYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.CMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.t
gMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
E]^EMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
+-	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.mYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
gs
"Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools. Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
E]^E)Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
(s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c'sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.&s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	%s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.$sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r#suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
+&	/s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1..sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r-suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.t,gMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
+Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q*Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
gs
5Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q4Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.3Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
2s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c1sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.0s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
C[\C<Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
;s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c:sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.9s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	8s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.7sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.t6gMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
1+&_1	Bs!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.AsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.C@Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.t?gMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
>Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q=Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.

er+V:eD-
12fb546150a8175c1aa95419a75e512972cb4c6c8eea1ade84e3319b1cfadaeaD,
c8f7c98bcb2f070e4421790cc39453b0046912b5c8325ad6660342177869da6eD+
e3048df9af89b5496455f0ad788ff0b492712c8c06683cf6f908894638139c9fD*
a7f93d258bd14e3d81be8c58b2998d78081d84b5f8f763c1bff64b3571ca321eD)
dabd6fc3fcccc9d794b28168afdd8fb94f2d78fda10a5751459cee469f8412d4D(
0986dce8e3a59471cabc7ed457e23c3f0fdc81e3cbab4093eaa0426e2d5d26efD'
3feced91f7391352cfca0debae0c2aa43febbeee7d24929c75cd8d1d5a6b782eD&
06a5cb180f3ca29cdae7dd9547b29c30079ef85e1809389608777308ad5e4c3aD%
9e77aa7192e0e6ca06b1a23c5e174410e0034b59dedc6cc1edf7458486f920edD$
23c887a392429ec463dea994475481a04b8745d5f29926c149d6f3f48c5ebde0D#
96abc02747879aa68bd335dadad5f1e2d5ea64c519db929820194757e80af933D"
4c4e8afba69331a45497c224ebaa7b237c5e25c3fa2dba00bb45fa49fc41aed8D!
af5e8ccb9d54f4f9b71774537a4c1e69aad8ae1b83815d24f5930bb72e20d0f8
gs
HMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QGMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.FMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
Es#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cDsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.Cs9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
R<Os9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	Ns!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.MsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rLsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.mKYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.CJMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.tIgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
rUsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
TMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QSMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.RMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
Qs#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cPsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.
_9E[Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
Zs#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cYsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.Xs9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	Ws!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.VsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.
_+&_as9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	`s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1._sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.t^gMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
]Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q\Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
tggMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
fMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QeMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.dMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
cs#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cbsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.
'9T&'cnsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.ms9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	ls!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.ksIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rjsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.miYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.ChMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.
rrtsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.msYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.
rMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QqMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.pMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
os#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.
_9EzMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
ys#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cxsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.ws9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	vs!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.usIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.
a+(as9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.~sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r}suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
|Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q{Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
22rsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.
_9E
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.
s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.		s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.
_+&_s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.
~9r~
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.CMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.
dudm%YMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.C$Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.t#gMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
"Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools. Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
E]^E,Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
+s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c*sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.)s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	(s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.'sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r&suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
+-	2s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.1sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r0suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.m/YMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.
.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q-Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
gs
8Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q7Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.6Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
5s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c4sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.3s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
E]^E?Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
>s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c=sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.<s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	;s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.:sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r9suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
+&	Es!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.DsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rCsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.tBgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
AMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q@Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.

er+V:eD:
3c12cdb5717ff04a0dcf949d40ddef5d878342fe63c8cf26ece6f2f0f56c9075D9
1594da41bb4b69a611ac9e605dec625b69dd2f867a53943a544a8babfb76594cD8
0cfe90113fcfe21d6f21f6022481283b9b35ca916c02484fc39e89b88fcffa8aD7
43561875a5de2607f06bea160d4eb38c49eb95d2de1193d32c75d69bbef928deD6
a3db401db86968bf26b166686f43ca87a750990d0b9e46fad7c8f63e89052035D5
a12a8a2185579f6577042b3b9876e89a3c3c99ff67c168c0388c79d64d4d9854D4
40ebdc19d1f43fa0892059019bcdba4bd97351c6d146ef74e530e00dc4732c4cD3
85c0d75554f340d99942609a8488c0ad5b2e4ddc0e40c1192056ab8ab8395492D2
1cb65029ad75fd77a7975a1a11ecf00d33c40ae006a565c6b49188cb7f9eb6ccD1
c5ef38f748c2f2a1c21e14d6274fec8b3391722d8c6c93cdd5f977075f798d88D0
6cbada440eaf05d5c86416fab118a0ab641f93992a6a4070b19938894fcb8bbbD/
01a6f6a9a36d8203819ae336a672955e40e9b1c9cf387d5ccd0942ebea8c147aD.
68e1429d8531b268902804fdf15f6eb8ffcadc2d36315c6090a3edb14eb2ab13
gs
KMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QJMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.IMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
Hs#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cGsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.Fs9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
C[\CRMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
Qs#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cPsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.Os9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	Ns!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.MsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.tLgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
1+&_1	Xs!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.WsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.CVMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.tUgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
TMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QSMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
gs
^Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q]Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.\Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
[s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cZsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.Ys9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
R<es9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	ds!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.csIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rbsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.maYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.C`Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.t_gMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
99rlsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.mkYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.
jMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QiMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.hMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
gs#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cfsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.
_9ErMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
qs#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cpsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.os9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	ns!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.msIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.
a+(axs9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	ws!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.vsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rusuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
tMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QsMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
22rsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.t~gMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
}Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q|Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.{Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
zs#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cysWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.
_9EMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.
_+&_s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	
s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.	sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.

s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.
~9r~
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.CMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.
uCMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
Cq'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556qABenjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651qKBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-125\d- Modify 0250-RHBZ-1610867-rescan-change.patch
  * Fix memory Leak
- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix NULL dereference
- Refresh 0252-RHBZ-1623595-cmd-error-status.patch
- Resolves: bz #1610867, #1638651
MM/ qoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506of~flrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|
")/5<BHOU[agntz 
!"#$%%,&2'8(?)E+K,R-X.^/e0l1r2x3456789: <#='>(?)@,A0B1C2D5E:F=G>HAIEKGLHMKNOOPPQQTRYSZT[U^VbWcXdYgZl[m\n]q^v_y`za}bcdefgh
ijklmnop q#r(s)t*u-v2w5x6y9z={>|?}B
Q0#qqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066"q}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q!qsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
$,@$'qABenjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651}&qBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h%qaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P$q1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
qq(q'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
MM/)qoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0,qqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066+q}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q*qsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
&,@&0q=Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}/qBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h.qaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P-q1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
qq1q'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
MM/2qoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q05qqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #171450664q}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q3qsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
,@&:qBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-136cG- Add 0274-UP-no-duplicate-command-keys.patch
- Resolves: bz #21349059q=Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}8qBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h7qaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P6q1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
C=q'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556<qABenjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651;qKBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-125\d- Modify 0250-RHBZ-1610867-rescan-change.patch
  * Fix memory Leak
- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix NULL dereference
- Refresh 0252-RHBZ-1623595-cmd-error-status.patch
- Resolves: bz #1610867, #1638651
MM/>qoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0AqqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066@q}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q?qsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
,@EqKBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-125\d- Modify 0250-RHBZ-1610867-rescan-change.patch
  * Fix memory Leak
- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix NULL dereference
- Refresh 0252-RHBZ-1623595-cmd-error-status.patch
- Resolves: bz #1610867, #1638651}DqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hCqaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197PBq1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420

er+V:eDG
3d901cc9a4697e9c08105de93d1a190650a8439e1dabe11a97d17c67cd1d951cDF
09d536dbeed2bb97193afabb9564cc6e6def3636f719ed0e3bbb8c0e575f7033DE
c1769c3e3380140052696701ca6809cb191ea6c245caf1c658a1b8bc580f13baDD
393b6f38ca21b31f198eb40d2fbdecb79a43ca0306ac436c4ebcc4fc8a15043aDC
61772a9e48d677eb7feb9225da4fdbfa417f99764a26adf0ba4e311baad2696cDB
ec4cb2d5a569d854ac525bd458045223e598500765770d860e5bf0b84a41767bDA
fe463cbf93e98cd763c89bf55103a9c84e8d48e998eb06542fe3e3fb72a10dd9D@
34ff7de8a4ca78de046e416a969184543fb961e44c8500ad933f5d0d9d71bdb4D?
1333d18f0d5f36acf0badba03a7250ddf92df7f789f4674ece2dfcfcd925f3b3D>
8bf0a6fa452bb777d2800beaf0ba2e84f3dd1b17964e1b1bb26b099bcd5ba413D=
49c502046e8fd1833a810286c8db37a87f18dc47667827f45a56267aefdac60fD<
973cf0ccc163c9374db09502b1e69f3323abc0960eca2ad66bfae874ac23d131D;
4800c473b78c5271f956b53fa3f8a3f696c8b2709fa3afd5457178a5946300eb
dGq'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556FqABenjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651
MM/HqoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0KqqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066Jq}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qIqsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
$,@$OqABenjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651}NqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hMqaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197PLq1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
qqPq'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
MM/QqoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0TqqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066Sq}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qRqsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
,@&YqABenjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651Xq=Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}WqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hVqaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197PUq1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
qqZq'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
MM/[qoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0^qqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066]q}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q\qsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
&,@&bq=Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}aqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h`qaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P_q1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
qqcq'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
MM/dqoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0gqqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066fq}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qeqsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
,@&lqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-136cG- Add 0274-UP-no-duplicate-command-keys.patch
- Resolves: bz #2134905kq=Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}jqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hiqaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197Phq1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
qqmq'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
MM/nqoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0qqqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066pq}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qoqsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
,@&vqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-136cG- Add 0274-UP-no-duplicate-command-keys.patch
- Resolves: bz #2134905uq=Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}tqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hsqaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197Prq1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
Cyq'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556xqABenjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651wqKBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-125\d- Modify 0250-RHBZ-1610867-rescan-change.patch
  * Fix memory Leak
- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix NULL dereference
- Refresh 0252-RHBZ-1623595-cmd-error-status.patch
- Resolves: bz #1610867, #1638651
MM/zqoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0}qqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066|q}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q{qsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
,@qKBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-125\d- Modify 0250-RHBZ-1610867-rescan-change.patch
  * Fix memory Leak
- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix NULL dereference
- Refresh 0252-RHBZ-1623595-cmd-error-status.patch
- Resolves: bz #1610867, #1638651}qBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hqaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P~q1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
dq'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556qABenjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651
MM/qoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0qqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066q}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qqsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
$,@$qABenjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651}
qBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h	qaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197Pq1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
qqq'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
MM/
qoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0qqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066q}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qqsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
,@&qABenjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651q=Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}qBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hqaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197Pq1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
qqq'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
MM/qoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0qqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066q}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qqsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
&,@&q=Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}qBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hqaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197Pq1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
qqq'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
MM/ qoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0#qqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066"q}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q!qsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
,@&(qBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-136cG- Add 0274-UP-no-duplicate-command-keys.patch
- Resolves: bz #2134905'q=Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}&qBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h%qaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P$q1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
qq)q'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
MM/*qoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0-qqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066,q}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q+qsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
,@&2qBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-136cG- Add 0274-UP-no-duplicate-command-keys.patch
- Resolves: bz #21349051q=Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}0qBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h/qaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P.q1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
C5q'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #16795564qABenjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #16386513qKBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-125\d- Modify 0250-RHBZ-1610867-rescan-change.patch
  * Fix memory Leak
- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix NULL dereference
- Refresh 0252-RHBZ-1623595-cmd-error-status.patch
- Resolves: bz #1610867, #1638651
MM/6qoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q09qqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #171450668q}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q7qsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
$,@$=qABenjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651}<qBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h;qaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P:q1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
qq>q'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
MM/?qoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0BqqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066Aq}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q@qsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
&,@&Fq=Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}EqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hDqaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197PCq1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420

er+V:eDT
7f4ef7b8732bcac3d9fd39fa13b53c8401e618cc64cf7e86b46a6a0bf9f5ae93DS
211c26bfbf530d58f28b3bff1ac40338e642a96b7252fd6857fcb26e533c5790DR
bfebf9b332bfdd37851d0e28304a7388d0da7c5c2ba905903d1294494041b80bDQ
30c56f4f794204c049aed74f749c3b0b0739f232b66c48497f125252af988405DP
b1b8c61d7f414e0bff5b987279a268865b3400e4618cc614c0e2852dd52aef50DO
31e1c574e3fa3fef3b015e2b2e1d685b860a8b96e7151d331b9ef708986965c3DN
33747e3cee335e0df270058b70d2ce33f91cadb372c26e1a24641083294b45b2DM
a288bfc4e0cabe06d845847deb1b0bbdf10a01f9707476ebbf61f3bc2e99e2a0DL
2d5e71a837c196e47d9d4ea6dfd48be8ec78faaf662f54465992a8340399b0ccDK
35b3f04497e7cd33947d10c42841c8a302879e0665aff842a760e318a83d90aaDJ
33fa2846ccf25385f17ff97c1999aeae26f83868dcd26164e5524c4255cb1ce1DI
31cb8b4500b30fc437c8e439643e9d1afd49b8c687a8be5c9b39c44c31f51d44DH
fce2a6c0ec49c42d5100944108bbb85b8a3e2685de9b583b1b4627e6f66b330e
qqGq'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
MM/HqoBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506
Q0KqqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066Jq}Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qIqsBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
,@&PqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-136cG- Add 0274-UP-no-duplicate-command-keys.patch
- Resolves: bz #2134905Oq=Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}NqBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hMqaBenjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197PLq1Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
")Si"[XiQMarian Csontos <mcsontos@redhat.com> - 0.8.5-3^- Check input file exists earlier.yWiMarian Csontos <mcsontos@redhat.com> - 0.8.5-2]@- Remove obsolete pool-inactive option from thin_trim man page.jVioMarian Csontos <mcsontos@redhat.com> - 0.8.5-1\F@- Additional fixes for thin_dump and thin_repair.jUioMarian Csontos <mcsontos@redhat.com> - 0.8.2-1\@- Fix tools requiring additional --repair option.zTi
Marian Csontos <mcsontos@redhat.com> - 0.8.1-1\~- Update to latest upstream release including various bug fixes.nSiwMarian Csontos <mcsontos@redhat.com> - 0.7.3-3Z
- Fix version 2 metadata corruption in cache_restore.bRi_Marian Csontos <mcsontos@redhat.com> - 0.7.3-2Yܶ@- Rebuilding with updated source tarball.SQi?Marian Csontos <mcsontos@redhat.com> - 0.7.3-1Yp@- Update to latest bugfix and documentation update release.
- *_restore tools wipe superblock as a last resort.
- Add thin_check --override-mapping-root.
)v)`kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objectsk_koPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{^k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)u]kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclib\kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebase[kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-75\}@- Resolves: #1672308 - Do not restart dhcp on NetworkManagers up eventsXZy;Marian Csontos <mcsontos@redhat.com> - 0.8.5-3.el7_9.2_h- Rebuild for Z stream.YyMarian Csontos <mcsontos@redhat.com> - 0.8.5-3.el7_9.1_a@- Underpopulated nodes are considered non fatal error by thin_check.
-w{khkoPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{gk
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)ufkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclibekPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebase\d}?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.1`@- Roll in CentOS BrandingTco=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217Rbk=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696{ak
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless mode
m|RwmpkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebaseokPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-75\}@- Resolves: #1672308 - Do not restart dhcp on NetworkManagers up events\n}?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.2ff- Roll in CentOS BrandingymiStepan Broz <sbroz@redhat.com> - 12:4.2.5-83.2fM@- Rebuild because of bind ABI changes related to CVE-2023-50387Tlo=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217Rkk=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696{jk
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless modeikPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objects

E\x}?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.1`@- Roll in CentOS BrandingTwo=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217Rvk=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696{uk
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless modetkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objectskskoPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{rk
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)uqkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclib
j|jTo=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217Rk=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696{~k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless mode}kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objectsk|koPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{{k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)uzkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclibykPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebase
3%%3kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objectskkoPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)ukPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclibkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebasekPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-75\}@- Resolves: #1672308 - Do not restart dhcp on NetworkManagers up events\}?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.2ff- Roll in CentOS BrandingyiStepan Broz <sbroz@redhat.com> - 12:4.2.5-83.2fM@- Rebuild because of bind ABI changes related to CVE-2023-50387
-w{kkoPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)ukPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclib
kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebase\}?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.1`@- Roll in CentOS BrandingTo=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217R
k=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696{	k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless mode
m|RwmkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebasekPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-75\}@- Resolves: #1672308 - Do not restart dhcp on NetworkManagers up events\}?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.2ff- Roll in CentOS BrandingyiStepan Broz <sbroz@redhat.com> - 12:4.2.5-83.2fM@- Rebuild because of bind ABI changes related to CVE-2023-50387To=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217Rk=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696{k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless modekPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objects

E\ }?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.1`@- Roll in CentOS BrandingTo=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217Rk=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696{k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless modekPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objectskkoPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)ukPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclib
;z~;R(k=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696{'k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless mode&kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objectsk%koPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{$k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)u#kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclib"kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebase!kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-75\}@- Resolves: #1672308 - Do not restart dhcp on NetworkManagers up events
`JNb`{0k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless mode/kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objectsk.koPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{-k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)u,kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclib+kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebase\*}?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.1`@- Roll in CentOS BrandingT)o=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217
Ty}k8koPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{7k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)u6kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclib5kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebase\4}?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.2ff- Roll in CentOS Brandingy3iStepan Broz <sbroz@redhat.com> - 12:4.2.5-83.2fM@- Rebuild because of bind ABI changes related to CVE-2023-50387T2o=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217R1k=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696
m|Rwm@kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebase?kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-75\}@- Resolves: #1672308 - Do not restart dhcp on NetworkManagers up events\>}?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.2ff- Roll in CentOS Brandingy=iStepan Broz <sbroz@redhat.com> - 12:4.2.5-83.2fM@- Rebuild because of bind ABI changes related to CVE-2023-50387T<o=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217R;k=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696{:k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless mode9kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objects

E\H}?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.1`@- Roll in CentOS BrandingTGo=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217RFk=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696{Ek
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless modeDkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objectskCkoPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{Bk
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)uAkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclib

er+V:eDa
419a628252f2a83438fabbadf25cbc862ef23160a9a3d32fa110f61a1f1f3930D`
3989ac4ab63df7b51e1ce010e2b0d2368a33f915f06ae6b659dd6861d3dc3721D_
49a6803a256d5206d45f93d9583e7333cd4961a731881b7a82c761bb7ea7c9abD^
912ce11b5c1438a25af1e1961d891e6421717a57685de5add6d528d3ff3bdf42D]
1e0e7cf67ede91280fd5a1d1a63490ea597c590a44d12ba3e9d2c08a05b703c1D\
a9ba907298e679306020035cb1d25f9afc4e33153f8395fbcfb0ce1578791a93D[
bbf2b7054c85cc8831c0ffba64a4cabdc3eb23c4d32ba5484b962d4c8f22ecdeDZ
7b812c97766f36c2e477c31f7c5cfaabf34e7bfaf746d34a7f6971d6abc3e95cDY
3b822a517d29541cd78da3a94ca8b9ce8095283d799bf7d7ebe96461744ae90dDX
eac7d9685870a65836a4ca60f270d56cb0278fbdcef6be718d7aae558eeab78dDW
a29e2e0a13cced40434f89b37fa93d3caf9d4d7726df5a200015fd9c03f045f6DV
5784610bb7a7b03cfd4ed995bd2f9d4785cdbc6dd40713274e6f1ae158558f20DU
4bfbeb71cf3639c4f6067ddf6c491f06976bc93d091646bb825481dd641a719f
;z~;RPk=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696{Ok
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless modeNkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objectskMkoPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{Lk
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)uKkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclibJkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebaseIkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-75\}@- Resolves: #1672308 - Do not restart dhcp on NetworkManagers up events
`JNb`{Xk
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless modeWkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objectskVkoPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{Uk
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)uTkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclibSkPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebase\R}?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.1`@- Roll in CentOS BrandingTQo=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217
Ty}k`koPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-79]?- Resolves:  #1756850 - Close FD in noreplay mode{_k
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-78]S- Detect time shifts to prevent ip address expiration (#1093803)u^kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-77\@- Resolves: #1712414 - Reset signal handlers set by isclib]kPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-76\- Resolves: #1704675 - Fix crash of dhcpd(6) triggered by bind rebase\\}?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.2ff- Roll in CentOS Brandingy[iStepan Broz <sbroz@redhat.com> - 12:4.2.5-83.2fM@- Rebuild because of bind ABI changes related to CVE-2023-50387TZo=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217RYk=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696
|RwchUuTim Waugh <twaugh@redhat.com> 3.2-11P{@- Ported i18n patch and reinstated it (bug #870460).]gUiTim Waugh <twaugh@redhat.com> 3.2-10PY- Fixed license as current source says GPLv3+.\f}?CentOS Sources <bugs@centos.org> - 4.2.5-83.el7.centos.2ff- Roll in CentOS BrandingyeiStepan Broz <sbroz@redhat.com> - 12:4.2.5-83.2fM@- Rebuild because of bind ABI changes related to CVE-2023-50387Tdo=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83.1`- Fix for CVE-2021-25217Rck=Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-83^AE- Revert fix for 1668696{bk
Pavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-81^(9@- Resolves: #1668696 - Update /etc/resolv.conf in stateless modeakPavel Zhukov <pzhukov@redhat.com> - 12:4.2.5-80^ P@- Resolves: #1697637 - Resize ldap buffers to truncate bigger objects

CgQY	CcrUuTim Waugh <twaugh@redhat.com> 3.2-11P{@- Ported i18n patch and reinstated it (bug #870460).]qUiTim Waugh <twaugh@redhat.com> 3.2-10PY- Fixed license as current source says GPLv3+.MpQMThan Ngo <than@redhat.com> - 3.3-6c@- Resolves: #2152980, regression[oQiThan Ngo <than@redhat.com> - 3.3-5[H- Resolves: #1611281, diff -y produces garbageJnY?Daniel Mach <dmach@redhat.com> - 3.3-4RU- Mass rebuild 2014-01-24JmY?Daniel Mach <dmach@redhat.com> - 3.3-3Rk- Mass rebuild 2013-12-27klSTim Waugh <twaugh@redhat.com> 3.3-2Rg@- Fixed multibyte handling logic for diff -Z (bug #1022417).BkS5Tim Waugh <twaugh@redhat.com> 3.3-1QQ- 3.3 (bug #927560).`jUoTim Waugh <twaugh@redhat.com> 3.2-13Q']- Fixed i18n handling of 'diff -E' (bug #914666).iFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.2-12Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild

1gQY	1e|YuPetr Oros <poros@redhat.com> - 1:3.0-3X!@- Hide irrelevant fixup message
- Resolves: #1384195m{YPetr Oros <poros@redhat.com> - 1:3.0-2Ws@- Unmask LRDIMM in memmory type detail
- Resolves: #1321342MzQMThan Ngo <than@redhat.com> - 3.3-6c@- Resolves: #2152980, regression[yQiThan Ngo <than@redhat.com> - 3.3-5[H- Resolves: #1611281, diff -y produces garbageJxY?Daniel Mach <dmach@redhat.com> - 3.3-4RU- Mass rebuild 2014-01-24JwY?Daniel Mach <dmach@redhat.com> - 3.3-3Rk- Mass rebuild 2013-12-27kvSTim Waugh <twaugh@redhat.com> 3.3-2Rg@- Fixed multibyte handling logic for diff -Z (bug #1022417).BuS5Tim Waugh <twaugh@redhat.com> 3.3-1QQ- 3.3 (bug #927560).`tUoTim Waugh <twaugh@redhat.com> 3.2-13Q']- Fixed i18n handling of 'diff -E' (bug #914666).sFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.2-12Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
q.^qcMLianbo Jiang <lijiang@redhat.com> - 1:3.2-5^@- Revert this patch("Use larger units for memory device and BIOS size")
- Resolves: rhbz#1767323<cLianbo Jiang <lijiang@redhat.com> - 1:3.2-4^r
@- Fix System Slot Information for PCIe SSD
- Resolves: rhbz#1793900
- Sync with upstream(commit:62bce59fed1)
- Resolves: rhbz#1767323c;Lianbo Jiang <lijiang@redhat.com> - 1:3.2-3\- Add "Logical non-volatile device" to the memory device types
- Resolves: rhbz#1664921gcoLianbo Jiang <lijiang@redhat.com> - 1:3.2-1[@- Sync with upstream 3.2
- Resolves: rhbz#1628992ccgLianbo Jiang <lijiang@redhat.com> - 1:3.1-1Z@- Sync with upstream
- Resolves: rhbz#1568227r~Y
Petr Oros <poros@redhat.com> - 1:3.0-5Y	@- Update compiler flags for hardened builds
- Resolves: #1420763Z}Y_Petr Oros <poros@redhat.com> - 1:3.0-4Xf@- Sync with upstream
- Resolves: #1385884
Oo0OsgPetr Menšík <pemensik@redhat.com> - 2.76-14^@- Stop treating SERVFAIL as successful response (#1815080)h
gmPetr Menšík <pemensik@redhat.com> - 2.76-13^^F- Do not ignore DHCPv6 relay messages (#1757247)e	ggPetr Menšík <pemensik@redhat.com> - 2.76-12^\@- Fix memory leak in create_helper (#1795369)gPetr Menšík <pemensik@redhat.com> - 2.76-11]@- Send dhcp_release even for addresses not on local network (#1752569)og{Petr Menšík <pemensik@redhat.com> - 2.76-10]- Fix TCP queries after interface recreation (#1721668)ieqPetr Menšík <pemensik@redhat.com> - 2.79-9\@- Fix passing of dnssec enabled queries (#1638703)tePetr Menšík <pemensik@redhat.com> - 2.76-8\@- Stop using privileged port for outbound queries (#1614331)
g5Lianbo Jiang <lijiang@redhat.com> - 1:3.2-5.1_@- Fix the "OUT OF SPEC" error for empty NVMe and DIMM slots
- Resolves: rhbz#1858345
v{	eggPetr Menšík <pemensik@redhat.com> - 2.76-12^\@- Fix memory leak in create_helper (#1795369)gPetr Menšík <pemensik@redhat.com> - 2.76-11]@- Send dhcp_release even for addresses not on local network (#1752569)og{Petr Menšík <pemensik@redhat.com> - 2.76-10]- Fix TCP queries after interface recreation (#1721668)ieqPetr Menšík <pemensik@redhat.com> - 2.79-9\@- Fix passing of dnssec enabled queries (#1638703)!kYPetr Menšík <pemensik@redhat.com> - 2.76-16.1_@- Accept responses only on correct sockets (CVE-2020-25684)
- Use strong verification on queries (CVE-2020-25685)
- Handle multiple identical DNS queries better (CVE-2020-25686)
- Link against nettle for sha256 hash implementationg
gkPetr Menšík <pemensik@redhat.com> - 2.76-16^@- Fix strict-mode retries on REFUSED (#1755610)g'Petr Menšík <pemensik@redhat.com> - 2.76-15^@- Forward non-recursive queries to upstream, but serve local names (#1755610)
+}kPetr Menšík <pemensik@redhat.com> - 2.76-17.1`%@- Fix occasional failures in netlink on many interfaces (#1887649)!kYPetr Menšík <pemensik@redhat.com> - 2.76-16.1_@- Accept responses only on correct sockets (CVE-2020-25684)
- Use strong verification on queries (CVE-2020-25685)
- Handle multiple identical DNS queries better (CVE-2020-25686)
- Link against nettle for sha256 hash implementationggkPetr Menšík <pemensik@redhat.com> - 2.76-16^@- Fix strict-mode retries on REFUSED (#1755610)g'Petr Menšík <pemensik@redhat.com> - 2.76-15^@- Forward non-recursive queries to upstream, but serve local names (#1755610)sgPetr Menšík <pemensik@redhat.com> - 2.76-14^@- Stop treating SERVFAIL as successful response (#1815080)hgmPetr Menšík <pemensik@redhat.com> - 2.76-13^^F- Do not ignore DHCPv6 relay messages (#1757247)
~5A!kYPetr Menšík <pemensik@redhat.com> - 2.76-16.1_@- Accept responses only on correct sockets (CVE-2020-25684)
- Use strong verification on queries (CVE-2020-25685)
- Handle multiple identical DNS queries better (CVE-2020-25686)
- Link against nettle for sha256 hash implementationggkPetr Menšík <pemensik@redhat.com> - 2.76-16^@- Fix strict-mode retries on REFUSED (#1755610)g'Petr Menšík <pemensik@redhat.com> - 2.76-15^@- Forward non-recursive queries to upstream, but serve local names (#1755610)sgPetr Menšík <pemensik@redhat.com> - 2.76-14^@- Stop treating SERVFAIL as successful response (#1815080)hgmPetr Menšík <pemensik@redhat.com> - 2.76-13^^F- Do not ignore DHCPv6 relay messages (#1757247)eggPetr Menšík <pemensik@redhat.com> - 2.76-12^\@- Fix memory leak in create_helper (#1795369)gPetr Menšík <pemensik@redhat.com> - 2.76-11]@- Send dhcp_release even for addresses not on local network (#1752569)
V@Ve'ggPetr Menšík <pemensik@redhat.com> - 2.76-12^\@- Fix memory leak in create_helper (#1795369)&gPetr Menšík <pemensik@redhat.com> - 2.76-11]@- Send dhcp_release even for addresses not on local network (#1752569)o%g{Petr Menšík <pemensik@redhat.com> - 2.76-10]- Fix TCP queries after interface recreation (#1721668)i$eqPetr Menšík <pemensik@redhat.com> - 2.79-9\@- Fix passing of dnssec enabled queries (#1638703)t#ePetr Menšík <pemensik@redhat.com> - 2.76-8\@- Stop using privileged port for outbound queries (#1614331)n"kuPetr Menšík <pemensik@redhat.com> - 2.76-17.3`B@- Accept replies from bound sockets again (#1923913)w!kPetr Menšík <pemensik@redhat.com> - 2.76-17.2`<@- Correct two regressions introduced by CVE fixes (#1923913)} kPetr Menšík <pemensik@redhat.com> - 2.76-17.1`%@- Fix occasional failures in netlink on many interfaces (#1887649)
(+(o.g{Petr Menšík <pemensik@redhat.com> - 2.76-10]- Fix TCP queries after interface recreation (#1721668)i-eqPetr Menšík <pemensik@redhat.com> - 2.79-9\@- Fix passing of dnssec enabled queries (#1638703)!,kYPetr Menšík <pemensik@redhat.com> - 2.76-16.1_@- Accept responses only on correct sockets (CVE-2020-25684)
- Use strong verification on queries (CVE-2020-25685)
- Handle multiple identical DNS queries better (CVE-2020-25686)
- Link against nettle for sha256 hash implementationg+gkPetr Menšík <pemensik@redhat.com> - 2.76-16^@- Fix strict-mode retries on REFUSED (#1755610)*g'Petr Menšík <pemensik@redhat.com> - 2.76-15^@- Forward non-recursive queries to upstream, but serve local names (#1755610)s)gPetr Menšík <pemensik@redhat.com> - 2.76-14^@- Stop treating SERVFAIL as successful response (#1815080)h(gmPetr Menšík <pemensik@redhat.com> - 2.76-13^^F- Do not ignore DHCPv6 relay messages (#1757247)
~5A!5kYPetr Menšík <pemensik@redhat.com> - 2.76-16.1_@- Accept responses only on correct sockets (CVE-2020-25684)
- Use strong verification on queries (CVE-2020-25685)
- Handle multiple identical DNS queries better (CVE-2020-25686)
- Link against nettle for sha256 hash implementationg4gkPetr Menšík <pemensik@redhat.com> - 2.76-16^@- Fix strict-mode retries on REFUSED (#1755610)3g'Petr Menšík <pemensik@redhat.com> - 2.76-15^@- Forward non-recursive queries to upstream, but serve local names (#1755610)s2gPetr Menšík <pemensik@redhat.com> - 2.76-14^@- Stop treating SERVFAIL as successful response (#1815080)h1gmPetr Menšík <pemensik@redhat.com> - 2.76-13^^F- Do not ignore DHCPv6 relay messages (#1757247)e0ggPetr Menšík <pemensik@redhat.com> - 2.76-12^\@- Fix memory leak in create_helper (#1795369)/gPetr Menšík <pemensik@redhat.com> - 2.76-11]@- Send dhcp_release even for addresses not on local network (#1752569)
++g<gkPetr Menšík <pemensik@redhat.com> - 2.76-16^@- Fix strict-mode retries on REFUSED (#1755610);g'Petr Menšík <pemensik@redhat.com> - 2.76-15^@- Forward non-recursive queries to upstream, but serve local names (#1755610)s:gPetr Menšík <pemensik@redhat.com> - 2.76-14^@- Stop treating SERVFAIL as successful response (#1815080)h9gmPetr Menšík <pemensik@redhat.com> - 2.76-13^^F- Do not ignore DHCPv6 relay messages (#1757247)e8ggPetr Menšík <pemensik@redhat.com> - 2.76-12^\@- Fix memory leak in create_helper (#1795369)7gPetr Menšík <pemensik@redhat.com> - 2.76-11]@- Send dhcp_release even for addresses not on local network (#1752569)}6kPetr Menšík <pemensik@redhat.com> - 2.76-17.1`%@- Fix occasional failures in netlink on many interfaces (#1887649)
X[pXB'Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.12-0.29.pre5P@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildtAmKamil Dudka <kdudka@redhat.com> - 0.12-0.28.pre5OY- do not crash if add_heartbeat() returned NULL (#798103)n@kuPetr Menšík <pemensik@redhat.com> - 2.76-17.3`B@- Accept replies from bound sockets again (#1923913)w?kPetr Menšík <pemensik@redhat.com> - 2.76-17.2`<@- Correct two regressions introduced by CVE fixes (#1923913)}>kPetr Menšík <pemensik@redhat.com> - 2.76-17.1`%@- Fix occasional failures in netlink on many interfaces (#1887649)!=kYPetr Menšík <pemensik@redhat.com> - 2.76-16.1_@- Accept responses only on correct sockets (CVE-2020-25684)
- Use strong verification on queries (CVE-2020-25685)
- Handle multiple identical DNS queries better (CVE-2020-25686)
- Link against nettle for sha256 hash implementation
{'{SIk?Daniel Mach <dmach@redhat.com> - 0.12-0.36.pre6RU- Mass rebuild 2014-01-24SHk?Daniel Mach <dmach@redhat.com> - 0.12-0.35.pre6Rk- Mass rebuild 2013-12-27AGmKamil Dudka <kdudka@redhat.com> - 0.12-0.34.pre6Q+R@- update to latest upstream pre-release
- drop unneeded patches
- fix autoconf warnings
- explicitly disable using OpenSSL and GnuTLSF'Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.12-0.33.pre5Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildoEmuKamil Dudka <kdudka@redhat.com> - 0.12-0.32.pre5P@- do not delegate GSSAPI credentials (CVE-2012-4545)DmKamil Dudka <kdudka@redhat.com> - 0.12-0.31.pre5Pr@- add default "ddg" dumb/smart rewrite prefixes for DuckDuckGo (#856348)vCmKamil Dudka <kdudka@redhat.com> - 0.12-0.30.pre5P<- fix specfile issues reported by the fedora-review script
lPkqJan Synáček <jsynacek@redhat.com> - 1:24.3-20Y@- fix unsafe enriched mode translations (#1490451)OkJan Synáček <jsynacek@redhat.com> - 1:24.3-19Xo- fix build failure on ppc64 (#1336711)
- fix emacs crashes (#1308518)iNeqPetr Hracek <phracek@redhat.com> - 1:24.3-18V	A- Fix for sbit on emacs binary
- Related: #1223033Me;Petr Hracek <phracek@redhat.com> - 1:24.3-17V	@- emacs on ppc64le fails to build from source when RELRO is enabled
- Related: #1223033Le=Petr Hracek <phracek@redhat.com> - 1:24.3-16U- emacs on ppc64le fails to build from source when RELRO is enabled
- Resolves: #1223033sKePetr Hracek <phracek@redhat.com> - 1:24.3-15U@- Updated texts in patch and SPEC file
- Resolves: #1223033hJmgKamil Dudka <kdudka@redhat.com> - 0.12-0.37.pre6Y- Rebuilt for js 48-bit VA support (#1439479)

er+V:eDn
7174a32cc247b70e650aa36730fa976b5d7e498a9fc59fde5c06de3be20d8da3Dm
e9ee7e077912afbee46d9de1440f905a3150a783ca98d2999145e7f0d4946b00Dl
cdc630a6947d25b54a576be1d51170f8ca7a920b446adaa54aece61b239e798dDk
91fc50b78a1f5d50c4f2a592996c690be37c4d7e9724a2dbd625eba57e9d607bDj
2847971791401757255fc2092497c37efa1f8f7440c3ce7fc60b243b497e8094Di
69714123fc4f27b58c1e15a2bdfef799961c0c2c3f1398116a458d05cf87f618Dh
2d55f68e1a5fb1da8eb138aca00951f0f028a8f3db6a4427488b57f1c043891eDg
67dc839e667e3f5b861596b011039393d6a243f7dfb880c5c787ed72ab1e601fDf
72415fc89f5dcb558370bd92e670638fc9add9ad19ba4ee77ef546520c9a9e39De
f2136014ff193c8527ea2351651b413e5c8cb5eeb1687c98dd2e6d544c6813bdDd
81d6abea697da32a4834b6bbe7be764845468cc2ee8e089861fd0eb80c2466c6Dc
a547520b96904888041cdae1529c93057c845c1215a8ac1a453c516eae9263a6Db
decf2a313c4d562a043eed4b9202d10b5c58750490b4d6db6e70c5a2bf2fe794
/<Ve=Petr Hracek <phracek@redhat.com> - 1:24.3-16U- emacs on ppc64le fails to build from source when RELRO is enabled
- Resolves: #1223033sUePetr Hracek <phracek@redhat.com> - 1:24.3-15U@- Updated texts in patch and SPEC file
- Resolves: #1223033zTkJacek Migacz <jmigacz@redhat.com> - 1:24.3-23.1d0- Fix htmlfontify.el command injection vulnerability (#2175177)aSccTomas Pelka <tpelka@redhat.com> - 1:24.3-23]@- Resolves: #1765208 rebuild against new IM}RkJan Synáček <jsynacek@redhat.com> - 1:24.3-22[@- refix: TLS certificate warnings should be hard errors (#1403643)iQkiJan Synáček <jsynacek@redhat.com> - 1:24.3-21[@- fix libjpeg detection fails with gcc7 (#1487557)
- fix Emacs GUI Toolbar icons missing (#1477745)
- fix hardening: TLS certificate warnings should be hard errors (#1403643)
<m|
 <a]ccTomas Pelka <tpelka@redhat.com> - 1:24.3-23]@- Resolves: #1765208 rebuild against new IM}\kJan Synáček <jsynacek@redhat.com> - 1:24.3-22[@- refix: TLS certificate warnings should be hard errors (#1403643)i[kiJan Synáček <jsynacek@redhat.com> - 1:24.3-21[@- fix libjpeg detection fails with gcc7 (#1487557)
- fix Emacs GUI Toolbar icons missing (#1477745)
- fix hardening: TLS certificate warnings should be hard errors (#1403643)lZkqJan Synáček <jsynacek@redhat.com> - 1:24.3-20Y@- fix unsafe enriched mode translations (#1490451)YkJan Synáček <jsynacek@redhat.com> - 1:24.3-19Xo- fix build failure on ppc64 (#1336711)
- fix emacs crashes (#1308518)iXeqPetr Hracek <phracek@redhat.com> - 1:24.3-18V	A- Fix for sbit on emacs binary
- Related: #1223033We;Petr Hracek <phracek@redhat.com> - 1:24.3-17V	@- emacs on ppc64le fails to build from source when RELRO is enabled
- Related: #1223033

yzldkqJan Synáček <jsynacek@redhat.com> - 1:24.3-20Y@- fix unsafe enriched mode translations (#1490451)ckJan Synáček <jsynacek@redhat.com> - 1:24.3-19Xo- fix build failure on ppc64 (#1336711)
- fix emacs crashes (#1308518)ibeqPetr Hracek <phracek@redhat.com> - 1:24.3-18V	A- Fix for sbit on emacs binary
- Related: #1223033ae;Petr Hracek <phracek@redhat.com> - 1:24.3-17V	@- emacs on ppc64le fails to build from source when RELRO is enabled
- Related: #1223033`e=Petr Hracek <phracek@redhat.com> - 1:24.3-16U- emacs on ppc64le fails to build from source when RELRO is enabled
- Resolves: #1223033s_ePetr Hracek <phracek@redhat.com> - 1:24.3-15U@- Updated texts in patch and SPEC file
- Resolves: #1223033z^kJacek Migacz <jmigacz@redhat.com> - 1:24.3-23.1d0- Fix htmlfontify.el command injection vulnerability (#2175177)
/<je=Petr Hracek <phracek@redhat.com> - 1:24.3-16U- emacs on ppc64le fails to build from source when RELRO is enabled
- Resolves: #1223033siePetr Hracek <phracek@redhat.com> - 1:24.3-15U@- Updated texts in patch and SPEC file
- Resolves: #1223033zhkJacek Migacz <jmigacz@redhat.com> - 1:24.3-23.1d0- Fix htmlfontify.el command injection vulnerability (#2175177)agccTomas Pelka <tpelka@redhat.com> - 1:24.3-23]@- Resolves: #1765208 rebuild against new IM}fkJan Synáček <jsynacek@redhat.com> - 1:24.3-22[@- refix: TLS certificate warnings should be hard errors (#1403643)iekiJan Synáček <jsynacek@redhat.com> - 1:24.3-21[@- fix libjpeg detection fails with gcc7 (#1487557)
- fix Emacs GUI Toolbar icons missing (#1477745)
- fix hardening: TLS certificate warnings should be hard errors (#1403643)
<m|
 <aqccTomas Pelka <tpelka@redhat.com> - 1:24.3-23]@- Resolves: #1765208 rebuild against new IM}pkJan Synáček <jsynacek@redhat.com> - 1:24.3-22[@- refix: TLS certificate warnings should be hard errors (#1403643)iokiJan Synáček <jsynacek@redhat.com> - 1:24.3-21[@- fix libjpeg detection fails with gcc7 (#1487557)
- fix Emacs GUI Toolbar icons missing (#1477745)
- fix hardening: TLS certificate warnings should be hard errors (#1403643)lnkqJan Synáček <jsynacek@redhat.com> - 1:24.3-20Y@- fix unsafe enriched mode translations (#1490451)mkJan Synáček <jsynacek@redhat.com> - 1:24.3-19Xo- fix build failure on ppc64 (#1336711)
- fix emacs crashes (#1308518)ileqPetr Hracek <phracek@redhat.com> - 1:24.3-18V	A- Fix for sbit on emacs binary
- Related: #1223033ke;Petr Hracek <phracek@redhat.com> - 1:24.3-17V	@- emacs on ppc64le fails to build from source when RELRO is enabled
- Related: #1223033
5tq{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[sqGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081zrkJacek Migacz <jmigacz@redhat.com> - 1:24.3-23.1d0- Fix htmlfontify.el command injection vulnerability (#2175177)
uTuxi)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Owq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059viQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.ui)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKl|{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:{kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008zu=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601yuoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.~i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5}q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.offlrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|GHKPX`hpx (08@HPX`hr|'.5<BIPV]djqtx|&-4;CKRYaºiúpĺwźƻǻȻɻʻ"˻*̻1ͻ8λ>ϻCлIѻPӻVԻ]ջdֻj׻qػxٻ~ڻۼܼݼ	޼߼"&'-0189:@CDJNOU
-!l:kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Oq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X5q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[qGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081sMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
uTui)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Oq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.	i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKl{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601
uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Oq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
b{zSbkJan Synáček <jsynacek@redhat.com> - 1:24.3-19Xo- fix build failure on ppc64 (#1336711)
- fix emacs crashes (#1308518)ieqPetr Hracek <phracek@redhat.com> - 1:24.3-18V	A- Fix for sbit on emacs binary
- Related: #1223033e;Petr Hracek <phracek@redhat.com> - 1:24.3-17V	@- emacs on ppc64le fails to build from source when RELRO is enabled
- Related: #1223033e=Petr Hracek <phracek@redhat.com> - 1:24.3-16U- emacs on ppc64le fails to build from source when RELRO is enabled
- Resolves: #1223033sePetr Hracek <phracek@redhat.com> - 1:24.3-15U@- Updated texts in patch and SPEC file
- Resolves: #1223033sMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
9$C9&e=Petr Hracek <phracek@redhat.com> - 1:24.3-16U- emacs on ppc64le fails to build from source when RELRO is enabled
- Resolves: #1223033s%ePetr Hracek <phracek@redhat.com> - 1:24.3-15U@- Updated texts in patch and SPEC file
- Resolves: #1223033z$kJacek Migacz <jmigacz@redhat.com> - 1:24.3-23.1d0- Fix htmlfontify.el command injection vulnerability (#2175177)a#ccTomas Pelka <tpelka@redhat.com> - 1:24.3-23]@- Resolves: #1765208 rebuild against new IM}"kJan Synáček <jsynacek@redhat.com> - 1:24.3-22[@- refix: TLS certificate warnings should be hard errors (#1403643)i!kiJan Synáček <jsynacek@redhat.com> - 1:24.3-21[@- fix libjpeg detection fails with gcc7 (#1487557)
- fix Emacs GUI Toolbar icons missing (#1477745)
- fix hardening: TLS certificate warnings should be hard errors (#1403643)l kqJan Synáček <jsynacek@redhat.com> - 1:24.3-20Y@- fix unsafe enriched mode translations (#1490451)
<m|
 <a-ccTomas Pelka <tpelka@redhat.com> - 1:24.3-23]@- Resolves: #1765208 rebuild against new IM},kJan Synáček <jsynacek@redhat.com> - 1:24.3-22[@- refix: TLS certificate warnings should be hard errors (#1403643)i+kiJan Synáček <jsynacek@redhat.com> - 1:24.3-21[@- fix libjpeg detection fails with gcc7 (#1487557)
- fix Emacs GUI Toolbar icons missing (#1477745)
- fix hardening: TLS certificate warnings should be hard errors (#1403643)l*kqJan Synáček <jsynacek@redhat.com> - 1:24.3-20Y@- fix unsafe enriched mode translations (#1490451))kJan Synáček <jsynacek@redhat.com> - 1:24.3-19Xo- fix build failure on ppc64 (#1336711)
- fix emacs crashes (#1308518)i(eqPetr Hracek <phracek@redhat.com> - 1:24.3-18V	A- Fix for sbit on emacs binary
- Related: #1223033'e;Petr Hracek <phracek@redhat.com> - 1:24.3-17V	@- emacs on ppc64le fails to build from source when RELRO is enabled
- Related: #1223033
QH}4]Milan Crha <mcrha@redhat.com> - 3.28.5-2\T4- Add patch for RH bug #1610744 (test-cal-client-get-revision could fail)E3]1Milan Crha <mcrha@redhat.com> - 3.28.5-1[^- Update to 3.28.5|2]Milan Crha <mcrha@redhat.com> - 3.28.4-1[L- Update to 3.28.4
- Remove patch for GNOME bug #796174 (fixed upstream)1]1Milan Crha <mcrha@redhat.com> - 3.28.3-2[(@- Add patch for GNOME bug #796174 (strcat() considered unsafe for buffer overflow)|0]Milan Crha <mcrha@redhat.com> - 3.28.3-1['- Update to 3.28.3
- Remove patch for GNOME bug #795997 (fixed upstream)//]Milan Crha <mcrha@redhat.com> - 3.28.2-1[@- Update to 3.28.2
- Add patch for GNOME bug #795997 (Fails to parse Google OAuth2 authorization code)
- Resolves: #1575495z.kJacek Migacz <jmigacz@redhat.com> - 1:24.3-23.1d0- Fix htmlfontify.el command injection vulnerability (#2175177)
^|g^;]1Milan Crha <mcrha@redhat.com> - 3.28.3-2[(@- Add patch for GNOME bug #796174 (strcat() considered unsafe for buffer overflow)|:]Milan Crha <mcrha@redhat.com> - 3.28.3-1['- Update to 3.28.3
- Remove patch for GNOME bug #795997 (fixed upstream)/9]Milan Crha <mcrha@redhat.com> - 3.28.2-1[@- Update to 3.28.2
- Add patch for GNOME bug #795997 (Fails to parse Google OAuth2 authorization code)
- Resolves: #1575495t8a	Milan Crha <mcrha@redhat.com> - 3.28.5-5.1bs@- Resolves: #2081786 (Backport patch for Google OAuth2 change)l7]Milan Crha <mcrha@redhat.com> - 3.28.5-5^@- Resolves: #1772103 (EDBusServer: Delay new module load)y6]Milan Crha <mcrha@redhat.com> - 3.28.5-4]S- Add patch related to evolution-ews' CVE-2019-3890 (RH bug #1696762)5]%Milan Crha <mcrha@redhat.com> - 3.28.5-3\@- Update patch for RH bug #1610744 (test-cal-client-get-revision could fail)
 95J /C]Milan Crha <mcrha@redhat.com> - 3.28.2-1[@- Update to 3.28.2
- Add patch for GNOME bug #795997 (Fails to parse Google OAuth2 authorization code)
- Resolves: #1575495tBa	Milan Crha <mcrha@redhat.com> - 3.28.5-5.1bs@- Resolves: #2081786 (Backport patch for Google OAuth2 change)lA]Milan Crha <mcrha@redhat.com> - 3.28.5-5^@- Resolves: #1772103 (EDBusServer: Delay new module load)y@]Milan Crha <mcrha@redhat.com> - 3.28.5-4]S- Add patch related to evolution-ews' CVE-2019-3890 (RH bug #1696762)?]%Milan Crha <mcrha@redhat.com> - 3.28.5-3\@- Update patch for RH bug #1610744 (test-cal-client-get-revision could fail)}>]Milan Crha <mcrha@redhat.com> - 3.28.5-2\T4- Add patch for RH bug #1610744 (test-cal-client-get-revision could fail)E=]1Milan Crha <mcrha@redhat.com> - 3.28.5-1[^- Update to 3.28.5|<]Milan Crha <mcrha@redhat.com> - 3.28.4-1[L- Update to 3.28.4
- Remove patch for GNOME bug #796174 (fixed upstream)
Ax0,AlK]Milan Crha <mcrha@redhat.com> - 3.28.5-5^@- Resolves: #1772103 (EDBusServer: Delay new module load)yJ]Milan Crha <mcrha@redhat.com> - 3.28.5-4]S- Add patch related to evolution-ews' CVE-2019-3890 (RH bug #1696762)I]%Milan Crha <mcrha@redhat.com> - 3.28.5-3\@- Update patch for RH bug #1610744 (test-cal-client-get-revision could fail)}H]Milan Crha <mcrha@redhat.com> - 3.28.5-2\T4- Add patch for RH bug #1610744 (test-cal-client-get-revision could fail)EG]1Milan Crha <mcrha@redhat.com> - 3.28.5-1[^- Update to 3.28.5|F]Milan Crha <mcrha@redhat.com> - 3.28.4-1[L- Update to 3.28.4
- Remove patch for GNOME bug #796174 (fixed upstream)E]1Milan Crha <mcrha@redhat.com> - 3.28.3-2[(@- Add patch for GNOME bug #796174 (strcat() considered unsafe for buffer overflow)|D]Milan Crha <mcrha@redhat.com> - 3.28.3-1['- Update to 3.28.3
- Remove patch for GNOME bug #795997 (fixed upstream)
WN}R]Milan Crha <mcrha@redhat.com> - 3.28.5-2\T4- Add patch for RH bug #1610744 (test-cal-client-get-revision could fail)EQ]1Milan Crha <mcrha@redhat.com> - 3.28.5-1[^- Update to 3.28.5|P]Milan Crha <mcrha@redhat.com> - 3.28.4-1[L- Update to 3.28.4
- Remove patch for GNOME bug #796174 (fixed upstream)O]1Milan Crha <mcrha@redhat.com> - 3.28.3-2[(@- Add patch for GNOME bug #796174 (strcat() considered unsafe for buffer overflow)|N]Milan Crha <mcrha@redhat.com> - 3.28.3-1['- Update to 3.28.3
- Remove patch for GNOME bug #795997 (fixed upstream)/M]Milan Crha <mcrha@redhat.com> - 3.28.2-1[@- Update to 3.28.2
- Add patch for GNOME bug #795997 (Fails to parse Google OAuth2 authorization code)
- Resolves: #1575495tLa	Milan Crha <mcrha@redhat.com> - 3.28.5-5.1bs@- Resolves: #2081786 (Backport patch for Google OAuth2 change)

er+V:eD{
4402a7fcf865ee506196d91c722ec2875470f134b63f3912ac69561ba10e5113Dz
18defd29c31366e3f3fc7602eed4307dcdd1028a8e25fd6823379fa2ef33eb6bDy
d219bddd9ca9b61182ef38132b073da37b5c7b6727fe9ef79c35acfe7e1aca0eDx
a52fbf59e2e7f8b7b912ee6fd5be7c84450b3ab1d4cb68690cfc3f306086b817Dw
a919c9e3a766f98e15edfc8dde8b699f46753980aaf8f4b46d2831fcc01cf9b7Dv
369ac51f105f8b0b9fb343deb57c8ed97f3e08bbb535d683866ddfd47b058675Du
1b57cc987d64b98efbaa6f796a3df838d4f4cc4a2b892e4e19685ea37ea8188dDt
284e903527e4376ba342697bff7afdcf76804823b3344908e0ad3589efb08d0eDs
a56dd9d75f85b76dd72f232aef6262710e4f66d7291c55f0e3467fa4c70855eeDr
006866668980a661dabcff054750dcfabee9be838cbdbe8f6554a12c8d2437e4Dq
1d2c5ccf5a54793d996b971ad4448b1d95a72bf1270703b1cdd944b0b4a82932Dp
98fa7e7c32572003a415282278a680123f7896108aa35e2ddad608cf9a8bf1b6Do
d057cb97f19e0b7a6e8769b9407b59d09edac0f8548ba4137a65575461013ea6
^|g^Y]1Milan Crha <mcrha@redhat.com> - 3.28.3-2[(@- Add patch for GNOME bug #796174 (strcat() considered unsafe for buffer overflow)|X]Milan Crha <mcrha@redhat.com> - 3.28.3-1['- Update to 3.28.3
- Remove patch for GNOME bug #795997 (fixed upstream)/W]Milan Crha <mcrha@redhat.com> - 3.28.2-1[@- Update to 3.28.2
- Add patch for GNOME bug #795997 (Fails to parse Google OAuth2 authorization code)
- Resolves: #1575495tVa	Milan Crha <mcrha@redhat.com> - 3.28.5-5.1bs@- Resolves: #2081786 (Backport patch for Google OAuth2 change)lU]Milan Crha <mcrha@redhat.com> - 3.28.5-5^@- Resolves: #1772103 (EDBusServer: Delay new module load)yT]Milan Crha <mcrha@redhat.com> - 3.28.5-4]S- Add patch related to evolution-ews' CVE-2019-3890 (RH bug #1696762)S]%Milan Crha <mcrha@redhat.com> - 3.28.5-3\@- Update patch for RH bug #1610744 (test-cal-client-get-revision could fail)
 95J /a]Milan Crha <mcrha@redhat.com> - 3.28.2-1[@- Update to 3.28.2
- Add patch for GNOME bug #795997 (Fails to parse Google OAuth2 authorization code)
- Resolves: #1575495t`a	Milan Crha <mcrha@redhat.com> - 3.28.5-5.1bs@- Resolves: #2081786 (Backport patch for Google OAuth2 change)l_]Milan Crha <mcrha@redhat.com> - 3.28.5-5^@- Resolves: #1772103 (EDBusServer: Delay new module load)y^]Milan Crha <mcrha@redhat.com> - 3.28.5-4]S- Add patch related to evolution-ews' CVE-2019-3890 (RH bug #1696762)]]%Milan Crha <mcrha@redhat.com> - 3.28.5-3\@- Update patch for RH bug #1610744 (test-cal-client-get-revision could fail)}\]Milan Crha <mcrha@redhat.com> - 3.28.5-2\T4- Add patch for RH bug #1610744 (test-cal-client-get-revision could fail)E[]1Milan Crha <mcrha@redhat.com> - 3.28.5-1[^- Update to 3.28.5|Z]Milan Crha <mcrha@redhat.com> - 3.28.4-1[L- Update to 3.28.4
- Remove patch for GNOME bug #796174 (fixed upstream)
Ax0,Ali]Milan Crha <mcrha@redhat.com> - 3.28.5-5^@- Resolves: #1772103 (EDBusServer: Delay new module load)yh]Milan Crha <mcrha@redhat.com> - 3.28.5-4]S- Add patch related to evolution-ews' CVE-2019-3890 (RH bug #1696762)g]%Milan Crha <mcrha@redhat.com> - 3.28.5-3\@- Update patch for RH bug #1610744 (test-cal-client-get-revision could fail)}f]Milan Crha <mcrha@redhat.com> - 3.28.5-2\T4- Add patch for RH bug #1610744 (test-cal-client-get-revision could fail)Ee]1Milan Crha <mcrha@redhat.com> - 3.28.5-1[^- Update to 3.28.5|d]Milan Crha <mcrha@redhat.com> - 3.28.4-1[L- Update to 3.28.4
- Remove patch for GNOME bug #796174 (fixed upstream)c]1Milan Crha <mcrha@redhat.com> - 3.28.3-2[(@- Add patch for GNOME bug #796174 (strcat() considered unsafe for buffer overflow)|b]Milan Crha <mcrha@redhat.com> - 3.28.3-1['- Update to 3.28.3
- Remove patch for GNOME bug #795997 (fixed upstream)
WN}p]Milan Crha <mcrha@redhat.com> - 3.28.5-2\T4- Add patch for RH bug #1610744 (test-cal-client-get-revision could fail)Eo]1Milan Crha <mcrha@redhat.com> - 3.28.5-1[^- Update to 3.28.5|n]Milan Crha <mcrha@redhat.com> - 3.28.4-1[L- Update to 3.28.4
- Remove patch for GNOME bug #796174 (fixed upstream)m]1Milan Crha <mcrha@redhat.com> - 3.28.3-2[(@- Add patch for GNOME bug #796174 (strcat() considered unsafe for buffer overflow)|l]Milan Crha <mcrha@redhat.com> - 3.28.3-1['- Update to 3.28.3
- Remove patch for GNOME bug #795997 (fixed upstream)/k]Milan Crha <mcrha@redhat.com> - 3.28.2-1[@- Update to 3.28.2
- Add patch for GNOME bug #795997 (Fails to parse Google OAuth2 authorization code)
- Resolves: #1575495tja	Milan Crha <mcrha@redhat.com> - 3.28.5-5.1bs@- Resolves: #2081786 (Backport patch for Google OAuth2 change)
^|g^w]1Milan Crha <mcrha@redhat.com> - 3.28.3-2[(@- Add patch for GNOME bug #796174 (strcat() considered unsafe for buffer overflow)|v]Milan Crha <mcrha@redhat.com> - 3.28.3-1['- Update to 3.28.3
- Remove patch for GNOME bug #795997 (fixed upstream)/u]Milan Crha <mcrha@redhat.com> - 3.28.2-1[@- Update to 3.28.2
- Add patch for GNOME bug #795997 (Fails to parse Google OAuth2 authorization code)
- Resolves: #1575495tta	Milan Crha <mcrha@redhat.com> - 3.28.5-5.1bs@- Resolves: #2081786 (Backport patch for Google OAuth2 change)ls]Milan Crha <mcrha@redhat.com> - 3.28.5-5^@- Resolves: #1772103 (EDBusServer: Delay new module load)yr]Milan Crha <mcrha@redhat.com> - 3.28.5-4]S- Add patch related to evolution-ews' CVE-2019-3890 (RH bug #1696762)q]%Milan Crha <mcrha@redhat.com> - 3.28.5-3\@- Update patch for RH bug #1610744 (test-cal-client-get-revision could fail)
 95J /]Milan Crha <mcrha@redhat.com> - 3.28.2-1[@- Update to 3.28.2
- Add patch for GNOME bug #795997 (Fails to parse Google OAuth2 authorization code)
- Resolves: #1575495t~a	Milan Crha <mcrha@redhat.com> - 3.28.5-5.1bs@- Resolves: #2081786 (Backport patch for Google OAuth2 change)l}]Milan Crha <mcrha@redhat.com> - 3.28.5-5^@- Resolves: #1772103 (EDBusServer: Delay new module load)y|]Milan Crha <mcrha@redhat.com> - 3.28.5-4]S- Add patch related to evolution-ews' CVE-2019-3890 (RH bug #1696762){]%Milan Crha <mcrha@redhat.com> - 3.28.5-3\@- Update patch for RH bug #1610744 (test-cal-client-get-revision could fail)}z]Milan Crha <mcrha@redhat.com> - 3.28.5-2\T4- Add patch for RH bug #1610744 (test-cal-client-get-revision could fail)Ey]1Milan Crha <mcrha@redhat.com> - 3.28.5-1[^- Update to 3.28.5|x]Milan Crha <mcrha@redhat.com> - 3.28.4-1[L- Update to 3.28.4
- Remove patch for GNOME bug #796174 (fixed upstream)
Ax0,Al]Milan Crha <mcrha@redhat.com> - 3.28.5-5^@- Resolves: #1772103 (EDBusServer: Delay new module load)y]Milan Crha <mcrha@redhat.com> - 3.28.5-4]S- Add patch related to evolution-ews' CVE-2019-3890 (RH bug #1696762)]%Milan Crha <mcrha@redhat.com> - 3.28.5-3\@- Update patch for RH bug #1610744 (test-cal-client-get-revision could fail)}]Milan Crha <mcrha@redhat.com> - 3.28.5-2\T4- Add patch for RH bug #1610744 (test-cal-client-get-revision could fail)E]1Milan Crha <mcrha@redhat.com> - 3.28.5-1[^- Update to 3.28.5|]Milan Crha <mcrha@redhat.com> - 3.28.4-1[L- Update to 3.28.4
- Remove patch for GNOME bug #796174 (fixed upstream)]1Milan Crha <mcrha@redhat.com> - 3.28.3-2[(@- Add patch for GNOME bug #796174 (strcat() considered unsafe for buffer overflow)|]Milan Crha <mcrha@redhat.com> - 3.28.3-1['- Update to 3.28.3
- Remove patch for GNOME bug #795997 (fixed upstream)
@y1@X]UMilan Crha <mcrha@redhat.com> - 3.28.5-4]@- Add patch for RH bug #1392567 (Sync CategoryList with mail Labels)
- Add patch for RH bug #1764669 (Send meeting change notifications only if being the organizer)
]5Milan Crha <mcrha@redhat.com> - 3.28.5-3]S- Add patch for RH bug #1696760 (CVE-2019-3890 - SSL Certificates are not validated)]/Milan Crha <mcrha@redhat.com> - 3.28.5-2[v- Add patches for RH bug #1633711 (Backport few minor regression fixes from 3.30)E]1Milan Crha <mcrha@redhat.com> - 3.28.5-1[^- Update to 3.28.5|
]Milan Crha <mcrha@redhat.com> - 3.28.4-1[L- Update to 3.28.4
- Remove patch for GNOME bug #796297 (fixed upstream)
	]?Milan Crha <mcrha@redhat.com> - 3.28.3-2[0@- Add patch for GNOME bug #796297 (Cannot modify existing meeting after fix for this bug)ta	Milan Crha <mcrha@redhat.com> - 3.28.5-5.1bs@- Resolves: #2081786 (Backport patch for Google OAuth2 change)
f[IE]1Milan Crha <mcrha@redhat.com> - 3.28.5-1[^- Update to 3.28.5|]Milan Crha <mcrha@redhat.com> - 3.28.4-1[L- Update to 3.28.4
- Remove patch for GNOME bug #796297 (fixed upstream)
]?Milan Crha <mcrha@redhat.com> - 3.28.3-2[0@- Add patch for GNOME bug #796297 (Cannot modify existing meeting after fix for this bug)~]!Milan Crha <mcrha@redhat.com> - 3.28.5-8_- Resolves: #1891558 (Birthday date of Contact depends on system timezone)}]Milan Crha <mcrha@redhat.com> - 3.28.5-7_- Resolves: #1887925 (Allow change of the Microsoft 365 OAuth2 endpoints)]3Milan Crha <mcrha@redhat.com> - 3.28.5-6^U@- Add patch for RH bug #1764669 (Reject creating meetings organized by other users)]QMilan Crha <mcrha@redhat.com> - 3.28.5-5])- Remove patch for RH bug #1764669 (Send meeting change notifications only if being the organizer)
jwuj}]Milan Crha <mcrha@redhat.com> - 3.28.5-7_- Resolves: #1887925 (Allow change of the Microsoft 365 OAuth2 endpoints)]3Milan Crha <mcrha@redhat.com> - 3.28.5-6^U@- Add patch for RH bug #1764669 (Reject creating meetings organized by other users)]QMilan Crha <mcrha@redhat.com> - 3.28.5-5])- Remove patch for RH bug #1764669 (Send meeting change notifications only if being the organizer)X]UMilan Crha <mcrha@redhat.com> - 3.28.5-4]@- Add patch for RH bug #1392567 (Sync CategoryList with mail Labels)
- Add patch for RH bug #1764669 (Send meeting change notifications only if being the organizer)]5Milan Crha <mcrha@redhat.com> - 3.28.5-3]S- Add patch for RH bug #1696760 (CVE-2019-3890 - SSL Certificates are not validated)]/Milan Crha <mcrha@redhat.com> - 3.28.5-2[v- Add patches for RH bug #1633711 (Backport few minor regression fixes from 3.30)
6o'6X"]UMilan Crha <mcrha@redhat.com> - 3.28.5-4]@- Add patch for RH bug #1392567 (Sync CategoryList with mail Labels)
- Add patch for RH bug #1764669 (Send meeting change notifications only if being the organizer)!]5Milan Crha <mcrha@redhat.com> - 3.28.5-3]S- Add patch for RH bug #1696760 (CVE-2019-3890 - SSL Certificates are not validated) ]/Milan Crha <mcrha@redhat.com> - 3.28.5-2[v- Add patches for RH bug #1633711 (Backport few minor regression fixes from 3.30)E]1Milan Crha <mcrha@redhat.com> - 3.28.5-1[^- Update to 3.28.5|]Milan Crha <mcrha@redhat.com> - 3.28.4-1[L- Update to 3.28.4
- Remove patch for GNOME bug #796297 (fixed upstream)
]?Milan Crha <mcrha@redhat.com> - 3.28.3-2[0@- Add patch for GNOME bug #796297 (Cannot modify existing meeting after fix for this bug)~]!Milan Crha <mcrha@redhat.com> - 3.28.5-8_- Resolves: #1891558 (Birthday date of Contact depends on system timezone)
 f[x#z W*eMJosef Ridky <jridky@redhat.com> - 0:1.8.18-4X+- Fix RPMDiff issues and rebuild%)egJosef Ridky <jridky@redhat.com> - 0:1.8.18-3X@- Fix issues with warning: dereferencing type-punned pointer 
  will break strict-aliasing rules from RPMDiffR(eCJosef Ridky <jridky@redhat.com> - 0:1.8.18-2X- Fix issue in file sources_'e]Josef Ridky <jridky@redhat.com> - 0:1.8.18-1X@- New upstream release 1.8.18 (#1398658)~&]!Milan Crha <mcrha@redhat.com> - 3.28.5-8_- Resolves: #1891558 (Birthday date of Contact depends on system timezone)}%]Milan Crha <mcrha@redhat.com> - 3.28.5-7_- Resolves: #1887925 (Allow change of the Microsoft 365 OAuth2 endpoints)$]3Milan Crha <mcrha@redhat.com> - 3.28.5-6^U@- Add patch for RH bug #1764669 (Reject creating meetings organized by other users)#]QMilan Crha <mcrha@redhat.com> - 3.28.5-5])- Remove patch for RH bug #1764669 (Send meeting change notifications only if being the organizer)
D'DR1eCJosef Ridky <jridky@redhat.com> - 0:1.8.18-2X- Fix issue in file sources0kSPavel Cahyna <pcahyna@redhat.com> - 0:1.8.18-10a{- Protect against negative values to memmove that caused
  "ipmitool sol activate" to crash against an IBM DataPower appliance
  (#1951480) and IP-131 Dayton blades in a SGI ICE-X (#2025519)
  Cherry-picked from upstream PR#78.i/scVáclav Doležal <vdolezal@redhat.com> - 0:1.8.18-9^_@- Disable -fstrict-aliasing (RPMDiff issue)^.sMVáclav Doležal <vdolezal@redhat.com> - 0:1.8.18-8^^F- Backport fix for CVE-2020-5208o-e}Josef Ridky <jridky@redhat.com> - 0:1.8.18-7Zy- Remove debug prints shown without -v option (#1483163),e=Josef Ridky <jridky@redhat.com> - 0:1.8.18-6Y{- Hide unrequested verbose output (#1483163)
- Fix doc for check input values (#1495098)o+e}Josef Ridky <jridky@redhat.com> - 0:1.8.18-5Xs- Remove RPMDiff fix file (#1439269) related to #1398658
W$i8scVáclav Doležal <vdolezal@redhat.com> - 0:1.8.18-9^_@- Disable -fstrict-aliasing (RPMDiff issue)^7sMVáclav Doležal <vdolezal@redhat.com> - 0:1.8.18-8^^F- Backport fix for CVE-2020-5208o6e}Josef Ridky <jridky@redhat.com> - 0:1.8.18-7Zy- Remove debug prints shown without -v option (#1483163)5e=Josef Ridky <jridky@redhat.com> - 0:1.8.18-6Y{- Hide unrequested verbose output (#1483163)
- Fix doc for check input values (#1495098)o4e}Josef Ridky <jridky@redhat.com> - 0:1.8.18-5Xs- Remove RPMDiff fix file (#1439269) related to #1398658W3eMJosef Ridky <jridky@redhat.com> - 0:1.8.18-4X+- Fix RPMDiff issues and rebuild%2egJosef Ridky <jridky@redhat.com> - 0:1.8.18-3X@- Fix issues with warning: dereferencing type-punned pointer 
  will break strict-aliasing rules from RPMDiff
OJO\>a[Jan Grulich <jgrulich@redhat.com> - 0.26-1YW@- Update to 0.26
  Resolves: bz#1420227K=[?Daniel Mach <dmach@redhat.com> - 0.23-6RU- Mass rebuild 2014-01-24K<[?Daniel Mach <dmach@redhat.com> - 0.23-5Rk- Mass rebuild 2013-12-27;Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.23-4Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuildw:g	Pavel Cahyna <pcahyna@redhat.com> - 1.8.18-11d- Add upstream ipmievd patch to check received msg id against expectation
  Fixes problem where SEL response is not recognized correctly
  when SEL request times out
  Resolves: rhbz#22245699kSPavel Cahyna <pcahyna@redhat.com> - 0:1.8.18-10a{- Protect against negative values to memmove that caused
  "ipmitool sol activate" to crash against an IBM DataPower appliance
  (#1951480) and IP-131 Dayton blades in a SGI ICE-X (#2025519)
  Cherry-picked from upstream PR#78.
KCeGJan Grulich <jgrulich@redhat.com> - 0.27.0-3^K- Validate relationship of the total size to the offset to avoid crash
  Resolves: bz#1775695bBecJan Grulich <jgrulich@redhat.com> - 0.27.0-2\X)@- Minor improvements
  Resolves: bz#1652637\AeWJan Grulich <jgrulich@redhat.com> - 0.27.0-1\=@- Exiv2 0.27.0
  Resolves: bz#1652637p@aJan Grulich <jgrulich@redhat.com> - 0.26-3Z@- Fix uncontrolled recursion in image.cpp:Exiv2::Image::printIFDStructure() which can allow a
  remote attacker to cause a denial of service via a crafted tif file
  Resolves: bz#1548410y?aJan Grulich <jgrulich@redhat.com> - 0.26-2Z- Fix heap-based buffer over-read in Exiv2::Image::byteSwap4 in image.cpp
  Resolves: bz#1547207

  Fix heap-based buffer over-read in Exiv2::getULong function in types.cpp
  Resolves: bz#1545232
Zs%yIaJan Grulich <jgrulich@redhat.com> - 0.26-2Z- Fix heap-based buffer over-read in Exiv2::Image::byteSwap4 in image.cpp
  Resolves: bz#1547207

  Fix heap-based buffer over-read in Exiv2::getULong function in types.cpp
  Resolves: bz#1545232\Ha[Jan Grulich <jgrulich@redhat.com> - 0.26-1YW@- Update to 0.26
  Resolves: bz#1420227KG[?Daniel Mach <dmach@redhat.com> - 0.23-6RU- Mass rebuild 2014-01-24KF[?Daniel Mach <dmach@redhat.com> - 0.23-5Rk- Mass rebuild 2013-12-27EFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.23-4Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild"DeaJan Grulich <jgrulich@redhat.com> - 0.27.0-4a- Fix heap-based buffer overflow vulnerability in jp2image.cpp that may lead to DoS
  Resolves: bz#1990352
"H	p"KP[?Daniel Mach <dmach@redhat.com> - 0.23-5Rk- Mass rebuild 2013-12-27OFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.23-4Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild"NeaJan Grulich <jgrulich@redhat.com> - 0.27.0-4a- Fix heap-based buffer overflow vulnerability in jp2image.cpp that may lead to DoS
  Resolves: bz#1990352MeGJan Grulich <jgrulich@redhat.com> - 0.27.0-3^K- Validate relationship of the total size to the offset to avoid crash
  Resolves: bz#1775695bLecJan Grulich <jgrulich@redhat.com> - 0.27.0-2\X)@- Minor improvements
  Resolves: bz#1652637\KeWJan Grulich <jgrulich@redhat.com> - 0.27.0-1\=@- Exiv2 0.27.0
  Resolves: bz#1652637pJaJan Grulich <jgrulich@redhat.com> - 0.26-3Z@- Fix uncontrolled recursion in image.cpp:Exiv2::Image::printIFDStructure() which can allow a
  remote attacker to cause a denial of service via a crafted tif file
  Resolves: bz#1548410

er+V:eD
a962654ff0fe134fdd88392c47a711e94bc84e08e27d0a7cb7d28e9150d2999aD
45f0406fbbb55abe1511ceade8ca9fb297ae44cce197166c9a3f70561dbffc30D
8246ba658ab0a84cdf2b467c142701ec560b9ced3db90dfd04a7275cb2636566D
301d479dffc9084746269cad6d9be379a3c01fafa139c9203aa5c98ca7e9d79eD
f4c0956c54c55adea5769904bb460f6ab64b017d31e9a73f0a047345be6dd6afD
6cc655263da0213df7eb5a2c6c63b5825361f55336855a67a7b33881d10ca955D
fc2d6ed7481cb42c62b4bd75126fc4237093c74ba7e87908a90815f672bdf45dD
b0179562abc1ff5d40c03661749ce4f7f4c7d58c428cecfc4a3711bfa98e6ec6D
c653aaa3759f6c65e6ccf1dafa36096bf4821f315dbf756943730947258100efD
54b72bac2daf97a8d1ba79e4288be55712b5b35027f2df547f3e0af93bd9b6a5D~
037e885e4b00fa8c73772c5a2e0f05aa735f04807e080c5819a8a15dade3d5dcD}
73cda0f598ca90fe3470940ed62663a7a5a1091731757b8e057fc929d3c1a209D|
1a5b2d18101ca9a398c7873900403ed4ffc7daf7fb801a9ce1649c3fafe185cf
SVbbVecJan Grulich <jgrulich@redhat.com> - 0.27.0-2\X)@- Minor improvements
  Resolves: bz#1652637\UeWJan Grulich <jgrulich@redhat.com> - 0.27.0-1\=@- Exiv2 0.27.0
  Resolves: bz#1652637pTaJan Grulich <jgrulich@redhat.com> - 0.26-3Z@- Fix uncontrolled recursion in image.cpp:Exiv2::Image::printIFDStructure() which can allow a
  remote attacker to cause a denial of service via a crafted tif file
  Resolves: bz#1548410ySaJan Grulich <jgrulich@redhat.com> - 0.26-2Z- Fix heap-based buffer over-read in Exiv2::Image::byteSwap4 in image.cpp
  Resolves: bz#1547207

  Fix heap-based buffer over-read in Exiv2::getULong function in types.cpp
  Resolves: bz#1545232\Ra[Jan Grulich <jgrulich@redhat.com> - 0.26-1YW@- Update to 0.26
  Resolves: bz#1420227KQ[?Daniel Mach <dmach@redhat.com> - 0.23-6RU- Mass rebuild 2014-01-24
0g(-0y]aJan Grulich <jgrulich@redhat.com> - 0.26-2Z- Fix heap-based buffer over-read in Exiv2::Image::byteSwap4 in image.cpp
  Resolves: bz#1547207

  Fix heap-based buffer over-read in Exiv2::getULong function in types.cpp
  Resolves: bz#1545232\\a[Jan Grulich <jgrulich@redhat.com> - 0.26-1YW@- Update to 0.26
  Resolves: bz#1420227K[[?Daniel Mach <dmach@redhat.com> - 0.23-6RU- Mass rebuild 2014-01-24KZ[?Daniel Mach <dmach@redhat.com> - 0.23-5Rk- Mass rebuild 2013-12-27YFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.23-4Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild"XeaJan Grulich <jgrulich@redhat.com> - 0.27.0-4a- Fix heap-based buffer overflow vulnerability in jp2image.cpp that may lead to DoS
  Resolves: bz#1990352WeGJan Grulich <jgrulich@redhat.com> - 0.27.0-3^K- Validate relationship of the total size to the offset to avoid crash
  Resolves: bz#1775695
"H	p"Kd[?Daniel Mach <dmach@redhat.com> - 0.23-5Rk- Mass rebuild 2013-12-27cFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.23-4Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild"beaJan Grulich <jgrulich@redhat.com> - 0.27.0-4a- Fix heap-based buffer overflow vulnerability in jp2image.cpp that may lead to DoS
  Resolves: bz#1990352aeGJan Grulich <jgrulich@redhat.com> - 0.27.0-3^K- Validate relationship of the total size to the offset to avoid crash
  Resolves: bz#1775695b`ecJan Grulich <jgrulich@redhat.com> - 0.27.0-2\X)@- Minor improvements
  Resolves: bz#1652637\_eWJan Grulich <jgrulich@redhat.com> - 0.27.0-1\=@- Exiv2 0.27.0
  Resolves: bz#1652637p^aJan Grulich <jgrulich@redhat.com> - 0.26-3Z@- Fix uncontrolled recursion in image.cpp:Exiv2::Image::printIFDStructure() which can allow a
  remote attacker to cause a denial of service via a crafted tif file
  Resolves: bz#1548410
SVbbjecJan Grulich <jgrulich@redhat.com> - 0.27.0-2\X)@- Minor improvements
  Resolves: bz#1652637\ieWJan Grulich <jgrulich@redhat.com> - 0.27.0-1\=@- Exiv2 0.27.0
  Resolves: bz#1652637phaJan Grulich <jgrulich@redhat.com> - 0.26-3Z@- Fix uncontrolled recursion in image.cpp:Exiv2::Image::printIFDStructure() which can allow a
  remote attacker to cause a denial of service via a crafted tif file
  Resolves: bz#1548410ygaJan Grulich <jgrulich@redhat.com> - 0.26-2Z- Fix heap-based buffer over-read in Exiv2::Image::byteSwap4 in image.cpp
  Resolves: bz#1547207

  Fix heap-based buffer over-read in Exiv2::getULong function in types.cpp
  Resolves: bz#1545232\fa[Jan Grulich <jgrulich@redhat.com> - 0.26-1YW@- Update to 0.26
  Resolves: bz#1420227Ke[?Daniel Mach <dmach@redhat.com> - 0.23-6RU- Mass rebuild 2014-01-24
0g(-0yqaJan Grulich <jgrulich@redhat.com> - 0.26-2Z- Fix heap-based buffer over-read in Exiv2::Image::byteSwap4 in image.cpp
  Resolves: bz#1547207

  Fix heap-based buffer over-read in Exiv2::getULong function in types.cpp
  Resolves: bz#1545232\pa[Jan Grulich <jgrulich@redhat.com> - 0.26-1YW@- Update to 0.26
  Resolves: bz#1420227Ko[?Daniel Mach <dmach@redhat.com> - 0.23-6RU- Mass rebuild 2014-01-24Kn[?Daniel Mach <dmach@redhat.com> - 0.23-5Rk- Mass rebuild 2013-12-27mFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.23-4Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild"leaJan Grulich <jgrulich@redhat.com> - 0.27.0-4a- Fix heap-based buffer overflow vulnerability in jp2image.cpp that may lead to DoS
  Resolves: bz#1990352keGJan Grulich <jgrulich@redhat.com> - 0.27.0-3^K- Validate relationship of the total size to the offset to avoid crash
  Resolves: bz#1775695
H	oSx[OJoe Orton <jorton@redhat.com> - 2.1.0-6Q@- fix "xmlwf -h" output (#948534)wFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.1.0-5Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild"veaJan Grulich <jgrulich@redhat.com> - 0.27.0-4a- Fix heap-based buffer overflow vulnerability in jp2image.cpp that may lead to DoS
  Resolves: bz#1990352ueGJan Grulich <jgrulich@redhat.com> - 0.27.0-3^K- Validate relationship of the total size to the offset to avoid crash
  Resolves: bz#1775695btecJan Grulich <jgrulich@redhat.com> - 0.27.0-2\X)@- Minor improvements
  Resolves: bz#1652637\seWJan Grulich <jgrulich@redhat.com> - 0.27.0-1\=@- Exiv2 0.27.0
  Resolves: bz#1652637praJan Grulich <jgrulich@redhat.com> - 0.26-3Z@- Fix uncontrolled recursion in image.cpp:Exiv2::Image::printIFDStructure() which can allow a
  remote attacker to cause a denial of service via a crafted tif file
  Resolves: bz#1548410
b	Qj~]{Joe Orton <jorton@redhat.com> - 2.1.0-12^- add security fixes for CVE-2018-20843, CVE-2019-15903W}]UJoe Orton <jorton@redhat.com> - 2.1.0-11]9- add security fix for CVE-2015-2716[|]]Joe Orton <jorton@redhat.com> - 2.1.0-10X6A- updated security fix for CVE-2016-0718V{[UJoe Orton <jorton@redhat.com> - 2.1.0-9X6@- add security fix for CVE-2016-0718Lz]?Daniel Mach <dmach@redhat.com> - 2.1.0-8RU- Mass rebuild 2014-01-24Ly]?Daniel Mach <dmach@redhat.com> - 2.1.0-7Rk- Mass rebuild 2013-12-27
ZZ"eaTomas Korbar <tkorbar@redhat.com> - 2.1.0-13b~- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
W>NWV[UJoe Orton <jorton@redhat.com> - 2.1.0-9X6@- add security fix for CVE-2016-0718L]?Daniel Mach <dmach@redhat.com> - 2.1.0-8RU- Mass rebuild 2014-01-24L]?Daniel Mach <dmach@redhat.com> - 2.1.0-7Rk- Mass rebuild 2013-12-27S[OJoe Orton <jorton@redhat.com> - 2.1.0-6Q@- fix "xmlwf -h" output (#948534)Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.1.0-5Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild>eTomas Korbar <tkorbar@redhat.com> - 2.1.0-14b8h- Fix multiple CVEs
- CVE-2022-25236 expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
- CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
- CVE-2022-25315 expat: integer overflow in storeRawNames()
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315
Hj]{Joe Orton <jorton@redhat.com> - 2.1.0-12^- add security fixes for CVE-2018-20843, CVE-2019-15903W]UJoe Orton <jorton@redhat.com> - 2.1.0-11]9- add security fix for CVE-2015-2716[]]Joe Orton <jorton@redhat.com> - 2.1.0-10X6A- updated security fix for CVE-2016-0718
ZZ"	eaTomas Korbar <tkorbar@redhat.com> - 2.1.0-13b~- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
9>J9W]UJoe Orton <jorton@redhat.com> - 2.1.0-11]9- add security fix for CVE-2015-2716[]]Joe Orton <jorton@redhat.com> - 2.1.0-10X6A- updated security fix for CVE-2016-0718V[UJoe Orton <jorton@redhat.com> - 2.1.0-9X6@- add security fix for CVE-2016-0718L
]?Daniel Mach <dmach@redhat.com> - 2.1.0-8RU- Mass rebuild 2014-01-24L]?Daniel Mach <dmach@redhat.com> - 2.1.0-7Rk- Mass rebuild 2013-12-27S[OJoe Orton <jorton@redhat.com> - 2.1.0-6Q@- fix "xmlwf -h" output (#948534)>
eTomas Korbar <tkorbar@redhat.com> - 2.1.0-14b8h- Fix multiple CVEs
- CVE-2022-25236 expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
- CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
- CVE-2022-25315 expat: integer overflow in storeRawNames()
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315
j]{Joe Orton <jorton@redhat.com> - 2.1.0-12^- add security fixes for CVE-2018-20843, CVE-2019-15903
ZZ"eaTomas Korbar <tkorbar@redhat.com> - 2.1.0-13b~- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
_>V_V[UJoe Orton <jorton@redhat.com> - 2.1.0-9X6@- add security fix for CVE-2016-0718L]?Daniel Mach <dmach@redhat.com> - 2.1.0-8RU- Mass rebuild 2014-01-24L]?Daniel Mach <dmach@redhat.com> - 2.1.0-7Rk- Mass rebuild 2013-12-27S[OJoe Orton <jorton@redhat.com> - 2.1.0-6Q@- fix "xmlwf -h" output (#948534)e9Tomas Korbar <tkorbar@redhat.com> - 2.1.0-15c:- Ensure raw tagnames are safe exiting internalEntityParser
- Resolves: CVE-2022-40674>eTomas Korbar <tkorbar@redhat.com> - 2.1.0-14b8h- Fix multiple CVEs
- CVE-2022-25236 expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
- CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
- CVE-2022-25315 expat: integer overflow in storeRawNames()
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315
Hj]{Joe Orton <jorton@redhat.com> - 2.1.0-12^- add security fixes for CVE-2018-20843, CVE-2019-15903W]UJoe Orton <jorton@redhat.com> - 2.1.0-11]9- add security fix for CVE-2015-2716[]]Joe Orton <jorton@redhat.com> - 2.1.0-10X6A- updated security fix for CVE-2016-0718
ZZ"eaTomas Korbar <tkorbar@redhat.com> - 2.1.0-13b~- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
>mL"]?Daniel Mach <dmach@redhat.com> - 2.1.0-8RU- Mass rebuild 2014-01-24L!]?Daniel Mach <dmach@redhat.com> - 2.1.0-7Rk- Mass rebuild 2013-12-27S [OJoe Orton <jorton@redhat.com> - 2.1.0-6Q@- fix "xmlwf -h" output (#948534)Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.1.0-5Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuilde9Tomas Korbar <tkorbar@redhat.com> - 2.1.0-15c:- Ensure raw tagnames are safe exiting internalEntityParser
- Resolves: CVE-2022-40674>eTomas Korbar <tkorbar@redhat.com> - 2.1.0-14b8h- Fix multiple CVEs
- CVE-2022-25236 expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
- CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
- CVE-2022-25315 expat: integer overflow in storeRawNames()
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315
Ij&]{Joe Orton <jorton@redhat.com> - 2.1.0-12^- add security fixes for CVE-2018-20843, CVE-2019-15903W%]UJoe Orton <jorton@redhat.com> - 2.1.0-11]9- add security fix for CVE-2015-2716[$]]Joe Orton <jorton@redhat.com> - 2.1.0-10X6A- updated security fix for CVE-2016-0718V#[UJoe Orton <jorton@redhat.com> - 2.1.0-9X6@- add security fix for CVE-2016-0718
ZZ"'eaTomas Korbar <tkorbar@redhat.com> - 2.1.0-13b~- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
W>NWV-[UJoe Orton <jorton@redhat.com> - 2.1.0-9X6@- add security fix for CVE-2016-0718L,]?Daniel Mach <dmach@redhat.com> - 2.1.0-8RU- Mass rebuild 2014-01-24L+]?Daniel Mach <dmach@redhat.com> - 2.1.0-7Rk- Mass rebuild 2013-12-27S*[OJoe Orton <jorton@redhat.com> - 2.1.0-6Q@- fix "xmlwf -h" output (#948534))Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.1.0-5Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild>(eTomas Korbar <tkorbar@redhat.com> - 2.1.0-14b8h- Fix multiple CVEs
- CVE-2022-25236 expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
- CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
- CVE-2022-25315 expat: integer overflow in storeRawNames()
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315
Hj0]{Joe Orton <jorton@redhat.com> - 2.1.0-12^- add security fixes for CVE-2018-20843, CVE-2019-15903W/]UJoe Orton <jorton@redhat.com> - 2.1.0-11]9- add security fix for CVE-2015-2716[.]]Joe Orton <jorton@redhat.com> - 2.1.0-10X6A- updated security fix for CVE-2016-0718
ZZ"1eaTomas Korbar <tkorbar@redhat.com> - 2.1.0-13b~- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
9>J9W8]UJoe Orton <jorton@redhat.com> - 2.1.0-11]9- add security fix for CVE-2015-2716[7]]Joe Orton <jorton@redhat.com> - 2.1.0-10X6A- updated security fix for CVE-2016-0718V6[UJoe Orton <jorton@redhat.com> - 2.1.0-9X6@- add security fix for CVE-2016-0718L5]?Daniel Mach <dmach@redhat.com> - 2.1.0-8RU- Mass rebuild 2014-01-24L4]?Daniel Mach <dmach@redhat.com> - 2.1.0-7Rk- Mass rebuild 2013-12-27S3[OJoe Orton <jorton@redhat.com> - 2.1.0-6Q@- fix "xmlwf -h" output (#948534)>2eTomas Korbar <tkorbar@redhat.com> - 2.1.0-14b8h- Fix multiple CVEs
- CVE-2022-25236 expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
- CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
- CVE-2022-25315 expat: integer overflow in storeRawNames()
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315
j9]{Joe Orton <jorton@redhat.com> - 2.1.0-12^- add security fixes for CVE-2018-20843, CVE-2019-15903
ZZ":eaTomas Korbar <tkorbar@redhat.com> - 2.1.0-13b~- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
_>V_V@[UJoe Orton <jorton@redhat.com> - 2.1.0-9X6@- add security fix for CVE-2016-0718L?]?Daniel Mach <dmach@redhat.com> - 2.1.0-8RU- Mass rebuild 2014-01-24L>]?Daniel Mach <dmach@redhat.com> - 2.1.0-7Rk- Mass rebuild 2013-12-27S=[OJoe Orton <jorton@redhat.com> - 2.1.0-6Q@- fix "xmlwf -h" output (#948534)<e9Tomas Korbar <tkorbar@redhat.com> - 2.1.0-15c:- Ensure raw tagnames are safe exiting internalEntityParser
- Resolves: CVE-2022-40674>;eTomas Korbar <tkorbar@redhat.com> - 2.1.0-14b8h- Fix multiple CVEs
- CVE-2022-25236 expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
- CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
- CVE-2022-25315 expat: integer overflow in storeRawNames()
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315
HjC]{Joe Orton <jorton@redhat.com> - 2.1.0-12^- add security fixes for CVE-2018-20843, CVE-2019-15903WB]UJoe Orton <jorton@redhat.com> - 2.1.0-11]9- add security fix for CVE-2015-2716[A]]Joe Orton <jorton@redhat.com> - 2.1.0-10X6A- updated security fix for CVE-2016-0718
ZZ"DeaTomas Korbar <tkorbar@redhat.com> - 2.1.0-13b~- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
>mLJ]?Daniel Mach <dmach@redhat.com> - 2.1.0-8RU- Mass rebuild 2014-01-24LI]?Daniel Mach <dmach@redhat.com> - 2.1.0-7Rk- Mass rebuild 2013-12-27SH[OJoe Orton <jorton@redhat.com> - 2.1.0-6Q@- fix "xmlwf -h" output (#948534)GFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.1.0-5Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildFe9Tomas Korbar <tkorbar@redhat.com> - 2.1.0-15c:- Ensure raw tagnames are safe exiting internalEntityParser
- Resolves: CVE-2022-40674>EeTomas Korbar <tkorbar@redhat.com> - 2.1.0-14b8h- Fix multiple CVEs
- CVE-2022-25236 expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
- CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
- CVE-2022-25315 expat: integer overflow in storeRawNames()
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315
IjN]{Joe Orton <jorton@redhat.com> - 2.1.0-12^- add security fixes for CVE-2018-20843, CVE-2019-15903WM]UJoe Orton <jorton@redhat.com> - 2.1.0-11]9- add security fix for CVE-2015-2716[L]]Joe Orton <jorton@redhat.com> - 2.1.0-10X6A- updated security fix for CVE-2016-0718VK[UJoe Orton <jorton@redhat.com> - 2.1.0-9X6@- add security fix for CVE-2016-0718
ZZ"OeaTomas Korbar <tkorbar@redhat.com> - 2.1.0-13b~- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
W>NWVU[U	Joe Orton <jorton@redhat.com> - 2.1.0-9X6@- add security fix for CVE-2016-0718LT]?	Daniel Mach <dmach@redhat.com> - 2.1.0-8RU- Mass rebuild 2014-01-24LS]?	Daniel Mach <dmach@redhat.com> - 2.1.0-7Rk- Mass rebuild 2013-12-27SR[O	Joe Orton <jorton@redhat.com> - 2.1.0-6Q@- fix "xmlwf -h" output (#948534)Q	Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.1.0-5Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild>PeTomas Korbar <tkorbar@redhat.com> - 2.1.0-14b8h- Fix multiple CVEs
- CVE-2022-25236 expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
- CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
- CVE-2022-25315 expat: integer overflow in storeRawNames()
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315

er+V:eD
e4434d6372a44237428f390b21eaa263d38ebe585fcde7c9b6d093bd6a53f942D
55a15d25343aa48f6f67cbbb7365207f4430960b97fe22eea6521df9ef5f6e1eD
997876dc6dace25c6299e9ca1dc76b8112d4862b054ac67c11bcfa1e81c637efD
36e226643adb16e51005fd729514451221b0570727d946df70bc555084b1ab43D
c59613f8305583361be758cf7921fe48cedfaca536f354535c5dca03087c3798D
c102608096eb8bfc89f563c1a82e55812f85dc764c578fc98b29fe740b014b88D
bb4a0d5f27950f8712ba44e0d94dac84d24f409c0064a28dd7e64dab38dea9bcD
ad0cdb4681378d6768d0ba8ff62f05cf6459eb32070c81c7d3eec65c844a8fa5D

7202bdb3eb9b58bc979d8ec45159b6e39ea0ff80df19efb9cc6274a852beee11D
8552fe474d6c38b9a301d6273b81897005c2a518b97ad149df81dca168a8bdc6D
77a2ace1d206cdce59078a04e1d50602e60fa9783490a87d7d894bfb57c1904cD

38165265e6956a27cc026b542a5b84342b4e8d479263713e10c9a0b0871d9705D	
46c46ba8573d8f101c53fe10179a66e853ec151d66f5dfb686fb60c5e75aa610
HjX]{	Joe Orton <jorton@redhat.com> - 2.1.0-12^- add security fixes for CVE-2018-20843, CVE-2019-15903WW]U	Joe Orton <jorton@redhat.com> - 2.1.0-11]9- add security fix for CVE-2015-2716[V]]	Joe Orton <jorton@redhat.com> - 2.1.0-10X6A- updated security fix for CVE-2016-0718
ZZ"Yea	Tomas Korbar <tkorbar@redhat.com> - 2.1.0-13b~- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
9>J9W`]U
Joe Orton <jorton@redhat.com> - 2.1.0-11]9- add security fix for CVE-2015-2716[_]]
Joe Orton <jorton@redhat.com> - 2.1.0-10X6A- updated security fix for CVE-2016-0718V^[U
Joe Orton <jorton@redhat.com> - 2.1.0-9X6@- add security fix for CVE-2016-0718L]]?
Daniel Mach <dmach@redhat.com> - 2.1.0-8RU- Mass rebuild 2014-01-24L\]?
Daniel Mach <dmach@redhat.com> - 2.1.0-7Rk- Mass rebuild 2013-12-27S[[O
Joe Orton <jorton@redhat.com> - 2.1.0-6Q@- fix "xmlwf -h" output (#948534)>Ze	Tomas Korbar <tkorbar@redhat.com> - 2.1.0-14b8h- Fix multiple CVEs
- CVE-2022-25236 expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
- CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
- CVE-2022-25315 expat: integer overflow in storeRawNames()
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315
ja]{
Joe Orton <jorton@redhat.com> - 2.1.0-12^- add security fixes for CVE-2018-20843, CVE-2019-15903
ZZ"bea
Tomas Korbar <tkorbar@redhat.com> - 2.1.0-13b~- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
_>V_Vh[UJoe Orton <jorton@redhat.com> - 2.1.0-9X6@- add security fix for CVE-2016-0718Lg]?Daniel Mach <dmach@redhat.com> - 2.1.0-8RU- Mass rebuild 2014-01-24Lf]?Daniel Mach <dmach@redhat.com> - 2.1.0-7Rk- Mass rebuild 2013-12-27Se[OJoe Orton <jorton@redhat.com> - 2.1.0-6Q@- fix "xmlwf -h" output (#948534)de9
Tomas Korbar <tkorbar@redhat.com> - 2.1.0-15c:- Ensure raw tagnames are safe exiting internalEntityParser
- Resolves: CVE-2022-40674>ce
Tomas Korbar <tkorbar@redhat.com> - 2.1.0-14b8h- Fix multiple CVEs
- CVE-2022-25236 expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
- CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
- CVE-2022-25315 expat: integer overflow in storeRawNames()
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315
Hjk]{Joe Orton <jorton@redhat.com> - 2.1.0-12^- add security fixes for CVE-2018-20843, CVE-2019-15903Wj]UJoe Orton <jorton@redhat.com> - 2.1.0-11]9- add security fix for CVE-2015-2716[i]]Joe Orton <jorton@redhat.com> - 2.1.0-10X6A- updated security fix for CVE-2016-0718
ZZ"leaTomas Korbar <tkorbar@redhat.com> - 2.1.0-13b~- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
Y>YOoq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784ne9Tomas Korbar <tkorbar@redhat.com> - 2.1.0-15c:- Ensure raw tagnames are safe exiting internalEntityParser
- Resolves: CVE-2022-40674>meTomas Korbar <tkorbar@redhat.com> - 2.1.0-14b8h- Fix multiple CVEs
- CVE-2022-25236 expat: namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
- CVE-2022-25235 expat: malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
- CVE-2022-25315 expat: integer overflow in storeRawNames()
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315
:u#:uqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YtqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058sqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561rqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lqq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-pqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818
Eq4ELzq)
Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-yq
Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818xu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149wuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024vq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
~q'
Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289~q
Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y}qC
Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058|q
Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561{q
Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205
^/^qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-|u
Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-
Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149u
Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
KvK9	uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
locYqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
!~!{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
		q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189
9/29w u}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
F"RF%qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561$qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L#q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-"qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O!q/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784
A#A*u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149)uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024(q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289'qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y&qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
:u#:0qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y/qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058.qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L,q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-+qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818
Qq4!QL5q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-|4uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#19057353u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#185011492uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#18620241q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
~:q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#18322899qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y8qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#16540587qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#18275616qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205
&/2&@qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561?qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{>uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|=uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735<u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149;uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#AEu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149DuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Cq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289BqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YAqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
KqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YJqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058IqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|HuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{GuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|FuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|QuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{PuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|OuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Nu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149MuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Lq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VVqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LUq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-TqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818OSq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wRu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759

er+V:eD"
457da3dc935ceedbf369f8d8283038086c61d7ec599b6b13c34f1a9eb692decdD!
f2bf2828a9c0dfda573e370c7710e37259fb9041de3d51ef97b7cd65188789a9D 
805b144f9365a51694ca9ecf28482dd714b37f78fa08e3a4a7a5aa22da4216deD
757772969a2b13e5983aef925c31b673696df5c322b359714f2a89267929bf4eD
0cd349e9faa4208c5a06dd623c32419cde907327603062ef0197ae238ecf9cb1D
815665d02d2dd24faf81af70e9152d3a62a47d616ae070372b69b3ce7b0c1e95D
dbc118d3ccfcbb7b3059ad8a684e25485e0745d8f682f5b8e2a16c1ab4a3100bD
22ad74d75ec657ae1c2e0ef0ec2331caf9bbe77cd9d4af628f4350d8891164d0D
42e5dee7b0556011cb8bdc92961b584ecf210268b03c4e68df01ba36dc1f30e1D
0c50466e187899042f37e621ad418348afddcf8a0b1ef74a9c42573da5425ecaD
2c656f5e90d00ae998a2b2a6a9d7caaa9328030aefb87a1ce161d941af33182eD
314a81ff92e3f3500ef8c7b95dd418bbf2ed11ea8d65031d6e8de42e8e43ab73D
5ec01f00815a52d61439e813a4a0958fc52c9c59500edb2e2fabac3c7fe068c8
KvK9[uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Zq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289YqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YXqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058WqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YaqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058`qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561_qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L^q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-]qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818\u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|fuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735eu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149duOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024cq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289bqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6lq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289kqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YjqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058iqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561hqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lgq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&rqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{puOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|ouOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735nu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149muOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Awu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149vuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024uq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289tqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YsqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
}qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y|qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058{qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|zuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{yuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|xuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024~q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Oq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9
uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y
qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058	qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&$qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561#qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{"uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|!uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735 u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#A)u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149(uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024'q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289&qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y%qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
/qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y.qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|,uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{+uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|*uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|5uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{4uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|3uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#19057352u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#185011491uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#18620240q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3V:q Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L9q) Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-8q Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O7q/ Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w6u}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9?u Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024>q' Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289=q Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y<qC Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058;q Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561ofjflrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|Y`abhklouz	 %*	0
5:@
EKQV[aflrw}
$ )!/"5#:$?&E'J(P)V+[,a-g.l/q0w1|234
5678#9):.;4<:=?>E?K@PAUB[D`EfFlGqHwI}JKL
MNOP#Q)R/S4T9U?VDWJXPYUZ[\a]f^k_q`va|bcd
efgh#i(
(l(YEqC!Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058Dq!Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561Cq!Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LBq)!Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-Aq!Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818@u- Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|Ju!Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Iu-!Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149Hu!Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Gq'!Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289Fq!Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6Pq'"Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289Oq"Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YNqC"Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058Mq"Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561Lq"Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LKq)"Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&Vq#Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561Uq#Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{Tu"Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|Su"Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Ru-"Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149Qu"Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024

er+V:eD/
c7b50fc58609f6e4057703fe1bb83fe6a7c2c9ca068b534e97ac8c7a78e4c8f4D.
6bca052cf755c10a9a15dd05c1eba4a527bd36e88354bfc05d9a678661d7d827D-
4bec36ddbf5963ce6aa8fffba7900ae727da0978060620165937170bee608f51D,
e899e4be36103040ff23d743f3f3ec0eaf8bddfc2604aee19b9ab12e587d87e8D+
f4df6c727e6e445ddca7fe286fc32ec9aed6c8a3fddf42faf905580926d1117aD*
e0a4a368252a2466ddc2b35c58646282829e8b14ff12d3237645aab8609ca5c2D)
5f5c399567e8888b62c997c08412e019f0c5ddf8dd28c78cfa0128928dcd853eD(
662a9d17ec8e137ca36a020dc0efbe8ae088dfd2e1dab2436cf4496bf31f3c75D'
b6ff39e8375e47ff8d8c06f442a8b78add02677aa81e66db47255f6469357012D&
293f6c4af159003426f1ce9255f1bc981d24fe6d1e848489c5b960eb8d9b7e85D%
e31ccbd3696503d01bf17eb08d66c852a75d233ea3040b15ee14477f72f2013dD$
84534b4e8a9f57e1d6cedeafa786721a479e210dc0b2bc07dd005e62c961e69eD#
575a71de43d9ee448ec1678d6e6396b7c3cc5de05454e3681e5a3f900c5dc4bc
A#A[u-#Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149Zu#Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Yq'#Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289Xq#Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YWqC#Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
aq$Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y`qC$Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058_q$Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|^u#Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{]u#Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|\u#Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|gu$Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{fu$Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|eu$Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735du-$Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149cu$Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024bq'$Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3Vlq%Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lkq)%Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-jq%Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Oiq/%Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784whu}$Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9qu%Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024pq'%Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289oq%Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YnqC%Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058mq%Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YwqC&Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058vq&Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561uq&Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Ltq)&Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-sq&Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818ru-%Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~||u&Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735{u-&Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149zu&Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024yq'&Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289xq&Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6q''Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqC'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561~q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L}q)'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&q(Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561q(Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{u'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|u'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149u'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#A
u-(Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149u(Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'(Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
q(Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y	qC(Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqC)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|u(Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{u(Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|u(Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|u)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{u)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|u)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149u)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q')Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3Vq*Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)*Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-q*Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Oq/*Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wu})Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9#u*Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024"q'*Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289!q*Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y qC*Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058q*Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y)qC+Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058(q+Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561'q+Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L&q)+Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-%q+Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818$u-*Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|.u+Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735-u-+Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149,u+Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024+q'+Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289*q+Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G64q',Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#18322893q,Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y2qC,Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#16540581q,Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#18275610q,Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L/q),Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&:q-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#18275619q-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{8u,Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|7u,Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#19057356u-,Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#185011495u,Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#A?u--Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149>u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024=q'-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289<q-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y;qC-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
Eq.Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YDqC.Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058Cq.Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|Bu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{Au-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|@u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|Ku.Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{Ju.Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|Iu.Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Hu-.Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149Gu.Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Fq'.Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VPq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LOq)/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-Nq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818OMq//Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wLu}.Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9Uu/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Tq'/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289Sq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YRqC/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058Qq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y[qC0Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058Zq0Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561Yq0Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LXq)0Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-Wq0Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Vu-/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114

er+V:eD<
9f8abcf48b89d3171a189ec5449a97b802ba649f300ad32218c8310d9ae89caaD;
63037d9ff075fdac3127a74533eb74eaba6a3dd7a6b714768f44507fd8962d88D:
e03fb473c4111b34ab231b026b46e185aba267a54abad312d1fc4be2fe1a79baD9
ddf36ad1ce4578114e5a65661c1a8de7696ede0b51d5d3a2d8ac551164a4d7ccD8
4bdf983ae009a8ef897188d860d0535c00a5071923c33261e644570fa2d5cb9dD7
7b0c0a663c4992773363ce6c177e9d75ad05e8f8ee19c76a4d1f71fdd6a97da0D6
a4e1b36b41fc592139af224d55fdf5ffecd2f6b528dd8ae73388911df76a9f02D5
f646388701bda1badf96a2fb3864cff8cec8c983277a87af8b050a51147a03afD4
bf7e4ecac92c09b957b31c3b99fe5124cb6807feecce32ee6137fa893ce3daecD3
056e7fe3c5a00be53248709c74120df1d6c073ef1b7b7beba63ff41d48f35c17D2
0c17cb1415294598f297a58396280f055f0f3258f080b1ab697bfe04bbe0008dD1
4d77c6049313415fe1c4aab3e4ee43727167a46b87e28723f6c79f4bffef3607D0
e2a3860deceb4f2f2ddc8390def1eb021196fee5ef075702ec1588374818efa6
~|`u0Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735_u-0Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149^u0Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024]q'0Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289\q0Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6fq'1Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289eq1Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YdqC1Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058cq1Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561bq1Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Laq)1Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&lq2Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561kq2Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{ju1Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|iu1Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735hu-1Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149gu1Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Aqu-2Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149pu2Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024oq'2Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289nq2Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YmqC2Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
wq3Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YvqC3Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058uq3Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|tu2Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{su2Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|ru2Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|}u3Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{|u3Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|{u3Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735zu-3Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149yu3Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024xq'3Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3Vq4Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)4Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-q4Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Oq/4Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w~u}3Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9u4Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'4Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289q4Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqC4Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058q4Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y
qC5Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058q5Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561q5Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L
q)5Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-	q5Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818u-4Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|u5Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-5Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149u5Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'5Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289q5Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6q'6Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289q6Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqC6Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058q6Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561q6Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)6Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&q7Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561q7Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{u6Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|u6Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-6Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149u6Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#A#u-7Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149"u7Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024!q'7Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289 q7Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqC7Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
)q8Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y(qC8Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058'q8Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|&u7Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{%u7Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|$u7Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|/u8Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{.u8Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|-u8Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735,u-8Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149+u8Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024*q'8Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3V4q9Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L3q)9Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-2q9Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O1q/9Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w0u}8Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK99u9Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#18620248q'9Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#18322897q9Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y6qC9Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#16540585q9Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y?qC:Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058>q:Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561=q:Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L<q):Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-;q:Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818:u-9Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|Du:Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Cu-:Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149Bu:Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Aq':Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289@q:Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6Jq';Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289Iq;Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YHqC;Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058Gq;Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561Fq;Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LEq);Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&Pq<Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561Oq<Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{Nu;Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|Mu;Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Lu-;Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149Ku;Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#AUu-<Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149Tu<Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Sq'<Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289Rq<Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YQqC<Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
[q=Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YZqC=Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058Yq=Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|Xu<Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{Wu<Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|Vu<Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735

er+V:eDI
ed6e07b307de61a56b4041aaba7661b6fcdeb599402390671b3db4d8c0b4cdfcDH
8f01b6b2a6ce4e4129d3b25510ee332c113e0f671df54f56ad2dff8e711a11b8DG
eb7bebdbd517434195d041324099366ce234dfd58929430224320ff59b866c8eDF
864bee28e84214e17a2569dc4782fe389e64424fc470fc80157b86f2bdf0df03DE
2ebe4dd6652fe19a01c6576bd236175a5952205b51f6f3c76a25a539af114ca1DD
e818d4e04d72d3014d26343beb92384fad7a4c394dde4f7dc2a541d0416f569fDC
132ce82de39a18ad1be89af9ce56bdf2cf2471eddae86a469dfbdaef42478652DB
55db8fa1e758d5038aa9f74ed8982f1b73505b989a9643ef81f8b704f975fb8cDA
2eb32fa5c1642715eed3bff00d204b72790f716770349e1a3307229ec9f1a88aD@
4badd67c65c46b09cdfb999c67dcf07efbec0e2b1b5ee21318fb415d90aff27eD?
1b7c83c31498a1d9eec34b76e89035fa039c4d34cdfb507851df956c9a5cb86bD>
8901005d391fcf6247d95caeaae9763898d0d5a0e8da308e73380bbdefdbbb1cD=
90b4df9d1f42ba4c9d6ed5a171805bd3aa1ab73ca030c78d62b088ffd716ff81
$q4!$|au=Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{`u=Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|_u=Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735^u-=Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149]u=Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024\q'=Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3Vfq>Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Leq)>Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-dq>Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Ocq/>Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wbu}=Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9ku>Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024jq'>Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289iq>Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YhqC>Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058gq>Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YqqC?Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058pq?Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561oq?Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lnq)?Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-mq?Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818lu->Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|vu?Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735uu-?Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149tu?Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024sq'?Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289rq?Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6|q'@Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289{q@Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YzqC@Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058yq@Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561xq@Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lwq)@Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&qAOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qAOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{u@Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|u@Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735~u-@Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149}u@Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Au-AOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uAOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'AOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qAOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCAOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058

qBOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCBOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qBOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|
uAOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{	uAOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uAOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|uBOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uBOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uBOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-BOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uBOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'BOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)COyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Oq/COyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wu}BOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9uCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'COyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y#qCDOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058"qDOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561!qDOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L q)DOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qDOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818u-COyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|(uDOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735'u-DOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149&uDOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024%q'DOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289$qDOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6.q'EOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289-qEOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y,qCEOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058+qEOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561*qEOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L)q)EOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&4qFOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#18275613qFOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{2uEOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|1uEOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#19057350u-EOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149/uEOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#A9u-FOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#185011498uFOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#18620247q'FOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#18322896qFOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y5qCFOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
?qGOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y>qCGOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058=qGOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|<uFOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{;uFOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|:uFOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|EuGOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{DuGOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|CuGOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Bu-GOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149AuGOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024@q'GOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VJqHOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LIq)HOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-HqHOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818OGq/HOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wFu}GOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9OuHOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Nq'HOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289MqHOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YLqCHOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058KqHOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YUqCIOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058TqIOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561SqIOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LRq)IOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-QqIOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Pu-HOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|ZuIOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Yu-IOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149XuIOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Wq'IOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289VqIOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738

er+V:eDV
147dc35e6fff3dff6a81de8b9ddae7411d557a2f80bb93a6b4040fde544b5c73DU
0c0ba36a5e8704ab304024f5f4bc9616e4592da8ef6293f27ee584cd13805973DT
176d124a27956ac315b44b6b42bb13fe2fa7702d805ae7b58731b8d634bc0a2eDS
34210a0ec25b1987cb28b7719bb7ab7d7eff1adb56711dc0f4835ba89256cc82DR
bf1f40d6279d065b649f886d586e1bc6bb518de89df420459f9ba36c8a3f403aDQ
129f6f9ff00bcf11fa14cab3ec12d80bf9b9612f1194adc7aaacead1b3e7b651DP
4935d172a32f8bef9fd07236702a965e4d14a6e86b534e6c52fbe4aad6047e03DO
87fc214b49a5aba9c5d113e739d9654287b4a0272123ff8eead1a12b7c845ec3DN
4e0fff288896ea81f4c997cb6ce0c357c6515c6987555c53ddbd8c800177f083DM
a8c33d4ab95933b150aa784ba9bae1d03d59e6633afd229fc51bafff1df0e892DL
e36b9d803bc4c2cac122e737759eaaf8944848895c016d80232d05a405a97587DK
e7be65394477619c3bc276a472efa4a7f642dce66c5dee203826d0391223391aDJ
5d10762096ebcbd7efdc8eecb2d15ca2b35d49c6fbf417a3f85b555ac622eafc
60$G6`q'JOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289_qJOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y^qCJOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058]qJOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561\qJOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L[q)JOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&fqKOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561eqKOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{duJOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|cuJOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735bu-JOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149auJOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Aku-KOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149juKOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024iq'KOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289hqKOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YgqCKOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
qqLOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YpqCLOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058oqLOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|nuKOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{muKOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|luKOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|wuLOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{vuLOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uuLOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735tu-LOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149suLOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024rq'LOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3V|qMOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L{q)MOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-zqMOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Oyq/MOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wxu}LOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9uMOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'MOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qMOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y~qCMOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058}qMOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YqCNOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qNOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qNOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)NOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qNOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818u-MOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|uNOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-NOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149
uNOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024	q'NOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qNOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6q'OOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L
q)OOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&qPOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qPOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{uOOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-OOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Au-POyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uPOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'POyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qPOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCPOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
#qQOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y"qCQOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058!qQOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561| uPOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uPOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uPOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|)uQOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{(uQOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|'uQOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735&u-QOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149%uQOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024$q'QOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3V.qROyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L-q)ROyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-,qROyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O+q/ROyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w*u}QOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK93uROyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#18620242q'ROyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#18322891qROyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y0qCROyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058/qROyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y9qCSOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#16540588qSOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#18275617qSOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L6q)SOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-5qSOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#18018184u-ROyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|>uSOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735=u-SOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149<uSOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024;q'SOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289:qSOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6Dq'TOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289CqTOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YBqCTOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058AqTOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561@qTOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L?q)TOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&JqUOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561IqUOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{HuTOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|GuTOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Fu-TOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149EuTOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#AOu-UOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149NuUOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Mq'UOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289LqUOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YKqCUOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
UqVOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YTqCVOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058SqVOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|RuUOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{QuUOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|PuUOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|[uVOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{ZuVOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|YuVOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Xu-VOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149WuVOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Vq'VOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3V`qWOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L_q)WOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-^qWOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O]q/WOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w\u}VOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759

er+V:eDc
31dbae1dc23e561a169170b6a4e76e5abb65227590e305195a2a4c4709cc4a0dDb
6fc93f49bcfb356742bd0f053b32fc44739f52e356d8575874ed5e03d9fd09baDa
7d006c10e1e850ab6583783df33de8d968fa27fd47068c159bb2bac55c7eeecaD`
222d1cb4f63704dc1cb456a7733ac13be509de7210e4f3ef68095502f871ad42D_
889cf274fa9d2dc353f72daefeafeef0bab8bbc22a11e69f5009602f524dfc5fD^
b023cc7bb4beba93c1fa4b4ea3d00f85891637ae3f1692b51863007e799f93e4D]
8649585113a6705fe59be338b82b0ec406c0c3351b940dbebdffabd40fbc2eb5D\
c24fe30d66c39a6dc7e1701a8503f46d3e747baaf032761258334310ad79e035D[
9952c1ad9640539f832b2907ecca1438442f4d21c5b1159a6b061b54d0245407DZ
600d4f94f14cc026544d704f5a8190f1e11d4020dcff350bfca31fef4c037731DY
ee225d31e25d3fd9c6524bed27748c75c0944037288a89578e3005fb2eedea8fDX
b2a7339af908b8ee4bf1f85d0d58404c6e69e1311f16a5ce08f7c4e01629bac6DW
3c80748d03286542b429491e9861564380252fcbcd1d92283ddfa799fb2dc3f5
KvK9euWOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024dq'WOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289cqWOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YbqCWOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058aqWOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YkqCXOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058jqXOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561iqXOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lhq)XOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-gqXOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818fu-WOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|puXOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735ou-XOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149nuXOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024mq'XOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289lqXOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6vq'YOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289uqYOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YtqCYOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058sqYOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561rqYOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lqq)YOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&|qZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561{qZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{zuYOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|yuYOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735xu-YOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149wuYOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Au-ZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'ZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289~qZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y}qCZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
q[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqC[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058q[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|uZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|
u[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{u[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|u[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
u-[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149	u[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3Vq\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-q\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Oq/\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wu}[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9u\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289q\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqC\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058q\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YqC]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058q]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561q]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-q]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818u-\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|"u]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735!u-]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149 u]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q']Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289q]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6(q'^Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289'q^Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y&qC^Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058%q^Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561$q^Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L#q)^Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&.q_Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561-q_Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{,u^Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|+u^Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735*u-^Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149)u^Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024offlrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|k4l9m?nEoJpOqUrZt`ufvkwqxwy|z{|}~#).39>DJOU[`ekpv|
"(.39?DIOTZ`ekqv{#(-38>DIOUZ_ejpv{"(-39>CINTZ_ekpu{
A#A3u-_Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#185011492u_Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#18620241q'_Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#18322890q_Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y/qC_Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
9q`Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y8qC`Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#16540587q`Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|6u_Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{5u_Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|4u_Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|?u`Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{>u`Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|=u`Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735<u-`Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149;u`Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024:q'`Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VDqaOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LCq)aOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-BqaOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818OAq/aOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w@u}`Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9IuaOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Hq'aOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289GqaOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YFqCaOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058EqaOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YOqCbOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058NqbOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561MqbOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LLq)bOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-KqbOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Ju-aOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|TubOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Su-bOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149RubOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Qq'bOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289PqbOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6Zq'cOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289YqcOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YXqCcOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058WqcOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561VqcOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LUq)cOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&`qdOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561_qdOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{^ucOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|]ucOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735\u-cOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149[ucOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024

er+V:eDp
47ba59d4b1cb5b673b1229b14f41032935be9d093380d4ebda5b7a3a020d1829Do
c19464cde9f5e6924a75e43dc5a5f2a6f67fe7b180bebf78fe28c2a9ea75b38aDn
733cd7b64f33a955dabc853a4b1cd0c8c37bf1e8e726fc0bacb1d1ce4472cea3Dm
b0a39d51fd2f8d6d5a8f011e24a249847065815606a7f38e2041f4b496cc0190Dl
a0725d3676ffa6a24b4686e544f68d9c21b869c274d28cebfafb3c70638c371eDk
bba4318d019ae161e780b129f85d5ab91b299e3b9745f99a659fc52dacdfb221Dj
6151436b0cdfffbc9de946bc989ec92ce8de7794357a065c433e0c8dfd3e7fdbDi
7f851a8769285e3f9758a4eaf850aac198635f11095424df455837066af7c141Dh
8dbf315b824ef3ed709ed82b3c42515cc6137b6f4eaf95ccff91f5d362b86985Dg
a1970a5fc923219ddca4fa8d05e7f29ee858edf46448313a44734fb4d4c4149dDf
22e3e72ea0793e34fa431ce4f6c77af3460b1cd5e67558a3b644f1e438900d99De
42ab3de394252ea2575955dde550d26c4c2d82245f48145c1880b3eee1f049e5Dd
f313883838c79487308bec6209cc25ea688f77759c6bbdb331c4237999334033
A#Aeu-dOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149dudOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024cq'dOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289bqdOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YaqCdOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
kqeOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YjqCeOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058iqeOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|hudOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{gudOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|fudOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|queOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{pueOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|oueOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735nu-eOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149mueOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024lq'eOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VvqfOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Luq)fOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-tqfOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Osq/fOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wru}eOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9{ufOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024zq'fOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289yqfOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YxqCfOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058wqfOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YqCgOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qgOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qgOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L~q)gOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-}qgOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818|u-fOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|ugOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-gOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149ugOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'gOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qgOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6q'hOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qhOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y
qChOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058	qhOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qhOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)hOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&qiOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qiOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{uhOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uhOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-hOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149
uhOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Au-iOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uiOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'iOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qiOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCiOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
qjOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCjOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qjOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|uiOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uiOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uiOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|#ujOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{"ujOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|!ujOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735 u-jOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149ujOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'jOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3V(qkOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L'q)kOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-&qkOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O%q/kOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w$u}jOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9-ukOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024,q'kOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289+qkOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y*qCkOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058)qkOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y3qClOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#16540582qlOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#18275611qlOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L0q)lOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-/qlOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818.u-kOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|8ulOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#19057357u-lOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#185011496ulOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#18620245q'lOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#18322894qlOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6>q'mOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289=qmOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y<qCmOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058;qmOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561:qmOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L9q)mOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&DqnOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561CqnOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{BumOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|AumOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735@u-mOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149?umOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#AIu-nOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149HunOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Gq'nOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289FqnOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YEqCnOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
OqoOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YNqCoOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058MqoOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|LunOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{KunOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|JunOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|UuoOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{TuoOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|SuoOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Ru-oOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149QuoOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Pq'oOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VZqpOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LYq)pOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-XqpOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818OWq/pOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wVu}oOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9_upOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024^q'pOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289]qpOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y\qCpOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058[qpOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YeqCqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058dqqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561cqqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lbq)qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-aqqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818`u-pOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114

er+V:eD}
0fa4711e307981d6c9174ab9d2a6a3091cae2a4a43da04ce41a45407c143d240D|
bffc06b208a2645d2beeed5ae0505ff7be55cec6055ed415ae076e3e74f9aa2eD{
83b3cec745768f57ddcdabe20c4c848fee7126552012cc9fa7a1be366825f4adDz
b050823fb61726e8976cc72b306b33896e52a61ba34741aaaacac29f20a9d428Dy
f65aabbd9e294d13896f966d93142b9e462abc508dc124cbced08758d3d9247aDx
f037f86f203b3b15569c8b08388aeeeba9eda00ceac6945410b851d91563d688Dw
de01b8c6bef6e8935094026fbbfa516daaf970a7e92df84e3705c559853ece19Dv
74cf9b03dd4c4fd8b948481f59523011514a6b13612c953041fe8c112c7aa0d9Du
e783291d5ab16df4900451958335994c05de05b904aa33cf87682f106e2baf20Dt
3b72db221eb1db189edcf9c97b83663b0494d24fa1fe73c09e6916b1baaec8e6Ds
eb1886e298af82bc97e979491381fe23e271aabb79f09bef435b84c876817fbdDr
ad3ed272a76cefffd6cfcbe64c326b1286965a0a1950072cb4a2337f839ca989Dq
a83eb350bcaf8f5bf58970e8c94bdcbdd5f690dc3d7e90d21bf5532d9a597c62
~|juqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735iu-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149huqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024gq'qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289fqqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6pq'rOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289oqrOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YnqCrOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058mqrOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561lqrOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lkq)rOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&vqsOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561uqsOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{turOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|surOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735ru-rOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149qurOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#A{u-sOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149zusOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024yq'sOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289xqsOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YwqCsOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
qtOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCtOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qtOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|~usOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{}usOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762||usOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|utOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{utOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|utOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-tOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149utOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'tOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VquOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
quOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O	q/uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wu}tOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9uuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289quOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
quOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YqCvOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qvOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qvOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)vOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qvOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818u-uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|uvOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-vOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uvOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'vOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qvOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6"q'wOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289!qwOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y qCwOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qwOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qwOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)wOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&(qxOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561'qxOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{&uwOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|%uwOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735$u-wOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149#uwOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#A-u-xOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149,uxOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024+q'xOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289*qxOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y)qCxOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
3qyOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y2qCyOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#16540581qyOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|0uxOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{/uxOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|.uxOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|9uyOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{8uyOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|7uyOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#19057356u-yOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#185011495uyOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#18620244q'yOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3V>qzOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L=q)zOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-<qzOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O;q/zOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w:u}yOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9CuzOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Bq'zOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289AqzOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y@qCzOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058?qzOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YIqC{Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058Hq{Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561Gq{Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LFq){Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-Eq{Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Du-zOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|Nu{Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Mu-{Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149Lu{Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Kq'{Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289Jq{Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6Tq'|Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289Sq|Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YRqC|Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058Qq|Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561Pq|Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LOq)|Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&Zq}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561Yq}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{Xu|Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|Wu|Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Vu-|Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149Uu|Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#A_u-}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149^u}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024]q'}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289\q}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y[qC}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
eq~Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YdqC~Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058cq~Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|bu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{au}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|`u}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735

er+V:eD

aae99874c09826e7ffdc47307dc7fa4aa1ef9302e99a8432186772a7619d629dD	
7621e69d1f6a5287ec45f7ae6e9410b61ce65c095de32ed792b022a4520de7d1D
f854a25eb972d3b371b5576e432a9a20947bb7be07e83253e98bd2b39025d16aD
daad2593294d57ecd2ba590f2b8292ca6c1a15ac312f2ce7da8dbb7128a21db5D
da3a8c2abd8f7012e5d4bebd1103714f6d567dbd1f5281431b01ffd6d61025fbD
48c1cdad82823961370ac3c16ed4a93a8b8b46bde9034024316e1a72af9522d4D
c6f14dac0ec25c398840115e52a340353f02aaea3834f3a0eba9c59477ed29acD
682b34f9ba65eb2126b3140d6fe7319d11e990cef5a3d74f66b79f00719e6adaD
dba6df762c2a7b4df2011636555ed8910dd7c702ac1a8c2233d5bdc1752907ddD
bece87454982682fbdb7722fda453b231999ee186bb714b2151fb7a2f81a9897D
411d4dcdad36f25940ac90a44c595935da1b410049409e9047bf8e5a0d896d00D
0ee97394870cffe996ee7e4b916ac7fd3a1843f7b577ee2bf1a309f6b5e3e325D~
79973cc33f53bcaa66861b86f5ca88df66744a2b5a58c2f2f7f0dc2e37c67a36
$q4!$|ku~Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{ju~Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|iu~Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735hu-~Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149gu~Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024fq'~Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VpqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Loq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-nqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Omq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wlu}~Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9uuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024tq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289sqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YrqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y{qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058zqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561yqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lxq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-wqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818vu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149~uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024}q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289|qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{
uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|	uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Au-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y
qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3V"qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L!q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
- qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Oq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9'uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024&q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289%qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y$qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058#qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y-qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058,qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561+qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L*q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-)qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818(u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|2uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#19057351u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#185011490uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024/q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289.qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G68q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#18322897qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y6qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#16540585qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#18275614qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L3q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&>qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561=qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{<uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|;uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735:u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#185011499uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#ACu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149BuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Aq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289@qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y?qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
IqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YHqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058GqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|FuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{EuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|DuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|OuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{NuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|MuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Lu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149KuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Jq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VTqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LSq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-RqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818OQq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wPu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9YuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Xq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289WqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YVqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058UqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y_qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058^qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561]qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L\q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-[qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Zu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|duOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735cu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149buOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024aq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289`qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738

er+V:eD
08ec368681cd5235d44e7c13637d697d5bc44aaf5cfd9f49fc33531191a5717bD
dbc4de07d0e60afa27428cc96344b4424c8cf8209e8961f014f4989de0ede96dD
8ba45a2931417326f5988ff2fa9db54c083bfab2f5fe260ea31072a26b0d9adbD
d60ccb9327412f5e9b92a65ce3c4d3ec7c9cef9e0d21433888157b9758c62587D
966ec9754e2cc3fe39729998dcef6f877a9061b02c36cada54ff696eb4dd98c6D
ab37db3638f3d63077ca3270c6b587f0147ede183844f7fd95cc12babea8f8a8D
94aaf8d6f0db1300c892d45a1a8334173bca651326cfadf717623f714460fe61D
6838d1704d6089791d6b3d53de842f0901465128bc97227e71cbfb2073418234D
03ea957f3e2be56bc876a29ef48424ad8cc38c240505a263f9907bb55882d20fD
32fdc77032a9de115471b54289fc5f0fd4e2fe3f428c90a14db22d18d246a781D

0f2b27230afc7e0f0e4681b53e974e613f93cdd1f542dd4b63a37b74db2caa55D
6d6d3ccc17a9eee0b41995b6db620df39e9070da91831a1ee3a9c9f9bf6eb135D
d0a250d18f4b89599438cfd448782db11f8012472af6df48eced91d60be23eb0
60$G6jq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289iqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YhqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058gqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561fqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Leq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&pqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561oqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{nuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|muOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735lu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149kuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Auu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149tuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024sq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289rqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
{qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YzqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058yqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|xuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{wuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|vuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735~u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149}uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024|q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Oq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289	qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&"qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561!qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{ uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#A'u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149&uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024%q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289$qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y#qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y,qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058+qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|*uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{)uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|(uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|3uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{2uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|1uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#19057350u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149/uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024.q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3V8qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L7q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-6qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O5q/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w4u}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9=uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024<q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289;qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y:qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#16540589qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YCqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058BqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561AqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L@q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-?qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818>u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|HuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Gu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149FuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Eq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289DqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6Nq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289MqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YLqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058KqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561JqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LIq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&TqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561SqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{RuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|QuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Pu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149OuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#AYu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149XuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Wq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289VqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YUqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
_qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y^qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058]qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|\uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{[uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|ZuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|euOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{duOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|cuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735bu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149auOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024`q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VjqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Liq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-hqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Ogq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wfu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759

er+V:eD$
cd5dcd832d5dda7bea32dbdbe45ad8e13ef022b0a9d83e5b78427944aaab8f18D#
847a5e41805b10521ebc6aff29431992c0a22a8d17c634a1e13970158fa1af9cD"
45aa06d1829f4839d099598b630eabc9be0756f534ae4a81d0d6b7ab5922bc09D!
4e697ffc60fca75a99deb8089617f94c12550b52fd5e8a07ec885967667c7541D 
b6d54a557b4be65879c789367443480c4c3cb12adfbb35c324b6786e2f8ba2a7D
65b46c58329dcd3a310fbfb4c8b9371639bb59c96629f150e82a7820305f44fbD
fc3bab612213d15e8f3305d921a6c746a042fa8d06b3e8b75aa25f4eeced3daeD
83c007c9ec430e38dbcdce8b868daa1718da2090b7ef60980dfaeff2c633aa2fD
25c4de241ae499bb87004a0bd23c0264cf0e5ec7003c83fa57962fc6ca0fff80D
d63186e6cef38839b7dec9223b2e71fce4525a6125dbb201cab77ddcd29b6eb3D
8126411e939ed28c342373246930b21454d5af2651f4d36c56e7d17b279978ffD
e4d444d844a4cafb1f7e4fa1a67562e38078b7cbb3816a7216492e9a2d40c822D
b067b77274a7e008ceafa9fe949f6649af4f291e1fe843cc01d5255b977ff6be
KvK9ouOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024nq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289mqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YlqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058kqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YuqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058tqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561sqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lrq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818pu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|zuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735yu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149xuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024wq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289vqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y~qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058}qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L{q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Au-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149
uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024	q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{
uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Oq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759ofVflrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|"'-28>CIOTY_djpu{"'-38=CHNTY_ejo	u
z
!',28=CINSY^dj!o"u#{$%&'()*!+',--2.7/=0B1H2N3S4Y5_6d7i8o:t;z<=>?@AB!C&D,E2F7G=HCIHJMKSLXM^NdOiPoRuSzTU
KvK9!uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024 q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y'qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058&qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561%qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L$q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-#qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818"u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|,uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735+u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149*uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024)q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289(qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G62q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#18322891qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y0qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058/qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561.qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L-q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&8qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#18275617qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{6uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|5uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#19057354u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#185011493uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#A=u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149<uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024;q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289:qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y9qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
CqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YBqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058AqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|@uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{?uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|>uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|IuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{HuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|GuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Fu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149EuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Dq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VNqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LMq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-LqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818OKq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wJu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9SuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Rq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289QqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YPqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058OqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YYqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058XqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561WqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LVq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-UqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Tu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|^uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735]u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149\uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024[q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289ZqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6dq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289cqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YbqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058aqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561`qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L_q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&jqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561iqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{huOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|guOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735fu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149euOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024

er+V:eD1
5bf7fa347b641deaa5b1dd5752635a5a43ee644e71cca2e924839f74490cf862D0
3baf28c0979d5f90558e58f7499f8c92082cc8e9b4e8e68acfa4d95a6a902be4D/
3af5287deb01c0880a6d6916b3fc0ecdfaf93e576369b1b9cfdcc1613bc22a7dD.
33beb19a202929092a6e1605a3f6115c5442714589a627267a8ba12528865a7eD-
8cab4a117a1efc20543417ed7f4d69f0626329800f58029dc586d0a2bdadea33D,
27091e98db08364ca7ce67c92ed7fea1f2ef9a1b64dd06f659d6bb1cf563d729D+
a4aa01b378a3f60ccb4500c7b55fd5e37fde220dcb3863302b729de23aefcf5aD*
332d0c5fbd59617b2854c4ef7acc7a7862676bdf591666e519d3b09c2f3435e8D)
ecb4654a5f2ad2d8e3539f0b0076eee523a54eda425ef270ec5cb0394fa1ea8cD(
04338d51e121bd3112024a6e032e9dc376c437e7d1914a17d85868c3c59e8f72D'
d31ed1bf33208a48c1659c4aa33c952c4a88624e0ef52fdda4e5cb196354ac40D&
d264ee805ecda49c30b17382368adfa7d60dde5fe60862b200ff3a5b11b02cfaD%
248724675fc45561c18b6906dfbeacda8c1e9b4451c512be528649e3e34c63b9
A#Aou-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149nuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024mq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289lqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YkqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
uqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YtqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058sqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|ruOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{quOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|puOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{zuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|yuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735xu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149wuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024vq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-~qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O}q/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w|u}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561	qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#A!u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149 uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
'qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y&qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058%qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|$uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{#uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|"uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|-uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{,uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|+uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735*u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149)uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024(q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3V2qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L1q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-0qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O/q/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w.u}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK97uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#18620246q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#18322895qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y4qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#16540583qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y=qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058<qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561;qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L:q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-9qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#18018188u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|BuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Au-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149@uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024?q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289>qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6Hq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289GqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YFqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058EqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561DqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LCq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&NqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561MqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{LuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|KuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Ju-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149IuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#ASu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149RuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Qq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289PqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YOqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
YqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YXqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058WqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|VuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{UuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|TuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|_uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{^uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|]uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735\u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149[uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Zq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VdqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lcq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-bqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Oaq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w`u}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9iuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024hq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289gqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YfqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058eqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YoqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058nqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561mqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Llq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-kqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818ju-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114

er+V:eD>
9bbb081fdd6485184aa28dae8f3c1946680fdf0f31efe538dc75912939ac72efD=
041f5f1e8b93254eb47e8b18434325a8ecfea6152330918662e991c8b435cdfeD<
f5670dae0add00bdfd492611247f9503be7281552df1cc745f5b359269462efdD;
64eaa7b016a8e2dfc63c23045a2a81e467d7e0553af8d19b447d9f84265a2b26D:
ae4a37c25fe4cd0a6a91a2140530796b4b2c6059cf099f2bd2f65504b92e3742D9
53777bef4b884ec988d12664f72eaadc76fa2b24890080c6649e74f9c9769d94D8
f7c83637d8468e19213b90ac92d161c309fd5941a55567c16d8598b7ff66e882D7
6389f5f5c812cb020dd4bcf4dc948be8137ffef92ecbea10a81268530ca43c7bD6
18a944fd24888ada7034062b23c8096dad6ee599c3c1262ac434394919b64aeeD5
4535717be95f1dcc2921d19bb37276451f877f99558ee69df6a67597d545a010D4
15a85325dd91b5d41165cb155f2faac7f1c67c75551d52a664027fc559a5c62cD3
2676b39f946e027f903e8815ed686e37a2b8101f353ca2063367ccce93da761bD2
2aba6dcda4b716437cd39f662b144aa8fe26ea6f15b54f36ae5c7340a33c8b36
~|tuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735su-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149ruOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024qq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289pqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6zq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289yqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YxqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058wqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561vqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Luq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{~uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|}uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735|u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Au-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y
qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058	qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149
uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Oq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y!qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058 qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|&uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735%u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149$uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024#q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289"qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6,q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289+qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y*qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058)qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561(qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L'q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&2qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#18275611qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{0uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|/uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735.u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149-uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#A7u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#185011496uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#18620245q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#18322894qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y3qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
=qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y<qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058;qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|:uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{9uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|8uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|CuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{BuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|AuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735@u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149?uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024>q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VHqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LGq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-FqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818OEq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wDu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9MuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Lq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289KqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YJqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058IqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YSqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058RqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561QqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LPq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-OqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Nu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|XuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Wu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149VuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Uq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289TqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6^q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289]qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y\qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058[qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561ZqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LYq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&dqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561cqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{buOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|auOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735`u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149_uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Aiu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149huOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024gq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289fqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YeqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
oqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YnqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058mqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|luOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{kuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|juOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735

er+V:eDK
9db93e031838e2ddbd104024296a70bd847b8e704bfa2e92f767297158bf6b6cDJ
a219a29b75fdb33749412440d21f8b1ff92ad6616637e7e8cb818daf66fabe36DI
8864cd46b197d894c0037ac70b483f8091d39212b9cf6ace09e8c117d76a1c12DH
0dc9fbacba7b11cb8fe67dd7a2596d89132d937ce3099a1e872d630f5f68fafcDG
5a34d2e48c7b78b23d4ae6c9697fa3094d3e9bc3dfdb7d09f1670206a32b7e46DF
23bb9783bb909c0cddbbcaeb08d2ecd0d27ba3325b65571783ef5837be019a60DE
af59395f80e4a8af28d6c6ccafe41de973b85b01eae99f978460cfe0198a5ee6DD
f93d558436474dcf26feea265313045cb98abbe57849c1f0f07a622d83612eb1DC
30fb1512e1cb3b565ab1bc735499011c641766b730df4ce0ba6baf035db92c70DB
9d6605784a491b25286fafef98f82226f7634b2197c483f0273690b3701d2853DA
cfbce8f5d94f01a7ce8c1dc8545168b7c3c1c2a62bae89f00a69ebd439002ffaD@
c5b8ab0d8d7cb70f48d43af7b11ed34cd4a069ee3f243e0b5c1601adbbf3b7baD?
87421442fb8dc3f0b7025e35dcc33c47b33e35e6cff668106fc871a7fdc443b7
$q4!$|uuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{tuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|suOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735ru-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149quOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024pq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VzqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lyq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-xqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Owq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wvu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024~q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289}qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y|qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058{qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|
uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735	u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Au-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
!qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|'uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{&uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|%uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735$u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149#uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024"q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3V,qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L+q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-*qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O)q/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w(u}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK91uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#18620240q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289/qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y.qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(Y7qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#16540586qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#18275615qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L4q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-3qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#18018182u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|<uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735;u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149:uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#18620249q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#18322898qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6Bq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289AqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y@qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058?qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561>qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L=q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&HqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561GqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{FuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|EuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Du-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149CuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#AMu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149LuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Kq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289JqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YIqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
SqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YRqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058QqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|PuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{OuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|NuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|YuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{XuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|WuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Vu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149UuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Tq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3V^qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L]q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-\qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O[q/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wZu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9cuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024bq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289aqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y`qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058_qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YiqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058hqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561gqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lfq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-eqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818du-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|nuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735mu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149luOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024kq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289jqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738

er+V:eDX
758f0b0b263f27bf6a17362a156e2d236f0210bb8fd11a69dbd5e2d9ca1be328DW
c0676678d1a3bcf8ce6a786607357db6145dd2dff6d685cc3e3b7312511343fcDV
0e63c2347e36ece8d4f15909b64a5a6c3b79f38a6e53f614e310fbfd86f26b06DU
f9c8ee59079e1a20cac32e3fe1b20f6f94b271c132efb4de7f5f0ebad73c632dDT
6813b3fd706e79a0721cb26c926c2fdd57aaf1300c3f48cd8573cbf02eb06168DS
3a7a5d5027216e07b3eae0f5b2cf013760700d03cca8961ca4395cd637ac3c5eDR
2b0dc7f8c8bffbe06bd0124f1cbc07bb9eda4e34b45db595e6101d68eee5ebedDQ
37356ac1734506c064e4fdf1e87d69a442a12767a7e98626e8c9c571fb460198DP
4874985f1d75f7c43dceb6929982f36fc7a9566042a70c22a42bc6e3e6a65b58DO
a52c89128003d6c528346ece42b32f7126708399f05995deaa7aa1e7035625a9DN
9c90fdb57f5b173c0200715d87a85083b5f8dd268a7aef1df7baddcd4f7ba0adDM
c7df39cc317144af8cab982c0134ec6182c78bfaafe8e47f94f33a0cd4991c97DL
c9587fe47330c8c9650ddea3de6ed9574b7027a816ed5dc48c5f19783f043700
60$G6tq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289sqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YrqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561pqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Loq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&zqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561yqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{xuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|wuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735vu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Au-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149~uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024}q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289|qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y{qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{
uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|	uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O
q/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~| uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6&q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289%qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y$qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058#qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561"qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L!q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&,qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561+qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{*uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|)uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735(u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149'uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#A1u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#185011490uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024/q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289.qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y-qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
7qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y6qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#16540585qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|4uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{3uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|2uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|=uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{<uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|;uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735:u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#185011499uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#18620248q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VBqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LAq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-@qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818O?q/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784w>u}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759
KvK9GuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Fq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289EqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YDqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058CqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YMqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058LqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561KqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LJq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-IqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Hu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|RuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Qu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149PuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024Oq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289NqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6Xq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289WqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YVqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058UqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561TqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205LSq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-
&/2&^qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561]qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{\uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|[uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735Zu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149YuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Acu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149buOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024aq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289`qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738Y_qCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
iqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YhqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058gqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|fuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{euOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|duOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|ouOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{nuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|muOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735lu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149kuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024jq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289
V3VtqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lsq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-rqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818Oqq/Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-31^- fence_compute/fence_evacuate: fix region_name content type and
  project shortopt in usage text and project-domain shortopt
  Resolves: rhbz#1760203
- fence_rhevm: add cookie support
  Resolves: rhbz#1763675
- fencing: improve stdin quote parsing
  Resolves: rhbz#1769784wpu}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759

er+V:eDe
c3729b12ca4075c75da87d40054a8cd81d3a2be928846fec9b090f2282da0809Dd
f0254a038a74be08cf548424dccbe986696e47e0e50cd52cf8f1ecdf5cf432b0Dc
e1db7a00d2204d116b7e75f87e236094c6578a2ebf4a48a7af11edd3618ebce3Db
b233baa0fb9d61676aea025d1f7b834810ad66467adee309673c302ed29261eeDa
87b930e9a82a5887d60c5bf35a95284a59744832eca1423a916a46ac5dc807a3D`
7d0c45c842a51eb4e14eecce16a8da906ea6668258c6fe279d9649645d4bd422D_
a4124d55ffe94d6e2682cb82eb1191d84b8b271f2950a8cbf86be4ade606a768D^
58a5f6025a63f07b9dc9793ec13c58029a3502315d1bb29d4c7015091c9e8dbeD]
c565a665dee8bff0a1df1f9e228b65e7935723b9a6e91ae26f4b30dc3b90452bD\
2f00c2ff15b5c113c361dc4ad8be22ff7ec2bde7c1098b7abe496171dc1d7b49D[
84e0987f67e674a41976b9cd147cec00e6c57db8a4feeb9b141b7fb607b890efDZ
8d6cfc5c9cef32a028f7938e7be7de7b81bde37d434b23891fb9c2f0583c18dfDY
164f86624a46a2f71b3b2a951d0544b44be7971180929255dc526785acc3a143
KvK9yuOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024xq'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289wqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YvqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058uqOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561
(l(YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058~qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561}qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205L|q)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-{qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-33^U@- fence-agents-lpar: build on non-ppc64le arch's
  Resolves: rhbz#1801818zu-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#1850114
~|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738
60$G6
q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289	qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205Lq)Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-34^g@- fence_aws: improve parameter logic to allow setting region parameter
  while using credentials from ~/.aws/config
  Resolves: rhbz#1673468
-offlrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|WXYZ!['\,]1^7_<`BaHbMcSdYe^fcgihnjtkzlmnopqr s&t,u1v7w=xByGzM{R|X}^~cioty
!+5@KValv"-8CMWaku
 +6AKU`kv ,8DOZep{)5@LXdp|)5?
&/2&qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-35^|@- fence_aws: fix possible race condition
  Resolves: rhbz#1816205{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|
uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024
A#Au-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058
qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-40^@- fence_vmware_rest: fix encoding issues
  Resolves: rhbz#1793738YqCOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-39^@- fence_vmware_rest: add filter parameter to avoid 1000 VM API limit
  and avoid failing when hitting it during the monitor-action
  Resolves: rhbz#1654058qOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-36^- fence_vmware_rest: improve exception handling
  Resolves: rhbz#1827561|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735
$q4!$|!uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.5an@- fence_aws: add "filter" parameter
  Resolves: rhbz#2003189{ uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.4`@- fence_azure_arm: fix MSI support
  Resolves: rhbz#1957762|uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.3_@- fence_aws: add support for IMDSv2
  Resolves: rhbz#1905735u-Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.2_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078
  Resolves: rhbz#18501149uOyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.1_'@- fence_lpar: fix issue with long username, hostname, etc not
  working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors

  Resolves: rhbz#1860545
  Resolves: rhbz#1862024q'Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41^˳@- fence_aws: improve logging and metadata/usage text
  Resolves: rhbz#1832289

K?IKO+aAEike Rathke <erack@redhat.com> - 102.9.0-4d- Update to 102.9.0 build2W*_SJan Horak <jhorak@redhat.com> - 102.9.0-2d	@- removed disable-openh264-downloadO)aAEike Rathke <erack@redhat.com> - 102.9.0-1d'@- Update to 102.9.0 build1O(aAEike Rathke <erack@redhat.com> - 102.8.0-2cw- Update to 102.8.0 build2O'aAEike Rathke <erack@redhat.com> - 102.8.0-1c=@- Update to 102.8.0 build1O&aAEike Rathke <erack@redhat.com> - 102.7.0-1cS@- Update to 102.7.0 build1%_-Jan Horak <jhorak@redhat.com> - 102.6.0-2c@- Add firefox-x11 subpackage to allow explicit run of firefox under x11 on RHEL9O$aAEike Rathke <erack@redhat.com> - 102.6.0-1c.- Update to 102.6.0 build1i#_wJan Horak <jhorak@redhat.com> - 102.5.0-2c@- Added libwebrtc screencast patch for newer featuresw"u}Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.2.1-41.6b@- fence_aws: fix IMDSv2 support
  Resolves: rhbz#2050759

q@eoqO5aAEike Rathke <erack@redhat.com> - 102.9.0-4d- Update to 102.9.0 build2W4_SJan Horak <jhorak@redhat.com> - 102.9.0-2d	@- removed disable-openh264-downloadO3aAEike Rathke <erack@redhat.com> - 102.9.0-1d'@- Update to 102.9.0 build1O2aAEike Rathke <erack@redhat.com> - 102.8.0-2cw- Update to 102.8.0 build2O1aAEike Rathke <erack@redhat.com> - 102.8.0-1c=@- Update to 102.8.0 build1O0aAEike Rathke <erack@redhat.com> - 102.7.0-1cS@- Update to 102.7.0 build1/_-Jan Horak <jhorak@redhat.com> - 102.6.0-2c@- Add firefox-x11 subpackage to allow explicit run of firefox under x11 on RHEL9O.aAEike Rathke <erack@redhat.com> - 102.6.0-1c.- Update to 102.6.0 build1i-_wJan Horak <jhorak@redhat.com> - 102.5.0-2c@- Added libwebrtc screencast patch for newer featuresQ,cCEike Rathke <erack@redhat.com> - 102.10.0-1d,@- Update to 102.10.0 build1
3#-/3Q@cCEike Rathke <erack@redhat.com> - 102.11.0-2dS@- Update to 102.11.0 build2Q?cCEike Rathke <erack@redhat.com> - 102.11.0-1dP@- Update to 102.11.0 build1Q>cCEike Rathke <erack@redhat.com> - 102.10.0-1d,@- Update to 102.10.0 build1O=aAEike Rathke <erack@redhat.com> - 102.9.0-4d- Update to 102.9.0 build2W<_SJan Horak <jhorak@redhat.com> - 102.9.0-2d	@- removed disable-openh264-downloadO;aAEike Rathke <erack@redhat.com> - 102.9.0-1d'@- Update to 102.9.0 build1O:aAEike Rathke <erack@redhat.com> - 102.8.0-2cw- Update to 102.8.0 build2O9aAEike Rathke <erack@redhat.com> - 102.8.0-1c=@- Update to 102.8.0 build1O8aAEike Rathke <erack@redhat.com> - 102.7.0-1cS@- Update to 102.7.0 build17_-Jan Horak <jhorak@redhat.com> - 102.6.0-2c@- Add firefox-x11 subpackage to allow explicit run of firefox under x11 on RHEL9Q6cCEike Rathke <erack@redhat.com> - 102.10.0-1d,@- Update to 102.10.0 build1
5w%//5OKaAEike Rathke <erack@redhat.com> - 102.8.0-1c=@- Update to 102.8.0 build1QJcCEike Rathke <erack@redhat.com> - 102.11.0-2dS@- Update to 102.11.0 build2QIcCEike Rathke <erack@redhat.com> - 102.11.0-1dP@- Update to 102.11.0 build1QHcCEike Rathke <erack@redhat.com> - 102.10.0-1d,@- Update to 102.10.0 build1OGaAEike Rathke <erack@redhat.com> - 102.9.0-4d- Update to 102.9.0 build2WF_SJan Horak <jhorak@redhat.com> - 102.9.0-2d	@- removed disable-openh264-downloadOEaAEike Rathke <erack@redhat.com> - 102.9.0-1d'@- Update to 102.9.0 build1ODaAEike Rathke <erack@redhat.com> - 102.8.0-2cw- Update to 102.8.0 build2OCaAEike Rathke <erack@redhat.com> - 102.8.0-1c=@- Update to 102.8.0 build1OBaAEike Rathke <erack@redhat.com> - 102.7.0-1cS@- Update to 102.7.0 build1A_-Jan Horak <jhorak@redhat.com> - 102.6.0-2c@- Add firefox-x11 subpackage to allow explicit run of firefox under x11 on RHEL9
-\\%-OVaAEike Rathke <erack@redhat.com> - 102.8.0-2cw- Update to 102.8.0 build2OUaAEike Rathke <erack@redhat.com> - 102.8.0-1c=@- Update to 102.8.0 build1QTcCEike Rathke <erack@redhat.com> - 102.12.0-1dw6- Update to 102.12.0 build1Se3Anton Bobrov <abobrov@redhat.com> 102.11.0-2dl- Do not import cert to certdb on override exception:
  rhbz#2118991
  mzbz@1833330QRcCEike Rathke <erack@redhat.com> - 102.11.0-2dS@- Update to 102.11.0 build2QQcCEike Rathke <erack@redhat.com> - 102.11.0-1dP@- Update to 102.11.0 build1QPcCEike Rathke <erack@redhat.com> - 102.10.0-1d,@- Update to 102.10.0 build1OOaAEike Rathke <erack@redhat.com> - 102.9.0-4d- Update to 102.9.0 build2WN_SJan Horak <jhorak@redhat.com> - 102.9.0-2d	@- removed disable-openh264-downloadOMaAEike Rathke <erack@redhat.com> - 102.9.0-1d'@- Update to 102.9.0 build1OLaAEike Rathke <erack@redhat.com> - 102.8.0-2cw- Update to 102.8.0 build2
%TZw#w%OaaAEike Rathke <erack@redhat.com> - 102.9.0-4d- Update to 102.9.0 build2W`_SJan Horak <jhorak@redhat.com> - 102.9.0-2d	@- removed disable-openh264-downloadO_aAEike Rathke <erack@redhat.com> - 102.9.0-1d'@- Update to 102.9.0 build1Q^cCEike Rathke <erack@redhat.com> - 102.12.0-1dw6- Update to 102.12.0 build1]e3Anton Bobrov <abobrov@redhat.com> 102.11.0-2dl- Do not import cert to certdb on override exception:
  rhbz#2118991
  mzbz@1833330Q\cCEike Rathke <erack@redhat.com> - 102.11.0-2dS@- Update to 102.11.0 build2Q[cCEike Rathke <erack@redhat.com> - 102.11.0-1dP@- Update to 102.11.0 build1QZcCEike Rathke <erack@redhat.com> - 102.10.0-1d,@- Update to 102.10.0 build1OYaAEike Rathke <erack@redhat.com> - 102.9.0-4d- Update to 102.9.0 build2WX_SJan Horak <jhorak@redhat.com> - 102.9.0-2d	@- removed disable-openh264-downloadOWaAEike Rathke <erack@redhat.com> - 102.9.0-1d'@- Update to 102.9.0 build1
'Xu!y'{'QlcCEike Rathke <erack@redhat.com> - 102.10.0-1d,@- Update to 102.10.0 build1OkaAEike Rathke <erack@redhat.com> - 102.9.0-4d- Update to 102.9.0 build2Wj_SJan Horak <jhorak@redhat.com> - 102.9.0-2d	@- removed disable-openh264-downloadOiaAEike Rathke <erack@redhat.com> - 102.9.0-1d'@- Update to 102.9.0 build1QhcCEike Rathke <erack@redhat.com> - 102.13.0-2d- Update to 102.13.0 build2QgcCEike Rathke <erack@redhat.com> - 102.13.0-1dr@- Update to 102.13.0 build1QfcCEike Rathke <erack@redhat.com> - 102.12.0-1dw6- Update to 102.12.0 build1ee3Anton Bobrov <abobrov@redhat.com> 102.11.0-2dl- Do not import cert to certdb on override exception:
  rhbz#2118991
  mzbz@1833330QdcCEike Rathke <erack@redhat.com> - 102.11.0-2dS@- Update to 102.11.0 build2QccCEike Rathke <erack@redhat.com> - 102.11.0-1dP@- Update to 102.11.0 build1QbcCEike Rathke <erack@redhat.com> - 102.10.0-1d,@- Update to 102.10.0 build1

BXu!y%Bve3Anton Bobrov <abobrov@redhat.com> 102.11.0-2dl- Do not import cert to certdb on override exception:
  rhbz#2118991
  mzbz@1833330QucCEike Rathke <erack@redhat.com> - 102.11.0-2dS@- Update to 102.11.0 build2QtcCEike Rathke <erack@redhat.com> - 102.11.0-1dP@- Update to 102.11.0 build1QscCEike Rathke <erack@redhat.com> - 102.10.0-1d,@- Update to 102.10.0 build1QrcCEike Rathke <erack@redhat.com> - 102.13.0-2d- Update to 102.13.0 build2QqcCEike Rathke <erack@redhat.com> - 102.13.0-1dr@- Update to 102.13.0 build1QpcCEike Rathke <erack@redhat.com> - 102.12.0-1dw6- Update to 102.12.0 build1oe3Anton Bobrov <abobrov@redhat.com> 102.11.0-2dl- Do not import cert to certdb on override exception:
  rhbz#2118991
  mzbz@1833330QncCEike Rathke <erack@redhat.com> - 102.11.0-2dS@- Update to 102.11.0 build2QmcCEike Rathke <erack@redhat.com> - 102.11.0-1dP@- Update to 102.11.0 build1

er+V:eDr
158e955d20950ef61a38c645accc22bd6cf37c7f31e06cdd3313c2bc5b0d969fDq
74484befc2ade710df325b9af62b87ffaef3b2b13a00935396297467ec8e98a8Dp
e0d62271ecc1d123dd2dfe6e63131923215ed05f9f87bb42cbe1c713b4cfec5dDo
4eb117f25866c9e447c845336fe608b5c30ec80262a6ffb3dfb33756f0001e62Dn
dd98390ecb2875b55a18bb8ce2f4fe960e7d8f308cf206decddcbcf25c6638c0Dm
9e0249e756fa1e3dfb334a1acf42d322e19676dcef92227940e29b52a2972853Dl
6341f007df657335759aa49bd308613667e9481106e29eff6fe1a74abfc9200aDk
ce4f5cfaaa8ee847baeaa1449c9bda07462f87ac1b32027dc3d2b1086d417890Dj
3fb0b77a99715fb931ff65f91089240046d339752c82495a1069470792e26818Di
ea41aafc4258682847158cad9b72b66d86e801649ba22dfbbb766d88ea1addafDh
2699d7c26ffc9f022f434f324f0530dfee3fbaba767104e9902922124ba69b63Dg
155f2a67548cb8ab54265b28dbf3f1e731e26cf182da45d98c95425930890046Df
97f2f474f7e410b8f477b1e905b6207ab4497c4def5fa6005eca7739687d0fca
.X[
e.QcCEike Rathke <erack@redhat.com> - 102.12.0-1dw6- Update to 102.12.0 build1e3Anton Bobrov <abobrov@redhat.com> 102.11.0-2dl- Do not import cert to certdb on override exception:
  rhbz#2118991
  mzbz@1833330QcCEike Rathke <erack@redhat.com> - 102.11.0-2dS@- Update to 102.11.0 build2Q~cCEike Rathke <erack@redhat.com> - 102.11.0-1dP@- Update to 102.11.0 build1Q}cCEike Rathke <erack@redhat.com> - 102.10.0-1d,@- Update to 102.10.0 build1K|c7Eike Rathke <erack@redhat.com> - 102.14.0-3d- Bump NVR to rebuildR{aGJan Horak <jhorak@redhat.com> - 102.14.0-2d- Rebuild due to rhbz#2228948QzcCEike Rathke <erack@redhat.com> - 102.14.0-1d@- Update to 102.14.0 build1QycCEike Rathke <erack@redhat.com> - 102.13.0-2d- Update to 102.13.0 build2QxcCEike Rathke <erack@redhat.com> - 102.13.0-1dr@- Update to 102.13.0 build1QwcCEike Rathke <erack@redhat.com> - 102.12.0-1dw6- Update to 102.12.0 build1
.Xa
*.QcCEike Rathke <erack@redhat.com> - 102.13.0-2d- Update to 102.13.0 build2QcCEike Rathke <erack@redhat.com> - 102.13.0-1dr@- Update to 102.13.0 build1Q
cCEike Rathke <erack@redhat.com> - 102.12.0-1dw6- Update to 102.12.0 build1	e3Anton Bobrov <abobrov@redhat.com> 102.11.0-2dl- Do not import cert to certdb on override exception:
  rhbz#2118991
  mzbz@1833330QcCEike Rathke <erack@redhat.com> - 102.11.0-2dS@- Update to 102.11.0 build2QcCEike Rathke <erack@redhat.com> - 102.11.0-1dP@- Update to 102.11.0 build1Kc7Eike Rathke <erack@redhat.com> - 102.14.0-3d- Bump NVR to rebuildRaGJan Horak <jhorak@redhat.com> - 102.14.0-2d- Rebuild due to rhbz#2228948QcCEike Rathke <erack@redhat.com> - 102.14.0-1d@- Update to 102.14.0 build1QcCEike Rathke <erack@redhat.com> - 102.13.0-2d- Update to 102.13.0 build2QcCEike Rathke <erack@redhat.com> - 102.13.0-1dr@- Update to 102.13.0 build1
.W	a
~*.QcCEike Rathke <erack@redhat.com> - 102.14.0-1d@- Update to 102.14.0 build1QcCEike Rathke <erack@redhat.com> - 102.13.0-2d- Update to 102.13.0 build2QcCEike Rathke <erack@redhat.com> - 102.13.0-1dr@- Update to 102.13.0 build1QcCEike Rathke <erack@redhat.com> - 102.12.0-1dw6- Update to 102.12.0 build1e3Anton Bobrov <abobrov@redhat.com> 102.11.0-2dl- Do not import cert to certdb on override exception:
  rhbz#2118991
  mzbz@1833330QcCEike Rathke <erack@redhat.com> - 102.11.0-2dS@- Update to 102.11.0 build2QcCEike Rathke <erack@redhat.com> - 102.11.0-1dP@- Update to 102.11.0 build1QcCEike Rathke <erack@redhat.com> - 102.15.0-1dF@- Update to 102.15.0 build2Kc7Eike Rathke <erack@redhat.com> - 102.14.0-3d- Bump NVR to rebuildRaGJan Horak <jhorak@redhat.com> - 102.14.0-2d- Rebuild due to rhbz#2228948Q
cCEike Rathke <erack@redhat.com> - 102.14.0-1d@- Update to 102.14.0 build1
i]	q{)il"_}Jan Horak <jhorak@redhat.com> - 102.3.0-7cEZ- Fix for expat CVE-2022-40674 and non functional webrtcN!_AJan Horak <jhorak@redhat.com> - 102.3.0-6c p- Update to 102.3.0 build1O aAEike Rathke <erack@redhat.com> - 91.12.0-1b?- Update to 91.12.0 build1OaAEike Rathke <erack@redhat.com> - 91.11.0-2bU- Update to 91.11.0 build2OaAEike Rathke <erack@redhat.com> - 91.11.0-1b- Update to 91.11.0 build1OaAEike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1L]?Jan Horak <jhorak@redhat.com> - 91.9.1-1b- Update to 91.9.1 build1F_1Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0QcCEike Rathke <erack@redhat.com> - 102.15.0-1dF@- Update to 102.15.0 build2Kc7Eike Rathke <erack@redhat.com> - 102.14.0-3d- Bump NVR to rebuildRaGJan Horak <jhorak@redhat.com> - 102.14.0-2d- Rebuild due to rhbz#2228948
j\r |+jO-aAEike Rathke <erack@redhat.com> - 102.4.0-1cF@- Update to 102.4.0 build1l,_}Jan Horak <jhorak@redhat.com> - 102.3.0-7cEZ- Fix for expat CVE-2022-40674 and non functional webrtcN+_AJan Horak <jhorak@redhat.com> - 102.3.0-6c p- Update to 102.3.0 build1O*aAEike Rathke <erack@redhat.com> - 91.12.0-1b?- Update to 91.12.0 build1O)aAEike Rathke <erack@redhat.com> - 91.11.0-2bU- Update to 91.11.0 build2O(aAEike Rathke <erack@redhat.com> - 91.11.0-1b- Update to 91.11.0 build1O'aAEike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1L&]?Jan Horak <jhorak@redhat.com> - 91.9.1-1b- Update to 91.9.1 build1F%_1Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0O$aAEike Rathke <erack@redhat.com> - 102.5.0-1ck@- Update to 102.5.0 build1O#aAEike Rathke <erack@redhat.com> - 102.4.0-1cF@- Update to 102.4.0 build1
D\
fTDO8aAEike Rathke <erack@redhat.com> - 102.6.0-1c.- Update to 102.6.0 build1i7_wJan Horak <jhorak@redhat.com> - 102.5.0-2c@- Added libwebrtc screencast patch for newer featuresO6aAEike Rathke <erack@redhat.com> - 102.5.0-1ck@- Update to 102.5.0 build1O5aAEike Rathke <erack@redhat.com> - 102.4.0-1cF@- Update to 102.4.0 build1l4_}Jan Horak <jhorak@redhat.com> - 102.3.0-7cEZ- Fix for expat CVE-2022-40674 and non functional webrtcN3_AJan Horak <jhorak@redhat.com> - 102.3.0-6c p- Update to 102.3.0 build1O2aAEike Rathke <erack@redhat.com> - 91.12.0-1b?- Update to 91.12.0 build1O1aAEike Rathke <erack@redhat.com> - 91.11.0-2bU- Update to 91.11.0 build2O0aAEike Rathke <erack@redhat.com> - 91.11.0-1b- Update to 91.11.0 build1O/aAEike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1O.aAEike Rathke <erack@redhat.com> - 102.5.0-1ck@- Update to 102.5.0 build1
D\
gTDOCaAEike Rathke <erack@redhat.com> - 91.11.0-2bU- Update to 91.11.0 build2OBaAEike Rathke <erack@redhat.com> - 102.6.0-1c.- Update to 102.6.0 build1iA_wJan Horak <jhorak@redhat.com> - 102.5.0-2c@- Added libwebrtc screencast patch for newer featuresO@aAEike Rathke <erack@redhat.com> - 102.5.0-1ck@- Update to 102.5.0 build1O?aAEike Rathke <erack@redhat.com> - 102.4.0-1cF@- Update to 102.4.0 build1l>_}Jan Horak <jhorak@redhat.com> - 102.3.0-7cEZ- Fix for expat CVE-2022-40674 and non functional webrtcN=_AJan Horak <jhorak@redhat.com> - 102.3.0-6c p- Update to 102.3.0 build1O<aAEike Rathke <erack@redhat.com> - 91.12.0-1b?- Update to 91.12.0 build1O;aAEike Rathke <erack@redhat.com> - 91.11.0-2bU- Update to 91.11.0 build2O:aAEike Rathke <erack@redhat.com> - 91.11.0-1b- Update to 91.11.0 build1O9aAEike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1

_]J_OMaAEike Rathke <erack@redhat.com> - 91.11.0-2bU- Update to 91.11.0 build2OLaAEike Rathke <erack@redhat.com> - 102.7.0-1cS@- Update to 102.7.0 build1K_-Jan Horak <jhorak@redhat.com> - 102.6.0-2c@- Add firefox-x11 subpackage to allow explicit run of firefox under x11 on RHEL9OJaAEike Rathke <erack@redhat.com> - 102.6.0-1c.- Update to 102.6.0 build1iI_wJan Horak <jhorak@redhat.com> - 102.5.0-2c@- Added libwebrtc screencast patch for newer featuresOHaAEike Rathke <erack@redhat.com> - 102.5.0-1ck@- Update to 102.5.0 build1OGaAEike Rathke <erack@redhat.com> - 102.4.0-1cF@- Update to 102.4.0 build1lF_}Jan Horak <jhorak@redhat.com> - 102.3.0-7cEZ- Fix for expat CVE-2022-40674 and non functional webrtcNE_AJan Horak <jhorak@redhat.com> - 102.3.0-6c p- Update to 102.3.0 build1ODaAEike Rathke <erack@redhat.com> - 91.12.0-1b?- Update to 91.12.0 build1

`]J`NW_AJan Horak <jhorak@redhat.com> - 102.3.0-6c p- Update to 102.3.0 build1OVaAEike Rathke <erack@redhat.com> - 102.7.0-1cS@- Update to 102.7.0 build1U_-Jan Horak <jhorak@redhat.com> - 102.6.0-2c@- Add firefox-x11 subpackage to allow explicit run of firefox under x11 on RHEL9OTaAEike Rathke <erack@redhat.com> - 102.6.0-1c.- Update to 102.6.0 build1iS_wJan Horak <jhorak@redhat.com> - 102.5.0-2c@- Added libwebrtc screencast patch for newer featuresORaAEike Rathke <erack@redhat.com> - 102.5.0-1ck@- Update to 102.5.0 build1OQaAEike Rathke <erack@redhat.com> - 102.4.0-1cF@- Update to 102.4.0 build1lP_}Jan Horak <jhorak@redhat.com> - 102.3.0-7cEZ- Fix for expat CVE-2022-40674 and non functional webrtcNO_AJan Horak <jhorak@redhat.com> - 102.3.0-6c p- Update to 102.3.0 build1ONaAEike Rathke <erack@redhat.com> - 91.12.0-1b?- Update to 91.12.0 build1

_?/T_Na_AJan Horak <jhorak@redhat.com> - 102.3.0-6c p- Update to 102.3.0 build1O`aAEike Rathke <erack@redhat.com> - 102.8.0-2cw- Update to 102.8.0 build2O_aAEike Rathke <erack@redhat.com> - 102.8.0-1c=@- Update to 102.8.0 build1O^aAEike Rathke <erack@redhat.com> - 102.7.0-1cS@- Update to 102.7.0 build1]_-Jan Horak <jhorak@redhat.com> - 102.6.0-2c@- Add firefox-x11 subpackage to allow explicit run of firefox under x11 on RHEL9O\aAEike Rathke <erack@redhat.com> - 102.6.0-1c.- Update to 102.6.0 build1i[_wJan Horak <jhorak@redhat.com> - 102.5.0-2c@- Added libwebrtc screencast patch for newer featuresOZaAEike Rathke <erack@redhat.com> - 102.5.0-1ck@- Update to 102.5.0 build1OYaAEike Rathke <erack@redhat.com> - 102.4.0-1cF@- Update to 102.4.0 build1lX_}Jan Horak <jhorak@redhat.com> - 102.3.0-7cEZ- Fix for expat CVE-2022-40674 and non functional webrtc

^?/T^OkaAEike Rathke <erack@redhat.com> - 102.5.0-1ck@- Update to 102.5.0 build1OjaAEike Rathke <erack@redhat.com> - 102.8.0-2cw- Update to 102.8.0 build2OiaAEike Rathke <erack@redhat.com> - 102.8.0-1c=@- Update to 102.8.0 build1OhaAEike Rathke <erack@redhat.com> - 102.7.0-1cS@- Update to 102.7.0 build1g_-Jan Horak <jhorak@redhat.com> - 102.6.0-2c@- Add firefox-x11 subpackage to allow explicit run of firefox under x11 on RHEL9OfaAEike Rathke <erack@redhat.com> - 102.6.0-1c.- Update to 102.6.0 build1ie_wJan Horak <jhorak@redhat.com> - 102.5.0-2c@- Added libwebrtc screencast patch for newer featuresOdaAEike Rathke <erack@redhat.com> - 102.5.0-1ck@- Update to 102.5.0 build1OcaAEike Rathke <erack@redhat.com> - 102.4.0-1cF@- Update to 102.4.0 build1lb_}Jan Horak <jhorak@redhat.com> - 102.3.0-7cEZ- Fix for expat CVE-2022-40674 and non functional webrtc

sBgqsOuaAEike Rathke <erack@redhat.com> - 102.5.0-1ck@- Update to 102.5.0 build1OtaAEike Rathke <erack@redhat.com> - 102.9.0-3d- Update to 102.9.0 build2Ws_SJan Horak <jhorak@redhat.com> - 102.9.0-2d	@- removed disable-openh264-downloadOraAEike Rathke <erack@redhat.com> - 102.9.0-1d'@- Update to 102.9.0 build1OqaAEike Rathke <erack@redhat.com> - 102.8.0-2cw- Update to 102.8.0 build2OpaAEike Rathke <erack@redhat.com> - 102.8.0-1c=@- Update to 102.8.0 build1OoaAEike Rathke <erack@redhat.com> - 102.7.0-1cS@- Update to 102.7.0 build1n_-Jan Horak <jhorak@redhat.com> - 102.6.0-2c@- Add firefox-x11 subpackage to allow explicit run of firefox under x11 on RHEL9OmaAEike Rathke <erack@redhat.com> - 102.6.0-1c.- Update to 102.6.0 build1il_wJan Horak <jhorak@redhat.com> - 102.5.0-2c@- Added libwebrtc screencast patch for newer features

er+V:eD
107322552a77011bd81b348ebfbb5f9181eec6a6de74a1a746e6bccf9773e1a6D~
7cc5e8e7cd7fd7b33ddc2f01d6d1866e7073a0a2e8ec65d4a8b21009e3f67777D}
b9339ad70e81b9edbe99c176f811eaa3f6b5564cff528ff56f4f44d677623c02D|
5b68af3481bd9ec99e96979c742095c04ad5a420aca88d0278499ae1949f56d7D{
649668855741b2c9edbad09dfdf69374c2011e1b429ea28cf0f6c96a62a14f57Dz
a2cead9a7e5666819ec51f9e5c76ccde1eaf396651494f7020eb59615a2f9a17Dy
a019256591b9ba5eafbd13f6202b604bb7a7441347110ad87f864f0f8d374298Dx
1a25dc8c20fd98c6b44d7a50ee5bbeab01a9250c1764965613176ca25661a781Dw
39a345eb07bae6f35b9362289fb910cb39998826047249bc3991a0ab55547bceDv
eabf42cd353ef8d1bad1431cc770d9f360563c64237198926aaa475aab327c3dDu
daff96fd89f92832ea99fda83cf1b76e717202ee8aa4dbe27e75350ce028065fDt
469ca6e8993db68735d7333e493a80dd4dde10f37d4c15b290e072922a543da8Ds
a83374c57cbdfe6fe09065ecf3df2781d4ed835b1b41143f2b4e74dde0e6a8cd

,Bgq,aKEike Rathke <erack@redhat.com> - 115.4.0-1e.w@- Update to 115.4.0 build1
- Add fix for CVE-2023-44488
- Set homepage from os-release HOME_URLO~aAEike Rathke <erack@redhat.com> - 102.9.0-3d- Update to 102.9.0 build2W}_SJan Horak <jhorak@redhat.com> - 102.9.0-2d	@- removed disable-openh264-downloadO|aAEike Rathke <erack@redhat.com> - 102.9.0-1d'@- Update to 102.9.0 build1O{aAEike Rathke <erack@redhat.com> - 102.8.0-2cw- Update to 102.8.0 build2OzaAEike Rathke <erack@redhat.com> - 102.8.0-1c=@- Update to 102.8.0 build1OyaAEike Rathke <erack@redhat.com> - 102.7.0-1cS@- Update to 102.7.0 build1x_-Jan Horak <jhorak@redhat.com> - 102.6.0-2c@- Add firefox-x11 subpackage to allow explicit run of firefox under x11 on RHEL9OwaAEike Rathke <erack@redhat.com> - 102.6.0-1c.- Update to 102.6.0 build1iv_wJan Horak <jhorak@redhat.com> - 102.5.0-2c@- Added libwebrtc screencast patch for newer features
!\
K`s!O
aAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1	aKEike Rathke <erack@redhat.com> - 115.4.0-1e.w@- Update to 115.4.0 build1
- Add fix for CVE-2023-44488
- Set homepage from os-release HOME_URLQcCEike Rathke <erack@redhat.com> - 115.10.0-1f-- Update to 115.10.0 build1K_;Jan Horak <jhorak@redhat.com> - 115.9.1-2f-- Removed expat CVE fixHa3Eike Rathke <erack@redhat.com> - 115.9.1-1er- Update to 115.9.1OaAEike Rathke <erack@redhat.com> - 115.9.0-2e8@- Update to 115.9.0 build2jawEike Rathke <erack@redhat.com> - 115.9.0-1eC- Update to 115.9.0 build1
- Fix expat CVE-2023-52425OaAEike Rathke <erack@redhat.com> - 115.8.0-1eY- Update to 115.8.0 build1OaAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1OaAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1OaAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1
h\
K^hOaAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1OaAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1OaAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1QcCEike Rathke <erack@redhat.com> - 115.10.0-1f-- Update to 115.10.0 build1K_;Jan Horak <jhorak@redhat.com> - 115.9.1-2f-- Removed expat CVE fixHa3Eike Rathke <erack@redhat.com> - 115.9.1-1er- Update to 115.9.1OaAEike Rathke <erack@redhat.com> - 115.9.0-2e8@- Update to 115.9.0 build2jawEike Rathke <erack@redhat.com> - 115.9.0-1eC- Update to 115.9.0 build1
- Fix expat CVE-2023-52425O
aAEike Rathke <erack@redhat.com> - 115.8.0-1eY- Update to 115.8.0 build1OaAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1OaAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1
fAV\
fO aAEike Rathke <erack@redhat.com> - 115.8.0-1eY- Update to 115.8.0 build1OaAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1OaAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1OaAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1QcCEike Rathke <erack@redhat.com> - 115.11.0-1f:- Update to 115.11.0 build1QcCEike Rathke <erack@redhat.com> - 115.10.0-1f-- Update to 115.10.0 build1K_;Jan Horak <jhorak@redhat.com> - 115.9.1-2f-- Removed expat CVE fixHa3Eike Rathke <erack@redhat.com> - 115.9.1-1er- Update to 115.9.1OaAEike Rathke <erack@redhat.com> - 115.9.0-2e8@- Update to 115.9.0 build2jawEike Rathke <erack@redhat.com> - 115.9.0-1eC- Update to 115.9.0 build1
- Fix expat CVE-2023-52425OaAEike Rathke <erack@redhat.com> - 115.8.0-1eY- Update to 115.8.0 build1
KAT\
KO+aAEike Rathke <erack@redhat.com> - 115.9.0-2e8@- Update to 115.9.0 build2j*awEike Rathke <erack@redhat.com> - 115.9.0-1eC- Update to 115.9.0 build1
- Fix expat CVE-2023-52425O)aAEike Rathke <erack@redhat.com> - 115.8.0-1eY- Update to 115.8.0 build1O(aAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1O'aAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1Q&cCEike Rathke <erack@redhat.com> - 115.11.0-1f:- Update to 115.11.0 build1Q%cCEike Rathke <erack@redhat.com> - 115.10.0-1f-- Update to 115.10.0 build1K$_;Jan Horak <jhorak@redhat.com> - 115.9.1-2f-- Removed expat CVE fixH#a3Eike Rathke <erack@redhat.com> - 115.9.1-1er- Update to 115.9.1O"aAEike Rathke <erack@redhat.com> - 115.9.0-2e8@- Update to 115.9.0 build2j!awEike Rathke <erack@redhat.com> - 115.9.0-1eC- Update to 115.9.0 build1
- Fix expat CVE-2023-52425
kgkukH6a3Eike Rathke <erack@redhat.com> - 115.9.1-1er- Update to 115.9.1O5aAEike Rathke <erack@redhat.com> - 115.9.0-2e8@- Update to 115.9.0 build2j4awEike Rathke <erack@redhat.com> - 115.9.0-1eC- Update to 115.9.0 build1
- Fix expat CVE-2023-52425O3aAEike Rathke <erack@redhat.com> - 115.8.0-1eY- Update to 115.8.0 build1O2aAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1O1aAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1Q0cCEike Rathke <erack@redhat.com> - 115.12.0-1f_- Update to 115.12.0 build1Q/cCEike Rathke <erack@redhat.com> - 115.11.0-1f:- Update to 115.11.0 build1Q.cCEike Rathke <erack@redhat.com> - 115.10.0-1f-- Update to 115.10.0 build1K-_;Jan Horak <jhorak@redhat.com> - 115.9.1-2f-- Removed expat CVE fixH,a3Eike Rathke <erack@redhat.com> - 115.9.1-1er- Update to 115.9.1
^
b|.HAa3Eike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1K@_;Jan Horak <jhorak@redhat.com> - 115.3.0-1e0@- Update to 115.3.0 ESRK?_;Jan Horak <jhorak@redhat.com> - 115.2.0-3d- Update to 115.2.0 ESRK>_;Jan Horak <jhorak@redhat.com> - 115.1.0-1dE@- Update to 115.1.0 ESRK=_;Jan Horak <jhorak@redhat.com> - 115.0.2-1d-@- Update to 115.0.2 ESRG<_3Jan Horak <jhorak@redhat.com> - 115.0b8-1d@- Update to 115.0b8Q;cCEike Rathke <erack@redhat.com> - 102.11.0-2dS@- Update to 102.11.0 build2Q:cCEike Rathke <erack@redhat.com> - 115.12.0-1f_- Update to 115.12.0 build1Q9cCEike Rathke <erack@redhat.com> - 115.11.0-1f:- Update to 115.11.0 build1Q8cCEike Rathke <erack@redhat.com> - 115.10.0-1f-- Update to 115.10.0 build1K7_;Jan Horak <jhorak@redhat.com> - 115.9.1-2f-- Removed expat CVE fix

go%;HKa3Eike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1KJ_;Jan Horak <jhorak@redhat.com> - 115.3.0-1e0@- Update to 115.3.0 ESRKI_;Jan Horak <jhorak@redhat.com> - 115.2.0-3d- Update to 115.2.0 ESRKH_;Jan Horak <jhorak@redhat.com> - 115.1.0-1dE@- Update to 115.1.0 ESRKG_;Jan Horak <jhorak@redhat.com> - 115.0.2-1d-@- Update to 115.0.2 ESRGF_3Jan Horak <jhorak@redhat.com> - 115.0b8-1d@- Update to 115.0b8QEcCEike Rathke <erack@redhat.com> - 102.11.0-2dS@- Update to 102.11.0 build2ODaAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1OCaAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1BaKEike Rathke <erack@redhat.com> - 115.4.0-1e.w@- Update to 115.4.0 build1
- Add fix for CVE-2023-44488
- Set homepage from os-release HOME_URL

]gy+A]UaKEike Rathke <erack@redhat.com> - 115.4.0-1e.w@- Update to 115.4.0 build1
- Add fix for CVE-2023-44488
- Set homepage from os-release HOME_URLHTa3Eike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1KS_;Jan Horak <jhorak@redhat.com> - 115.3.0-1e0@- Update to 115.3.0 ESRKR_;Jan Horak <jhorak@redhat.com> - 115.2.0-3d- Update to 115.2.0 ESRKQ_;Jan Horak <jhorak@redhat.com> - 115.1.0-1dE@- Update to 115.1.0 ESRKP_;Jan Horak <jhorak@redhat.com> - 115.0.2-1d-@- Update to 115.0.2 ESRGO_3Jan Horak <jhorak@redhat.com> - 115.0b8-1d@- Update to 115.0b8ONaAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1OMaAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1LaKEike Rathke <erack@redhat.com> - 115.4.0-1e.w@- Update to 115.4.0 build1
- Add fix for CVE-2023-44488
- Set homepage from os-release HOME_URL
R\
r$=RO`aAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1_aKEike Rathke <erack@redhat.com> - 115.4.0-1e.w@- Update to 115.4.0 build1
- Add fix for CVE-2023-44488
- Set homepage from os-release HOME_URLH^a3Eike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1K]_;Jan Horak <jhorak@redhat.com> - 115.3.0-1e0@- Update to 115.3.0 ESRK\_;Jan Horak <jhorak@redhat.com> - 115.2.0-3d- Update to 115.2.0 ESRK[_;Jan Horak <jhorak@redhat.com> - 115.1.0-1dE@- Update to 115.1.0 ESRKZ_;Jan Horak <jhorak@redhat.com> - 115.0.2-1d-@- Update to 115.0.2 ESRGY_3Jan Horak <jhorak@redhat.com> - 115.0b8-1d@- Update to 115.0b8OXaAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1OWaAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1OVaAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1
J\r$@JOkaAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1OjaAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1OiaAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1haKEike Rathke <erack@redhat.com> - 115.4.0-1e.w@- Update to 115.4.0 build1
- Add fix for CVE-2023-44488
- Set homepage from os-release HOME_URLHga3Eike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1Kf_;Jan Horak <jhorak@redhat.com> - 115.3.0-1e0@- Update to 115.3.0 ESRKe_;Jan Horak <jhorak@redhat.com> - 115.2.0-3d- Update to 115.2.0 ESRKd_;Jan Horak <jhorak@redhat.com> - 115.1.0-1dE@- Update to 115.1.0 ESRKc_;Jan Horak <jhorak@redhat.com> - 115.0.2-1d-@- Update to 115.0.2 ESRObaAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1OaaAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1
J`v+@JOvaAEike Rathke <erack@redhat.com> - 115.8.0-1eY- Update to 115.8.0 build1OuaAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1OtaAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1OsaAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1raKEike Rathke <erack@redhat.com> - 115.4.0-1e.w@- Update to 115.4.0 build1
- Add fix for CVE-2023-44488
- Set homepage from os-release HOME_URLHqa3Eike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1Kp_;Jan Horak <jhorak@redhat.com> - 115.3.0-1e0@- Update to 115.3.0 ESRKo_;Jan Horak <jhorak@redhat.com> - 115.2.0-3d- Update to 115.2.0 ESRKn_;Jan Horak <jhorak@redhat.com> - 115.1.0-1dE@- Update to 115.1.0 ESRKm_;Jan Horak <jhorak@redhat.com> - 115.0.2-1d-@- Update to 115.0.2 ESROlaAEike Rathke <erack@redhat.com> - 115.8.0-1eY- Update to 115.8.0 build1

er+V:eD
7724d8a7b5c53b6b19107130e41d127672ad5e6814dd6d9cdf6130a27f22354bD
6a6db0a030199ad5a8e0edde0f8458ca5391f94ac4ccd7a93c3c186326026cc3D

d09bdd004c3fac87661119d619afb43d9ad9824ef8a2e58fa51c55f0211f12d9D	
de58dba9cc8af79c110d13626931309529fa1a8782a121fbfc29dd03e58e58b6D
13154f5e2510e00d260ae211027b13f44ca11e49508ba2237ccccda2eea337b2D
fc48a72a9a0a8898553b10f1e151b5cb865e23d1ae5200c58cf22572c71ff6acD
a6fc6ceec2ef96703e31fadfc56988518eb77de39ff4fd2e69fa98b88e033dd7D
843fb795c9bf323f16859c41219123409abcc114812537da012befe15091fbc3D
6d8bf16512d109e75893de1fd5c3fff8aa8557a12556eccd6e6c8fbfd7f184adD
74e98e4966e80435f954bb2859be485730a97c3e547acc848d76d50f49af0329D
06de00e45a444bd8381c6526ee4a204b80511ebbca8c8b0b52bfd9d9bacec74cD
2f160bf3a57455fd82821ea858e6ab2789596f1ae502a2b3968383670f17296fD
33dd225ef7b01c077e7d0977782fa69f3d8fd4cea6363f4cde213cc37694b3a2
.g|*|.K_;Jan Horak <jhorak@redhat.com> - 115.3.0-1e0@- Update to 115.3.0 ESRHa3Eike Rathke <erack@redhat.com> - 115.9.1-1er- Update to 115.9.1OaAEike Rathke <erack@redhat.com> - 115.9.0-2e8@- Update to 115.9.0 build2j~awEike Rathke <erack@redhat.com> - 115.9.0-1eC- Update to 115.9.0 build1
- Fix expat CVE-2023-52425O}aAEike Rathke <erack@redhat.com> - 115.8.0-1eY- Update to 115.8.0 build1O|aAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1O{aAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1OzaAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1yaKEike Rathke <erack@redhat.com> - 115.4.0-1e.w@- Update to 115.4.0 build1
- Add fix for CVE-2023-44488
- Set homepage from os-release HOME_URLHxa3Eike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1Kw_;Jan Horak <jhorak@redhat.com> - 115.3.0-1e0@- Update to 115.3.0 ESR

x&gHa3Eike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1H
a3Eike Rathke <erack@redhat.com> - 115.9.1-1er- Update to 115.9.1O	aAEike Rathke <erack@redhat.com> - 115.9.0-2e8@- Update to 115.9.0 build2jawEike Rathke <erack@redhat.com> - 115.9.0-1eC- Update to 115.9.0 build1
- Fix expat CVE-2023-52425OaAEike Rathke <erack@redhat.com> - 115.8.0-1eY- Update to 115.8.0 build1OaAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1OaAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1OaAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1aKEike Rathke <erack@redhat.com> - 115.4.0-1e.w@- Update to 115.4.0 build1
- Add fix for CVE-2023-44488
- Set homepage from os-release HOME_URLHa3Eike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1

|gq`|Ha3Eike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1K_;Jan Horak <jhorak@redhat.com> - 115.9.1-2f-- Removed expat CVE fixHa3Eike Rathke <erack@redhat.com> - 115.9.1-1er- Update to 115.9.1OaAEike Rathke <erack@redhat.com> - 115.9.0-2e8@- Update to 115.9.0 build2jawEike Rathke <erack@redhat.com> - 115.9.0-1eC- Update to 115.9.0 build1
- Fix expat CVE-2023-52425OaAEike Rathke <erack@redhat.com> - 115.8.0-1eY- Update to 115.8.0 build1OaAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1OaAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1O
aAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1aKEike Rathke <erack@redhat.com> - 115.4.0-1e.w@- Update to 115.4.0 build1
- Add fix for CVE-2023-44488
- Set homepage from os-release HOME_URL
7gq`7I ]9Jan Horak <jhorak@redhat.com> - 68.6.1-1^- Update to 68.6.1 ESRAG?Jan Horak <jhorak@redhat.com>^_@- Update to 68.6.0 build1K_;Jan Horak <jhorak@redhat.com> - 115.9.1-2f-- Removed expat CVE fixHa3Eike Rathke <erack@redhat.com> - 115.9.1-1er- Update to 115.9.1OaAEike Rathke <erack@redhat.com> - 115.9.0-2e8@- Update to 115.9.0 build2jawEike Rathke <erack@redhat.com> - 115.9.0-1eC- Update to 115.9.0 build1
- Fix expat CVE-2023-52425OaAEike Rathke <erack@redhat.com> - 115.8.0-1eY- Update to 115.8.0 build1OaAEike Rathke <erack@redhat.com> - 115.7.0-1eo- Update to 115.7.0 build1OaAEike Rathke <erack@redhat.com> - 115.6.0-1exK@- Update to 115.6.0 build1OaAEike Rathke <erack@redhat.com> - 115.5.0-1eSa@- Update to 115.5.0 build1aKEike Rathke <erack@redhat.com> - 115.4.0-1e.w@- Update to 115.4.0 build1
- Add fix for CVE-2023-44488
- Set homepage from os-release HOME_URL
_Wg"T_W,mEMartin Stransky <stransky@redhat.com> - 68.7.0-3^@- Added fix for rhbz#1821418L+]?Jan Horak <jhorak@redhat.com> - 68.7.0-2^k@- Update to 68.7.0 build3I*]9Jan Horak <jhorak@redhat.com> - 68.6.1-1^- Update to 68.6.1 ESRA)G?Jan Horak <jhorak@redhat.com>^_@- Update to 68.6.0 build1B(GAJan Horak <jhorak@redhat.com>_>e- Update to 68.12.0 build1B'GAJan Horak <jhorak@redhat.com>_{- Update to 68.11.0 build1B&GAJan Horak <jhorak@redhat.com>^@- Update to 68.10.0 build1`%G}Jan Horak <jhorak@redhat.com>^@- Update to 68.9.0 build1
- Added patch for pipewire 0.3F$GIJan Horak <jhorak@redhat.com>^>@- Added s390x specific patchesA#G?Jan Horak <jhorak@redhat.com>^l@- Update to 68.8.0 build1W"mEMartin Stransky <stransky@redhat.com> - 68.7.0-3^@- Added fix for rhbz#1821418L!]?Jan Horak <jhorak@redhat.com> - 68.7.0-2^k@- Update to 68.7.0 build3
UsASU[8]]Jan Horak <jhorak@redhat.com> - 78.7.0-3`"y@- Fixing install prefix for the homepageM7_?Eike Rathke <erack@redhat.com> - 78.7.0-2`
@- Update to 78.7.0 build2M6_?Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0 build1M5_?Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1 build1L4]?Jan Horak <jhorak@redhat.com> - 78.6.0-1_
- Update to 78.6.0 build1L3]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build1B2GAJan Horak <jhorak@redhat.com>_>e- Update to 68.12.0 build1B1GAJan Horak <jhorak@redhat.com>_{- Update to 68.11.0 build1B0GAJan Horak <jhorak@redhat.com>^@- Update to 68.10.0 build1`/G}Jan Horak <jhorak@redhat.com>^@- Update to 68.9.0 build1
- Added patch for pipewire 0.3F.GIJan Horak <jhorak@redhat.com>^>@- Added s390x specific patchesA-G?Jan Horak <jhorak@redhat.com>^l@- Update to 68.8.0 build1
Gg}.>GMD_?Eike Rathke <erack@redhat.com> - 78.8.0-1`-@- Update to 78.8.0 build2FC_1Eike Rathke <erack@redhat.com> - 78.7.1-1`"yA- Update to 78.7.1[B]]Jan Horak <jhorak@redhat.com> - 78.7.0-3`"y@- Fixing install prefix for the homepageMA_?Eike Rathke <erack@redhat.com> - 78.7.0-2`
@- Update to 78.7.0 build2M@_?Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0 build1M?_?Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1 build1L>]?Jan Horak <jhorak@redhat.com> - 78.6.0-1_
- Update to 78.6.0 build1L=]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build1H<a3Eike Rathke <erack@redhat.com> - 78.10.0-1`~@- Update to 78.10.0M;_?Eike Rathke <erack@redhat.com> - 78.9.0-1`Q@- Update to 78.9.0 build1M:_?Eike Rathke <erack@redhat.com> - 78.8.0-1`-@- Update to 78.8.0 build2F9_1Eike Rathke <erack@redhat.com> - 78.7.1-1`"yA- Update to 78.7.1
xeg~3xfOaoEike Rathke <erack@redhat.com> - 78.11.0-2`- Fix rhel_minor_version for dist .el8_4 and .el8ONaAEike Rathke <erack@redhat.com> - 78.11.0-1`- Update to 78.11.0 build1HMa3Eike Rathke <erack@redhat.com> - 78.10.0-1`~@- Update to 78.10.0ML_?Eike Rathke <erack@redhat.com> - 78.9.0-1`Q@- Update to 78.9.0 build1MK_?Eike Rathke <erack@redhat.com> - 78.8.0-1`-@- Update to 78.8.0 build2FJ_1Eike Rathke <erack@redhat.com> - 78.7.1-1`"yA- Update to 78.7.1[I]]Jan Horak <jhorak@redhat.com> - 78.7.0-3`"y@- Fixing install prefix for the homepageMH_?Eike Rathke <erack@redhat.com> - 78.7.0-2`
@- Update to 78.7.0 build2MG_?Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0 build1HFa3Eike Rathke <erack@redhat.com> - 78.10.0-1`~@- Update to 78.10.0ME_?Eike Rathke <erack@redhat.com> - 78.9.0-1`Q@- Update to 78.9.0 build1
[T]
r [YZaU	Eike Rathke <erack@redhat.com> - 78.11.0-3`- Update to 78.11.0 build2 (release)fYao	Eike Rathke <erack@redhat.com> - 78.11.0-2`- Fix rhel_minor_version for dist .el8_4 and .el8OXaA	Eike Rathke <erack@redhat.com> - 78.11.0-1`- Update to 78.11.0 build1HWa3	Eike Rathke <erack@redhat.com> - 78.10.0-1`~@- Update to 78.10.0MV_?	Eike Rathke <erack@redhat.com> - 78.9.0-1`Q@- Update to 78.9.0 build1MU_?	Eike Rathke <erack@redhat.com> - 78.8.0-1`-@- Update to 78.8.0 build2FT_1	Eike Rathke <erack@redhat.com> - 78.7.1-1`"yA- Update to 78.7.1[S]]	Jan Horak <jhorak@redhat.com> - 78.7.0-3`"y@- Fixing install prefix for the homepageMR_?	Eike Rathke <erack@redhat.com> - 78.7.0-2`
@- Update to 78.7.0 build2MQ_?	Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0 build1YPaUEike Rathke <erack@redhat.com> - 78.11.0-3`- Update to 78.11.0 build2 (release)
eR	iceMe_?Eike Rathke <erack@redhat.com> - 78.7.0-2`
@- Update to 78.7.0 build2OdaA
Eike Rathke <erack@redhat.com> - 78.12.0-1`@- Update to 78.12.0 build1YcaU
Eike Rathke <erack@redhat.com> - 78.11.0-3`- Update to 78.11.0 build2 (release)fbao
Eike Rathke <erack@redhat.com> - 78.11.0-2`- Fix rhel_minor_version for dist .el8_4 and .el8OaaA
Eike Rathke <erack@redhat.com> - 78.11.0-1`- Update to 78.11.0 build1H`a3
Eike Rathke <erack@redhat.com> - 78.10.0-1`~@- Update to 78.10.0M__?
Eike Rathke <erack@redhat.com> - 78.9.0-1`Q@- Update to 78.9.0 build1M^_?
Eike Rathke <erack@redhat.com> - 78.8.0-1`-@- Update to 78.8.0 build2F]_1
Eike Rathke <erack@redhat.com> - 78.7.1-1`"yA- Update to 78.7.1[\]]
Jan Horak <jhorak@redhat.com> - 78.7.0-3`"y@- Fixing install prefix for the homepageM[_?
Eike Rathke <erack@redhat.com> - 78.7.0-2`
@- Update to 78.7.0 build2
eY	nWeMp_?Eike Rathke <erack@redhat.com> - 78.9.0-1`Q@- Update to 78.9.0 build1Mo_?Eike Rathke <erack@redhat.com> - 78.8.0-1`-@- Update to 78.8.0 build2OnaAEike Rathke <erack@redhat.com> - 78.12.0-1`@- Update to 78.12.0 build1YmaUEike Rathke <erack@redhat.com> - 78.11.0-3`- Update to 78.11.0 build2 (release)flaoEike Rathke <erack@redhat.com> - 78.11.0-2`- Fix rhel_minor_version for dist .el8_4 and .el8OkaAEike Rathke <erack@redhat.com> - 78.11.0-1`- Update to 78.11.0 build1Hja3Eike Rathke <erack@redhat.com> - 78.10.0-1`~@- Update to 78.10.0Mi_?Eike Rathke <erack@redhat.com> - 78.9.0-1`Q@- Update to 78.9.0 build1Mh_?Eike Rathke <erack@redhat.com> - 78.8.0-1`-@- Update to 78.8.0 build2Fg_1Eike Rathke <erack@redhat.com> - 78.7.1-1`"yA- Update to 78.7.1[f]]Jan Horak <jhorak@redhat.com> - 78.7.0-3`"y@- Fixing install prefix for the homepage
icLTiH{a3
Eike Rathke <erack@redhat.com> - 78.10.0-1`~@- Update to 78.10.0Mz_?
Eike Rathke <erack@redhat.com> - 78.9.0-1`Q@- Update to 78.9.0 build1My_?
Eike Rathke <erack@redhat.com> - 78.8.0-1`-@- Update to 78.8.0 build2OxaAEike Rathke <erack@redhat.com> - 78.13.0-2a- Update to 78.13.0 build2OwaAEike Rathke <erack@redhat.com> - 78.13.0-1a	/- Update to 78.13.0 build1Qv_GJan Horak <jhorak@redhat.com> - 78.12.0-2`t- Rebuild to pickup older nssOuaAEike Rathke <erack@redhat.com> - 78.12.0-1`@- Update to 78.12.0 build1YtaUEike Rathke <erack@redhat.com> - 78.11.0-3`- Update to 78.11.0 build2 (release)fsaoEike Rathke <erack@redhat.com> - 78.11.0-2`- Fix rhel_minor_version for dist .el8_4 and .el8OraAEike Rathke <erack@redhat.com> - 78.11.0-1`- Update to 78.11.0 build1Hqa3Eike Rathke <erack@redhat.com> - 78.10.0-1`~@- Update to 78.10.0

er+V:eD
b351574a459bf47d5aed5e921e49e33fc565cab9b3d72ce5cd6fefba1b6f83c9D
a64d622fd50cce3d3743013a5534e4fed4985139f60314ee23246e08601835cfD
765577455a2956ce537d4c4d5768286fbead171668c41853b5d6f0989dd4013cD
6ce9a07c50256531ba281b344b048ba26881b6d3612f2c4ee5f35d0801d8be57D
4276584eb593d2fb304ab50518d7e2c4f955abe8fc5b3d1b9f0dd053d363f298D
cb3a549fe050cd75184479500b542065e37366ce62d90769646352bf2d9798a2D
d8f95fca6716286e91c7ab7b9be9bd359800c870cc0bdb90128bf93397e9352dD
54c6e6aa53fe175c25dc35fe3f6476d9b195d85a4fc5e64d5625d1731cc5b1ceD
c95a549af2d83400b97e70bcf7ebf1fbbb8b58bb768c6f7761edc982d7326504D
06c9237d3d292ac356ab89dc89e2e9d7f41d6b52eaa838d872573cdeac93d2e7D
2a94cd35eaf2c096188c8f30e38bb1ae656122294b6b2f692f185e9533bf7f02D
4612dc1b815321d8acda2baafa9107d32d2e88453f1c98a341c59936db87f826D

64a964dbf122edcb897186c8824b60976d45bd7ddce017d938404771e1396a1e
IECOIfaoEike Rathke <erack@redhat.com> - 78.11.0-2`- Fix rhel_minor_version for dist .el8_4 and .el8OaAEike Rathke <erack@redhat.com> - 78.11.0-1`- Update to 78.11.0 build1Ha3Eike Rathke <erack@redhat.com> - 78.10.0-1`~@- Update to 78.10.0M_?Eike Rathke <erack@redhat.com> - 78.9.0-1`Q@- Update to 78.9.0 build1OaA
Eike Rathke <erack@redhat.com> - 78.13.0-2a- Update to 78.13.0 build2OaA
Eike Rathke <erack@redhat.com> - 78.13.0-1a	/- Update to 78.13.0 build1Q_G
Jan Horak <jhorak@redhat.com> - 78.12.0-2`t- Rebuild to pickup older nssOaA
Eike Rathke <erack@redhat.com> - 78.12.0-1`@- Update to 78.12.0 build1Y~aU
Eike Rathke <erack@redhat.com> - 78.11.0-3`- Update to 78.11.0 build2 (release)f}ao
Eike Rathke <erack@redhat.com> - 78.11.0-2`- Fix rhel_minor_version for dist .el8_4 and .el8O|aA
Eike Rathke <erack@redhat.com> - 78.11.0-1`- Update to 78.11.0 build1
VRZmVYaUEike Rathke <erack@redhat.com> - 78.11.0-3`- Update to 78.11.0 build2 (release)faoEike Rathke <erack@redhat.com> - 78.11.0-2`- Fix rhel_minor_version for dist .el8_4 and .el8OaAEike Rathke <erack@redhat.com> - 78.11.0-1`- Update to 78.11.0 build1Ha3Eike Rathke <erack@redhat.com> - 78.10.0-1`~@- Update to 78.10.0M
_?Eike Rathke <erack@redhat.com> - 78.9.0-1`Q@- Update to 78.9.0 build1OaAEike Rathke <erack@redhat.com> - 78.14.0-1a0- Update to 78.14.0 build1OaAEike Rathke <erack@redhat.com> - 78.13.0-2a- Update to 78.13.0 build2O
aAEike Rathke <erack@redhat.com> - 78.13.0-1a	/- Update to 78.13.0 build1Q	_GJan Horak <jhorak@redhat.com> - 78.12.0-2`t- Rebuild to pickup older nssOaAEike Rathke <erack@redhat.com> - 78.12.0-1`@- Update to 78.12.0 build1YaUEike Rathke <erack@redhat.com> - 78.11.0-3`- Update to 78.11.0 build2 (release)
AZdw.ABGAJan Horak <jhorak@redhat.com>_@- Update to 68.11.0 build1BGAJan Horak <jhorak@redhat.com>^@- Update to 68.10.0 build1`G}Jan Horak <jhorak@redhat.com>^@- Update to 68.9.0 build1
- Added patch for pipewire 0.3FGIJan Horak <jhorak@redhat.com>^>@- Added s390x specific patchesAG?Jan Horak <jhorak@redhat.com>^l@- Update to 68.8.0 build1WmEMartin Stransky <stransky@redhat.com> - 68.7.0-3^@- Added fix for rhbz#1821418L]?Jan Horak <jhorak@redhat.com> - 68.7.0-2^k@- Update to 68.7.0 build3OaAEike Rathke <erack@redhat.com> - 78.14.0-1a0- Update to 78.14.0 build1OaAEike Rathke <erack@redhat.com> - 78.13.0-2a- Update to 78.13.0 build2OaAEike Rathke <erack@redhat.com> - 78.13.0-1a	/- Update to 78.13.0 build1Q_GJan Horak <jhorak@redhat.com> - 78.12.0-2`t- Rebuild to pickup older nssOaAEike Rathke <erack@redhat.com> - 78.12.0-1`@- Update to 78.12.0 build1
hmu1@hA)G?Jan Horak <jhorak@redhat.com>_d@- Update to 78.3.0 build1L(]?Jan Horak <jhorak@redhat.com> - 78.2.0-3_;- Update to 78.2.0 build1B'GAJan Horak <jhorak@redhat.com>_@- Update to 68.11.0 build1B&GAJan Horak <jhorak@redhat.com>^@- Update to 68.10.0 build1`%G}Jan Horak <jhorak@redhat.com>^@- Update to 68.9.0 build1
- Added patch for pipewire 0.3F$GIJan Horak <jhorak@redhat.com>^>@- Added s390x specific patchesA#G?Jan Horak <jhorak@redhat.com>^l@- Update to 68.8.0 build1W"mEMartin Stransky <stransky@redhat.com> - 68.7.0-3^@- Added fix for rhbz#1821418L!]?Jan Horak <jhorak@redhat.com> - 68.7.0-2^k@- Update to 68.7.0 build3L ]?Jan Horak <jhorak@redhat.com> - 78.4.0-1_@- Update to 78.4.0 build2AG?Jan Horak <jhorak@redhat.com>_d@- Update to 78.3.0 build1L]?Jan Horak <jhorak@redhat.com> - 78.2.0-3_;- Update to 78.2.0 build1
&h{,Io&F5GIJan Horak <jhorak@redhat.com>^>@- Added s390x specific patchesR4Ceerack@redhat.com - 78.4.1-1_- Update to 78.4.1
- Filtering nss/nspr libs3]'Jan Horak <jhorak@redhat.com> - 78.4.0-3_- Fixing flatpak build, fixing firefox.sh.in to not disable langpacks loadingM2]AJan Horak <jhorak@redhat.com> - 78.4.0-2_- Enable addon sideloadingL1]?Jan Horak <jhorak@redhat.com> - 78.4.0-1_@- Update to 78.4.0 build2A0G?Jan Horak <jhorak@redhat.com>_d@- Update to 78.3.0 build1L/]?Jan Horak <jhorak@redhat.com> - 78.2.0-3_;- Update to 78.2.0 build1B.GAJan Horak <jhorak@redhat.com>_@- Update to 68.11.0 build1B-GAJan Horak <jhorak@redhat.com>^@- Update to 68.10.0 build1`,G}Jan Horak <jhorak@redhat.com>^@- Update to 68.9.0 build1
- Added patch for pipewire 0.3F+GIJan Horak <jhorak@redhat.com>^>@- Added s390x specific patchesL*]?Jan Horak <jhorak@redhat.com> - 78.4.0-1_@- Update to 78.4.0 build2
_X1\_B@GAJan Horak <jhorak@redhat.com>^@- Update to 68.10.0 build1`?G}Jan Horak <jhorak@redhat.com>^@- Update to 68.9.0 build1
- Added patch for pipewire 0.3R>Ceerack@redhat.com - 78.4.1-1_- Update to 78.4.1
- Filtering nss/nspr libs=]'Jan Horak <jhorak@redhat.com> - 78.4.0-3_- Fixing flatpak build, fixing firefox.sh.in to not disable langpacks loadingM<]AJan Horak <jhorak@redhat.com> - 78.4.0-2_- Enable addon sideloadingL;]?Jan Horak <jhorak@redhat.com> - 78.4.0-1_@- Update to 78.4.0 build2A:G?Jan Horak <jhorak@redhat.com>_d@- Update to 78.3.0 build1L9]?Jan Horak <jhorak@redhat.com> - 78.2.0-3_;- Update to 78.2.0 build1B8GAJan Horak <jhorak@redhat.com>_@- Update to 68.11.0 build1B7GAJan Horak <jhorak@redhat.com>^@- Update to 68.10.0 build1`6G}Jan Horak <jhorak@redhat.com>^@- Update to 68.9.0 build1
- Added patch for pipewire 0.3
>l(z>LL]?Jan Horak <jhorak@redhat.com> - 78.2.0-3_;- Update to 78.2.0 build1BKGAJan Horak <jhorak@redhat.com>_@- Update to 68.11.0 build1BJGAJan Horak <jhorak@redhat.com>^@- Update to 68.10.0 build1`IG}Jan Horak <jhorak@redhat.com>^@- Update to 68.9.0 build1
- Added patch for pipewire 0.3LH]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build18GC1erack@redhat.com - 78.4.1-1_- Update to 78.4.1F]'Jan Horak <jhorak@redhat.com> - 78.4.0-3_- Fixing flatpak build, fixing firefox.sh.in to not disable langpacks loadingME]AJan Horak <jhorak@redhat.com> - 78.4.0-2_- Enable addon sideloadingLD]?Jan Horak <jhorak@redhat.com> - 78.4.0-1_@- Update to 78.4.0 build2ACG?Jan Horak <jhorak@redhat.com>_d@- Update to 78.3.0 build1LB]?Jan Horak <jhorak@redhat.com> - 78.2.0-3_;- Update to 78.2.0 build1BAGAJan Horak <jhorak@redhat.com>_@- Update to 68.11.0 build1
Rm]5RMX]AJan Horak <jhorak@redhat.com> - 78.4.0-2_- Enable addon sideloadingLW]?Jan Horak <jhorak@redhat.com> - 78.4.0-1_@- Update to 78.4.0 build2AVG?Jan Horak <jhorak@redhat.com>_d@- Update to 78.3.0 build1LU]?Jan Horak <jhorak@redhat.com> - 78.2.0-3_;- Update to 78.2.0 build1BTGAJan Horak <jhorak@redhat.com>_@- Update to 68.11.0 build1BSGAJan Horak <jhorak@redhat.com>^@- Update to 68.10.0 build1LR]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build18QC1erack@redhat.com - 78.4.1-1_- Update to 78.4.1P]'Jan Horak <jhorak@redhat.com> - 78.4.0-3_- Fixing flatpak build, fixing firefox.sh.in to not disable langpacks loadingMO]AJan Horak <jhorak@redhat.com> - 78.4.0-2_- Enable addon sideloadingLN]?Jan Horak <jhorak@redhat.com> - 78.4.0-1_@- Update to 78.4.0 build2AMG?Jan Horak <jhorak@redhat.com>_d@- Update to 78.3.0 build1
&{@]6a&8dC1erack@redhat.com - 78.4.1-1_- Update to 78.4.1c]'Jan Horak <jhorak@redhat.com> - 78.4.0-3_- Fixing flatpak build, fixing firefox.sh.in to not disable langpacks loadingMb]AJan Horak <jhorak@redhat.com> - 78.4.0-2_- Enable addon sideloadingLa]?Jan Horak <jhorak@redhat.com> - 78.4.0-1_@- Update to 78.4.0 build2A`G?Jan Horak <jhorak@redhat.com>_d@- Update to 78.3.0 build1L_]?Jan Horak <jhorak@redhat.com> - 78.2.0-3_;- Update to 78.2.0 build1B^GAJan Horak <jhorak@redhat.com>_@- Update to 68.11.0 build1B]GAJan Horak <jhorak@redhat.com>^@- Update to 68.10.0 build1L\]?Jan Horak <jhorak@redhat.com> - 78.6.0-1_
- Update to 78.6.0 build1L[]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build18ZC1erack@redhat.com - 78.4.1-1_- Update to 78.4.1Y]'Jan Horak <jhorak@redhat.com> - 78.4.0-3_- Fixing flatpak build, fixing firefox.sh.in to not disable langpacks loading
=b;f+=Mp_?Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1 build1Lo]?Jan Horak <jhorak@redhat.com> - 78.6.0-1_
- Update to 78.6.0 build1Ln]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build18mC1erack@redhat.com - 78.4.1-1_- Update to 78.4.1l]'Jan Horak <jhorak@redhat.com> - 78.4.0-3_- Fixing flatpak build, fixing firefox.sh.in to not disable langpacks loadingMk]AJan Horak <jhorak@redhat.com> - 78.4.0-2_- Enable addon sideloadingLj]?Jan Horak <jhorak@redhat.com> - 78.4.0-1_@- Update to 78.4.0 build2AiG?Jan Horak <jhorak@redhat.com>_d@- Update to 78.3.0 build1Lh]?Jan Horak <jhorak@redhat.com> - 78.2.0-3_;- Update to 78.2.0 build1BgGAJan Horak <jhorak@redhat.com>_@- Update to 68.11.0 build1Lf]?Jan Horak <jhorak@redhat.com> - 78.6.0-1_
- Update to 78.6.0 build1Le]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build1
Hl(z+HL|]?Jan Horak <jhorak@redhat.com> - 78.4.0-1_@- Update to 78.4.0 build2A{G?Jan Horak <jhorak@redhat.com>_d@- Update to 78.3.0 build1Mz_?Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1 build1Ly]?Jan Horak <jhorak@redhat.com> - 78.6.0-1_
- Update to 78.6.0 build1Lx]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build18wC1erack@redhat.com - 78.4.1-1_- Update to 78.4.1v]'Jan Horak <jhorak@redhat.com> - 78.4.0-3_- Fixing flatpak build, fixing firefox.sh.in to not disable langpacks loadingMu]AJan Horak <jhorak@redhat.com> - 78.4.0-2_- Enable addon sideloadingLt]?Jan Horak <jhorak@redhat.com> - 78.4.0-1_@- Update to 78.4.0 build2AsG?Jan Horak <jhorak@redhat.com>_d@- Update to 78.3.0 build1Lr]?Jan Horak <jhorak@redhat.com> - 78.2.0-3_;- Update to 78.2.0 build1BqGAJan Horak <jhorak@redhat.com>_@- Update to 68.11.0 build1

er+V:eD&
6d7bcceec43abb616cbffadcf76d1c208a4f658a0625d17e0b0315b3e5a4c252D%
e063c651b9c19f3ff44c19dafd53594a57c6c58f609c5e0e419a4b724c4b5f87D$
40f292198cfd1d640409908c391eac750a799c0007158bd95505cc00794862e8D#
3430976f8acda648d8659eecbc9ab33a1dcb14139a6206b64b25c7a1129d685eD"
49a94cfaa934548d43b739e469156d5cbf8467609c08c9d7583ecd18912a49b7D!
66d5ac31048d37a6a1e65da7b344292d028e8fbb82d4b9d710ab79080280254cD 
98f19e1b800783ce86112ad1cabb55fccc84a4979bb77d07ffceab8d38da6f2aD
44600066daf3f3b57b9e269737e0b0dfcd410f3a524fbbd74aec3162d6f84f7cD
67cc5f25f8e6a42f9536eb9dbe7e22e3fab22c55d87d37db23cb90136913067eD
802ef81827f925a8e48e7eac8b4f0c0e44a7873cc15a96c696316840d6541191D
c51cb2eba6f030cce0b81686cebf834e0aad1fb747875ef6fc8d06c6930fe18aD
2fe8803bf3b71fc183107689fe53ca7b40a655e57b4fc6531786f97143f55b5fD
f455772710a92ccc156759199ca532b9536d567cda99884613c0d4ec6f35ed4c
+RbM]AJan Horak <jhorak@redhat.com> - 78.4.0-2_- Enable addon sideloadingL]?Jan Horak <jhorak@redhat.com> - 78.4.0-1_@- Update to 78.4.0 build2AG?Jan Horak <jhorak@redhat.com>_d@- Update to 78.3.0 build1M_?Eike Rathke <erack@redhat.com> - 78.7.0-2`
@- Update to 78.7.0 build2M_?Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0 build1M_?Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1 build1L]?Jan Horak <jhorak@redhat.com> - 78.6.0-1_
- Update to 78.6.0 build1L]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build18C1erack@redhat.com - 78.4.1-1_- Update to 78.4.1~]'Jan Horak <jhorak@redhat.com> - 78.4.0-3_- Fixing flatpak build, fixing firefox.sh.in to not disable langpacks loadingM}]AJan Horak <jhorak@redhat.com> - 78.4.0-2_- Enable addon sideloading
T{@R-TL]?Jan Horak <jhorak@redhat.com> - 78.6.0-1_
- Update to 78.6.0 build1L]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build18C1erack@redhat.com - 78.4.1-1_- Update to 78.4.1]'Jan Horak <jhorak@redhat.com> - 78.4.0-3_- Fixing flatpak build, fixing firefox.sh.in to not disable langpacks loadingM_?Eike Rathke <erack@redhat.com> - 78.7.0-2`
@- Update to 78.7.0 build2M
_?Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0 build1M_?Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1 build1L]?Jan Horak <jhorak@redhat.com> - 78.6.0-1_
- Update to 78.6.0 build1L
]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build18	C1erack@redhat.com - 78.4.1-1_- Update to 78.4.1]'Jan Horak <jhorak@redhat.com> - 78.4.0-3_- Fixing flatpak build, fixing firefox.sh.in to not disable langpacks loading
k`iY
kM_?Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1 build1L]?Jan Horak <jhorak@redhat.com> - 78.6.0-1_
- Update to 78.6.0 build1L]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build18C1erack@redhat.com - 78.4.1-1_- Update to 78.4.1]'Jan Horak <jhorak@redhat.com> - 78.4.0-3_- Fixing flatpak build, fixing firefox.sh.in to not disable langpacks loadingM_?Eike Rathke <erack@redhat.com> - 78.8.0-1`-@- Update to 78.8.0 build2F_1Eike Rathke <erack@redhat.com> - 78.7.1-1`"yA- Update to 78.7.1[]]Jan Horak <jhorak@redhat.com> - 78.7.0-3`"y@- Fixing install prefix for the homepageM_?Eike Rathke <erack@redhat.com> - 78.7.0-2`
@- Update to 78.7.0 build2M_?Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0 build1M_?Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1 build1
B`i.@B[)]]Jan Horak <jhorak@redhat.com> - 78.7.0-3`"y@- Fixing install prefix for the homepageM(_?Eike Rathke <erack@redhat.com> - 78.7.0-2`
@- Update to 78.7.0 build2M'_?Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0 build1M&_?Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1 build1L%]?Jan Horak <jhorak@redhat.com> - 78.6.0-1_
- Update to 78.6.0 build1L$]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build18#C1erack@redhat.com - 78.4.1-1_- Update to 78.4.1M"_?Eike Rathke <erack@redhat.com> - 78.8.0-1`-@- Update to 78.8.0 build2F!_1Eike Rathke <erack@redhat.com> - 78.7.1-1`"yA- Update to 78.7.1[ ]]Jan Horak <jhorak@redhat.com> - 78.7.0-3`"y@- Fixing install prefix for the homepageM_?Eike Rathke <erack@redhat.com> - 78.7.0-2`
@- Update to 78.7.0 build2M_?Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0 build1
Wg>NWM5_?Eike Rathke <erack@redhat.com> - 78.8.0-1`-@- Update to 78.8.0 build2F4_1Eike Rathke <erack@redhat.com> - 78.7.1-1`"yA- Update to 78.7.1[3]]Jan Horak <jhorak@redhat.com> - 78.7.0-3`"y@- Fixing install prefix for the homepageM2_?Eike Rathke <erack@redhat.com> - 78.7.0-2`
@- Update to 78.7.0 build2M1_?Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0 build1M0_?Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1 build1L/]?Jan Horak <jhorak@redhat.com> - 78.6.0-1_
- Update to 78.6.0 build1L.]?Jan Horak <jhorak@redhat.com> - 78.5.0-1_- Update to 78.5.0 build18-C1erack@redhat.com - 78.4.1-1_- Update to 78.4.1M,_?Eike Rathke <erack@redhat.com> - 78.9.0-1`Q@- Update to 78.9.0 build1M+_?Eike Rathke <erack@redhat.com> - 78.8.0-1`-@- Update to 78.8.0 build2F*_1Eike Rathke <erack@redhat.com> - 78.7.1-1`"yA- Update to 78.7.1

>%Co>L?]? Jan Horak <jhorak@redhat.com> - 91.9.1-1b- Update to 91.9.1 build1F>_1 Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0F=_1 Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0M<_? Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3;]% Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315M:_? Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build29]A Jan Horak <jhorak@redhat.com> - 91.6.0-2b- Install langpacks to the browser/extensions to make them available in UI:
  rhbz#2030190M8_? Eike Rathke <erack@redhat.com> - 91.6.0-1arA- Update to 91.6.0 build17]3 Jan Horak <jhorak@redhat.com> - 91.5.0-2ar@- Use default update channel to fix non working enterprise policies:
  rhbz#2044667M6_?Eike Rathke <erack@redhat.com> - 78.9.0-1`Q@- Update to 78.9.0 build1

<#Am<LI]?!Jan Horak <jhorak@redhat.com> - 91.9.1-1b- Update to 91.9.1 build1FH_1!Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0FG_1!Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0MF_?!Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3E]%!Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315MD_?!Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build2C]A!Jan Horak <jhorak@redhat.com> - 91.6.0-2b- Install langpacks to the browser/extensions to make them available in UI:
  rhbz#2030190MB_?!Eike Rathke <erack@redhat.com> - 91.6.0-1arA- Update to 91.6.0 build1A]3!Jan Horak <jhorak@redhat.com> - 91.5.0-2ar@- Use default update channel to fix non working enterprise policies:
  rhbz#2044667O@aA Eike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1
!Hfs!OTaA"Eike Rathke <erack@redhat.com> - 91.11.0-2bU- Update to 91.11.0 build2OSaA"Eike Rathke <erack@redhat.com> - 91.11.0-1b- Update to 91.11.0 build1ORaA"Eike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1LQ]?"Jan Horak <jhorak@redhat.com> - 91.9.1-1b- Update to 91.9.1 build1FP_1"Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0FO_1"Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0MN_?"Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3M]%"Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315ML_?"Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build2K]A"Jan Horak <jhorak@redhat.com> - 91.6.0-2b- Install langpacks to the browser/extensions to make them available in UI:
  rhbz#2030190OJaA!Eike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1
#nJis#M__?$Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build2O^aA#Eike Rathke <erack@redhat.com> - 91.11.0-2bU- Update to 91.11.0 build2O]aA#Eike Rathke <erack@redhat.com> - 91.11.0-1b- Update to 91.11.0 build1O\aA#Eike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1L[]?#Jan Horak <jhorak@redhat.com> - 91.9.1-1b- Update to 91.9.1 build1FZ_1#Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0FY_1#Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0MX_?#Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3W]%#Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315MV_?#Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build2U]A#Jan Horak <jhorak@redhat.com> - 91.6.0-2b- Install langpacks to the browser/extensions to make them available in UI:
  rhbz#2030190
/|,KU/j]%%Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315Mi_?%Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build2OhaA$Eike Rathke <erack@redhat.com> - 91.12.0-1b?- Update to 91.12.0 build1OgaA$Eike Rathke <erack@redhat.com> - 91.11.0-2bU- Update to 91.11.0 build2OfaA$Eike Rathke <erack@redhat.com> - 91.11.0-1b- Update to 91.11.0 build1OeaA$Eike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1Ld]?$Jan Horak <jhorak@redhat.com> - 91.9.1-1b- Update to 91.9.1 build1Fc_1$Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0Fb_1$Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0Ma_?$Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3`]%$Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315
!g}+j!Fv_1&Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0Fu_1&Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0Mt_?&Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3s]%&Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315OraA%Eike Rathke <erack@redhat.com> - 91.12.0-1b?- Update to 91.12.0 build1OqaA%Eike Rathke <erack@redhat.com> - 91.11.0-2bU- Update to 91.11.0 build2OpaA%Eike Rathke <erack@redhat.com> - 91.11.0-1b- Update to 91.11.0 build1OoaA%Eike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1Ln]?%Jan Horak <jhorak@redhat.com> - 91.9.1-1b- Update to 91.9.1 build1Fm_1%Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0Fl_1%Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0Mk_?%Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3
b_
iCbL]?'Jan Horak <jhorak@redhat.com> - 91.9.1-1b- Update to 91.9.1 build1F_1'Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0F_1'Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0M~_?'Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3}]%'Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315O|aA&Eike Rathke <erack@redhat.com> - 91.13.0-1b@- Update to 91.13.0 build1O{aA&Eike Rathke <erack@redhat.com> - 91.12.0-1b?- Update to 91.12.0 build1OzaA&Eike Rathke <erack@redhat.com> - 91.11.0-2bU- Update to 91.11.0 build2OyaA&Eike Rathke <erack@redhat.com> - 91.11.0-1b- Update to 91.11.0 build1OxaA&Eike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1Lw]?&Jan Horak <jhorak@redhat.com> - 91.9.1-1b- Update to 91.9.1 build1

er+V:eD3
0b48a1dc6bd965ac5f800c44cf498da51c5fd0ec07bf16a07911d66f89932c4bD2
078df219eb34b52cef5f93c17533da34f2eceaec30e85da8944716d38dfee196D1
61eb1f5291daee31b9568e4897e13e2fa0260d850c62490f336ee5f55b31703bD0
f9138cc0c8bd84737691daa9f6f8f6914ee52bef60ec7862c2921c8d8743faa7D/
42e22ddc4f5145c86fda06a008ba1415e8c40c3caa32ca21f81ce460fa3e2bf5D.
d84e36f29bdfc3258ea945056512bc5478db08e97bee521c8debc13bb0e514b1D-
903e1d0ede27725fa4cc5c201b48de10f5cbd5f90594a9cb1c3a7e06037b2fe0D,
8c0eff6015d46baf10cb337069eb8d7100741d665dddd559e9e053509293cad7D+
6d5b1649b1e98557b5173af9108f9a86fc71dcf1bec82baed2b16dc82c6491d4D*
91c597c3c15155bea7576d423bb897ce5644669e24f2b918fb694fe845700c49D)
524031feb4b382103cd67a6e7a15219524577b7af9ecf3f8b7e5ca443bb043aaD(
c472916040722df81c63f7a4b84001545fcde6fe7ff88a7d90493dac79e09626D'
97afe94345fd3c005c2618f3f48fcbae76e8b91619f9bfe40ec51d70d2b90c75
)\
fOm)A
G?(Jan Horak <jhorak@redhat.com>a- Update to 91.0.1 build1EY5(Jan Horak <jhorak@redhat.com> - 91.0-1aj@- Update to 91.0 ESRCY1(Jan Horak <jhorak@redhat.com> - 91.0-1a@- Update to 91.0b8Q
_G(Jan Horak <jhorak@redhat.com> - 78.12.0-2`t- Rebuild to pickup older nssO	aA(Eike Rathke <erack@redhat.com> - 78.12.0-1`@- Update to 78.12.0 build1YaU(Eike Rathke <erack@redhat.com> - 78.11.0-3`- Update to 78.11.0 build2 (release)fao(Eike Rathke <erack@redhat.com> - 78.11.0-2`- Fix rhel_minor_version for dist .el8_4 and .el8OaA'Eike Rathke <erack@redhat.com> - 91.13.0-1b@- Update to 91.13.0 build1OaA'Eike Rathke <erack@redhat.com> - 91.12.0-1b?- Update to 91.12.0 build1OaA'Eike Rathke <erack@redhat.com> - 91.11.0-2bU- Update to 91.11.0 build2OaA'Eike Rathke <erack@redhat.com> - 91.11.0-1b- Update to 91.11.0 build1OaA'Eike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1
]b$~8]L]?)Jan Horak <jhorak@redhat.com> - 91.1.0-1aA@- Update to 91.1.0 build1AG?)Jan Horak <jhorak@redhat.com>a- Update to 91.0.1 build1EY5)Jan Horak <jhorak@redhat.com> - 91.0-1aj@- Update to 91.0 ESRCY1)Jan Horak <jhorak@redhat.com> - 91.0-1a@- Update to 91.0b8Q_G)Jan Horak <jhorak@redhat.com> - 78.12.0-2`t- Rebuild to pickup older nssOaA)Eike Rathke <erack@redhat.com> - 78.12.0-1`@- Update to 78.12.0 build1YaU)Eike Rathke <erack@redhat.com> - 78.11.0-3`- Update to 78.11.0 build2 (release)fao)Eike Rathke <erack@redhat.com> - 78.11.0-2`- Fix rhel_minor_version for dist .el8_4 and .el8v](Jan Horak <jhorak@redhat.com> - 91.2.0-4aZ- Disable webrender on the s390x due to wrong colors: rhbz#2009503L]?(Jan Horak <jhorak@redhat.com> - 91.2.0-3aTU@- Update to 91.2.0 build1L]?(Jan Horak <jhorak@redhat.com> - 91.1.0-1aA@- Update to 91.1.0 build1
N8Lq"NX#]W*Jan Horak <jhorak@redhat.com> - 91.2.0-5aqV@- Fixed crashes when FIPS is enabled.v"]*Jan Horak <jhorak@redhat.com> - 91.2.0-4aZ- Disable webrender on the s390x due to wrong colors: rhbz#2009503L!]?*Jan Horak <jhorak@redhat.com> - 91.2.0-3aTU@- Update to 91.2.0 build1L ]?*Jan Horak <jhorak@redhat.com> - 91.1.0-1aA@- Update to 91.1.0 build1AG?*Jan Horak <jhorak@redhat.com>a- Update to 91.0.1 build1EY5*Jan Horak <jhorak@redhat.com> - 91.0-1aj@- Update to 91.0 ESRCY1*Jan Horak <jhorak@redhat.com> - 91.0-1a@- Update to 91.0b8Q_G*Jan Horak <jhorak@redhat.com> - 78.12.0-2`t- Rebuild to pickup older nssOaA*Eike Rathke <erack@redhat.com> - 78.12.0-1`@- Update to 78.12.0 build1v])Jan Horak <jhorak@redhat.com> - 91.2.0-4aZ- Disable webrender on the s390x due to wrong colors: rhbz#2009503L]?)Jan Horak <jhorak@redhat.com> - 91.2.0-3aTU@- Update to 91.2.0 build1
"^
|8!v"Q/_G,Jan Horak <jhorak@redhat.com> - 78.12.0-2`t- Rebuild to pickup older nssM._?+Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1X-]W+Jan Horak <jhorak@redhat.com> - 91.2.0-5aqV@- Fixed crashes when FIPS is enabled.v,]+Jan Horak <jhorak@redhat.com> - 91.2.0-4aZ- Disable webrender on the s390x due to wrong colors: rhbz#2009503L+]?+Jan Horak <jhorak@redhat.com> - 91.2.0-3aTU@- Update to 91.2.0 build1L*]?+Jan Horak <jhorak@redhat.com> - 91.1.0-1aA@- Update to 91.1.0 build1A)G?+Jan Horak <jhorak@redhat.com>a- Update to 91.0.1 build1E(Y5+Jan Horak <jhorak@redhat.com> - 91.0-1aj@- Update to 91.0 ESRC'Y1+Jan Horak <jhorak@redhat.com> - 91.0-1a@- Update to 91.0b8Q&_G+Jan Horak <jhorak@redhat.com> - 78.12.0-2`t- Rebuild to pickup older nssO%aA+Eike Rathke <erack@redhat.com> - 78.12.0-1`@- Update to 78.12.0 build1M$_?*Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1
:r.l:E;Y5-Jan Horak <jhorak@redhat.com> - 91.0-1aj@- Update to 91.0 ESRC:Y1-Jan Horak <jhorak@redhat.com> - 91.0-1a@- Update to 91.0b8Q9_G-Jan Horak <jhorak@redhat.com> - 78.12.0-2`t- Rebuild to pickup older nssM8_?,Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1M7_?,Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1X6]W,Jan Horak <jhorak@redhat.com> - 91.2.0-5aqV@- Fixed crashes when FIPS is enabled.v5],Jan Horak <jhorak@redhat.com> - 91.2.0-4aZ- Disable webrender on the s390x due to wrong colors: rhbz#2009503L4]?,Jan Horak <jhorak@redhat.com> - 91.2.0-3aTU@- Update to 91.2.0 build1L3]?,Jan Horak <jhorak@redhat.com> - 91.1.0-1aA@- Update to 91.1.0 build1A2G?,Jan Horak <jhorak@redhat.com>a- Update to 91.0.1 build1E1Y5,Jan Horak <jhorak@redhat.com> - 91.0-1aj@- Update to 91.0 ESRC0Y1,Jan Horak <jhorak@redhat.com> - 91.0-1a@- Update to 91.0b8
:mJd:LG]?.Jan Horak <jhorak@redhat.com> - 91.2.0-3aTU@- Update to 91.2.0 build1LF]?.Jan Horak <jhorak@redhat.com> - 91.1.0-1aA@- Update to 91.1.0 build1AEG?.Jan Horak <jhorak@redhat.com>a- Update to 91.0.1 build1EDY5.Jan Horak <jhorak@redhat.com> - 91.0-1aj@- Update to 91.0 ESRCCY1.Jan Horak <jhorak@redhat.com> - 91.0-1a@- Update to 91.0b8MB_?-Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1MA_?-Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1X@]W-Jan Horak <jhorak@redhat.com> - 91.2.0-5aqV@- Fixed crashes when FIPS is enabled.v?]-Jan Horak <jhorak@redhat.com> - 91.2.0-4aZ- Disable webrender on the s390x due to wrong colors: rhbz#2009503L>]?-Jan Horak <jhorak@redhat.com> - 91.2.0-3aTU@- Update to 91.2.0 build1L=]?-Jan Horak <jhorak@redhat.com> - 91.1.0-1aA@- Update to 91.1.0 build1A<G?-Jan Horak <jhorak@redhat.com>a- Update to 91.0.1 build1
S,<jSvR]/Jan Horak <jhorak@redhat.com> - 91.2.0-4aZ- Disable webrender on the s390x due to wrong colors: rhbz#2009503LQ]?/Jan Horak <jhorak@redhat.com> - 91.2.0-3aTU@- Update to 91.2.0 build1LP]?/Jan Horak <jhorak@redhat.com> - 91.1.0-1aA@- Update to 91.1.0 build1AOG?/Jan Horak <jhorak@redhat.com>a- Update to 91.0.1 build1ENY5/Jan Horak <jhorak@redhat.com> - 91.0-1aj@- Update to 91.0 ESRCMY1/Jan Horak <jhorak@redhat.com> - 91.0-1a@- Update to 91.0b8ML_?.Eike Rathke <erack@redhat.com> - 91.5.0-1a- Update to 91.5.0 build1MK_?.Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1MJ_?.Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1XI]W.Jan Horak <jhorak@redhat.com> - 91.2.0-5aqV@- Fixed crashes when FIPS is enabled.vH].Jan Horak <jhorak@redhat.com> - 91.2.0-4aZ- Disable webrender on the s390x due to wrong colors: rhbz#2009503
CUfCC]]]a0Jan Horak <jhorak@redhat.com> - 91.4.0-2a5- Added fix for failing addons signatures.M\_?0Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1M[_?0Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1XZ]W0Jan Horak <jhorak@redhat.com> - 91.2.0-5aqV@- Fixed crashes when FIPS is enabled.vY]0Jan Horak <jhorak@redhat.com> - 91.2.0-4aZ- Disable webrender on the s390x due to wrong colors: rhbz#2009503LX]?0Jan Horak <jhorak@redhat.com> - 91.2.0-3aTU@- Update to 91.2.0 build1LW]?0Jan Horak <jhorak@redhat.com> - 91.1.0-1aA@- Update to 91.1.0 build1MV_?/Eike Rathke <erack@redhat.com> - 91.5.0-1a- Update to 91.5.0 build1MU_?/Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1MT_?/Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1XS]W/Jan Horak <jhorak@redhat.com> - 91.2.0-5aqV@- Fixed crashes when FIPS is enabled.

c%7cc]g]a1Jan Horak <jhorak@redhat.com> - 91.4.0-2a5- Added fix for failing addons signatures.Mf_?1Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1Me_?1Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1Xd]W1Jan Horak <jhorak@redhat.com> - 91.2.0-5aqV@- Fixed crashes when FIPS is enabled.vc]1Jan Horak <jhorak@redhat.com> - 91.2.0-4aZ- Disable webrender on the s390x due to wrong colors: rhbz#2009503Lb]?1Jan Horak <jhorak@redhat.com> - 91.2.0-3aTU@- Update to 91.2.0 build1La]?1Jan Horak <jhorak@redhat.com> - 91.1.0-1aA@- Update to 91.1.0 build1M`_?0Eike Rathke <erack@redhat.com> - 91.6.0-1arA- Update to 91.6.0 build1_]30Jan Horak <jhorak@redhat.com> - 91.5.0-2ar@- Use default update channel to fix non working enterprise policies:
  rhbz#2044667M^_?0Eike Rathke <erack@redhat.com> - 91.5.0-1a- Update to 91.5.0 build1
	%5Mp_?2Eike Rathke <erack@redhat.com> - 91.6.0-1arA- Update to 91.6.0 build1o]32Jan Horak <jhorak@redhat.com> - 91.5.0-2ar@- Use default update channel to fix non working enterprise policies:
  rhbz#2044667Mn_?2Eike Rathke <erack@redhat.com> - 91.5.0-1a- Update to 91.5.0 build1]m]a2Jan Horak <jhorak@redhat.com> - 91.4.0-2a5- Added fix for failing addons signatures.Ml_?2Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1Mk_?2Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1Mj_?1Eike Rathke <erack@redhat.com> - 91.6.0-1arA- Update to 91.6.0 build1i]31Jan Horak <jhorak@redhat.com> - 91.5.0-2ar@- Use default update channel to fix non working enterprise policies:
  rhbz#2044667Mh_?1Eike Rathke <erack@redhat.com> - 91.5.0-1a- Update to 91.5.0 build1

nJJoMz_?3Eike Rathke <erack@redhat.com> - 91.6.0-1arA- Update to 91.6.0 build1y]33Jan Horak <jhorak@redhat.com> - 91.5.0-2ar@- Use default update channel to fix non working enterprise policies:
  rhbz#2044667Mx_?3Eike Rathke <erack@redhat.com> - 91.5.0-1a- Update to 91.5.0 build1]w]a3Jan Horak <jhorak@redhat.com> - 91.4.0-2a5- Added fix for failing addons signatures.Mv_?3Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1Mu_?3Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1Mt_?2Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3s]%2Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315Mr_?2Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build2q]A2Jan Horak <jhorak@redhat.com> - 91.6.0-2b- Install langpacks to the browser/extensions to make them available in UI:
  rhbz#2030190
	onJJoM_?4Eike Rathke <erack@redhat.com> - 91.6.0-1arA- Update to 91.6.0 build1]34Jan Horak <jhorak@redhat.com> - 91.5.0-2ar@- Use default update channel to fix non working enterprise policies:
  rhbz#2044667M_?4Eike Rathke <erack@redhat.com> - 91.5.0-1a- Update to 91.5.0 build1]]a4Jan Horak <jhorak@redhat.com> - 91.4.0-2a5- Added fix for failing addons signatures.M_?4Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1M~_?3Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3}]%3Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315M|_?3Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build2{]A3Jan Horak <jhorak@redhat.com> - 91.6.0-2b- Install langpacks to the browser/extensions to make them available in UI:
  rhbz#2030190

er+V:eD@
c515fb742f9fbf6e205c91df3d75b991bc0e87b359f64d944d2e6930b0b37ce8D?
36e338a02697b1f86cb751a4d30e96bbb9a01a424dfe6f050474e28f832d3b2dD>
5c481b40303686e7be3e1c4fb48c29d0e1c8d41c8eec46b55771c7970af95954D=
a2b22dc88f61d0fa6de4fcb62e090f383e630fc264c56ad005c9c508b1c0fcb2D<
d247f05fd2f22a9dc59679f6c668b92c75b8f5beb481c99983a0b6d26d10bb08D;
2ba8ed563d8e7d31e393c915f3705b7c8c4c991ca337616916c90e4a14049411D:
e65c76e2da0feca843e2f481d8447767d71a1f723ceeca4f9720896b896a6e7eD9
a40300c549d06a08cce3881d68a82db4bbd0d600667f58fd2017f98bd033fa4eD8
e3fe1238b3aefa061d1f4c2e420e93639cafe3a21ce171d5f4a80fbe6aa7e555D7
c448f7707d3e7d90b0f7376b9e91d551448d8304a6b162d474c8cf243b7f11e5D6
34f10adeaa6be7f713c3b688736291759f254661968bf607fab161503364705fD5
48c754619fa5b6636c02b2b5d79f0529027a96e638760d84ff74df57ece87bd2D4
5a169173d476ff530595d0ae6b03d7f7fba5bf999d95a008a477896efb71218d

&nJQv&M
_?5Eike Rathke <erack@redhat.com> - 91.6.0-1arA- Update to 91.6.0 build1]35Jan Horak <jhorak@redhat.com> - 91.5.0-2ar@- Use default update channel to fix non working enterprise policies:
  rhbz#2044667M_?5Eike Rathke <erack@redhat.com> - 91.5.0-1a- Update to 91.5.0 build1]
]a5Jan Horak <jhorak@redhat.com> - 91.4.0-2a5- Added fix for failing addons signatures.M	_?5Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1F_14Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0M_?4Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3]%4Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315M_?4Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build2]A4Jan Horak <jhorak@redhat.com> - 91.6.0-2b- Install langpacks to the browser/extensions to make them available in UI:
  rhbz#2030190
	vnJQvM_?6Eike Rathke <erack@redhat.com> - 91.6.0-1arA- Update to 91.6.0 build1]36Jan Horak <jhorak@redhat.com> - 91.5.0-2ar@- Use default update channel to fix non working enterprise policies:
  rhbz#2044667M_?6Eike Rathke <erack@redhat.com> - 91.5.0-1a- Update to 91.5.0 build1]]a6Jan Horak <jhorak@redhat.com> - 91.4.0-2a5- Added fix for failing addons signatures.F_15Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0M_?5Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3]%5Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315M_?5Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build2]A5Jan Horak <jhorak@redhat.com> - 91.6.0-2b- Install langpacks to the browser/extensions to make them available in UI:
  rhbz#2030190

-nJX}-M _?7Eike Rathke <erack@redhat.com> - 91.6.0-1arA- Update to 91.6.0 build1]37Jan Horak <jhorak@redhat.com> - 91.5.0-2ar@- Use default update channel to fix non working enterprise policies:
  rhbz#2044667M_?7Eike Rathke <erack@redhat.com> - 91.5.0-1a- Update to 91.5.0 build1]]a7Jan Horak <jhorak@redhat.com> - 91.4.0-2a5- Added fix for failing addons signatures.F_16Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0F_16Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0M_?6Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3]%6Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315M_?6Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build2]A6Jan Horak <jhorak@redhat.com> - 91.6.0-2b- Install langpacks to the browser/extensions to make them available in UI:
  rhbz#2030190
	nJhM)_?8Eike Rathke <erack@redhat.com> - 91.6.0-1arA- Update to 91.6.0 build1(]38Jan Horak <jhorak@redhat.com> - 91.5.0-2ar@- Use default update channel to fix non working enterprise policies:
  rhbz#2044667M'_?8Eike Rathke <erack@redhat.com> - 91.5.0-1a- Update to 91.5.0 build1F&_17Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0F%_17Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0M$_?7Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3#]%7Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315M"_?7Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build2!]A7Jan Horak <jhorak@redhat.com> - 91.6.0-2b- Install langpacks to the browser/extensions to make them available in UI:
  rhbz#2030190

>nJi>M3_?9Eike Rathke <erack@redhat.com> - 91.6.0-1arA- Update to 91.6.0 build12]39Jan Horak <jhorak@redhat.com> - 91.5.0-2ar@- Use default update channel to fix non working enterprise policies:
  rhbz#2044667M1_?9Eike Rathke <erack@redhat.com> - 91.5.0-1a- Update to 91.5.0 build1L0]?8Jan Horak <jhorak@redhat.com> - 91.9.1-1b- Update to 91.9.1 build1F/_18Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0F._18Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0M-_?8Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build3,]%8Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315M+_?8Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build2*]A8Jan Horak <jhorak@redhat.com> - 91.6.0-2b- Install langpacks to the browser/extensions to make them available in UI:
  rhbz#2030190
)nJi)<;a:Eric Garver <egarver@redhat.com> - 0.6.3-3]>- backport recent upstream stable fixes
- backport fix --remove-rules deleting all direct rules
- backport fix unable to delete rich rule forward-port
- backport fix forward-port for external zone hijacking internal zone
- backport fix testsuite iptables lockingL:]?9Jan Horak <jhorak@redhat.com> - 91.9.1-1b- Update to 91.9.1 build1F9_19Eike Rathke <erack@redhat.com> - 91.9.0-1bg- Update to 91.9.0F8_19Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0M7_?9Eike Rathke <erack@redhat.com> - 91.7.0-3b%- Update to 91.7.0 build36]%9Jan Horak <jhorak@redhat.com> - 91.7.0-2b\@- Added expat backports of CVE-2022-25235, CVE-2022-25236 and CVE-2022-25315M5_?9Eike Rathke <erack@redhat.com> - 91.7.0-1b
- Update to 91.7.0 build24]A9Jan Horak <jhorak@redhat.com> - 91.6.0-2b- Install langpacks to the browser/extensions to make them available in UI:
  rhbz#2030190
	$@o}`Dca:Eric Garver <egarver@redhat.com> - 0.6.3-12_Wr@- fix(zone): cache rule_str for rich rulesaCcc:Eric Garver <egarver@redhat.com> - 0.6.3-11^@- feat(service): add RH-Satellite-6-Capsule
Bc3:Eric Garver <egarver@redhat.com> - 0.6.3-10^- fix: add logrotate policy
- fix: checkIP6: strip leading/trailing square bracketshAas:Eric Garver <egarver@redhat.com> - 0.6.3-9^9\- fix: firewalld not falling back to interface zonec@ai:Eric Garver <egarver@redhat.com> - 0.6.3-8]X- fix: failure to load modules no longer fatall?a{:Eric Garver <egarver@redhat.com> - 0.6.3-7]- fix: Revert "ebtables: drop support for broute table"r>a:Eric Garver <egarver@redhat.com> - 0.6.3-6]nU- fix: direct: removeRules() not removing all rules in chaind=ak:Eric Garver <egarver@redhat.com> - 0.6.3-5]QT- doc: add --default-config and --system-configr<a:Eric Garver <egarver@redhat.com> - 0.6.3-4]QT- fix: guarantee zone source dispatch is sorted by zone name
	$@o}`Mca;Eric Garver <egarver@redhat.com> - 0.6.3-12_Wr@- fix(zone): cache rule_str for rich rulesaLcc;Eric Garver <egarver@redhat.com> - 0.6.3-11^@- feat(service): add RH-Satellite-6-Capsule
Kc3;Eric Garver <egarver@redhat.com> - 0.6.3-10^- fix: add logrotate policy
- fix: checkIP6: strip leading/trailing square bracketshJas;Eric Garver <egarver@redhat.com> - 0.6.3-9^9\- fix: firewalld not falling back to interface zonecIai;Eric Garver <egarver@redhat.com> - 0.6.3-8]X- fix: failure to load modules no longer fatallHa{;Eric Garver <egarver@redhat.com> - 0.6.3-7]- fix: Revert "ebtables: drop support for broute table"rGa;Eric Garver <egarver@redhat.com> - 0.6.3-6]nU- fix: direct: removeRules() not removing all rules in chaindFak;Eric Garver <egarver@redhat.com> - 0.6.3-5]QT- doc: add --default-config and --system-configrEa;Eric Garver <egarver@redhat.com> - 0.6.3-4]QT- fix: guarantee zone source dispatch is sorted by zone name
)Os)cTai<Eric Garver <egarver@redhat.com> - 0.6.3-8]X- fix: failure to load modules no longer fatallSa{<Eric Garver <egarver@redhat.com> - 0.6.3-7]- fix: Revert "ebtables: drop support for broute table"rRa<Eric Garver <egarver@redhat.com> - 0.6.3-6]nU- fix: direct: removeRules() not removing all rules in chaindQak<Eric Garver <egarver@redhat.com> - 0.6.3-5]QT- doc: add --default-config and --system-configrPa<Eric Garver <egarver@redhat.com> - 0.6.3-4]QT- fix: guarantee zone source dispatch is sorted by zone name<Oa<Eric Garver <egarver@redhat.com> - 0.6.3-3]>- backport recent upstream stable fixes
- backport fix --remove-rules deleting all direct rules
- backport fix unable to delete rich rule forward-port
- backport fix forward-port for external zone hijacking internal zone
- backport fix testsuite iptables lockingnNc};Eric Garver <egarver@redhat.com> - 0.6.3-13`x*- doc: clarify --set-target values "default" vs "reject"
	@dc]ai=Eric Garver <egarver@redhat.com> - 0.6.3-8]X- fix: failure to load modules no longer fatall\a{=Eric Garver <egarver@redhat.com> - 0.6.3-7]- fix: Revert "ebtables: drop support for broute table"r[a=Eric Garver <egarver@redhat.com> - 0.6.3-6]nU- fix: direct: removeRules() not removing all rules in chaindZak=Eric Garver <egarver@redhat.com> - 0.6.3-5]QT- doc: add --default-config and --system-configrYa=Eric Garver <egarver@redhat.com> - 0.6.3-4]QT- fix: guarantee zone source dispatch is sorted by zone name`Xca<Eric Garver <egarver@redhat.com> - 0.6.3-12_Wr@- fix(zone): cache rule_str for rich rulesaWcc<Eric Garver <egarver@redhat.com> - 0.6.3-11^@- feat(service): add RH-Satellite-6-Capsule
Vc3<Eric Garver <egarver@redhat.com> - 0.6.3-10^- fix: add logrotate policy
- fix: checkIP6: strip leading/trailing square bracketshUas<Eric Garver <egarver@redhat.com> - 0.6.3-9^9\- fix: firewalld not falling back to interface zone
@rda>Eric Garver <egarver@redhat.com> - 0.6.3-4]QT- fix: guarantee zone source dispatch is sorted by zone name<ca>Eric Garver <egarver@redhat.com> - 0.6.3-3]>- backport recent upstream stable fixes
- backport fix --remove-rules deleting all direct rules
- backport fix unable to delete rich rule forward-port
- backport fix forward-port for external zone hijacking internal zone
- backport fix testsuite iptables lockingnbc}=Eric Garver <egarver@redhat.com> - 0.6.3-13`x*- doc: clarify --set-target values "default" vs "reject"`aca=Eric Garver <egarver@redhat.com> - 0.6.3-12_Wr@- fix(zone): cache rule_str for rich rulesa`cc=Eric Garver <egarver@redhat.com> - 0.6.3-11^@- feat(service): add RH-Satellite-6-Capsule
_c3=Eric Garver <egarver@redhat.com> - 0.6.3-10^- fix: add logrotate policy
- fix: checkIP6: strip leading/trailing square bracketsh^as=Eric Garver <egarver@redhat.com> - 0.6.3-9^9\- fix: firewalld not falling back to interface zone
	$OVrma?Eric Garver <egarver@redhat.com> - 0.6.3-4]QT- fix: guarantee zone source dispatch is sorted by zone name`lca>Eric Garver <egarver@redhat.com> - 0.6.3-12_Wr@- fix(zone): cache rule_str for rich rulesakcc>Eric Garver <egarver@redhat.com> - 0.6.3-11^@- feat(service): add RH-Satellite-6-Capsule
jc3>Eric Garver <egarver@redhat.com> - 0.6.3-10^- fix: add logrotate policy
- fix: checkIP6: strip leading/trailing square bracketshias>Eric Garver <egarver@redhat.com> - 0.6.3-9^9\- fix: firewalld not falling back to interface zonechai>Eric Garver <egarver@redhat.com> - 0.6.3-8]X- fix: failure to load modules no longer fatallga{>Eric Garver <egarver@redhat.com> - 0.6.3-7]- fix: Revert "ebtables: drop support for broute table"rfa>Eric Garver <egarver@redhat.com> - 0.6.3-6]nU- fix: direct: removeRules() not removing all rules in chaindeak>Eric Garver <egarver@redhat.com> - 0.6.3-5]QT- doc: add --default-config and --system-config
	$OVnvc}?Eric Garver <egarver@redhat.com> - 0.6.3-13`x*- doc: clarify --set-target values "default" vs "reject"`uca?Eric Garver <egarver@redhat.com> - 0.6.3-12_Wr@- fix(zone): cache rule_str for rich rulesatcc?Eric Garver <egarver@redhat.com> - 0.6.3-11^@- feat(service): add RH-Satellite-6-Capsule
sc3?Eric Garver <egarver@redhat.com> - 0.6.3-10^- fix: add logrotate policy
- fix: checkIP6: strip leading/trailing square bracketshras?Eric Garver <egarver@redhat.com> - 0.6.3-9^9\- fix: firewalld not falling back to interface zonecqai?Eric Garver <egarver@redhat.com> - 0.6.3-8]X- fix: failure to load modules no longer fatallpa{?Eric Garver <egarver@redhat.com> - 0.6.3-7]- fix: Revert "ebtables: drop support for broute table"roa?Eric Garver <egarver@redhat.com> - 0.6.3-6]nU- fix: direct: removeRules() not removing all rules in chaindnak?Eric Garver <egarver@redhat.com> - 0.6.3-5]QT- doc: add --default-config and --system-config
/Ko/h}as@Eric Garver <egarver@redhat.com> - 0.6.3-9^9\- fix: firewalld not falling back to interface zonec|ai@Eric Garver <egarver@redhat.com> - 0.6.3-8]X- fix: failure to load modules no longer fatall{a{@Eric Garver <egarver@redhat.com> - 0.6.3-7]- fix: Revert "ebtables: drop support for broute table"rza@Eric Garver <egarver@redhat.com> - 0.6.3-6]nU- fix: direct: removeRules() not removing all rules in chaindyak@Eric Garver <egarver@redhat.com> - 0.6.3-5]QT- doc: add --default-config and --system-configrxa@Eric Garver <egarver@redhat.com> - 0.6.3-4]QT- fix: guarantee zone source dispatch is sorted by zone name<wa@Eric Garver <egarver@redhat.com> - 0.6.3-3]>- backport recent upstream stable fixes
- backport fix --remove-rules deleting all direct rules
- backport fix unable to delete rich rule forward-port
- backport fix forward-port for external zone hijacking internal zone
- backport fix testsuite iptables locking
	r6ZhasAEric Garver <egarver@redhat.com> - 0.6.3-9^9\- fix: firewalld not falling back to interface zonecaiAEric Garver <egarver@redhat.com> - 0.6.3-8]X- fix: failure to load modules no longer fatalla{AEric Garver <egarver@redhat.com> - 0.6.3-7]- fix: Revert "ebtables: drop support for broute table"raAEric Garver <egarver@redhat.com> - 0.6.3-6]nU- fix: direct: removeRules() not removing all rules in chaindakAEric Garver <egarver@redhat.com> - 0.6.3-5]QT- doc: add --default-config and --system-configraAEric Garver <egarver@redhat.com> - 0.6.3-4]QT- fix: guarantee zone source dispatch is sorted by zone name`ca@Eric Garver <egarver@redhat.com> - 0.6.3-12_Wr@- fix(zone): cache rule_str for rich rulesacc@Eric Garver <egarver@redhat.com> - 0.6.3-11^@- feat(service): add RH-Satellite-6-Capsule
~c3@Eric Garver <egarver@redhat.com> - 0.6.3-10^- fix: add logrotate policy
- fix: checkIP6: strip leading/trailing square brackets

er+V:eDM
1e46d6b60429dbed54c038855d87f27518fd4c4f7f6e66a15ff60a3bda266f78DL
c3bdafdc7b5df1eae10ff90840698573957b8409268bf2a94cf0a31564d3658cDK
1979501bae62e6070c0c6037b5547a69c4342485df1f9dd821ad18a174b0bd48DJ
85ac0468355fd6847c79849e947fd3b5d88f606ad3aa6fd06cb4aca3fe3c9fc8DI
031f000698ae93b4d5d19e31521dddc308fa90b6dfee2faed3b23620d47fd150DH
91d045022efb0cd2e147b359f329cbd083f5efa2e778b5a35adf22874dba15e2DG
aeadded2fd899332eca7c3d0d69c10f06ba09b988bbb0be751dfc6ea05b1a753DF
724795eec6065da1df593d22a6a359fc5b241aec5a3916cbec646ff78f2196baDE
f19ae45fcb7a758368a349bdd8244b1029ea8e22cd16b83c2fd74bcfa32253b6DD
84fb40705d6f0704a0543373e2e266ea3565b3125d70e1cf4d3a2ef8497670a0DC
ac621916b414525cdb8e9a02b622a0b85c0f539979311abe60541cc0da534032DB
0e230546571aa26c06f1097967584ab4b9e777e7ca6c94d45f8706a36bdccc22DA
4706b7d5da4cf50b5e9a1e2b512bf1746aac5d7ff7525f047e6a79a392d7f548
	fr:'fa[kBDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Z[]BDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)f
[uBDavid King <dking@redhat.com> - 1.0.2-3\3?@- Backport patches to improve OCI support (#1660137)RcEBKalev Lember <klember@redhat.com> - 1.0.2-2[Q@- Update to 1.0.2 (#1570030)RcEBKalev Lember <klember@redhat.com> - 1.0.1-1[- Update to 1.0.1 (#1570030)n
c}AEric Garver <egarver@redhat.com> - 0.6.3-13`x*- doc: clarify --set-target values "default" vs "reject"`	caAEric Garver <egarver@redhat.com> - 0.6.3-12_Wr@- fix(zone): cache rule_str for rich rulesaccAEric Garver <egarver@redhat.com> - 0.6.3-11^@- feat(service): add RH-Satellite-6-Capsule
c3AEric Garver <egarver@redhat.com> - 0.6.3-10^- fix: add logrotate policy
- fix: checkIP6: strip leading/trailing square brackets

VJ0rVX[YCDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)a[kCDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Z[]CDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)f[uCDavid King <dking@redhat.com> - 1.0.2-3\3?@- Backport patches to improve OCI support (#1660137)RcECKalev Lember <klember@redhat.com> - 1.0.2-2[Q@- Update to 1.0.2 (#1570030)R]KBDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)mc{BKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340RcEBKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)X[YBDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)X[YBDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)

VP6pVX#[YDDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)X"[YDDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)a![kDDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Z []DDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)f[uDDavid King <dking@redhat.com> - 1.0.2-3\3?@- Backport patches to improve OCI support (#1660137)R]KCDavid King <dking@redhat.com> - 1.0.9-11`X- Fix CVE-2021-21381 (#1938059)R]KCDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)mc{CKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340RcECKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)X[YCDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)

g;3rgR-cEEKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)X,[YEDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)X+[YEDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)a*[kEDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Z)[]EDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)[(oKDDebarshi Ray <rishi@fedoraproject.org> - 1.0.9-12ay?@- Fix CVE-2021-41133 (#2012864)R']KDDavid King <dking@redhat.com> - 1.0.9-11`X- Fix CVE-2021-21381 (#1938059)R&]KDDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)m%c{DKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340R$cEDKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)

f;:'fa7[kFDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Z6[]FDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)f5[uFDavid King <dking@redhat.com> - 1.0.2-3\3?@- Backport patches to improve OCI support (#1660137)R4cEFKalev Lember <klember@redhat.com> - 1.0.2-2[Q@- Update to 1.0.2 (#1570030)R3cEFKalev Lember <klember@redhat.com> - 1.0.1-1[- Update to 1.0.1 (#1570030)K2e5EKalev Lember <klember@redhat.com> - 1.0.9-13fb@- Fix CVE-2024-32462[1oKEDebarshi Ray <rishi@fedoraproject.org> - 1.0.9-12ay?@- Fix CVE-2021-41133 (#2012864)R0]KEDavid King <dking@redhat.com> - 1.0.9-11`X- Fix CVE-2021-21381 (#1938059)R/]KEDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)m.c{EKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340

VJ0rVXA[YGDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)a@[kGDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Z?[]GDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)f>[uGDavid King <dking@redhat.com> - 1.0.2-3\3?@- Backport patches to improve OCI support (#1660137)R=cEGKalev Lember <klember@redhat.com> - 1.0.2-2[Q@- Update to 1.0.2 (#1570030)R<]KFDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)m;c{FKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340R:cEFKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)X9[YFDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)X8[YFDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)

VP6pVXK[YHDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)XJ[YHDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)aI[kHDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)ZH[]HDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)fG[uHDavid King <dking@redhat.com> - 1.0.2-3\3?@- Backport patches to improve OCI support (#1660137)RF]KGDavid King <dking@redhat.com> - 1.0.9-11`X- Fix CVE-2021-21381 (#1938059)RE]KGDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)mDc{GKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340RCcEGKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)XB[YGDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)

g;3rgRUcEIKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)XT[YIDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)XS[YIDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)aR[kIDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)ZQ[]IDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)[PoKHDebarshi Ray <rishi@fedoraproject.org> - 1.0.9-12ay?@- Fix CVE-2021-41133 (#2012864)RO]KHDavid King <dking@redhat.com> - 1.0.9-11`X- Fix CVE-2021-21381 (#1938059)RN]KHDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)mMc{HKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340RLcEHKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)

f;:'fa_[kJDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Z^[]JDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)f][uJDavid King <dking@redhat.com> - 1.0.2-3\3?@- Backport patches to improve OCI support (#1660137)R\cEJKalev Lember <klember@redhat.com> - 1.0.2-2[Q@- Update to 1.0.2 (#1570030)R[cEJKalev Lember <klember@redhat.com> - 1.0.1-1[- Update to 1.0.1 (#1570030)KZe5IKalev Lember <klember@redhat.com> - 1.0.9-13fb@- Fix CVE-2024-32462[YoKIDebarshi Ray <rishi@fedoraproject.org> - 1.0.9-12ay?@- Fix CVE-2021-41133 (#2012864)RX]KIDavid King <dking@redhat.com> - 1.0.9-11`X- Fix CVE-2021-21381 (#1938059)RW]KIDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)mVc{IKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340

VJ0rVXi[YKDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)ah[kKDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Zg[]KDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)ff[uKDavid King <dking@redhat.com> - 1.0.2-3\3?@- Backport patches to improve OCI support (#1660137)RecEKKalev Lember <klember@redhat.com> - 1.0.2-2[Q@- Update to 1.0.2 (#1570030)Rd]KJDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)mcc{JKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340RbcEJKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)Xa[YJDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)X`[YJDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)

VP6pVXs[YLDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)Xr[YLDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)aq[kLDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Zp[]LDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)fo[uLDavid King <dking@redhat.com> - 1.0.2-3\3?@- Backport patches to improve OCI support (#1660137)Rn]KKDavid King <dking@redhat.com> - 1.0.9-11`X- Fix CVE-2021-21381 (#1938059)Rm]KKDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)mlc{KKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340RkcEKKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)Xj[YKDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)

g;3rgR}cEMKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)X|[YMDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)X{[YMDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)az[kMDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Zy[]MDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)[xoKLDebarshi Ray <rishi@fedoraproject.org> - 1.0.9-12ay?@- Fix CVE-2021-41133 (#2012864)Rw]KLDavid King <dking@redhat.com> - 1.0.9-11`X- Fix CVE-2021-21381 (#1938059)Rv]KLDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)muc{LKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340RtcELKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)

f;:'fa[kNDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Z[]NDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)f[uNDavid King <dking@redhat.com> - 1.0.2-3\3?@- Backport patches to improve OCI support (#1660137)RcENKalev Lember <klember@redhat.com> - 1.0.2-2[Q@- Update to 1.0.2 (#1570030)RcENKalev Lember <klember@redhat.com> - 1.0.1-1[- Update to 1.0.1 (#1570030)Ke5MKalev Lember <klember@redhat.com> - 1.0.9-13fb@- Fix CVE-2024-32462[oKMDebarshi Ray <rishi@fedoraproject.org> - 1.0.9-12ay?@- Fix CVE-2021-41133 (#2012864)R]KMDavid King <dking@redhat.com> - 1.0.9-11`X- Fix CVE-2021-21381 (#1938059)R]KMDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)m~c{MKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340

er+V:eDZ
f44cd6beef0e0285e87ceddb589f3ce6b36f4340a280ed674cc37aa7141b8397DY
ef82a93c26a7db64bb635cb373e0bf00ab1038b8e42c02b37a970cc41e97ef34DX
c2b79101f730ccfa892ffdfdb7ce4d806f9960bc302581dc10991c7321dd4e24DW
1e843fde687553231eecf687163be424f4d2df8b4398e28a34c6dff791e1b161DV
f61c338504f42e88dbef95a448e0e1aa1c04a89586134610472f384c31966981DU
7ea68138245e021dc4dbaf9e1b990e5250e1b72ebca41352896a1b5dbceda2fbDT
4b031b0a3b505796cae1f7221a96821c6c953c4e2f94f8869bfc2a6139af8b2aDS
cddc3744f22b625662ab15986f90fc202f14ece03ac5fce4fbde2d656b5f38ddDR
5cd33852a9e9061d05228552a9fa6fe6b3b0667fc738828b9df7e633dbe46bd5DQ
a300fb68037da47d07903271c1b04a1bf9b9ce2da5c1a0e56fcede7f6614fa62DP
ddd64d000d677447dbb3a66637d5f9d9064439fbdd584fdad1f5aea0b47ef550DO
e251fe0d7ffbb8b51c6644310756c5ea0a0ea8d5282cb0ecda819c8ff161dfecDN
6a5560cf575ee9bfa9cac85044e94e3bce3ea85e26431c99e41877289cf82b64

VJ0rVX[YODavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)a[kODavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Z[]ODavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)f[uODavid King <dking@redhat.com> - 1.0.2-3\3?@- Backport patches to improve OCI support (#1660137)R
cEOKalev Lember <klember@redhat.com> - 1.0.2-2[Q@- Update to 1.0.2 (#1570030)R]KNDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)mc{NKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340R
cENKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)X	[YNDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)X[YNDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)of	Iflrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|T_jv
#/;GR]gpz
 )3;DMT]dmv}#-7AKU_is}			%	/	8	A	J	S		[	
d	m	v	
					'	.	5	<	C	K	S	Z	a	i	r	{		 	"	#	$%	%-	&5	'=	(D	*L	+T	,]	-e	.n	/r	1t	2x	3|	5~	6	7	8	9	:	;	<	= 	>$	?(	@+	A0	B4	C8	D<	F?	GD	HH

VP6pVX[YPDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)X[YPDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)a[kPDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Z[]PDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)f[uPDavid King <dking@redhat.com> - 1.0.2-3\3?@- Backport patches to improve OCI support (#1660137)R]KODavid King <dking@redhat.com> - 1.0.9-11`X- Fix CVE-2021-21381 (#1938059)R]KODavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)mc{OKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340RcEOKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)X[YODavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)

g;3rgR%cEQKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)X$[YQDavid King <dking@redhat.com> - 1.0.2-7\@- Fix IOCSTI sandbox bypass (#1700652)X#[YQDavid King <dking@redhat.com> - 1.0.2-6\f- Tweak /proc sandbox patch (#1675435)a"[kQDavid King <dking@redhat.com> - 1.0.2-5\d- Do not mount /proc in root sandbox (#1675435)Z![]QDavid King <dking@redhat.com> - 1.0.2-4\<y- Apply the OCI support patch (#1660137)[ oKPDebarshi Ray <rishi@fedoraproject.org> - 1.0.9-12ay?@- Fix CVE-2021-41133 (#2012864)R]KPDavid King <dking@redhat.com> - 1.0.9-11`X- Fix CVE-2021-21381 (#1938059)R]KPDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)mc{PKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340RcEPKalev Lember <klember@redhat.com> - 1.0.9-8]@- Update to 1.0.9 (#1753591)

8;:#8M/_?RDaniel Mach <dmach@redhat.com> - 1.3.0-11Rk- Mass rebuild 2013-12-27.RFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-10Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildZ-Y_RAdam Tkac <atkac redhat com> - 1.3.0-9P9@- rebuild due to "jpeg8-ABI" feature drops,YRAdam Tkac <atkac redhat com> - 1.3.0-8P- fix ABI breakage caused by fltk-1_v4.3.x-cursor.patch (#883026)A+Y-RAdam Tkac <atkac redhat com> - 1.3.0-7PN@- add xcursor BRK*e5QKalev Lember <klember@redhat.com> - 1.0.9-13fb@- Fix CVE-2024-32462[)oKQDebarshi Ray <rishi@fedoraproject.org> - 1.0.9-12ay?@- Fix CVE-2021-41133 (#2012864)R(]KQDavid King <dking@redhat.com> - 1.0.9-11`X- Fix CVE-2021-21381 (#1938059)R']KQDavid King <dking@redhat.com> - 1.0.9-10`@- Fix CVE-2021-21261 (#1918771)m&c{QKalev Lember <klember@redhat.com> - 1.0.9-9^1s- Backport OCI fixes from upstream
- Resolves: #1796340
	FK8SFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-10Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildZ7Y_SAdam Tkac <atkac redhat com> - 1.3.0-9P9@- rebuild due to "jpeg8-ABI" feature drops6YSAdam Tkac <atkac redhat com> - 1.3.0-8P- fix ABI breakage caused by fltk-1_v4.3.x-cursor.patch (#883026)A5Y-SAdam Tkac <atkac redhat com> - 1.3.0-7PN@- add xcursor BR{4cRJan Grulich <jgrulich@redhat.com> - 1.3.4-3b- Fix segfault if using very large selections
  Resolves: bz#19998193cMRJan Grulich <jgrulich@redhat.com> - 1.3.4-2^Nt- Do not drop linker flags for main library when --use-xxx option is used
  Resolves: bz#1510482]2c[RJan Grulich <jgrulich@redhat.com> - 1.3.4-1X}@- Re-base to 1.3.4 (+ sync with Fedora)M1_?RDaniel Mach <dmach@redhat.com> - 1.3.0-13RU- Mass rebuild 2014-01-24g0coRPetr Hracek <phracek@redhat.com> - 1.3.0-12R@- Resolves: #1048857 fltk does not build on RHEL7
	fF}9fZAY_TAdam Tkac <atkac redhat com> - 1.3.0-9P9@- rebuild due to "jpeg8-ABI" feature drops@YTAdam Tkac <atkac redhat com> - 1.3.0-8P- fix ABI breakage caused by fltk-1_v4.3.x-cursor.patch (#883026)A?Y-TAdam Tkac <atkac redhat com> - 1.3.0-7PN@- add xcursor BR{>cSJan Grulich <jgrulich@redhat.com> - 1.3.4-3b- Fix segfault if using very large selections
  Resolves: bz#1999819=cMSJan Grulich <jgrulich@redhat.com> - 1.3.4-2^Nt- Do not drop linker flags for main library when --use-xxx option is used
  Resolves: bz#1510482]<c[SJan Grulich <jgrulich@redhat.com> - 1.3.4-1X}@- Re-base to 1.3.4 (+ sync with Fedora)M;_?SDaniel Mach <dmach@redhat.com> - 1.3.0-13RU- Mass rebuild 2014-01-24g:coSPetr Hracek <phracek@redhat.com> - 1.3.0-12R@- Resolves: #1048857 fltk does not build on RHEL7M9_?SDaniel Mach <dmach@redhat.com> - 1.3.0-11Rk- Mass rebuild 2013-12-27
	(e[`(sJYUAdam Tkac <atkac redhat com> - 1.3.0-8P- fix ABI breakage caused by fltk-1_v4.3.x-cursor.patch (#883026)AIY-UAdam Tkac <atkac redhat com> - 1.3.0-7PN@- add xcursor BR{HcTJan Grulich <jgrulich@redhat.com> - 1.3.4-3b- Fix segfault if using very large selections
  Resolves: bz#1999819GcMTJan Grulich <jgrulich@redhat.com> - 1.3.4-2^Nt- Do not drop linker flags for main library when --use-xxx option is used
  Resolves: bz#1510482]Fc[TJan Grulich <jgrulich@redhat.com> - 1.3.4-1X}@- Re-base to 1.3.4 (+ sync with Fedora)ME_?TDaniel Mach <dmach@redhat.com> - 1.3.0-13RU- Mass rebuild 2014-01-24gDcoTPetr Hracek <phracek@redhat.com> - 1.3.0-12R@- Resolves: #1048857 fltk does not build on RHEL7MC_?TDaniel Mach <dmach@redhat.com> - 1.3.0-11Rk- Mass rebuild 2013-12-27BTFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-10Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
	ANAASY-VAdam Tkac <atkac redhat com> - 1.3.0-7PN@- add xcursor BR{RcUJan Grulich <jgrulich@redhat.com> - 1.3.4-3b- Fix segfault if using very large selections
  Resolves: bz#1999819QcMUJan Grulich <jgrulich@redhat.com> - 1.3.4-2^Nt- Do not drop linker flags for main library when --use-xxx option is used
  Resolves: bz#1510482]Pc[UJan Grulich <jgrulich@redhat.com> - 1.3.4-1X}@- Re-base to 1.3.4 (+ sync with Fedora)MO_?UDaniel Mach <dmach@redhat.com> - 1.3.0-13RU- Mass rebuild 2014-01-24gNcoUPetr Hracek <phracek@redhat.com> - 1.3.0-12R@- Resolves: #1048857 fltk does not build on RHEL7MM_?UDaniel Mach <dmach@redhat.com> - 1.3.0-11Rk- Mass rebuild 2013-12-27LUFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-10Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildZKY_UAdam Tkac <atkac redhat com> - 1.3.0-9P9@- rebuild due to "jpeg8-ABI" feature drop
-B([cMVJan Grulich <jgrulich@redhat.com> - 1.3.4-2^Nt- Do not drop linker flags for main library when --use-xxx option is used
  Resolves: bz#1510482]Zc[VJan Grulich <jgrulich@redhat.com> - 1.3.4-1X}@- Re-base to 1.3.4 (+ sync with Fedora)MY_?VDaniel Mach <dmach@redhat.com> - 1.3.0-13RU- Mass rebuild 2014-01-24gXcoVPetr Hracek <phracek@redhat.com> - 1.3.0-12R@- Resolves: #1048857 fltk does not build on RHEL7MW_?VDaniel Mach <dmach@redhat.com> - 1.3.0-11Rk- Mass rebuild 2013-12-27VVFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-10Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildZUY_VAdam Tkac <atkac redhat com> - 1.3.0-9P9@- rebuild due to "jpeg8-ABI" feature dropsTYVAdam Tkac <atkac redhat com> - 1.3.0-8P- fix ABI breakage caused by fltk-1_v4.3.x-cursor.patch (#883026)
	f>kf]dc[WJan Grulich <jgrulich@redhat.com> - 1.3.4-1X}@- Re-base to 1.3.4 (+ sync with Fedora)Mc_?WDaniel Mach <dmach@redhat.com> - 1.3.0-13RU- Mass rebuild 2014-01-24gbcoWPetr Hracek <phracek@redhat.com> - 1.3.0-12R@- Resolves: #1048857 fltk does not build on RHEL7Ma_?WDaniel Mach <dmach@redhat.com> - 1.3.0-11Rk- Mass rebuild 2013-12-27`WFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-10Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildZ_Y_WAdam Tkac <atkac redhat com> - 1.3.0-9P9@- rebuild due to "jpeg8-ABI" feature drops^YWAdam Tkac <atkac redhat com> - 1.3.0-8P- fix ABI breakage caused by fltk-1_v4.3.x-cursor.patch (#883026)A]Y-WAdam Tkac <atkac redhat com> - 1.3.0-7PN@- add xcursor BR{\cVJan Grulich <jgrulich@redhat.com> - 1.3.4-3b- Fix segfault if using very large selections
  Resolves: bz#1999819
	+e-5{+Mm_?XDaniel Mach <dmach@redhat.com> - 1.3.0-13RU- Mass rebuild 2014-01-24glcoXPetr Hracek <phracek@redhat.com> - 1.3.0-12R@- Resolves: #1048857 fltk does not build on RHEL7Mk_?XDaniel Mach <dmach@redhat.com> - 1.3.0-11Rk- Mass rebuild 2013-12-27jXFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-10Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildZiY_XAdam Tkac <atkac redhat com> - 1.3.0-9P9@- rebuild due to "jpeg8-ABI" feature dropshYXAdam Tkac <atkac redhat com> - 1.3.0-8P- fix ABI breakage caused by fltk-1_v4.3.x-cursor.patch (#883026)AgY-XAdam Tkac <atkac redhat com> - 1.3.0-7PN@- add xcursor BR{fcWJan Grulich <jgrulich@redhat.com> - 1.3.4-3b- Fix segfault if using very large selections
  Resolves: bz#1999819ecMWJan Grulich <jgrulich@redhat.com> - 1.3.4-2^Nt- Do not drop linker flags for main library when --use-xxx option is used
  Resolves: bz#1510482
	7FK7Lv]?YDaniel Mach <dmach@redhat.com> - 4.0.9-6RU- Mass rebuild 2014-01-24Lu]?YDaniel Mach <dmach@redhat.com> - 4.0.9-5Rk- Mass rebuild 2013-12-27steYJiri Popelka <jpopelka@redhat.com> - 4.0.9-4R- Correct Obsoletes/Provides printer-filters (bug #1035450)|s[YTim Waugh <twaugh@redhat.com> - 4.0.9-3Q@- Obsolete/provide printer-filters package now it has gone (bug #967316).yrk	YTom Callaway <spot@fedoraproject.org> - 4.0.9-2Q@- remove Artistic test scripts from source tarball (bz 967406)>qeYJiri Popelka <jpopelka@redhat.com> - 4.0.9-1Q?- 4.0.9{pcXJan Grulich <jgrulich@redhat.com> - 1.3.4-3b- Fix segfault if using very large selections
  Resolves: bz#1999819ocMXJan Grulich <jgrulich@redhat.com> - 1.3.4-2^Nt- Do not drop linker flags for main library when --use-xxx option is used
  Resolves: bz#1510482]nc[XJan Grulich <jgrulich@redhat.com> - 1.3.4-1X}@- Re-base to 1.3.4 (+ sync with Fedora)
	*:+ny*L]?ZDaniel Mach <dmach@redhat.com> - 4.0.9-5Rk- Mass rebuild 2013-12-27s~eZJiri Popelka <jpopelka@redhat.com> - 4.0.9-4R- Correct Obsoletes/Provides printer-filters (bug #1035450)|}[ZTim Waugh <twaugh@redhat.com> - 4.0.9-3Q@- Obsolete/provide printer-filters package now it has gone (bug #967316).y|k	ZTom Callaway <spot@fedoraproject.org> - 4.0.9-2Q@- remove Artistic test scripts from source tarball (bz 967406)>{eZJiri Popelka <jpopelka@redhat.com> - 4.0.9-1Q?- 4.0.9zg)YZdenek Dohnal <zdohnal@redhat.com> - 4.0.9-10_- 1891679 - [RHEL 7] foomatic-rip files up /var/spool/tmp with temporary filesyeYZdenek Dohnal <zdohnal@redhat.com> - 4.0.9-9\@- 1707559 - removal of option in ghostscript caused foomatic-rip to failkx[YTim Waugh <twaugh@redhat.com> - 4.0.9-8S- Put some text into foomatic-preferred-drivers man page.Uw[SYTim Waugh <twaugh@redhat.com> - 4.0.9-7S@- Ship more manpages (bug #948965).
	FYg[FWeM[Ondrej Holy <oholy@redhat.com> - 2.0.0-1.rc4\mA@- Update to 2.0.0-rc4 (#1291254)__c[Ondrej Holy <oholy@redhat.com> - 1.0.2-15Zq- Fix smartcard usage in manpage (#1428041)V_Q[Ondrej Holy <oholy@redhat.com> - 1.0.2-14Z@- Add FIPS mode support (#1363811)~_[Ondrej Holy <oholy@redhat.com> - 1.0.2-13Y- Fix NTLM on big endian (#1204742)
- Fix colors on big endian (#1308810)g)ZZdenek Dohnal <zdohnal@redhat.com> - 4.0.9-10_- 1891679 - [RHEL 7] foomatic-rip files up /var/spool/tmp with temporary fileseZZdenek Dohnal <zdohnal@redhat.com> - 4.0.9-9\@- 1707559 - removal of option in ghostscript caused foomatic-rip to failk[ZTim Waugh <twaugh@redhat.com> - 4.0.9-8S- Put some text into foomatic-preferred-drivers man page.U[SZTim Waugh <twaugh@redhat.com> - 4.0.9-7S@- Ship more manpages (bug #948965).L]?ZDaniel Mach <dmach@redhat.com> - 4.0.9-6RU- Mass rebuild 2014-01-24

er+V:eDg
d2c7c9daa4378bb677e4fa893b6839ebef8009ea1e132569083c4a845ec60a22Df
779af39181edc4bdb4e091b266ec46176447a4ccc0941c928f999ed3fa780cacDe
bb549c96d2986def32a70c8f766e2a23ac2dd2f4c76e72e116fdc699bd0c6eb9Dd
5dfc9505dc8c10ee2fa6b344d1a86a8ea57d43b15353225888d1f9888a840220Dc
8c8b857999a32f70ec103af37b684d4c2eb482a3f8d75f62cec86acb6c10e940Db
530c5e0227cf705a60da80a809db414020ef88b26923ed6828fe285d4f1b5e18Da
564e997b9c790bd2ccb1bc895a8ace373c5af426e771063ebc24eb3ac892b979D`
b06da13bab5aee0690c6d98073ecafe702d73f53e8e1b9421e90fe7928ba1d17D_
1ca99a830f21e3f243a3f20099285c28e83738059736b8931da396f1b77e1b0aD^
b884e513e4fabc67d102225daf07a6948f3c7aba4eea99292cf5bbaa993d41e7D]
5496c1582c68c5314603d320dbb44e5435532564f1a4c6068e8040f2767a1797D\
7b4f34148e411ba03bffe54c35102df45b1e78e1ed461d8ba62a118f517e96d9D[
a4f2dc5f488dc7bd53211931528d9c122391fbf1997e99e33a04a33c38c67995
BD[B~_\Ondrej Holy <oholy@redhat.com> - 1.0.2-13Y- Fix NTLM on big endian (#1204742)
- Fix colors on big endian (#1308810)gC[Jan Grulich <jgrulich@redhat.com> - 2:2.2.0-5ab- Update: Refactored RPC gateway parser (rhbz#2017944)
  + fix issues discovered by Covscanf
gi[Jan Grulich <jgrulich@redhat.com> - 2:2.2.0-4a@- Refactored RPC gateway parser (rhbz#2017944)}g[Felipe Borges <feborges@redhat.com> - 2.1.1-3a- Add checks for bitmap and glyph width/heigth values (rhbz#2017951)O]E[Ondrej Holy <oholy@redhat.com> - 2.1.1-2^˳@- Update to 2.1.1 (#1834286)|
e[Ondrej Holy <oholy@redhat.com> - 2.0.0-4.rc4^- CVE-2020-11521: Fix out-of-bounds write in planar.c (#1837621)
- CVE-2020-11523: Fix integer overflow in region.c (#1837622)
- CVE-2020-11524: Fix out-of-bounds write in interleaved.c (#1837623)g	em[Ondrej Holy <oholy@redhat.com> - 2.0.0-2.rc4^@- Fix SCARD_INSUFFICIENT_BUFFER error (#1765199)
FE/Ffgi\Jan Grulich <jgrulich@redhat.com> - 2:2.2.0-4a@- Refactored RPC gateway parser (rhbz#2017944)}g\Felipe Borges <feborges@redhat.com> - 2.1.1-3a- Add checks for bitmap and glyph width/heigth values (rhbz#2017951)O]E\Ondrej Holy <oholy@redhat.com> - 2.1.1-2^˳@- Update to 2.1.1 (#1834286)|e\Ondrej Holy <oholy@redhat.com> - 2.0.0-4.rc4^- CVE-2020-11521: Fix out-of-bounds write in planar.c (#1837621)
- CVE-2020-11523: Fix integer overflow in region.c (#1837622)
- CVE-2020-11524: Fix out-of-bounds write in interleaved.c (#1837623)gem\Ondrej Holy <oholy@redhat.com> - 2.0.0-2.rc4^@- Fix SCARD_INSUFFICIENT_BUFFER error (#1765199)WeM\Ondrej Holy <oholy@redhat.com> - 2.0.0-1.rc4\mA@- Update to 2.0.0-rc4 (#1291254)__c\Ondrej Holy <oholy@redhat.com> - 1.0.2-15Zq- Fix smartcard usage in manpage (#1428041)V_Q\Ondrej Holy <oholy@redhat.com> - 1.0.2-14Z@- Add FIPS mode support (#1363811)
hh,hh|e]Ondrej Holy <oholy@redhat.com> - 2.0.0-4.rc4^- CVE-2020-11521: Fix out-of-bounds write in planar.c (#1837621)
- CVE-2020-11523: Fix integer overflow in region.c (#1837622)
- CVE-2020-11524: Fix out-of-bounds write in interleaved.c (#1837623)gem]Ondrej Holy <oholy@redhat.com> - 2.0.0-2.rc4^@- Fix SCARD_INSUFFICIENT_BUFFER error (#1765199)WeM]Ondrej Holy <oholy@redhat.com> - 2.0.0-1.rc4\mA@- Update to 2.0.0-rc4 (#1291254)__c]Ondrej Holy <oholy@redhat.com> - 1.0.2-15Zq- Fix smartcard usage in manpage (#1428041)V_Q]Ondrej Holy <oholy@redhat.com> - 1.0.2-14Z@- Add FIPS mode support (#1363811)~_]Ondrej Holy <oholy@redhat.com> - 1.0.2-13Y- Fix NTLM on big endian (#1204742)
- Fix colors on big endian (#1308810)gC\Jan Grulich <jgrulich@redhat.com> - 2:2.2.0-5ab- Update: Refactored RPC gateway parser (rhbz#2017944)
  + fix issues discovered by Covscan
	-.-S-g'em^Ondrej Holy <oholy@redhat.com> - 2.0.0-2.rc4^@- Fix SCARD_INSUFFICIENT_BUFFER error (#1765199)W&eM^Ondrej Holy <oholy@redhat.com> - 2.0.0-1.rc4\mA@- Update to 2.0.0-rc4 (#1291254)_%_c^Ondrej Holy <oholy@redhat.com> - 1.0.2-15Zq- Fix smartcard usage in manpage (#1428041)V$_Q^Ondrej Holy <oholy@redhat.com> - 1.0.2-14Z@- Add FIPS mode support (#1363811)~#_^Ondrej Holy <oholy@redhat.com> - 1.0.2-13Y- Fix NTLM on big endian (#1204742)
- Fix colors on big endian (#1308810)"gC]Jan Grulich <jgrulich@redhat.com> - 2:2.2.0-5ab- Update: Refactored RPC gateway parser (rhbz#2017944)
  + fix issues discovered by Covscanf!gi]Jan Grulich <jgrulich@redhat.com> - 2:2.2.0-4a@- Refactored RPC gateway parser (rhbz#2017944)} g]Felipe Borges <feborges@redhat.com> - 2.1.1-3a- Add checks for bitmap and glyph width/heigth values (rhbz#2017951)O]E]Ondrej Holy <oholy@redhat.com> - 2.1.1-2^˳@- Update to 2.1.1 (#1834286)
S.-SV._Q_Ondrej Holy <oholy@redhat.com> - 1.0.2-14Z@- Add FIPS mode support (#1363811)~-__Ondrej Holy <oholy@redhat.com> - 1.0.2-13Y- Fix NTLM on big endian (#1204742)
- Fix colors on big endian (#1308810),gC^Jan Grulich <jgrulich@redhat.com> - 2:2.2.0-5ab- Update: Refactored RPC gateway parser (rhbz#2017944)
  + fix issues discovered by Covscanf+gi^Jan Grulich <jgrulich@redhat.com> - 2:2.2.0-4a@- Refactored RPC gateway parser (rhbz#2017944)}*g^Felipe Borges <feborges@redhat.com> - 2.1.1-3a- Add checks for bitmap and glyph width/heigth values (rhbz#2017951)O)]E^Ondrej Holy <oholy@redhat.com> - 2.1.1-2^˳@- Update to 2.1.1 (#1834286)|(e^Ondrej Holy <oholy@redhat.com> - 2.0.0-4.rc4^- CVE-2020-11521: Fix out-of-bounds write in planar.c (#1837621)
- CVE-2020-11523: Fix integer overflow in region.c (#1837622)
- CVE-2020-11524: Fix out-of-bounds write in interleaved.c (#1837623)
Df5gi_Jan Grulich <jgrulich@redhat.com> - 2:2.2.0-4a@- Refactored RPC gateway parser (rhbz#2017944)}4g_Felipe Borges <feborges@redhat.com> - 2.1.1-3a- Add checks for bitmap and glyph width/heigth values (rhbz#2017951)O3]E_Ondrej Holy <oholy@redhat.com> - 2.1.1-2^˳@- Update to 2.1.1 (#1834286)|2e_Ondrej Holy <oholy@redhat.com> - 2.0.0-4.rc4^- CVE-2020-11521: Fix out-of-bounds write in planar.c (#1837621)
- CVE-2020-11523: Fix integer overflow in region.c (#1837622)
- CVE-2020-11524: Fix out-of-bounds write in interleaved.c (#1837623)g1em_Ondrej Holy <oholy@redhat.com> - 2.0.0-2.rc4^@- Fix SCARD_INSUFFICIENT_BUFFER error (#1765199)W0eM_Ondrej Holy <oholy@redhat.com> - 2.0.0-1.rc4\mA@- Update to 2.0.0-rc4 (#1291254)_/_c_Ondrej Holy <oholy@redhat.com> - 1.0.2-15Zq- Fix smartcard usage in manpage (#1428041)
yhPVy|<]`Marek Kasik <mkasik@redhat.com> - 2.8-11[@- Preserve API/ABI compatibility for public symbols
- Resolves: #1576504[;eU`Richard Hughes <rhughes@redhat.com> - 2.8-10[- Update to 2.8
- Resolves: #1576504m:c{`Marek Kasik <mkasik@redhat.com> - 2.4.11-15XA- Fix shellcheck warning (coverity)
- Related: #13681419c+`Marek Kasik <mkasik@redhat.com> - 2.4.11-14X@- Backport functions for reading signed values from stream
- Resolves: #1381678z8c`Marek Kasik <mkasik@redhat.com> - 2.4.11-13X- Don't show path of non-existing libtool file
- Resolves: #13681417cM`Marek Kasik <mkasik@redhat.com> - 2.4.11-12V3- Define _FILE_OFFSET_BITS=64 to handle inodes higher than or equal to 2^31
- Resolves: #13032686gC_Jan Grulich <jgrulich@redhat.com> - 2:2.2.0-5ab- Update: Refactored RPC gateway parser (rhbz#2017944)
  + fix issues discovered by Covscan
ipiCc+aMarek Kasik <mkasik@redhat.com> - 2.4.11-14X@- Backport functions for reading signed values from stream
- Resolves: #1381678zBcaMarek Kasik <mkasik@redhat.com> - 2.4.11-13X- Don't show path of non-existing libtool file
- Resolves: #1368141AcMaMarek Kasik <mkasik@redhat.com> - 2.4.11-12V3- Define _FILE_OFFSET_BITS=64 to handle inodes higher than or equal to 2^31
- Resolves: #1303268@m;`Marek Kasik <mkasik@redhat.com> - 2.8-14.el7_9.1_@- Test bitmap size earlier for PNGs
- Fix memory leak in pngshim.c
- Resolves: #1891635j?]{`Marek Kasik <mkasik@redhat.com> - 2.8-14\M- Fix rendering in monochrome mode
- Resolves: #1657479>]1`Marek Kasik <mkasik@redhat.com> - 2.8-13[- Fix definition of constant ft_encoding_gb2312 in freetype.h
- Resolves: #1645218d=]o`Marek Kasik <mkasik@redhat.com> - 2.8-12[o- Fix loading of avar tables
- Resolves: #1576504
#2LU#KcMbMarek Kasik <mkasik@redhat.com> - 2.4.11-12V3- Define _FILE_OFFSET_BITS=64 to handle inodes higher than or equal to 2^31
- Resolves: #1303268Jm;aMarek Kasik <mkasik@redhat.com> - 2.8-14.el7_9.1_@- Test bitmap size earlier for PNGs
- Fix memory leak in pngshim.c
- Resolves: #1891635jI]{aMarek Kasik <mkasik@redhat.com> - 2.8-14\M- Fix rendering in monochrome mode
- Resolves: #1657479H]1aMarek Kasik <mkasik@redhat.com> - 2.8-13[- Fix definition of constant ft_encoding_gb2312 in freetype.h
- Resolves: #1645218dG]oaMarek Kasik <mkasik@redhat.com> - 2.8-12[o- Fix loading of avar tables
- Resolves: #1576504|F]aMarek Kasik <mkasik@redhat.com> - 2.8-11[@- Preserve API/ABI compatibility for public symbols
- Resolves: #1576504[EeUaRichard Hughes <rhughes@redhat.com> - 2.8-10[- Update to 2.8
- Resolves: #1576504mDc{aMarek Kasik <mkasik@redhat.com> - 2.4.11-15XA- Fix shellcheck warning (coverity)
- Related: #1368141
N+ENjS]{bMarek Kasik <mkasik@redhat.com> - 2.8-14\M- Fix rendering in monochrome mode
- Resolves: #1657479R]1bMarek Kasik <mkasik@redhat.com> - 2.8-13[- Fix definition of constant ft_encoding_gb2312 in freetype.h
- Resolves: #1645218dQ]obMarek Kasik <mkasik@redhat.com> - 2.8-12[o- Fix loading of avar tables
- Resolves: #1576504|P]bMarek Kasik <mkasik@redhat.com> - 2.8-11[@- Preserve API/ABI compatibility for public symbols
- Resolves: #1576504[OeUbRichard Hughes <rhughes@redhat.com> - 2.8-10[- Update to 2.8
- Resolves: #1576504mNc{bMarek Kasik <mkasik@redhat.com> - 2.4.11-15XA- Fix shellcheck warning (coverity)
- Related: #1368141Mc+bMarek Kasik <mkasik@redhat.com> - 2.4.11-14X@- Backport functions for reading signed values from stream
- Resolves: #1381678zLcbMarek Kasik <mkasik@redhat.com> - 2.4.11-13X- Don't show path of non-existing libtool file
- Resolves: #1368141
ziQWz|Z]cMarek Kasik <mkasik@redhat.com> - 2.8-11[@- Preserve API/ABI compatibility for public symbols
- Resolves: #1576504[YeUcRichard Hughes <rhughes@redhat.com> - 2.8-10[- Update to 2.8
- Resolves: #1576504mXc{cMarek Kasik <mkasik@redhat.com> - 2.4.11-15XA- Fix shellcheck warning (coverity)
- Related: #1368141Wc+cMarek Kasik <mkasik@redhat.com> - 2.4.11-14X@- Backport functions for reading signed values from stream
- Resolves: #1381678zVccMarek Kasik <mkasik@redhat.com> - 2.4.11-13X- Don't show path of non-existing libtool file
- Resolves: #1368141UcMcMarek Kasik <mkasik@redhat.com> - 2.4.11-12V3- Define _FILE_OFFSET_BITS=64 to handle inodes higher than or equal to 2^31
- Resolves: #1303268Tm;bMarek Kasik <mkasik@redhat.com> - 2.8-14.el7_9.1_@- Test bitmap size earlier for PNGs
- Fix memory leak in pngshim.c
- Resolves: #1891635
ipiac+dMarek Kasik <mkasik@redhat.com> - 2.4.11-14X@- Backport functions for reading signed values from stream
- Resolves: #1381678z`cdMarek Kasik <mkasik@redhat.com> - 2.4.11-13X- Don't show path of non-existing libtool file
- Resolves: #1368141_cMdMarek Kasik <mkasik@redhat.com> - 2.4.11-12V3- Define _FILE_OFFSET_BITS=64 to handle inodes higher than or equal to 2^31
- Resolves: #1303268^m;cMarek Kasik <mkasik@redhat.com> - 2.8-14.el7_9.1_@- Test bitmap size earlier for PNGs
- Fix memory leak in pngshim.c
- Resolves: #1891635j]]{cMarek Kasik <mkasik@redhat.com> - 2.8-14\M- Fix rendering in monochrome mode
- Resolves: #1657479\]1cMarek Kasik <mkasik@redhat.com> - 2.8-13[- Fix definition of constant ft_encoding_gb2312 in freetype.h
- Resolves: #1645218d[]ocMarek Kasik <mkasik@redhat.com> - 2.8-12[o- Fix loading of avar tables
- Resolves: #1576504
"2LU"ieFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.0.35-18P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuildhm;dMarek Kasik <mkasik@redhat.com> - 2.8-14.el7_9.1_@- Test bitmap size earlier for PNGs
- Fix memory leak in pngshim.c
- Resolves: #1891635jg]{dMarek Kasik <mkasik@redhat.com> - 2.8-14\M- Fix rendering in monochrome mode
- Resolves: #1657479f]1dMarek Kasik <mkasik@redhat.com> - 2.8-13[- Fix definition of constant ft_encoding_gb2312 in freetype.h
- Resolves: #1645218de]odMarek Kasik <mkasik@redhat.com> - 2.8-12[o- Fix loading of avar tables
- Resolves: #1576504|d]dMarek Kasik <mkasik@redhat.com> - 2.8-11[@- Preserve API/ABI compatibility for public symbols
- Resolves: #1576504[ceUdRichard Hughes <rhughes@redhat.com> - 2.8-10[- Update to 2.8
- Resolves: #1576504mbc{dMarek Kasik <mkasik@redhat.com> - 2.4.11-15XA- Fix shellcheck warning (coverity)
- Related: #1368141
	Vb re]eFilip Januš <fjanus@redhat.com> - 2.0.35-27_- Fix CVE-2016-5766
- Resolves: #1356813
- Upstream patch: https://github.com/libgd/libgd/commit/aba3db8Nqa?eDaniel Mach <dmach@redhat.com> - 2.0.35-26RU- Mass rebuild 2014-01-24Npa?eDaniel Mach <dmach@redhat.com> - 2.0.35-25Rk- Mass rebuild 2013-12-27Loc9eHonza Horak <hhorak@redhat.com> - 2.0.35-24QP<A- Fix build on aarch64TncIeHonza Horak <hhorak@redhat.com> - 2.0.35-23QP<@- Fix issues found by CoveritymeFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.0.35-22Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild\l]_eAdam Tkac <atkac redhat com> - 2.0.35-21P9@- rebuild due to "jpeg8-ABI" feature dropPk]GeAdam Tkac <atkac redhat com> - 2.0.35-20PO@- rebuild against new libjpeg&jckeHonza Horak <hhorak@redhat.com> - 2.0.35-19P<- Spec file cleanup
- Compile and run test suite during build
- Using chrpath to get rid of --rpath in gd-progs
	$dglu$N{a?fDaniel Mach <dmach@redhat.com> - 2.0.35-26RU- Mass rebuild 2014-01-24Nza?fDaniel Mach <dmach@redhat.com> - 2.0.35-25Rk- Mass rebuild 2013-12-27Lyc9fHonza Horak <hhorak@redhat.com> - 2.0.35-24QP<A- Fix build on aarch64TxcIfHonza Horak <hhorak@redhat.com> - 2.0.35-23QP<@- Fix issues found by CoveritywfFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.0.35-22Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild\v]_fAdam Tkac <atkac redhat com> - 2.0.35-21P9@- rebuild due to "jpeg8-ABI" feature dropPu]GfAdam Tkac <atkac redhat com> - 2.0.35-20PO@- rebuild against new libjpeg&tckfHonza Horak <hhorak@redhat.com> - 2.0.35-19P<- Spec file cleanup
- Compile and run test suite during build
- Using chrpath to get rid of --rpath in gd-progssfFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.0.35-18P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
"\dq"Lc9gHonza Horak <hhorak@redhat.com> - 2.0.35-24QP<A- Fix build on aarch64TcIgHonza Horak <hhorak@redhat.com> - 2.0.35-23QP<@- Fix issues found by CoveritygFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.0.35-22Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild\]_gAdam Tkac <atkac redhat com> - 2.0.35-21P9@- rebuild due to "jpeg8-ABI" feature dropP]GgAdam Tkac <atkac redhat com> - 2.0.35-20PO@- rebuild against new libjpeg&~ckgHonza Horak <hhorak@redhat.com> - 2.0.35-19P<- Spec file cleanup
- Compile and run test suite during build
- Using chrpath to get rid of --rpath in gd-progs}gFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.0.35-18P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild |e]fFilip Januš <fjanus@redhat.com> - 2.0.35-27_- Fix CVE-2016-5766
- Resolves: #1356813
- Upstream patch: https://github.com/libgd/libgd/commit/aba3db8
&^t!&hFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.0.35-22Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild\
]_hAdam Tkac <atkac redhat com> - 2.0.35-21P9@- rebuild due to "jpeg8-ABI" feature dropP	]GhAdam Tkac <atkac redhat com> - 2.0.35-20PO@- rebuild against new libjpeg&ckhHonza Horak <hhorak@redhat.com> - 2.0.35-19P<- Spec file cleanup
- Compile and run test suite during build
- Using chrpath to get rid of --rpath in gd-progshFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.0.35-18P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild e]gFilip Januš <fjanus@redhat.com> - 2.0.35-27_- Fix CVE-2016-5766
- Resolves: #1356813
- Upstream patch: https://github.com/libgd/libgd/commit/aba3db8Na?gDaniel Mach <dmach@redhat.com> - 2.0.35-26RU- Mass rebuild 2014-01-24Na?gDaniel Mach <dmach@redhat.com> - 2.0.35-25Rk- Mass rebuild 2013-12-27

er+V:eDt
570aef75009a72d1f785eeeb0cf1e9b1c5113c73c46a3a7c2eebe0f87a44655bDs
bb408fa95bcf415eb2f22a47b9881db4b7939785d83fa16655c8dc2709c0e454Dr
076ae5a31f58ce2e33f04de674fed5086fd8f72a8e802528d833f3033c017469Dq
9a97f6e2d20a2e98ad20844706c47bf2fc689c6975c67067aa46d4ab03c1e47aDp
b3523f6bd479abca1bc4c70f870af2423e9747ad2cb185692334588138742f50Do
0debd7af9974202b568d8b8c1c87e8d70139dd2dbc62ba9bf7a9e72fe64c3990Dn
d0b3530450134364f48fc2529fb28b6ba4924562e2743be8a4a9531df24ce934Dm
d9df089dfd6da09a0d335f5f7217eb49fb786af4bc6bdc86f8f5780e9588cb54Dl
aa4d5c25ee0ab0c6200041d7babcc2186123b17af2126662b27bed0013787faaDk
eba7c5a667e7db88684d709d6c7106aa972e55a41d27a79736afb8d0eec1de6dDj
a4c7433fc835c54d8bf366a26b4dc41534ab33b1bd9437ea1ba37c1150958611Di
3e01c37b17dac632211d855274ca843a3926cde218387315d5124f7b90008656Dh
8c0250c573335738373e9064ccc227bb57bf3a3ce5d859aa2fe9f129bbc28592
	Z	x{\]_iAdam Tkac <atkac redhat com> - 2.0.35-21P9@- rebuild due to "jpeg8-ABI" feature dropP]GiAdam Tkac <atkac redhat com> - 2.0.35-20PO@- rebuild against new libjpeg&ckiHonza Horak <hhorak@redhat.com> - 2.0.35-19P<- Spec file cleanup
- Compile and run test suite during build
- Using chrpath to get rid of --rpath in gd-progsiFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.0.35-18P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild e]hFilip Januš <fjanus@redhat.com> - 2.0.35-27_- Fix CVE-2016-5766
- Resolves: #1356813
- Upstream patch: https://github.com/libgd/libgd/commit/aba3db8Na?hDaniel Mach <dmach@redhat.com> - 2.0.35-26RU- Mass rebuild 2014-01-24Na?hDaniel Mach <dmach@redhat.com> - 2.0.35-25Rk- Mass rebuild 2013-12-27L
c9hHonza Horak <hhorak@redhat.com> - 2.0.35-24QP<A- Fix build on aarch64TcIhHonza Horak <hhorak@redhat.com> - 2.0.35-23QP<@- Fix issues found by Coverity
	!d
mx!{cjRay Strode <rstrode@redhat.com> - 3.28.2-25_m- Backport some libgdm leak fixes from upstream
  Resolves: #1882821`_ejRay Strode <rstrode@redhat.com> 3.28.2-24_cO- Fix FD leak on logout
  Resolves: #1877583scjRay Strode <rstrode@redhat.com> - 3.28.2-23^- Support exotic keyboard layouts better
  Related: #1734143 e]iFilip Januš <fjanus@redhat.com> - 2.0.35-27_- Fix CVE-2016-5766
- Resolves: #1356813
- Upstream patch: https://github.com/libgd/libgd/commit/aba3db8Na?iDaniel Mach <dmach@redhat.com> - 2.0.35-26RU- Mass rebuild 2014-01-24Na?iDaniel Mach <dmach@redhat.com> - 2.0.35-25Rk- Mass rebuild 2013-12-27Lc9iHonza Horak <hhorak@redhat.com> - 2.0.35-24QP<A- Fix build on aarch64TcIiHonza Horak <hhorak@redhat.com> - 2.0.35-23QP<@- Fix issues found by CoverityiFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.0.35-22Q@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
t'3Rts%cmRay Strode <rstrode@redhat.com> - 3.28.2-23^- Support exotic keyboard layouts better
  Related: #1734143e$cklRay Strode <rstrode@redhat.com> - 3.28.2-26_#- Fix warning during unlock
  Related: #1897063{#clRay Strode <rstrode@redhat.com> - 3.28.2-25_m- Backport some libgdm leak fixes from upstream
  Resolves: #1882821`"_elRay Strode <rstrode@redhat.com> 3.28.2-24_cO- Fix FD leak on logout
  Resolves: #1877583s!clRay Strode <rstrode@redhat.com> - 3.28.2-23^- Support exotic keyboard layouts better
  Related: #1734143{ ckRay Strode <rstrode@redhat.com> - 3.28.2-25_m- Backport some libgdm leak fixes from upstream
  Resolves: #1882821`_ekRay Strode <rstrode@redhat.com> 3.28.2-24_cO- Fix FD leak on logout
  Resolves: #1877583sckRay Strode <rstrode@redhat.com> - 3.28.2-23^- Support exotic keyboard layouts better
  Related: #1734143
A``-_eoRay Strode <rstrode@redhat.com> 3.28.2-24_cO- Fix FD leak on logout
  Resolves: #1877583s,coRay Strode <rstrode@redhat.com> - 3.28.2-23^- Support exotic keyboard layouts better
  Related: #1734143{+cnRay Strode <rstrode@redhat.com> - 3.28.2-25_m- Backport some libgdm leak fixes from upstream
  Resolves: #1882821`*_enRay Strode <rstrode@redhat.com> 3.28.2-24_cO- Fix FD leak on logout
  Resolves: #1877583s)cnRay Strode <rstrode@redhat.com> - 3.28.2-23^- Support exotic keyboard layouts better
  Related: #1734143e(ckmRay Strode <rstrode@redhat.com> - 3.28.2-26_#- Fix warning during unlock
  Related: #1897063{'cmRay Strode <rstrode@redhat.com> - 3.28.2-25_m- Backport some libgdm leak fixes from upstream
  Resolves: #1882821`&_emRay Strode <rstrode@redhat.com> 3.28.2-24_cO- Fix FD leak on logout
  Resolves: #1877583
l+Ml{5cqRay Strode <rstrode@redhat.com> - 3.28.2-25_m- Backport some libgdm leak fixes from upstream
  Resolves: #1882821`4_eqRay Strode <rstrode@redhat.com> 3.28.2-24_cO- Fix FD leak on logout
  Resolves: #1877583s3cqRay Strode <rstrode@redhat.com> - 3.28.2-23^- Support exotic keyboard layouts better
  Related: #1734143e2ckpRay Strode <rstrode@redhat.com> - 3.28.2-26_#- Fix warning during unlock
  Related: #1897063{1cpRay Strode <rstrode@redhat.com> - 3.28.2-25_m- Backport some libgdm leak fixes from upstream
  Resolves: #1882821`0_epRay Strode <rstrode@redhat.com> 3.28.2-24_cO- Fix FD leak on logout
  Resolves: #1877583s/cpRay Strode <rstrode@redhat.com> - 3.28.2-23^- Support exotic keyboard layouts better
  Related: #1734143{.coRay Strode <rstrode@redhat.com> - 3.28.2-25_m- Backport some libgdm leak fixes from upstream
  Resolves: #1882821
t"Ahts=ctRay Strode <rstrode@redhat.com> - 3.28.2-23^- Support exotic keyboard layouts better
  Related: #1734143{<csRay Strode <rstrode@redhat.com> - 3.28.2-25_m- Backport some libgdm leak fixes from upstream
  Resolves: #1882821`;_esRay Strode <rstrode@redhat.com> 3.28.2-24_cO- Fix FD leak on logout
  Resolves: #1877583s:csRay Strode <rstrode@redhat.com> - 3.28.2-23^- Support exotic keyboard layouts better
  Related: #1734143{9crRay Strode <rstrode@redhat.com> - 3.28.2-25_m- Backport some libgdm leak fixes from upstream
  Resolves: #1882821`8_erRay Strode <rstrode@redhat.com> 3.28.2-24_cO- Fix FD leak on logout
  Resolves: #1877583s7crRay Strode <rstrode@redhat.com> - 3.28.2-23^- Support exotic keyboard layouts better
  Related: #1734143e6ckqRay Strode <rstrode@redhat.com> - 3.28.2-26_#- Fix warning during unlock
  Related: #1897063
A`eDckuRay Strode <rstrode@redhat.com> - 3.28.2-26_#- Fix warning during unlock
  Related: #1897063{CcuRay Strode <rstrode@redhat.com> - 3.28.2-25_m- Backport some libgdm leak fixes from upstream
  Resolves: #1882821`B_euRay Strode <rstrode@redhat.com> 3.28.2-24_cO- Fix FD leak on logout
  Resolves: #1877583sAcuRay Strode <rstrode@redhat.com> - 3.28.2-23^- Support exotic keyboard layouts better
  Related: #1734143e@cktRay Strode <rstrode@redhat.com> - 3.28.2-26_#- Fix warning during unlock
  Related: #1897063{?ctRay Strode <rstrode@redhat.com> - 3.28.2-25_m- Backport some libgdm leak fixes from upstream
  Resolves: #1882821`>_etRay Strode <rstrode@redhat.com> 3.28.2-24_cO- Fix FD leak on logout
  Resolves: #1877583

er+V:eD
3e669a493af1a126cce0a77eecae0864765c9b701b5640962ecfa5a8ec1afc30D
36fed680eaa8454cb71901db4b5393c54c16fdfc72c0901bc461231559e164efD
48db0a9dafc6ecf4c0b955075d04ff198a44fa5b1bdea37a0f03af3d9d75e1a6D~
5268af6fbc32bf7411d9d0df3379c86428de9b0d25cbcbd8a6f1703caac79829D}
d977ef2c9e09f15898d44de8446c4e0984f357c637fa6b2194f05cf87e8abc29D|
c4a681b60727112a37ddcabfef6cfcafd36496fa1748cd9e419ad0d579eeb740D{
3b2af1cbe29d541a936e2a76af8f1cc07780ea069f8cc04404f4b2f85184abfcDz
b3306affa940e0e2ab3cd9caec8dda837e626fe8043ec669f8465d62b7b08ed5Dy
c0c2b524cce50372b06ea8c7a4618f02d379ce6a9cbf9b2a7bbd6e21c4a80dd7Dx
666bdeb5237f9bac4020a4b5da35bdc2b27ec3fe6d28b4e3823d1ad165c013b5Dw
73e2cf9bb12255322e5252ec0b918e3e62d5c6df5b610dd7d2ecf351b34f1365Dv
0f6e2c2f22024dd4f9db5cb729bdd2f2744882ba37e965a50b954f861c99243bDu
9b205c9658e9caf5ecd6d928179b7e7b36aa629b18e33540805f21a0d0b9f939
lxxlML_?vDaniel Mach <dmach@redhat.com> - 0.2.0-18RU- Mass rebuild 2014-01-24MK_?vDaniel Mach <dmach@redhat.com> - 0.2.0-17Rk- Mass rebuild 2013-12-27iJeqvNils Philippsen <nils@redhat.com> - 0.2.0-16R@- remove BR: w3m, it's only needed for "make dist"MIo/vRex Dieter <rdieter@fedoraproject.org> - 0.2.0-15R- rebuild (exiv2)OHo3vRex Dieter <rdieter@fedoraproject.org> - 0.2.0-14R- rebuild (openexr)[GkOvKalev Lember <kalevlember@gmail.com> - 0.2.0-13R1- Rebuilt for ilmbase soname bumpFvFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.0-12Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_RebuildiEeovNils Philippsen <nils@redhat.com> - 0.2.0-11Qo@- replace lua-5.2 patch by upstream commit
- fix buffer overflow in and add plausibility checks to ppm-load op
  (CVE-2012-4433)
- fix multi-lib issue in generated documentation
[Obi[iTeqwNils Philippsen <nils@redhat.com> - 0.2.0-16R@- remove BR: w3m, it's only needed for "make dist"MSo/wRex Dieter <rdieter@fedoraproject.org> - 0.2.0-15R- rebuild (exiv2)ORo3wRex Dieter <rdieter@fedoraproject.org> - 0.2.0-14R- rebuild (openexr)[QkOwKalev Lember <kalevlember@gmail.com> - 0.2.0-13R1- Rebuilt for ilmbase soname bumpPwFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.0-12Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_RebuildiOeowNils Philippsen <nils@redhat.com> - 0.2.0-11Qo@- replace lua-5.2 patch by upstream commit
- fix buffer overflow in and add plausibility checks to ppm-load op
  (CVE-2012-4433)
- fix multi-lib issue in generated documentationVNeKvJosef Ridky <jridky@redhat.com> - 0.2.0-19.1aq@- fix CVE-2021-45463 (#2035416)UMaMvJosef Ridky <jridky@redhat.com> - 0.2.0-19X@- add Requires: dcraw (#1279144)
	'`'w'M]o/xRex Dieter <rdieter@fedoraproject.org> - 0.2.0-15R- rebuild (exiv2)O\o3xRex Dieter <rdieter@fedoraproject.org> - 0.2.0-14R- rebuild (openexr)[[kOxKalev Lember <kalevlember@gmail.com> - 0.2.0-13R1- Rebuilt for ilmbase soname bumpZxFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.0-12Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_RebuildiYeoxNils Philippsen <nils@redhat.com> - 0.2.0-11Qo@- replace lua-5.2 patch by upstream commit
- fix buffer overflow in and add plausibility checks to ppm-load op
  (CVE-2012-4433)
- fix multi-lib issue in generated documentationVXeKwJosef Ridky <jridky@redhat.com> - 0.2.0-19.1aq@- fix CVE-2021-45463 (#2035416)UWaMwJosef Ridky <jridky@redhat.com> - 0.2.0-19X@- add Requires: dcraw (#1279144)MV_?wDaniel Mach <dmach@redhat.com> - 0.2.0-18RU- Mass rebuild 2014-01-24MU_?wDaniel Mach <dmach@redhat.com> - 0.2.0-17Rk- Mass rebuild 2013-12-27
]DCV][ekOyKalev Lember <kalevlember@gmail.com> - 0.2.0-13R1- Rebuilt for ilmbase soname bumpdyFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.0-12Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_RebuildiceoyNils Philippsen <nils@redhat.com> - 0.2.0-11Qo@- replace lua-5.2 patch by upstream commit
- fix buffer overflow in and add plausibility checks to ppm-load op
  (CVE-2012-4433)
- fix multi-lib issue in generated documentationVbeKxJosef Ridky <jridky@redhat.com> - 0.2.0-19.1aq@- fix CVE-2021-45463 (#2035416)UaaMxJosef Ridky <jridky@redhat.com> - 0.2.0-19X@- add Requires: dcraw (#1279144)M`_?xDaniel Mach <dmach@redhat.com> - 0.2.0-18RU- Mass rebuild 2014-01-24M__?xDaniel Mach <dmach@redhat.com> - 0.2.0-17Rk- Mass rebuild 2013-12-27i^eqxNils Philippsen <nils@redhat.com> - 0.2.0-16R@- remove BR: w3m, it's only needed for "make dist"
	2^R2nzFedora Release Engineering <releng@fedoraproject.org> - 2.2.2-2V- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_RebuildXmaQzPaul Howarth <paul@city-fan.org> - 2.2.2-1V- Update to 2.2.2
  - geoipupdate now calls fsync on the database directory after a rename to
    make it durable in the event of a crash
- Update autotools patchVleKyJosef Ridky <jridky@redhat.com> - 0.2.0-19.1aq@- fix CVE-2021-45463 (#2035416)UkaMyJosef Ridky <jridky@redhat.com> - 0.2.0-19X@- add Requires: dcraw (#1279144)Mj_?yDaniel Mach <dmach@redhat.com> - 0.2.0-18RU- Mass rebuild 2014-01-24Mi_?yDaniel Mach <dmach@redhat.com> - 0.2.0-17Rk- Mass rebuild 2013-12-27iheqyNils Philippsen <nils@redhat.com> - 0.2.0-16R@- remove BR: w3m, it's only needed for "make dist"Mgo/yRex Dieter <rdieter@fedoraproject.org> - 0.2.0-15R- rebuild (exiv2)Ofo3yRex Dieter <rdieter@fedoraproject.org> - 0.2.0-14R- rebuild (openexr)
rzFedora Release Engineering <releng@fedoraproject.org> - 2.4.0-2Yx@- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild'qaozPaul Howarth <paul@city-fan.org> - 2.4.0-1Y(- Update to 2.4.0
  - geoipupdate now checks that	0pzFedora Release Engineering <releng@fedoraproject.org> - 2.3.1-2X@- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild^oa]zPaul Howarth <paul@city-fan.org> - 2.3.1-1Xn5@- Update to 2.3.1
  - geoipupdate now uses TCP keep-alive when compiled with cURL 7.25 or
    greater
  - Previously, on an invalid gzip file, geoipupdate would output binary data
    to stderr; it now displays an appropriate error message
  - Install README, ChangeLog, GeoIP.conf.default etc. into docdir (GH#33)
  - $(sysconfdir) is now created if it doesn't exist (GH#33)
  - The sample config file is now usable (GH#33) the database directory is writable: if it is
    not, it reports the problem and aborts
  - geoipupdate now acquires a lock when starting up to ensure only one
    instance may run at a time: a new option, 'LockFile', exists to set the
    file to use as a lock ('.geoipupdate.lock' in the database directory by
    default)
  - geoipupdate now prints out additional information from the server when a
    download request results in something other than HTTP status 2xx; this
    provides more information when the API does not respond with a database
    file
  - ${datarootdir}/GeoIP is now created on 'make install' (GH#29)
  - Previously, a variable named 'ERROR' was used, which caused issues building
    on Windows (GH#36)
- Drop EL-5 support
  - Drop BuildRoot: and Group: tags
  - Drop explicit buildroot cleaning in %install section
  - Drop explicit %clean section
  - noarch subpackages always available now
  - libcurl-devel always available now
"d">tazPaul Howarth <paul@city-fan.org> - 2.5.0-1Ye- Update to 2.5.0
  - Replace use of strnlen() due to lack of universal availability (GH#71)
  - Document the 'LockFile' option in the 'GeoIP.conf' man page (GH#64)
  - Remove unused base64 library (GH#68)
  - Add the new configuration option 'PreserveFileTimes'; if set, the
    downloaded files will get the same modification times as their original on
    the server (default is '0') (GH#63)
  - Use the correct types when calling 'curl_easy_setopt()'; this fixes
    warnings generated by libcurl's 'typecheck-gcc.h' (GH#61)
  - In 'GeoIP.conf', the 'UserId' option was renamed to 'AccountID' and the
    'ProductIds' option was renamed to 'EditionIDs'; the old options will
    continue to work, but upgrading to the new names is recommended for
    forward compatibilitys%zFedora Release Engineering <releng@fedoraproject.org> - 2.4.0-3Y- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
!x{Fedora Release Engineering <releng@fedoraproject.org> - 2.2.2-2V- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_RebuildXwaQ{Paul Howarth <paul@city-fan.org> - 2.2.2-1V- Update to 2.2.2
  - geoipupdate now calls fsync on the database directory after a rename to
    make it durable in the event of a crash
- Update autotools patchvizMichal Ruprich <mruprich@redhat.com> - 2.5.0-2dFo@- Resolves: #2188376 - Add support for hashed license keys to geoipupdateyuizMichal Ruprich <mruprich@redhat.com> - 2.5.0-1\]o@- Resolves: #1643470 - Add geoipupdate package
- Initial commit
|{Fedora Release Engineering <releng@fedoraproject.org> - 2.4.0-2Yx@- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild'{ao{Paul Howarth <paul@city-fan.org> - 2.4.0-1Y(- Update to 2.4.0
  - geoipupdate now checks that	4z{Fedora Release Engineering <releng@fedoraproject.org> - 2.3.1-2X@- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild^ya]{Paul Howarth <paul@city-fan.org> - 2.3.1-1Xn5@- Update to 2.3.1
  - geoipupdate now uses TCP keep-alive when compiled with cURL 7.25 or
    greater
  - Previously, on an invalid gzip file, geoipupdate would output binary data
    to stderr; it now displays an appropriate error message
  - Install README, ChangeLog, GeoIP.conf.default etc. into docdir (GH#33)
  - $(sysconfdir) is now created if it doesn't exist (GH#33)
  - The sample config file is now usable (GH#33) the database directory is writable: if it is
    not, it reports the problem and aborts
  - geoipupdate now acquires a lock when starting up to ensure only one
    instance may run at a time: a new option, 'LockFile', exists to set the
    file to use as a lock ('.geoipupdate.lock' in the database directory by
    default)
  - geoipupdate now prints out additional information from the server when a
    download request results in something other than HTTP status 2xx; this
    provides more information when the API does not respond with a database
    file
  - ${datarootdir}/GeoIP is now created on 'make install' (GH#29)
  - Previously, a variable named 'ERROR' was used, which caused issues building
    on Windows (GH#36)
- Drop EL-5 support
  - Drop BuildRoot: and Group: tags
  - Drop explicit buildroot cleaning in %install section
  - Drop explicit %clean section
  - noarch subpackages always available now
  - libcurl-devel always available now
"d">~a{Paul Howarth <paul@city-fan.org> - 2.5.0-1Ye- Update to 2.5.0
  - Replace use of strnlen() due to lack of universal availability (GH#71)
  - Document the 'LockFile' option in the 'GeoIP.conf' man page (GH#64)
  - Remove unused base64 library (GH#68)
  - Add the new configuration option 'PreserveFileTimes'; if set, the
    downloaded files will get the same modification times as their original on
    the server (default is '0') (GH#63)
  - Use the correct types when calling 'curl_easy_setopt()'; this fixes
    warnings generated by libcurl's 'typecheck-gcc.h' (GH#61)
  - In 'GeoIP.conf', the 'UserId' option was renamed to 'AccountID' and the
    'ProductIds' option was renamed to 'EditionIDs'; the old options will
    continue to work, but upgrading to the new names is recommended for
    forward compatibility}%{Fedora Release Engineering <releng@fedoraproject.org> - 2.4.0-3Y- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
9x9e|Andrew Price <anprice@redhat.com> - 3.1.10-6Z&@- gfs2_edit: Print offsets of indirect pointers
  Resolves: rhbz#15189387e|Andrew Price <anprice@redhat.com> - 3.1.10-5Y- Update URL in spec file
  Resolves: rhbz#1501738
- fsck.gfs2: Make -p, -n and -y conflicting options
  Resolves: rhbz#1507091e-|Andrew Price <anprice@redhat.com> - 3.1.10-4Y- gfs2_edit savemeta: Fix up saving of dinodes/symlinks
  Resolves: rhbz#1482542ue|Andrew Price <anprice@redhat.com> - 3.1.10-3X- libgfs2: Issue one write per rgrp when creating them
- mkfs.gfs2: Fix resource group alignment issue
- mkfs.gfs2: Free unnecessary cached pages, disable readahead
  Resolves: rhbz#1440269i{Michal Ruprich <mruprich@redhat.com> - 2.5.0-2dFo@- Resolves: #2188376 - Add support for hashed license keys to geoipupdateyi{Michal Ruprich <mruprich@redhat.com> - 2.5.0-1\]o@- Resolves: #1643470 - Add geoipupdate package
- Initial commit
:s*:lgs|Andrew Price <anprice@redhat.com> - 3.1.10-10^- libgfs2: Use sizeof for 'reserved' fields in ondisk.c
- fsck.gfs2: Disambiguate 'check_data'
- gfs2-utils: Accept a char* instead of a buffer head in gfs2_check_meta
- fsck.gfs2: Disambiguate check_metalist
- fsck.gfs2: Fix segfault in build_and_check_metalist
- fsck.gfs2: Retain context for indirect pointers in ->check_metalist
- fsck.gfs2: Clear bad indirect block pointers when bitmap meets expectations
  Resolves: rhbz#14877264e|Andrew Price <anprice@redhat.com> - 3.1.10-9[- fsck.gfs2: Don't check fs formats we don't recognise
- libgfs2: Fix pointer cast byte order issue
  Resolves: rhbz#1616389
e7|Andrew Price <anprice@redhat.com> - 3.1.10-8[,- glocktop: Remove a non-existent flag from the usage string
  Resolves: rhbz#1544944	e/|Andrew Price <anprice@redhat.com> - 3.1.10-7Z>- mkfs.gfs2: Scale down journal size for smaller devices
  Resolves: rhbz#1498068
4^45q{}Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[qG}Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081
k3|Andrew Price <anprice@redhat.com> - 3.1.10-11.1_u- mkfs.gfs2: Don't use i/o limits hints <4K for block size
  Resolves: rhbz#1853625	gW|Andrew Price <anprice@redhat.com> - 3.1.10-11^(@- gfs2_jadd: Handle out-of-space issues
- gfs2_jadd: error handling overhaul
  Resolves: rhbz#1837640
uTui)}Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Oq/}Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059iQ}Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.
i)}Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKl{	}Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:k}Vít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008u=}Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601uo}Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;iQ~Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.i)~Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5q{~Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:k~Vít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008u=~Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601uo~Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387i)~Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Oq/~Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X5 q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[qGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081s~Masahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365{	~Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
uTu$i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1O#q/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059"iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.!i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKl({	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:'kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008&u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601%uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;+iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.*i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5)q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:0kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008/u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601.uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387-i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1O,q/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X54q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[3qGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #12840812sMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #21883651{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
uTu8i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1O7q/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #12130596iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.5i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKl<{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:;kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008:u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-526019uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387

er+V:eD
bf6b711d995c2cfcd7c146204145b34ce97998804eb37c62306f383d81097962D

7f8cb3fbedf15a4146ccc43a641071e7f99fbde04c72526476d5cd90545e4644D
6f603069d8c52e3cf80cd2299fead7f8539598c42a9cd85ae42363724530da93D
6a1b6459f1f724a4030deb520745ead7657fcaae71a35ba2905022d5da341997D

5c264476a12da876822ba10518576ea9ba06566847192d58c4642df8ad70f0deD	
eace35203de4fbc64ea081a27197877a56615d25b23b30e79f559209ff736310D
ae71e0763354a3a81b14cb8bd4de22629e35e59b0045199ad6958323fac31e30D
2f40644349b7b023a5ac1b6045dc14e19a4d5af38ffd90e8907d4b98929b12b2D
e07e25a4f64939f2fc2c8dfbcd0358561025cfc19d01318d054b161d02e76a80D
4a1eda7aca52060e944393a7b40798a1e90bbd8b4ffcf3bdfe5779ccbe2acc43D
e4d4ae004f1e33c3542d967b6301d6307f9a848be51a7008ff5726259a3e5a5dD
a0b6efe5d9993351a08c5873bc1be89455d96a5535d9bf69e24384ab21850577D
c37e4471ce6ce9e562309ca353e9b1cd0725d1ec5d073e80ad7a9ba3f32732c1
G;?iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.>i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5=q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:DkVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008Cu=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601BuoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387Ai)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1O@q/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X5Hq{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[GqGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081FsMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365E{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
uTuLi)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1OKq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059JiQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.Ii)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKlP{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:OkVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008Nu=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601MuoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;SiQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.Ri)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5Qq{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:XkVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008Wu=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601VuoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387Ui)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1OTq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X5\q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[[qGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081ZsMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365Y{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
uTu`i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1O_q/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059^iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.]i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKld{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:ckVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008bu=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601auoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;giQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.fi)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5eq{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:lkVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008ku=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601juoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387ii)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Ohq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X5pq{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[oqGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081nsMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365m{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
uTuti)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Osq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059riQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.qi)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKlx{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:wkVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008vu=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601uuoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;{iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.zi)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5yq{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601~uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387}i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1O|q/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X5q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[qGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081sMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
uTui)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Oq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKl{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008
u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601	uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5
q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Oq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X5q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[qGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081sMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
uTui)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Oq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKl {	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;#iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well."i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5!q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:(kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008'u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601&uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387%i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1O$q/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X5,q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[+qGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081*sMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365){	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
uTu0i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1O/q/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059.iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.-i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKl4{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:3kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-110082u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-526011uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;7iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.6i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.55q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:<kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008;u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601:uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-13879i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1O8q/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X5@q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[?qGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081>sMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365={	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067

er+V:eD
497230bf98b04ad42a5e86190210020c9d693a673e748256dfdae01fda278f6bD
e3c6ac455f3f655e70629ab69610a70ab4f4e55490536ec08dc32ec06031f28bD
6c21b000ed4eaee655f575de1d380dded8d228f9631df396279ba89debbe6faeD
ce44bc6fbc305c3861c8d26e236f8872ccd1827001528bced75ea5a087db84d4D
84b71cd28250d68d8dd0c9a9da4983782f0ef2c5888c5734b7d12841ff61313bD
ee8a7377ed0c955a55eec8ea39cbb91e5c2b99a4b050e0f4136075e5c7c87796D
b649840984828bb702a86f59b74053d9fb62a7d9512eed421f9ac6fd2c5e648aD
e6b35740952d21b92b5fd63b78ed0f5a4649c9aeb22cf9cb5af2d6c5c8a86dc3D
37036b6e228127d501401f8546d504c70f6e51fcc1271a33342effbc6d6a62cdD
44fdf0fd6b2ea0867e2530297d92b753e9b67534567ffa09595ff50bc74c9886D
4f181bcb90816497b5e18006556c8e9c5e26bb5a1da4f5be2acce0472c81866dD
087a9eb6f7e5a03f17d35ced5aea62e436334f59bd027880ae3be3eb69257219D
37146ed7255163cbdf3bb94a0f5e8ea9cb46eeddd0d269546fb213017f212548
uTuDi)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1OCq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059BiQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.Ai)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKlH{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:GkVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008Fu=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601EuoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;KiQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.Ji)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5Iq{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:PkVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008Ou=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601NuoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387Mi)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1OLq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X5Tq{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[SqGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081RsMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365Q{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
uTuXi)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1OWq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059ViQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.Ui)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKl\{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:[kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008Zu=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601YuoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;_iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.^i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5]q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:dkVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008cu=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601buoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387ai)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1O`q/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X5hq{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[gqGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081fsMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365e{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
uTuli)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Okq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059jiQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.ii)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKlp{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:okVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008nu=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601muoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;siQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.ri)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5qq{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:xkVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008wu=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601vuoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387ui)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Otq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X5|q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[{qGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081zsMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365y{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
uTui)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Oq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059~iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.}i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKl{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387of	flrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|	JP	KS	LX	M\	N`	Od	Pg	Ql	Rp	St	Tx	U{	V	W	X	Y	Z	[	\	]	^ 	_#	`(	a,	b0	c4	d7	e<	f@	hD	iH	jK	kP	lT	mX	n\	o_	pd	qh	rl	sp	ts	ux	v|	w	x	z	{	|	}	~		 	'	.	5	<	C	J	Q	X	_	f	m	t	{							$	(	/	4	;	@	G	N	U	\	c	k	r	y						"	)	0	7	>	E	L	S	Z	a	e	i	o	t	{							&
G;iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l:kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601
uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387	i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Oq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
X{X5q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[qGSebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081sMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365
{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
uTui)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Oq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
lKl{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
G;iQPavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5q{Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
-!l: kVít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008u=Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601uoOndrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387i)Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Oq/Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
3{~E3'uEMichael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-7^2- Backport patch to limit access to files when copying (CVE-2019-12450)
  Resolves: #1722099o&iyJens Petersen <petersen@redhat.com> - 2.56.1-6^@- Backport patches for GDBus auth
  Resolves: #1777221%aKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000$uEMichael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-7^2- Backport patch to limit access to files when copying (CVE-2019-12450)
  Resolves: #1722099o#iyJens Petersen <petersen@redhat.com> - 2.56.1-6^@- Backport patches for GDBus auth
  Resolves: #1777221"sMasahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365!{	Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067
Mgc_M.uEMichael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-7^2- Backport patch to limit access to files when copying (CVE-2019-12450)
  Resolves: #1722099o-iyJens Petersen <petersen@redhat.com> - 2.56.1-6^@- Backport patches for GDBus auth
  Resolves: #1777221h,u_Michael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-9`@- Fix CVE-2021-27219
  Resolves: #1960596+aKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000h*u_Michael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-9`@- Fix CVE-2021-27219
  Resolves: #1960596)aKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000(aKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000

er+V:eD(
79588570ccbd1df263463cf10a5d97ef323266e2abedfeb2fefafd34609a08dfD'
45fefc5e38fdda8877b262c158dcf1558ddd8b48fca3c2cd58b21d90e637096fD&
449fcca21f14ce7eafdbe53266ec3665872f2ce58cd9fd10b5ebe923ec7e12a2D%
cb1bff3dcdabc1801553de1e4bae164ca1ca0aa473eebe3e7afd8360d53dcad7D$
b65a283b2abdd24d3efe7491ad9fbe6bab445307ebf30070af80a0fd335b8560D#
d1d53660bffa4c0d03720470eba69755d1fe600ebcd13dc49a736237a10983ebD"
3c79cb3de74e545373941c507295276cafff95e505438c0bb771fd73deb0cf11D!
722785536ad769e0f2077e33c2c6aa02937baf01e2357433b6873c7a444503daD 
0506a69ed5099abb05188f0ad253ebf7fb23f9516de5789b336622a000b67e9dD
e10f54c5d580e560b5d4611357d17fabf744c685d0597c57f65096c26149632cD
c1b656d07a2265aaad3c80a8e621f30eacc4d7131ecac7e66fade5608ce366e2D
0918063cb9b48c317391f431d587661c39613d95bd83d01ca9029660d7a1dfd9D
8509fe4641cb16b24f3aced3e8cb56ef28648055b03221b4d4cb4017259e1995
gU#5aKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000h4u_Michael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-9`@- Fix CVE-2021-27219
  Resolves: #19605963aKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #17170002aKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #17170001uEMichael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-7^2- Backport patch to limit access to files when copying (CVE-2019-12450)
  Resolves: #1722099o0iyJens Petersen <petersen@redhat.com> - 2.56.1-6^@- Backport patches for GDBus auth
  Resolves: #1777221/aKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000
t#Qto<iyJens Petersen <petersen@redhat.com> - 2.56.1-6^@- Backport patches for GDBus auth
  Resolves: #1777221h;u_Michael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-9`@- Fix CVE-2021-27219
  Resolves: #1960596:aKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #17170009aKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #17170008uEMichael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-7^2- Backport patch to limit access to files when copying (CVE-2019-12450)
  Resolves: #1722099o7iyJens Petersen <petersen@redhat.com> - 2.56.1-6^@- Backport patches for GDBus auth
  Resolves: #1777221h6u_Michael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-9`@- Fix CVE-2021-27219
  Resolves: #1960596
`.QCaKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000BuEMichael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-7^2- Backport patch to limit access to files when copying (CVE-2019-12450)
  Resolves: #1722099oAiyJens Petersen <petersen@redhat.com> - 2.56.1-6^@- Backport patches for GDBus auth
  Resolves: #1777221h@u_Michael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-9`@- Fix CVE-2021-27219
  Resolves: #1960596?aKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000>aKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000=uEMichael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-7^2- Backport patch to limit access to files when copying (CVE-2019-12450)
  Resolves: #1722099
MUQMhJu_Michael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-9`@- Fix CVE-2021-27219
  Resolves: #1960596IaKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000hHu_Michael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-9`@- Fix CVE-2021-27219
  Resolves: #1960596GaKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000FaKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000EuEMichael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-7^2- Backport patch to limit access to files when copying (CVE-2019-12450)
  Resolves: #1722099oDiyJens Petersen <petersen@redhat.com> - 2.56.1-6^@- Backport patches for GDBus auth
  Resolves: #1777221

er+V:eD5
d2c498e78241cc2d36124d37d4771f877da25de95d6a31c1ad42e1287fdda746D4
136c98f13aca8088f8a6db32a4f1c09e88ab4e875a90611b2c854ca63a7db95aD3
7b99cae552eb8e3aa9044c06a0c67601794c80300cf140324bc228da9d9f0c30D2
d7000378e73195f460b1df7dafb97183eefb63440b39636075973f460f0b141dD1
c67a99f8d73138551a0d40218c32828b28c8df46641ed69f149aa858bfb4476cD0
d0c3a21a7ae050cc88bb11365edee8ae76ce4656de55be60d371d691353d0a2aD/
a09b59d166ae4f96e35aa50238b29f47cbf2e30ed154a83dd200b7627918a160D.
b2b420ac2c03b3a2e4cadd073857498446180ec51a863fe30335c9da3a963fdeD-
ee561a3f0dd8945edec3478e8426cc324bdf6fc5fe6a31d762cfae60d3e14830D,
d41ecaf1cea900f2c9354fc197197c80a88316766208fa264735e4153be0668eD+
c7dec18b5dff68e91dd42275e011d20aecbe60817c948f50fef7adfc8276ec34D*
1f62ae8c12fed4f7639f910b2b5ff758d169ec26fdf5536df0cfd5d6bee2d247D)
bbce7868f8e66ee5f69db6702fdb909d81b8c17bb4f7417dbf08a87ef2a26308
\UQ\Qi/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)cPiaFlorian Weimer <fweimer@redhat.com> - 2.17-313^0"@- Remove problematic Obsoletes: (#1795573)hOu_Michael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-9`@- Fix CVE-2021-27219
  Resolves: #1960596NaKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000MaKRay Strode <rstrode@redhat.com> - 2.56.1-8_@- Backport patch to fix leak in g_signal_connect_object
  Resolves: 1887862
  Related: #1717000LuEMichael Catanzaro <mcatanzaro@redhat.com> - 2.56.1-7^2- Backport patch to limit access to files when copying (CVE-2019-12450)
  Resolves: #1722099oKiyJens Petersen <petersen@redhat.com> - 2.56.1-6^@- Backport patches for GDBus auth
  Resolves: #1777221
O~}O/XiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xWi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)ViCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zUi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hTikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)SiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uRiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)
yz_i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h^ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)]iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)u\iFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)[i/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)cZiaFlorian Weimer <fweimer@redhat.com> - 2.17-313^0"@- Remove problematic Obsoletes: (#1795573)xYi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)
-|ND-fiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)ueiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)di/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)xci	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/biwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xai	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)`iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)
ffms]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xli	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/kiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xji	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)iiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zhi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hgikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)
sqZrsxti	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)siCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zri
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hqikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)piOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uoiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)ni/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)
jMiRjz{i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hzikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)yiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uxiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)fws]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xvi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/uiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)
d|NjduiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)
s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/~iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x}i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)|iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)
LayzLx	i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)
	jxi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h
ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)
s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f
s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)
Mi"hikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)5iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)
_V_
s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)
G5
$s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f#s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x"i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/!iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)5iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
jGCjU(m?Florian Weimer <fweimer@redhat.com> - 2.17-326.2f0@- nscd: Do not use sendfile for the netgroup cache
- nscd: Use-after-free in netgroup cache
- CVE-2021-27645: nscd: double-free in netgroup cache
- CVE-2024-33599: nscd: buffer overflow in netgroup cache (RHEL-34263)
- CVE-2024-33600: nscd: null pointer dereferences in netgroup cache
- CVE-2024-33601: nscd: crash on out-of-memory condition
- CVE-2024-33602: nscd: memory corruption with NSS netgroup modules'm=Florian Weimer <fweimer@redhat.com> - 2.17-326.1fh@- CVE-2024-2961: Out of bounds write in iconv conversion to ISO-2022-CN-EXT (RHEL-31803)i&WDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)5%iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
2]y25/iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
.s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f-s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x,i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/+iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x*i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)r)m{Florian Weimer <fweimer@redhat.com> - 2.17-326.3f3@- nscd: Fix timeout type in netgroup cache (RHEL-34263)
3#3x4i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)r3m{Florian Weimer <fweimer@redhat.com> - 2.17-326.3f3@- nscd: Fix timeout type in netgroup cache (RHEL-34263)U2m?Florian Weimer <fweimer@redhat.com> - 2.17-326.2f0@- nscd: Do not use sendfile for the netgroup cache
- nscd: Use-after-free in netgroup cache
- CVE-2021-27645: nscd: double-free in netgroup cache
- CVE-2024-33599: nscd: buffer overflow in netgroup cache (RHEL-34263)
- CVE-2024-33600: nscd: null pointer dereferences in netgroup cache
- CVE-2024-33601: nscd: crash on out-of-memory condition
- CVE-2024-33602: nscd: memory corruption with NSS netgroup modules1m=Florian Weimer <fweimer@redhat.com> - 2.17-326.1fh@- CVE-2024-2961: Out of bounds write in iconv conversion to ISO-2022-CN-EXT (RHEL-31803)i0WDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)
Mi";m=Florian Weimer <fweimer@redhat.com> - 2.17-326.1fh@- CVE-2024-2961: Out of bounds write in iconv conversion to ISO-2022-CN-EXT (RHEL-31803)i:WDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)59iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
8s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f7s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x6i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/5iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)
F'GF@iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)z?i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h>ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)r=m{Florian Weimer <fweimer@redhat.com> - 2.17-326.3f3@- nscd: Fix timeout type in netgroup cache (RHEL-34263)U<m?Florian Weimer <fweimer@redhat.com> - 2.17-326.2f0@- nscd: Do not use sendfile for the netgroup cache
- nscd: Use-after-free in netgroup cache
- CVE-2021-27645: nscd: double-free in netgroup cache
- CVE-2024-33599: nscd: buffer overflow in netgroup cache (RHEL-34263)
- CVE-2024-33600: nscd: null pointer dereferences in netgroup cache
- CVE-2024-33601: nscd: crash on out-of-memory condition
- CVE-2024-33602: nscd: memory corruption with NSS netgroup modules

er+V:eDB
ff4671dfa3a8f95a13b8ba51b2a558742445e61b30cbb1cf07788364ca2bb076DA
aab72ef4b89bc4481b87f7aaf225cbdefb62073dddddc7fc7c2b94ab11a0a936D@
acbb0c34227bd9c7bba35cfa08b4942dd141ee4ccadd128d8acedaef5e31522cD?
1cdd1bc2cbd53aa25851e70a8024e7e85db9b9d0fcdfcc2df323c89e5944ec7aD>
43b68e9aee5969d0a7628cb49b8b9e8a4b328432cd2bbf3a542567a7d9be9cc8D=
aba75d84977de2cd5e9da00e763912c5e72ba28b55b17e081014e97ca13ce809D<
9d6c8bed9c4d8626f8fd6586301ec93617410de9408cd2b65fef37c2cea142c9D;
f48caf62db65a846a2e5bf134e7e6a5aa0bcc81a67c9995255a33f3f18ab9f65D:
0fbc642e2648e77838d136eb26008e221d165a8465fd50b51c8e7ef52d5c3376D9
f48d75115ac638576d608849a173ace6a70c2430a2e0226487652befdf004b27D8
c59d4299cbd7dc796fc38b8ac3ad9e4a8030d20ee8831940a24af8b28a84cca5D7
58dd6ecca9f9c38c402d46c56efacaf2a8739de21c64f22dfb3f9887f2de6c94D6
7b92de985a23ef4b67bd11135a92917ca99025920b1e4db59517205a2278c3f1
;W`;iGWDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)5FiFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
Es#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fDs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xCi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/BiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xAi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)
ffNs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xMi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/LiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xKi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)JiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zIi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hHikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)
ArMXAUiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uTiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)Si/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)cRiaFlorian Weimer <fweimer@redhat.com> - 2.17-313^0"@- Remove problematic Obsoletes: (#1795573)iQWDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)5PiFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
Os#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)
\f\\i/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)x[i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/ZiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xYi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)XiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zWi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hVikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)
O~}O/ciwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xbi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)aiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)z`i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h_ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)^iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)u]iFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)
xki	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)jiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zii
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hhikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)giOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)ufiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)fes]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xdi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)
TMi<Tzri
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hqikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)piOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)
os#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fns]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xmi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/liwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)
#|Nj#5yiFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
xs#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fws]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xvi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/uiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xti	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)siCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)
;W`;iWDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)5iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
~s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f}s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x|i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/{iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xzi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)
2h2zi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)rm{Florian Weimer <fweimer@redhat.com> - 2.17-326.3f3@- nscd: Fix timeout type in netgroup cache (RHEL-34263)Um?Florian Weimer <fweimer@redhat.com> - 2.17-326.2f0@- nscd: Do not use sendfile for the netgroup cache
- nscd: Use-after-free in netgroup cache
- CVE-2021-27645: nscd: double-free in netgroup cache
- CVE-2024-33599: nscd: buffer overflow in netgroup cache (RHEL-34263)
- CVE-2024-33600: nscd: null pointer dereferences in netgroup cache
- CVE-2024-33601: nscd: crash on out-of-memory condition
- CVE-2024-33602: nscd: memory corruption with NSS netgroup modulesm=Florian Weimer <fweimer@redhat.com> - 2.17-326.1fh@- CVE-2024-2961: Out of bounds write in iconv conversion to ISO-2022-CN-EXT (RHEL-31803)
#|Nj#5iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f
s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x	i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)
.'iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)i/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)ciaFlorian Weimer <fweimer@redhat.com> - 2.17-313^0"@- Remove problematic Obsoletes: (#1795573)i
WDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)
KWbKiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)i/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)ciaFlorian Weimer <fweimer@redhat.com> - 2.17-313^0"@- Remove problematic Obsoletes: (#1795573)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)
\f\"i/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)x!i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/ iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)
O~}O/)iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x(i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)'iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)z&i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h%ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)$iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)u#iFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)
vz0i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h/ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816).iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)u-iFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325),i/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)f+s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x*i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)
S|NjS7iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)u6iFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)f5s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x4i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/3iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x2i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)1iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)
ff>s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x=i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/<iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x;i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380):iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)z9i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h8ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)
tr[stxEi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)DiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zCi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hBikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)AiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)u@iFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)
?s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)

er+V:eDO
cffd614b0edc8b160d92daa7f3c4c4dffd5e33a66532c35ee32132d1b56e63b7DN
91de6d1a2c900bf6a030d637e635ba8bed416176970159ef63c61ba70f93a275DM
b3e7d51cd260028cee1b21b2d94a9e4694745e0e673f10a05aebb54a5a4928abDL
c4697b0258943ed3a070f75ed2b1163ddeb2746108163a6b372318bfc419db74DK
9ba71fe357dd09d1913b30b0bd83507588d8cb06eda6f2c15326f3f1384c6180DJ
b05ac36a6c2c5fb2a3b34dee8aff347281f1ee28b49846b4add728a5cd69f06aDI
68765f29d06d31652e80d398846d899e7437a836c1fffeb61248afa76e51b90fDH
178ac00cbf99e924ca4b26e5bede47496404e34c1fe48906789d80dd955c9793DG
9c54883a611d1da210a5b0909cd7fd415b6c99473614fab81bae9df9cf8c6be2DF
15c7b778a896d0c127b0468d18a519b750dbd5a649ccba7fbb6b5b215b7243d6DE
a25ea7a2e7fdf9c96aa665fd1d337fa501a8be996a208eede238af6018d94012DD
7ea4c424cb331a1de27539fd790be4a991e6525f0d33035d854f2e66e0c2e274DC
235d7a11f2bec5ce59b3207ad420c1a0034747f77ac4902d343951c7bd4109d6
TMi<TzLi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hKikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)JiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)
Is#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fHs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xGi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/FiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)
#|Nj#5SiFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
Rs#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fQs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xPi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/OiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xNi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)MiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)
LayzLxZi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/YiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xXi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)WiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zVi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hUikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)TiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)
>	P">fas]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x`i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/_iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x^i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)5]iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
\s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f[s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)
rMem=Florian Weimer <fweimer@redhat.com> - 2.17-326.1fh@- CVE-2024-2961: Out of bounds write in iconv conversion to ISO-2022-CN-EXT (RHEL-31803)idWDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)5ciFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
bs#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)
'7/iiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xhi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)rgm{Florian Weimer <fweimer@redhat.com> - 2.17-326.3f3@- nscd: Fix timeout type in netgroup cache (RHEL-34263)Ufm?Florian Weimer <fweimer@redhat.com> - 2.17-326.2f0@- nscd: Do not use sendfile for the netgroup cache
- nscd: Use-after-free in netgroup cache
- CVE-2021-27645: nscd: double-free in netgroup cache
- CVE-2024-33599: nscd: buffer overflow in netgroup cache (RHEL-34263)
- CVE-2024-33600: nscd: null pointer dereferences in netgroup cache
- CVE-2024-33601: nscd: crash on out-of-memory condition
- CVE-2024-33602: nscd: memory corruption with NSS netgroup modules
iom=Florian Weimer <fweimer@redhat.com> - 2.17-326.1fh@- CVE-2024-2961: Out of bounds write in iconv conversion to ISO-2022-CN-EXT (RHEL-31803)inWDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)5miFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
ls#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fks]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xji	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)
F'GFtiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zsi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hrikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)rqm{Florian Weimer <fweimer@redhat.com> - 2.17-326.3f3@- nscd: Fix timeout type in netgroup cache (RHEL-34263)Upm?Florian Weimer <fweimer@redhat.com> - 2.17-326.2f0@- nscd: Do not use sendfile for the netgroup cache
- nscd: Use-after-free in netgroup cache
- CVE-2021-27645: nscd: double-free in netgroup cache
- CVE-2024-33599: nscd: buffer overflow in netgroup cache (RHEL-34263)
- CVE-2024-33600: nscd: null pointer dereferences in netgroup cache
- CVE-2024-33601: nscd: crash on out-of-memory condition
- CVE-2024-33602: nscd: memory corruption with NSS netgroup modules
;W`;i{WDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)5ziFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
ys#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fxs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xwi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/viwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xui	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)
ffs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)~iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)z}i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h|ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)
ArMXA	iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)i/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)ciaFlorian Weimer <fweimer@redhat.com> - 2.17-313^0"@- Remove problematic Obsoletes: (#1795573)iWDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)5iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)
\f\i/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x
i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h
ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)
O~}O/iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)
xi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)fs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)
TMi<Tz&i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h%ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)$iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)
#s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f"s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x!i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/ iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)
#|Nj#5-iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
,s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f+s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x*i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/)iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x(i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)'iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)
;W`;i4WDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)53iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
2s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f1s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x0i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)//iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x.i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)
2h2z9i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h8ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)r7m{Florian Weimer <fweimer@redhat.com> - 2.17-326.3f3@- nscd: Fix timeout type in netgroup cache (RHEL-34263)U6m?Florian Weimer <fweimer@redhat.com> - 2.17-326.2f0@- nscd: Do not use sendfile for the netgroup cache
- nscd: Use-after-free in netgroup cache
- CVE-2021-27645: nscd: double-free in netgroup cache
- CVE-2024-33599: nscd: buffer overflow in netgroup cache (RHEL-34263)
- CVE-2024-33600: nscd: null pointer dereferences in netgroup cache
- CVE-2024-33601: nscd: crash on out-of-memory condition
- CVE-2024-33602: nscd: memory corruption with NSS netgroup modules5m=Florian Weimer <fweimer@redhat.com> - 2.17-326.1fh@- CVE-2024-2961: Out of bounds write in iconv conversion to ISO-2022-CN-EXT (RHEL-31803)
#|Nj#5@iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
?s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f>s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x=i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/<iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x;i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380):iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)
.'HiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zGi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hFikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)EiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uDiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)Ci/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)cBiaFlorian Weimer <fweimer@redhat.com> - 2.17-313^0"@- Remove problematic Obsoletes: (#1795573)iAWDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)

er+V:eD\
deefbf7dc62157f10bf35bfcceae5fb497403a6fbf86fef1e8cfd5636f7bad10D[
670e8233e94a81c11ff801e9565903257b0694462a07b7f8724d3008d060ad94DZ
2fda5e0025c27a97a92116265279bc7592a072372d95f68ec7c2e289e884155bDY
df21a3fb768e603f322d9c16831a48f1a953dcc954f4b9b79e30a3e77107cd77DX
4266dcf7867c8c57f9684916eb7d5867aba2298775bf2e55af86bb7d8b4ef39cDW
5e130e7019c26fc26493cc8b1c227f57d4451afda99fda03e0dac4bd46628980DV
f7501b0cdc7eb8f83b56ce263d1a1408914f103af339c893bd31a587ad345cd3DU
f2fa340f24195c35a86b3ed5c2f4ca5405ba1e6482aab26dd1e8d7ce339a73fbDT
6815b9d123a4214f4d4bf68b7d0d6c2ea059a5ed94bf0abe1b157d1e14de7f6cDS
49e01e923bc5d1026751341c9a01ab8ef4d50d8b17e94f179de33afcbfb0b234DR
eae7a2d2bc9f6058c113c27e6bdea6677a865df0f7924ed51165a2653c2d2175DQ
650dc5eb73a88b8297704da202b361a3a2367643c25269a9d667ea5803dbc397DP
aeb54137355c495d8cbda465df5347f7e0075a2330f89bc679ccd9d8f8d5b4f6
KWbKOiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uNiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)Mi/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)cLiaFlorian Weimer <fweimer@redhat.com> - 2.17-313^0"@- Remove problematic Obsoletes: (#1795573)xKi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/JiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xIi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)
\f\Vi/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)xUi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/TiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xSi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)RiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zQi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hPikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)
O~}O/]iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x\i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)[iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zZi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hYikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)XiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uWiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)
vzdi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hcikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)biOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uaiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)`i/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)f_s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x^i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)
S|NjSkiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)ujiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)fis]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xhi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/giwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xfi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)eiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)
ffrs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xqi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/piwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xoi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)niCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zmi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hlikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)
tr[stxyi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)xiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zwi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hvikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)uiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)utiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)
ss#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)
TMi<Tzi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)~iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)
}s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f|s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x{i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/ziwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)
#|Nj#5iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)
LayzLxi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/
iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)z
i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h	ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)
>	P">fs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)5iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)
rMm=Florian Weimer <fweimer@redhat.com> - 2.17-326.1fh@- CVE-2024-2961: Out of bounds write in iconv conversion to ISO-2022-CN-EXT (RHEL-31803)iWDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)5iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)
'7/iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)rm{Florian Weimer <fweimer@redhat.com> - 2.17-326.3f3@- nscd: Fix timeout type in netgroup cache (RHEL-34263)Um?Florian Weimer <fweimer@redhat.com> - 2.17-326.2f0@- nscd: Do not use sendfile for the netgroup cache
- nscd: Use-after-free in netgroup cache
- CVE-2021-27645: nscd: double-free in netgroup cache
- CVE-2024-33599: nscd: buffer overflow in netgroup cache (RHEL-34263)
- CVE-2024-33600: nscd: null pointer dereferences in netgroup cache
- CVE-2024-33601: nscd: crash on out-of-memory condition
- CVE-2024-33602: nscd: memory corruption with NSS netgroup modules
i#m=Florian Weimer <fweimer@redhat.com> - 2.17-326.1fh@- CVE-2024-2961: Out of bounds write in iconv conversion to ISO-2022-CN-EXT (RHEL-31803)i"WDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)5!iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
 s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)
F'GF(iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)z'i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h&ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)r%m{Florian Weimer <fweimer@redhat.com> - 2.17-326.3f3@- nscd: Fix timeout type in netgroup cache (RHEL-34263)U$m?Florian Weimer <fweimer@redhat.com> - 2.17-326.2f0@- nscd: Do not use sendfile for the netgroup cache
- nscd: Use-after-free in netgroup cache
- CVE-2021-27645: nscd: double-free in netgroup cache
- CVE-2024-33599: nscd: buffer overflow in netgroup cache (RHEL-34263)
- CVE-2024-33600: nscd: null pointer dereferences in netgroup cache
- CVE-2024-33601: nscd: crash on out-of-memory condition
- CVE-2024-33602: nscd: memory corruption with NSS netgroup modules
;W`;i/WDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)5.iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
-s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f,s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x+i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/*iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x)i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)
ff6s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x5i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/4iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x3i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)2iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)z1i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h0ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)
ArMXA=iOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)u<iFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325);i/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)c:iaFlorian Weimer <fweimer@redhat.com> - 2.17-313^0"@- Remove problematic Obsoletes: (#1795573)i9WDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)58iFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
7s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)
\f\Di/Florian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)xCi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/BiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xAi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)@iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)z?i
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h>ikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)

er+V:eDi
5c3a51f2cd800bc1eb63007add93f02cb14e4acbe93b537fa3fb5d1a05f91ceaDh
9ff292253bb056d6533811af24502ff8e6b9f03d370e153698aff7cc1cb568b6Dg
794055514a0043fb0a97d85b7e623b6862a4861b6e488835385596d392b4f24eDf
a9cdf7b1790648907c553d9bd3ea79400a2884d68c1cb870f1c3d0c0ef2af44dDe
63e5114d5fdf7fa2162781d184e8588d2af92fd268bf72cf0824edd0ad85d504Dd
83e83351bd9f8e17bb928673f2236a6035cf3a335789585a60a5d5068c2c8b23Dc
68fdae357028fe930922530fba8f0491b1f04b11e6ce8cc9f6c7b362bfe37101Db
bffa643f42fbf585a2b14d6c8bfb9d7ac804826cf20ad4d14bbdc3c996290615Da
b8969d6cee16b77e095cb73262e74f3bea7aeaacc386fb96ed8274c2732c2893D`
71b7e0dd87fd725a96f1b8e998c7b16f7c063cf2f5888312df9191de086378b7D_
4c33dc16f8bf9f19d59d71c209205c27c9923c2016d5ca5f3409885c95bd8be4D^
ae5b869408794a434481ba8d5927690a56b9e2045b44efc1cca5b637285e435cD]
cafdbebcda7664e47d81f647d715249983cbe0bb4b063c1d56ab327a8766e2d0
O~}O/KiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xJi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)IiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zHi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hGikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)FiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uEiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)
xSi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)RiCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zQi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hPikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)OiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uNiFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)fMs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xLi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)
TMi<TzZi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hYikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)XiOCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)
Ws#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fVs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xUi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/TiwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)
#|Nj#5aiFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
`s#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f_s]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)x^i	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/]iwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x\i	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)[iCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)
;W`;ihWDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)5giFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
fs#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fes]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xdi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/ciwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xbi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)
2h2zmi
Carlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hlikFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)rkm{Florian Weimer <fweimer@redhat.com> - 2.17-326.3f3@- nscd: Fix timeout type in netgroup cache (RHEL-34263)Ujm?Florian Weimer <fweimer@redhat.com> - 2.17-326.2f0@- nscd: Do not use sendfile for the netgroup cache
- nscd: Use-after-free in netgroup cache
- CVE-2021-27645: nscd: double-free in netgroup cache
- CVE-2024-33599: nscd: buffer overflow in netgroup cache (RHEL-34263)
- CVE-2024-33600: nscd: null pointer dereferences in netgroup cache
- CVE-2024-33601: nscd: crash on out-of-memory condition
- CVE-2024-33602: nscd: memory corruption with NSS netgroup modulesim=Florian Weimer <fweimer@redhat.com> - 2.17-326.1fh@- CVE-2024-2961: Out of bounds write in iconv conversion to ISO-2022-CN-EXT (RHEL-31803)
#|Nj#5tiFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
ss#Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)frs]Siddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xqi	Carlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/piwCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xoi	Carlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)niCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)

;0Ib~;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49.1`/@- fixes bugs bz#1930561`};Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49_G@- fixes bugs bz#1286171`|;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-48_- fixes bugs bz#1895301v{gGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-47_@- fixes bugs bz#1286171 bz#1821743 bz#1837926kzQGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-46_"- fixes bugs bz#1873469 bz#1881823Vyu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-45_X- fixes bugs bz#1785714Vxu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-44_P- fixes bugs bz#1460657Vwu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-43_P- fixes bugs bz#1460657Vvu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-42_O@- fixes bugs bz#1785714iuWDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)
D4lD`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-58`- fixes bugs bz#1945143\1Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-57`[- fixes bugs bz#1600379 bz#1689375 bz#1782428 bz#1798897 bz#1815462 
  bz#1889966 bz#1891403 bz#1901468 bz#1903911 bz#1908635 bz#1917488 bz#1918018 
  bz#1919132 bz#1925425 bz#1927411 bz#1927640 bz#1928676 bz#1942816 bz#1943467 
  bz#1945143 bz#1946171 bz#1957191 bz#1957641b;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.2`@- fixes bugs bz#1953901b;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.1`e@- fixes bugs bz#1927235`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56`v@- fixes bugs bz#1948547`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-55`T@- fixes bugs bz#1939372fyWCentOS Sources <bugs@centos.org> - 6.0-49.1.el7.centos`P- remove vendor and/or packager lines
	+dK+kQGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-46_"- fixes bugs bz#1873469 bz#1881823V
u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-45_X- fixes bugs bz#1785714Vu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-44_P- fixes bugs bz#1460657Vu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-43_P- fixes bugs bz#1460657V
u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-42_O@- fixes bugs bz#1785714d	uWCentOS Sources <bugs@centos.org> - 6.0-61.el7.centosbL/@- remove vendor and/or packager lines`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-61a- fixes bugs bz#1973566RGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-60ad'@- fixes bugs bz#1668303 bz#1853631 bz#1901468 bz#1904137 bz#1911665 
  bz#1962972 bz#1973566 bz#1994593 bz#1995029 bz#1997447 bz#2006205`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-59`E- fixes bugs bz#1689375
	c$\-cb;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.2`@- fixes bugs bz#1953901b;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.1`e@- fixes bugs bz#1927235`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56`v@- fixes bugs bz#1948547`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-55`T@- fixes bugs bz#1939372fyWCentOS Sources <bugs@centos.org> - 6.0-49.1.el7.centos`P- remove vendor and/or packager linesb;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49.1`/@- fixes bugs bz#1930561`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49_G@- fixes bugs bz#1286171`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-48_- fixes bugs bz#1895301vgGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-47_@- fixes bugs bz#1286171 bz#1821743 bz#1837926
:=:duWCentOS Sources <bugs@centos.org> - 6.0-61.el7.centosbL/@- remove vendor and/or packager lines`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-61a- fixes bugs bz#1973566RGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-60ad'@- fixes bugs bz#1668303 bz#1853631 bz#1901468 bz#1904137 bz#1911665 
  bz#1962972 bz#1973566 bz#1994593 bz#1995029 bz#1997447 bz#2006205`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-59`E- fixes bugs bz#1689375`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-58`- fixes bugs bz#1945143\1Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-57`[- fixes bugs bz#1600379 bz#1689375 bz#1782428 bz#1798897 bz#1815462 
  bz#1889966 bz#1891403 bz#1901468 bz#1903911 bz#1908635 bz#1917488 bz#1918018 
  bz#1919132 bz#1925425 bz#1927411 bz#1927640 bz#1928676 bz#1942816 bz#1943467 
  bz#1945143 bz#1946171 bz#1957191 bz#1957641

!N.R!f'yWCentOS Sources <bugs@centos.org> - 6.0-49.1.el7.centos`P- remove vendor and/or packager linesb&;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49.1`/@- fixes bugs bz#1930561`%;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49_G@- fixes bugs bz#1286171`$;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-48_- fixes bugs bz#1895301v#gGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-47_@- fixes bugs bz#1286171 bz#1821743 bz#1837926k"QGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-46_"- fixes bugs bz#1873469 bz#1881823V!u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-45_X- fixes bugs bz#1785714V u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-44_P- fixes bugs bz#1460657Vu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-43_P- fixes bugs bz#1460657Vu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-42_O@- fixes bugs bz#1785714
J:pJ`.;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-59`E- fixes bugs bz#1689375`-;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-58`- fixes bugs bz#1945143\,1Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-57`[- fixes bugs bz#1600379 bz#1689375 bz#1782428 bz#1798897 bz#1815462 
  bz#1889966 bz#1891403 bz#1901468 bz#1903911 bz#1908635 bz#1917488 bz#1918018 
  bz#1919132 bz#1925425 bz#1927411 bz#1927640 bz#1928676 bz#1942816 bz#1943467 
  bz#1945143 bz#1946171 bz#1957191 bz#1957641b+;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.2`@- fixes bugs bz#1953901b*;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.1`e@- fixes bugs bz#1927235`);Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56`v@- fixes bugs bz#1948547`(;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-55`T@- fixes bugs bz#1939372
*`Uk6QGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-46_"- fixes bugs bz#1873469 bz#1881823V5u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-45_X- fixes bugs bz#1785714V4u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-44_P- fixes bugs bz#1460657V3u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-43_P- fixes bugs bz#1460657V2u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-42_O@- fixes bugs bz#1785714d1uWCentOS Sources <bugs@centos.org> - 6.0-61.el7.centosbL/@- remove vendor and/or packager lines`0;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-61a- fixes bugs bz#1973566R/Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-60ad'@- fixes bugs bz#1668303 bz#1853631 bz#1901468 bz#1904137 bz#1911665 
  bz#1962972 bz#1973566 bz#1994593 bz#1995029 bz#1997447 bz#2006205
	c$\-cb?;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.2`@- fixes bugs bz#1953901b>;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.1`e@- fixes bugs bz#1927235`=;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56`v@- fixes bugs bz#1948547`<;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-55`T@- fixes bugs bz#1939372f;yWCentOS Sources <bugs@centos.org> - 6.0-49.1.el7.centos`P- remove vendor and/or packager linesb:;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49.1`/@- fixes bugs bz#1930561`9;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49_G@- fixes bugs bz#1286171`8;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-48_- fixes bugs bz#1895301v7gGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-47_@- fixes bugs bz#1286171 bz#1821743 bz#1837926
:=:dEuWCentOS Sources <bugs@centos.org> - 6.0-61.el7.centosbL/@- remove vendor and/or packager lines`D;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-61a- fixes bugs bz#1973566RCGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-60ad'@- fixes bugs bz#1668303 bz#1853631 bz#1901468 bz#1904137 bz#1911665 
  bz#1962972 bz#1973566 bz#1994593 bz#1995029 bz#1997447 bz#2006205`B;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-59`E- fixes bugs bz#1689375`A;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-58`- fixes bugs bz#1945143\@1Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-57`[- fixes bugs bz#1600379 bz#1689375 bz#1782428 bz#1798897 bz#1815462 
  bz#1889966 bz#1891403 bz#1901468 bz#1903911 bz#1908635 bz#1917488 bz#1918018 
  bz#1919132 bz#1925425 bz#1927411 bz#1927640 bz#1928676 bz#1942816 bz#1943467 
  bz#1945143 bz#1946171 bz#1957191 bz#1957641

er+V:eDv
72811299e34ce97ab4abb454b8e728ca0bcc192a314cab3cc6799df21cc7b92bDu
c40a3a99e0047693ac6789e2c35f28639c6c6c3dafcaa8083ab1f6aec4279cd6Dt
aa8159ebe427848a84e44ec1263eb6e8467bd09994185803163c9501ede167adDs
dd928d632917d65ac27ed05d45f342a550ac01430159ae99363d9a406701fe04Dr
276df6b2e20398eb1acd7d2327f480491884ec450b49410d4cad1f010cba2e36Dq
ea5bee404d5fc3e07b6c6c946b4663fdc9b4befd89d89e5fd0c57da7b27800ecDp
b843af350666656b6246dd355d5e90fac356a7c6b609118d69957fefcf9350b3Do
a100ffb8d2d8478959b6d515f8a57612af98cd23cd3f340be8fdc45b223ebd2bDn
b83531fbbb21a612cb6bf9dd29ef1ba3afdeacd82de1d86b9949dac00d9edecbDm
b808a968c2ce3fd33503aecac4b0f640badeb9c4fc64b22515676fc26677bdbaDl
18f14d208b245267c6cc29b0b7074e0e030ee89e895659c26047d4186135bd94Dk
6c06e0b4e7b36d4a64097557ada558aaa42f90b60af6f66d06329756c6ea57c9Dj
b126c7678a3e74f9a0dca6136f61a6fdd9471991c6ce22a72c08d8a8aa86f2e1

!N.R!fOyWCentOS Sources <bugs@centos.org> - 6.0-49.1.el7.centos`P- remove vendor and/or packager linesbN;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49.1`/@- fixes bugs bz#1930561`M;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49_G@- fixes bugs bz#1286171`L;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-48_- fixes bugs bz#1895301vKgGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-47_@- fixes bugs bz#1286171 bz#1821743 bz#1837926kJQGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-46_"- fixes bugs bz#1873469 bz#1881823VIu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-45_X- fixes bugs bz#1785714VHu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-44_P- fixes bugs bz#1460657VGu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-43_P- fixes bugs bz#1460657VFu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-42_O@- fixes bugs bz#1785714
J:pJ`V;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-59`E- fixes bugs bz#1689375`U;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-58`- fixes bugs bz#1945143\T1Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-57`[- fixes bugs bz#1600379 bz#1689375 bz#1782428 bz#1798897 bz#1815462 
  bz#1889966 bz#1891403 bz#1901468 bz#1903911 bz#1908635 bz#1917488 bz#1918018 
  bz#1919132 bz#1925425 bz#1927411 bz#1927640 bz#1928676 bz#1942816 bz#1943467 
  bz#1945143 bz#1946171 bz#1957191 bz#1957641bS;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.2`@- fixes bugs bz#1953901bR;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.1`e@- fixes bugs bz#1927235`Q;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56`v@- fixes bugs bz#1948547`P;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-55`T@- fixes bugs bz#1939372
*`Uk^QGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-46_"- fixes bugs bz#1873469 bz#1881823V]u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-45_X- fixes bugs bz#1785714V\u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-44_P- fixes bugs bz#1460657V[u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-43_P- fixes bugs bz#1460657VZu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-42_O@- fixes bugs bz#1785714dYuWCentOS Sources <bugs@centos.org> - 6.0-61.el7.centosbL/@- remove vendor and/or packager lines`X;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-61a- fixes bugs bz#1973566RWGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-60ad'@- fixes bugs bz#1668303 bz#1853631 bz#1901468 bz#1904137 bz#1911665 
  bz#1962972 bz#1973566 bz#1994593 bz#1995029 bz#1997447 bz#2006205
	c$\-cbg;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.2`@- fixes bugs bz#1953901bf;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.1`e@- fixes bugs bz#1927235`e;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56`v@- fixes bugs bz#1948547`d;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-55`T@- fixes bugs bz#1939372fcyWCentOS Sources <bugs@centos.org> - 6.0-49.1.el7.centos`P- remove vendor and/or packager linesbb;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49.1`/@- fixes bugs bz#1930561`a;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49_G@- fixes bugs bz#1286171``;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-48_- fixes bugs bz#1895301v_gGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-47_@- fixes bugs bz#1286171 bz#1821743 bz#1837926
:=:dmuWCentOS Sources <bugs@centos.org> - 6.0-61.el7.centosbL/@- remove vendor and/or packager lines`l;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-61a- fixes bugs bz#1973566RkGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-60ad'@- fixes bugs bz#1668303 bz#1853631 bz#1901468 bz#1904137 bz#1911665 
  bz#1962972 bz#1973566 bz#1994593 bz#1995029 bz#1997447 bz#2006205`j;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-59`E- fixes bugs bz#1689375`i;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-58`- fixes bugs bz#1945143\h1Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-57`[- fixes bugs bz#1600379 bz#1689375 bz#1782428 bz#1798897 bz#1815462 
  bz#1889966 bz#1891403 bz#1901468 bz#1903911 bz#1908635 bz#1917488 bz#1918018 
  bz#1919132 bz#1925425 bz#1927411 bz#1927640 bz#1928676 bz#1942816 bz#1943467 
  bz#1945143 bz#1946171 bz#1957191 bz#1957641

!N.R!fwyWCentOS Sources <bugs@centos.org> - 6.0-49.1.el7.centos`P- remove vendor and/or packager linesbv;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49.1`/@- fixes bugs bz#1930561`u;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49_G@- fixes bugs bz#1286171`t;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-48_- fixes bugs bz#1895301vsgGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-47_@- fixes bugs bz#1286171 bz#1821743 bz#1837926krQGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-46_"- fixes bugs bz#1873469 bz#1881823Vqu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-45_X- fixes bugs bz#1785714Vpu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-44_P- fixes bugs bz#1460657Vou;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-43_P- fixes bugs bz#1460657Vnu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-42_O@- fixes bugs bz#1785714of
6flrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|	4	9	@	H	O	V	]	d	k	r	y							#	(	/	6	=	D	K	S	Z	a	h	m	t	~					'	.	6	?	E	O	V	^	g	m	w	~					&	.	7	=	C	I	O	W
_
e
l
s
x




	

 
'
-

5
=
E
M
S
Y
`
f
m
t
z





"
)
 0
!6
"=
#D
$J
%Q
'X
(^
)e
*l
+r
,y
-
.
/

0
1
2!
3(
4.
55
J:pJ`~;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-59`E- fixes bugs bz#1689375`};Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-58`- fixes bugs bz#1945143\|1Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-57`[- fixes bugs bz#1600379 bz#1689375 bz#1782428 bz#1798897 bz#1815462 
  bz#1889966 bz#1891403 bz#1901468 bz#1903911 bz#1908635 bz#1917488 bz#1918018 
  bz#1919132 bz#1925425 bz#1927411 bz#1927640 bz#1928676 bz#1942816 bz#1943467 
  bz#1945143 bz#1946171 bz#1957191 bz#1957641b{;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.2`@- fixes bugs bz#1953901bz;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.1`e@- fixes bugs bz#1927235`y;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56`v@- fixes bugs bz#1948547`x;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-55`T@- fixes bugs bz#1939372
*`UkQGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-46_"- fixes bugs bz#1873469 bz#1881823Vu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-45_X- fixes bugs bz#1785714Vu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-44_P- fixes bugs bz#1460657Vu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-43_P- fixes bugs bz#1460657Vu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-42_O@- fixes bugs bz#1785714duWCentOS Sources <bugs@centos.org> - 6.0-61.el7.centosbL/@- remove vendor and/or packager lines`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-61a- fixes bugs bz#1973566RGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-60ad'@- fixes bugs bz#1668303 bz#1853631 bz#1901468 bz#1904137 bz#1911665 
  bz#1962972 bz#1973566 bz#1994593 bz#1995029 bz#1997447 bz#2006205
	c$\-cb;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.2`@- fixes bugs bz#1953901b;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.1`e@- fixes bugs bz#1927235`
;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56`v@- fixes bugs bz#1948547`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-55`T@- fixes bugs bz#1939372fyWCentOS Sources <bugs@centos.org> - 6.0-49.1.el7.centos`P- remove vendor and/or packager linesb
;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49.1`/@- fixes bugs bz#1930561`	;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49_G@- fixes bugs bz#1286171`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-48_- fixes bugs bz#1895301vgGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-47_@- fixes bugs bz#1286171 bz#1821743 bz#1837926
:=:duWCentOS Sources <bugs@centos.org> - 6.0-61.el7.centosbL/@- remove vendor and/or packager lines`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-61a- fixes bugs bz#1973566RGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-60ad'@- fixes bugs bz#1668303 bz#1853631 bz#1901468 bz#1904137 bz#1911665 
  bz#1962972 bz#1973566 bz#1994593 bz#1995029 bz#1997447 bz#2006205`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-59`E- fixes bugs bz#1689375`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-58`- fixes bugs bz#1945143\1Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-57`[- fixes bugs bz#1600379 bz#1689375 bz#1782428 bz#1798897 bz#1815462 
  bz#1889966 bz#1891403 bz#1901468 bz#1903911 bz#1908635 bz#1917488 bz#1918018 
  bz#1919132 bz#1925425 bz#1927411 bz#1927640 bz#1928676 bz#1942816 bz#1943467 
  bz#1945143 bz#1946171 bz#1957191 bz#1957641

!N.R!fyWCentOS Sources <bugs@centos.org> - 6.0-49.1.el7.centos`P- remove vendor and/or packager linesb;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49.1`/@- fixes bugs bz#1930561`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49_G@- fixes bugs bz#1286171`;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-48_- fixes bugs bz#1895301vgGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-47_@- fixes bugs bz#1286171 bz#1821743 bz#1837926kQGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-46_"- fixes bugs bz#1873469 bz#1881823Vu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-45_X- fixes bugs bz#1785714Vu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-44_P- fixes bugs bz#1460657Vu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-43_P- fixes bugs bz#1460657Vu;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-42_O@- fixes bugs bz#1785714
J:pJ`&;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-59`E- fixes bugs bz#1689375`%;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-58`- fixes bugs bz#1945143\$1Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-57`[- fixes bugs bz#1600379 bz#1689375 bz#1782428 bz#1798897 bz#1815462 
  bz#1889966 bz#1891403 bz#1901468 bz#1903911 bz#1908635 bz#1917488 bz#1918018 
  bz#1919132 bz#1925425 bz#1927411 bz#1927640 bz#1928676 bz#1942816 bz#1943467 
  bz#1945143 bz#1946171 bz#1957191 bz#1957641b#;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.2`@- fixes bugs bz#1953901b";Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.1`e@- fixes bugs bz#1927235`!;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56`v@- fixes bugs bz#1948547` ;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-55`T@- fixes bugs bz#1939372
*`Uk.QGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-46_"- fixes bugs bz#1873469 bz#1881823V-u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-45_X- fixes bugs bz#1785714V,u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-44_P- fixes bugs bz#1460657V+u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-43_P- fixes bugs bz#1460657V*u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-42_O@- fixes bugs bz#1785714d)uWCentOS Sources <bugs@centos.org> - 6.0-61.el7.centosbL/@- remove vendor and/or packager lines`(;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-61a- fixes bugs bz#1973566R'Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-60ad'@- fixes bugs bz#1668303 bz#1853631 bz#1901468 bz#1904137 bz#1911665 
  bz#1962972 bz#1973566 bz#1994593 bz#1995029 bz#1997447 bz#2006205
	c$\-cb7;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.2`@- fixes bugs bz#1953901b6;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.1`e@- fixes bugs bz#1927235`5;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56`v@- fixes bugs bz#1948547`4;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-55`T@- fixes bugs bz#1939372f3yWCentOS Sources <bugs@centos.org> - 6.0-49.1.el7.centos`P- remove vendor and/or packager linesb2;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49.1`/@- fixes bugs bz#1930561`1;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49_G@- fixes bugs bz#1286171`0;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-48_- fixes bugs bz#1895301v/gGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-47_@- fixes bugs bz#1286171 bz#1821743 bz#1837926
:=:d=uWCentOS Sources <bugs@centos.org> - 6.0-61.el7.centosbL/@- remove vendor and/or packager lines`<;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-61a- fixes bugs bz#1973566R;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-60ad'@- fixes bugs bz#1668303 bz#1853631 bz#1901468 bz#1904137 bz#1911665 
  bz#1962972 bz#1973566 bz#1994593 bz#1995029 bz#1997447 bz#2006205`:;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-59`E- fixes bugs bz#1689375`9;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-58`- fixes bugs bz#1945143\81Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-57`[- fixes bugs bz#1600379 bz#1689375 bz#1782428 bz#1798897 bz#1815462 
  bz#1889966 bz#1891403 bz#1901468 bz#1903911 bz#1908635 bz#1917488 bz#1918018 
  bz#1919132 bz#1925425 bz#1927411 bz#1927640 bz#1928676 bz#1942816 bz#1943467 
  bz#1945143 bz#1946171 bz#1957191 bz#1957641
PjitCsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yBeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270AeJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357r@qwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n?msCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,>qiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501
jePjrIqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nHmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417Gs
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371Fs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624Es-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058DsFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999

er+V:eD
8afb8e27332a8489152d37ca03c25098d73ea51e0982b87f6a7bb7d35104b927D
6ff94086763de7dbc7a08197fae9ec80ef7dbba995606dc86e245517b4635a11D
68b19039b1e53465dc3f08f0e56e24f7e1672b449a51dd05f8ae10ff49416b66D
86f47f4e0ba937bd5cc3e11936092ae2624f85a10417a53a3620844161158224D
821df7321c6fd01dc77f9435ba556d7b08cfdfdb262113c4223883e34adeedf3D~
195f9b3429ced50e475e3f14ae59ece2ac1f581466cf6713231c9da9927283e0D}
b08dd14ff4c9cde964c7eb832ae4496d321debc822b86b970f8051ca8589c6b3D|
c4456d3a9934c3fe90a0750649cc735745508843da43735b39aa5cdcaadb99a4D{
d6af98392b986204b8b504202adcf13ec1eca355c819f9d4a1ee4d8448a14c55Dz
be7ce57daa28ef35ce7974665112d6551b70b8c48b1c14c9fb067c8aae658533Dy
134432ad69b8ff48c6929ed4f645153058d8cb0020dbb0be3eeb7ead882052b9Dx
838f9c1a4495b9f9bd85ed4019e8c2dc8ac645f72e221541ed03338c1cea45bdDw
e67c1938cd59583e0619d2d7e8c5830ae4585c3509d473ef7f73fac3a559c82f
Z{ZOs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624Ns-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058MsFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tLsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yKeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270JeJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
p$W]'Rui Matos <rmatos@redhat.com> - 3.22.1-4Y- Make our password validation similar to anaconda's
  Resolves: rhbz#1447941V]3Rui Matos <rmatos@redhat.com> - 3.22.1-3Y- Disable 'software' page as it doesn't make sense in RHEL
  Resolves: rhbz#1446735xU]Rui Matos <rmatos@redhat.com> - 3.22.1-2XC- Honor anaconda's firstboot being disabled
  Resolves: rhbz#1226819ITe1Kalev Lember <klember@redhat.com> - 3.22.1-1W%- Update to 3.22.1ISe1Kalev Lember <klember@redhat.com> - 3.22.0-1W@- Update to 3.22.0KRg3Kalev Lember <klember@redhat.com> - 3.21.92-1W@- Update to 3.21.92qQssFlorian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419Ps
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
Cv"sCk_ayRay Strode <rstrode@redhat.com> - 3.28.1-4\F@- Fix busy loop in account plugin
  Resolves: #1600161^^a_Ray Strode <rstrode@redhat.com> - 3.28.1-2[Y- Fix account schema
  Resolves: #1597353^]e[Kalev Lember <klember@redhat.com> - 3.28.1-1ZJ@- Update to 3.28.1
- Resolves: #1568621+\ioBastien Nocera <bnocera@redhat.com> - 3.26.2-9Z$+ gnome-settings-daemon-3.26.2-9
- Revert automatic suspend after inactivity, it was rejected
- Related: #1449171q[ymMichael Catanzaro <mcatanzaro@redhat.com> - 3.28.0-2.1b- Remove timezone boundaries
  Related: #2098257zZaRay Strode <rstrode@redhat.com> - 3.28.0-2\F@- Ensure vendora logo gets used instead of foot
  Resolves: #1711308`Yi[Richard Hughes <rhughes@redhat.com> - 3.28.0-1[- Update to 3.28.0
- Resolves: #1568175X]1Rui Matos <rmatos@redhat.com> - 3.22.1-5Y@- Update session definition files to work with GNOME 3.26
  Resolves: rhbz#1506607
qfee!Benjamin Berg <bberg@redhat.com> - 3.28.1-10_@- Prevent automatic logout warning in greeter sessions
  Related: #1729296:dcBenjamin Berg <bberg@redhat.com> - 3.28.1-9_- Keep auto-logout working inside VMs
  Resolves: #1672998
- Never log out automatically from greeter sessions
  Resolves: #1729296	cm'Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]rJ@- Add display mapping check specific for the Dell Canvas
  Resolves: #1548320bm7Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7]L- Fallback scale properly without org.gnome.Mutter.DisplayConfig
  Resolves: #1556776sam}Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]J@- Handle rfkill device disappearing
  Resolves: #1691197`m+Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]5@- Added patch for - keyboard: Enable ibus for OSK purposes
  Resolves: #1632904
Q!lm7Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7]L- Fallback scale properly without org.gnome.Mutter.DisplayConfig
  Resolves: #1556776skm}Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]J@- Handle rfkill device disappearing
  Resolves: #1691197jm+Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]5@- Added patch for - keyboard: Enable ibus for OSK purposes
  Resolves: #1632904kiayRay Strode <rstrode@redhat.com> - 3.28.1-4\F@- Fix busy loop in account plugin
  Resolves: #1600161^ha_Ray Strode <rstrode@redhat.com> - 3.28.1-2[Y- Fix account schema
  Resolves: #1597353^ge[Kalev Lember <klember@redhat.com> - 3.28.1-1ZJ@- Update to 3.28.1
- Resolves: #1568621+fioBastien Nocera <bnocera@redhat.com> - 3.26.2-9Z$+ gnome-settings-daemon-3.26.2-9
- Revert automatic suspend after inactivity, it was rejected
- Related: #1449171
ps/mpsm+Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]5@- Added patch for - keyboard: Enable ibus for OSK purposes
  Resolves: #1632904krayRay Strode <rstrode@redhat.com> - 3.28.1-4\F@- Fix busy loop in account plugin
  Resolves: #1600161^qa_Ray Strode <rstrode@redhat.com> - 3.28.1-2[Y- Fix account schema
  Resolves: #1597353^pe[Kalev Lember <klember@redhat.com> - 3.28.1-1ZJ@- Update to 3.28.1
- Resolves: #1568621oe!Benjamin Berg <bberg@redhat.com> - 3.28.1-10_@- Prevent automatic logout warning in greeter sessions
  Related: #1729296:ncBenjamin Berg <bberg@redhat.com> - 3.28.1-9_- Keep auto-logout working inside VMs
  Resolves: #1672998
- Never log out automatically from greeter sessions
  Resolves: #1729296	mm'Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]rJ@- Add display mapping check specific for the Dell Canvas
  Resolves: #1548320
$h$xe!Benjamin Berg <bberg@redhat.com> - 3.28.1-10_@- Prevent automatic logout warning in greeter sessions
  Related: #1729296:wcBenjamin Berg <bberg@redhat.com> - 3.28.1-9_- Keep auto-logout working inside VMs
  Resolves: #1672998
- Never log out automatically from greeter sessions
  Resolves: #1729296	vm'Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]rJ@- Add display mapping check specific for the Dell Canvas
  Resolves: #1548320um7Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7]L- Fallback scale properly without org.gnome.Mutter.DisplayConfig
  Resolves: #1556776stm}Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]J@- Handle rfkill device disappearing
  Resolves: #1691197
"*-"m7Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7]L- Fallback scale properly without org.gnome.Mutter.DisplayConfig
  Resolves: #1556776s~m}Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]J@- Handle rfkill device disappearing
  Resolves: #1691197}m+Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]5@- Added patch for - keyboard: Enable ibus for OSK purposes
  Resolves: #1632904k|ayRay Strode <rstrode@redhat.com> - 3.28.1-4\F@- Fix busy loop in account plugin
  Resolves: #1600161^{a_Ray Strode <rstrode@redhat.com> - 3.28.1-2[Y- Fix account schema
  Resolves: #1597353^ze[Kalev Lember <klember@redhat.com> - 3.28.1-1ZJ@- Update to 3.28.1
- Resolves: #1568621yo3Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-11`t- Fix possible crash on gsd-media-keys startup
  Resolves: #1878167
- Ignore permission issues during gsd-housekeeping file deletion
  Resolves: #1909954
- Revert mapping of "XF86RFKill" key
  Resolves: #1888412
ls/l+ioBastien Nocera <bnocera@redhat.com> - 3.26.2-9Z$+ gnome-settings-daemon-3.26.2-9
- Revert automatic suspend after inactivity, it was rejected
- Related: #1449171o3Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-11`t- Fix possible crash on gsd-media-keys startup
  Resolves: #1878167
- Ignore permission issues during gsd-housekeeping file deletion
  Resolves: #1909954
- Revert mapping of "XF86RFKill" key
  Resolves: #1888412e!Benjamin Berg <bberg@redhat.com> - 3.28.1-10_@- Prevent automatic logout warning in greeter sessions
  Related: #1729296:cBenjamin Berg <bberg@redhat.com> - 3.28.1-9_- Keep auto-logout working inside VMs
  Resolves: #1672998
- Never log out automatically from greeter sessions
  Resolves: #1729296	m'Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]rJ@- Add display mapping check specific for the Dell Canvas
  Resolves: #1548320
>A6	m'Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]rJ@- Add display mapping check specific for the Dell Canvas
  Resolves: #1548320
m7Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7]L- Fallback scale properly without org.gnome.Mutter.DisplayConfig
  Resolves: #1556776s	m}Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]J@- Handle rfkill device disappearing
  Resolves: #1691197m+Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]5@- Added patch for - keyboard: Enable ibus for OSK purposes
  Resolves: #1632904kayRay Strode <rstrode@redhat.com> - 3.28.1-4\F@- Fix busy loop in account plugin
  Resolves: #1600161^a_Ray Strode <rstrode@redhat.com> - 3.28.1-2[Y- Fix account schema
  Resolves: #1597353^e[Kalev Lember <klember@redhat.com> - 3.28.1-1ZJ@- Update to 3.28.1
- Resolves: #1568621
NB
KNm+Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]5@- Added patch for - keyboard: Enable ibus for OSK purposes
  Resolves: #1632904kayRay Strode <rstrode@redhat.com> - 3.28.1-4\F@- Fix busy loop in account plugin
  Resolves: #1600161^a_Ray Strode <rstrode@redhat.com> - 3.28.1-2[Y- Fix account schema
  Resolves: #1597353^e[Kalev Lember <klember@redhat.com> - 3.28.1-1ZJ@- Update to 3.28.1
- Resolves: #1568621+ioBastien Nocera <bnocera@redhat.com> - 3.26.2-9Z$+ gnome-settings-daemon-3.26.2-9
- Revert automatic suspend after inactivity, it was rejected
- Related: #1449171
e!Benjamin Berg <bberg@redhat.com> - 3.28.1-10_@- Prevent automatic logout warning in greeter sessions
  Related: #1729296:cBenjamin Berg <bberg@redhat.com> - 3.28.1-9_- Keep auto-logout working inside VMs
  Resolves: #1672998
- Never log out automatically from greeter sessions
  Resolves: #1729296
bh$b^a_Ray Strode <rstrode@redhat.com> - 3.28.1-2[Y- Fix account schema
  Resolves: #1597353^e[Kalev Lember <klember@redhat.com> - 3.28.1-1ZJ@- Update to 3.28.1
- Resolves: #1568621e!Benjamin Berg <bberg@redhat.com> - 3.28.1-10_@- Prevent automatic logout warning in greeter sessions
  Related: #1729296:cBenjamin Berg <bberg@redhat.com> - 3.28.1-9_- Keep auto-logout working inside VMs
  Resolves: #1672998
- Never log out automatically from greeter sessions
  Resolves: #1729296	m'Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]rJ@- Add display mapping check specific for the Dell Canvas
  Resolves: #1548320m7Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7]L- Fallback scale properly without org.gnome.Mutter.DisplayConfig
  Resolves: #1556776sm}Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]J@- Handle rfkill device disappearing
  Resolves: #1691197
'k' e!Benjamin Berg <bberg@redhat.com> - 3.28.1-10_@- Prevent automatic logout warning in greeter sessions
  Related: #1729296:cBenjamin Berg <bberg@redhat.com> - 3.28.1-9_- Keep auto-logout working inside VMs
  Resolves: #1672998
- Never log out automatically from greeter sessions
  Resolves: #1729296	m'Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]rJ@- Add display mapping check specific for the Dell Canvas
  Resolves: #1548320m7Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7]L- Fallback scale properly without org.gnome.Mutter.DisplayConfig
  Resolves: #1556776sm}Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]J@- Handle rfkill device disappearing
  Resolves: #1691197m+Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]5@- Added patch for - keyboard: Enable ibus for OSK purposes
  Resolves: #1632904kayRay Strode <rstrode@redhat.com> - 3.28.1-4\F@- Fix busy loop in account plugin
  Resolves: #1600161
"*-"'m7Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-7]L- Fallback scale properly without org.gnome.Mutter.DisplayConfig
  Resolves: #1556776s&m}Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-6]J@- Handle rfkill device disappearing
  Resolves: #1691197%m+Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-5]5@- Added patch for - keyboard: Enable ibus for OSK purposes
  Resolves: #1632904k$ayRay Strode <rstrode@redhat.com> - 3.28.1-4\F@- Fix busy loop in account plugin
  Resolves: #1600161^#a_Ray Strode <rstrode@redhat.com> - 3.28.1-2[Y- Fix account schema
  Resolves: #1597353^"e[Kalev Lember <klember@redhat.com> - 3.28.1-1ZJ@- Update to 3.28.1
- Resolves: #1568621!o3Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-11`t- Fix possible crash on gsd-media-keys startup
  Resolves: #1878167
- Ignore permission issues during gsd-housekeeping file deletion
  Resolves: #1909954
- Revert mapping of "XF86RFKill" key
  Resolves: #1888412
s/q-ssFlorian Müllner <fmuellner@redhat.com> - 3.28.3-24]N@- Fix orphaned animation actors
  Related: #1753799,c7Ray Strode <rstrode@redhat.coM> - 3.28.3-23]|@- Fix "Not Listed?" entry to shows characters instead of bullets
  Resolves: #1772896+o3Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-11`t- Fix possible crash on gsd-media-keys startup
  Resolves: #1878167
- Ignore permission issues during gsd-housekeeping file deletion
  Resolves: #1909954
- Revert mapping of "XF86RFKill" key
  Resolves: #1888412*e!Benjamin Berg <bberg@redhat.com> - 3.28.1-10_@- Prevent automatic logout warning in greeter sessions
  Related: #1729296:)cBenjamin Berg <bberg@redhat.com> - 3.28.1-9_- Keep auto-logout working inside VMs
  Resolves: #1672998
- Never log out automatically from greeter sessions
  Resolves: #1729296	(m'Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]rJ@- Add display mapping check specific for the Dell Canvas
  Resolves: #1548320
XXX5cQRay Strode <rstrode@redhat.com> - 3.28.3-32_#- Fix crasher
  Resolves: #1897063[4cWRay Strode <rstrode@redhat.com> - 3.28.3-31_@- Add leak fixes
  Resolves: #18819953s%Florian Müllner <fmuellner@redhat.com> - 3.28.3-30^)@- Wake up lock screen when deactivated programmatically
  Resolves: #1850201k2sgFlorian Müllner <fmuellner@redhat.com> - 3.28.3-29^@- Squash more JS warnings
  Related: #17511211sFlorian Müllner <fmuellner@redhat.com> - 3.28.3-28^@- Fix some (harmless but annoying) JS warnings
  Related: #1751121|0sFlorian Müllner <fmuellner@redhat.com> - 3.28.3-27^V@- Avoid warning on early signal emission
  Resolves: #1735700u/s{Florian Müllner <fmuellner@redhat.com> - 3.28.3-26^1- Fix IM set-content-type handling
  Resolves: #1771841s.swFlorian Müllner <fmuellner@redhat.com> - 3.28.3-25^@- Improve performance under load
  Resolves: #1824871
?,?[=cWRay Strode <rstrode@redhat.com> - 3.28.3-31_@- Add leak fixes
  Resolves: #1881995<s%Florian Müllner <fmuellner@redhat.com> - 3.28.3-30^)@- Wake up lock screen when deactivated programmatically
  Resolves: #1850201k;sgFlorian Müllner <fmuellner@redhat.com> - 3.28.3-29^@- Squash more JS warnings
  Related: #1751121:sFlorian Müllner <fmuellner@redhat.com> - 3.28.3-28^@- Fix some (harmless but annoying) JS warnings
  Related: #1751121|9sFlorian Müllner <fmuellner@redhat.com> - 3.28.3-27^V@- Avoid warning on early signal emission
  Resolves: #1735700u8s{Florian Müllner <fmuellner@redhat.com> - 3.28.3-26^1- Fix IM set-content-type handling
  Resolves: #1771841s7swFlorian Müllner <fmuellner@redhat.com> - 3.28.3-25^@- Improve performance under load
  Resolves: #1824871q6ssFlorian Müllner <fmuellner@redhat.com> - 3.28.3-24]N@- Fix orphaned animation actors
  Related: #1753799
B1C?BEs%Florian Müllner <fmuellner@redhat.com> - 3.28.3-30^)@- Wake up lock screen when deactivated programmatically
  Resolves: #1850201kDsgFlorian Müllner <fmuellner@redhat.com> - 3.28.3-29^@- Squash more JS warnings
  Related: #1751121CsFlorian Müllner <fmuellner@redhat.com> - 3.28.3-28^@- Fix some (harmless but annoying) JS warnings
  Related: #1751121|BsFlorian Müllner <fmuellner@redhat.com> - 3.28.3-27^V@- Avoid warning on early signal emission
  Resolves: #1735700uAs{Florian Müllner <fmuellner@redhat.com> - 3.28.3-26^1- Fix IM set-content-type handling
  Resolves: #1771841s@swFlorian Müllner <fmuellner@redhat.com> - 3.28.3-25^@- Improve performance under load
  Resolves: #1824871q?ssFlorian Müllner <fmuellner@redhat.com> - 3.28.3-33`	l- Guard against StWidget crash
  Resolves: #1861428X>cQRay Strode <rstrode@redhat.com> - 3.28.3-32_#- Fix crasher
  Resolves: #1897063
JGeDJMeJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357rLqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nKmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,JqiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501kIsgFlorian Müllner <fmuellner@redhat.com> - 3.29.3-34`- Fix another JS warning
  Resolves: #1860445qHssFlorian Müllner <fmuellner@redhat.com> - 3.28.3-33`	l- Guard against StWidget crash
  Resolves: #1861428XGcQRay Strode <rstrode@redhat.com> - 3.28.3-32_#- Fix crasher
  Resolves: #1897063[FcWRay Strode <rstrode@redhat.com> - 3.28.3-31_@- Add leak fixes
  Resolves: #1881995

er+V:eD
e09b5f3555e23622b184571a63391c9f149a33111cf6ec9a07616cecca01c1c3D
996c2919ed070ff29e27f8c9e3ec7f7ce69e1eea9e9da6d559423f84983ba41cD
8d8f18480a50ae9e2993b7bee4e3a0d583f2b6288ec60e32b2b42a5b4256456aD

1afd010d898c09610cd98864d1e601d56fbb031d59f51f0e0e1a08fc482b006fD
9c633fbd6673e42c90f906b0939d7603ab4b721859bff248db9a4cc0489b32a6D
abb8fad659ee9b374da07546268016023d98393401191ae5ac9ac40748aad0edD

d3f83e6ec632331c1a4225feeaaf7c261512e7eb7a079d16b971c7c027fa3c0bD	
90b70e89b675963abcce8494de690686f885b273dc190de89560db7345231837D
d8e476878a37bbc6056f5f2cfa3f1c9b9406ca06fd0c7ba1bb6e17b09a385ae9D
8d5c171c9ce6a333fe8241291edf73b4b6bbed0df2258efac8cfac13210aba97D
b06ece51d62eb4905a59da18d4a041ada4dc1d9541693245f60fa02f0ec302deD
30eb275b4ea0c87a84abafbe22dd3006c16cac9a0fa0c57de243a23c72d28adfD
db4ef1e0a6b2f44fef3fdb8ad686016dcfa25ae6374a3646a9c898f01668d499
]
r]Ss
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371Rs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624Qs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058PsFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tOsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yNeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270
YsFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tXsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yWeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270VeJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357rUqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nTmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417
NmX4Nr`qwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n_msCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,^qiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501q]ssFlorian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419\s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371[s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624Zs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Zfs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624es-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058dsFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tcsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102ybeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270aeJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 msFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tlsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102ykeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270jeJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357riqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nhmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417gs
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4NrtqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nsmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,rqiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qqssFlorian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419ps
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371os-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624ns-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Zzs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624ys-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058xsFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999twsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yveJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270ueJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 s	Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tsy	Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102ye	Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270~e	Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357r}qw	Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n|ms	Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417{s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4Nrqw
Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nms
Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,qi
Florian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qss	Florian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419s
	Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371s-	Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624s-	Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Zs-
Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624
s-
Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tsy
Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y
e
Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270	e
Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 sFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270eJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357rqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417s

Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4NrqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,qiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qssFlorian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Z"s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624!s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058 sFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270eJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 )s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t(sy
Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y'e
Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270&e
Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357r%qw
Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n$ms
Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417#s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4Nr0qwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n/msCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,.qiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501q-ss
Florian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419,s

Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371+s-
Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624*s-
Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Z6s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #19016245s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #18480584sFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t3syFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y2eJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #17782701eJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 =sFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t<syFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y;eJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270:eJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357r9qwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n8msCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #17024177s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4NrDqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nCmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,BqiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qAssFlorian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419@s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371?s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624>s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{ZJs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624Is-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058HsFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tGsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yFeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270EeJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 QsFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tPsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yOeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270NeJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357rMqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nLmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417Ks
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371

er+V:eD
de133553b72273258b6a99609593572620371fffa43173a2338c8558bfa99e7eD
a3f82abae1cfa7453d9b8553062e87caf6acf5fab2d57ec6ba1cd09335b548f8D
44c332e4f12eed26da249463f404e2a9b0a26965d3864059eabafa8b359ad304D
c2dee3fc80a476ec4b0960d8a193508056f424e74141e414c57914a3c8f07e86D
0f15bf4e21cca58586fae47893052796624bb20d948f2087a88fa6589059216aD
86d37b5ad18b07654ecb4a92153db1f1929859e2e00c1a74b0455e6a33a22949D
db707f9fd1fe35154ab4047938dc0ffe4a07327789e176680886a697d796b61eD
bd606511a1c296702ecfd01d1fa8f5651c4c51d34d4f242cd3fe75de4b25c299D
5e7fbcbc653f613c746c3e1bb2b62d8fcc19ac0cf1d92487882d5541de4284c0D
ae2e332cb8ed86d6de74c580f47de47f6f0d33330807f898fad3b7a0b8ffa440D
728ac150acc4c81d235b89af0449b11ae268d8c5ea5df6ca8b54c4f90b3deb7cD
d2cc1f66c9ca4847924aa950f6bf6e884b94331ad97c0150bd241fccb76ae118D
1dcd5933cc511b7268b7c46d30ee331788e825ef5dc6aeefc373ae7708e575f7
NmX4NrXqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nWmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,VqiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qUssFlorian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419Ts
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371Ss-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624Rs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Z^s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624]s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058\sFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t[syFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yZeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270YeJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 esFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tdsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yceJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270beJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357raqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n`msCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417_s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4NrlqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nkmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,jqiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qissFlorian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419hs
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371gs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624fs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Zrs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624qs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058psFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tosyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yneJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270meJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 ysFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999txsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yweJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270veJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357ruqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286ntmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417ss
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4NrqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,~qiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501q}ssFlorian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419|s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371{s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624zs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Zs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058sFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270eJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 
sFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270
eJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357r	qwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4NrqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,qiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qssFlorian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Zs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058sFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270eJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 !sFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t syFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270eJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357rqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4Nr(qwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n'msCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,&qiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501q%ssFlorian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419$s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371#s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624"s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Z.s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624-s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058,sFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t+syFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y*eJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270)eJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 5sFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t4syFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y3eJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #17782702eJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357r1qwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n0msCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417/s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4Nr<qwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n;msCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,:qiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501q9ssFlorian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #18754198s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #19043717s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #19016246s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{ZBs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624As-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058@sFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t?syFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y>eJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270=eJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 IsFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tHsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yGeJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270FeJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357rEqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nDmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417Cs
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4NrPqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nOmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,NqiFlorian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qMssFlorian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419Ls
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371Ks-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624Js-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058

er+V:eD*
44d06a1ca389cc452e21dee550e31d9247c635c403355f8fa7df144b76f7ee8eD)
d8dd9b50628f10da8aacac180c1d67e558c1ea21f01087d813dcd0249e74edbdD(
b4cbf615b36395073b874a9c133a8bf54fd76e3016b591c08aa9bb4e0bc70679D'
7c3a5727b1fac7e2de0318d8d80ec9c79f8d4817cde856564f2029e02691769fD&
c480e3a1a9b563578db18be5b147c32561044872ed18447819bf430f2cde21c2D%
2a85a789f09834655fede0beff4a30eea8c21356b1669e49795509c63d513254D$
82c766a327f786b1d8e1cf34a5ed50e63b48ed813b1e42b1cdf8bdbe7d349866D#
f37f01eec61a287a1271577470666ad9b985aa271aa8eec00beb21627c77dd76D"
589b285340071ac5a04d6fc61453fbc9ef5c7d6c4d24c934c944d51787ae5966D!
163f0d23cfe8fd01038ccb7746a4af46b5d8859204698181d3dcc73e81d8fb94D 
ae74b02c469234e1874d6852f03edc12b68b262ee96a49590345a04f69d92c18D
4e2fdfb11cf1f7b0f724741e7730e02c2e6ab6bc2b306bf41ace3283e2b8739bD
1661002b4d684efd2898ed72901055d3f780eab559156150f5421b5f448d823d
Z{ZVs-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624Us-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058TsFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tSsyFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yReJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270QeJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 ]sFlorian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t\syFlorian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y[eJonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270ZeJonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357rYqwFlorian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nXmsCarlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417Ws
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4Nrdqw Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286ncms Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,bqi Florian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qassFlorian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419`s
Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371_s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624^s-Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Zjs- Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624is- Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058hs Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tgsy Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yfe Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270ee Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 qs!Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tpsy!Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yoe!Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270ne!Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357rmqw!Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nlms!Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417ks
 Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4Nrxqw"Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nwms"Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,vqi"Florian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501quss!Florian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419ts
!Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371ss-!Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624rs-!Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Z~s-"Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624}s-"Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058|s"Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t{sy"Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yze"Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270ye"Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 s#Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tsy#Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102ye#Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270e#Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357rqw#Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nms#Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417s
"Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4Nrqw$Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nms$Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,
qi$Florian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501q	ss#Florian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419s
#Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371s-#Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624s-#Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Zs-$Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624s-$Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058s$Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tsy$Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102ye$Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270
e$Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 s%Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tsy%Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102ye%Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270e%Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357rqw%Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nms%Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417s
$Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4Nr qw&Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nms&Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,qi&Florian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qss%Florian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419s
%Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371s-%Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624s-%Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Z&s-&Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624%s-&Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058$s&Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t#sy&Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y"e&Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270!e&Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 -s'Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t,sy'Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y+e'Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270*e'Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357r)qw'Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n(ms'Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417's
&Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4Nr4qw(Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n3ms(Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,2qi(Florian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501q1ss'Florian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #18754190s
'Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371/s-'Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624.s-'Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Z:s-(Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #19016249s-(Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #18480588s(Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t7sy(Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y6e(Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #17782705e(Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 As)Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t@sy)Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y?e)Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270>e)Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357r=qw)Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n<ms)Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417;s
(Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4NrHqw*Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nGms*Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,Fqi*Florian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qEss)Florian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419Ds
)Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371Cs-)Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624Bs-)Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{ZNs-*Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624Ms-*Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058Ls*Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tKsy*Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yJe*Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270Ie*Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 Us+Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tTsy+Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102ySe+Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270Re+Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357rQqw+Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nPms+Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417Os
*Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371

er+V:eD7
87b4bf85d74acb5f568e2cb39c5b3f1c972eba5db5f0219021c385fcf2d29732D6
c80cdecf0a4d4edc4e52f018171be3aaff999a6abe4579401f05dcf51a2e2586D5
425b1c0988b4a82a7edad5a994ae16e7775d36d9efe1e2cfab48f0893276a38cD4
2790ee1f2222b6bacc39245756529d819aa586d22b8f921a30392fabf1e845ccD3
6b9b9395896aada874edc170d344039f28e922ef896e327a1058aac608e3bf71D2
f759508ca587ecc4ba720b9a7958780468e4b3259069514d52bbb9963d29f17eD1
3d16cbc8797f49fcd4f8fd66dcd9abf0441a825f9ad6028f0548e6003c0e2366D0
547b0510681fd163f611bd36836750eb87f43894c5f7c7b2578765bbcce090bdD/
9408ed4cf3bb74bfe932474193ada99007d34cf9c767bbc2acddae99d4db12feD.
017e2d09736a9888ed8e38dca3b1a005fcfebb65e0d3d31617fa9ba35f62526dD-
7af718b81b8f45b39e82ed35fcd1065c8dd2f178f9310777598dc5f3544dd695D,
bdc8ab95aa96bf3f851a6cd97f2d9c878fe34101ff383e7ab7f2c5eb11a13d78D+
f0264bd6f2bbb5db07d005243d60a13920c116e9e1b122e88fab4886f3ff1bc8
NmX4Nr\qw,Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286n[ms,Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,Zqi,Florian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qYss+Florian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419Xs
+Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371Ws-+Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624Vs-+Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Zbs-,Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624as-,Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058`s,Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t_sy,Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y^e,Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270]e,Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 is-Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999thsy-Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yge-Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270fe-Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357reqw-Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286ndms-Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417cs
,Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4Nrpqw.Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286noms.Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,nqi.Florian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qmss-Florian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419ls
-Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371ks--Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624js--Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Zvs-.Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624us-.Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058ts.Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tssy.Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102yre.Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270qe.Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 }s/Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999t|sy/Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102y{e/Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270ze/Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357ryqw/Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nxms/Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417ws
.Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
NmX4Nrqw0Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nms0Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417,qi0Florian Müllner <fmuellner@redhat.com> - 3.28.1-7\@- Add window-grouper extension
  Resolves: #1355845

- Add disable-screenshield extension
  Resolves: #1643501qss/Florian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419s
/Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371s-/Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624~s-/Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
Z{Z
s-0Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624	s-0Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058s0Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tsy0Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102ye0Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270e0Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357
~
 s1Florian Müllner <fmuellner@redhat.com> - 3.28.1-13^- Adjust dash-to-dock for classic backports
  Resolves: #1805920
- Fix inconsistent state in window-list prefs dialog
  Resolves: #1613835
- Add accessible name to status icons
  Resolves: #1600999tsy1Florian Müllner <fmuellner@redhat.com> - 3.28.1-12^- Drop faulty patch from backport
  Resolves: #1782102ye1Jonas Ådahl <jadahl@redhat.com> - 3.28.1-11]B- A couple of fixes to the classic backports
  Resolves: #1778270e1Jonas Ådahl <jadahl@redhat.com> - 3.28.1-10]V- Fix unwanted appearance of workspace switcher menu
  Resolves: #1752357r
qw1Florian Müllner <fmuellner@redhat.com> - 3.28.1-9]bx@- Make classic mode more classic
  Resolves: #1720286nms1Carlos Garnacho <cgarnach@redhat.com> - 3.28.1-8]M`@- Add extra-osk-keys extension
  Resolves: #1702417s
0Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371
mX$=2Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233qss1Florian Müllner <fmuellner@redhat.com> - 3.28.1-17`x*- Override lg foreground color
  Resolves: #1875419s
1Florian Müllner <fmuellner@redhat.com> - 3.28.1-16`@- Fix stuck window picker after screen lock
  Resolves: #1904371s-1Florian Müllner <fmuellner@redhat.com> - 3.28.1-15`@- Add workspace tooltips to workspace-indicator/window-list
  Resolves: #1901624s-1Florian Müllner <fmuellner@redhat.com> - 3.28.1-14^- Fix workspace switch in window-list outside GNOME Classic
  Resolves: #1848058
TQTzy2Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.Q2Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#19421482Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298%2Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240+2Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+K2Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
,S,#"	=3Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233!	3Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240" G3Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987gyY2Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733y72Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gw[2Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860
ZRZy(w3Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-'	Q3Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148&	3Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298%	%3Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240$	+3Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*#	K3Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!-%4Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240,+4Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240++K4Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$*=4Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233f)u[3Robbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>934%5Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240g3yY4Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-287332y74Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g1w[4Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z0y4Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860./Q4Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148.4Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9E;w5Nicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460g:yY5Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-287339y75Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g8w[5Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z7y5Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.6Q5Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#194214855Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'?Q6Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
>6Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213k=wc5Nicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~<w5Nicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvWBcM6Peter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QAcA6Peter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V@/6Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#G	=6Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233F	6Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"EG6Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aDcc6Peter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rCc6Peter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%L	7Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"KG7Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aJcc7Peter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rIc7Peter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705WHcM7Peter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`Q	7Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298P	%7Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240O	+7Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*N	K7Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#M	=7Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233

er+V:eDD
f5037b5658870caf9db57fef7e511d690b1959170ab11cfda5aa83f814633ba2DC
17166fc5096e5f62c88e7eff8f2e850bf452600e5d52eaf11a1dff4bc21c285fDB
6ddc8fea6aac5d2cf395f1d06506d529fc6fde104aa7ced09ed3d16f8996db76DA
50c11af52b9c7aba5a74a2beb07e802550af036c3a37feb00b9bfca7b241ffa1D@
3f5208ad5e6d40b1cdbd818874e03c204f1a94371bda2f9525511fe0a0803522D?
91c532ed3ffc0c3a3ff8c2e0c2f2eea28b1497fd586422e4640ae48504011029D>
53dc9de016bb6fc2c1a005c20044580f8d5de2f99f77df7527b054e08cb02e1eD=
ba3679dbdaf62ecae1a485bd198e4127a1c7605fffa6492fb32ed97c97eff892D<
c13dc951f499e2d4af158a7e69ac636e75289d333b51e67cf3b6c1c3b573e7dfD;
553cb086c6ccc5df943b00d1342272a201f6f00d3833176eb02708135da3101eD:
27bc90124c2fa6f18a9edb3748c392b723f315a736b6b34038195625871ecf2bD9
abb495131866830ec1e5474b69876de363e44c471e7221b10ce992f1f526f966D8
4aea4b143d8173155f3ca2e53011c25de372518c46da064056b3507555cdc03a
A
hA#V	=8Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233U	8Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"TG8Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aScc8Peter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rRc8Peter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-[	Q8Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148Z	8Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298Y	%8Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240X	+8Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*W	K8Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240of
flrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|
7B
8I
9P
;V
<]
=d
>j
?q
@x
A~
B
C
D
E
F 
G&
H-
I4
J:
KA
LH
MN
NU
P\
Qb
Ri
Sp
Tv
U}
V
W

X
Y
Z
["
\(
]-
^4
_;
`?
aB
bG
cL
dQ
fV
g[
i_
jb
kg
lm
mr
nx
o}
p
q
r
s
t
u
v!
w&
x+
y/
z2
{7
|=
}B
~H
M
T
[
_
b
g
l
q
v
{








$
+
/
2
7
<
A
F
K
O
R
W
]
b
h
m
t
{








r'_Q9Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
^9Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+]Y9Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952J\9Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvWbcM9Peter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QacA9Peter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V`/9Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+gK:Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$f=:Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"eG9Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987adcc9Peter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcc9Peter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2gmw[:Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zly:Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.kQ:Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148j:Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298i%:Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240h+:Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#r	=;Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233q	;Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"pG;Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987goyY:Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733ny7:Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZyxw;Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-w	Q;Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148v	;Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298u	%;Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240t	+;Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*s	K;Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!}%<Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240|+<Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+{K<Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$z=<Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233fyu[;Robbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93%=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240gyY<Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733y7<Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gw[<Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zy<Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.Q<Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148~<Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9Ew=Nicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460g
yY=Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733	y7=Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gw[=Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zy=Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.Q=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'Q>Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
>Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213k
wc=Nicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~w=Nicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvWcM>Peter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QcA>Peter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V/>Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#	=>Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233	>Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"G>Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987acc>Peter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rc>Peter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%	?Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"G?Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987acc?Peter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rc?Peter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705WcM?Peter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`!	?Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298 	%?Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+?Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*	K?Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#	=?Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#&	=@Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233%	@Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"$G@Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a#cc@Peter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r"c@Peter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-+	Q@Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148*	@Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298)	%@Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240(	+@Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*'	K@Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'/QAJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
.AJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+-YAJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952J,AJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvW2cMAPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Q1cAAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V0/AJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+7KBJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$6=BJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"5GAJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a4ccAPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r3cAPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2g=w[BRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z<yBRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.;QBJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148:BJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#17592989%BJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#18922408+BJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#B	=CJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233A	CJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"@GCJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987g?yYBRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733>y7BRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZyHwCRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-G	QCJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148F	CJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298E	%CJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240D	+CJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*C	KCJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!M%DJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240L+DJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+KKDJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$J=DJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233fIu[CRobbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93T%EJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240gSyYDRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733Ry7DRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gQw[DRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zPyDRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.OQDJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148NDJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298

er+V:eDQ
72b814596920effa935ebdde082d64181b5aa2f44485a058f2535c54828f931eDP
f85c959b9b36039c3d4707a5c1e73243be76f1191f9b467bae50a18a9612af31DO
660894a2c18d390472d0f133b53c845c1ecffde9327004870721603cd1f91b48DN
64a62730fee8363341816507f9171c57a6c6433b7c7418501dbfc6686c446190DM
31e074062d36f692f0ee2ec64a68e0193b540bf85cc09b3fd7a6f3384ab55806DL
121ae3d3bc314678d6d4591403f12a7aac992b4097837f5c93e9dfa346814e6bDK
92d5b94aea2121671cd099763736607349b3607d2d2e2e681811cd2f4c86ba88DJ
06444e0746003a76118ae6a9895e5592ab3c18c2bf85ab614b50a43dd56980b9DI
ccaed81377566681009e212ad6067bf7a462c3a7df25aa078d71854dc61496baDH
6fa281a1277a0474df3c2033953900cb085700242c41a44cda525992e8b7c5c6DG
51c06da7ce2ef116cd43474b64056e939ccb0ae0e6198dd907ee842fdc5005b9DF
ba8057e4e0424cbc1521c650fa3a07edba34cbd8e90391f5273ce5c22d55e305DE
445eab0d09b92ba9a49ba8c3bfd3c3eee915acfbb0d71c89b249baf899d7fcb2
Em>9E[wENicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460gZyYERobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733Yy7ERobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gXw[ERobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zWyERobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.VQEJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148UEJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'_QFJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
^FJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213k]wcENicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~\wENicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvWbcMFPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QacAFPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V`/FJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#g	=FJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233f	FJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"eGFJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987adccFPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rccFPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%l	GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"kGGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987ajccGPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705ricGPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705WhcMGPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`q	GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298p	%GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240o	+GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*n	KGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#m	=GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#v	=HJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233u	HJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"tGHJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987asccHPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rrcHPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-{	QHJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148z	HJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298y	%HJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240x	+HJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*w	KHJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'QIJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
~IJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+}YIJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952J|IJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvWcMIPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QcAIPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V/IJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+KJJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$=JJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"GIJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987accIPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcIPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2g
w[JRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zyJRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.QJJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148
JJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%JJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240+JJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#	=KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GKJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987gyYJRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733y7JRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZywKRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-	QKJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*	KKJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!%LJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240+LJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+KLJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$=LJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233fu[KRobbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93$%MJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240g#yYLRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733"y7LRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g!w[LRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z yLRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.QLJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148LJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9E+wMNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460g*yYMRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733)y7MRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g(w[MRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z'yMRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.&QMJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148%MJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'/QNJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
.NJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213k-wcMNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~,wMNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvW2cMNPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Q1cANPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V0/NJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#7	=NJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-202336	NJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"5GNJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a4ccNPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r3cNPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%<	OJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240";GOJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a:ccOPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r9cOPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705W8cMOPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`A	OJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298@	%OJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240?	+OJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*>	KOJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#=	=OJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#F	=PJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233E	PJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"DGPJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aCccPPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rBcPPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-K	QPJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148J	PJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298I	%PJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240H	+PJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*G	KPJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'OQQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
NQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+MYQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952JLQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvWRcMQPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QQcAQPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311VP/QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+WKRJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$V=RJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"UGQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aTccQPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rScQPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705

er+V:eD^
9cd2077252d68212f08dd81f3353a8d296b4983fd631071221ad12978b80e2d3D]
fa40075494cdb791de80bb9dd16a60c61c5e4200559523fc4cb22ded671eda5aD\
9df3dd0592a54ada722f373efb2ba882dada990b05e08814608a1d5fb236de64D[
1b5fd99f401b83a160bcf8506fd135056203e2df730c72f49440fe457a1ec20eDZ
3d0d4dbcbdb1f804aa9e133124ebb735a5037654221d45f8e93d4e81c3cc2f75DY
ce893faa55582d8281001d9876f4ceaddca9de5adf25f32692196a6e85a1aa48DX
4c3662507f01c062009127bb3ab45ab19236e6dcc70fe08ca363713b45cf9229DW
fede7faa428def30a78d440b2dfd020e0a972bca7601dbd552274dc2f98434c9DV
c03ba838a367a50725a5bad5793e263d9c1c7d7e962a29cd8e0b093cf5a0056dDU
c30d6ca286d3a7294da3e5596cf791d5c1314667173d02f21d751e689e05d52bDT
2543d29db08633a435d64df84ea00c6bdfb481a55fd6621a7e31190ab94c1ddfDS
783b344765a19ddce5583dff7a5df7639ac3de2a002a21d71a0528d6aaae8258DR
d80f9a89dac504f4ac37f8ea511d7ea892e9a02e191b8bf374506a66f6ff3395
a2g]w[RRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z\yRRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.[QRJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148ZRJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298Y%RJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240X+RJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#b	=SJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233a	SJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"`GSJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987g_yYRRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733^y7RRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZyhwSRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-g	QSJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148f	SJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298e	%SJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240d	+SJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*c	KSJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!m%TJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240l+TJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+kKTJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$j=TJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233fiu[SRobbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93t%UJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240gsyYTRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733ry7TRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gqw[TRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zpyTRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.oQTJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148nTJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9E{wUNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460gzyYURobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733yy7URobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gxw[URobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zwyURobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.vQUJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148uUJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'QVJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
~VJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213k}wcUNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~|wUNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvWcMVPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QcAVPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V/VJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#	=VJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233	VJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GVJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987accVPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcVPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%	WJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GWJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a
ccWPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r	cWPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705WcMWPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`	WJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%WJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+WJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*	KWJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#
	=WJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#	=XJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233	XJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GXJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987accXPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcXPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-	QXJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148	XJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%XJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+XJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*	KXJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'QYJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
YJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+YYJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952JYJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvW"cMYPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Q!cAYPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V /YJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+'KZJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$&=ZJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"%GYJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a$ccYPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r#cYPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2g-w[ZRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z,yZRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.+QZJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148*ZJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298)%ZJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240(+ZJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#2	=[Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-202331	[Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"0G[Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987g/yYZRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733.y7ZRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZy8w[Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-7	Q[Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#19421486	[Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#17592985	%[Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#18922404	+[Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*3	K[Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!=%\Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240<+\Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+;K\Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$:=\Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233f9u[[Robbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93D%]Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240gCyY\Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733By7\Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gAw[\Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z@y\Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.?Q\Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148>\Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9EKw]Nicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460gJyY]Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733Iy7]Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gHw[]Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zGy]Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.FQ]Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148E]Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'OQ^Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
N^Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213kMwc]Nicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~Lw]Nicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvWRcM^Peter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QQcA^Peter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311VP/^Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#W	=^Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233V	^Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"UG^Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aTcc^Peter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rSc^Peter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705

er+V:eDk
7999b3417dab3aca80a1f8a57c6a7b9f98efab7f9c530e0131e8ee2cbd026459Dj
42ea2b85b1cebb4239ade45fc36a1b309a29b95be50d26bf314165428aeb66acDi
f659cc4a3ded31fe85ee2123860696b26f1983182f66c76b6a76d0e5dc5f3d2fDh
035b347d3201307242fcde833202a8aa1505b93cbfed75f9f4aa400f16f19cefDg
c4c001caa89f5bff6fb1c4dbee4050dbbb93bd7c79c16d2c309103992c0b7987Df
104ab2ef65171e91197d612304922a2a41a03bb8e9cbd65666f2899ffca2d489De
6629074551d9fb3315ab487254009bfbf5ff68dc9d1c73b4aa5c866e5448129cDd
eeb0a2f82f3dc57694d35b3eaf181212193a3ecdcce63837ee1d869a138901d0Dc
1ffc8e6c986e1cc0d0bec287cc7ad4bbb77cd0ccc1bcb147a4d5be35dbe062eaDb
311a90d5eda02bf4ce86639848bc226ee6a17f1a66b1f15375a48b77a3d6b9acDa
5d260748ee7254fcf65c3e3312e541e2f9883d21279926f45ee85ad44eb5b4e7D`
7709c0d2acd7ad42cb32f7de9cac262193958bda0a1f863ea37484f52147282aD_
62597c6811ab1a4372c93868c223a056ac2947a911f6b318ab3df4ead1b06de3
%/%\	_Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"[G_Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aZcc_Peter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rYc_Peter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705WXcM_Peter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`a	_Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298`	%_Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240_	+_Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*^	K_Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#]	=_Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#f	=`Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233e	`Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"dG`Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987accc`Peter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rbc`Peter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-k	Q`Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148j	`Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298i	%`Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240h	+`Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*g	K`Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'oQaJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
naJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+mYaJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952JlaJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvWrcMaPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QqcAaPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Vp/aJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+wKbJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$v=bJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"uGaJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987atccaPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rscaPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2g}w[bRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z|ybRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.{QbJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148zbJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298y%bJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240x+bJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#	=cJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233	cJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GcJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987gyYbRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733~y7bRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZywcRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-	QcJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148	cJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%cJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+cJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*	KcJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!
%dJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240+dJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+KdJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$
=dJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233f	u[cRobbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93%eJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240gyYdRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733y7dRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gw[dRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zydRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.QdJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148dJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9EweNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460gyYeRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733y7eRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gw[eRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zyeRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.QeJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148eJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'QfJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
fJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213kwceNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~weNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvW"cMfPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Q!cAfPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V /fJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#'	=fJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233&	fJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"%GfJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a$ccfPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r#cfPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%,	gJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"+GgJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a*ccgPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r)cgPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705W(cMgPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`1	gJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#17592980	%gJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240/	+gJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*.	KgJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#-	=gJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#6	=hJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-202335	hJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"4GhJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a3cchPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r2chPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-;	QhJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148:	hJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#17592989	%hJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#18922408	+hJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*7	KhJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'?QiJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
>iJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+=YiJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952J<iJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvWBcMiPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QAcAiPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V@/iJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+GKjJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$F=jJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"EGiJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aDcciPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rCciPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2gMw[jRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zLyjRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.KQjJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148JjJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298I%jJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240H+jJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#R	=kJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233Q	kJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"PGkJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987gOyYjRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733Ny7jRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZyXwkRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-W	QkJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148V	kJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298U	%kJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240T	+kJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*S	KkJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!]%lJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240\+lJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+[KlJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$Z=lJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233fYu[kRobbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860

er+V:eDx
ee54ecaecccdbbb8de156e19a27d770e04d61778a19ef2dc30478b7fcfe65865Dw
664f64a4a6b87e761d7b0bc0efba577178e77a23ec390ffb222b9caee6c3206aDv
557d4fb63564285a746012864ee4fa67be9d0f1756df5771b7f9380de46393c5Du
61afac8f37a4ea3ff4615ff2c44e669f884f9d092a45699fc0fd2dcac09465d8Dt
82932d0635147c1a6bbad3358a167d3e6f1a59a1ee3cce64d41ef8729a3f2993Ds
ebce0b46fb13981f4746adf603b6f96c83356c88ae4ed0053fdb5b506fbb97b1Dr
63c3055a3e9d4079dcbfedfed3e049509ed10bdc0f3de7959902ff8cfcec5e9fDq
05a40b72da0cf303bc79e3b58cda8c7f7edb3f19a201eca57225af9a1e012bebDp
c7a38de9170db3ea671c715e4f878f1c3731c4a067bcb77c2c9827c8cd02d694Do
1a506ab0d1bb5fe446384f454d2e3cccb4d626df0d87e0effd61680d6a9d026bDn
e769db0a6566751d86087f44601cb2aedbda527c4a514beaa8e8a1f4a9d2d02eDm
bcebc5d5ae20b6fbf0a5f35a2831414d8ad7aa1ea1720883560416fbd5db15b7Dl
a4e5c86a1cca9f1fc22a2b9ee7b057a8c3cf9a4e26ee74373e8878ad6288731a
3m>93d%mJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240gcyYlRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733by7lRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gaw[lRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z`ylRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860._QlJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148^lJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9EkwmNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460gjyYmRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733iy7mRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733ghw[mRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zgymRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.fQmJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148emJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'oQnJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
nnJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213kmwcmNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~lwmNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvWrcMnPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QqcAnPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Vp/nJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#w	=nJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233v	nJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"uGnJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987atccnPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rscnPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%|	oJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"{GoJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987azccoPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rycoPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705WxcMoPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`	oJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%oJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+oJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*~	KoJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#}	=oJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#	=pJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233	pJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GpJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987accpPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcpPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-	QpJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148
	pJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298		%pJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+pJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*	KpJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240of!flrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|
'
-
2
8
=
D
K
O
R
W
\
a
f
k
o
r
w
}







"
'
,
1
6
;
?
B
G
M
R
X
]
d
k
o
r
w
|







"
(
-
4
;
?
B
G
L
Q
V
[
_
b
g
m
r
x
}






!
&
+
/27=BHMT[_
bgl
qv{
$+/27<AFK O
r'QqJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
qJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+
YqJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952JqJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvWcMqPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QcAqPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V/qJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+KrJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$=rJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"GqJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987accqPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcqPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2gw[rRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zyrRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.QrJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148rJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298%rJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240+rJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#"	=sJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233!	sJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240" GsJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987gyYrRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733y7rRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZy(wsRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-'	QsJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148&	sJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298%	%sJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240$	+sJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*#	KsJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!-%tJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240,+tJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240++KtJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$*=tJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233f)u[sRobbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>934%uJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240g3yYtRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-287332y7tRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g1w[tRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z0ytRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860./QtJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148.tJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9E;wuNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460g:yYuRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-287339y7uRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g8w[uRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z7yuRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.6QuJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#19421485uJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'?QvJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
>vJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213k=wcuNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~<wuNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvWBcMvPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QAcAvPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V@/vJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#G	=vJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233F	vJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"EGvJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aDccvPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rCcvPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%L	wJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"KGwJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aJccwPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rIcwPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705WHcMwPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`Q	wJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298P	%wJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240O	+wJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*N	KwJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#M	=wJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#V	=xJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233U	xJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"TGxJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aSccxPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rRcxPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-[	QxJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148Z	xJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298Y	%xJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240X	+xJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*W	KxJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240

er+V:eD
e319773b66bb4f0227b1608807845710d392639797e4f0e6714024b71cb7b1f7D
56b6f928a45667b9da2599adf7728717580afc5e3ce24bbe5dfa41d4e9881447D
648913500d3bbad2fc637cb3b8d8bfeafa3a89bbf0fb33504657bab719b25763D
bd9209ce7471aae3638a5d0464764e35ae7dd88dd1526747997c8bbec7ceb786D
bd55b6e53bef2770d4702bf6fb6bcd13145e761a809da1a07423a7e1e3898f82D
de291c1622d5eebba6a97c0060a631087ecd9651815e7294c243b6f31e580508D
ec3383b51ed106826513f9c2945df6ff25b528b122a9b848b069c9e8d6cb5e46D~
b929a42b8d0177a7813b33484e7fc53ee017c678c48081d067dcde010be775d9D}
70d313100de0a9a28bad9868e3267b01f56634e7b633d7519f3153020d8c77b7D|
82b2eaccefb7228d0de8dd9a88417b5a3b5cd4911bacf3931b092c0c35f16e7aD{
88e98b9e84008f81960ec7ef7833a591eded866cb407e6fef47c13d1ecb21d53Dz
8ee9327d2fb76742bd611491c6f916eebd397da0976737f7b48eec36a25080b9Dy
f2ef03a6ec5037c50e7f13a6a7c2465e14b247e48ec9b158e91bbf86094e3dd1
r'_QyJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
^yJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+]YyJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952J\yJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvWbcMyPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QacAyPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V`/yJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+gKzJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$f=zJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"eGyJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987adccyPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rccyPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2gmw[zRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zlyzRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.kQzJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148jzJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298i%zJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240h+zJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#r	={Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233q	{Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"pG{Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987goyYzRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733ny7zRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZyxw{Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-w	Q{Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148v	{Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298u	%{Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240t	+{Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*s	K{Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!}%|Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240|+|Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+{K|Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$z=|Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233fyu[{Robbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93%}Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240gyY|Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733y7|Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gw[|Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zy|Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.Q|Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148~|Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9Ew}Nicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460g
yY}Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733	y7}Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gw[}Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zy}Robbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.Q}Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148}Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'Q~Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
~Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213k
wc}Nicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~w}Nicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvWcM~Peter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QcA~Peter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V/~Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#	=~Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233	~Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"G~Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987acc~Peter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rc~Peter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987accPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705WcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`!	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298 	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#&	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233%	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"$GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a#ccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r"cPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-+	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148*	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298)	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240(	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*'	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'/QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
.Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+-YJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952J,Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvW2cMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Q1cAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V0/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+7KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$6=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"5GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a4ccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r3cPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2g=w[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z<yRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.;QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148:Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#17592989%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#18922408+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#B	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233A	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"@GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987g?yYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733>y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZyHwRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-G	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148F	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298E	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240D	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*C	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!M%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240L+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+KKJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$J=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233fIu[Robbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93T%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240gSyYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733Ry7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gQw[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zPyRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.OQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148NJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9E[wNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460gZyYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733Yy7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gXw[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zWyRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.VQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148UJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'_QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
^Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213k]wcNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~\wNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460

er+V:eD
36aad460808510bfa2e38f113711d7d1b1ec88d77ddb1badbedd8829e5c8dd02D
456aa067cc96e03aaa605e52a86cc973f7a8dab09337cce112097a4608dd143aD
c4bb36e81ea1d28a9b054d4a06f11d8ff53cc6d3f1e8523504685e0998b38dd6D
27bf800e475fe735de26f8983bba34eab9261ed1b48593690d77e5bc7d0acde1D
93a54cb9f013c14a0d42bbb9abed4ec7186612d1288e74148ff8fa20ccc973a6D

2445bee7e1332244f8b40961bfe9f59880197fd2e4ea9800c0b288239d229acbD
6c1525a5d4f0e9045c028f3d1abe0c4e7e9aa2e3216a1472b79d3f60b02d135dD
e0b87fa8a61f451d3299d6569707241d3342eab4af1de892fd6bf8e03d5551d8D

4bb74807b09db308a56c244e21970f4698de871955175c9b552234229de92f91D	
dc1039bae026e06f606e2a26e159743f3cf3ed19a75609cb5664372c17b4d90cD
4011ecba5e1b135d1f741f84948ead212a82a060f0cf75bab01b2a37fdd319c0D
504528b2f64bf9e246a93ff851b9fbf624d77355d1d57587ae1acaa4522c8fcbD
fa679cc7ff7900d485618ebb16638390e1b2e4a43f1278263dc8722680e307ab
v&QvWbcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QacAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V`/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#g	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233f	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"eGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987adccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rccPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%l	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"kGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987ajccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705ricPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705WhcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`q	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298p	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240o	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*n	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#m	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#v	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233u	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"tGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987asccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rrcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-{	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148z	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298y	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240x	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*w	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
~Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+}YJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952J|Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvWcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QcAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987accPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2g
w[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zyRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148
Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987gyYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZywRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233fu[Robbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93$%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240g#yYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733"y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g!w[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z yRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9E+wNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460g*yYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733)y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g(w[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z'yRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.&QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'/QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
.Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213k-wcNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~,wNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvW2cMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Q1cAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V0/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#7	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-202336	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"5GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a4ccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r3cPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%<	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240";GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a:ccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r9cPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705W8cMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`A	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298@	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240?	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*>	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#=	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#F	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233E	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"DGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aCccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rBcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-K	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148J	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298I	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240H	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*G	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'OQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
NJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+MYJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952JLJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvWRcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QQcAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311VP/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+WKJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$V=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"UGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aTccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rScPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2g]w[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z\yRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.[QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148ZJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298Y%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240X+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#b	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233a	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"`GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987g_yYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733^y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733

er+V:eD
81c536f389863d868ed8bc21eae1b2225ce8631429c5df133d0e769c3f340f77D
324c9d5ad49eb48866d128a022079508c40c45aa4d4176abc382f606369448d0D
7179cfedeaf917db1ff4e9e2c9261746c977c39ff98d06e7bed342cca2633c45D
9eb8a6c91f46c6b191c972052582bf84913f5b8b77d733b9a22599022ce86a8bD
20d48e214a59a2848b7152ea8c378eda0ab10d93902bef3627ec70603b8ad96fD
1b94bec42529799dff727dd6082c4b038c96227041b81d95f21ee5457cb4c089D
4ed29d175fb03385533dbaacc9824611743ebcc84d3ce5fa6f376a5568058d49D
9a5aad884099ccb669c4d020f69ddfec584bec4cb676f93818cd67346ee348d0D
7d9adf9e27536faf7c726121ff0e58d8a0d0c473168713c55c95d74da74c2ebfD
938086442b2d90233bb54c18a12a65965685e408b96dafa4e36c18a4179676dfD
0d89f6cb70bf9117dfd174a86c11de319ac44c664effcaa3b959f00d436ae1a2D
92dc223c986a6952b0510b50be70d54b8def042975f883b9a1ecb8d0f62a138bD
f566582c4354cf859dbaad8604aeac5c8344f7e81c02de69fe4124ea1537501c
ZRZyhwRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-g	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148f	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298e	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240d	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*c	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
4h94oy7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gnw[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zmyRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.lQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148kJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298j%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240fiu[Robbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
'uQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
tJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213kswcNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~rwNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460qwNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460gpyYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733
v&QvWxcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QwcAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Vv/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#}	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233|	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"{GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987azccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rycPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987accPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705W~cMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"
GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a	ccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*
	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+YJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952JJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvWcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QcAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987accPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2g#w[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z"yRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.!QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148 Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#(	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233'	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"&GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987g%yYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733$y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZy.wRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860--	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148,	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298+	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240*	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*)	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!3%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#18922402+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+1KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$0=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233f/u[Robbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93:%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240g9yYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-287338y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g7w[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z6yRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.5QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#19421484Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9EAwNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460g@yYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733?y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g>w[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z=yRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.<QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148;Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'EQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
DJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213kCwcNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~BwNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvWHcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QGcAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311VF/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#M	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233L	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"KGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aJccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rIcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%R	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"QGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aPccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rOcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705WNcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`W	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298V	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240U	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*T	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#S	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#\	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233[	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"ZGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aYccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rXcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-a	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148`	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298_	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240^	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*]	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240

er+V:eD,
7ed3fc20ba01570a826ffa2af023ade0d8581765238cc534b73fe6e9508c4bebD+
6a3415f454a536cd4bddf7dbc03ff8c17e3484e1d6e9df356fd2660f6f7a96b3D*
2e5c474731992282d7faabe7c8d55f7253fbce05507a987f3bd332681c4e839cD)
97484ec3860cbfbbd5c2af0639469ee8d66a3f43238adbf11b9b14a0c86c978aD(
37726d4a426ccbdf697e55aa4f02f394d32283a3df6de51d99714a596409ae64D'
e446b1822c2b1f232e747d463041aa38f581221d371740705042a6966578d818D&
87c30f42a079f461de618eaafd1eeb3225bf684cb0b4fe11da401f0550be3c80D%
3cd32436440b9a64a4f9971f907fba98209aeed82000b3d7441689e93ed58cb6D$
6765ca1b27d1b3812e3c6442a00515395c3887ebcddeefb849912f45c005c54eD#
3ea9a16edeb166326b2db578b5d4fbc8f9700179808b798dd4c33c6f0d273beaD"
573cc1166190452dbe3b43b1be7bef29a1ffa0ed9f8dbfd29b063674c60834d3D!
78d3877b596cc832e4549e218cae35c884640fcb1d8e5764ee09a774a110fb45D 
b301b3885fb4d5b57bd90b729ff75d74dc31e2f35a8ae3b5efa64901202f1497
r'eQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
dJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+cYJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952JbJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvWhcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QgcAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Vf/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+mKJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$l=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"kGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987ajccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705ricPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2gsw[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zryRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.qQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148pJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298o%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240n+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#x	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233w	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"vGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987guyYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733ty7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZy~wRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-}	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148|	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298{	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240z	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*y	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233fu[Robbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93
%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240g	yYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gw[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zyRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9EwNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460gyYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gw[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z
yRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213kwcNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~wNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvWcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QcAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987accPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%"	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"!GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a ccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705WcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`'	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298&	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240%	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*$	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240##	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#,	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233+	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"*GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a)ccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r(cPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-1	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#19421480	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298/	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240.	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*-	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'5QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
4Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+3YJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952J2Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvW8cMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Q7cAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V6/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765offlrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|"W#]$b&h'o(u)x*}+,-./012#3(4.536:7A8E9H:M;R<W=\>a@eAhBmCsDxE~FG
HIJKL"M'N,O1P5Q8S=TCUHVNWSXZYaZe\h]m^r_w`|abcd
efgh#i*j1k5l8m=nBoGpLqQrUsXt]ucvhxnyszz{|}~
!%(/7>FMU\dkrz	'
)
)+=KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$<=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233";GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a:ccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r9cPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2gCw[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zByRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.AQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148@Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298?%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240>+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#H	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233G	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"FGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987gEyYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733Dy7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZyNwRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-M	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148L	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298K	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240J	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*I	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!S%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240R+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+QKJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$P=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233fOu[Robbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93Z%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240gYyYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733Xy7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gWw[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zVyRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.UQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148TJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9EawNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460g`yYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733_y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g^w[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z]yRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.\QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148[Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'eQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
dJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213kcwcNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~bwNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460

er+V:eD9
63a16686d243cda459362fe273e2bf3e64a84899038415039c265f34388b8257D8
0eb359490eab964f970cb8d6fd9987a38a3e3f9c585348941c53fb1b709c71f1D7
a4dd90b3a38f048451db9452be71e7a4b4d0cfa945c1fb18335881ddf88355f3D6
f020458306c1798b97bbe293da7347160996bd9a1e89d548f4012bde28cc4a52D5
86614c497d063d072a270460ce1367ee6647bfa57eb10ec1f02b27e267bfff67D4
4c61a98e630cf29009706ab099ff7870c3593c7eb39e9d0edb5e059359012e52D3
b4fb6c1de92fa5a737add5cf91cb77255e46b3c6bd53cb56fb0440dba5b32f9dD2
00608301be4450298d9a4f75fc3a36ab657c6083731a7fe1510fb0044564bb52D1
81c248f72126ea7b1e33a7f47a8133ab505675f4db87438422eb0a47bb6f2bf0D0
82bf486bffe227eaa4681fdcf6cb4c2225d25b5dbdad8b4009f3da4a506834efD/
6457ba14ffee5554b41e56b32c8a9f8c2873e5ebe04d17cbb12e0e3e6edd3933D.
201819cd83614093dbe14240fec542722aadee2886e13b2006ee8f6f0c063950D-
bbc7199164da8d3b64fe85a385ca152120db612e702d3318ac67877b9c25e534
v&QvWhcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QgcAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Vf/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#m	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233l	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"kGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987ajccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705ricPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%r	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"qGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987apccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rocPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705WncMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`w	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298v	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240u	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*t	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#s	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#|	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233{	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"zGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987ayccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rxcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240~	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*}	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+YJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952JJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvWcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QcAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+
KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a
ccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r	cPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2gw[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zyRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987gyYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733
ZRZywRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!#%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240"+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+!KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$ =Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233fu[Robbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93*%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240g)yYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733(y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g'w[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z&yRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.%QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148$Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9E1wNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460g0yYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733/y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g.w[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z-yRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.,QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'5QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
4Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213k3wcNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~2wNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvW8cMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Q7cAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V6/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#=	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233<	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240";GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a:ccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r9cPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%B	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"AGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a@ccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r?cPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705W>cMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`G	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298F	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240E	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*D	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#C	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#L	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233K	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"JGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aIccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rHcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-Q	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148P	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298O	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240N	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*M	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'UQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
TJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+SYJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952JRJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvWXcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QWcAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311VV/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
)
)+]KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$\=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233"[GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987aZccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rYcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
a2gcw[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zbyRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.aQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148`Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298_%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240^+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240
eU#h	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233g	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"fGJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987geyYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733dy7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733

er+V:eDF
53f42f617e8184218d75676860dfcd10bd810905d61d6d241b88ff372c208b42DE
3704909dce1c80a6e3fa47ea59c51797dbe73c34511a242cf1e0756e078fba23DD
d9821c48f2918944061117f3ab8c87a78a29d2649124aeb7f47f886ec7903dd6DC
251baa632d0d33e46681b76fba3f93cc9ea07b9084a6dbc7bb018c50a1abb9b1DB
13c2180392f13ede0d3e45cf8895eb123d78ede2ff65fcaf4c05232a7cba595bDA
dfe598bbcefc64fd6bb542cf6d1966fef6a3995e68fa2b6cc2ed34220ca65ee8D@
c0e72c1dbf2c72f272577dc891736d1403dd928b5e9f236721ea261f99677b61D?
1e1c43fd5f02a819df67f4ea70bbc1d3725d96664de7ae2da966f9456b5ececfD>
dfcf30fce1599be0699955042c34db80273d1dc14cc38af5a8f91b02ab70060bD=
40778cececacdc153601f3e0bdde3c295376d9e7a17eef328a28fd1f1d7e2f2eD<
c67c4c4063b74aae72efd079229bf2ca2167a39844fe319e3e726d3df81c4767D;
764b6da4f9a89bd034bdb5f3c7e3d13f7fcd081d64b01ef179ecd51b31ec0e20D:
82d9617a439490782837e05a5e05310b0748f064a0556d264fbc615afd85671b
ZRZynwRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.e7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860-m	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148l	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298k	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240j	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*i	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
o!s%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240r+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240+qKJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240$p=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233fou[Robbie Harwood <rharwood@redhat.com> - 2.02-087.e7.9bB- Bump for signing
- Resolves: #1892860
3m>93z%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240gyyYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733xy7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733gww[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860zvyRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.uQJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148tJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
Em>9EwNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.12e- Font CVE fixes and bump SBAT (CVE-2022-2601)
- Resolves: RHEL-23460gyYRobbie Harwood <rharwood@redhat.com> - 2.02-087.el7.11ct- Bump sbat
- Resolves: CVE-2022-28733y7Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.10c#- Backport the relevant CVE fixes from the 2022-05-24 drop
- Resolves: CVE-2022-28733g~w[Robbie Harwood <rharwood@redhat.com> - 2.02-087.el7.9bB- Bump for signing
- Resolves: #1892860z}yRobbie Harwood <rharwood@redhat.com> - 2.02-0.87.el7.8b(- Fix accidental reboot in grub_exit
- Resolves: #1892860.|QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148{Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.el7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298
'QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213kwcNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.14e- Rebuild for signing
- Related: RHEL-23460~wNicolas Frayer <nfrayer@redhat.com> - 2.02-087.el7.13e6@- safemath: add grub_cast for gcc < 5.1
- Related: RHEL-23460
v&QvWcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311QcAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
A
hA#
	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a
ccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r	cPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
%/%	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987accPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705WcMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
`+`	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240#	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233
A
hA#	=Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.2`8- Fix another batch of CVEs
  Resolves: CVE-2020-14372
  Resolves: CVE-2020-25632
  Resolves: CVE-2020-25647
  Resolves: CVE-2020-27749
  Resolves: CVE-2020-27779
  Resolves: CVE-2021-20225
  Resolves: CVE-2021-20233	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.1_- Fix keyboards that report IBM PC AT scan codes
  Resolves: rhbz#1892240"GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987accPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705rcPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
R-!	QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.7`Z- Fix boot failures in ppc64le caused by storage race condition (diegodo)
  Resolves: rhbz#1942148 	Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.6`B@- Fix ppc64le performance issues (diegodo)
  Resolves: rhbz#1759298	%Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.5`@- Add the at keyboard patches that weren't included
  Resolves: rhbz#1892240	+Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.4`@- add keylayouts and at_keyboard modules to EFI binary
  Resolves: rhbz#1892240*	KJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87.e7.3`?z@- at_keyboard: use set 1 when keyboard is in Translate mode (rmetrich)
  Resolves: rhbz#1892240
r'%QJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.81]{- Only make grub2-tools Obsoletes and Provides grub2-tools-efi for x86_64
  Resolves: rhbz#1748019
$Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.80\e- Rebuild with correct build target for signing
  Resolves: rhbz#1693213+#YJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.79\@- Ignore the modification time when doing RPM verification of /boot/efi files
  Resolves: rhbz#1496952J"Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.78\+@- Prevent errors from diskfilter scan of removable drives
  Resolves: rhbz#1446418
- Avoid grub2-efi package to overwrite existing /boot/grub2/grubenv file
  Resolves: rhbz#1497918
- Remove glibc32 and glibc-static(x86-32) BuildRequires
  Resolves: rhbz#1614259
v&QvW(cMPeter Jones <pjones@redhat.com> - 2.02-0.84_p@- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311Q'cAPeter Jones <pjones@redhat.com> - 2.02-0.83_@- Fix several CVEs:
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311V&/Javier Martinez Canillas <javierm@redhat.com> - 2.02-0.82^x- Prepend prefix when HTTP path is relative
- efi/http: Export {fw,http}_path variables to make them global
  Resolves: rhbz#1616395
- efi/http: Enclose literal IPv6 addresses in square brackets
- efi/net: Allow to specify a port number in addresses
- efi/ip4_config: Improve check to detect literal IPv6 addresses
- efi/net: Print a debug message if parsing the address fails
  Resolves: rhbz#1732765
#
#l/guRobbie Harwood <rharwood@redhat.com> 0.7.0-24\@- Add a safety timeout to epoll
- Resolves: #1687899y.g
Robbie Harwood <rharwood@redhat.com> 0.7.0-23\- Use pthread keys for thread local storage
- Resolves: #1618375q-gRobbie Harwood <rharwood@redhat.com> 0.7.0-22\- Add hack to support read-only root
- Resolves: #1542567{,gRobbie Harwood <rharwood@redhat.com> 0.7.0-21[o- Always choose highest requested debug level
- Resolves: #1505741"+GJavier Martinez Canillas <javierm@redhat.com> - 2.02-0.87_C- Fix TFTP timeouts when trying to fetch files larger than 65535 KiB
  Resolves: rhbz#1869987a*ccPeter Jones <pjones@redhat.com> - 2.02-0.86_- Fix a mis-merge
  Related: CVE-2020-15705r)cPeter Jones <pjones@redhat.com> - 2.02-0.85_- Couple more late fixes.
  Resolves: CVE-2020-10713
  Resolves: CVE-2020-14308
  Resolves: CVE-2020-14309
  Resolves: CVE-2020-14310
  Resolves: CVE-2020-14311
  Resolves: CVE-2020-15705
IurIQ7g?Colin Walters <walters@verbum.org> 0.10.23-16QU@- Drop PyXML BR (#914060)N6i7Bastien Nocera <bnocera@redhat.com> 0.10.23-15Q8@- Remove gmyth plugin5gRobbie Harwood <rharwood@redhat.com> 0.7.0-30`Z- Always free ciphertext data in gp_encrypt_buffer
- Resolves: #1887438w4g	Robbie Harwood <rharwood@redhat.com> 0.7.0-29^- Make syslog of call status configurable
- Resolves: #13734213g%Robbie Harwood <rharwood@redhat.com> 0.7.0-28]m- Fix double free of popt context when querying version
- Resolves: #17528102g+Robbie Harwood <rharwood@redhat.com> 0.7.0-27]5@- Update docs to reflect actual behavior of krb5_principal
- Resolves: #15530941gRobbie Harwood <rharwood@redhat.com> 0.7.0-26\Ɋ@- Avoid uninitialized free when allocating buffers
- Resolves: #1699331x0gRobbie Harwood <rharwood@redhat.com> 0.7.0-25\8- Fix explicit NULL deref on some enctypes
- Resolves: #1699331
^Kfn^i>imWim Taymans <wtaymans@redhat.com> - 0.10.23-23X- Rebuild with hardened flags
Resolves: #1420764 =iYWim Taymans <wtaymans@redhat.com> - 0.10.23-22XG- h264parse: Ensure codec_data has the required size when reading number of SPS
Resolves: rhbz#1400839"<i]Wim Taymans <wtaymans@redhat.com> - 0.10.23-21XF@- Remove insecure NSF plugin
- vmncdec: Sanity-check width/height before using it
Resolves: rhbz#1400839O;c?Daniel Mach <dmach@redhat.com> - 0.10.23-20RU- Mass rebuild 2014-01-24O:c?Daniel Mach <dmach@redhat.com> - 0.10.23-19Rk- Mass rebuild 2013-12-279g9Colin Walters <walters@verbum.org> 0.10.23-18Q@- Move soundtouch-devel BR to outside RHEL conditional, since
  it is available there.18g}Colin Walters <walters@verbum.org> 0.10.23-17QUA- Hack the gtk-doc to remove plugin docs that are not shipped
- Drop mythtv, opencv sources that are no longer buildable
Vi"Fi]Wim Taymans <wtaymans@redhat.com> - 0.10.23-21XF@- Remove insecure NSF plugin
- vmncdec: Sanity-check width/height before using it
Resolves: rhbz#1400839OEc?Daniel Mach <dmach@redhat.com> - 0.10.23-20RU- Mass rebuild 2014-01-24ODc?Daniel Mach <dmach@redhat.com> - 0.10.23-19Rk- Mass rebuild 2013-12-27Cg9Colin Walters <walters@verbum.org> 0.10.23-18Q@- Move soundtouch-devel BR to outside RHEL conditional, since
  it is available there.1Bg}Colin Walters <walters@verbum.org> 0.10.23-17QUA- Hack the gtk-doc to remove plugin docs that are not shipped
- Drop mythtv, opencv sources that are no longer buildableQAg?Colin Walters <walters@verbum.org> 0.10.23-16QU@- Drop PyXML BR (#914060)N@i7Bastien Nocera <bnocera@redhat.com> 0.10.23-15Q8@- Remove gmyth plugin&?ieWim Taymans <wtaymans@redhat.com> - 0.10.23-24ey- Patch CVE-2023-44446: MXF demuxer use-after-free
- Disable gtk-doc to fix the build
- Resolves: RHEL-16792
Y\FYMg9Colin Walters <walters@verbum.org> 0.10.23-18Q@- Move soundtouch-devel BR to outside RHEL conditional, since
  it is available there.1Lg}Colin Walters <walters@verbum.org> 0.10.23-17QUA- Hack the gtk-doc to remove plugin docs that are not shipped
- Drop mythtv, opencv sources that are no longer buildableQKg?Colin Walters <walters@verbum.org> 0.10.23-16QU@- Drop PyXML BR (#914060)NJi7Bastien Nocera <bnocera@redhat.com> 0.10.23-15Q8@- Remove gmyth plugin&IieWim Taymans <wtaymans@redhat.com> - 0.10.23-24ey- Patch CVE-2023-44446: MXF demuxer use-after-free
- Disable gtk-doc to fix the build
- Resolves: RHEL-16792iHimWim Taymans <wtaymans@redhat.com> - 0.10.23-23X- Rebuild with hardened flags
Resolves: #1420764 GiYWim Taymans <wtaymans@redhat.com> - 0.10.23-22XG- h264parse: Ensure codec_data has the required size when reading number of SPS
Resolves: rhbz#1400839
W\WQUg?Colin Walters <walters@verbum.org> 0.10.23-16QU@- Drop PyXML BR (#914060)NTi7Bastien Nocera <bnocera@redhat.com> 0.10.23-15Q8@- Remove gmyth plugin&SieWim Taymans <wtaymans@redhat.com> - 0.10.23-24ey- Patch CVE-2023-44446: MXF demuxer use-after-free
- Disable gtk-doc to fix the build
- Resolves: RHEL-16792iRimWim Taymans <wtaymans@redhat.com> - 0.10.23-23X- Rebuild with hardened flags
Resolves: #1420764 QiYWim Taymans <wtaymans@redhat.com> - 0.10.23-22XG- h264parse: Ensure codec_data has the required size when reading number of SPS
Resolves: rhbz#1400839"Pi]Wim Taymans <wtaymans@redhat.com> - 0.10.23-21XF@- Remove insecure NSF plugin
- vmncdec: Sanity-check width/height before using it
Resolves: rhbz#1400839OOc?Daniel Mach <dmach@redhat.com> - 0.10.23-20RU- Mass rebuild 2014-01-24ONc?Daniel Mach <dmach@redhat.com> - 0.10.23-19Rk- Mass rebuild 2013-12-27
^Kfn^i\imWim Taymans <wtaymans@redhat.com> - 0.10.23-23X- Rebuild with hardened flags
Resolves: #1420764 [iYWim Taymans <wtaymans@redhat.com> - 0.10.23-22XG- h264parse: Ensure codec_data has the required size when reading number of SPS
Resolves: rhbz#1400839"Zi]Wim Taymans <wtaymans@redhat.com> - 0.10.23-21XF@- Remove insecure NSF plugin
- vmncdec: Sanity-check width/height before using it
Resolves: rhbz#1400839OYc?Daniel Mach <dmach@redhat.com> - 0.10.23-20RU- Mass rebuild 2014-01-24OXc?Daniel Mach <dmach@redhat.com> - 0.10.23-19Rk- Mass rebuild 2013-12-27Wg9Colin Walters <walters@verbum.org> 0.10.23-18Q@- Move soundtouch-devel BR to outside RHEL conditional, since
  it is available there.1Vg}Colin Walters <walters@verbum.org> 0.10.23-17QUA- Hack the gtk-doc to remove plugin docs that are not shipped
- Drop mythtv, opencv sources that are no longer buildable
Vi"di]Wim Taymans <wtaymans@redhat.com> - 0.10.23-21XF@- Remove insecure NSF plugin
- vmncdec: Sanity-check width/height before using it
Resolves: rhbz#1400839Occ?Daniel Mach <dmach@redhat.com> - 0.10.23-20RU- Mass rebuild 2014-01-24Obc?Daniel Mach <dmach@redhat.com> - 0.10.23-19Rk- Mass rebuild 2013-12-27ag9Colin Walters <walters@verbum.org> 0.10.23-18Q@- Move soundtouch-devel BR to outside RHEL conditional, since
  it is available there.1`g}Colin Walters <walters@verbum.org> 0.10.23-17QUA- Hack the gtk-doc to remove plugin docs that are not shipped
- Drop mythtv, opencv sources that are no longer buildableQ_g?Colin Walters <walters@verbum.org> 0.10.23-16QU@- Drop PyXML BR (#914060)N^i7Bastien Nocera <bnocera@redhat.com> 0.10.23-15Q8@- Remove gmyth plugin&]ieWim Taymans <wtaymans@redhat.com> - 0.10.23-24ey- Patch CVE-2023-44446: MXF demuxer use-after-free
- Disable gtk-doc to fix the build
- Resolves: RHEL-16792
\FikcsWim Taymans <wtaymans@redhat.com> - 1.4.5-4WF@- rebuild for libdvdnav update
- Resolves: #1340047jc7Wim Taymans <wtaymans@redhat.com> - 1.4.5-3U- Update audiomixer unit test for big endian
- add missing patch
- Resolves: #1226909cicgWim Taymans <wtaymans@redhat.com> - 1.4.5-2U- Update ORC backup file
- Resolves: #1174403\hcYWim Taymans <wtaymans@redhat.com> - 1.4.5-1UQ@- Update to 1.4.5
- Resolves: #1174403&gieWim Taymans <wtaymans@redhat.com> - 0.10.23-24ey- Patch CVE-2023-44446: MXF demuxer use-after-free
- Disable gtk-doc to fix the build
- Resolves: RHEL-16792ifimWim Taymans <wtaymans@redhat.com> - 0.10.23-23X- Rebuild with hardened flags
Resolves: #1420764 eiYWim Taymans <wtaymans@redhat.com> - 0.10.23-22XG- h264parse: Ensure codec_data has the required size when reading number of SPS
Resolves: rhbz#1400839

er+V:eDS
62ccf282c2df0d4b0fb164fedda7d42b0e9be1966f8da03fdcebfb08cf4e5456DR
e6abdcee27c8de20b83368d087e14b888bef04262eb07ab80e58e528334e1a1cDQ
2468aa7b84cd02bdd3dadf04f5dd64bbffc5ae57ff7ef4a973bc74b29757bf6fDP
677cbb3bd9f4a461b86460be4a5a9ef23ab126d06907725c3ffe789009559936DO
73c486ff61695559ce4daae66d613f19b44873db66b308ac0f3d693c35e6bc5cDN
ce776b97b4d788033910fe00975ced115a86f293d3c25e4ef91029227b0d3a15DM
8ff288d2044bc096fa50399fcc642f5cb7c09ba23f131fb8b2386f6228076ff1DL
2aa040acfde2b250770d5a5742e1a2a67ac343654200b1286fcf39302661446cDK
99fafc8a49fe4f04b587c0c5dfb8876f9377969f4f143426ab749dc0f84a48a8DJ
0b299d62c2e3249e8aa1132f170b5b2eb81a8441f5fcb1b29f9970da5b40d33dDI
8819df992dd160364ba0aee29998326c7fce6c403594c9abe3dc7e8c293bea83DH
b6fa4027fc4b1885bba1e19874919c93e8cbaa34816975d67e07e866d7a53bf3DG
4e09aa7b08c80287291584ba0426ddf0d69699ff7e4f0bc6cc8e1a788e10bc57
yzU|y\rcYWim Taymans <wtaymans@redhat.com> - 1.4.5-1UQ@- Update to 1.4.5
- Resolves: #1174403 qe]Wim Taymans <wtaymans@redhat.com> - 1.10.4-4ey- Patch CVE-2023-44446: MXF demuxer use-after-free
- Disable gtk-doc to fix build
- Resolves: RHEL-16793ipeqWim Taymans <wtaymans@redhat.com> - 1.10.4-3Yd- Disable wayland sink plugin
- Resolves: #1488978joesWim Taymans <wtaymans@redhat.com> - 1.10.4-2XC- Disable plugins
- Fix origin
- Resolves: #1429587xne
Wim Taymans <wtaymans@redhat.com> - 1.10.4-1XO@- Update to 1.10.4
- Remove unbuilt plugins
- Resolves: #1429587&mckWim Taymans <wtaymans@redhat.com> - 1.4.5-6XG- Fix h264 and h265 buffer size checks
- Fix mpegts pat parsing and add more size checks
Resolves: rhbz#1400898lc#Wim Taymans <wtaymans@redhat.com> - 1.4.5-5XF@- vmncdec: Sanity-check width/height before using it
Resolves: rhbz#1400898

nizeqWim Taymans <wtaymans@redhat.com> - 1.10.4-3Yd- Disable wayland sink plugin
- Resolves: #1488978jyesWim Taymans <wtaymans@redhat.com> - 1.10.4-2XC- Disable plugins
- Fix origin
- Resolves: #1429587xxe
Wim Taymans <wtaymans@redhat.com> - 1.10.4-1XO@- Update to 1.10.4
- Remove unbuilt plugins
- Resolves: #1429587&wckWim Taymans <wtaymans@redhat.com> - 1.4.5-6XG- Fix h264 and h265 buffer size checks
- Fix mpegts pat parsing and add more size checks
Resolves: rhbz#1400898vc#Wim Taymans <wtaymans@redhat.com> - 1.4.5-5XF@- vmncdec: Sanity-check width/height before using it
Resolves: rhbz#1400898iucsWim Taymans <wtaymans@redhat.com> - 1.4.5-4WF@- rebuild for libdvdnav update
- Resolves: #1340047tc7Wim Taymans <wtaymans@redhat.com> - 1.4.5-3U- Update audiomixer unit test for big endian
- add missing patch
- Resolves: #1226909cscgWim Taymans <wtaymans@redhat.com> - 1.4.5-2U- Update ORC backup file
- Resolves: #1174403
k\k&ckWim Taymans <wtaymans@redhat.com> - 1.4.5-6XG- Fix h264 and h265 buffer size checks
- Fix mpegts pat parsing and add more size checks
Resolves: rhbz#1400898c#Wim Taymans <wtaymans@redhat.com> - 1.4.5-5XF@- vmncdec: Sanity-check width/height before using it
Resolves: rhbz#1400898icsWim Taymans <wtaymans@redhat.com> - 1.4.5-4WF@- rebuild for libdvdnav update
- Resolves: #1340047~c7Wim Taymans <wtaymans@redhat.com> - 1.4.5-3U- Update audiomixer unit test for big endian
- add missing patch
- Resolves: #1226909c}cgWim Taymans <wtaymans@redhat.com> - 1.4.5-2U- Update ORC backup file
- Resolves: #1174403\|cYWim Taymans <wtaymans@redhat.com> - 1.4.5-1UQ@- Update to 1.4.5
- Resolves: #1174403 {e]Wim Taymans <wtaymans@redhat.com> - 1.10.4-4ey- Patch CVE-2023-44446: MXF demuxer use-after-free
- Disable gtk-doc to fix build
- Resolves: RHEL-16793
GCGi	csWim Taymans <wtaymans@redhat.com> - 1.4.5-4WF@- rebuild for libdvdnav update
- Resolves: #1340047c7Wim Taymans <wtaymans@redhat.com> - 1.4.5-3U- Update audiomixer unit test for big endian
- add missing patch
- Resolves: #1226909ccgWim Taymans <wtaymans@redhat.com> - 1.4.5-2U- Update ORC backup file
- Resolves: #1174403\cYWim Taymans <wtaymans@redhat.com> - 1.4.5-1UQ@- Update to 1.4.5
- Resolves: #1174403 e]Wim Taymans <wtaymans@redhat.com> - 1.10.4-4ey- Patch CVE-2023-44446: MXF demuxer use-after-free
- Disable gtk-doc to fix build
- Resolves: RHEL-16793ieqWim Taymans <wtaymans@redhat.com> - 1.10.4-3Yd- Disable wayland sink plugin
- Resolves: #1488978jesWim Taymans <wtaymans@redhat.com> - 1.10.4-2XC- Disable plugins
- Fix origin
- Resolves: #1429587xe
Wim Taymans <wtaymans@redhat.com> - 1.10.4-1XO@- Update to 1.10.4
- Remove unbuilt plugins
- Resolves: #1429587
yzU|y\cYWim Taymans <wtaymans@redhat.com> - 1.4.5-1UQ@- Update to 1.4.5
- Resolves: #1174403 e]Wim Taymans <wtaymans@redhat.com> - 1.10.4-4ey- Patch CVE-2023-44446: MXF demuxer use-after-free
- Disable gtk-doc to fix build
- Resolves: RHEL-16793ieqWim Taymans <wtaymans@redhat.com> - 1.10.4-3Yd- Disable wayland sink plugin
- Resolves: #1488978j
esWim Taymans <wtaymans@redhat.com> - 1.10.4-2XC- Disable plugins
- Fix origin
- Resolves: #1429587xe
Wim Taymans <wtaymans@redhat.com> - 1.10.4-1XO@- Update to 1.10.4
- Remove unbuilt plugins
- Resolves: #1429587&ckWim Taymans <wtaymans@redhat.com> - 1.4.5-6XG- Fix h264 and h265 buffer size checks
- Fix mpegts pat parsing and add more size checks
Resolves: rhbz#1400898
c#Wim Taymans <wtaymans@redhat.com> - 1.4.5-5XF@- vmncdec: Sanity-check width/height before using it
Resolves: rhbz#1400898

nieqWim Taymans <wtaymans@redhat.com> - 1.10.4-3Yd- Disable wayland sink plugin
- Resolves: #1488978jesWim Taymans <wtaymans@redhat.com> - 1.10.4-2XC- Disable plugins
- Fix origin
- Resolves: #1429587xe
Wim Taymans <wtaymans@redhat.com> - 1.10.4-1XO@- Update to 1.10.4
- Remove unbuilt plugins
- Resolves: #1429587&ckWim Taymans <wtaymans@redhat.com> - 1.4.5-6XG- Fix h264 and h265 buffer size checks
- Fix mpegts pat parsing and add more size checks
Resolves: rhbz#1400898c#Wim Taymans <wtaymans@redhat.com> - 1.4.5-5XF@- vmncdec: Sanity-check width/height before using it
Resolves: rhbz#1400898icsWim Taymans <wtaymans@redhat.com> - 1.4.5-4WF@- rebuild for libdvdnav update
- Resolves: #1340047c7Wim Taymans <wtaymans@redhat.com> - 1.4.5-3U- Update audiomixer unit test for big endian
- add missing patch
- Resolves: #1226909ccgWim Taymans <wtaymans@redhat.com> - 1.4.5-2U- Update ORC backup file
- Resolves: #1174403
k\k&ckWim Taymans <wtaymans@redhat.com> - 1.4.5-6XG- Fix h264 and h265 buffer size checks
- Fix mpegts pat parsing and add more size checks
Resolves: rhbz#1400898c#Wim Taymans <wtaymans@redhat.com> - 1.4.5-5XF@- vmncdec: Sanity-check width/height before using it
Resolves: rhbz#1400898icsWim Taymans <wtaymans@redhat.com> - 1.4.5-4WF@- rebuild for libdvdnav update
- Resolves: #1340047c7Wim Taymans <wtaymans@redhat.com> - 1.4.5-3U- Update audiomixer unit test for big endian
- add missing patch
- Resolves: #1226909ccgWim Taymans <wtaymans@redhat.com> - 1.4.5-2U- Update ORC backup file
- Resolves: #1174403\cYWim Taymans <wtaymans@redhat.com> - 1.4.5-1UQ@- Update to 1.4.5
- Resolves: #1174403 e]Wim Taymans <wtaymans@redhat.com> - 1.10.4-4ey- Patch CVE-2023-44446: MXF demuxer use-after-free
- Disable gtk-doc to fix build
- Resolves: RHEL-16793
LLb'ceRay Strode <rstrode@redhat.com> - 3.22.30-6_P- Fix leak on VT switch
  Resolves: #1882574c&_kDavid King <dking@redhat.com> - 3.22.30-8b- Further treeview a11y refcount fix (#1965195)%_3David King <dking@redhat.com> - 3.22.30-7aZ@- Fix treeview a11y refcounting (#1965195)
- Avoid cellarea resize crash (#1962215)b$ceRay Strode <rstrode@redhat.com> - 3.22.30-6_P- Fix leak on VT switch
  Resolves: #1882574 #e]Wim Taymans <wtaymans@redhat.com> - 1.10.4-4ey- Patch CVE-2023-44446: MXF demuxer use-after-free
- Disable gtk-doc to fix build
- Resolves: RHEL-16793i"eqWim Taymans <wtaymans@redhat.com> - 1.10.4-3Yd- Disable wayland sink plugin
- Resolves: #1488978j!esWim Taymans <wtaymans@redhat.com> - 1.10.4-2XC- Disable plugins
- Fix origin
- Resolves: #1429587x e
Wim Taymans <wtaymans@redhat.com> - 1.10.4-1XO@- Update to 1.10.4
- Remove unbuilt plugins
- Resolves: #1429587
aRa/_3David King <dking@redhat.com> - 3.22.30-7aZ@- Fix treeview a11y refcounting (#1965195)
- Avoid cellarea resize crash (#1962215)b.ceRay Strode <rstrode@redhat.com> - 3.22.30-6_P- Fix leak on VT switch
  Resolves: #1882574b-ceRay Strode <rstrode@redhat.com> - 3.22.30-6_P- Fix leak on VT switch
  Resolves: #1882574c,_kDavid King <dking@redhat.com> - 3.22.30-8b- Further treeview a11y refcount fix (#1965195)+_3David King <dking@redhat.com> - 3.22.30-7aZ@- Fix treeview a11y refcounting (#1965195)
- Avoid cellarea resize crash (#1962215)c*_kDavid King <dking@redhat.com> - 3.22.30-8b- Further treeview a11y refcount fix (#1965195))_3David King <dking@redhat.com> - 3.22.30-7aZ@- Fix treeview a11y refcounting (#1965195)
- Avoid cellarea resize crash (#1962215)b(ceRay Strode <rstrode@redhat.com> - 3.22.30-6_P- Fix leak on VT switch
  Resolves: #1882574

er+V:eD`
d5da28b2cc382844aa578c0eb19c23535d011518b699a177d00f377554f5c80aD_
86993bde440204eca01ab08264c50ea2e67b216b8b0460a9abd7ed1e48864926D^
835e86766eabc1d9ae0e8b151d9721a415b5dfdc6b9dc31497b790dc7f51e60dD]
aaa642c4d8ab309bd427dfe250bcf2154390e1fe39eeec98c816058e6da39c2fD\
42f1179fa155a1a3b4448c2b7429ab632d2e5b7216612cb0f5458e96d9c9e738D[
a20718245cbc3ce096de1da99acc9aadce7082881bcdc0b1576352b2959e8db8DZ
fbfc27e8e45f88c94b069c77e301bd007e2e4c2d7e71b268fcaa0c9bee8f84a6DY
dee28e194d7127f17697a1e4475e1ffb525b9887c34d90564152f147605360acDX
c697cda85543d0498850f1a43781d8a7a9027a93e2d04cb19345ead2d9caab5cDW
f7c28e4b2e40bd7978b5bd740987494914a4fb3430ca45bea2cc9a5f94c01b50DV
4459ade066985609ab1ac51574d24bb466645a717a2ff3a30e417a8b91609a87DU
4c591b2e577a321d2a3be5e390eecceec9fe2e18c4d4f269ef41f4ecb0ef6c0cDT
052c8eb21db8776433111192ff5a74c5160dfebb1bfcc701324165599256b321
`CQ`7_3David King <dking@redhat.com> - 3.22.30-7aZ@- Fix treeview a11y refcounting (#1965195)
- Avoid cellarea resize crash (#1962215)b6ceRay Strode <rstrode@redhat.com> - 3.22.30-6_P- Fix leak on VT switch
  Resolves: #1882574c5_kDavid King <dking@redhat.com> - 3.22.30-8b- Further treeview a11y refcount fix (#1965195)4_3David King <dking@redhat.com> - 3.22.30-7aZ@- Fix treeview a11y refcounting (#1965195)
- Avoid cellarea resize crash (#1962215)b3ceRay Strode <rstrode@redhat.com> - 3.22.30-6_P- Fix leak on VT switch
  Resolves: #1882574c2_kDavid King <dking@redhat.com> - 3.22.30-8b- Further treeview a11y refcount fix (#1965195)1_3David King <dking@redhat.com> - 3.22.30-7aZ@- Fix treeview a11y refcounting (#1965195)
- Avoid cellarea resize crash (#1962215)c0_kDavid King <dking@redhat.com> - 3.22.30-8b- Further treeview a11y refcount fix (#1965195)
5CRV?y7Peter Robinson <pbrobinson@fedoraproject.org> 0.20.0-2Q&@- Obsolete gupnp-valac>_kDavid King <dking@redhat.com> - 3.22.30-8b- Further treeview a11y refcount fix (#1965195)=_3David King <dking@redhat.com> - 3.22.30-7aZ@- Fix treeview a11y refcounting (#1965195)
- Avoid cellarea resize crash (#1962215)b<ceRay Strode <rstrode@redhat.com> - 3.22.30-6_P- Fix leak on VT switch
  Resolves: #1882574c;_kDavid King <dking@redhat.com> - 3.22.30-8b- Further treeview a11y refcount fix (#1965195):_3David King <dking@redhat.com> - 3.22.30-7aZ@- Fix treeview a11y refcounting (#1965195)
- Avoid cellarea resize crash (#1962215)b9ceRay Strode <rstrode@redhat.com> - 3.22.30-6_P- Fix leak on VT switch
  Resolves: #1882574c8_kDavid King <dking@redhat.com> - 3.22.30-8b- Further treeview a11y refcount fix (#1965195)
&d,&pGg}Richard Hughes <rhughes@redhat.com> - 1.0.2-5[)+ Update to latest upstream version
- Resolves: #1569980lFguBastien Nocera <bnocera@redhat.com> - 1.0.1-1X	@+ gupnp-1.0.1-1
- Rebase to 1.0.1
Resolves: #1386985EqDebarshi Ray <rishi@fedoraproject.org> - 0.20.13-1UlI@- Update to 0.20.13 and re-enable vala bindings
Resolves: #1225451MD_?Daniel Mach <dmach@redhat.com> - 0.20.3-3RU- Mass rebuild 2014-01-24MC_?Daniel Mach <dmach@redhat.com> - 0.20.3-2Rk- Mass rebuild 2013-12-27By9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.3-1Q?@- 0.20.3 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.3.newsAy9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.2-1QiH- 0.20.2 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.2.news@y9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.1-1Q5@- 0.20.1 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.1.news
80\8OqDebarshi Ray <rishi@fedoraproject.org> - 0.20.13-1UlI@- Update to 0.20.13 and re-enable vala bindings
Resolves: #1225451MN_?Daniel Mach <dmach@redhat.com> - 0.20.3-3RU- Mass rebuild 2014-01-24MM_?Daniel Mach <dmach@redhat.com> - 0.20.3-2Rk- Mass rebuild 2013-12-27Ly9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.3-1Q?@- 0.20.3 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.3.newsKy9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.2-1QiH- 0.20.2 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.2.newsJy9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.1-1Q5@- 0.20.1 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.1.newsVIy7Peter Robinson <pbrobinson@fedoraproject.org> 0.20.0-2Q&@- Obsolete gupnp-valatHgBastien Nocera <bnocera@redhat.com> - 1.0.2-6`[+ gupnp-1.0.3-3
- Fix DNS rebind issue
- Resolves: #1964706
*Nz*MW_?Daniel Mach <dmach@redhat.com> - 0.20.3-2Rk- Mass rebuild 2013-12-27Vy9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.3-1Q?@- 0.20.3 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.3.newsUy9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.2-1QiH- 0.20.2 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.2.newsTy9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.1-1Q5@- 0.20.1 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.1.newsVSy7Peter Robinson <pbrobinson@fedoraproject.org> 0.20.0-2Q&@- Obsolete gupnp-valatRgBastien Nocera <bnocera@redhat.com> - 1.0.2-6`[+ gupnp-1.0.3-3
- Fix DNS rebind issue
- Resolves: #1964706pQg}Richard Hughes <rhughes@redhat.com> - 1.0.2-5[)+ Update to latest upstream version
- Resolves: #1569980lPguBastien Nocera <bnocera@redhat.com> - 1.0.1-1X	@+ gupnp-1.0.1-1
- Rebase to 1.0.1
Resolves: #1386985

er+V:eDm
8fbe338dd8adc0ef568214985a4b86d964a490b7b5eb963f88ed406169b64c43Dl
35f5c229e131ffb525fc38628dbe4dc399fd7f6077f047e169dc8e5ddcce20e8Dk
9f51218b8454129029c134ac7b8c3cfdae6f1bd1938cb010314534defd013717Dj
cce9b9d8e55d003cd7be906f5603d626c0f14b8e422e5123076eb85b9dab7694Di
b716a9548efd53a938625df1910ca436cae1cbf92940422987c01ae7cbb040e3Dh
dc73b498dea020241c15f040008e6f96731b9a67cfa83b452c60a9d4510edd41Dg
dacb7b788cec2e57fc23d0ff804942ec81a7a415eee8eca5a9a61540c86d896aDf
4634b74cfe7dbc9b83774cbbc50314221241227045a9199072df357ddda72bf3De
28f3ff68224de0783083894b44eefc57e4833a53461ce91f1f4656bbc1b0eb9fDd
717c6856842ddb6b4eca2817cbb3adfce002d371a61b322c8c74761e57ae5bcfDc
bc77febf9b5e706cc4d68361638309818761fa19dfe82ca91496f40a23d81bacDb
ecb7f8d19fb659a35a4a25d22a891cfd89fd55cc12d791df222c33eba1c9dbdbDa
160346449f601718afb8de2d7f7e0aeb2ac8a5f4e2163d2f74d1b98233db4002
B,JzB_y9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.2-1QiH- 0.20.2 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.2.news^y9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.1-1Q5@- 0.20.1 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.1.newsV]y7Peter Robinson <pbrobinson@fedoraproject.org> 0.20.0-2Q&@- Obsolete gupnp-valat\gBastien Nocera <bnocera@redhat.com> - 1.0.2-6`[+ gupnp-1.0.3-3
- Fix DNS rebind issue
- Resolves: #1964706p[g}Richard Hughes <rhughes@redhat.com> - 1.0.2-5[)+ Update to latest upstream version
- Resolves: #1569980lZguBastien Nocera <bnocera@redhat.com> - 1.0.1-1X	@+ gupnp-1.0.1-1
- Rebase to 1.0.1
Resolves: #1386985YqDebarshi Ray <rishi@fedoraproject.org> - 0.20.13-1UlI@- Update to 0.20.13 and re-enable vala bindings
Resolves: #1225451MX_?Daniel Mach <dmach@redhat.com> - 0.20.3-3RU- Mass rebuild 2014-01-24
d@^Vgy7Peter Robinson <pbrobinson@fedoraproject.org> 0.20.0-2Q&@- Obsolete gupnp-valatfgBastien Nocera <bnocera@redhat.com> - 1.0.2-6`[+ gupnp-1.0.3-3
- Fix DNS rebind issue
- Resolves: #1964706peg}Richard Hughes <rhughes@redhat.com> - 1.0.2-5[)+ Update to latest upstream version
- Resolves: #1569980ldguBastien Nocera <bnocera@redhat.com> - 1.0.1-1X	@+ gupnp-1.0.1-1
- Rebase to 1.0.1
Resolves: #1386985cqDebarshi Ray <rishi@fedoraproject.org> - 0.20.13-1UlI@- Update to 0.20.13 and re-enable vala bindings
Resolves: #1225451Mb_?Daniel Mach <dmach@redhat.com> - 0.20.3-3RU- Mass rebuild 2014-01-24Ma_?Daniel Mach <dmach@redhat.com> - 0.20.3-2Rk- Mass rebuild 2013-12-27`y9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.3-1Q?@- 0.20.3 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.3.news
&d,&pog}Richard Hughes <rhughes@redhat.com> - 1.0.2-5[)+ Update to latest upstream version
- Resolves: #1569980lnguBastien Nocera <bnocera@redhat.com> - 1.0.1-1X	@+ gupnp-1.0.1-1
- Rebase to 1.0.1
Resolves: #1386985mqDebarshi Ray <rishi@fedoraproject.org> - 0.20.13-1UlI@- Update to 0.20.13 and re-enable vala bindings
Resolves: #1225451Ml_?Daniel Mach <dmach@redhat.com> - 0.20.3-3RU- Mass rebuild 2014-01-24Mk_?Daniel Mach <dmach@redhat.com> - 0.20.3-2Rk- Mass rebuild 2013-12-27jy9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.3-1Q?@- 0.20.3 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.3.newsiy9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.2-1QiH- 0.20.2 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.2.newshy9Peter Robinson <pbrobinson@fedoraproject.org> 0.20.1-1Q5@- 0.20.1 release
- http://ftp.gnome.org/pub/GNOME/sources/gupnp/0.20/gupnp-0.20.1.news
5+Kl5Rw_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^ve[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268xu_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)at_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)is_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256qr_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[q_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993tpgBastien Nocera <bnocera@redhat.com> - 1.0.2-6`[+ gupnp-1.0.3-3
- Fix DNS rebind issue
- Resolves: #1964706
	&Ff&^e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a~_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i}_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256q|_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[{_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993ez_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|y_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)rx_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)
"*6b"^e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256e_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)
1*6X1a_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256T_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)s
_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)e_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r
_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R	_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)
%$NZ|%T_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)s_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)e_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)
7.^7r _Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256q_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993
"Im"r(_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R'_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^&e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x%_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a$_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i#_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256e"_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|!_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)
	/Lz/x1_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a0_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i/_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256q._Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[-_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993T,_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)s+_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)e*_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|)_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)
"Tm"x9_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a8_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i7_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256e6_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|5_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r4_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R3_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^2e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268
BTmB[A_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993T@_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)s?_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)e>_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|=_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r<_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R;_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^:e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268
 A
rH_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)RG_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^Fe[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268xE_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)aD_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)iC_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256qB_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993
"Im"rP_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)RO_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^Ne[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268xM_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)aL_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)iK_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256eJ_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|I_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)
	/Lz/xY_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)aX_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)iW_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256qV_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[U_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993TT_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)sS_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)eR_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|Q_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)

er+V:eDz
cc2af8b460ae945f1afdf5f03ea0b48e40aa3372a33d96e0408d1256c8c0294eDy
a0b60429c7fcd5fba41b9a28504facb63c1539487333911e73e7e2b166b38981Dx
96f852d003908ae51e7c33a2d18e329760dd559b5ca3c8a594e3d2a5ebf41ce5Dw
2590f93594e0978b11599b182212244c231fcb0808dff97b691b518fbd531adaDv
72fedcf3bf921b3e8efb6e27a94cc4edfe624334e5b7a143442d707cfb625b06Du
93d59adb2af4416388006f622bdf8c0f758944b16c04ac683b05b66a90cd48c7Dt
527d093e43a30a0f0ec3101a8926eeba2b14e4496c495e70a1d5a3ceca45adbdDs
34a08308f948f94b0ad18d9d233e22453d984465c89a58935ec1185d071e7f4dDr
0b42148789300af59e74814b7d8cb50a3c1453dc197a498f2f37cdc75a6a97d7Dq
8453856c66fc79e7ec946e471ab4cddd8112886e40b99a72093c616592b2258fDp
938d5007ce1dff2b3235913a2a5efe8141b51ff690ea6d5b59b6289df55ab4f8Do
b95af4b262010256013a4265ab61dfb37bf37e1d4ca12de8b007b315ae8a9b1cDn
51af7b29f1554b6ee4cfc1be4f18e91dcb17d8795d87ad960cb26d3fe381cc64
/Tm/ia_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256q`_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[__[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993e^_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|]_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r\_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R[_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^Ze[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268
"!u"ii_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256eh_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|g_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)rf_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)Re_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^de[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268xc_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)ab_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)
!usq_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)ep_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|o_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)rn_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)Rm_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^le[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268xk_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)aj_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)
3=^'3|y_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)rx_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)Rw_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^ve[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268xu_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)at_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)is_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256Tr_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)
	M"m)M^e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256q~_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[}_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993T|_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)s{_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)ez_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)
,*6p,a
_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i	_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256q_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993e_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)
"$NZ"a_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256e_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R
_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)
%$NZ|%T_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)s_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)e_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)
"0T~	"e"_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|!_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r _Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256
3a^*e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x)_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a(_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i'_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256q&_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[%_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993T$_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)s#_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)
"*6b"^2e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x1_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a0_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i/_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256e._oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|-_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r,_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R+_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)
/*6X/q:_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[9_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993T8_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)s7_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)e6_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|5_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r4_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R3_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)
"0T~	"eB_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|A_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r@_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R?_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^>e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x=_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a<_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i;_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256
"0T~	"eJ_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|I_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)rH_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)RG_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^Fe[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268xE_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)aD_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)iC_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256
3a^Re[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268xQ_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)aP_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)iO_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256qN_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[M_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993TL_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)sK_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)
"*6b"^Ze[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268xY_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)aX_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)iW_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256eV_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|U_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)rT_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)RS_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)

er+V:eD
ace18d3c4c3acb71a8d4c5a6930f0ae58e655462938d91d3ef45aef7694df479D
79eacef92a2947aefaab902e53fada60dc27d9c173b1e175f1ce4db04d6c653eD
59b2eac344b965618bc03745e27bb5c92278b9fa7c3a6327c3f89fdda6289a54D
eb18e0e118e44349b3d8917b223e6ca7e2331d41d2e49ec2e8a65f091985bfb7D
f94ef4ce18a021edb2b5a72fc87092d88e8c7b4aac3c605213fea20cdeefb002D
a38a894774d443bd314d09acaa9ee6056116e25f757c9e76290fe30450b9ca95D
78de7ead3aa002c4e670d2a6bb86af61059a4efe2b86257958242df65bc50d42D
3cf6225627d15b57e6db240be4821a47a55d2bf482e4fe8f1928862282e7998eD
073a61debf16645920e116641fcf09bdcef80147f54754057c18515f5ebe1f8cD~
09277f1295e2db1f4f90bd3fce359dd8150009233cbba997650480e544b67766D}
474549f2d0c95b83d89f1d651d078459863a9e1f202ab7c4c64e77e2735fab8aD|
b9b11e2c45c327237aea9d0fd84d0d41db9d2a4137822d95f71cedd3ae9145c2D{
858c36d8de6e26caf93ad7dc07224b2b333fcf1617a211b7303e44cdd15a6f3d
/*6X/qb_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[a_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993T`_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)s__	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)e^_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|]_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r\_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R[_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)
"0T~	"ej_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|i_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)rh_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)Rg_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^fe[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268xe_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)ad_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)ic_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256
"0T~	"er_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|q_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)rp_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)Ro_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^ne[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268xm_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)al_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)ik_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256
3a^ze[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268xy_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)ax_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)iw_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256qv_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[u_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993Tt_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)ss_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)
"*6b"^e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256e~_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|}_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r|_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R{_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)
/*6X/q
_Ondrej Holy <oholy@redhat.com> - 1.30.4-2XPA- Add explicit gvfs-client requirements
- Resolves: #1386993[	_[Ondrej Holy <oholy@redhat.com> - 1.30.4-1XP@- Update to 1.30.4
- Resolves: #1386993T_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)s_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)e_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)
"0T~	"e_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x
_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256
"0T~	"e_oOndrej Holy <oholy@redhat.com> - 1.36.2-5`- Fix udisks2 volume monitor leaks (rhbz#1944813)|_Ondrej Holy <oholy@redhat.com> - 1.36.2-4^1- Fix udisks2 volume monitor crashes when stopping drive (rhbz#1758237)r_Ondrej Holy <oholy@redhat.com> - 1.36.2-3\f- Force NT1 protocol version for workgroup support (#1619719)R_GOndrej Holy <oholy@redhat.com> - 1.36.2-2\R@- Prevent spawning new daemons if outgoing operation exists (#1632960)
- CVE-2019-3827: Prevent access if any authentication agent isn't available (#1673887)^e[Kalev Lember <klember@redhat.com> - 1.36.2-1Z@- Update to 1.36.2
- Resolves: #1569268x_Ondrej Holy <oholy@redhat.com> - 1.30.4-5Z- Fix network backend crashes when creating proxy failed (#1465302)a_gOndrej Holy <oholy@redhat.com> - 1.30.4-4Y- Rebuild against newer libgphoto2 (#1500216)i_wOndrej Holy <oholy@redhat.com> - 1.30.4-3X- Handle SecurID password prompt
- Resolves: #1440256
P3tPJ"Y?Daniel Mach <dmach@redhat.com> - 1.5-7RU- Mass rebuild 2014-01-24J!Y?Daniel Mach <dmach@redhat.com> - 1.5-6Rk- Mass rebuild 2013-12-27 c+Petr Stodulka <pstodulk@redhat.com> - 1.5-5R- fix issue with nonblocking open for PAR and OFL file
  Resolves: rhbz#1028052Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.5-4Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildWADaniel Drake <dsd@laptop.org> - 1.5-3P6@- Fix "gzip --rsyncable" functionality by removing a spurious blank line from
  the patch.Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.5-2P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildT_MOndrej Holy <oholy@redhat.com> - 1.36.2-7bU- Fix unapplied patch (#2093816)s_	Ondrej Holy <oholy@redhat.com> - 1.36.2-6bx@- Use O_RDWR to fix fstat when writing on SMB share (#2093816)offlrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|7?GOW_gow (19AHPYaiqy
"*2:BJRZbjrz
")17>DJQW^ekqx~")+.247;>@DGIMQSVXZ\`dinsxz}!#&	(
*,0
4
)c)d)akRyan O'Hara <rohara@redhat.com> - 1.5.18-3Wi,@- Fix TCP user timeout patch for 1.5.18 releasel(a{Ryan O'Hara <rohara@redhat.com> - 1.5.18-2Wb- Add TARGET to install-bin for haproxy-systemd-wrappera'aeRyan O'Hara <rohara@redhat.com> - 1.5.18-1WaC@- Update to stable release 1.5.18 (#1344012)&g%Jakub Martisko <jamartis@redhat.com> - 1.5-11b^@- fix an arbitrary-file-write vulnerability in zgrep
Resolves: CVE-2022-1271)%gmJakub Martisko <jamartis@redhat.com> - 1.5-10Yz- doc change: missing grep options are now mentioned in the zgrep 
  man pages/help message
  Resolves: #1437002V$cMPetr Stodulka <pstodulk@redhat.com> - 1.5-9Xf@- fix zfoce
  Resolves: #1382054
#c3Petr Stodulka <pstodulk@redhat.com> - 1.5-8U- Gzip overwrite existing files when user choose "no" on yes/no question.
  It's due to wrong dupicit declaration of yesno() function in gzip.h
  which is compiled wrong with -O2 option.
  Resolves: rhbz#1201689
IdV1s=Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.2S- Resolves: rhbz#1125544j0esRyan O'Hara <rohara@redhat.com> - 1.5.18-9.1`@- Fix health checks for flapping servers (#1947750)|/aRyan O'Hara <rohara@redhat.com> - 1.5.18-9\v{- Detect down servers with mutliple tcp-check connect rules (#1677420)c.aiRyan O'Hara <rohara@redhat.com> - 1.5.18-8[Xf@- Build with USE_GETADDRINFO option (#1598491)]-a]Ryan O'Hara <rohara@redhat.com> - 1.5.18-7Z- Rebuild with openssl-1.0.2k (#1509139)l,a{Ryan O'Hara <rohara@redhat.com> - 1.5.18-6Y#@- Use KillMode=mixed in systemd service file (#1444709)q+aRyan O'Hara <rohara@redhat.com> - 1.5.18-5X~@- Use soft-static allocation for haproxy UID/GID (#1386130)q*aRyan O'Hara <rohara@redhat.com> - 1.5.18-4X,J@- Return correct exit codes from systemd-wrapper (#1391990)
ljo7soRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$6sWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.B5sRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056n4smRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
3s)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#11589922s/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056
p_rpn>smRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
=s)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992<s/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056V;s=Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.2S- Resolves: rhbz#1125544:u;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#19505009uRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{8sRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983
: Du;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500CuRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{BsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983oAsoRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$@sWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.B?sRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056
ljoJsoRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$IsWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.BHsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056nGsmRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
Fs)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992Es/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056
=_?=nQsmRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
Ps)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992Os/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056NuRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.12a@- Limit recursion in ri-records (CVE-2021-3622)
  resolves: rhbz#1976193Mu;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500LuRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{KsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983
: Wu;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500VuRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{UsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983oTsoRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$SsWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.BRsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056
t$^sWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.B]sRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056n\smRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
[s)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992Zs/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056VYs=Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.2S- Resolves: rhbz#1125544XuRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.12a@- Limit recursion in ri-records (CVE-2021-3622)
  resolves: rhbz#1976193

er+V:eD
07cfec6beda5578439d467fa4a51b7e846ea94e1eb455753928367e7fd96ac68D
35fc790f76f1d12e738a6b5cd1438085704844f9c267638a15f9cc080376b10dD
9a93379d2c2af5db3ccd19b3b12e93f6dee917f2156fc18048525a7a90b313caD
c425b045fd266e2130faf0b97fe7cadc5218ad8cbb8e87ffbafe1d35b166ff43D
e083624285f3f8668aeebe5e4297e96c9e4ea9ed3cece7a3318166272f0fe11aD
4cf62f2fe312ff9b70310eeb760aecc8141285cba4ffec167b47f1cd26cb8fecD
95e6995373810d5b756222856d1b5d2f7d82bcb15022cc12282cbc282404516fD

c1f39d4de68160899478e6a3a13d87ca0cbb510af261d0319a2c3f3690cf263fD
bc29e9309d0d6c8bcbf454c1d73fd5eda133e3cd0a96c01283bd3c2830a03310D
233182440f451ea41600279219e708b82494832752dd921ec2f2e4c0ab2a7353D

d39fb02417c772d1ee5c9eb6d9a3981e59719475b6865e25c7e431882fec497bD	
fd358c591bdefefe4f8f4b730734f8e570c3f50680413739ef8785c99d73fdddD
12aa178b2c59b3f4c2d815f73b977ffeb7703da8b0da0e7a3a6f02c9aebee2a4
oo
es)	Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992ds/	Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056Vcs=	Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.2S- Resolves: rhbz#1125544bu;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500auRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{`sRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983o_soRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983
!1ku	Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{js	Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983oiso	Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$hsW	Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.Bgs	Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056nfsm	Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
ae@	a$qsW
Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.Bps
Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056nosm
Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
ns)
Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992ms/
Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056lu;	Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500
<a<
xs)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992ws/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056vu
Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.12a@- Limit recursion in ri-records (CVE-2021-3622)
  resolves: rhbz#1976193uu;
Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500tu
Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{ss
Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983orso
Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983
!1~uRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{}sRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983o|soRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983${sWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.BzsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056nysmRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
}e*}#Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:1.8.1.3-10Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildmgwTomas Radej <tradej@redhat.com> - 1:1.8.1.3-9P7l- Switched from SysV to systemd
- Spec rearrangements!Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:1.8.1.3-8P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildbuSAlexander Kurtakov <akurtako@redhat.com> 1:1.8.1.3-7O~- Switch to servlet 3.0 by default.Gg+Tomas Radej <tradej@redhat.com> - 1:1.8.1.3-6OX@- Fixed symlinkuRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.12a@- Limit recursion in ri-records (CVE-2021-3622)
  resolves: rhbz#1976193u;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500
sIbuS
Alexander Kurtakov <akurtako@redhat.com> 1:1.8.1.3-7O~- Switch to servlet 3.0 by default.Gg+
Tomas Radej <tradej@redhat.com> - 1:1.8.1.3-6OX@- Fixed symlink
w'Mikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-15ch@- Fix possible remote code execution vulnerability
- Resolves: CVE-2022-418538	w{Mikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-14VZ- Remove dependency on initscripts
- Add After=network.target to systemd service
- Resolves: rhbz#1283893, rhbz#1269717Qg?Daniel Mach <dmach@redhat.com> - 1:1.8.1.3-13Rk- Mass rebuild 2013-12-27wMikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-12Qz- Rebuild to regenerate API documentation
- Resolves: CVE-2013-1571	wMikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-11Q- Fix incorrect permissions on systemd unit file
- Resolves: rhbz#963911
.bS>.8w{
Mikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-14VZ- Remove dependency on initscripts
- Add After=network.target to systemd service
- Resolves: rhbz#1283893, rhbz#1269717Qg?
Daniel Mach <dmach@redhat.com> - 1:1.8.1.3-13Rk- Mass rebuild 2013-12-27w
Mikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-12Qz- Rebuild to regenerate API documentation
- Resolves: CVE-2013-1571	w
Mikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-11Q- Fix incorrect permissions on systemd unit file
- Resolves: rhbz#963911#
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:1.8.1.3-10Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuildmgw
Tomas Radej <tradej@redhat.com> - 1:1.8.1.3-9P7l- Switched from SysV to systemd
- Spec rearrangements
!
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:1.8.1.3-8P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
n$!	wMikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-11Q- Fix incorrect permissions on systemd unit file
- Resolves: rhbz#963911#Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:1.8.1.3-10Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildmgwTomas Radej <tradej@redhat.com> - 1:1.8.1.3-9P7l- Switched from SysV to systemd
- Spec rearrangements!Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:1.8.1.3-8P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildbuSAlexander Kurtakov <akurtako@redhat.com> 1:1.8.1.3-7O~- Switch to servlet 3.0 by default.Gg+Tomas Radej <tradej@redhat.com> - 1:1.8.1.3-6OX@- Fixed symlinkw'
Mikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-15ch@- Fix possible remote code execution vulnerability
- Resolves: CVE-2022-41853
x$h'm"gwTomas Radej <tradej@redhat.com> - 1:1.8.1.3-9P7l- Switched from SysV to systemd
- Spec rearrangements!!Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:1.8.1.3-8P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuildb uSAlexander Kurtakov <akurtako@redhat.com> 1:1.8.1.3-7O~- Switch to servlet 3.0 by default.Gg+Tomas Radej <tradej@redhat.com> - 1:1.8.1.3-6OX@- Fixed symlinkw'Mikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-15ch@- Fix possible remote code execution vulnerability
- Resolves: CVE-2022-418538w{Mikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-14VZ- Remove dependency on initscripts
- Add After=network.target to systemd service
- Resolves: rhbz#1283893, rhbz#1269717Qg?Daniel Mach <dmach@redhat.com> - 1:1.8.1.3-13Rk- Mass rebuild 2013-12-27wMikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-12Qz- Rebuild to regenerate API documentation
- Resolves: CVE-2013-1571
6aL<6q)]Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)(w'Mikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-15ch@- Fix possible remote code execution vulnerability
- Resolves: CVE-2022-418538'w{Mikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-14VZ- Remove dependency on initscripts
- Add After=network.target to systemd service
- Resolves: rhbz#1283893, rhbz#1269717Q&g?Daniel Mach <dmach@redhat.com> - 1:1.8.1.3-13Rk- Mass rebuild 2013-12-27%wMikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-12Qz- Rebuild to regenerate API documentation
- Resolves: CVE-2013-1571	$wMikolaj Izdebski <mizdebsk@redhat.com> - 1:1.8.1.3-11Q- Fix incorrect permissions on systemd unit file
- Resolves: rhbz#963911##Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:1.8.1.3-10Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
+k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connectionT*k?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistency
22G.k%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications-kILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec,]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)
kbP2}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.1ah- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases.1qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S0k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues/k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
4k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connectionT3k?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistency
22G7k%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications6kILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec5]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)
kb;q/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.:qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S9k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues8k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
),)>kILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec=]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)P<}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.2a@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases
5@k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG?k%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
d-DqkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentCq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.BqmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SAk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
EEGkILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timePF}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.4aZ@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesFEW7Luboš Uhliarik <luhliari@redhat.com>a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
5Ik9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGHk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
d-MqkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentLq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.KqmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SJk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
Qm7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-88[+@- Resolves: #1527295 - httpd with worker/event mpm segfaults after multiple
  SIGUSR1PP}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.5b<]@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases:OqLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSNq7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
44TSk?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyqR]Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)
hkhVkILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timecU]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)Tk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
5Xk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGWk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
NZy%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos_- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesSYk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues

er+V:eD!
1032b8922d675f553db7b6424ba04c52bf5594bf148d3c80cf447060379be540D 
fbb00aafe5d8bd8b4ce85814f2d529e893f31e915c6393c651859d9dd4be56abD
3d4ce04e90a019a713860f38b262e7e948563f62770c6d7fa6bafd59e0ad0580D
82d5ee0b6f067209f21584e5acc7fc2bea3ab64f1d41f52bbe4bddc612f4670dD
f359b38fcffcd9d7ae7daab258f4fd7abea1c839790269254b9b1fbebcb55ba1D
80b89881a4e050f35e7e02a7da9f7eeb5a152b057a835557cd8472b6f91d182aD
57e3a74cb68c72426ee6a022b286950bbc4ac0c0a450be5d5e07d0a0ac91fcc0D
6598e08634815038cb179701fefe7d97564cc4df49d4858c66ac323e5c9c5628D
1562216c2581239f50ab2fbbcd1a38b49ace932313a42d97acd2fa2767606ffdD
18b6542a7872436ef0c7efd318aadaca8d2c6de3a49d4cd5fd54986bf4b9109eD
1243b5c5c37f8cff61bef905abb14b3fec79b4baf0f8804006af238bbc09108fD
760d5445bc23c3428607195fc5e872474f29cb02a1ec8cc53a0bc41b6771e204D
4d58a246d4453df6a19b52d675c58ebe8d648d62ede5f2fc0cbcb709d686a098
5\k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG[k%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
d-`qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart content_q/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.^qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S]k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
j>jPd}%CentOS Sources <bugs@centos.org> - 2.4.6-98.el7.centos.6c@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases)cqcLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:bqLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSaq7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
kb-iqkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contenthq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.gqmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sfk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issuesek9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
O>OFnOAJohnny Hughes <johnny@centos.org>d-b- Manual CentOS Debranding"mqULuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)lqcLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:kqLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSjq7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
kb-sqkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentrq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.qqmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Spk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issuesok9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
>xqLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-99.1dJc- Resolves: #2190143 - mod_rewrite regression with CVE-2023-25690"wqULuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)vqcLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:uqLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierStq7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
44Tzk?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyqy]Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)
hkh}kILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec|]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889){k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
5k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG~k%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
##P}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.1ah- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases.qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connectionTk?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistency
22Gk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applicationskILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)
kbq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.
qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S	k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issuesk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
),)kILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec
]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)P}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.2a@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases
5k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
d-qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
EEkILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timeP}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.4aZ@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesFW7Luboš Uhliarik <luhliari@redhat.com>a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
5k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
d-qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
!m7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-88[+@- Resolves: #1527295 - httpd with worker/event mpm segfaults after multiple
  SIGUSR1P }%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.5b<]@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases:qLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSq7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
44T#k?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyq"]Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)
hkh&kILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec%]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)$k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
5(k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG'k%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
N*y%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos_- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesS)k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
5,k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG+k%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
d-0qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart content/q/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix..qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S-k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
j>jP4}%CentOS Sources <bugs@centos.org> - 2.4.6-98.el7.centos.6c@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases)3qcLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:2qLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierS1q7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
kb-9qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart content8q/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.7qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S6k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues5k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
O>OF>OAJohnny Hughes <johnny@centos.org>d-b- Manual CentOS Debranding"=qULuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)<qcLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:;qLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierS:q7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
kb-CqkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentBq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.AqmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S@k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues?k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
>HqLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-99.1dJc- Resolves: #2190143 - mod_rewrite regression with CVE-2023-25690"GqULuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)FqcLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:EqLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSDq7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
44TJk? Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyqI] Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)
hkhMkI Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timecL]m Joe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)Kk9 Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
5Ok9 Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGNk% Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
##PR}% CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.1ah- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases.Qqm Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SPk= Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
Tk9!Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connectionTSk?!Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistency
22GWk%!Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applicationsVkI!Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timecU]m!Joe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)
kb[q/!Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.Zqm!Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SYk=!Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issuesXk9!Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
),)^kI"Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec]]m"Joe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)P\}%!CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.2a@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases

er+V:eD.
4317de17f229764365281623322d3bfc068eeae3772e61937438e1e190c1251eD-
80b0aaff62516f728ee4d1972185e7b7b5f5d15ea67da82dd19429fac70a5b23D,
0094b5e088ab7669b50681c5ee1c139c5ea4b295dff26681ef9aabc6f5a119dbD+
601f376aa7ef59f60e13ba11f0a9a7286b883a945173b5b829fe2e939b6b3d1eD*
8fefb0595d7ec2b0969e86042785c698809542ecd2b793434519146c6285a65eD)
ab57b19bedc00d6be037859d8d8126fff6c0f4421a2b085376f188106987b7e2D(
2efed6a1834b9396c783a23359a0750766c22f944cdc5953485f45050af967feD'
27c88f137de5866849397dd80af6fd026191916624a901d7d157db89d720351bD&
1900d58b22825187824aca7c1c6d194d7a401d5fcf0c433dc2037ac97141b1fdD%
4112f1f23e8f476ae869ef1e7ba7b1dcd072616c0fcd173ce6f6a784d7d9f05fD$
5ca852164720791fe6e270a360e14b479b57e0fa1f71c93c1e582a9179353c61D#
a52b0985bc9791dee53f7a73f22051cc229824892249b53b748eaad81619a0bfD"
fd5c2fb9ea8fe33dda81b2c13693c8901313964b621a4845172a14c12df1439a
5`k9"Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG_k%"Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
d-dqk"Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentcq/"Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.bqm"Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sak="Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
EEgkI#Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timePf}%"CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.4aZ@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesFeW7"Luboš Uhliarik <luhliari@redhat.com>a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
5ik9#Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGhk%#Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
d-mqk#Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentlq/#Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.kqm#Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sjk=#Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
qm7$Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-88[+@- Resolves: #1527295 - httpd with worker/event mpm segfaults after multiple
  SIGUSR1Pp}%#CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.5b<]@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases:oq#Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSnq7#Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
44Tsk?$Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyqr]$Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)
hkhvkI$Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timecu]m$Joe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)tk9$Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
5xk9$Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGwk%$Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
Nzy%$CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos_- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesSyk=$Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
5|k9%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG{k%%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
d-qk%Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentq/%Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.~qm%Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S}k=%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
j>jP}%%CentOS Sources <bugs@centos.org> - 2.4.6-98.el7.centos.6c@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases)qc%Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:q%Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSq7%Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
kb-	qk&Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentq/&Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.qm&Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sk=&Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issuesk9&Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
O>OFOA&Johnny Hughes <johnny@centos.org>d-b- Manual CentOS Debranding"
qU&Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)qc&Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:q&Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierS
q7&Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
kb-qk'Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentq/'Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.qm'Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sk='Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issuesk9'Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
>q'Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-99.1dJc- Resolves: #2190143 - mod_rewrite regression with CVE-2023-25690"qU'Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)qc'Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:q'Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSq7'Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
44Tk?(Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyq](Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)
hkhkI(Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec]m(Joe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)k9(Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
5k9(Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGk%(Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
##P"}%(CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.1ah- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases.!qm(Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S k=(Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
$k9)Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connectionT#k?)Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistency
22G'k%)Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications&kI)Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec%]m)Joe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)
kb+q/)Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.*qm)Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S)k=)Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues(k9)Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
),).kI*Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec-]m*Joe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)P,}%)CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.2a@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases
50k9*Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG/k%*Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
d-4qk*Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart content3q/*Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.2qm*Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S1k=*Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
EE7kI+Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timeP6}%*CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.4aZ@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesF5W7*Luboš Uhliarik <luhliari@redhat.com>a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
59k9+Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG8k%+Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
d-=qk+Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart content<q/+Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.;qm+Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S:k=+Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
Am7,Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-88[+@- Resolves: #1527295 - httpd with worker/event mpm segfaults after multiple
  SIGUSR1P@}%+CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.5b<]@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases:?q+Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierS>q7+Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
44TCk?,Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyqB],Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)
hkhFkI,Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timecE]m,Joe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)Dk9,Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
5Hk9,Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGGk%,Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
NJy%,CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos_- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesSIk=,Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issuesofflrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|>CHJMORTW[^`dgim q!s"v#x$z%|&'(	)*+,-./"0$1'2+3.405467798=9A:C;F<H=J?L@PATBYC^EcFhGnHuI|JK
LMNO&P-Q4R;SBTIUPVWW^XeZl[t\{]^
_`ab&c-d4e;fBgIhPiWj^kemlnsoyq}rtu
wxyz{"}$~'*-0469<?
5Lk9-Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGKk%-Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
d-Pqk-Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentOq/-Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.Nqm-Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SMk=-Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
j>jPT}%-CentOS Sources <bugs@centos.org> - 2.4.6-98.el7.centos.6c@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases)Sqc-Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:Rq-Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSQq7-Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
kb-Yqk.Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentXq/.Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.Wqm.Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SVk=.Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issuesUk9.Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
O>OF^OA.Johnny Hughes <johnny@centos.org>d-b- Manual CentOS Debranding"]qU.Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)\qc.Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:[q.Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSZq7.Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session

er+V:eD;
e58be69903032ce19789e8066ac18b837e6cf4b67db9460c5dbac4897f678352D:
b750d9875369ddf78843edcdbe9053b4d4a7e6d7bc2ca858b563d14bf5a16e4bD9
93736c157e6c574d78df16b0ccdcb3d5d5bc0856fb66a7d43da85bfe6d0149a6D8
1cd00988d4a50430747550422159355a53806a543c45da98d1b08a6114cde7cdD7
6f853b40dd81bacb35a8698a21c1a1d6663fa911cc8c99485387e4e10aa1cec1D6
0261a6827bcb70a4d4e0bbabff124f88c79ad1171f8d19e379a2e019e4867abfD5
5fbeceddf0bf8f98be4ae1abfe85a15497949baa0f03eb2097d8bd245122c6caD4
796aeedf2cba1ce6592411175e3cf65482a97625d933bb4da8a28f0d16cf34f0D3
c96966864df3d8f7e446dbab1aaaf13a2bc50887d2c246af4d21658831913c1cD2
d70d1392ce3021f70e51c4dc35c2fa251da70e2e0b7384fc3ca8003c9c2f59bfD1
b021fb63d01712466969d8b248713efeb2085fedebff3f3d2e0f0500cd70ea47D0
6c3c6e8e517dcf759d5a75600d88260d972e071d18adcef801da195de54076b6D/
a07b8c2dfe81595e9e9b35a3f4a4c913496728d0ab4422f3a5e00e2c9d5174ad
kb-cqk/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentbq//Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.aqm/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S`k=/Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues_k9/Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
>hq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-99.1dJc- Resolves: #2190143 - mod_rewrite regression with CVE-2023-25690"gqU/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)fqc/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:eq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSdq7/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
ND:N
n[;0Honggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585VmYU0Jarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296lY)0Jarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541xkY0Jarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426jY?0Jarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#16874268iY0Jarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274
Y
{UYuk1Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL barqtk{1Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-4\O- Resolves: #1693926 - Commit hangul preedit with mouse
sk+1Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-3\@- Resolves: #1671187 - ibus.conf does not set QT_IM_MODULE with qt5 ibus moduler[O0Honggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699q[C0Honggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
p[;0Honggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482bo[m0Honggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
y_|c_1Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks{m1Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowszm1Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionzyk1Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()xk1Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspwky1Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.povk1Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's death
zrv|zzk2Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()k2Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspky2Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.pok2Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathk2Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL barq~k{2Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-4\O- Resolves: #1693926 - Commit hangul preedit with mouse
}k+2Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-3\@- Resolves: #1671187 - ibus.conf does not set QT_IM_MODULE with qt5 ibus module
|
k3Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsp	ky3Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.pok3Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathk3Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar_c_2Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaksm2Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsm2Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regression
yk4Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar}m3Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-14d8- Resolves: #2175871 - Update ibus-2175871-x11-Xephyr-query.patchm3Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-13d@- Resolves: #2175871 - Avoid to hang the process with SIGUSR1 signal_c_3Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks
m3Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsm3Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionzk3Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()
y_c_4Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaksm4Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsm4Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionzk4Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()k4Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspky4Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.pok4Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's death
x|nrxpky5Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.pok5Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathk5Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL barqk{5Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-4\O- Resolves: #1693926 - Commit hangul preedit with mouse
k+5Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-3\@- Resolves: #1671187 - ibus.conf does not set QT_IM_MODULE with qt5 ibus module}m4Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-14d8- Resolves: #2175871 - Update ibus-2175871-x11-Xephyr-query.patchm4Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-13d@- Resolves: #2175871 - Avoid to hang the process with SIGUSR1 signal
{zq&k{6Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-4\O- Resolves: #1693926 - Commit hangul preedit with mouse
%k+6Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-3\@- Resolves: #1671187 - ibus.conf does not set QT_IM_MODULE with qt5 ibus module_$c_5Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks#m5Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows"m5Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionz!k5Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid() k5Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows
rx~|r-m6Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows,m6Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionz+k6Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()*k6Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsp)ky6Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.po(k6Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's death'k6Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar
4m7Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionz3k7Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()2k7Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsp1ky7Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.po0k7Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's death/k7Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar_.c_6Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks
zp;ky8Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.po:k8Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's death9k8Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar}8m7Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-14d8- Resolves: #2175871 - Update ibus-2175871-x11-Xephyr-query.patch7m7Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-13d@- Resolves: #2175871 - Avoid to hang the process with SIGUSR1 signal_6c_7Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks5m7Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows
{z}Bm8Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-14d8- Resolves: #2175871 - Update ibus-2175871-x11-Xephyr-query.patchAm8Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-13d@- Resolves: #2175871 - Avoid to hang the process with SIGUSR1 signal_@c_8Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks?m8Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows>m8Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionz=k8Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()<k8Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows
zrv|zzIk9Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()Hk9Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspGky9Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.poFk9Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathEk9Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL barqDk{9Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-4\O- Resolves: #1693926 - Commit hangul preedit with mouse
Ck+9Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-3\@- Resolves: #1671187 - ibus.conf does not set QT_IM_MODULE with qt5 ibus module
|Pk:Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspOky:Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.poNk:Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathMk:Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar_Lc_9Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaksKm9Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsJm9Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regression
y
Wk+;Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-3\@- Resolves: #1671187 - ibus.conf does not set QT_IM_MODULE with qt5 ibus module}Vm:Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-14d8- Resolves: #2175871 - Update ibus-2175871-x11-Xephyr-query.patchUm:Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-13d@- Resolves: #2175871 - Avoid to hang the process with SIGUSR1 signal_Tc_:Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaksSm:Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsRm:Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionzQk:Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()
}
^m;Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionz]k;Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()\k;Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsp[ky;Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.poZk;Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathYk;Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL barqXk{;Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-4\O- Resolves: #1693926 - Commit hangul preedit with mouse
zpeky<Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.podk<Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathck<Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL barqbk{<Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-4\O- Resolves: #1693926 - Commit hangul preedit with mouse
ak+<Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-3\@- Resolves: #1671187 - ibus.conf does not set QT_IM_MODULE with qt5 ibus module_`c_;Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks_m;Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows

er+V:eDH
982b829b97c5eb8400e883ee7e5cd1199ec463fe88265cc6be5560667a3366eeDG
a22140d2598b1d94d1cef9f4d960ba6d9726634bd9bec4682f6338583e5bedbeDF
449b85f4d50008df3b5663b39feaa09ec5df8f99f0a2327e0e8e846345963022DE
f74f11e10a148e5f0fa3445db786553e080cb5d020e255c3b688dfd528ab6f2cDD
c3b0298c3bbfa69481b4841885e4c53580433e8d4610ea22939be12d797bd88aDC
7690f944ed218f74b3624308e1a4d4ddbbef310d2d09257774fdfdadf5cd3916DB
9550ba6de8671ca79fa26dead08e944ef94706fde1c73e99c2c59e595b752061DA
7a99b195e228185309513ea38f47665d85c3f48be1efc08b2131eebb4af1771cD@
476abb9c019d06d8fbb8b7d20433405022b208c2c777b1de0c036fff3108fc7eD?
b1f22640d57b95b5f307687ba9cae4a938f5332030e06b6e6ade62170f059a4fD>
faf21678af2663e54fcc8f5016f8bcab54c797e4a2817cccba232b0e673d3370D=
4c96449444e550b77b9d63a86b708d50e9b146f62a64f89fbfce2abfa49c871fD<
1b1b3c99c21402de3620ed1fecbd44518682eccd70866a5c3c361b33f649f188
{z
lk=Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathkk=Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar_jc_<Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaksim<Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowshm<Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionzgk<Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()fk<Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows
}tm=Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-14d8- Resolves: #2175871 - Update ibus-2175871-x11-Xephyr-query.patchsm=Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-13d@- Resolves: #2175871 - Avoid to hang the process with SIGUSR1 signal_rc_=Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaksqm=Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspm=Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionzok=Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()nk=Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspmky=Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.po
rx~|r{m>Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowszm>Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionzyk>Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()xk>Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspwky>Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.povk>Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathuk>Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar
k?Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathk?Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL barqk{?Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-4\O- Resolves: #1693926 - Commit hangul preedit with mouse
k+?Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-3\@- Resolves: #1671187 - ibus.conf does not set QT_IM_MODULE with qt5 ibus module}~m>Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-14d8- Resolves: #2175871 - Update ibus-2175871-x11-Xephyr-query.patch}m>Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-13d@- Resolves: #2175871 - Avoid to hang the process with SIGUSR1 signal_|c_>Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks
q
k{@Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-4\O- Resolves: #1693926 - Commit hangul preedit with mouse
	k+@Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-3\@- Resolves: #1671187 - ibus.conf does not set QT_IM_MODULE with qt5 ibus module_c_?Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaksm?Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsm?Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionzk?Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()k?Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspky?Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.po
rx~|rm@Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsm@Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionzk@Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()k@Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsp
ky@Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.pok@Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathk@Takao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar
mATakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionzkATakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()kATakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspkyATakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.pokATakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathkATakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar_c_@Ray Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks
zpkyBTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.pokBTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathkBTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar}mATakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-14d8- Resolves: #2175871 - Update ibus-2175871-x11-Xephyr-query.patchmATakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-13d@- Resolves: #2175871 - Avoid to hang the process with SIGUSR1 signal_c_ARay Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaksmATakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows
{z}&mBTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-14d8- Resolves: #2175871 - Update ibus-2175871-x11-Xephyr-query.patch%mBTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-13d@- Resolves: #2175871 - Avoid to hang the process with SIGUSR1 signal_$c_BRay Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks#mBTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows"mBTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionz!kBTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid() kBTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows
zrv|zz-kCTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid(),kCTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsp+kyCTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.po*kCTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's death)kCTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL barq(k{CTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-4\O- Resolves: #1693926 - Commit hangul preedit with mouse
'k+CTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-3\@- Resolves: #1671187 - ibus.conf does not set QT_IM_MODULE with qt5 ibus module
|
4kDTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's death3kDTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL barq2k{DTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-4\O- Resolves: #1693926 - Commit hangul preedit with mouse
1k+DTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-3\@- Resolves: #1671187 - ibus.conf does not set QT_IM_MODULE with qt5 ibus module_0c_CRay Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks/mCTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows.mCTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regression
;kETakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar_:c_DRay Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks9mDTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows8mDTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionz7kDTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()6kDTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsp5kyDTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.po
y_Bc_ERay Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaksAmETakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows@mETakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionz?kETakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()>kETakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsp=kyETakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.po<kETakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's death
x|tzxzIkFTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()HkFTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspGkyFTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.poFkFTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathEkFTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar}DmETakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-14d8- Resolves: #2175871 - Update ibus-2175871-x11-Xephyr-query.patchCmETakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-13d@- Resolves: #2175871 - Avoid to hang the process with SIGUSR1 signal
|qPk{GTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-4\O- Resolves: #1693926 - Commit hangul preedit with mouse
Ok+GTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-3\@- Resolves: #1671187 - ibus.conf does not set QT_IM_MODULE with qt5 ibus module}NmFTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-14d8- Resolves: #2175871 - Update ibus-2175871-x11-Xephyr-query.patchMmFTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-13d@- Resolves: #2175871 - Avoid to hang the process with SIGUSR1 signal_Lc_FRay Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaksKmFTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsJmFTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regression
rx~|rWmGTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsVmGTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionzUkGTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()TkGTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspSkyGTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.poRkGTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathQkGTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar
^mHTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionz]kHTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()\kHTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsp[kyHTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.poZkHTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathYkHTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar_Xc_GRay Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks
zekITakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL barqdk{ITakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-4\O- Resolves: #1693926 - Commit hangul preedit with mouse
ck+ITakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-3\@- Resolves: #1671187 - ibus.conf does not set QT_IM_MODULE with qt5 ibus module}bmHTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-14d8- Resolves: #2175871 - Update ibus-2175871-x11-Xephyr-query.patchamHTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-13d@- Resolves: #2175871 - Avoid to hang the process with SIGUSR1 signal_`c_HRay Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leaks_mHTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allows

er+V:eDU
2c9b86ff8b1784c1b3fe907125539409c664ed05d051c38e8a810200fe93b330DT
d7aa835b93bc87305149d24877aa4eb93af26e9c534bda18564bb0727392139cDS
2aa53317687b50178bded94e1bdf4d35e70e1210e700ac30dff774aab3e3736bDR
a01dae3f1eb932f0bc862e5f5466508b803a3d1c7bbc6b989e42cef1534de0e3DQ
488103f93db3517ddb11caa529814abccd07f454858bec9681eec8375c544207DP
f24fba7955a7d873bfbd39bae28a5c850f2c27928e1cd98d54264fe51a7d4befDO
ff13cc6851b7555532b91dc5f8a9c7b73fb8f47f0f39be06ad101f6250c679c5DN
e9ccc19a3fa831005a0f5568fdabe7c13acd32de915df5fe49983a0214fb34d3DM
d4c752f14b919fcec87f8f21c7401dc7c9b2ceb39af9d43b03be700c06316653DL
32a6e9291813e4daadd971db10a8925ff8233160eb5a5a4fb45d5590f18f2893DK
78d39bca758e7f5e4b5122c075cbb2a2c1d8ab9c258b4f91f4744f9ff29a5e8dDJ
892bbb9cf85d74f25b2bd5cf3702f0da63f86e4093b201704e571b7d86a65f14DI
66fc4721d3b2689eac33494f18ab2cf85d9ee8d1dd8532c964f11eeff008e9f1
y_lc_IRay Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leakskmITakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsjmITakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionzikITakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()hkITakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspgkyITakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.pofkITakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's death
rx~|rsmJTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-11^H- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowsrmJTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-10^@- Resolves: #1777369 - Revert ibus CVE fix because of Qt5 regressionzqkJTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-9]4@- Resolves: #1750835 - Delete duplicated g_dbus_generate_guid()pkJTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-8]@- Resolves: #1750835 - Fix CVE-2019-14822 missing authorization allowspokyJTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-7]M`@- Resolves: #1686913 - Fix rpmdiff inspection in ko.ponkJTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-6]Ik- Resolves: #1686913 - ibus-daemon always will exits with parent's deathmkJTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-5\s@- Resolves: #1693926 - Commit hangul preedit with clicking out of URL bar
+fbyYoKJiri Vanek <jvanek@redhat.com> 1.6.2-4W~- fixed typo in provides
- Resolves: rhbz#1299537AxY+KJiri Vanek <jvanek@redhat.com> 1.6.2-3W-@- added --family to make it part of javas alternatives alignment
- java-javaver-openjdk collected into preffered_java 
- Resolves: rhbz#1299537NwYEKJiri Vanek <jvanek@redhat.com> 1.6.2-1V- updated to 1.6.2
- fixed also rhbz#1303437 - packagp}vmJTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-14d8- Resolves: #2175871 - Update ibus-2175871-x11-Xephyr-query.patchumJTakao Fujiwara <tfujiwar@redhat.com> - 1.5.17-13d@- Resolves: #2175871 - Avoid to hang the process with SIGUSR1 signal_tc_JRay Strode <rstrode@redhat.com> - 1.5.17-12_@- Resolves: #1882009 - Fix GVariant leakse owns /etc/bash_completion.d but it should not own it 
- generated maven metadata (isntalled but not used. 
set -e 
   _pompart="need" 
   _jarpart="tobe" 
_filelist=".mfiles" 
install -dm 755 /builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64/usr/share/maven-fragments 
for _dir in /usr/lib/java %{_javajnidir} /usr/share/java; do 
    if [ -f /builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64$_dir/$_jarpart ]; then 
	_jpath="/builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64$_dir/$_jarpart" 
    fi 
done 
python -m /usr/share/java-utils/maven_depmap   \
          -p "/usr" -n "" \
          /builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64/usr/share/maven-fragments/icedtea-web \
          /builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64/usr/share/maven-poms/$_pompart \
        >> ${_filelist} 
sed -i 's:/builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64::' ${_filelist} 
sort -u -o ${_filelist} ${_filelist} 


- Resolves: rhbz#1299537
Y}Y]KJiri Vanek <jvanek@redhat.com> 1.7.1-1Z7* bump to 1.7.1
- Resolves: rhbz#1475411|U/KJiri Vanek <jvanek@redhat.com> 1.7-3YZ@- javaws specific manpage renmed from -suffix to .suffix
- Resolves: rhbz#1475411q{UKJiri Vanek <jvanek@redhat.com> 1.7-2YBA- gathered various patches from usptream
- Resolves: rhbz#1475411gzU{KJiri Vanek <jvanek@redhat.com> 1.7-1YB@- updated to itw 1.7 and sync from fedora
- added forgotten slaves of itweb-settings policyeditor
- Own %{_datadir}/%{name} dir
- Mark non-English man pages with %lang
- Install COPYING as %license
- last three by Ville Skytta <ville.skytta@iki.fi> via 1481270
- for sake of rpms added patch0, bashCompDirHardcodedAgain.patch to hardcode bashcompletion dir
- removed maven macros in favour of manual handling (bug)
- Resolves: rhbz#1475411
(ZR(bYoLJiri Vanek <jvanek@redhat.com> 1.6.2-4W~- fixed typo in provides
- Resolves: rhbz#1299537AY+LJiri Vanek <jvanek@redhat.com> 1.6.2-3W-@- added --family to make it part of javas alternatives alignment
- java-javaver-openjdk collected into preffered_java 
- Resolves: rhbz#1299537NYELJiri Vanek <jvanek@redhat.com> 1.6.2-1V- updated to 1.6.2
- fixed also rhbz#1303437 - packagsYSKJiri Vanek <jvanek@redhat.com> 1.7.1-4_- Added Patch6, altjava.patch to make usage of alt-java prefferd over java
- Resolves: rhbz#1901639YKKJiri Vanek <jvanek@redhat.com> 1.7.1-3]0_A- Added Patch5, testTuning.patch to make tests pass inclean envirnment
- Resolves: rhbz#1724958
~YCKJiri Vanek <jvanek@redhat.com> 1.7.1-2]0_@- added patch1, patch4 and patch11 to fix CVE-2019-10182
- added patch2 to fix CVE-2019-10181
- added patch3 and patch33 to fix CVE-2019-10185
- Resolves: rhbz#1724958 
- Resolves: rhbz#1725928 
- Resolves: rhbz#1724989e owns /etc/bash_completion.d but it should not own it 
- generated maven metadata (isntalled but not used. 
set -e 
   _pompart="need" 
   _jarpart="tobe" 
_filelist=".mfiles" 
install -dm 755 /builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64/usr/share/maven-fragments 
for _dir in /usr/lib/java %{_javajnidir} /usr/share/java; do 
    if [ -f /builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64$_dir/$_jarpart ]; then 
	_jpath="/builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64$_dir/$_jarpart" 
    fi 
done 
python -m /usr/share/java-utils/maven_depmap   \
          -p "/usr" -n "" \
          /builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64/usr/share/maven-fragments/icedtea-web \
          /builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64/usr/share/maven-poms/$_pompart \
        >> ${_filelist} 
sed -i 's:/builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64::' ${_filelist} 
sort -u -o ${_filelist} ${_filelist} 


- Resolves: rhbz#1299537
YY]LJiri Vanek <jvanek@redhat.com> 1.7.1-1Z7* bump to 1.7.1
- Resolves: rhbz#1475411U/LJiri Vanek <jvanek@redhat.com> 1.7-3YZ@- javaws specific manpage renmed from -suffix to .suffix
- Resolves: rhbz#1475411qULJiri Vanek <jvanek@redhat.com> 1.7-2YBA- gathered various patches from usptream
- Resolves: rhbz#1475411gU{LJiri Vanek <jvanek@redhat.com> 1.7-1YB@- updated to itw 1.7 and sync from fedora
- added forgotten slaves of itweb-settings policyeditor
- Own %{_datadir}/%{name} dir
- Mark non-English man pages with %lang
- Install COPYING as %license
- last three by Ville Skytta <ville.skytta@iki.fi> via 1481270
- for sake of rpms added patch0, bashCompDirHardcodedAgain.patch to hardcode bashcompletion dir
- removed maven macros in favour of manual handling (bug)
- Resolves: rhbz#1475411
(ZR(b
YoMJiri Vanek <jvanek@redhat.com> 1.6.2-4W~- fixed typo in provides
- Resolves: rhbz#1299537AY+MJiri Vanek <jvanek@redhat.com> 1.6.2-3W-@- added --family to make it part of javas alternatives alignment
- java-javaver-openjdk collected into preffered_java 
- Resolves: rhbz#1299537NYEMJiri Vanek <jvanek@redhat.com> 1.6.2-1V- updated to 1.6.2
- fixed also rhbz#1303437 - packagv
YSLJiri Vanek <jvanek@redhat.com> 1.7.1-4_- Added Patch6, altjava.patch to make usage of alt-java prefferd over java
- Resolves: rhbz#1901639	YKLJiri Vanek <jvanek@redhat.com> 1.7.1-3]0_A- Added Patch5, testTuning.patch to make tests pass inclean envirnment
- Resolves: rhbz#1724958
YCLJiri Vanek <jvanek@redhat.com> 1.7.1-2]0_@- added patch1, patch4 and patch11 to fix CVE-2019-10182
- added patch2 to fix CVE-2019-10181
- added patch3 and patch33 to fix CVE-2019-10185
- Resolves: rhbz#1724958 
- Resolves: rhbz#1725928 
- Resolves: rhbz#1724989e owns /etc/bash_completion.d but it should not own it 
- generated maven metadata (isntalled but not used. 
set -e 
   _pompart="need" 
   _jarpart="tobe" 
_filelist=".mfiles" 
install -dm 755 /builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64/usr/share/maven-fragments 
for _dir in /usr/lib/java %{_javajnidir} /usr/share/java; do 
    if [ -f /builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64$_dir/$_jarpart ]; then 
	_jpath="/builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64$_dir/$_jarpart" 
    fi 
done 
python -m /usr/share/java-utils/maven_depmap   \
          -p "/usr" -n "" \
          /builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64/usr/share/maven-fragments/icedtea-web \
          /builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64/usr/share/maven-poms/$_pompart \
        >> ${_filelist} 
sed -i 's:/builddir/build/BUILDROOT/icedtea-web-1.7.1-4.el7_9.x86_64::' ${_filelist} 
sort -u -o ${_filelist} ${_filelist} 


- Resolves: rhbz#1299537
YY]MJiri Vanek <jvanek@redhat.com> 1.7.1-1Z7* bump to 1.7.1
- Resolves: rhbz#1475411U/MJiri Vanek <jvanek@redhat.com> 1.7-3YZ@- javaws specific manpage renmed from -suffix to .suffix
- Resolves: rhbz#1475411qUMJiri Vanek <jvanek@redhat.com> 1.7-2YBA- gathered various patches from usptream
- Resolves: rhbz#1475411gU{MJiri Vanek <jvanek@redhat.com> 1.7-1YB@- updated to itw 1.7 and sync from fedora
- added forgotten slaves of itweb-settings policyeditor
- Own %{_datadir}/%{name} dir
- Mark non-English man pages with %lang
- Install COPYING as %license
- last three by Ville Skytta <ville.skytta@iki.fi> via 1481270
- for sake of rpms added patch0, bashCompDirHardcodedAgain.patch to hardcode bashcompletion dir
- removed maven macros in favour of manual handling (bug)
- Resolves: rhbz#1475411
4Z4{NDavid Kaspar [Dee'Kej] <dkaspar@redhat.com> - 9.49.46-1[@- ifup-post: fix incorrect condition for RESOLV_MODS (bug #1610411){NDavid Kaspar [Dee'Kej] <dkaspar@redhat.com> - 9.49.45-1[W- network: parsing of /proc/mounts returned (bug #1572659)
- netconsole: LSB header added (bug #1508489)
- ifdown-eth: no longer needed 'pidof -x dhclient' condition removed (bug #1559384)YSMJiri Vanek <jvanek@redhat.com> 1.7.1-4_- Added Patch6, altjava.patch to make usage of alt-java prefferd over java
- Resolves: rhbz#1901639YKMJiri Vanek <jvanek@redhat.com> 1.7.1-3]0_A- Added Patch5, testTuning.patch to make tests pass inclean envirnment
- Resolves: rhbz#1724958
YCMJiri Vanek <jvanek@redhat.com> 1.7.1-2]0_@- added patch1, patch4 and patch11 to fix CVE-2019-10182
- added patch2 to fix CVE-2019-10181
- added patch3 and patch33 to fix CVE-2019-10185
- Resolves: rhbz#1724958 
- Resolves: rhbz#1725928 
- Resolves: rhbz#1724989
+&+caiNJan Macku <jamacku@redhat.com> - 9.49.53-1^Ǿ- rwtab: Add support for chrony (bug #1838260)aCNJan Macku <jamacku@redhat.con> - 9.49.52-1^x- ifup-eth: Switch to bc utility, which supports floating point computations (bug #1609687)ZaWNJan Macku <jamacku@redhat.com> - 9.49.51-1^r
@- Fix inline comment - (bug #1773798)aCNJan Macku <jamacku@redhat.com> - 9.49.50-1^h- Wait for scope link addresses as well as for scope global addresses - ipv6 (bug #1773798)a]NJan Macku <jamacku@redhat.com> - 9.49.49-1]Z@- ifup-eth: Check that device name is set (bug #1741830)
- Add option for IPv6 GRE tunnel (bug #1691552)aacNJan Macku <jamacku@redhat.com> - 9.49.48-1]Ik- network: don't fail with IFDOWN_ON_SHUTDOWN (bug #1693977)
- Configure autorelabel service to output to journal and to console if set (bug #1634661)
- Fix changelog typo^a_NJan Macku <jamacku@redhat.com> - 9.49.47-1\- Fix file permissions for /var/log/dmesg
}OFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1nqoNJan Macku <jamacku@redhat.com> - 9.49.53-1.el7_9.1_- rwtab: Allow updating mlocate.db (bug #1880095)
YY ";OFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o|}!}OFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv }qOFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|$uOFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm#UOFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
ly'kOFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\&3OFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ%OFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
&'&}*}PFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv)}qPFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issue\(}?OCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.10a*@- Roll in CentOS Brandingther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
dd|-uPFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm,UPFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. +;PFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
ly0kPFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\/3PFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ.PFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
ww 4;QFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}3}QFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offset\2}?PCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.11b@- Roll in CentOS Brandingy1kPFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|6uQFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm5UQFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
ly9kQFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\83QFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ7QFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
\<}?QCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.12cb[- Roll in CentOS Branding|;qQFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginy:kQFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
dd|?uRFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm>URFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. =;RFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
lyBkRFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\A3RFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ@RFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|DqRFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginyCkRFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
aF;RFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configVE%RFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
|HuSFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmGUSFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
lyKkSFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\J3SFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differISFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|MqSFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginyLkSFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
88PSFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakaO;SFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configVN%SFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
lySkTFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\R3TFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differQTFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|UqTFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginyTkTFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
Z8Z\Z}?TCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.16e- Roll in CentOS Branding|YsTFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protectionXTFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakaW;TFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configVV%TFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
 y]kUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy\kUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\[3UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ
V_%UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|^qUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
W\d}?UCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.17ff- Roll in CentOS Branding8cw{UJulien Rische <jrische@redhat.com> - 4.6.8-5.el7_9.17f_- Resolves: RHEL-29926 ipa: user can obtain a hash of the passwords of all domain users and perform offline brute force|bsUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protectionaUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka`;UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config

er+V:eDb
5eee4ed6f4cdcbe1b9de452b76bc924f965eab492a06b0b7f5bb0bbb156d824fDa
c59e261df9c78880ac906231fc2cce51d269a2a4bdd58d5cccea75abe0465c0bD`
558dc0f83e3862c9b965afa5b391a230262f95f6a63563d97c9110ca4deccd16D_
d91d835f435d138d7db35fab1aba38aaba2d467d57ccdc15593e6e37665d9e9dD^
0c844b3fd55943ad6df491c0f9396667119e7d8f737d079ca70e1e354c04d769D]
7dfa4db17abc05d6bf097a9695e02d8f0889d219fe48c90d147cef40ee6a34e0D\
833dc73a5ec23e1c5d73db93091846da2a990c4c750e903a4a09f3a61282dab0D[
779491f4aff62cb66747a794b7b823e9645eed730e157ff87a8425bfd96871c9DZ
509cf9ac14798ddb50f8710817ee91492ef1e1b1a27d3921e30b5434858dc294DY
8b49fbdabac5e8dd32d8de8826af7fee4b0eeab0828f5ad71004efba08ce1b40DX
74fb87c43d42d2e134909edffc5d2d759fa9ac176e342697b6d590d62ca8a11fDW
2310b0e53fdf17749832f558cf06510e127435a1cce7658a84665de1bf9fa2e7DV
08dfe3130e723092bcc8145c8b90e71cc35804a68abc5879143350368fece38b
XXgVFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipaPf#VFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agentsaeEVFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-10.el7]- Resolves: #1728123 - EMBARGOED CVE-2019-10195 ipa: FreeIPA: batch API logging user passwords to /var/log/httpd/error_log [rhel-7]
  - CVE-2019-10195: Don't log passwords embedded in commands in calls using batch
- Resolves: #1773550 - IPA upgrade fails for latest ipa package when adtrust is installed
  - Do not run trust upgrade code if master lacks Samba bindings
- Resolves: #1767302 - EMBARGOED CVE-2019-14867 ipa: Denial of service in IPA server due to wrong use of ber_scanf() [rhel-7.8]
  - Make sure to have storage space for tag-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


oh}cVFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!i}GVFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}j}VFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY m;VFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}l}VFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvk}qVFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
__pWFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipaPo#WFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agents[n{?VCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.4`P- Roll in CentOS Branding-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


oq}cWFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!r}GWFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}s}WFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY v;WFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}u}WFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvt}qWFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
BByXFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa[x{?WCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.5`- Roll in CentOS BrandingmwUWFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


oz}cXFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!{}GXFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}|}XFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY ;XFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}~}XFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}}qXFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
22[{?XCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.6`[- Roll in CentOS Branding|uXFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUXFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.


o}cYFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!}GYFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}}YFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY ;YFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}}YFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qYFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|
uYFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm	UYFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
l!
}GZFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords[{?YCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.7`- Roll in CentOS BrandingYFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
}}}ZFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY ;ZFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}}ZFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qZFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|uZFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUZFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
.l.[{?ZCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.9aex- Roll in CentOS Branding\3ZFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differZFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
}}}[Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY ;[Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}}[Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}q[Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|u[Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmU[Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
lyk[Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\3[Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ[Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
&'&}"}\Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv!}q\Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issue\ }?[CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.10a*@- Roll in CentOS Brandingther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
dd|%u\Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm$U\Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. #;\Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
ly(k\Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\'3\Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ&\Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
ww ,;]Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by oˁ}+}]Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offset\*}?\CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.11b@- Roll in CentOS Brandingy)k\Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupof
!flrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|DFHKMPSUZ]_dghijmpqrsvyz{|

"%(,.147:<>@CEHKMRUW\_`abehijknqrstwz{|}



	








 
$
&
)
,
/
2
4
6
8
;
=
@
C
E
 Jther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|.u]Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm-U]Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
ly1k]Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\03]Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ/]Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
\4}?]CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.12cb[- Roll in CentOS Branding|3q]Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginy2k]Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
dd|7u^Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm6U^Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. 5;^Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
ly:k^Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\93^Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ8^Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|<q^Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginy;k^Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
a>;^Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configV=%^Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
|@u_Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm?U_Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
lyCk_Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\B3_Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differA_Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|Eq_Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginyDk_Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
88H_Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakaG;_Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configVF%_Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
lyKk`Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\J3`Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differI`Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|Mq`Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginyLk`Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
Z8Z\R}?`CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.16e- Roll in CentOS Branding|Qs`Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protectionP`Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakaO;`Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configVN%`Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
 yUkaFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyTkaFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\S3aFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ
VW%aFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|VqaFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
W\\}?aCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.17ff- Roll in CentOS Branding8[w{aJulien Rische <jrische@redhat.com> - 4.6.8-5.el7_9.17f_- Resolves: RHEL-29926 ipa: user can obtain a hash of the passwords of all domain users and perform offline brute force|ZsaFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protectionYaFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakaX;aFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
XX_bFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa߁P^#bFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agentsa]EbFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-10.el7]- Resolves: #1728123 - EMBARGOED CVE-2019-10195 ipa: FreeIPA: batch API logging user passwords to /var/log/httpd/error_log [rhel-7]
  - CVE-2019-10195: Don't log passwords embedded in commands in calls using batch
- Resolves: #1773550 - IPA upgrade fails for latest ipa package when adtrust is installed
  - Do not run trust upgrade code if master lacks Samba bindings
- Resolves: #1767302 - EMBARGOED CVE-2019-14867 ipa: Denial of service in IPA server due to wrong use of ber_scanf() [rhel-7.8]
  - Make sure to have storage space for tag-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


o`}cbFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!a}GbFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}b}bFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY e;bFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}d}bFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvc}qbFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
__hcFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipaPg#cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agents[f{?bCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.4`P- Roll in CentOS Branding

er+V:eDo
96d4abfe67bd7a9d955276cf0a4e0987e05c018e86c09903e0f0417e753e77acDn
8087b4408319998ae1d6b166c84ecab64a54cea6ca23c0fa10d0108446ac99c1Dm
e7250202a7c16893d5954675d11df0fab80808b7c4c5c285328f1c4315027ceeDl
017eff95084da1072645aceed55c7d64fe45d437ca48fa5ec6446759047a4d0dDk
708df0316ccfbaa7713f5cc4d0174450936ff711924ac55e5527b630498ef3d4Dj
a7f79e36bdad845ee95ab0dcf81c2ac21d35da133b48c0cb448fbd6f1f3a5ceaDi
acedb410f50fe7ddd7938fec4bc88806e9f316f2c58569efa76c504f5ef11916Dh
4206286662c3bca7d5dec45b6571835c5c580374921fcc382635bbf1caddac77Dg
9a646552f12a087de4493fe8a4dfec0a5fb87521f568758c6136443c9644c22fDf
8089409b82d6904e6a2853e0d520b54e8935468e99ddd4cec8394dcee0e731d7De
bbc75e7ebe20ce9f9b3a0c5ed5ebce0ec757c6a71b928408b3219bb857294882Dd
f07e21fd43e16c0797d167891e1f8dd87c7bcf4ac4177307aec21e25a55ece03Dc
ef279f239f0fe62929c62165d00a4076c51667ba82c640a3790df88dfa67ffa1-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


oi}ccFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!j}GcFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}k}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY n;cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}m}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvl}qcFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
BBqdFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa[p{?cCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.5`- Roll in CentOS BrandingmoUcFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


or}cdFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!s}GdFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}t}dFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY w;dFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}v}dFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvu}qdFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
22[z{?dCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.6`[- Roll in CentOS Branding|yudFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmxUdFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.


o{}ceFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!|}GeFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}}}eFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY ;eFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}}eFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv~}qeFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|ueFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUeFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
l!}GfFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords[{?eCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.7`- Roll in CentOS BrandingeFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
}}}fFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY 	;fFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
}}fFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qfFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|ufFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm
UfFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
.l.[{?fCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.9aex- Roll in CentOS Branding\
3fFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differfFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
}}}gFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY ;gFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
	}}gFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qgFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|ugFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUgFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
lykgFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\3gFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differgFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
&'&}}hFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qhFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issue\}?gCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.10a*@- Roll in CentOS Brandingther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
dd|uhFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUhFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. ;hFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o


ly khFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\3hFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differhFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
ww $;iFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
}#}iFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offset\"}?hCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.11b@- Roll in CentOS Brandingy!khFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|&uiFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm%UiFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
ly)kiFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\(3iFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ'iFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
\,}?iCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.12cb[- Roll in CentOS Branding|+qiFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginy*kiFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
dd|/ujFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm.UjFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. -;jFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o

ly2kjFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\13jFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ0jFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|4qjFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginy3kjFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
a6;jFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configV5%jFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
|8ukFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm7UkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
ly;kkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\:3kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ9kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|=qkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginy<kkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
88@kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka?;kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configV>%kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
lyCklFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\B3lFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differAlFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|EqlFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginyDklFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
Z8Z\J}?lCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.16e- Roll in CentOS Branding|IslFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protectionHlFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakaG;lFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configVF%lFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
 yMkmFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyLkmFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\K3mFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ
VO%mFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|NqmFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
W\T}?mCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.17ff- Roll in CentOS Branding8Sw{mJulien Rische <jrische@redhat.com> - 4.6.8-5.el7_9.17f_- Resolves: RHEL-29926 ipa: user can obtain a hash of the passwords of all domain users and perform offline brute force|RsmFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protectionQmFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakaP;mFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
XXWnFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa
%PV#nFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agentsaUEnFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-10.el7]- Resolves: #1728123 - EMBARGOED CVE-2019-10195 ipa: FreeIPA: batch API logging user passwords to /var/log/httpd/error_log [rhel-7]
  - CVE-2019-10195: Don't log passwords embedded in commands in calls using batch
- Resolves: #1773550 - IPA upgrade fails for latest ipa package when adtrust is installed
  - Do not run trust upgrade code if master lacks Samba bindings
- Resolves: #1767302 - EMBARGOED CVE-2019-14867 ipa: Denial of service in IPA server due to wrong use of ber_scanf() [rhel-7.8]
  - Make sure to have storage space for tag
&-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss
'd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


oX}cnFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!Y}GnFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}Z}nFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY ];nFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
,}\}nFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv[}qnFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
__`oFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa
.P_#oFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agents[^{?nCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.4`P- Roll in CentOS Branding
/-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss
0d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


oa}coFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!b}GoFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}c}oFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY f;oFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
5}e}oFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvd}qoFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
BBipFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa
8[h{?oCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.5`- Roll in CentOS BrandingmgUoFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.

er+V:eD|
951d300e30de3f44fa83fea5bff378fb53589245060530b325e00fa9f6c7f5d3D{
13e6e0aca27ac928a13a8392353c51dcc310d1458f84cf2c8811620996c73fc2Dz
065be8dcad1accb013d907c343f946bf2aee0c7ebe74cc8d43c80d008e10fed5Dy
d2df50179ec4ae53b3b02398bb8ed1d376fddb157a0b2c4996e0c09559793409Dx
3268859dec4857e91df2b98be2c4c1039a81c1208032d1627ffafee642953fc2Dw
9fe30f8f94bda5cdd5390de29d8a6c4c8f6dbbb9aeec90fb2dbf9da761d3e515Dv
9277a339164ce4554d7e44a5274d72e8acdef0f65c7e2f5ae1558953312edbfcDu
f3480d9490430ccdec35a8db1fdcd4f48fc92476fd17dea7b616fd9995372e88Dt
6fc0812fc250d841a58cd125c88d60ba6c53d4c751c3c985ba925f28e597e5adDs
47f19899e75c7c9a5b74f30643d69d0ccff2cf5451546d7ad1a727bccaaf0ea4Dr
ceba479b3f7e61b1f98d50e4797543b538d563b420b419155fedeead08a06b2eDq
d2db9132b158642ca3acdce95a3018565ff05f4497c6fa76140e7a98a3a959f3Dp
3bc9984dc4e0e90245e74d760cf04b6707669b3289dc3e70c040cdfde4d44319
9-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss
:d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


oj}cpFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!k}GpFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}l}pFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY o;pFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
?}n}pFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvm}qpFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
22[r{?pCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.6`[- Roll in CentOS Branding|qupFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmpUpFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.


os}cqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!t}GqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}u}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY x;qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
E}w}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvv}qqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|zuqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmyUqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
l!}}GrFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords[|{?qCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.7`- Roll in CentOS Branding{qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
}}~}rFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY ;rFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
J}}rFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qrFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|urFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUrFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
.l.[{?rCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.9aex- Roll in CentOS Branding\3rFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differrFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
}}}sFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY 
;sFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
O}	}sFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qsFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|usFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUsFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
lyksFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\3sFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ
sFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
&'&}}tFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qtFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issue\}?sCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.10a*@- Roll in CentOS Brandingther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
dd|utFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUtFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. ;tFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
S
lyktFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\3tFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differtFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
ww ;uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
W}}uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offset\}?tCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.11b@- Roll in CentOS BrandingyktFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|uuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
ly!kuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\ 3uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
\$}?uCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.12cb[- Roll in CentOS Branding|#quFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginy"kuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
dd|'uvFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm&UvFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. %;vFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
[
ly*kvFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\)3vFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ(vFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|,qvFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginy+kvFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
a.;vFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configV-%vFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
|0uwFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm/UwFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
ly3kwFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\23wFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ1wFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|5qwFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginy4kwFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupof
flrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|
"O
#T
$W
(X
)Y
*Z
+]
-`
1a
2b
3c
4f
6i
;j
<k
=l
>o
@r
As
Bt
Cu
Dx
Fz
G}
H~
I
K
L
M
N

P
Q
R
T
U
V
X
Y!
Z$
\'
]*
^,
_.
`0
a3
b5
d8
e;
f=
gB
hE
iG
jL
kO
oP
pQ
qR
rU
tX
xY
yZ
z[
{^
}a
b
c
d
g
j
k
l
m
p
r
u
v
y
{
~













"
$
&
(
+
-
0
3
5
:
=
?
D
G
H
I
J
M
P
Q
888wFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka7;wFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configV6%wFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
ly;kxFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\:3xFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ9xFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|=qxFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginy<kxFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
Z8Z\B}?xCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.16e- Roll in CentOS Branding|AsxFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protection@xFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka?;xFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configV>%xFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
 yEkyFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyDkyFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\C3yFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ
VG%yFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|FqyFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
W\L}?yCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.17ff- Roll in CentOS Branding8Kw{yJulien Rische <jrische@redhat.com> - 4.6.8-5.el7_9.17f_- Resolves: RHEL-29926 ipa: user can obtain a hash of the passwords of all domain users and perform offline brute force|JsyFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protectionIyFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakaH;yFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
XXOzFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa
lPN#zFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agentsaMEzFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-10.el7]- Resolves: #1728123 - EMBARGOED CVE-2019-10195 ipa: FreeIPA: batch API logging user passwords to /var/log/httpd/error_log [rhel-7]
  - CVE-2019-10195: Don't log passwords embedded in commands in calls using batch
- Resolves: #1773550 - IPA upgrade fails for latest ipa package when adtrust is installed
  - Do not run trust upgrade code if master lacks Samba bindings
- Resolves: #1767302 - EMBARGOED CVE-2019-14867 ipa: Denial of service in IPA server due to wrong use of ber_scanf() [rhel-7.8]
  - Make sure to have storage space for tag
m-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss
nd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


oP}czFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!Q}GzFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}R}zFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY U;zFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
s}T}zFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvS}qzFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
__X{Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa
uPW#{Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agents[V{?zCentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.4`P- Roll in CentOS Branding
v-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss
wd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


oY}c{Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!Z}G{Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}[}{Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY ^;{Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
|}]}{Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv\}q{Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
BBa|Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa
~[`{?{CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.5`- Roll in CentOS Brandingm_U{Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss
d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


ob}c|Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!c}G|Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}d}|Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY g;|Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
}f}|Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetve}q|Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
22[j{?|CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.6`[- Roll in CentOS Branding|iu|Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmhU|Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.

er+V:eD	
26057397691d0e4487c2c746c43e15367dce434090f9495b535dab7657e51a9cD
0720c43c680146e7a676c6340d3f1529fb116ef0c12105b5b84f41a448512564D
44df7609ed5e477add5d58e49530bb036fc2ff1d94098c85b2111eeb85a31168D
0b22b530fe470f3e466de0b4c9a662510b4feffc3540c2add9689e58fe543a56D
e8fcf04ec6289d6ed5e26623877c40ac8ff5d22653e6acfb45465877e4ff0dc5D
46014250185344e990623d8284713f5bcea7006c7779fc959f7da3d39032c89bD
addcd00db9e64f493d8286287e758d561f51abb09ce1ba2dd73f4b708c60e866D
cd7ab4d402e24250450215dd316bc8db5cbabc2abdaf16110521f6e623589deaD
95ca57f8286ce2eaacee848405bb95f1e3ae571def5526f34c8d1abdb873b30cD
c3063c4a546358bcf8640da753ea13f90ccbb18da78588f7c8a9b3011eccfd55D
ac419246df9921713ed1c65bf7621fa6b5266999545f33a73aab328bcd38d3f0D~
7bfce38ec77185d1696e388cecf4163509c7884933ded369897a1fcf77610b49D}
da1dc98d83517de259389f28cb15535a0c5b895342f95881d9cdb88529401e7a


ok}c}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!l}G}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}m}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY p;}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
}o}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvn}q}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|ru}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmqU}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
l!u}G~Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords[t{?}CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.7`- Roll in CentOS Brandings}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
}}v}~Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY y;~Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
}x}~Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvw}q~Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|{u~Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmzU~Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
.l.[~{?~CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.9aex- Roll in CentOS Branding\}3~Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ|~Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
}}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
lykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
&'&}
}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv	}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issue\}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.10a*@- Roll in CentOS Brandingther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
dd|
uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o

lykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
ww ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offset\}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.11b@- Roll in CentOS BrandingykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
lykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
\}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.12cb[- Roll in CentOS Branding|qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
dd|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o

ly"kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\!3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|$qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginy#kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
a&;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configV%%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
|(uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm'UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
ly+kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\*3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ)Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|-qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginy,kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
880Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka/;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configV.%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
ly3kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\23Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ1Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
|5qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginy4kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host group
Z8Z\:}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.16e- Roll in CentOS Branding|9sFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protection8Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka7;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configV6%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file
 y=kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy<kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\;3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ
V?%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|>qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
W\D}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.17ff- Roll in CentOS Branding8Cw{Julien Rische <jrische@redhat.com> - 4.6.8-5.el7_9.17f_- Resolves: RHEL-29926 ipa: user can obtain a hash of the passwords of all domain users and perform offline brute force|BsFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protectionAFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka@;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
XXGFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa
PF#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agentsaEEFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-10.el7]- Resolves: #1728123 - EMBARGOED CVE-2019-10195 ipa: FreeIPA: batch API logging user passwords to /var/log/httpd/error_log [rhel-7]
  - CVE-2019-10195: Don't log passwords embedded in commands in calls using batch
- Resolves: #1773550 - IPA upgrade fails for latest ipa package when adtrust is installed
  - Do not run trust upgrade code if master lacks Samba bindings
- Resolves: #1767302 - EMBARGOED CVE-2019-14867 ipa: Denial of service in IPA server due to wrong use of ber_scanf() [rhel-7.8]
  - Make sure to have storage space for tag
-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss
d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


oH}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!I}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}J}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY M;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
}L}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvK}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
__PFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa
PO#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agents[N{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.4`P- Roll in CentOS Branding
-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss
d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


oQ}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!R}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}S}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY V;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
}U}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvT}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
BBYFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa
[X{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.5`- Roll in CentOS BrandingmWUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss
d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts


oZ}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
![}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}\}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY _;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
ˁ}^}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv]}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
22[b{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.6`[- Roll in CentOS Branding|auFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm`UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.


oc}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!d}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
}}e}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY h;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
с}g}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvf}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|juFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmiUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
l!m}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords[l{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.7`- Roll in CentOS BrandingkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server

er+V:eD
b11d559c42557a76fa28ec310e056c9da6ea2279ff9e9d2550f053c95a60eb4cD
1838c4a50fba6cc7f01b473b8ebeaa6c7edb92cac0662a563b2b802ffa0fb3aaD
185387ed3f5744ba48ddfaf8a3d5ccc041f095dff1ea382c043dbe6835d3e739D
26b65e8ddb2e0f1b106113ae92e86c40572c636fadb1825dfa21ea13c21ecc4cD
fe9ddea76d491834446326906a81c67139192d20db46b613104c60028b90693bD
86cef284a27c740098bf41032dcb527c08c5847589bc56cd6dda05d37f714bdcD
83da2d9387fb7b54637b838d32f6027693e46e5eaa5f85a337fda688683830f5D
80ce6a4a15f013d38eba7effe54a0be427263f17ea3cccd5f299625962e17ef3D
7362e3afa20e7270f6bd0843928dbc50fc58aee6b6187699194d02979a9c9b4bD

56a814e3eeaf048c77ba188904c435aeaea3d62cc3a5cb3e815e9921e1d60166D
0f9586b6d0d300edc438c789f89bb5cc08cc5ad9ef33210f4da2aa9cb0977f06D
505e596b1b77d05f545fd3684fbdd8591bf9ca308db67ff0a6b36dd0a1341c17D

d3b825ecf0857cf7486c9085c1579cac88394eb38dbc27d654ff8a989aa9f4f2piwinsx} &,28>DJPV\bhntz
"(.4:@FLRX^djpv|9:o*8FTbp2~]m%2?LԁYfs.
CX'm4AN[Âhׂu-)C6XCmP]jwn؄+8=EYR_lyȅ -*:JGTan{҆"*/C<[IsVcp}և
$ 19>QKiXerLj&Ԉ3@MZ	g	!t	)	E	g	(	5	B	O	ĉ\	؉i	v	

&
:*
O7
eD
Q
^
k
ӊx
	%?,[9y*%'*06<BHNTZ`flrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|S`mzԌ!.D;YHlUbo
7|
	
ԍ$#s0=̍JWdq7~Rs%Ԏ2?.LnYfʎs&
g'4A-N[[huCq)6CP]>jiw+98`ER_ܑly4W| -Ӓ:G*TCan{h̓9"/<yIΓV>cp	}s
۔=$1>yKXCer  { !E&!3""@"BM"`Z"sg"t"""ɖ"(#5#9B#lO#\#ϖi$v$X$~$$*$7$ԗD$Q$^%k
}}n}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY q;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
ف}p}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvo}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|suFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmrUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
.l.[v{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.9aex- Roll in CentOS Branding\u3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differtFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
}}w}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
YY z;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
ށ}y}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvx}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
||uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm{UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
lykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role\~3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
#%#}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issue\}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.10a*@- Roll in CentOS Brandingther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
aa|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o

k\3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
"$"}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offset\
}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.11b@- Roll in CentOS Brandingy	kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller rolether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
aa|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm
UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o

k\3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
ykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
rr ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
\}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.12cb[- Roll in CentOS Branding|qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
ykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
(| uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.a;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
k\"3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ!Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
y$kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy#kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V&%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|%qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
\*3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ)Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server(Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka';Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
y,kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy+kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V.%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|-qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
\33Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ\2}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.16e- Roll in CentOS Branding|1sFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protection0Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka/;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
y5kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy4kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V7%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|6qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugineSJSY_ekqw}$+29@GNU\cjqx '.5<CJQX_fmt{
S
V
Y
Z
[
\
_
b
c
d
e
h
j
m
n
q
s
v
w
z
|

၀
぀
䁀
偀
灀
聀
遀
ꁀ
쁀
큀


 
"
$
&
*
,
.
3
5
7
<
?@ABEH	I
JKNQRSTWZ[\]`bef i"k#n%o&r(t)v*y+{-}./123
4
6789:;<=>"?$@&A+B-C/D4E7I8
S\<}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.17ff- Roll in CentOS Branding8;w{Julien Rische <jrische@redhat.com> - 4.6.8-5.el7_9.17f_- Resolves: RHEL-29926 ipa: user can obtain a hash of the passwords of all domain users and perform offline brute force|:sFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protection9Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka8;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
UU?Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa
P>#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agentsa=EFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-10.el7]- Resolves: #1728123 - EMBARGOED CVE-2019-10195 ipa: FreeIPA: batch API logging user passwords to /var/log/httpd/error_log [rhel-7]
  - CVE-2019-10195: Don't log passwords embedded in commands in calls using batch
- Resolves: #1773550 - IPA upgrade fails for latest ipa package when adtrust is installed
  - Do not run trust upgrade code if master lacks Samba bindings
- Resolves: #1767302 - EMBARGOED CVE-2019-14867 ipa: Denial of service in IPA server due to wrong use of ber_scanf() [rhel-7.8]
  - Make sure to have storage space for tag
-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss
d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
o@}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!A}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||B}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV E;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}D}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvC}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
\\HFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipaPG#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agents[F{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.4`P- Roll in CentOS Branding-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
oI}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!J}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||K}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV N;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o
}M}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvL}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
??QFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa[P{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.5`- Roll in CentOS BrandingmOUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
oR}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!S}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||T}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV W;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}V}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvU}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
//[Z{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.6`[- Roll in CentOS Branding|YuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmXUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
o[}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!\}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||]}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV `;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}_}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv^}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|buFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmaUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k!e}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords[d{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.7`- Roll in CentOS BrandingcFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
||f}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV i;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o!}h}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvg}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|kuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmjUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
+k+[n{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.9aex- Roll in CentOS Branding\m3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differlFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server

er+V:eD#
58790e773666a310f1c4417f46de1fb127437bce225ed0d9cbf6b4a08054ae98D"
d315bb2c28ee908b28dcdf583c02c6e2135a1e2a504eab6b1b0b1ea2366cd38cD!
78d5b1f2129f41fe187e0ac04949364deea63d749d50862bb7767f1e00444a71D 
5dd078d9c34f67aacb48cc5f22103833d14b4bfa4bc86f6a4d5ba09de9cdbdcbD
e0fb73f01affcb06ca29acf2c378ce6d3035f42a90552ed157bd34ccf137226fD
6dcf38b2dd21eea79940f1fdaf48332d6c3ecaa1fd0add17464537dd24fef021D
fe59e0e08fdd30fac03b78e5e5afd3169677c15d89d0797bddd5d5e796f2e43aD
06e8b2bd304cd09ba4be27cd71f6e46da23994939ba405275e37c1d39b91f75bD
f2a56e1e7ae1606a974d68a45c31824b05cfcb8ff28d94b4d090080e6e76c3a7D
5e7f113d0a50e93468c406b83d0079441feedc8fdc94a3867761526c5cf7b4adD
724104b78d65c37a7c944beaca3bddc2e94e0e2766838104816b951ec6b107c5D
133710e665511ae5f9d0928eba116d6f2d1f06f71afbe0e7013e3d46a1238e21D
878d2dbcd884adb9e2de690242d04710df89bee67b51aa86e9468e01de78341b
||o}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV r;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o'}q}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvp}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|tuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmsUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\v3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
"vy}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issue\x}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.10a*@- Roll in CentOS BrandingywkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
 {;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o,}z}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|}uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm|UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ~Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
"$"}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offset\}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.11b@- Roll in CentOS BrandingykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller rolether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
aa|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o0
k\3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
y
kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy	kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
rr 
;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o5\}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.12cb[- Roll in CentOS Branding|qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
ykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
(|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.a;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
k\3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
ykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
\"3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ!Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
y$kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy#kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V&%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|%qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
\+3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ\*}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.16e- Roll in CentOS Branding|)sFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protection(Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka';Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
y-kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy,kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V/%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|.qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
S\4}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.17ff- Roll in CentOS Branding83w{Julien Rische <jrische@redhat.com> - 4.6.8-5.el7_9.17f_- Resolves: RHEL-29926 ipa: user can obtain a hash of the passwords of all domain users and perform offline brute force|2sFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protection1Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka0;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
UU7Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipaFP6#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agentsa5EFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-10.el7]- Resolves: #1728123 - EMBARGOED CVE-2019-10195 ipa: FreeIPA: batch API logging user passwords to /var/log/httpd/error_log [rhel-7]
  - CVE-2019-10195: Don't log passwords embedded in commands in calls using batch
- Resolves: #1773550 - IPA upgrade fails for latest ipa package when adtrust is installed
  - Do not run trust upgrade code if master lacks Samba bindings
- Resolves: #1767302 - EMBARGOED CVE-2019-14867 ipa: Denial of service in IPA server due to wrong use of ber_scanf() [rhel-7.8]
  - Make sure to have storage space for tagG-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssHd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
o8}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!9}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||:}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV =;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by oM}<}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv;}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
\\@Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipaOP?#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agents[>{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.4`P- Roll in CentOS BrandingP-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssQd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
oA}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!B}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||C}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV F;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by oV}E}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvD}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
??IFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipaX[H{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.5`- Roll in CentOS BrandingmGUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.Y-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssZd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
oJ}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!K}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||L}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV O;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o_}N}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvM}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
//[R{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.6`[- Roll in CentOS Branding|QuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmPUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
oS}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!T}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||U}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV X;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by oe}W}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvV}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|ZuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmYUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k!]}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords[\{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.7`- Roll in CentOS Branding[Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
||^}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV a;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by oj}`}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv_}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|cuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmbUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
+k+[f{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.9aex- Roll in CentOS Branding\e3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differdFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
||g}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV j;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by oo}i}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvh}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|luFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmkUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\n3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differmFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
"vq}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issue\p}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.10a*@- Roll in CentOS BrandingyokFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role

er+V:eD0
76813e1abc18c641eb46092531885c18b9c6ddd5e9dc4e228b79d8c1701b18aaD/
3b2f3d7b1d885c5edc646e442aa9d94f1445bf4eedc14e0b85c4b0d8f69524a8D.
dab287aa189bc4e289c79998917467ba4a97037e00fe28be6d93e2537aed7bb7D-
98fb1fad0191aec5d51055b0a98b319339dfdb3295a687465da5a1122d7998b7D,
4f37e8e35d62af3023fa7e8393ded5ec181f09c19bbdf8f8210919d800c883acD+
97cdaffa439041e92b0a8642fd10637591e412ee471c5dd1572dd88e2d6decc7D*
78c54e3e24da878a2395d1db2fe940598eade355a2ed7955fe408e1151a3bdebD)
b98e50cb5344b27eeecb7c8f6a0bd8ae65ea51bfc626a744f6d64347692558a8D(
bdfe37339f1054699a6343f8d578f712a70a609276a9b8ed1eee991f37771614D'
3a9e272508ed53c6c3ca36cc4d1c537b9a6096425aa6339399939cfb7a44d1c2D&
c8dfb7c69048e40d89f055121f7bf399c85c51f08160824fe50d9434c253a4a3D%
50b41570ec21f348d3c7adf1b62909fcf0674e4f13126166d7667664345d4f42D$
908fa60367f005eeb06ef2422874df47c562ea782942062b68547373fdaa4040
 s;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by ou}r}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|uuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmtUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\w3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differvFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
"$"}{}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offset\z}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.11b@- Roll in CentOS BrandingyykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyxkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller rolether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
aa|~uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm}UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. |;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by oy
k\3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
ykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
rr ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o~\}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.12cb[- Roll in CentOS Branding|qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\	3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
ykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy
kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V
%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
(|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.a;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA configbRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{K:L=N@RASBTCUFWI[J\K]L^O`RaSbTcUdXfZg]h^iakclfmgnjplqnrqtsvuwwx{z~{|}	
#%',/012589:;>ABCDGJKLMPRUVY[_ekry	#Á)ā/Ł5Ɓ;ǁBȁIɁOʁVˁ\́b
k\3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
ykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
\3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA serverFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
ykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
\#3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ\"}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.16e- Roll in CentOS Branding|!sFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protection Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
y%kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy$kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V'%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|&qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
S\,}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.17ff- Roll in CentOS Branding8+w{Julien Rische <jrische@redhat.com> - 4.6.8-5.el7_9.17f_- Resolves: RHEL-29926 ipa: user can obtain a hash of the passwords of all domain users and perform offline brute force|*sFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protection)Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka(;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
UU/Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipaP.#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agentsa-EFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-10.el7]- Resolves: #1728123 - EMBARGOED CVE-2019-10195 ipa: FreeIPA: batch API logging user passwords to /var/log/httpd/error_log [rhel-7]
  - CVE-2019-10195: Don't log passwords embedded in commands in calls using batch
- Resolves: #1773550 - IPA upgrade fails for latest ipa package when adtrust is installed
  - Do not run trust upgrade code if master lacks Samba bindings
- Resolves: #1767302 - EMBARGOED CVE-2019-14867 ipa: Denial of service in IPA server due to wrong use of ber_scanf() [rhel-7.8]
  - Make sure to have storage space for tag-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
o0}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!1}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||2}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV 5;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}4}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv3}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
\\8Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipaP7#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agents[6{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.4`P- Roll in CentOS Branding-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
o9}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!:}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||;}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV >;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}=}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv<}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
??AFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa[@{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.5`- Roll in CentOS Brandingm?UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sssd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
oB}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!C}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||D}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV G;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}F}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvE}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
//[J{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.6`[- Roll in CentOS Branding|IuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmHUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
oK}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!L}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||M}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV P;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}O}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvN}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|RuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmQUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k!U}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords[T{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.7`- Roll in CentOS BrandingSFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
||V}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV Y;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o}X}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvW}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|[uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmZUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k+~_iMichal Ruprich <mruprich@redhat.com> - 3.1.6-1X- Resolves: #913329 - [RFE] include iperf3 in RHEL 7
- initial build[^{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.9aex- Roll in CentOS Branding\]3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ\Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
3A3e={Michal Ruprich - 3.1.7-2X•@- Related: #913329 - [RFE] include iperf3 in RHEL 7
                   - adding requires to spec file for devel package:di
Michal Ruprich <mruprich@redhat.com> - 3.1.7-1XC- Related: #913329 - [RFE] include iperf3 in RHEL 7
                   - adding latest version before including iperf3 in RHEL-7~ciMichal Ruprich <mruprich@redhat.com> - 3.1.6-1X- Resolves: #913329 - [RFE] include iperf3 in RHEL 7
- initial buildb]5Stepan Broz <sbroz@redhat.com> - 3.1.7-3d@- Resolves: #2224558 - iperf3: memory allocation hazard and crash
  (CVE-2023-38403)a={Michal Ruprich - 3.1.7-2X•@- Related: #913329 - [RFE] include iperf3 in RHEL 7
                   - adding requires to spec file for devel package:`i
Michal Ruprich <mruprich@redhat.com> - 3.1.7-1XC- Related: #913329 - [RFE] include iperf3 in RHEL 7
                   - adding latest version before including iperf3 in RHEL-7
s2~kiMichal Ruprich <mruprich@redhat.com> - 3.1.6-1X- Resolves: #913329 - [RFE] include iperf3 in RHEL 7
- initial buildj]5Stepan Broz <sbroz@redhat.com> - 3.1.7-3d@- Resolves: #2224558 - iperf3: memory allocation hazard and crash
  (CVE-2023-38403)i={Michal Ruprich - 3.1.7-2X•@- Related: #913329 - [RFE] include iperf3 in RHEL 7
                   - adding requires to spec file for devel package:hi
Michal Ruprich <mruprich@redhat.com> - 3.1.7-1XC- Related: #913329 - [RFE] include iperf3 in RHEL 7
                   - adding latest version before including iperf3 in RHEL-7~giMichal Ruprich <mruprich@redhat.com> - 3.1.6-1X- Resolves: #913329 - [RFE] include iperf3 in RHEL 7
- initial buildf]5Stepan Broz <sbroz@redhat.com> - 3.1.7-3d@- Resolves: #2224558 - iperf3: memory allocation hazard and crash
  (CVE-2023-38403)

er+V:eD=
596e62671849cfd110b4ac4c57b171fec5bb07301be496f20b9b86d591947ebeD<
1eac2001120394176840294e989343eb699519e8284843a3cdd14f5fb3f39a95D;
7d3b3df85df3f1d47ab959aa42eea6f3302b166b9e37ef92779c1c8acedfd671D:
0e0b806579667e86ea70685a838f8c23073e5084c9c3135588b05d5d395ec9d3D9
73be1cce35dd9bd5fb59093ba5faf459b1f723fec8ccad9d13b18e6e1b249b10D8
30f252a9be101e11f5009f24025e69ac8850c0e429134629fceda20f9508a261D7
559d3f3c580f94eb5e25df5db277b1e4076d0d1911bd304941680178b21d9e5fD6
31535d62fcdd33c68d7c941c0b2b9e56b4f4749c5c04518d19b67a70214a8012D5
b4ef197940e3c4fa8fa6153875480c974b0ffa36f4534e7c04d901e91440e53cD4
514e7d973b405b3d0028fc7df9e3b46ac3dbc49e864417967dad13ed6c1a344dD3
46fcca6c6687e1d7465d0f99ea219de21f84bde74cc822721a5e55a13bf97a0cD2
e85016af12ca079ec7dcd10cfe41ca3eb0ae74f337e7db981ea8289ce132cc0bD1
1b0076a98d327d7bc0db69b985d05e02f9d0e927d5d7645ad2a14dba64ceaf52
VA[VWreMJosef Ridky <jridky@redhat.com> - 0:1.8.18-4X+- Fix RPMDiff issues and rebuild%qegJosef Ridky <jridky@redhat.com> - 0:1.8.18-3X@- Fix issues with warning: dereferencing type-punned pointer 
  will break strict-aliasing rules from RPMDiffRpeCJosef Ridky <jridky@redhat.com> - 0:1.8.18-2X- Fix issue in file sources_oe]Josef Ridky <jridky@redhat.com> - 0:1.8.18-1X@- New upstream release 1.8.18 (#1398658)n]5Stepan Broz <sbroz@redhat.com> - 3.1.7-3d@- Resolves: #2224558 - iperf3: memory allocation hazard and crash
  (CVE-2023-38403)m={Michal Ruprich - 3.1.7-2X•@- Related: #913329 - [RFE] include iperf3 in RHEL 7
                   - adding requires to spec file for devel package:li
Michal Ruprich <mruprich@redhat.com> - 3.1.7-1XC- Related: #913329 - [RFE] include iperf3 in RHEL 7
                   - adding latest version before including iperf3 in RHEL-7
=#=RyeCJosef Ridky <jridky@redhat.com> - 0:1.8.18-2X- Fix issue in file sourcesxkSPavel Cahyna <pcahyna@redhat.com> - 0:1.8.18-10a{- Protect against negative values to memmove that caused
  "ipmitool sol activate" to crash against an IBM DataPower appliance
  (#1951480) and IP-131 Dayton blades in a SGI ICE-X (#2025519)
  Cherry-picked from upstream PR#78.iwscVáclav Doležal <vdolezal@redhat.com> - 0:1.8.18-9^_@- Disable -fstrict-aliasing (RPMDiff issue)^vsMVáclav Doležal <vdolezal@redhat.com> - 0:1.8.18-8^^F- Backport fix for CVE-2020-5208oue}Josef Ridky <jridky@redhat.com> - 0:1.8.18-7Zy- Remove debug prints shown without -v option (#1483163)te=Josef Ridky <jridky@redhat.com> - 0:1.8.18-6Y{- Hide unrequested verbose output (#1483163)
- Fix doc for check input values (#1495098)ose}Josef Ridky <jridky@redhat.com> - 0:1.8.18-5Xs- Remove RPMDiff fix file (#1439269) related to #1398658
ViscVáclav Doležal <vdolezal@redhat.com> - 0:1.8.18-9^_@- Disable -fstrict-aliasing (RPMDiff issue)^sMVáclav Doležal <vdolezal@redhat.com> - 0:1.8.18-8^^F- Backport fix for CVE-2020-5208o~e}Josef Ridky <jridky@redhat.com> - 0:1.8.18-7Zy- Remove debug prints shown without -v option (#1483163)}e=Josef Ridky <jridky@redhat.com> - 0:1.8.18-6Y{- Hide unrequested verbose output (#1483163)
- Fix doc for check input values (#1495098)o|e}Josef Ridky <jridky@redhat.com> - 0:1.8.18-5Xs- Remove RPMDiff fix file (#1439269) related to #1398658W{eMJosef Ridky <jridky@redhat.com> - 0:1.8.18-4X+- Fix RPMDiff issues and rebuild%zegJosef Ridky <jridky@redhat.com> - 0:1.8.18-3X@- Fix issues with warning: dereferencing type-punned pointer 
  will break strict-aliasing rules from RPMDiff
<<Qi;Sinny Kumari <skumari@redhat.com> - 2.4.11.1-1W- Resolves: #1274367 - [7.3 FEAT] iprutils package update
- Resolves: #1297921 - IPR: Raid migration fails to kick while executing through command lineJa5Jakub Čajka <jcajka@redhat.com> - 2.4.8-1UJ@- Resolves: #1182038 - [7.2 FEAT] iprutils package update - ppc64/ppc64le
- Resolves: #1183460 - RHEL7.1 BE: iprutils: Set known zeroed after formatwg	Pavel Cahyna <pcahyna@redhat.com> - 1.8.18-11d- Add upstream ipmievd patch to check received msg id against expectation
  Fixes problem where SEL response is not recognized correctly
  when SEL request times out
  Resolves: rhbz#2224569kSPavel Cahyna <pcahyna@redhat.com> - 0:1.8.18-10a{- Protect against negative values to memmove that caused
  "ipmitool sol activate" to crash against an IBM DataPower appliance
  (#1951480) and IP-131 Dayton blades in a SGI ICE-X (#2025519)
  Cherry-picked from upstream PR#78.
!L)!	i/Sinny Kumari <skumari@redhat.com> - 2.4.16.1-1[(@- Resolves: #1587834 - vpdupdate takes over an hour on system with 104 drive
- Resolves: #1521052 - iprutils package update for POWER
- Resolves: #1547891 - iprconfig unable to Download microcode on all applicable devices
- Resolves: #1576013 - iprconfig tools shows wrong error message, while creating raid using RI SSDs and normal SSDstiSinny Kumari <skumari@redhat.com> - 2.4.15.1-1Y- Resolves: #1456500 - iprutils package update to 2.4.15.1iSinny Kumari <skumari@redhat.com> - 2.4.14.1-1X- Resolves: #1384382 - [7.4 FEAT] iprutils package update - ppc64/ppc64leiESinny Kumari <skumari@redhat.com> - 2.4.13.1-1W:- Rebase to upstream release 2.4.13.1
- Resolves: #1369259 - Fix known zeroed state tracking/iwSinny Kumari <skumari@redhat.com> - 2.4.12.1-1Wt@- Resolves: #1364131 - Integrate various important bug fixes for iprutils in
  RHEL7.3 by updating iprutils to 2.4.12
p?dxpwiChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_sessioni)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure conditiongigChris Leech <cleech@redhat.com> - 6.2.0.874-12][- 1389071 handle newer ISCSI_ERR_NOP_TIMEDOUT code from the kernel
- 1624670 Login negotiation failed due to CHAP_N values do not match
          (rec update race condition)\
iSChris Leech <cleech@redhat.com> - 6.2.0.874-11\@- 1649401, 1649413 iscsiuio updatesw[Than Ngo <than@redhat.com> - 2.4.17.1-3]9- Resolves: #1763626 - iprconfig hangs while raiding drives on crow3Y[[Than Ngo <than@redhat.com> - 2.4.17.1-2\{- Related: #1643408 - fix rpmdiff issue`
[iThan Ngo <than@redhat.com> - 2.4.17.1-1\w@- Resolves: #1643408 - iprutils package update
 mn \iSChris Leech <cleech@redhat.com> - 6.2.0.874-11\@- 1649401, 1649413 iscsiuio updates}iChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at onceiimChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement"i]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)Ni5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup valueiChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardeningi5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forking
!y!Ni5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup valueiChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardeningi5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forkingwiChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_sessioni)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure conditiongigChris Leech <cleech@redhat.com> - 6.2.0.874-12][- 1389071 handle newer ISCSI_ERR_NOP_TIMEDOUT code from the kernel
- 1624670 Login negotiation failed due to CHAP_N values do not match
          (rec update race condition)
wYkww#iChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_session"i)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure conditiong!igChris Leech <cleech@redhat.com> - 6.2.0.874-12][- 1389071 handle newer ISCSI_ERR_NOP_TIMEDOUT code from the kernel
- 1624670 Login negotiation failed due to CHAP_N values do not match
          (rec update race condition)} iChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at onceiimChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement"i]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)
mn})iChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at oncei(imChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement"'i]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)N&i5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup value%iChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardening$i5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forking
co{c/iChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardening.i5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forkingw-iChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_session,i)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure conditiong+igChris Leech <cleech@redhat.com> - 6.2.0.874-12][- 1389071 handle newer ISCSI_ERR_NOP_TIMEDOUT code from the kernel
- 1624670 Login negotiation failed due to CHAP_N values do not match
          (rec update race condition)*i1Chris Leech <cleech@redhat.com> - 6.2.0.874-21a- 1989972 set proper attr in rpm db for lockfiles, fixes rpm verificiation warning
z-z5i)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure condition4i1Chris Leech <cleech@redhat.com> - 6.2.0.874-21a- 1989972 set proper attr in rpm db for lockfiles, fixes rpm verificiation warning}3iChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at oncei2imChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement"1i]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)N0i5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup value
mi;imChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement":i]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)N9i5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup value8iChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardening7i5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forkingw6iChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_session
SskSBiChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardeningAi5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forkingw@iChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_session?i)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure conditionw>iChris Leech <cleech@redhat.com> - 6.2.0.874-22a^@- 1946578 fix segfault on case mismatch in config/record file=i1Chris Leech <cleech@redhat.com> - 6.2.0.874-21a- 1989972 set proper attr in rpm db for lockfiles, fixes rpm verificiation warning}<iChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at once
,-,\IiSChris Leech <cleech@redhat.com> - 6.2.0.874-11\@- 1649401, 1649413 iscsiuio updateswHiChris Leech <cleech@redhat.com> - 6.2.0.874-22a^@- 1946578 fix segfault on case mismatch in config/record fileGi1Chris Leech <cleech@redhat.com> - 6.2.0.874-21a- 1989972 set proper attr in rpm db for lockfiles, fixes rpm verificiation warning}FiChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at onceiEimChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement"Di]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)NCi5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup value
!y!NOi5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup valueNiChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardeningMi5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forkingwLiChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_sessionKi)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure conditiongJigChris Leech <cleech@redhat.com> - 6.2.0.874-12][- 1389071 handle newer ISCSI_ERR_NOP_TIMEDOUT code from the kernel
- 1624670 Login negotiation failed due to CHAP_N values do not match
          (rec update race condition)
YkwViChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_sessionUi)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure conditiongTigChris Leech <cleech@redhat.com> - 6.2.0.874-12][- 1389071 handle newer ISCSI_ERR_NOP_TIMEDOUT code from the kernel
- 1624670 Login negotiation failed due to CHAP_N values do not match
          (rec update race condition)\SiSChris Leech <cleech@redhat.com> - 6.2.0.874-11\@- 1649401, 1649413 iscsiuio updates}RiChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at onceiQimChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement"Pi]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)
mn}\iChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at oncei[imChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement"Zi]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)NYi5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup valueXiChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardeningWi5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forking

er+V:eDJ
d4448c84868ba851628434b5cedc79248ebbc6aeda79ecb6339065c844d6d809DI
b41a681dfb0b8b82973c7815eeee4cc5e3fc5e27cb13f55d251186c29146a4f3DH
3e0a8c76f0c416e9b2f67cade48b3e2606a3fc3b47348110c033aa2cc1835a00DG
372372d382848eb9ecb5e551dd606aa646c12d3683f43b876ed5191e7a529c3eDF
77269448e020f6a70c9a9ee15224c6dffd91e47f8c5a0c05dc8281dec47ff3f1DE
447681bd8d74b001a4a5461694a948bba8dce453c2c054b8fb5d38408b7888a3DD
144001826455a5ca11b8e1701396ee66db5af5d0c7831453aba1309eb708a6c2DC
147c8de55409cc60a709e9f72364ee69759e7361564a732c0fd192e6fdd46d75DB
092cc13ed7af9de7e0332c1da0285f190396f1b75256ecd162899d06cf9b0e1aDA
d65cdceba1822f154d19bc4845ed70da24d2b51bcaadb12af03fe2668101a3eaD@
ddf90c0ec436cf18228ba0646f73776e9a121426e0c05038fb1f4378646ff646D?
e1163c5b5240558b24ddea7085492d62d63dd722ce6b4775724583c2ebcffdf2D>
a551edad1e9e549e9010c83ff60ebed361a870676f10b405c22b4a301de84699
!y!Nbi5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup valueaiChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardening`i5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forkingw_iChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_session^i)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure conditiong]igChris Leech <cleech@redhat.com> - 6.2.0.874-12][- 1389071 handle newer ISCSI_ERR_NOP_TIMEDOUT code from the kernel
- 1624670 Login negotiation failed due to CHAP_N values do not match
          (rec update race condition)
aYkahi)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure conditionggigChris Leech <cleech@redhat.com> - 6.2.0.874-12][- 1389071 handle newer ISCSI_ERR_NOP_TIMEDOUT code from the kernel
- 1624670 Login negotiation failed due to CHAP_N values do not match
          (rec update race condition)fi1Chris Leech <cleech@redhat.com> - 6.2.0.874-21a- 1989972 set proper attr in rpm db for lockfiles, fixes rpm verificiation warning}eiChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at onceidimChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement"ci]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)
minimChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement"mi]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)Nli5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup valuekiChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardeningji5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forkingwiiChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_session
aStiChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardeningsi5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forkingwriChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_sessionqi)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure conditionpi1Chris Leech <cleech@redhat.com> - 6.2.0.874-21a- 1989972 set proper attr in rpm db for lockfiles, fixes rpm verificiation warning}oiChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at once
-wziChris Leech <cleech@redhat.com> - 6.2.0.874-22a^@- 1946578 fix segfault on case mismatch in config/record fileyi1Chris Leech <cleech@redhat.com> - 6.2.0.874-21a- 1989972 set proper attr in rpm db for lockfiles, fixes rpm verificiation warning}xiChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at onceiwimChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement"vi]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)Nui5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup value
fse
f"i]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)Ni5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup value~iChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardening}i5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forkingw|iChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_session{i)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure condition
--i)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure conditiongigChris Leech <cleech@redhat.com> - 6.2.0.874-12][- 1389071 handle newer ISCSI_ERR_NOP_TIMEDOUT code from the kernel
- 1624670 Login negotiation failed due to CHAP_N values do not match
          (rec update race condition)\iSChris Leech <cleech@redhat.com> - 6.2.0.874-11\@- 1649401, 1649413 iscsiuio updateswiChris Leech <cleech@redhat.com> - 6.2.0.874-22a^@- 1946578 fix segfault on case mismatch in config/record filei1Chris Leech <cleech@redhat.com> - 6.2.0.874-21a- 1989972 set proper attr in rpm db for lockfiles, fixes rpm verificiation warning}iChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at onceiimChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement
mi
imChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement"i]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)Ni5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup value
iChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardening	i5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forkingwiChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_session
ssiChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardeningi5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forkingwiChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_sessioni)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure conditiongigChris Leech <cleech@redhat.com> - 6.2.0.874-12][- 1389071 handle newer ISCSI_ERR_NOP_TIMEDOUT code from the kernel
- 1624670 Login negotiation failed due to CHAP_N values do not match
          (rec update race condition)}iChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at once
z-zi)Chris Leech <cleech@redhat.com> - 6.2.0.874-13]_@- 1724579 iscsiuio update, allow processing requests in DHCP failure conditioni1Chris Leech <cleech@redhat.com> - 6.2.0.874-21a- 1989972 set proper attr in rpm db for lockfiles, fixes rpm verificiation warning}iChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at onceiimChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement"i]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)Ni5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup value
miimChris Leech <cleech@redhat.com> - 6.2.0.874-19^@- 1851250 fix libiscsi for libcrypto requirement"i]Chris Leech <cleech@redhat.com> - 6.2.0.874-18^- 1809945 backport new CHAP modes for FIPS environments (SHA1 and SHA256 only, no SHA3 in OpenSSL-1.0.2)Ni5Chris Leech <cleech@redhat.com> - 6.2.0.874-17]@- 1518367 boot from iSCSI not establishing all sessions persistently
- 1667965 A manual restart of iscsi.service modifies records node.startup valueiChris Leech <cleech@redhat.com> - 6.2.0.874-16]W- upstream iscsiuio/configure.ac changes were breaking build hardeningi5Chris Leech <cleech@redhat.com> - 6.2.0.874-15]@- 1396651 Update service files, support sd_notify instead of pid files, stop forkingwiChris Leech <cleech@redhat.com> - 6.2.0.874-14]x- 1598647 update boot gateway information during sync_session
zsz$+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)Q#Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)w"iChris Leech <cleech@redhat.com> - 6.2.0.874-22a^@- 1946578 fix segfault on case mismatch in config/record file!i1Chris Leech <cleech@redhat.com> - 6.2.0.874-21a- 1989972 set proper attr in rpm db for lockfiles, fixes rpm verificiation warning} iChris Leech <cleech@redhat.com> - 6.2.0.874-20_ts@- 1881245 iscsiadm regression when discovering many targets at once
/)5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t(iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T''Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F&Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(%OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (.OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package-+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){,	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)+5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m*[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D345Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m3[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)25Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t1iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T0'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F/Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
F8Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(7OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageM6Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){5	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{>	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)=5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m<[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410);5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t:iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T9'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\tCiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TB'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FAJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1@]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)M?Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH1I]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MHRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){G	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)F5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mE[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)D5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$L+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)QKBruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^J5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
/Q5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tPiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TO'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FNJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(MOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (VOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageU+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){T	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)S5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mR[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D3\5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)Z5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tYiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TX'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FWJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
F`Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(_OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageM^Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){]	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)

er+V:eDW
68ad96ff2728b35a2bfef5e46685a550d379ee6937f9081450a2c2f4c5e5c68cDV
562577dc40b07d4f6bfc5f0a837b2a0772968b369b1e30f1b6c11338772ecc1aDU
0daf2f065c20c572dbd4c2cd864cef8c197f640a926ce017c7343205b4e5e77dDT
9f2c5064a36e0190d1fb7f175cee62952c7e32951856a1ec5c9a427f2148aac2DS
df41fca55a3d1bff5343ac8fd47f2dabaf9e5da86bb0851f46af715e74c7cd59DR
eeff2dd2126e05da5903de0991d891313049be87f35dda8f67c383779761163fDQ
829050a62694fea5287076cdabeec66b15fe994809fcdd5931ebb992d47fecd4DP
dd6a74f8a692f2fe556164b50fc2c03bcb46f1e09f4aa5d99bc036cfaf80970fDO
7454f4ffa83154415c00c37d9cb1e5e253feeb7dd34081b445318d2340ae4e42DN
a7388c34d0bff23da18ea8026b4ad61a7789dc2606148be90e9c8b6440e41fbdDM
f6017656fae735dfc5831c4b635cb2dda2cae8615a1d0a4b66898f7a6b9f168bDL
bbd3efd923fc7315be5c5ab97b3a2459859dcca70068d448ba1d7a8aca4b9af0DK
6d01edd55d9f52f8ba1366e53274676bc33d48854b4465e49a15f474ddd0672f
'{f	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)e5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)md[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)c5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tbiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)Ta'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\tkiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)Tj'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FiJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1h]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MgRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH1q]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MpRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){o	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)n5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mm[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)l5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$t+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)QsBruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^r5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
/y5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)txiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)Tw'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FvJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(uOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (~OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package}+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){|	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787){5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mz[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D35Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageMRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t
iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T	'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH1]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)QBruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
/!5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (&OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package%+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){$	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)#5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m"[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D3,5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m+[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)*5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t)iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T('Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F'Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
F0Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(/OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageM.Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){-	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{6	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)55Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m4[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)35Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t2iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T1'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\t;iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T:'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F9Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)18]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)M7Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH1A]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)M@Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){?	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)>5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m=[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)<5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$D+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)QCBruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^B5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021bR5RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{ρnЁtсzҁӁԁ
Ձցׁ؁$ف)ځ.ہ4܁8݁>ށC߁IL၄Q⁄Vい\䁄`恄f灄k聄q遄tꁄy끄~쁅큅!&,06;ADINTX^cilqv|	

$(.39<AFLPV[adint x!~"#	$%&'( )&*++1,4-9.>/D0H1N2S3Y4\
/I5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tHiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TG'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FFJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(EOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (NOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageM+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){L	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)K5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mJ[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D3T5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mS[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)R5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tQiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TP'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FOJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
FXJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(WOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageMVRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){U	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{^	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)]5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m\[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)[5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tZiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TY'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\tciJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)Tb'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FaJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1`]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)M_Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)

er+V:eDd
1316ac625663f9009c64a89e399d60b4191a5bea7e69797e85132da3ccbcbc77Dc
a714e0889c00122a44ccbbd66032e67123e1f75d8cdad594e32de4c09400de94Db
60e92e4b5eccd578699334e15aeedbd39648619e8c4fcfdafec19e48fe080697Da
c5658a365bac1d6a010849f23983b9904b689b2d9191ee2bb6e12c828ec3855dD`
973367a3a9c98b25bdcff626cce24fd23fe78725e3f446889ec5a9091fc9c005D_
21ed5458a8abe02695e7c68bd4c068debb35056a454d12b095dcc9c2dd435449D^
236b16f4eff9a720f06ea780d58be74598f1326a04d143dea2ea6a3bf5dfb061D]
467ea07622b7bd1dc0694405f23e3047a904f677d60e58b4778fc8e889c2d224D\
a746cbe3d7985ed9de3d8ea2565a0ba9d0e55c9e16d298d608b40797a31b231bD[
4bf12266defcaeaaa70a5bbe431d815b7c435f5f95d2be12d8be7de214533e53DZ
0fa3ba7dae428c14500eba9a62de5fd03fb07234b8db1fea572d45fa78f0e0d7DY
4a764611d924b3be2baab6d6ffd5fc562fe6a7c2c08cede4d58bb7259f7a0f35DX
fe20198b1c59cd2bd81f50412b770ffdbe657e59f816450e2235e0863704f4d5
H`OH1i]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MhRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){g	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)f5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)me[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)d5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$l+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)QkBruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^j5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
/q5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tpiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)To'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FnJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(mOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (vOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageu+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){t	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)s5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mr[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D3|5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m{[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)z5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tyiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)Tx'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FwJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageM~Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){}	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T
'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F	Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH1]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m
[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)QBruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
/5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D3$5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m#[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)"5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t!iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T 'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
F(Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)('OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageM&Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){%	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{.	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)-5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m,[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)+5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t*iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T)'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\t3iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T2'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F1Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)10]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)M/Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH19]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)M8Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){7	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)65Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m5[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)45Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$<+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)Q;Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^:5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
/A5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t@iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T?'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F>Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(=OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (FOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageE+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){D	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)C5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mB[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D3L5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mK[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)J5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tIiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TH'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FGJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
FPJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(OOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageMNRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){M	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{V	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)U5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mT[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)S5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tRiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TQ'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\t[iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TZ'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FYJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1X]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MWRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH1a]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)M`Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){_	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)^5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m][Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)\5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$d+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)QcBruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^b5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021

er+V:eDq
ed293f56a8fa1ff864e007c158a2833d672efa0618a2cd57b24f8ee570b7df80Dp
f9157874165a2f0bfd45d4225d6b6665f3447d99d8b0b7c31b884b462c45218eDo
3f3a9c60625ad194ae3406fcef007e24a583db933f244ad66404e2ce22e8628bDn
4214383e3e5d362039f4752421a5c4dd66c7a5aad772859a41684a0b984c5373Dm
b91c19d3211778e075a890f5366a6f8e279f0f8516238accd9f976e88ae5d259Dl
203db2e870a8753e2c1ba5897367c0822ee2a5c79b866fa6486effebd9f23b96Dk
c21af136e37b18345d2d844866515fe9c44bedd736b4e98701ea2e6a2210c5a4Dj
e26a698ca51f4049464d83df1c17062a826cf136c188c2d3994ed01f90974ab6Di
55b8fbe53a3211935d82bafb555f9585fbe02d4aad743ea7bfe9b68c31fff322Dh
7046aa1eabc63c20c57732ab2750fd10c21bc29fbb4198fbd9497b0323bb525dDg
71ab07234942e8c84134be2b225f1e3f417e7974f4dcf6a080e9820b68b1b81cDf
247fc0e92238ee99057179d386718ac73601d9dcbbf86ef80e98ec27d4c7d86fDe
3820c04e5244db590096c735cfebaf9c275d7ef5d644f71712940bd565f671e7
/i5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)thiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)Tg'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FfJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(eOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (nOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packagem+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){l	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)k5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mj[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D3t5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)ms[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)r5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tqiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)Tp'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FoJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
FxJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(wOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageMvRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){u	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{~	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)}5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m|[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410){5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tziJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)Ty'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH1	]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)QBruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^
5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
/5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(
OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D35Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
F Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageMRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{&	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)%5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m$[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)#5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t"iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T!'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\t+iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T*'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F)Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1(]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)M'Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH11]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)M0Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){/	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787).5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m-[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410),5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$4+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)Q3Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^25Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
/95Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t8iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T7'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F6Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(5OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (>OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package=+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){<	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787);5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m:[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D3D5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mC[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)B5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tAiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T@'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F?Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
FHJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(GOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageMFRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){E	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{N	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)M5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mL[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)K5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tJiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TI'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\tSiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TR'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FQJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1P]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MORado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH1Y]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MXRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){W	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)V5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mU[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)T5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$\+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)Q[Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^Z5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
/a5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t`iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T_'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F^Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(]OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (fOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packagee+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){d	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)c5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mb[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)

er+V:eD~
cc95d52dd6acca1790e3c4f0dd8c26d939c93423de333d2066dece7bf767d545D}
22bfec4ae12f95ec0baa30ad642504987294442f2a28150fd5c850b8aeb04373D|
5e65bcb053440eb744a0b29be0f36cc5c82a7fab303e26ad6ee2a714bfd4651cD{
ab9a79dcba43eba518e5c0bd8261fae155c1951f0d9f9de1194a57e26a1c43f4Dz
9a949108d90656bc8587b16aed99265931bfd33e4912eebc815b4acd99d709f0Dy
e6ffa74bab49f49dde242d6ce151c85a071ed9f55bbfe61e19f182d53a82496cDx
081e9334981d1b4b5c7b0096cade8b94d105829885494e80e9e2ca16d37b30a4Dw
544b35d1b0c600d66cc166c5f116fe849ac376a65105997c84d89296afb22861Dv
48b1742bdd262f815457ccce6a8412a9c65dc9affb811fc52a31da14b7fe7f4eDu
740cba8784afe4330523ae1c3ed41bce93c5537dad8f467cf1fdc17ea21f53e1Dt
ffd9abc7bf1c18a5121be12799691f3e50e09ec00e67de327db03a1cf7a29d6cDs
9653063ff86adaa3cf63420a5d68c5ebb55e16a3bbe27a79314e37a1bf604fdfDr
bb99b24bb6932637a09babfa34970f02619096864977bef0bf48a0e701ea428a
35\D3l5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mk[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)j5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tiiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)Th'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FgJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
FpJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(oOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageMnRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){m	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{v	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)u5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mt[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)s5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)triJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)Tq'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\t{iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)Tz'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FyJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1x]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MwRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH1]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)~5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m}[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)|5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)QBruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
/	5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m
[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D35Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageMRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\t#iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T"'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F!Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1 ]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH1)]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)M(Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){'	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)&5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m%[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)$5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$,+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)Q+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^*5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
/15Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t0iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T/'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F.Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(-OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (6OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package5+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){4	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)35Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m2[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D3<5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m;[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410):5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t9iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T8'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F7Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
F@Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(?OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageM>Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){=	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{F	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)E5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mD[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)C5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tBiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TA'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\tKiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TJ'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FIJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1H]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MGRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH1Q]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MPRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){O	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)N5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mM[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)L5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$T+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)QSBruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^R5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
/Y5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tXiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)TW'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FVJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(UOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (^OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package]+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){\	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)[5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mZ[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D3d5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mc[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)b5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)taiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T`'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F_Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
FhJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(gOJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageMfRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){e	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)

er+V:eD
fde70f28b5a0ce727403a12e9a6a39a8f953d1975000b7be4be8c5434c4d3556D

830680293bf892ad9b57630cd1fd50d4415343677c361c32b8b849c399daeb14D	
c38c420b6dbc3c61cd71784ca87f3a88f4a61d461e77b66508742c89d1d7e1fdD
ec2503de79ebe13134bfc568d71d9a2c99d9f6d109eb2f80a8198fb2e331bb9fD
a2e99881f1afb105ba6355f4eef86e839d3ccf60d9543490c748c71e96cb2256D
c017fccf387f4e86a1ff26de3d85c015ae1bdfc53bf1e30acf131d4aa4f5011fD
83e709af69a954f17415b836c06c639e57234896cfbc5a9d849530590fd960efD
d512882b1e6a2e0854dd99d20a3bdcbbfa71dd8002a9647e11460a803a49a486D
f563d696d882905f6633fed7a3fe77d0876a29170b14175715b53e21a84887b1D
591c8ad60cbb62f0c95441ec820072142ae5392cedd248fc81f71eb1d8a699fbD
13c3f114dacf10594cbfa9365b4107f3ea7e4dbc3dd4f7d0362049b983ea8f56D
33293b1fe8b0638219c4a88ea8d7217eb55c5b4e227d7945c14a9121db97e4d1D
9fc87325642e8e0a01c8a46507e124f43ad0d86942ddd1f2e5d1722588e7359c
'{n	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)m5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)ml[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)k5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tjiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)Ti'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\tsiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)Tr'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FqJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1p]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MoRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH1y]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MxRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){w	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)v5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)mu[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)t5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
$G$|+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)Q{Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)^z5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
/5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F~Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(}OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package
 pM (OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
35\D35Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)
5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t	iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageMRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){
	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
\.x\tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)MRado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
H`OH1!]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)M Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)
`T&Y)Jarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541x%YJarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426$Y?Jarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#16874268#YJarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274^"5Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-4021
u%0u,[OHonggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699+[CHonggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
*[;Honggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482b)[mHonggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
([;Honggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585V'YUJarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296
&20	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o/	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L.	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665-	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f -4	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'3{UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#18766652	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#18766651	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{6f8l9p:v;{<=>	?@ABC#D)E,F1G6H<I@JFKKLQMTNYO^PdQhSnTsUyV|WXYZ[\]!^&_,`0a4c6d:e>f@gEhGiIjNkQlSmWn[o^pbqfrjtmurvuwxx}yz{	|
}~#'+.369=@DGJNQTVZ]_adgimprt
:6wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{5yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
&2:	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o9	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L8	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#18766657	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f ->	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'={UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665<	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665;	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665
:@wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{?yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
r/;rE	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665D	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665C	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665oB	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665LA	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665
"T"-G	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'F{UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665
:IwAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{HyAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
WKzWN	!	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665M		Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665oL	U	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665LK		Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#18766650JcAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062
f-Q	Q	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'P{U	Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665O	!	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665
:Sw	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{Ry	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
:K::W	k
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903EV	
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#1901690U{

Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#19016900Tc	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062
Aa:[	k
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903ZZ	+
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[Y	-
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903:X	k
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903
``^7
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963k]Y
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908963\	
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903
0x0:b	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903:a	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903E`	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#1901690_{
Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#1901690
q Aqf	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903:e	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903Zd	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[c	-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903
q:j	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081:i	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#1938081h7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963kgYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908963

er+V:eD
e6bd9014923fd5db4edcfc633f2800d2d9eda0bd0b416f22bfe615c9c8abf000D
9c883d2d32a12c3f672b6e40119adf476d62ae4bacb40ce0a88634b864d19701D
bbc54477e470a694a3032e391624ba33b9753f81d283b60a19dca7c1c52b35c4D
efd5c472cec8f06ea30eaa8cef287b401fcdf4b0a30e6b2531888ea03f1f9549D
ef07f2b266e0d616931d672568f5c39d7789f51adb7332df77df77b19e7882a4D
e9fa16cde65d0d202fe417fb0585d64a534cd25d39e715a1fb32a75e6620e475D
dfee136c3e1717a2003cc2ab23a101250a304de173d85ce35e611d5481bc08efD
e43708faf11f54060a6b8d9ee565f6c43fdf9b7c1d5537257443dcfe58320462D
880ff35253177a36cd35ad8763cde4cb91281f1e945561e8856f21de6d706dbbD
bea9e14dd6778afded7cb4e5d5a5f3fa3b0fefe9bafbf913cd21dd494fc8a966D
2ef14c819a2c602bcce68d1f84b1e8143bb560f7737ba254e3b07d9c4302af67D

c5741b7e80a2b537f19292e12c2a7fc0a403f25be8a24c117ecec3e7b88a182aD
bc12fc1a4e756efa8689dfeed9925dee6bea368e4e5e865c6972641a3d1f894d
B+Bdm	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#19380811l	YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081k	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081
4A4r7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201kqYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201:p	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:o	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081:n	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081
cAcu	+
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081:t	k
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081:s	k
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#1938081
Ja:x	k
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081dw	?
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#19380811v	Y
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081
gAg}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024|7
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201k{Y
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201:z	k
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:y	k
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081
,mr	[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809O~	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809
AR:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809j	KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809
]:		kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809O	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
AJj
	KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809r	[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:
	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809
Ak1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#1999735'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809
6x"	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#1999735
ZBPqZ'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
dX9	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#19997351Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#1999735
YZ#	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m"	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359!	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735" 	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
+m9'	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359&	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359%	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735$'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
YZ+	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m*	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359)	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"(	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
00_.AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P-	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809,'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
aBa93	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"2	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#199973591	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#199973590	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359/	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735
/6'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z5	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m4	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
G"9	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735_8AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P7	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
ZBPqZ='Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z<	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m;	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359:	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
qGqQ@	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_?AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P>	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/9D	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"C	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
BAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=A	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
/G'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826ZF	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mE	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
qGqQJ	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_IAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366PH	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/qmN	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359M	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
LAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=K	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
!
PQ	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809P'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826ZO	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=T	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529QS	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_RAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aaVAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
ZBPqZZ'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826ZY	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mX	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359W	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
qGqQ]	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_\AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P[	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=^	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
~p~ma	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735`Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
!
Pd	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809c'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Zb	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=g	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Qf	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_eAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aaiAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
hAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
gO]~gm'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Zl	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mk	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735,j[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383

er+V:eD%
339e96b8a52bc311433f3ed0ce535dd62f4808232fb75bf0eaf2b4f0cd82f726D$
04a4cfccd1c263a0f3de420c2200f1e9d5485e3f5734a0c08f2c01c3be01b144D#
230daa889ac4a0bede450aeb0258b6c9db6746486271506eb2037b877bbce588D"
40afa7c237d384eb15a196fb651eecd913e28b743ba7734e05849c45323ff597D!
a58a0b8408d78f804c67f0633541c402b9020555a4986e3fde782bf8544f5f06D 
e4b6df13c59f0686bb12ef575deeaeb4ba581e4d0dd1d2595bf0d7ed9ad2e65fD
e8b67a41970fcee6a5eee5fa362a4648b27e47a04ae221fba0de5f5bc2c64e37D
0ec52bd7a95347c5c330df35b5067f28cdd262383f84e176598367ad11c98a27D
4e6c5997489d089dba27aefe96602ec7208298c2e48067c3ef634fd5a6da5f0dD
7a53443e34cc7fe98a4371e9025389c86bc36e38ca424a98b85b4224bbcac1c8D
f261f44a0301705f4e2b2a56556cdb340ae2487517c8ca12013301b3a983bd58D
bd48e9a406f3a105ecd028149cc4b8df348dc33f19ec4151daa74115a22b11feD
7a967bdf7823255236452e9a45977d7f6c253c9f3c88f18a80ae1ceb606319fd
qGqQp	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_oAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366Pn	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
rAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=q	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,t[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383sAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
00_wAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366Pv	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809u'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
Y*hY
zAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=y	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Qx	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,|[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383{Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
 	7 'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826M~Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r}gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
qGqQ	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
	7_	AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
Y*hY
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q
	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
))_AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366n_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
Y*hY
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
Q	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529n_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
/>/
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,![Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383 Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf$	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M#Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r"gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n%_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
dQ'	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529&1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
/>/
)Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=(	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,+[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383*Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf.	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r,gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n/_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
dd01Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
p,2[ Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#21123831 Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf5	C Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M4 Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r3g Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n6_ Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\8	} Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#222110671 Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
F?Ft:k Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<9	o Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
p,<[!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383;!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf?	C!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M>!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r=g!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n@_!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\B	}!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106A1!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
t?FtME"Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695tDk!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<C	o!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
fF	C"Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191
nG_"Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\I	}"Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106H1"Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)LqA"Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tKk"Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<J	o"Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99N3"Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%MM"Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
C.CfP	C#Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MO#Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695
nQ_#Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\S	}#Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106R1#Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458bR	RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{z|	!$%')+./02568:<?@BEFGÁIāLŁNƁPǁQȁSʁVˁX́Ź]΁_ρbЁdсgҁiӁlՁnցqׁsہv܁x݁{ށ}⁌が䁌偌
恌灌职遌ꁌ끌쁌"큌%'+/26:>AFILQUY]aejnsw{

)?F)VqA#Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tUk#Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<T	o#Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99X3#Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%WM#Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
\d\Z	}$Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106Y1$Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)]qA$Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319t\k$Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<[	o$Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99_3$Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%^M$Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69db	?$Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xa	g$Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914E`
$Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
\d\d	}%Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106c1%Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)gqA%Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tfk%Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<e	o%Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99i3%Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%hM%Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69dl	?%Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xk	g%Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914Ej
%Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630

er+V:eD2
fec7ec65b7db46bf359cb0e984f68dfa1d760320e274306052a510c5d288ed1aD1
55baaa197af05067cb206423655392e7b0a52e3ee9144a1fde30de40eb599d5aD0
3f7b46638efdb99c13fe45aa513af69cad728c4ffca568196d21fed273ba7f97D/
c50443dc25797f6103ba04c6929511b3b0ddfbc2d0ba5c3b956094079715ca98D.
5aa6c18760291c5e22fa5fd2f7960f92c9547071b62e9766ae30bbe111f5e714D-
824340802392135f9a064de630acd55a619c7b8240b3aa7ae13f664637c0f023D,
2bf9825999c7f3930c1032ad0b77786e49c18ee2996e142adc2d28d3b61709edD+
3278f8dbfd0afa8e751afeffde943cb66ed2c2a57495f39ce66a95c3bf852edeD*
542eec90efcf10ac7a2c505eed834595826e5ac255df60ccfed65594368d644cD)
3a95d1dbf8e717a5e29b32daea78a11867867d80343e09ffc29f6c9dedd70720D(
4261abb467f2744c5f43003c5dff6813e00cd4a52c72325f233dddfa3008e983D'
dc69ec026bc1c217d4ab702f2ab40cc5fe01355f2ba29351877fb7a58751e541D&
0ee22c6eb0445485cec58e7d73154100a461cce8a0bf2a9e3b8350e6ad3d073e
99n3&Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%mM&Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69^q?&Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xp	g&Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914Eo
&Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KTs
&Thomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direc؁Or	&Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926eam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82vg&Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926Du	&Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267t	e&Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstr
99x3'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%wM'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69^{?'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xz	g'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914Ey
'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KT}
'Thomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direc߁O|	'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926eam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82g'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926D	'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267~	e'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstr
&2	(Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o	U(Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L	(Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665	(Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f -	Q(Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'{U(Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665	!(Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665	!(Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665
:
w(Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{	y(Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
&2	)Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o
	U)Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L	)Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665	)Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f -	Q)Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'{U)Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665	!)Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665	!)Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665
:w)Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{y)Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
r/;r	!*Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665	!*Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665	*Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o	U*Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L	*Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665
"T"-	Q*Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'{U*Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665
:w*Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{y*Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
WKzW"	!+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665!	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o 	U+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#18766650c*Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062
f-%	Q+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'${U+Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665#	!+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665
:'w+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{&y+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
:K::+	k,Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903E*	,Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#1901690){
,Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#19016900(c+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062
Aa:/	k,Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903Z.	+,Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[-	-,Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903:,	k,Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903
``27,Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963k1Y,Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#19089630	,Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903
0x0:6	k-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903:5	k-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903E4	-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#19016903{
-Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#1901690
q Aq:	-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903:9	k-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903Z8	+-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[7	--Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903
q:>	k.Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081:=	k.Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#1938081<7-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963k;Y-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908963
B+BdA	?.Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#19380811@	Y.Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081?	+.Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081
4A4F7.Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201kEY.Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201:D	k.Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:C	k.Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081:B	k.Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081
cAcI	+/Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081:H	k/Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081:G	k/Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#1938081
Ja:L	k/Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081dK	?/Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#19380811J	Y/Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081
gAgQ0Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024P7/Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201kOY/Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201:N	k/Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:M	k/Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081
,mrU	[0Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:T	k0Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809:S	k0Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809OR	0Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809
AR:Y	k0Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:X	k0Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809jW	K0Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:V	k0Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809
]:]	k1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809O\	1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809[1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024Z'0Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
AJja	K1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:`	k1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809r_	[1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:^	k1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809
Ake12Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#1999735d'1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395:c	k1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:b	k1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809
6x"j	;2Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19997359i	i2Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359h	i2Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359g	i2Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735f	2Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#1999735
ZBPqZn'2Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Zm	+2Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929ml	Q2Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359k	i2Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735

er+V:eD?
58f0137ac65f40eaa3ff281ba91bb68d78f71041a8ab7a9d08578d3ba06cc792D>
054e750bc6d0c6d60f45a6fb60b3bc08bf7902623d269b106db0969e6a028abbD=
56e522d6f6a849ac7522778022a72719f7d1b252990db7cf3bed6b06f753b096D<
4f005504d21283f588231c70d4fdfecc7393a4b60fa72b1498f6aba2985e1d0bD;
46de5f99129eb78da5ff4975f706a21b2b68e99ac0a5aba0c19ea1b67daa44c9D:
3831827b92fb33007bdf9bb579f1947d04221cf988fdfd40615012e00b9500a3D9
89218a788c99c93aaa563b09b3f7b71ed061025bda32116e0f5ad78d034e5d94D8
086c33b98ecb7adbc59297b29fb3fc219e4beda421611ef17471f6cc8e0a9b6fD7
98887262492c65c2f5769777ce9b0419c04f0f6dbf264e6ea58451ec3eb69bd6D6
6b024502ff2b69fb4876076ce49575439e5b94cae11c486cd7c59b464106d825D5
e648ee67624dc2ef09455b433a6f9e43ed3a673d6a32275422c2cd824c5d2e02D4
b62cc8d7fa7e89475ac858e1c622dd266841dcd23fd2841b274d435990854ddeD3
3c68468d65b23e5a50cce88db5e3d11674fb488c8e0bf375200f6f529c438a20
dX9s	i3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359r	i3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359q	i3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735p	3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#1999735o13Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#1999735
YZw	+3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mv	Q3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359u	i3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"t	;3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
+m9{	i4Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359z	i4Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359y	i4Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735x'3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
YZ	+4Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m~	Q4Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359}	i4Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"|	;4Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
00_A4Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P	4Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809'4Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
aBa9	i5Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"	;5Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19997359	i5Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359	i5Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359	i5Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735
/
'5Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z		+5Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	Q5Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
G"
	;6Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735_A5Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P	5Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
ZBPqZ'6Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+6Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	Q6Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359	i6Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
qGqQ	6Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_A6Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P	6Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/9	i7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"	;7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
6Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	q6Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
/'7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	Q7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
qGqQ	7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_A7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P	7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/qm"	Q8Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359!	i8Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
 7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	q7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
!
P%	8Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809$'8Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z#	+8Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=(	q8Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q'	8Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_&A8Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aa*8Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
)8Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
ZBPqZ.'9Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z-	+9Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m,	Q9Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359+	i9Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
qGqQ1	9Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_0A9Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P/	9Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
39Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=2	q9Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
~p~m5	Q:Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#199973549Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
!
P8	:Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#20228097':Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z6	+:Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=;	q:Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q:	:Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_9A:Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aa=:Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
<:Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
gO]~gA';Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z@	+;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m?	Q;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735,>[:Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383
qGqQD	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_CA;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366PB	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
F;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=E	q;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,H[;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383G;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
00_KA<Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366PJ	<Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809I'<Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
Y*hY
N<Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=M	q<Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529QL	<Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,P[<Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383O<Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
 	7 S'=Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826MR<Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rQg<Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
qGqQV	=Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_UA=Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366PT	=Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
X=Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=W	q=Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,Z[=Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383Y=Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
	7_]A>Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366M\=Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r[g=Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
Y*hY
`>Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=_	q>Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q^	>Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,b[>Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383a>Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lfe	C>Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191Md>Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rcg>Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
))_gA?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366nf_>Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
Y*hY
j?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=i	q?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Qh	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,l[?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383k?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lfo	C?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191Mn?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rmg?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
Qq	@Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529np_?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111

er+V:eDL
6982c05564f03f4db81df93b42eeb29b22e1c82675c42eaf1077f90bf1847c7aDK
2c301bfa4814d7a20e642e7fec605dacbeef49885fa13f382cd7c85e03e827dfDJ
5c3e30fe5f331dff8d929397fe55cd6da4c97325fd1c26f6c51b2567a15414e5DI
556772de85dcdb8d7bf429e3cca280e03ffdcdd1ee99bff14fef8b64b6c102a5DH
d76bb9d2f1d62a9fed452572a310fc87fca445e6330ebfd58bbedafcd6dc171bDG
6c8d7f6e3e1e16170883c18ddcbe50ef6eb86c9a8222fb7fe4f75b91670adc57DF
be2cf27ae12e4ffcf8e8d79ef82ec36c4c7d67299d1b3bf9e1ceb0325e08de8bDE
0150773cdef45797820d481008b2e7297bc32060b190f3493a27354e52ffb8baDD
f676e5412e87446863b10f16b82807f5a4324279353554edb7aeb3cfa9143061DC
a33d9ecd05eaa2248f7384075877e78357534a302081fc03a9b5f0dcc71df48fDB
06d6c8fc8acd6bccaac9dcec5bc4fadf0a2b38f66fac335962e0352a7d2bf9bfDA
60647855ba6fb280673a3654ce82ab9610ce8bcdca3ea825ad3ea4023b200fdcD@
ea3f0bb12ce7b5c386ca301b0f16f7dddafa4ed5f63b2ab2cd2fe297d066f387
/>/
s@Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=r	q@Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,u[@Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383t@Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lfx	C@Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191Mw@Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rvg@Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
ny_@Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
dQ{	AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529z1@Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
/>/
}AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=|	qAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,[AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383~AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502bRuRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{

"%(*.1358;=ADFHKN P!S"V#X$Z%]&`'b(e)g*j+l,o-q/s0u1x2y3{4}5789:;	<
=>?@ABCDEFG H"I$J%K'L*M,N.O1P3Q6R8S;T=U@VBWEXG\J]L^O_QcTdXe\f^gbhfihjmkolqmvoyp{qrst

L	7Lf	CAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n_AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
dd1AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
p,[BAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383BAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf		CBAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MBAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgBAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n
_BAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\	}BAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#22211061BAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
F?FtkBAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<
	oBAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
p,[CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf	CCAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MCAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgCAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n_CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\	}CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#22211061CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
t?FtMDAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695tkCAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<	oCAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
f	CDAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191
n_DAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\	}DAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#22211061DAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F) qADJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tkDAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<	oDAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99"3DAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%!MDAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
C.Cf$	CEAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M#EAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695
n%_EAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\'	}EAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106&1EAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)*qAEJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319t)kEAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<(	oEAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99,3EAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%+MEAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
\d\.	}FAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106-1FAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)1qAFJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319t0kFAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106</	oFAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
9933FAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%2MFAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69d6	?FAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965x5	gFAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914E4
FAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
\d\8	}GAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#222110671GAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F);qAGJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319t:kGAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<9	oGAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99=3GAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%<MGAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69d@	?GAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965x?	gGAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914E>
GAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
99B3HAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%AMHAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69^E?HAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xD	gHAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914EC
HAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KTG
HThomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direcYOF	HAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926[eam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82JgHAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926DI	HAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267H	eHAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstrZ
99L3IAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%KMIAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69^O?IAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xN	gIAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914EM
IAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KTQ
IThomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direc`OP	IAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926beam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82TgIAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926DS	IAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267R	eIAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstra
&2X	JAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665oW	UJAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665LV	JAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665U	JAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f -\	QJAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'[{UJJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665Z	!JAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665Y	!JAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665
:^wJAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{]yJAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
&2b	KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665oa	UKAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L`	KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665_	KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f -f	QKAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'e{UKJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665d	!KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665c	!KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665
:hwKAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{gyKAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
r/;rm	!LAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665l	!LAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665k	LAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665oj	ULAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665Li	LAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665
"T"-o	QLAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'n{ULJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665
:qwLAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{pyLAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
WKzWv	!MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665u	MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665ot	UMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665Ls	MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#18766650rcLAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062

er+V:eDY
e1931c2c08f74962ec1d742c785c518f1942b86d552b9e27d9cb776d4c555f8aDX
758d2c3a908dc2f48b1ab2c25ec323231a54e2b646281ebbd88192b61617775eDW
518082fd34ea1c14e44917a04af17aa6e3307369f369dbe369f0fdf4e5b8e1eaDV
5013f655f5321c66d30f6ab553d640e8a1df541105200e36eeae415ca903a7acDU
f97dd6a530e0dc37dde8d1e71e04e877196e4f36ac6754904cd6a5e8e0e4990fDT
9512843f182c5c1950953d11669afc9c97394a90e3b4ebda1834fab7b5a97d88DS
5001584535af6ba52a00d1913b2b5f60df1239116a2cbcff84db48a9359bd3a3DR
c6fc833a542f540c1edc0431e34f06b0cd121fc635294ae62ae5d48fab254ddfDQ
242b3c3eb9d45d48b5e607845d5fbc380afca79449f49cf9cd801ea4a95ef419DP
124b95517eeee9deb9fa4cef2707b16c5530d6c6f263462b2c3deb2f8811b3d8DO
917745f55091ed42757a3d445e0f98ebd8e84ff75ab716acbdd8f6e1c584a8fdDN
2e1ba328190cee6e94f98145224aec06902152d1cc3188f06c1ac84dc0887d0bDM
7a5f1f1bd0da49fe22b1022a7bf998826161eacca343e82125f1b036b9cdbdac
f-y	QMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'x{UMJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665w	!MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665
:{wMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{zyMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
:K::	kNAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903E~	NAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#1901690}{
NJiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#19016900|cMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062
Aa:	kNAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903Z	+NAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[	-NAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903:	kNAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903
``7NAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963kYNAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908963	NAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903
0x0:
	kOAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903:		kOAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903E	OAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#1901690{
OJiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#1901690
q Aq	OAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903:
	kOAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903Z	+OAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[	-OAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903
q:	kPAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081:	kPAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#19380817OAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963kYOAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908963
B+Bd	?PAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#19380811	YPAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081	+PAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081
4A47PAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201kYPAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201:	kPAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:	kPAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081:	kPAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081
cAc	+QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081:	kQAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081:	kQAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#1938081
Ja: 	kQAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081d	?QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#19380811	YQAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081
gAg%RAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024$7QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201k#YQAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201:"	kQAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:!	kQAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081
,mr)	[RAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:(	kRAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809:'	kRAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809O&	RAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809
AR:-	kRAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:,	kRAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809j+	KRAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:*	kRAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809
]:1	kSAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809O0	SAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809/SAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024.'RAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
AJj5	KSAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:4	kSAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809r3	[SAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:2	kSAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809
Ak91TAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#19997358'SAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395:7	kSAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:6	kSAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809
6x">	;TAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19997359=	iTAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359<	iTAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359;	iTAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735:	TAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#1999735
ZBPqZB'TAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826ZA	+TAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m@	QTAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359?	iTAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
dX9G	iUAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359F	iUAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359E	iUAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735D	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#1999735C1UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#1999735
YZK	+UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mJ	QUAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359I	iUAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"H	;UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
+m9O	iVAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359N	iVAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359M	iVAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735L'UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
YZS	+VAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mR	QVAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359Q	iVAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"P	;VAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
00_VAVAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366PU	VAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809T'VAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
aBa9[	iWAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"Z	;WAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19997359Y	iWAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359X	iWAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359W	iWAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735
/^'WAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z]	+WAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m\	QWAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
G"a	;XAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735_`AWAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P_	WAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
ZBPqZe'XAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Zd	+XAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mc	QXAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359b	iXAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
qGqQh	XAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_gAXAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366Pf	XAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/9l	iYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"k	;YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
jXAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=i	qXAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
/o'YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Zn	+YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mm	QYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
qGqQr	YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_qAYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366Pp	YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/qmv	QZAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359u	iZAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
tYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=s	qYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529

er+V:eDf
dc1cfb04b799c30dca02faae2f75f5cc94d83b63b11cf8e7acb33ed1b252117fDe
2b1a27963b4d2d2d4589a7d96e361c8f4359cb51ad10f5e108215c381d491ba3Dd
cb3ea59253d078a2c7a60ff6f6c3f55bf94679248c132be8e27c534245acd6c8Dc
1ab3f90a7eed6a0e8f44c9833e1def98bdbceb194f37062e21cfb6fb030563e2Db
3b5a17995e4660d4c305944c4a13cd1bd8bdda18b9d69d13031b2b1044e1cd77Da
aa3730bd40f0c5b60ded75b15d9a0b7f845a26219a0a739f877d6d2ac7161c6fD`
0c8fb84a63da81ffc9727d465f04ac197820bce6473ad8ca5f2d241c6cdfb9a7D_
7de0016fd49560394d1c4f5584dd396e5b41989957702068ef31979934c299ddD^
f13d571f41792afa9d08465580b23f08ff7dd564e51f40e42a9b9f3a0ff77b62D]
1f0f6113c67eb17059e2588bc76ce4d1ce793113d638c89faf42684d92ac2c3eD\
6d23e0e03a7a536fe3cae17f34dc45960c361e2ee84b11158681f3db86dbb0b3D[
f0c9b7b923d47df8b92aa0c427d4754da9c2d22e9eb87e436c06305406998a3cDZ
96d0ea79b3da11f9b3d85598dae3187e501c54728cd8509492569f9dc2c1670f
!
Py	ZAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809x'ZAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Zw	+ZAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=|	qZAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q{	ZAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_zAZAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aa~ZAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
}ZAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
ZBPqZ'[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	Q[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359	i[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
qGqQ	[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_A[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P	[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	q[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
~p~m		Q\Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
!
P	\Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809'\Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z
	+\Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=	q\Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q	\Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_
A\Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aa\Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
\Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
gO]~g']Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+]Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	Q]Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735,[\Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383
qGqQ	]Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_A]Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P	]Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
]Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	q]Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,[]Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383]Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
00_A^Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P	^Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809'^Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
Y*hY
"^Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=!	q^Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q 	^Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{vwxyz {%|)}-~159>BGKOSV[^aehlorvy|~	"$'*,.1469;>@CEGILMOQSVWXZ]^`bdghÁjāmŁnƁoǁqȁtɁvˁx́ý{΁~ρЁсҁӁ
ԁՁցׁ؁فځ
p,$[^Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383#^Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
 	7 ''_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826M&^Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r%g^Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
qGqQ*	_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_)A_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P(	_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
,_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=+	q_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,.[_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383-_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
	7_1A`Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366M0_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r/g_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
Y*hY
4`Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=3	q`Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q2	`Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,6[`Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#21123835`Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf9	C`Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M8`Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r7g`Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
))_;AaAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366n:_`Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
Y*hY
>aAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422==	qaAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q<	aAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,@[aAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383?aAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7LfC	CaAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MBaAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rAgaAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
QE	bAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529nD_aAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
/>/
GbAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=F	qbAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,I[bAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383HbAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7LfL	CbAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MKbAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rJgbAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
nM_bAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
dQO	cAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529N1bAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
/>/
QcAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=P	qcAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,S[cAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383RcAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7LfV	CcAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MUcAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rTgcAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
nW_cAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
ddX1cAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
p,Z[dAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383YdAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf]	CdAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M\dAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r[gdAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n^_dAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\`	}dAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106_1dAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
F?FtbkdAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<a	odAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
p,d[eAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383ceAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lfg	CeAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MfeAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695regeAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
nh_eAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\j	}eAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106i1eAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
t?FtMmfAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695tlkeAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<k	oeAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
fn	CfAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191
no_fAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\q	}fAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106p1fAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)tqAfJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tskfAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<r	ofAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99v3fAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%uMfAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577

er+V:eDs
8fab540ec8ac058e28cb3e62a08c210f00ce22695ad5a2b0412d48e0f77c285aDr
2ff94d80fcae8e5f2ae6416eb0e955f4149e7639722b5426b2b8f12150cc14bbDq
313a86e45fc4b42084c618c11f233c1ab6950f5af7ce19f962ea3fd1020736ebDp
da4cd5b16857b9f434f773471d103d61dba9fbe99a3264cfce051444c342cf1bDo
009c4fd4d1a151a215ef1a31eb4f5b076e16ad5bd1c6bed249571dfdde69a686Dn
bd09647e7e930afde068aa13eae3a3f7166bcf0d4918c52f525b47c511c7b692Dm
030b52a92f3fd60b2df1b1fee6a964377bc4d80776dbdfcfae051132e0c3815cDl
811548ea9fa1b1fd4ba32a27977ce75a08bd90e1f90d50bbdfaabe36480c3f46Dk
b7c575cffd422a15f77eaeb8f4a41cc6e965c486511f363df2d62887b7934eb0Dj
66c5f4e48d6872789f81a04ef48fceb67a1705aadd369b0ccff804cb0eefeda9Di
a18aeb73905ede9c9bd2f5ab9736372813b7662678482ea5ad4990ce21b77ae9Dh
985cd3c30e1357c60af6a5b4425c5d16eca3e6970da5871aca65ecca4c468cd1Dg
1a73f880c24703aeacd0795c62a4ddd8fe4db2ca199a961180176c9713e3fdf2
C.Cfx	CgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MwgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695
ny_gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\{	}gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106z1gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)~qAgJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319t}kgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<|	ogAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
993gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%MgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
\d\	}hAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#22211061hAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)qAhJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tkhAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<	ohAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
993hAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%MhAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69d
	?hAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965x		ghAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914E
hAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
\d\	}iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#22211061iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)qAiJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tkiAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<
	oiAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
993iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%MiAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69d	?iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965x	giAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914E
iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
993jAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%MjAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69^?jAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965x	gjAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914E
jAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KT
jThomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direcہO	jAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926eam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82gjAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926D	jAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267	ejAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstr
99 3kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%MkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69^#?kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965x"	gkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914E!
kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KT%
kThomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direcO$	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926eam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82(gkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926D'	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267&	ekAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstr
&2,	lAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o+	UlAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L*	lAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665)	lAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f -0	QlAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'/{UlJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665.	!lAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665-	!lAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665
:2wlAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{1ylAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
&26	mAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o5	UmAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L4	mAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#18766653	mAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f -:	QmAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'9{UmJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#18766658	!mAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#18766657	!mAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665
:<wmAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{;ymAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
r/;rA	!nAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665@	!nAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665?	nAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o>	UnAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L=	nAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665
"T"-C	QnAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'B{UnJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665
:EwnAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{DynAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
WKzWJ	!oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665I	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665oH	UoAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665LG	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#18766650FcnAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062
f-M	QoAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'L{UoJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665K	!oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665
:OwoAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{NyoAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
:K::S	kpAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903ER	pAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#1901690Q{
pJiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#19016900PcoAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062
Aa:W	kpAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903ZV	+pAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[U	-pAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903:T	kpAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903
``Z7pAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963kYYpAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908963X	pAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903
0x0:^	kqAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903:]	kqAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903E\	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#1901690[{
qJiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#1901690
q Aqb	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903:a	kqAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903Z`	+qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[_	-qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903
q:f	krAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081:e	krAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#1938081d7qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963kcYqAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908963
B+Bdi	?rAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#19380811h	YrAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081g	+rAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081
4A4n7rAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201kmYrAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201:l	krAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:k	krAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081:j	krAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081
cAcq	+sAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081:p	ksAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081:o	ksAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#1938081
Ja:t	ksAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081ds	?sAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#19380811r	YsAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081
gAgytAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024x7sAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201kwYsAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201:v	ksAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:u	ksAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081

er+V:eD
496ca22ef6b436dbee6813613f31f2ebe1718fbe7c53d90796a6f3f18ee0a331D
3fc86cf389acff5dfff9dfd65e25b9d96d358214bd2bd236061ed31d647ad9bbD~
fd17cae7a3075f2ad58ed62ad9a2bb016b9d0ecbda3ed31b464e395e00f4dcb9D}
5435c138b53b3d77c61b682fd1142b6ebad9946a7aafbb1f722f6f9a4896a265D|
e1e1b8adc5317dafcd61f9374708c3ef7388ecd2591a47bb2dfdedc0eee9d389D{
8b93611a7e50ab8b817c59d6ef504cf63f14b1ba210b4da69add3f3176898478Dz
f22ced6e5193aa0b22495fa95e9de588c04f9afa2d6070faf801306fc7e68363Dy
c2800a0089be75b093cde6c6c8289a71707f6b56b3e1e3655e237dd5229856efDx
7fa5ad9d67b6a38b005e9e2a1e8217c78399fa4a6135965a3d32ed6d2ab0889cDw
1282baff4a36da2985cd30f9ea8f45ff5c8aa9ed747e858cf20363a7b30022abDv
769a4e98dcdf66de7159dd3adbff251c61fcb448ebdacbcc474122895e9cf709Du
2ced5602fa70385602b80de9a0a4dd9347186ade416907e8bb7fd066af18f6e3Dt
00dfecc575f562ca6c58f3290ca7fda9b19bbacf629d7c687dc4242984f8bb37
,mr}	[tAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:|	ktAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809:{	ktAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809Oz	tAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809
AR:	ktAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:	ktAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809j	KtAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:~	ktAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809
]:	kuAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809O	uAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809uAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024'tAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
AJj		KuAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:	kuAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809r	[uAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:	kuAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809
Ak
1vAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#1999735'uAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395:	kuAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:
	kuAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809
6x"	;vAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19997359	ivAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359	ivAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359	ivAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735	vAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#1999735
ZBPqZ'vAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+vAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	QvAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359	ivAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
dX9	iwAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359	iwAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359	iwAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735	wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#19997351wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#1999735
YZ	+wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	QwAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359	iwAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"	;wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
+m9#	ixAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359"	ixAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359!	ixAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735 'wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
YZ'	+xAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m&	QxAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359%	ixAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"$	;xAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
00_*AxAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P)	xAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809('xAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
aBa9/	iyAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735".	;yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19997359-	iyAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359,	iyAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359+	iyAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735
/2'yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z1	+yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m0	QyAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
G"5	;zAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735_4AyAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P3	yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
ZBPqZ9'zAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z8	+zAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m7	QzAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#199973596	izAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735bRGRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{߁ #ၑ%偑(恑,灑0聑2遑6ꁑ:끑<쁑A큑CEJMOSWZ^bfinqty}	
#'	*
/25
9<@CFJMPRVY[]`ceil n!p"s#v$x%{'~()*+,
-
./012345 6!7#8%9':*;+<,=.>1?2@4A6B8C;D<E>FA
qGqQ<	zAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_;AzAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P:	zAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/9@	i{Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"?	;{Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
>zAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422==	qzAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
/C'{Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826ZB	+{Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mA	Q{Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
qGqQF	{Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_EA{Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366PD	{Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/qmJ	Q|Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359I	i|Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
H{Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=G	q{Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
!
PM	|Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809L'|Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826ZK	+|Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=P	q|Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529QO	|Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_NA|Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aaR|Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
Q|Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
ZBPqZV'}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826ZU	+}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mT	Q}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359S	i}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
qGqQY	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_XA}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366PW	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
[}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=Z	q}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
~p~m]	Q~Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735\}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
!
P`	~Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809_'~Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z^	+~Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=c	q~Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Qb	~Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_aA~Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aae~Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
d~Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
gO]~gi'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Zh	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mg	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735,f[~Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383
qGqQl	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_kAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366Pj	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
nAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=m	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,p[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
00_sAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366Pr	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809q'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
Y*hY
vAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=u	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Qt	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,x[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
 	7 {'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826MzAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rygAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695

er+V:eD

832470ee4b64e39723111ada3304a733f57c404fb89c7383123a52f33bbde6d6D
bd49c65cde81a93d80eed77c33ebfb093577ce199e9c182c9d77e73774072f37D
7b1c52bbe226abacf3c7479ca52c3d631af47e215754ccfb2ad53c6226e13392D

42867004de7a228cf85955e79762cca11cfedcace4742b7caa46109e8131839aD	
76640b341c1b50d068385f178412bff6541f41c567500e0f8e16463cdeb30c40D
6e70e53e5187df893930a8cf3cec44c126d94196925b1a43fa27f481acdeb5bbD
e14e58cd6c0a61d873c99c10de7e5a36ec844b84147e4656a784e33c1b0715b4D
81b502f5e282e58db43c00894f89f50523953165c64a408ef983aa2829145c7aD
30f27f7cbabd3d9bee929e1fa43a3ac2a916c5a427598ee5e816dd100518994dD
ee0b6ee143ba37c13abc5858fef0725d5b30992afdcaff90babcd5af1ac812c8D
67c66396a0ecb57afd6c3a2f070e239f41c72943e3c3994c64e68c02a4cc1829D
4b31ab8ebd6b1481a2299adfff2b7d616abc0233760f8745ec256b96b86d0077D
7479424a5b57460d14eb031904fe5f6c5eacebff7fa6b708fb1b98b33a6b3900
qGqQ~	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_}AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P|	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
	7_AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
Y*hY
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,
[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf
	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
))_AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366n_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
Y*hY
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
Q	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529n_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
/>/
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf 	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n!_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
dQ#	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529"1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
/>/
%Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=$	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,'[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383&Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf*	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M)Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r(gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n+_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
dd,1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
p,.[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf1	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M0Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r/gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n2_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\4	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#222110631Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
F?Ft6kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<5	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
p,8[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#21123837Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf;	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M:Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r9gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n<_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\>	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106=1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
t?FtMAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695t@kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<?	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
fB	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191
nC_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\E	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106D1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)HqAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tGkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<F	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99J3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%IMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
C.CfL	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MKAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695
nM_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\O	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106N1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)RqAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tQkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<P	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99T3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%SMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
\d\V	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106U1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)YqAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tXkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<W	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99[3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%ZMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69d^	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965x]	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914E\
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
\d\`	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106_1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)cqAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tbkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<a	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99e3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%dMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69dh	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xg	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914Ef
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
99j3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%iMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69^m?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xl	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914Ek
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KTo
Thomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direc\On	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926^eam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926Dq	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267p	eAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstr]
99t3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%sMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69^w?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xv	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914Eu
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KTy
Thomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direccOx	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926eeam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82|gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926D{	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267z	eAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstrd

er+V:eD
a706d40bf0fcf24324c24d5742ca54450b84792752d49ed7af95192bcd3e4527D
2f7c6c553d364083a3603f33a066c8031c3bc2f1e9c8bb2d64b355daf9a42c2bD
71e8109b89c2bfa0c40687b649c02bd70e7702214ec1fb76fe606db76ace6affD
0a35810bd924f95ae2af1ba31051f64c8683e42b953329a6af07ea00495f96a2D
c7627b2a018e4b1db2b6131608528eae404bf3c43ab252995b1d5f7196ab97e1D
614205bf0041e0a5d32d64bd0743218a5ed52c6dcd8e5880076d87abff2016b2D
bc495afc92d333d543576431a1cfc03dccc3bda5282057211d2065d0032129f1D
f3ebae8493971694208c96d6d6286e660e797bed742700585d403ce9fd145072D
39bc056b01daeb577a1d13e5d56959179803eea2c53c39eeff982663bc189df1D
7afb4c27414189dd2a2cc1df1ce6c80ad77c0eb59aca381a22a3f4033f950c67D
1497a77c838103e684f02aef90dea21228feaeec08fb162ab52cb8db75cd682fD
97077fe95c5fd7927b97fea9e945e2065d9ef3dd5ca4eb757666fdc5b42ad749D
56b0e8da36b334813521cd572d937eb75a589047d4c9a956b630d239792bf4e6
&2	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L~	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665}	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f -	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'{UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665
:wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
&2
	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o		UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f -	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'
{UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665
:wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
r/;r	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665
"T"-	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'{UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665
:wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
WKzW	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#18766650cAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062
f-!	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665' {UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665
:#wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{"yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
:K::'	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903E&	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#1901690%{
Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#19016900$cAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062
Aa:+	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903Z*	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[)	-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903:(	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903
``.7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963k-YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908963,	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903
0x0:2	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903:1	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903E0	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#1901690/{
Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#1901690
q Aq6	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903:5	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903Z4	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[3	-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903
q::	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081:9	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#193808187Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963k7YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908963bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{HCIEJHKJLLMMNOORPTQVRYS[T^U`VcWeXhYjZm[o_r`tawbyf|hijk
lmnopqr!s#t'u+v.w2x6y:{=|B}E~HMQUY]afjosw{~	
!$&*-/1479=@BDGJLORTVY\^acfhk
B+Bd=	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#19380811<	YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081;	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081
4A4B7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201kAYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201:@	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:?	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081:>	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081
cAcE	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081:D	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081:C	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#1938081
Ja:H	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081dG	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#19380811F	YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081
gAgMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024L7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201kKYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201:J	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:I	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081
,mrQ	[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:P	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809:O	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809ON	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809
AR:U	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:T	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809jS	KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:R	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809
]:Y	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809OX	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809WAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024V'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
AJj]	KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:\	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809r[	[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:Z	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809
Aka1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#1999735`'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395:_	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:^	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809
6x"f	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19997359e	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359d	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359c	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735b	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#1999735
ZBPqZj'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Zi	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mh	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359g	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
dX9o	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359n	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359m	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735l	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#1999735k1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#1999735
YZs	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mr	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359q	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"p	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
+m9w	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359v	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359u	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735t'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
YZ{	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mz	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359y	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"x	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
00_~AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P}	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809|'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826

er+V:eD'
6182e47b9746410469ab21c90f69c924a80ceff0a394abd6a25a441e8d6cc49eD&
b554df264228a60d69e256e2f70f55d320abe544bb18085a944c35b983f83b21D%
214fc2bc53e4979642949a2ce8ea6bd43bff20e98fa27016ae4ad1be3c189b60D$
f154f7fbe4285c64fd5d8032253657798d0717ac258ce5a8ece9b6e798df388cD#
d2490b1f0f83f60017971858b0aa1f5aba0285093f3b53cdaa0e5a1dd65b282bD"
f82689a8168490ea030790e836a9ce025ac23d19836b5ef4eb2d441b7d99d8a0D!
11babb3c74159846537e70da4fb01e148e8741a334bdc4689a5eb16b24a1a181D 
12efe5e7e0fc2ad175b1c36f053e1a4532e1f85d27fe3489623cb945a5908677D
5941cfa3708aa1d7eae457e8f0abc55a55d5a84eadb56473770f0a82215aa495D
c204a4ffd212c3a27c0afea8e7c43b386fac6da8dfb78049b8fff2cea01ea128D
3d985b2d2ec13d506f3e32f82236c706a953bf9178605bd7e9c559e99fe33c06D
d17c2ab42cfa6667afaac7434e92be20fd0330b7a2cf8ad897daec993049f5e9D
a3cd127f94e232f4ccaddd486ee240986e25b65c51ab664b49ec511d5310482c
aBa9	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735
/'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
G"		;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735_AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
ZBPqZ
'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359
	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
qGqQ	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/9	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
/'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
qGqQ	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/qm	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
!
P!	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809 'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=$	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q#	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_"AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aa&Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
%Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
ZBPqZ*'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z)	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m(	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359'	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
qGqQ-	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_,AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P+	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
/Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=.	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
~p~m1	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997350Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
!
P4	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#20228093'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z2	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=7	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q6	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_5AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aa9Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
8Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
gO]~g='Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z<	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m;	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735,:[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383
qGqQ@	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_?AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P>	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
BAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=A	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,D[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
00_GAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366PF	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809E'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
Y*hY
JAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=I	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529QH	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,L[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
 	7 O'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826MNAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rMgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
qGqQR	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_QAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366PP	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
TAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=S	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,V[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
	7_YAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366MXAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rWgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
Y*hY
\Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=[	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529QZ	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,^[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383]Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lfa	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M`Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r_gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
))_cAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366nb_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
Y*hY
fAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=e	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Qd	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,h[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lfk	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MjAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rigAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
Qm	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529nl_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
/>/
oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=n	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,q[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383pAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lft	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MsAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rrgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
nu_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
dQw	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529v1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
/>/
yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=x	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,{[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383zAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf~	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r|gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
dd1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458

er+V:eD4
60639db656637bac71a8495c83b9cc351c89b200e836ed3343dfa6bca29e3956D3
09c09056918a1d0fcf94103b7cc7f9728ea6f763a2c2d3db5a1a470846afc777D2
43d76c869fe744e94bf344aa66f638f4afcac144a43ed4d8336d4147ae3bb81eD1
29bd25debd6689e7eb9f2261280bdb1b0233f6d1bf8099f49d31d530c4432eb0D0
e55f9021fa118e217df9db527f05fb35638c68975d0977584ac974b8c6a6bddfD/
903dd1548295c69291a624080d2c82e710a22a8ff376f018d6fd3a0f4d907c85D.
5f5b887dfc9f6ab8986542411f965a160cefec2bd50e34635046cb950eb7d93dD-
60f47d3d5a4d59ab230916a44b7ecff881116a21de176de5276bd96e52ac5c3eD,
61ce4b03660d33874c07cc8931ddbfe63af33129c020331fef0850ec847167e3D+
13c47236e82fe68997766cf6d15ce0201350f4f534beee1f7e77dbee3e461cf0D*
f5e02cd3cf204b648c7dd511674fd8b54070efe7521303ff43080cfcb8b074a3D)
6dce766bf15259d4d1a7aba1acd135a56d9bb61b6d653cef2da6590e890d9fd9D(
ad1b644027e6c6f011f3ffcc714aa27825b548561a43f88debe325f3ed0dee5e
p,[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#22211061Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
F?Ft
kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<		oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
p,[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r
gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#22211061Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
t?FtMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695tkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
f	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191
n_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#22211061Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)qAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
993Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
C.Cf 	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695
n!_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\#	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106"1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)&qAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319t%kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<$	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99(3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%'MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
\d\*	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106)1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)-qAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319t,kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<+	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99/3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%.MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69d2	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965x1	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914E0
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
\d\4	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#222110631Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)7qAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319t6kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<5	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
9993Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%8MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69d<	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965x;	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914E:
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
99>3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%=MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69^A?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965x@	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914E?
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KTC
Thomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direcށOB	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926eam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82FgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926DE	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267D	eAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstr
99H3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%GMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{oqtuwy{~Á
āŁƁǁȁɁʁˁ́́΁ ρ!Ё#с&ҁ(Ӂ*ԁ-Ձ/ց2ׁ4؁7ف9ځ<ہ>܁A݁CၖF⁖H䁖K偖M遖PꁖT끖X쁖Z큖_acgkorv{"%(*-0247	:
<?B
DGIKMPQRTWXZ]^_adf
69^K?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xJ	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914EI
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KTM
Thomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direcOL	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926eam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82PgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926DO	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267N	eAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstr
&2T	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665oS	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665LR	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665Q	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f -X	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'W{UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665V	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665U	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665
:ZwAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{YyAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
r/;r_	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665^	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665]	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o\	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L[	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665
"T"-a	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'`{UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665
:cwAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{byAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
:K::g	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903Ef	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#1901690e{
Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#19016900dcAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062
Aa:k	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903Zj	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[i	-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903:h	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903
`:o	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#1938081n7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963kmYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908963l	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903
lA"l1r	YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081q	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081:p	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081
X:v	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:u	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081:t	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081ds	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#1938081
RqR:{	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809Oz	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024x7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201kwYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201
AJj	KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:~	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809r}	[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:|	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809
Ak1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#1999735'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809

er+V:eDA
919e733f2ea0f03322ddd4ac6824dcb44dd6d5fcaabb66ccb9afee48b8b78718D@
0b44e2a7472e36fcf462b7b85a5bbc147c95150b55e8d7e6dc3fe4977c7cdc76D?
f707cfc509f1fd8d7d482b5937245f4dbfc078d16c4defb7fef772d41daac079D>
c253a31b070bc89bcd355eeb3c549a299fb205b9c6badcc9d3e7254057f26ef3D=
6a35640d03a1109ec551440c9e15e05aac57712c85cd6644b826678181e23b5dD<
b436b196f3c2735dddfe5727a948d1a2e443bdebffd7018905aa2558baba56d9D;
3daac146d8edbefdb34bcb729d74336de8f1afbaee929dc55464706da7615618D:
46a04b65f068cbfdca98fdfb989911df818cda7f362078f3f1fdede4d819cc71D9
8b0d31d3b3732537ed9539107e868dbb4725488aa14e7a5070bee4b31e133318D8
1724001fdb91ff6c4e1fcf64bccf981017dfd7ab649f21c1333810e6cbd8e9c6D7
029a613293d1ba49b765f0f2ec6fc0b71f6fd43fb1ceff50f43e05dc84f98d20D6
bf1fe8afbf03b29de5f3eba68d356ac251478692658c6449b4cda08c73d4d4f8D5
5a11f15beb55665259230a77f5624af4b896062e2a61b610d31d355500431f88
6x"	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#1999735
ZBPqZ'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m
	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359		iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
aBa9	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359
	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735
/'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
G"	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735_AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
ZBPqZ'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
qGqQ	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/qm"	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359!	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
 Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
!
P%	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809$'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z#	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=(	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q'	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_&AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aa*Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
)Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
/-'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z,	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m+	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
qGqQ0	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_/AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P.	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
2Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=1	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,4[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#21123833Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
00_7AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P6	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#20228095'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
Y*hY
:Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=9	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q8	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,<[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
	7_?AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366M>Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r=gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
Y*hY
BAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=A	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q@	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,D[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7LfG	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MFAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rEgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
QI	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529nH_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
/>/
KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=J	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,M[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383LAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7LfP	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MOAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rNgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
nQ_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
ddR1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
p,T[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383SAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7LfW	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MVAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rUgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
nX_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\Z	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106Y1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
t?FtM]Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695t\kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<[	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
f^	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191
n__Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\a	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106`1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)dqAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tckAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<b	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99f3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%eMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
\d\h	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106g1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)kqAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tjkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<i	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99m3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%lMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69dp	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xo	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914En
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
99r3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%qMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69^u?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xt	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914Es
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KTw
Thomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direc&Ov	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926(eam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82zgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926Dy	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267x	eAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstr'
&2~	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o}	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L|	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665{	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f -	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'{UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665
:wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665

er+V:eDN
c62386a6973d93798bd5a17ee72907932c0796c21589648ab5f313805f6ae46cDM
fa80c361dec771feb54951286af7bb8032aef89cd8ded021b942b091ad431e5dDL
5c0a4fb7b658b9dca77b858ff98bd534bbc056c94aa438b11b253b1da80720a4DK
a3461547f0108720d6413695a5d1110d735d6a9359910eca40e788f625bab184DJ
5b66719aa307b84457c7ac3edc58f4b71cc65248e0ef006e5fee0c3e52896b5fDI
707c34f7fa9d4787f56722da43ebdb1458d9855c217691d5688c6bde0306a2b7DH
575e728d855d72fba88b860be7518db2c8fa0dc1add9046074dd5d320e1156bbDG
be582ab129bf0e7739face571fb544ef2d038667883f4d15867fa2c2c302f748DF
c72c2effb396db8fd12fe1bf50dc5ae0543a4d684cc6990bc2a8f8c1c707bd2aDE
9deefb8ac4e6a1d43c4894b9e5daf58d70b43a9f12952164dc89a1d15e5a400cDD
0380151eff2395148f47a991620ec2bd74e74d330969f2c6d6c0a064a0278166DC
895038cbd6764ef3eb9ee3cd61f7aeb95255a9dab0f3a8da8ecf81d235a2abc1DB
3f73609586cbfb03e673487d50c8317cc03657e173b51bd38b9491c79062a838
r/;r		!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665
"T"-	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'
{UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665
:
wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
:K::	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903E	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#1901690{
Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#19016900cAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062
Aa:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903Z	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[	-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903
`:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#19380817Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963kYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908963	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903
lA"l1	YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081
X: 	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081d	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#1938081
RqR:%	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809O$	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809#Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024"7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201k!YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201
AJj)	KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:(	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809r'	[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:&	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809
Ak-1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#1999735,'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395:+	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:*	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809
6x"2	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#199973591	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#199973590	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359/	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735.	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#1999735
ZBPqZ6'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z5	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m4	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#199973593	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
aBa9;	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735":	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#199973599	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#199973598	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#199973597	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735
/>'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z=	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m<	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
G"A	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735_@AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P?	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
ZBPqZE'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826ZD	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mC	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359B	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
qGqQH	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_GAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366PF	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/qmL	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359K	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
JAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=I	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
!
PO	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809N'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826ZM	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=R	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529QQ	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_PAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aaTAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
SAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
/W'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826ZV	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mU	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
qGqQZ	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_YAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366PX	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
\Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=[	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,^[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383]Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
00_aAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P`	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809_'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
Y*hY
dAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=c	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Qb	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,f[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383eAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
	7_iAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366MhAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rggAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
Y*hY
lAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=k	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Qj	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,n[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383mAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lfq	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MpAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rogAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{ k!m"p#r$u%w)z*~+,.	/0
12345 6%7)8-92:6;;<>=A>E?H@LAOBRCTDWEZF\G^HaIdJfKiLlMnNqPsQuRwSzT{U|V~WXYZ\]	^_`abcdefg!k$l(m,n.o2p6q8r=s?tAuFvIwKxOySzV{Z|^}b~ejmpuy}	
Qs	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529nr_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
/>/
uAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=t	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,w[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383vAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lfz	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MyAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rxgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n{_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
dd|1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
p,~[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#22211061Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
t?FtMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695tkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106

er+V:eD[
dfbc0cbaf5fb588c23fcfdacafa9024ed6efd13bfbb1cf69316269cbaee79463DZ
dfa6a2ee9076eba358c12de54d5d936a15a282109538f6772bdb75582afd0584DY
1112275758e024da6aed300ab9d35464cd221ed62c67a573bd71242d60a699bfDX
109d66ff27fd10890453e0e8e39139cafcd73f6341aac559e6f00b019b08a12fDW
1b30b4a38b3fef0e81dd1879d3e9b159f739eadedc3e869eb5947a4bd3b25968DV
fae889b06ab0ce312053475d9327bbc3ab774b5205f23a802574f40fb6dd1621DU
05a1a1334799c302fd4621a4dab067e901b9fbea4d7d269ebc6e9bea8d855923DT
0f67dd341c128a15768806e3944c813d90260a364561887b61378a18ff049547DS
0a551f7e2a238413dc99c1846c2fa6ce5424327eb7cae6cffdcc8530fe613c92DR
7a192ba7047354c7646edd4e2c5e44dc140a332186434319479f733ea0d3a469DQ
f1014b0e635f3231b9775aea6acf589330dd8192d714a231b5392dff24ffc861DP
fa816cfd764e59f3d6af36d6fe658eaf2ad7d0af0472a9bef2ab112995965b1fDO
5d35f8e8e692daf8ad4f89ccba227841148704f4f1a52d100f8d5555f6e2c562
f	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191
n	_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106
1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)qAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319t
kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
993Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
\d\	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#22211061Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)qAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
993Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69d	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965x	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914E
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
993Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69^?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965x	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914E
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KT!
Thomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direchO 	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926jeam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82$gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926D#	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267"	eAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstri
&2(	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o'	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L&	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665%	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f -,	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'+{UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665*	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665)	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665
:.wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{-yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
&22	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o1	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L0	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_EA- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665/	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.1.ea_E@- Update to aarch64-shenandoah-jdk8u272-b05-shenandoah-merge-2020-08-28.
- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464
- Resolves: rhbz#1876665
f -6	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'5{UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#18766654	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#18766653	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665
:8wAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{7yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
r/;r=	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665<	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665;	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665o:	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665L9	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#1876665
"T"-?	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'>{UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665
:AwAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{@yAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
WKzWF	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b08-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b08 (EA).
- Resolves: rhbz#1876665E	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b07-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b07.
- Resolves: rhbz#1876665oD	UAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u272-b06.
- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)
- Resolves: rhbz#1876665LC	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b05-0.2.ea_E@- Enable JFR on x86, now we have JDK-8252096: Shenandoah: adjust SerialPageShiftCount for x86_32 and JFR
- Resolves: rhbz#18766650BcAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062
f-I	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Improve quoting of vendor name
- Resolves: rhbz#1876665'H{UJiri Vanek <jvanek@redhat.com> - 1:1.8.0.272.b09-0.1.ea_9- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Resolves: rhbz#1876665G	!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b09-0.0.ea_@- Update to aarch64-shenandoah-jdk8u272-b09 (EA).
- Resolves: rhbz#1876665
:KwAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-1_@- Add backport of JDK-8215727: "Restore JFR thread sampler loop to old / previous behaviour"
- Resolves: rhbz#1876665{JyAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.272.b10-0_- Update to aarch64-shenandoah-jdk8u272-b10.
- Switch to GA mode for final release.
- Update release notes for 8u272 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302
- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
:K::O	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903EN	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#1901690M{
Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#19016900LcAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.275.b01-0_:- Update to aarch64-shenandoah-jdk8u275-b01 (GA)
- Update release notes for 8u275.
- Resolves: rhbz#1895062
Aa:S	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903ZR	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[Q	-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903:P	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903
``V7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963kUYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908963T	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903
0x0:Z	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b03-0.0.ea_`@- Update to aarch64-shenandoah-jdk8u282-b03 (EA)
- Update release notes for 8u282-b03.
- Resolves: rhbz#1903903:Y	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b02-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b02 (EA)
- Update release notes for 8u282-b02.
- Resolves: rhbz#1903903EX	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Extend RH1750419 alt-java fix to include external debuginfo, following JDK-8252395 in 8u282-b01
- Resolves: rhbz#1901690W{
Jiri Vanek <jvanek@redhat.com> - 1:1.8.0.282.b01-0.1.ea_j- Added patch600: rh1750419-redhat_alt_java.patch
- Replaced alt-java placeholder with real patched alt-java
- Removed patch529: rh1566890-CVE_2018_3639-speculative_store_bypass.patch
- Removed patch531: rh1566890-CVE_2018_3639-speculative_store_bypass_toggle.patch
- Both surpassed by new patch
- Resolves: rhbz#1901690
q Aq^	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u282-b07 (EA)
- Update release notes for 8u282-b07.
- Fix placement issue in release notes, caught by comparing with vanilla version.
- Resolves: rhbz#1903903:]	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b06-0.0.ea_- Update to aarch64-shenandoah-jdk8u282-b06 (EA)
- Update release notes for 8u282-b06.
- Resolves: rhbz#1903903Z\	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b05-0.0.ea_=- Update to aarch64-shenandoah-jdk8u282-b05 (EA)
- Update release notes for 8u282-b05 and make some minor corrections.
- Resolves: rhbz#1903903[[	-Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b04-0.0.ea_@- Update to aarch64-shenandoah-jdk8u282-b04 (EA)
- Update release notes for 8u282-b04.
- Remove upstreamed patch PR3519
- Resolves: rhbz#1903903
q:b	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081:a	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#1938081`7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-1`&- Cleanup package descriptions and version number placement.
- Resolves: rhbz#1908963k_YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.282.b08-0`- Update to aarch64-shenandoah-jdk8u282-b08 (GA)
- Update release notes for 8u282-b08.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908963
B+Bde	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#19380811d	YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081c	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081
4A4j7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201kiYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201:h	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:g	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081:f	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081
cAcm	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.1.ea`S@- Re-organise S/390 patches for upstream submission, separating 8u upstream from Shenandoah fixes.
- Add new formatting case found in memprofiler.cpp on debug builds to PR3593 patch.
- Resolves: rhbz#1938081:l	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.0.ea`F- Update to aarch64-shenandoah-jdk8u292-b05 (EA)
- Update release notes for 8u292-b05.
- Resolves: rhbz#1938081:k	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b04-0.0.ea`B@- Update to aarch64-shenandoah-jdk8u292-b04 (EA)
- Update release notes for 8u292-b04.
- Resolves: rhbz#1938081
Ja:p	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b07-0.0.ea`\{@- Update to aarch64-shenandoah-jdk8u292-b07 (EA)
- Update release notes for 8u292-b07.
- Resolves: rhbz#1938081do	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b06-0.0.ea`X- Update to aarch64-shenandoah-jdk8u292-b06 (EA)
- Update release notes for 8u292-b06.
- Require tzdata 2020f due to JDK-8259048
- Resolves: rhbz#19380811n	YAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b05-0.2.ea`S@- Update to aarch64-shenandoah-jdk8u292-b05-shenandoah-merge-2021-03-11 (EA)
- Update release notes for 8u292-b05-shenandoah-merge-2021-03-11.
- Extend s390 patch to fix issue caused by JDK-8252660 backport and lack of JDK-8188813 in 8u.
- Revise JDK-8252660 s390 failure to make _soft_max_size a jlong so pointer types are accurate.
- Resolves: rhbz#1938081
gAguAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024t7Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-1`pA- Add CVE numbers.
- Require tzdata 2021a due to JDK-8260356
- Resolves: rhbz#1938201ksYAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-0`n@- Update to aarch64-shenandoah-jdk8u292-b10 (GA)
- Update release notes for 8u292-b10.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1938201:r	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b09-0.0.ea`c- Update to aarch64-shenandoah-jdk8u292-b09 (EA)
- Update release notes for 8u292-b09.
- Resolves: rhbz#1938081:q	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b08-0.0.ea`_@- Update to aarch64-shenandoah-jdk8u292-b08 (EA)
- Update release notes for 8u292-b08.
- Resolves: rhbz#1938081
,mry	[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:x	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809:w	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809Ov	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809
AR:}	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:|	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809j{	KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:z	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809
]:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b02-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b02 (EA)
- Update release notes for 8u302-b02.
- Resolves: rhbz#1967809O	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b01-0.0.ea`@- Update to aarch64-shenandoah-jdk8u302-b01 (EA)
- Update release notes for 8u302-b01.
- Switch to EA mode.
- Resolves: rhbz#1967809Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.292.b10-2`@- Add JDK-8266929 backport for RH1960024.
- Resolves: rhbz#1960024~'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
AJj	KAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b05-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b05 (EA)
- Update release notes for 8u302-b05.
- Remove JDK-8266929/RH1960024 as now upstream.
- Resolves: rhbz#1967809:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b04-0.0.ea`\- Update to aarch64-shenandoah-jdk8u302-b04 (EA)
- Update release notes for 8u302-b04.
- Resolves: rhbz#1967809r	[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.1.ea`@- Update to aarch64-shenandoah-jdk8u302-b03-shenandoah-merge-2021-06-23 (EA)
- Update release notes for 8u302-b03-shenandoah-merge-2021-06-23.
- Resolves: rhbz#1967809:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b03-0.0.ea`h@- Update to aarch64-shenandoah-jdk8u302-b03 (EA)
- Update release notes for 8u302-b03.
- Resolves: rhbz#1967809
Ak	1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#1999735'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-0`t- Update to aarch64-shenandoah-jdk8u302-b08 (EA)
- Update release notes for 8u302-b08.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b07-0.0.ea`- Update to aarch64-shenandoah-jdk8u302-b07 (EA)
- Update release notes for 8u302-b07.
- Resolves: rhbz#1967809:	kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b06-0.0.ea`E- Update to aarch64-shenandoah-jdk8u302-b06 (EA)
- Update release notes for 8u302-b06.
- Resolves: rhbz#1967809

er+V:eDh
8468dd2d01e7228ce1d031241b5387d85911912180e2b91324d509c7631724aeDg
e2c654e3afba7eae27baf8ba94d32ce0d7b64ee9e4d712f07c55fe5511ac0e78Df
906005c50af3c97fba3c5a02b14b7ce32f662a5eafb00675e8750675b8323966De
ecf0213aa5f1df68903633d6e37f83ba74657dcdfef00998680e1d13d4107e9bDd
d8cc4f7ba48ecdc9de7b819650b043bff67e2a0f66f0100cff7b2021dfdb7019Dc
cd7ecade58c83774da56075ecbc93181d0299693efa4a31b09f39a234ea8c0d8Db
42a032cda37e42e63ccb183ecdaa7710140521828aa8549a8f19dd0bc7fbea36Da
88bc32f0b32b7bb8891d9dd012f0481bd2103ca60cadb3ebc387b8645c331524D`
c2c9b259e70aede7a57ebe7fa8a93a475866d4cce68f6b903edb0875c829bc6cD_
fe81316791b5a33fb6e458bc981914e5a5c7d16da0e818f6b455b94fd257fbd8D^
eb68e76343740b950f6fb531ed5af6afc884e16c3ca61bdb35b1d2115d73f0c4D]
eb2e226e824b06855d4cf867531fb5f3409412d883d6e56543603660748ecfbbD\
7f67e4364ed1e323c02f8bdeafb086bb8d6633c2da0a3139a1a54be82a87bdec
6x"	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19997359
	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735
	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#1999735
ZBPqZ'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
dX9	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&A- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b01-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b01 (EA)
- Update release notes for 8u312-b01.
- Switch to EA mode.
- Remove "-clean" suffix as no 8u312 builds are unclean.
- Related: rhbz#19997351Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.302.b08-1a;H- Remove non-Free test and demo files from source tarball.
- Related: rhbz#1999735
YZ	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
+m9	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
YZ#	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m"	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359!	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735" 	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
00_&AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P%	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809$'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
aBa9+	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735"*	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19997359)	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.1.eaaP`- Update to aarch64-shenandoah-jdk8u312-b04 (EA)
- Update release notes for 8u312-b04.
- Related: rhbz#19997359(	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b03-0.1.eaaM- Update to aarch64-shenandoah-jdk8u312-b03 (EA)
- Update release notes for 8u312-b03.
- Related: rhbz#19997359'	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b02-0.1.eaaG&@- Update to aarch64-shenandoah-jdk8u312-b02 (EA)
- Update release notes for 8u312-b02.
- Related: rhbz#1999735
/.'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z-	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m,	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
G"1	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735_0AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P/	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
ZBPqZ5'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z4	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m3	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#199973592	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
qGqQ8	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_7AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P6	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/9<	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735";	;Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b04-0.2.eaaQ@- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999735
:Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=9	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
/?'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Z>	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929m=	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735
qGqQB	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_AAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366P@	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
>/qmF	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359E	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
DAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=C	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
!
PI	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809H'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826ZG	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=L	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529QK	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_JAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aaNAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
ZBPqZR'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826ZQ	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mP	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#19997359O	iAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.1.eaaU- Update to aarch64-shenandoah-jdk8u312-b05 (EA)
- Update release notes for 8u312-b05.
- Related: rhbz#1999735
qGqQU	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_TAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366PS	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
WAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=V	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
~p~mY	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735XAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
!
P\	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809['Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826ZZ	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929
=_	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q^	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_]AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366
aaaAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
`Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422
gO]~ge'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826Zd	+Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.3.eaaf@- Add patch to improve performance of common separators in Scanner.useLocale
- Move alt-java patch to correct section.
- Resolves: rhbz#1862929mc	QAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b05-0.2.eaaex- Update to aarch64-shenandoah-jdk8u312-b05-shenandoah-merge-2021-10-07
- Update release notes for 8u312-b05-shenandoah-merge-2021-10-07.
- Resolves: rhbz#1999735,b[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383
qGqQh	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_gAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366Pf	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
jAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=i	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,l[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
00_oAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366Pn	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809m'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826
Y*hY
rAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=q	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Qp	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,t[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383sAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
 	7 w'Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.312.b07-1aim@- Update to aarch64-shenandoah-jdk8u312-b07 (EA)
- Update release notes for 8u312-b07.
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2011826MvAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rugAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
qGqQz	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529_yAAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366Px	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b04-0.1.eaa- Update to aarch64-shenandoah-jdk8u322-b04 (EA)
- Update release notes for 8u322-b04.
- Require tzdata 2021c as of JDK-8274407.
- Switch to EA mode.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Related: rhbz#2022809
/>/
|Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422={	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,~[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
	7_AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
Y*hY
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf		CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
))_AAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.322.b06-1a@- Update to aarch64-shenandoah-jdk8u322-b06 (EA)
- Update release notes for 8u322-b06.
- Switch to GA mode for final release.
- Require tzdata 2021e as of JDK-8275766.
- Update tarball generation script to use git following shenandoah-jdk8u's move to github
- Resolves: rhbz#2039366n
_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111

er+V:eDu
dda309e14f66aa1f8ced19d835b7e6ff04827b05e42baed38cfbde2ea01b3351Dt
d6029c8033366f8fa025ecb16d28c0d7ebe9ff2aa2c4b0f27fd5af20a22fc2d0Ds
52d1677bb4b0b6cf9d2e5dcd4c9cb2e58dee114d048654302dd20d27a8d31eceDr
f926be88eca8a48d3a20210809bb3b3034814e0660e27737f39f9db9589b332dDq
1a8bb6d0d5d3a9bbd2452e189a4bddbc5fb7dd910ae645de886896daf57d324bDp
9984ba09f2a5bb2165cfe6589c4861a4ae3214b1932e9978e0648e075937b182Do
ab64f5672ee9bcce92e16118c4c13b43b53597bb1ec2a50445c04cb3b9eeef74Dn
a9b3782c3c170d426ed6352d73a207121cb78d86ee04aff09e0065659d0cddb7Dm
ac4d6d11bf69e5b905738e3547274f544c6780aad810056708d4cdb6ef2f2842Dl
b1e27eaa8378961d1d5aa1cfe6e8b864169425ac61e6881ca154a93ccff6d67aDk
8a6cef14e08d6e8b37d66e40c1ac1a7bedf36720f015c5cf16ef968d5bd61eb9Dj
7315923a129e703d18cf9c04318c3fce2223c31b6b9d9f8742322e1c2bfd100dDi
8e64b7d56dda27658b854cd7ae4711c43c6b16b97ee01075b4c86e7bea44f202
Y*hY
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=
	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529Q	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529
p,[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
Q	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#2047529n_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
/>/
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422=	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{#&+.158<?BFILNRUWY\_aehjlortwz|~	!#&'(Á*ā-Ł.Ɓ0ǁ2ȁ4Ɂ7ʁ8ˁ:́=́>΁?ρAЁDсFҁHӁIԁKՁNցPׁR؁UفWځZہ\܁_݁aށd߁fiၛk偛n恛p灛s聛u쁛x큛y{	
p,[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695rgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
dQ	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b01-0.1.eab\@- Update to shenandoah-jdk8u332-b01 (EA)
- Update release notes for shenandoah-8u332-b01.
- Switch to EA mode.
- Related: rhbz#20475291Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
/>/
!Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b09-1b]R- Update to shenandoah-jdk8u332-b09 (GA)
- Update release notes for 8u332-b09.
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-04-19 @ 1pm PT.
- Resolves: rhbz#2073422= 	qAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.332.b06-0.1.eab]R- Update to shenandoah-jdk8u332-b06 (EA)
- Update release notes for shenandoah-8u332-b06.
- Resolves: rhbz#2047529
p,#[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383"Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf&	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M%Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r$gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n'_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
dd(1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
p,*[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#2112383)Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf-	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M,Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r+gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n._Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\0	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106/1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
F?Ft2kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<1	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
p,4[Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.345.b01-1b- Update to shenandoah-jdk8u345-b01 (GA)
- Update release notes for 8u345-b01.
- Resolves: rhbz#21123833Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.342.b07-1b- Update to shenandoah-jdk8u342-b07
- Update release notes for shenandoah-8u342-b07.
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Remove redundant "REPOS" variable from tarball script
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Rebase JDK-8186464 patch so it applies after JDK-8190753
- Resolves: rhbz#2106502
L	7Lf7	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191M6Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695r5gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-1cIO@- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- * This tarball is embargoed until 2022-10-18 @ 1pm PT. *
- Resolves: rhbz#2133695
n8_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\:	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#222110691Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
t?FtM=Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695t<kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u372-b05 (GA)
- Update release notes for shenandoah-8u372-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<;	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
f>	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191
n?_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\A	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106@1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)DqAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tCkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<B	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99F3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%EMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
C.CfH	CAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b07-0.1.eac- Update to shenandoah-jdk8u362-b07 (EA)
- Update release notes for shenandoah-8u362-b07.
- Switch to EA mode for 8u362 pre-release builds.
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Drop tzdata patches for 2022d & 2022e (JDK-8294357 & JDK-8295173) which are now upstream
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150191MGAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.352.b08-2cK@- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Add test to ensure timezones can be translated
- Related: rhbz#2133695
nI_Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.362.b08-1cG- Update to shenandoah-jdk8u352-b08 (GA)
- Update release notes for shenandoah-8u352-b08.
- Fix broken links and missing release notes in older releases.
- Drop RH1163501 patch which is not upstream or in 11, 17 & 19 packages and seems obsolete
  - Patch was broken by inclusion of "JDK-8293554: Enhanced DH Key Exchanges"
  - Patch was added for a specific corner case of a 4096-bit DH key on a Fedora host that no longer exists
  - Fedora now appears to be using RSA and the JDK now supports ECC in preference to large DH keys
- Resolves: rhbz#2160111
\d\K	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106J1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)NqAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tMkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<L	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99P3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%OMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
\d\R	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106Q1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)UqAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319tTkAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<S	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99W3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%VMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69dZ	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xY	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914EX
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
\d\\	}Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b01-0.1.ead - Update to shenandoah-jdk8u382-b01 (EA)
- Update release notes for shenandoah-8u382-b01.
- Switch to EA mode.
- Remove JDK-8271199 patch which is now upstream.
- Related: rhbz#2221106[1Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.372.b07-1d>@- Update to shenandoah-jdk8u372-b07 (GA)
- Update release notes for shenandoah-8u372-b07.
- Require tzdata 2023c due to inclusion of JDK-8305113 in 8u372-b07
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Include JDK-8271199 backport early ahead of 8u382 (RH2175317)
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
- Resolves: rhbz#2159458
)?F)_qAJiri Vanek <jvanek@redhat.com> - 1:1.8.0.392.b08-1e%<- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11319t^kAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b05-1d8- Update to shenandoah-jdk8u382-b05 (GA)
- Update release notes for shenandoah-8u382-b05.
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106<]	oAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.382.b04-0.1.ead@- Update to shenandoah-jdk8u382-b04 (EA)
- Update release notes for shenandoah-8u382-b04.
- Related: rhbz#2221106
99a3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%`MAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69dd	?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-0.1.eae@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xc	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914Eb
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
99f3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%eMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69^i?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xh	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914Eg
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KTk
Thomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direcOj	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926eam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82ngAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926Dm	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267l	eAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstr
99p3Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-2e-%- Revert jcmd move as jcmd will not operate without tools.jar
- Related: RHEL-13577%oMAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-1e%<- Update to shenandoah-jdk8u392-b08 (GA)
- Update release notes for shenandoah-8u392-b08.
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Regenerate PR2462 patch following JDK-8315135
- Add backport of JDK-8312489 heading upstream for 8u402 (see OPENJDK-2095)
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12212
- Resolves: RHEL-13574
- Resolves: RHEL-13575
- Resolves: RHEL-13576
- Resolves: RHEL-11319
- Resolves: RHEL-13577
69^s?Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b06-1e@- Update to shenandoah-jdk8u402-b06 (GA)
- Update release notes for shenandoah-8u402-b06.
- Drop local copy of JDK-8312489 which is now included upstream
- Switch to GA mode.
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-17914
- Resolves: RHEL-20965xr	gAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.402.b01-0.1.eaeL@- Update to shenandoah-jdk8u402-b01 (EA)
- Update release notes for shenandoah-8u402-b01.
- Switch to EA mode.
- Sync NEWS with vanilla branch version.
- Related: RHEL-17914Eq
Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.392.b08-3e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19630
K,KTu
Thomas Fitzsimmons <fitzsim@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary direcOt	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eae!@- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926tory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926eam tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926
82xgAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b08-1f@- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926Dw	Andrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b07-0.1.eaf- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-309267v	eAndrew Hughes <gnu.andrew@redhat.com> - 1:1.8.0.412.b01-0.1.eaer- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstr
ggyw3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff {;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pzQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#~AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?}yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907|7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ggw3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff ;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#	AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#19039077Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907K
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907

er+V:eD
43ba47c5fe93e659e2128f88d812fbff89a0212d3f97b085a69f6ec65e2a1b2aD
9b6758993720f8e305448717bc270151ffeedba84a7961f0c5e110065eb6f188D
17ed16fa6fa0dce15c8b3485e9d01613b70ef05e54ce42b4ead591c57c7f47aaD
d2619ceca8fca7e9ee19cea2143fbd219429e9f9b06409934c366c8d6fb4cefbD~
447af92c743509fb44207fbeccdb5f8b9f35865517ad94009935976e7e5339edD}
07b97f3f2c7b61f7d3f1361ef0cb40ea95320f3213ff8441345dd39ed092edffD|
176be26252edd9349f87c81796fa0c0c19ed3e8dbd43a82b201b7ebab75624edD{
f8d118dd0c38e6be586da71c24bb8639d30d388d9b57e276ec52b9ac2f649eadDz
a2e3eec180d90a42cea830a8b5f0fa6890394a9b51d4349667c8010da5d2d418Dy
88ac66f78b2cf64dc6ea2d02f58193bd752cb598be4fa33a9328f2bf4d42de00Dx
aba0487fc98846f969d23ad65f98b2fddc20c5a9ecbd166216fb523452d2cb47Dw
0768c02eab146e2f88cb0c3f41aee2d4f7b14dbdde274b3955f2155eb21cf944Dv
322851c3e3042c4bb07d4bb68b94af8a35852bcac51ee3546cab4f53bc08392b
ff ;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907p
QAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#19039077Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb{1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff ;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#19039077Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb {1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
+9+	$}Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082##AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527!	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527
`X``{){}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#(AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#'AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#&AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#%AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082
dXE#-AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527+	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527*{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
RJR#2AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#1AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#0AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#/AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082	.}Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082
d{7{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#6AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#5AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#19380824{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{3{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228
d\#;AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#:AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811[91Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#19678118{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
;;#?AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082{>{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]=5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^<7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811
\XX\[C1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#1967811B{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{A{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#@AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082
X]G5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^F7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811#EAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#DAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811
zzKmSJiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{J{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]I5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811{H{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
?W:?WO)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936N{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936M{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$L{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873
XX]S5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811 R{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{Q{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#PAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936
\W{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$V{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873UmSJiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{T{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
]a]]{[{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#ZAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WY)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936X{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936
[_{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936^{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$]{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873 \{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
WW c{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{b{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#aAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936W`)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1$g{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873{f{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qe]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JdwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#kAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Wj)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936i{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936h{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qo]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JnwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 m{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{l{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
DDr{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936q{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936{p{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
WW v{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{u{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#tAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Ws)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1z{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{y{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qx]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JwwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#~AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936W})Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936|{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936{{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 {GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
^JwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 {GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
	{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+
{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V
'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531

er+V:eD
34157ccac81b1fd2400592605aa6918ce36609a1d9a3b2cf1b602234d548488dD
e912503786155640b2280491e5de73ce270fcfcaf9fc882663359bec6597f790D

385d88da6f3dbafec168b9405c82b40252b4f9d9df0ef1b7328108f1b7de4898D
e813e31fc27015fa715af1d13ab9191ba9af31d93085ac2e76e58359305bc66aD
5c04fbcd46e3e025d84e9e8ddf45f002a83926d8117b74d5e0012aa43c934978D

d965d09a6d6db58488fc06f0a1f491c8769c8295f4e6dfaec5bf9e496cc72debD	
efe004dfc7fcd0160427a7f637f2cab140b7a315eee7143e1894e834e4a70487D
c76cdef35908893f12eaa11205c3140dbd9f989ea6e01fd9bc00741c05bdb4c5D
a6859e4664d6b26565182fc6c6f79171ac40e3aabb90299e00efc46e4acf5bc3D
8ef9940c8eab06db4d162a8e62feb96b91bf5674ca74e3d18247cbacdb1fedd1D
e63709673c8670886d3e9e2205785adba63f0186853bcf74298fcce168c18f0dD
839aadc2fbe0a7a4b708e39eb1e3e9359bbbad64641fd674e425f561de5d004aD
0f0fa59eb6e08ac74519d59b709ce746a54f5ac7294b9ef563943eea5bdc327d
[{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 {GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
,^,+{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805
^v^{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422
D%}~D {Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;"{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$!m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
%{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{${}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q#]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D*{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+){]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z({{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#'AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V&'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;,{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$+m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
^#0AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V/'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531.{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{-{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
Q$4m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#21065103{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+2{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z1{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422
;5{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
gBgV9'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#20475318{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{7{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#20393666{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
vXYv$>m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510={Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+<{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z;{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#:AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531bRdRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{ $)-27;?CGKOSW	[
_cg
korvz~	 "%*, 0!4"5#9$>&?'B(C)G*K+M,Q-T.X/[0^1b2e3h4l5n6q7t8w9z:};<=>?	@ABDEFHIJ"K%M(N+P.Q0R3S7U9V<X@YCZF\J]N^T_Y`^acbgcl
;?{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
Z$Bm]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510A{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422@{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
;C{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510

W4GcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731F]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373REAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373D{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
d\dK{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422&J{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>I{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695H9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
W;M{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$Lm]	Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510

W4Qc	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731P]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RO	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373N{5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&T{S	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>S{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695R9	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373

W4Xc
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731W]
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RV
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373U{5
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&[{S
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>Z{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695Y9
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}^}
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q]]
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&\G
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192

W4bcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731a]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R`Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373_{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&e{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>d{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695c9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}h}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qg]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&fGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
*J*>l{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695k9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#21303734jcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731i]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373
*U*&nGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&m{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
q}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}p}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qo]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
--4tc
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731s]
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373_r{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
\&w{S
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>v{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695u9
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}z}
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qy]
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&xG
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
MtM>}{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695_|{E
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182{}
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111
*U*&GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&~{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XT>{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
*U*&	GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q
]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_
{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XTq]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106

er+V:eD
47f52ae65081a918aa822fb28261dafe5b707b012d7f07714f3beff7a4d49f45D
d7d58e3708a957c3e2d7c60c347de4ffa8baf7169446426889d9fd0618af02c9D
637c8c01ec07ac21fcb709f52f870af6526eaa83bd2915683f8a6f983072e500D
da13c76a95a624d2a68550bf3fcf6a40650e79fef0cb040d51e46aa293093fb8D
580eedc42430dabee13298aaafa5f6d0828a7c8ee03e48cc34e248044b273c98D
2f0d2a97bc011f105608fc115346133185d5789361484a950ec00bcc5e36bc70D
1e8d63f3eb80cd678a21631ab2ebcb9b62ce51bba0f293bfe51b327fad1145e2D
102055158159425115e1f789e5fc2320b09a7a6f4b5b764de3614f437bfa3e71D
f878ae8eff1fab58c570c743d050866a386253258cd06a481221516b31ab7bc9D
134406c95bb0e98bfe18a35cc06ff8a3deca7248e9196efcee6eb05a7a0dcd55D
ff8272f92c772a5d757bacb85570f4468e0c2c40956746d49494f1daa5041086D
98d431e1523dbb3f7b2df74717a2e41dc1d70f15e80c7fdb07bb88cc13a58c4dD
47479ca82c3c2c2c7d65a383dba4f54f39f315bfe0571d1d9129c0d4101abdd8
r_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192
!%!{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdGmAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('"{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229!{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106# AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
u_%{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182,${_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdL#mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
!%!({Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#'AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.&WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,+{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdO*mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'){UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
?8=?y.{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v-gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C,{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
ii.0WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_/{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('3{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#22362292{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#1AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
uv7gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C6{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642,5{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdT4mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
9{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106y8{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966
II,<{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdW;mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320':{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\@}=Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy?{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v>gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C={
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
}C{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106&Bs[Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~AsAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
II,F{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd[EmAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'D{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\J}=Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundyI{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966vHgAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031CG{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
n}n
NSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665PM#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665&Ls[Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~KsAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
sOsTAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SSs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}R{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zQyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650PcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665zOyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
/</zYyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
XSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665PW#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665Vw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KUw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
KLt^Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665S]s5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}\{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665z[yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650ZcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665
::Scs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}b{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zayAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665`w?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665K_w!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
}-
gwSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610fw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665Kew!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665dAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665
|&{|}l{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zkyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665&jwWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]iwESeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275shiJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
'(U'
qwSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610pw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665Kow!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665nAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665Sms5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665
{&{&twWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]swESeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sriJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
gguw3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff w;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pvQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#zAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907x7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{~{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I}
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907K|Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ggw3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff ;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#19039077Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff 
;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907p	QAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#
AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#19039077Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb{1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907

er+V:eD)
70b5a86232c1ba2b2535285ea1e7951e1c2ce4779402d9ef8b14a9e2574922c4D(
386d6eeb6ec186c7d3ac868781a062f7659e7f29629bf7919767ced443ced16eD'
6afa89d1f93f0c18b712d80864bb7c05453680e7c2ef4267277d1a05fc5f3ed5D&
91265a7a7ea601e581e1e9d0927369baa2509184619fcbfe483ba909db979caaD%
7b73f05a3cad8a9e27146ed66584c90db157d3c8dd9073156714b06d53ae16b4D$
569c3afb20ee7aa02a316df5870c65b53bb314376059e9e761ab3e81622b3891D#
245bfc9c157989c74777ef47e429b5b2823da6b25f940cc71fd0fae7aa230185D"
5effb3b9f9c3b2e58564ce52ef1e7d855cc8030a6d8903d0d257eb9a2f166a73D!
708f19a2413ea0ae0ab9a7619a05c06675c69004d477b56b71ac6ec988ee1cc4D 
c1a1ba3ae8f745008a0b7e5c0e4663241db1a386d16bd54eef846e125686cebaD
02f897ee795a6592d97ca15c780cbdd6ca2bc2a793d53ef279ad3f01f27d472cD
f72a7e95336d9380f37c46d2de0b736c876a15b4c1e7dbb4c351ca2552bbc411D
6eb48672224acb21d0dbc83835af74ba98ee85d8e9d3991623af2bc0d57d6761
ff ;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#19039077Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb{1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
+9+	 }Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527
`X``{%{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#$AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082##AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#"AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#!AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082
dXE#)AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527'	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527&{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
RJR#.AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#-AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#,AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#+AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082	*}Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082
d{3{} Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#2A Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#1A Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#19380820{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{/{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228
d\#7A Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#6A Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811[51 Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#19678114{5 Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
;;#;A!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082{:{} Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]95 Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^87 Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811
\XX\[?1!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#1967811>{5!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{={}!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#<A!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082
X]C5!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^B7!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811#AA!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#@A!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811
zzGmS"Jiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{F{}"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]E5"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811{D{}!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
?W:?WK)"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936J{;"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936I{7"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$H{O"Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873
XX]O5#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811 N{G"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{M{}"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#LA"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936
\S{7#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$R{O#Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873QmS#Jiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{P{}#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
]a]]{W{}#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#VA#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WU)#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936T{;#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936
[[{;$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936Z{7$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$Y{O$Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873 X{G#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
WW _{G$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{^{}$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#]A$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936W\)$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1$c{O%Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873{b{}$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qa]$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810J`w$Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#gA%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Wf)%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936e{;%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936d{7%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qk]%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810Jjw%Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 i{G%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{h{}%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
DDn{;&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936m{7&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936{l{}%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
WW r{G&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{q{}&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#pA&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Wo)&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1v{A&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{u{}&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qt]&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810Jsw&Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#zA'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Wy)'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936x{;'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936w{7'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[q~]'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810J}w'Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 |{G'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{{{}'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
^Jw(Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 {G(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{A'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
{A(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q](Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D
{(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+	{](Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#A(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
[{{})Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q
])Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810Jw)Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 {G)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{etfugwh{i~jklmn
oprstu v%w)x.y3z7{;|?}C~GKOSW[_cgknrvz~
!&(,015:;>?CGIMPTWZ^adhjmpsvy{~

Áā!Ɓ$ǁ'Ɂ*ʁ,ˁ/́3΁5
,^,+{])Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#A)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V')Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{A)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805
^v^{A*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810{)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422

er+V:eD6
5830fa7abe16fd9ef562c14318f17462eb9ebe4e2473b4b94827dab6efc8cb5bD5
33f79495a144745f0bf779634202c2e16ec9ce1d545d08ada1d51ff124397d75D4
bbfa941de4ca08de5ac2912c49346b26f8b10f79c9dedcc1c73b7593d728b8d9D3
5732a4798be4c87badb456e95d85a69fdcc47d79f536cdf10bf8bfe8ac5353abD2
f97f8b49e1c67b65e3bc3821a5542f91cff1d9241f858a36d041fae368a1f2fcD1
08b94d6efe931c32344ea97bafacefaf26b7ab57c499ee718b7466ba31c94321D0
a5344af6f4e55dc3241835e173e61da3faccff81e74b16a504ca025d31166199D/
82943aa98d57823fabd6521b0364b533551b4f5b299febc13bc41d5342b5583cD.
2d39e047ddef688bbc3b526d384126a7602bf927866cbbd6d9306cf24221253dD-
0781ec76d6ef76f218a16289f31a21e27af4064a2fa1f213a49828a67e50c669D,
d434ab93e69642120974f37b28bf06b2fc55a8b51e2bb5b62b339413bcc1b605D+
6bba16931590ee051b717e6cc7eaf6319e483746bab088b484dada27e5f230d5D*
4660a5a7faa79cea2990c384533fca3da9b3ac6afdf6f55b36b2cad51352c3e0
D%}~D{*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#A*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;{}*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$m]*Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
!{A+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{ {}+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D&{+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+%{]+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z${{+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422##A+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V"'+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;({}+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$'m]+Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
^#,A,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V+',Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531*{A,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{){},Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
Q$0m],Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510/{,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+.{],Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z-{{,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422
;1{},Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
gBgV5'-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#20475314{A-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{3{}-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#20393662{5,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
vXYv$:m]-Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#21065109{-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+8{]-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z7{{-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#6A-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531
;;{}-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
Z$>m].Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510={.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422<{5-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
;?{}.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510

W4Cc.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731B].Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RA.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373@{5.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
d\dG{/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422&F{S.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>E{.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695D9.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
W;I{}/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$Hm]/Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510

W4Mc/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731L]/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RK/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373J{5/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&P{S/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>O{/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695N9/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373

W4Tc0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731S]0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RR0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373Q{50Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&W{S0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>V{0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695U90Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}Z}0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qY]0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&XG0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192

W4^c1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731]]1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R\1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373[{51Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&a{S1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>`{1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695_91Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}d}1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qc]1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&bG1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
*J*>h{2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695g92Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#21303734fc2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731e]2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373
*U*&jG2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&i{S2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
m}2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}l}2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qk]2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
--4pc3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731o]3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373_n{E2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
\&s{S3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>r{3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695q93Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}v}3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qu]3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&tG3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
MtM>y{4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695_x{E3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182w}3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111
*U*&{G4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&z{S4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
~}4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}}4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q|]4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.W4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{E4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XT>{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695{4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
*U*&G5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&{S5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
}5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q]5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.
W5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_	{E5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XTq
]6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
r_{E6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182}6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192
!%!{6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.W6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,{_6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmA6Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'{U6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217

er+V:eDC
6b0ef069c7763a3ba0b61d3804a6919fa06467de6088cbbcda7c568dfc3309b0DB
62730a490f70fb743015316019c09c1992ef54947750f054eaaf08ff9a387163DA
e3e0d812a13816d47ae085d4f88c2d0f4d8affad6568434ab0f720442981017bD@
d81b0c0ebf60fb1b4d6ccb36f93b9d93064cf246ecff7f7c16b2ddbb61c57c91D?
0a5287477758b2371bd5090dfacaf9dd93c3f1cc379245204f8a143593599b48D>
f24dce379d6c501f95ff094a43c786cc4932cecf9af4ed5ad162b4159d5a2007D=
645b31999a5a9633d017660dd3029d098a23145a02bcc776967acb3d0414464cD<
e2febf7854a5223cbd8ac5101e3cb5cc8a2a9ac22a6ed7712ad25b139199fee2D;
107479062ac7d45131a7f63b41712cb8d8bbc15a68e65ae36bc4612536690957D:
c6578be082e094285bfff45773f10ef576902f4e6d7f9f5a58b810e7e4d8ab9aD9
d64ee0696017c879c9cac304b66dad0523eafec9464a87a647d5b5c2a19e2466D8
db87f894acc24775904c7b50e997fa12818c4c6368e17139307fd37433372e1eD7
5e128b028063e43ec93a59c4107b46344a43bc260f99578b7c4a2b788885cc7e
}7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q]7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.W7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{E7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('{U7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
u_!{E8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182, {_7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdłmA7Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
!%!${8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106##A8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106."W8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,'{_8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdȂ&mA8Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'%{U8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
?8=?y*{y8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v)g8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C({
8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
ii.,W9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_+{E9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('/{U9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229.{9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#-A9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
uv3g9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C2{
9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642,1{_9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd͂0mA9Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
5{:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106y4{y9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966
II,8{_:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdЂ7mA:Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'6{U:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\<}=:Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy;{y:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v:g:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C9{
:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
}?{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106&>s[:Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~=s:Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
II,B{_;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdԂAmA;Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'@{U;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\F}=;Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundyE{y;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966vDg;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031CC{
;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
n}n
J<Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665PI#<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665&Hs[;Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~Gs;Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
sOsP<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SOs5<Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}N{<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zMy<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650Lc<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665zKy<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
/</zUy=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
T=Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665PS#=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665Rw?<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KQw!<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
KLtZ=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SYs5=Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}X{=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zWy=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650Vc=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665
::S_s5>Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}^{>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665z]y>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665\w?=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665K[w!=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
}-
cw>Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610bw?>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665Kaw!>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665`>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665
|&{|}h{?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zgy?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665&fwW>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]ewE>Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sdi>Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
'(U'
mw?Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610lw??Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665Kkw!?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665j?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665Sis5?Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665
{&{&pwW?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]owE?Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sni?Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
ggqw3@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff s;@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907prQ@Andrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#wA@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#vA@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?uy@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907t7@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{z{}@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970Iy
@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907Kx@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
gg{w3AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff };AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907p|QAAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#AAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#AAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907~7AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{{}AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff ;BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pQBAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#
ABAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#	ABAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yBAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#19039077BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb{1BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{
{}BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KBAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff ;CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pQCAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#ACAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#ACAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yCAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#19039077CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb{1CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{{}CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KCAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907

er+V:eDP
3e729bea301dda80bd7dad924182af1a8859d3473da42b7cb9ed78adebef8963DO
1b9fbe198a3af7e79bb697022c8043d39441c77daf5446b0e0b8e7f5c18603c8DN
5a64f67b760664231aa056ce36899a472656f882e163cec3ee2c913fe4b34140DM
b1355c30321cdcfe6f3fc6298e8e7995196ed2edc8127aa23cee6fb0def56d65DL
5dc4485c972bd78d1637297056bbcc819f90e800c1681f449d5ab226d2b8772bDK
b620f989048c7f2f276ae3cbc4a5217f51cff7aad191e75030d927f8022e7c5aDJ
8b57170fd0541d89c862ecea52f823ede947a5b16983a9646cf0c6e4970996b4DI
fed7b567e393c86119acb36d69b38b769bcb51e24ddcf415141d81230fdc54a8DH
f87df491c22e76385180845739c13ba05724afcded006f1e0f2114ff956460e9DG
5b9c35a49f05bdae1d6d9ae13688adb2f1aa9eed15604ea80e3126af3ad89c77DF
1a762e2d8882a0c051d0a322eb97ba3c2fbdb843e16699bb702cecd284f238faDE
905c6cb39018d44fe1113513cbf517b142fbc537206ae23c0ce00c299f5e39a4DD
7f18b428cb0449058380cba27d10eac85a6389b6c3393ef6454032f2dda04023
+9+	}DJayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082#ADAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082DAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527	DAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527
`X``{!{}DAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228# ADAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#ADAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#ADAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#ADAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082
dXE#%AEAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082$EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527#	EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527"{5DAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
RJR#*AEAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#)AEAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#(AEAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#'AEAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082	&}EJayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082
d{/{}FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#.AFAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#-AFAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082,{5EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{+{}EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228
d\#3AFAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#2AFAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811[11FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#19678110{5FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
;;#7AGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082{6{}FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]55FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^47FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811
\XX\[;1GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#1967811:{5GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{9{}GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#8AGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082
X]?5GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^>7GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811#=AGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#<AGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811
zzCmSHJiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{B{}HAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]A5HAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811{@{}GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
?W:?WG)HAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936F{;HAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936E{7HAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$D{OHSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873
XX]K5IAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811 J{GHAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{I{}HAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#HAHAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936
\O{7IAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$N{OISeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873MmSIJiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{L{}IAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
]a]]{S{}IAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#RAIAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WQ)IAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936P{;IAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936
[W{;JAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936V{7JAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$U{OJSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873 T{GIAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
WW [{GJAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{Z{}JAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#YAJAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WX)JAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936bR7RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{с<ҁ?ӁBՁFցJׁP؁UفZځ_ہc܁h݁mށp߁qsၡw⁡zち{䁡}偢恢灢聢
遢ꁢ끢쁢!%*/37;?CGKOSW[_cgjnrvz~	


"$(,-167:;?CEIL P!S"V#Z$]%`&d'f(i)l*o+r,u-w.z/|01234	56
1$_{OKSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873{^{}JAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]]JAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810J\wJJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#cAKAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Wb)KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936a{;KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936`{7KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qg]KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JfwKJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 e{GKAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{d{}KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
DDj{;LAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936i{7LAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936{h{}KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
WW n{GLAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{m{}LAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#lALAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Wk)LAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1r{ALAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{q{}LAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qp]LAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JowLJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#vAMAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Wu)MAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936t{;MAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936s{7MAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qz]MAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JywMJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 x{GMAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{w{}MAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
^J~wNJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 }{GNAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332|{AMAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{{}MAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
{ANAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}NAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]NAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D{NAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]NAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{NAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#ANAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'NAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
[{
{}OAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q	]OAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JwOJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 {GOAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
,^,+{]OAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{OAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#
AOAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'OAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{AOAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805
^v^{APAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}PAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]PAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810{OAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422
D%}~D{PAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]PAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{PAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#APAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'PAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;{}PAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$m]PJiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510

er+V:eD]
bd616a68bac2dba0c3050b8d3da7ce5d016fa05d03d2c3ca41e478309141d6d8D\
026420613efcc87726ba91b165fc0b746ce24ff329555220967db5cc979a803aD[
5dfcf8baeded2f96a2597b878a1006d7eb03d4d61927a000e1528dd9008b0671DZ
d47daec1adb6903ec50993bb856136c6ca6c1d28610a211a0082c8b683162941DY
bce793675eea8330ee5714f685ee6bf75de56dd9f106dbbe3149d9fa9d144416DX
acb345f09856db7783a06a30026e252117dbee4274e86ea5b3c2959410f22b01DW
a71605698db58a372ff02ab6d78041cca4507c94f4bdc16507ec30994e53892fDV
fdcabd5524523efc4fa2f438cdb2f40de42b6606b73bbff9e8f65e21ea81f437DU
0e30ee127b67a51aaff1ffe3ae0cb616b808bc21850fe2f23be2b229a8bb8853DT
f81e7c1a0f24f7ca56cedc1938c0e1bba78c74ad082589529118fe1d795d6748DS
5f692d98607238270b572db3bdedd64d8b9eb468b0cc08cead1d6b23aae63718DR
7f5933636add693e7d9a57c9d29615c25c2163009b4d680b43a93c0f252fc3c4DQ
d91a5237171093f889f2e37c55c5cbf4f02728ff2fb050c08f0547c1c7cf5f63
{AQAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}QAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]QAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D"{QAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+!{]QAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z {{QAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#AQAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'QAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;${}QAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$#m]QJiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
^#(ARAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V''RAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531&{ARAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{%{}RAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
Q$,m]RJiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510+{RAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+*{]RAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z){{RAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422
;-{}RAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
gBgV1'SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#20475310{ASAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{/{}SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366.{5RAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
vXYv$6m]SJiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#21065105{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+4{]SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z3{{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#2ASAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531
;7{}SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
Z$:m]TJiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#21065109{TAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#20734228{5SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
;;{}TAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510

W4?cTAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731>]TAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R=TAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373<{5TAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
d\dC{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422&B{STAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>A{TAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695@9TAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
W;E{}UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$Dm]UJiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510

W4IcUAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731H]UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RGUAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373F{5UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&L{SUAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>K{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695J9UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373

W4PcVAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731O]VAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RNVAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373M{5VAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&S{SVAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>R{VAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695Q9VAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}V}VAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qU]VAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&TGVAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192

W4ZcWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731Y]WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RXWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373W{5WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&]{SWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>\{WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695[9WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}`}WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q_]WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&^GWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
*J*>d{XAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695c9XAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#21303734bcXAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731a]XAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373
*U*&fGXAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&e{SXAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
i}XAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}h}XAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qg]XAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
--4lcYAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731k]YAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373_j{EXAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
\&o{SYAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>n{YAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695m9YAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}r}YAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qq]YAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&pGYAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
MtM>u{ZAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695_t{EYAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182s}YAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111
*U*&wGZAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&v{SZAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
z}ZAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}y}ZAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qx]ZAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.|WZAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{{EZAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XT>{[Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695~{ZAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#}AZAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
*U*&G[Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&{S[Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
}[Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}[Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q][Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.W[Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{E[Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XTq	]\Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192{[Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A[Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
r_{E\Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182}\Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}
}\Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192
!%!{\Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A\Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.
W\Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,{_\Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd8mA\Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'{U\Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
}]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q]]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.W]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{E]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('{U]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
u_{E^Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182,{_]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd=mA]Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217

er+V:eDj
0b25bab3a8a0341d22387d3674f6676645e3d3d497d2de92de115a56fa012b1bDi
33ead8c29c4da7be1c35398bea14adbd1069eb04196df8a75ddffab71562e778Dh
0de12d2701881f7f8bd093302babcb112ad65af4943bd2e0d2bcb2884f12012dDg
89818b9dde137228b185c849e8eec7f90bed6867be5b294a8b8121f52776af6aDf
f2a450757e610e9d7a49050e04cab12edad074ddca95fd92a67972bd61fcbabaDe
0f4b94a13ab49a4fb2ac8ff3106cdaa6e83e43757720457189e685e7a55ed6d6Dd
970a62a2a5e145cc2c8fa7e55e770b427abb4943c6d8e85bb81c928a192bb407Dc
22d64046fb95580843be1a65bdeaa8f2a9beca7721f0af5f20f9263a59cc2977Db
c76bb943b6a1a6711f5c6301f55730c1b173e983e6b7b095c9d0135c7b6a52f0Da
7abbb0853851a20592aac6a51b52bbe28466f3f0ee1d83a240a39b4e4f336537D`
2f2f67956f80076c79a81d009a5aee971589176deeda7985a84ca07ae0164a5aD_
3603a5475d52875262a18bc253888633c218b9df5c6fbdfad0972c07da32b981D^
72866ddd3fc9bb8286ebd7b4f6c5d977fc3e7925268a253cfefe4511c6e90150
!%! {^Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A^Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.W^Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,#{_^Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdA"mA^Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'!{U^Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
?8=?y&{y^Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v%g^Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C${
^Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
ii.(W_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_'{E_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('+{U_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229*{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#)A_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
uv/g_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C.{
_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642,-{__Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdF,mA_Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
1{`Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106y0{y_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966
II,4{_`Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdI3mA`Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'2{U`Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\8}=`Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy7{y`Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v6g`Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C5{
`Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
};{aAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106&:s[`Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~9s`Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
II,>{_aAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdM=mAaJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'<{UaAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\B}=aAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundyA{yaAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v@gaAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C?{
aAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
n}n
FbSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665PE#bAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665&Ds[aAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~CsaAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
sOsLbAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SKs5bJiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}J{bAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zIybAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650HcbAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665zGybAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
/</zQycAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
PcSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665PO#cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665Nw?bAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KMw!bAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
KLtVcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SUs5cJiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}T{cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zSycAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650RccAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665
::S[s5dJiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}Z{dAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zYydAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665Xw?cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KWw!cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
}-
_wdSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610^w?dAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665K]w!dAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665\dAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665
|&{|}d{eAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zcyeAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665&bwWdAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]awEdSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275s`idJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
'(U'
iweSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610hw?eAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665Kgw!eAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665feAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665Ses5eJiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665
{&{&lwWeAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]kwEeSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sjieJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
ggmw3fAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff o;fAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pnQfAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#sAfAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#rAfAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?qyfAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907p7fAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{v{}fAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970Iu
fAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KtfAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ggww3gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff y;gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pxQgAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#}AgAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#|AgAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?{ygAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907z7gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{{}gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907K~gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff ;hAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pQhAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#AhAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#AhAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yhAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#19039077hAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb
{1hAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{	{}hAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
hAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KhAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff ;iAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pQiAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#AiAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#AiAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yiAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907
7iAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb{1iAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{{}iAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
iAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KiAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
+9+	}jJayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082#AjAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082jAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527	jAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527
`X``{{}jAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#AjAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#AjAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#AjAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#AjAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082
dXE#!AkAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082 kAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527	kAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527{5jAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736

er+V:eDw
3038e1befe3903f7b2bfb4fb5ed1ee07a0ba36db33ae2aae4ba05e4040d2b65fDv
1619875cba8598818f4bb31d4ba22a7d88804cab9b8ed1e66cb4cf18b1b446cbDu
ecd28bfd8a7f97d111587dec88746bdc8143ed9ea22a73f2c05141e5361dc7c2Dt
0f91ee82a0f353071438675ca34ab961c867b90d20e8e45c2472604fdc1165ecDs
d5fa6533d980b7889d1404f6dda42ce2de80411d4079bd78b7ce3257cb36e5deDr
d24b5e95b20420b1e37b28037c9bd5175c6fbfd17e6a78347fb26b2792a126efDq
237858b698163e9a4615ec1ab98636d66cd7e26deb3512708bd88164019a1994Dp
2e548be4d940969b8feee6cc4ffb8dde5ac295e684713eba0f96b20f287e7b40Do
cd2e66ab8554e43fed6cf3a6fe7067b925de6a4ebe0acd82af46e341ce011229Dn
5ec49c65245b5b4768c2ac475d313f22f92daa8114cbfc555c7189d5844f7b24Dm
f1402f59f4309e9a2ad497a9699c098b61381170de7f600a6a7636db589400d5Dl
155a01df2abb9e5b0463d2bbe0314d3147245d1540cc0e5026de16abc670d0e6Dk
19cc17be5a8b2b11edcbc35b6648252c7d5913d500ab82bda2d44c47f0d3f440
RJR#&AkAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#%AkAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#$AkAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082##AkAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082	"}kJayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{9:;<? @#B&C(D+E/G1H4J8K;L>NBOFPLQQRVS[T_UdViWlXmYoZs[v\w]y^}_`ab
cdefgh!j&l+m/n3o7p;q?rCsGtKuOvSwWx[y_zc{f|j}n~rvz} $()-2367;?AEHLORVY\`behk
d{+{}lAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#*AlAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#)AlAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082({5kAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{'{}kAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228
d\#/AlAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#.AlAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811[-1lAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#1967811,{5lAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
;;#3AmAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082{2{}lAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]15lAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^07lAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811
\XX\[71mAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#19678116{5mAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{5{}mAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#4AmAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082
X];5mAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^:7mAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811#9AmAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#8AmAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811
zz?mSnJiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{>{}nAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]=5nAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811{<{}mAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
?W:?WC)nAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936B{;nAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936A{7nAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$@{OnSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873
XX]G5oAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811 F{GnAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{E{}nAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#DAnAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936
\K{7oAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$J{OoSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873ImSoJiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{H{}oAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
]a]]{O{}oAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#NAoAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WM)oAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936L{;oAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936
[S{;pAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936R{7pAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$Q{OpSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873 P{GoAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
WW W{GpAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{V{}pAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#UApAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WT)pAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1$[{OqSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873{Z{}pAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qY]pAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JXwpJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#_AqAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936W^)qAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936]{;qAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936\{7qAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qc]qAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JbwqJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 a{GqAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{`{}qAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
DDf{;rAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936e{7rAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936{d{}qAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
WW j{GrAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{i{}rAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#hArAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Wg)rAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1n{ArAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{m{}rAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366ql]rAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JkwrJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#rAsAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Wq)sAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936p{;sAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936o{7sAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qv]sAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JuwsJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 t{GsAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{s{}sAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
^JzwtJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 y{GtAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332x{AsAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{w{}sAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
}{AtAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{|{}tAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q{]tAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D{tAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]tAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{tAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#AtAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V~'tAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
[{{}uAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]uAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JwuJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 {GuAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
,^,+{]uAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z
{{uAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#	AuAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'uAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{AuAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805
^v^{AvAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}vAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q
]vAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810{uAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422
D%}~D{vAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]vAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{vAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#AvAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'vAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;{}vAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$m]vJiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
{AwAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}wAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]wAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D{wAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]wAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{wAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#AwAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'wAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W; {}wAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$m]wJiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510

er+V:eD
e87677e240924426b72cfef3f1ea5a1e88a7a4f5e9fd2f778a2cc3fa1a10069aD
76f4f248ab4aaef273c6428865ba506ee4dcc78c5a1d7c81a8d95a729a9ac4a0D
f7f969b6625cce5d7207b8a291d03841700e7b868361f6f98ce61bb3cc624622D
97eec08dd36b082c41af38fa508339931bbf380795208dfcf82213afc0e5486dD
cb236ed8e588d128b8cdc78afdce6379dcd39b817725c547e7f06734476accd8D
dff37a0add22b38eab5365de428508592ec00dc762e1cb45853495efb7c80c04D~
764c4140bd73b1c0bdc434edd88f8c15595f4b1c04c426277e3e1b098ebe7d16D}
64083e41574124b62214c724c95ecf69227a63f84cb8ea3c1b91c9e46909d214D|
95793f42b845d0ea4f32a235ac9b117b776a44e3f656a26633a3012f93a31bfeD{
f95f722b442bc9d91784e68a17b61860bc39197eaa93b49c63ee4572dd5a1007Dz
46649389b1065af3dd7807f1fef23cb1e6f50351ea151d97424e8b8a75c616f3Dy
8bebe621091a0ae4cea699aab647472b02128fdedc6cd35f7a87166bd62ed233Dx
4c39d29f58affbbc0dca6ea29bd2dd9b75658d24d46f216c7de17b46f021b13e
^#$AxAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V#'xAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531"{AxAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{!{}xAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
Q$(m]xJiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510'{xAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+&{]xAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z%{{xAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422
;){}xAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
gBgV-'yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531,{AyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{+{}yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366*{5xAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
vXYv$2m]yJiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#21065101{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+0{]yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z/{{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#.AyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531
;3{}yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
Z$6m]zJiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#21065105{zAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#20734224{5yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
;7{}zAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510

W4;czAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731:]zAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R9zAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#21303738{5zAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
d\d?{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422&>{SzAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>={zAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695<9zAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
W;A{}{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$@m]{Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510

W4Ec{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731D]{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RC{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373B{5{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&H{S{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>G{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695F9{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373

W4Lc|Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731K]|Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RJ|Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373I{5|Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&O{S|Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>N{|Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695M9|Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}R}|Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qQ]|Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&PG|Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192

W4Vc}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731U]}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RT}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373S{5}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&Y{S}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>X{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695W9}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}\}}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q[]}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&ZG}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
*J*>`{~Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695_9~Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#21303734^c~Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731]]~Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373
*U*&bG~Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&a{S~Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
e}~Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}d}~Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qc]~Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
--4hcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731g]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373_f{E~Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
\&k{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>j{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695i9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}n}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qm]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&lGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
MtM>q{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695_p{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182o}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111
*U*&sGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&r{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
v}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}u}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qt]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.xWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_w{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XT>{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695z{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#yAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
*U*&}GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&|{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q~]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XTq]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
r_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192
!%!{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#
AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.	WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd
mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
u_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
!%!{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
?8=?y"{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v!gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C {
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642

er+V:eD
4c86c1c3d77ede8a23e4eef1b4c3e4de9e50b799ed8dc0e6a6091ff032631cf6D
2b98912d64d86fdfe8af76dc95ea23e41332536c8e0ef98223e9a33f2d227f22D
c77e3e9c9f9cc48a40bb188838bad833e1ea361ee0ba3424abed546f3945d701D
e78824bc6d2ccd3f5942b851ce6c3323367ca0cfa615dc8c95158aee19c123feD

d1a6eb397fc04c57428b2ed1f9e3077ed639a5877ef02b2312725fb99c17c807D
30c32ac3292a24f2136302bf5bf2d8ebf572bc2b8c57b4cb3c50ffeb223e144eD
eb01e604d2abe850e31d2092b9db3c5b0df3ee2c53ee80d31ea248c0962ea297D

9b0f357ea1eeba57c0d266260414871735cb04729cc62e43ab7bc3503538cb95D	
bce31a77615b379250e7eba11be12018aecf44bf33cd3d92aba684b157074907D
56ec7e50303f9b981bec76c83f17fd6d6eaafaf4b44ba798d7dd4592b9c6663dD
fc6444986c7f47167fd58aa8888952344750766901c89c5c31b69ed13631e92dD
e6d47a4c88646ebb1f6ff54dd92d1dda1c8abb10bc8530e1cfe498c70ff1db87D
226ad3151c609e6c6ae4f2fcadec7bd71f08fdb6c976380ebc8d8c0eac5afbfd
ii.$WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_#{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT(''{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229&{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#%AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
uv+gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C*{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642,){_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd(mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
-{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106y,{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966
II,0{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd‚/mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'.{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\4}=Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy3{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v2gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C1{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
}7{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106&6s[Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~5sAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
II,:{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdƂ9mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'8{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\>}=Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy={yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v<gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C;{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
n}n
BSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665PA#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665&@s[Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~?sAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
sOsHAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SGs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}F{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zEyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650DcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665zCyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
/</zMyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
LSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665PK#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665Jw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KIw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
KLtRAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SQs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}P{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zOyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650NcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665
::SWs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}V{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zUyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665Tw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KSw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
}-
[wSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610Zw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KYw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665XAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665
|&{|}`{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665z_yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665&^wWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]]wESeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275s\iJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
'(U'
ewSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610dw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665Kcw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665bAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665Sas5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665
{&{&hwWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]gwESeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sfiJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
ggiw3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff k;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pjQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#oAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#nAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?myAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907l7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{r{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970Iq
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KpAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ggsw3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff u;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907ptQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{qsvx{}"$'+-0Á4ā7Ł:ǁ>ȁBɁHʁMˁŔẂ[΁`ρeЁhсiҁkӁoԁrՁsցu؁yف|ځ~ہ܁݁ށ߁ၨ⁨と"䁨'恨+灨/聨3遨7ꁨ;끨?쁨C큨GKOSW[_bfjnrvy~ $%)	.
/23
7;=A
q#yAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#xAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?wyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907v7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{|{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KzAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff ~;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907p}QAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#19039077Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb{1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff ;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?
yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907	7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb{1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907K
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
+9+	}Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527
`X``{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082
dXE#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
RJR#"AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#!AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082# AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082	}Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082
d{'{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#&AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#%AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082${5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{#{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228

er+V:eD
7086a3c094b4e91c8ec76f30de930c4f4c0d0eb7f9617e94c419d74aabb4f793D
e9370bcf27554400437736d6d3c4091baa10166592baf0f0a1912084c024255dD
499aafdde42137b651f07de95acdb9b2b0426c0923756ba0bb98c74731260debD
694a1661be3ee29b44619821670f2826998a9100cefc0efc36d04db24b211e47D
1f2763028ec3d49595e594f3c26e4361b3462c3391db1c8dbebdb12aeb792896D
efa7cbf450462d4d95389173c50afbb6786eb202258fbc8ba90ef57e2459561aD
4521dde116f75afbb70beca46c5f369e56507e92501cb8051a6caf5aebe62defD
87e7e547e429b8f05895e13d2852cf0bb18f91a4aba2a1bddc445c950284fc3aD
54bf6ecd682245bc83076c67fa21c5c7db62c883a50972dc40dbfeda8a121125D
18a12adf2bee6b8b9f5f9ed18be2ae1759d9d9d3aaeac59fd9a62973cfd8e759D
e61584e7d9905cb45027e741b94c7b54f6b883091b652d2e13a682d244a0d9c9D
f3c1504a0f9e8be3e261212092e89009d8b01f3fe0f1804ed10e767846e87d26D
49275f52aa1c71edc688e6802a1f2c8b136594807077f4aa90e4e2686edd8ddb
d\#+AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#*AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811[)1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#1967811({5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
;;#/AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082{.{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]-5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^,7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811
\XX\[31Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#19678112{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{1{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#0AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082
X]75Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^67Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811#5AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#4AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811
zz;mSJiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{:{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]95Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811{8{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
?W:?W?)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936>{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936={7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$<{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873
XX]C5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811 B{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{A{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#@AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936
\G{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$F{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873EmSJiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{D{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
]a]]{K{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#JAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WI)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936H{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936
[O{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936N{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$M{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873 L{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
WW S{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{R{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#QAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WP)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1$W{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873{V{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qU]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JTwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#[AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WZ)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936Y{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936X{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[q_]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810J^wJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 ]{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{\{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
DDb{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936a{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936{`{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
WW f{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{e{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#dAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Wc)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1j{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{i{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qh]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JgwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#nAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Wm)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936l{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936k{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qr]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JqwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 p{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{o{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
^JvwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 u{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332t{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{s{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
y{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{x{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qw]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D~{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+}{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z|{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531Vz'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
[{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 {GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
,^,+{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805
^v^{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{
{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q	]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422
D%}~D{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#
AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
^# AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
Q$$m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510#{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+"{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z!{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422
;%{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
gBgV)'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531({AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{'{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366&{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512

er+V:eD+
f17e881111b5bdf792e8c6c4ebf56c864fe82ead7236e9d1714054bb3577b4c1D*
c538ef407bc0967b16f615b25eb59fae617d84051826819aa6837e85e7ff4db9D)
b153786a744ee0f5ed2df73a98fd3332ceb25e5bd7615afa48574656dfca002fD(
478b6dae53400cf32a4edf127885888456e0d40687b130621abfb48015757969D'
58fb7f4dacffd07cdbe657ec86f4af0d40760828a968dd894a92ea0fc7028255D&
0cb275f3f74903e0b995fb60bd6d2d45b6d75c0f10a329bf957ff43cddf17096D%
28a98571198ec6a28a437669678c624aad4fa1d5a6a2dd1bfb4884dddc584a5cD$
0688bc15522e5a3eee9f6ec2d771f77743a5979f6ac5afa0ec5059daa5926e35D#
bb040f65e782eb45f2e750692dccebe3a40db82890f2982e835b5946fb8a3a13D"
feeaaecf67702b0e5815ef109a94fbdbbce95e0e6228db0f8c286f9f61a845ddD!
9c713d3f8c2da0e96f093a322cd54bca18ff323dd824b4a6cfa730232160f754D 
e450e9d5bc1c7f5f5f4f8b5d7ce575e0a5756a4bab5ed98be38ec59c1ffb0276D
529b379f29069f8d8015829e0ce51b950cdfd5764b3d2de634462f2f45957b29
vXYv$.m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510-{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+,{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z+{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#*AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531
;/{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
Z$2m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#21065101{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#20734220{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
;3{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510

W47cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#213037316]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#21303734{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
d\d;{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422&:{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>9{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#213369589Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
W;={}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$<m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510

W4AcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731@]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373>{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&D{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>C{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695B9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373

W4HcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731G]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RFAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373E{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&K{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>J{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695I9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}N}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qM]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&LGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192

W4RcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731Q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RPAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373O{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&U{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>T{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695S9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}X}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qW]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&VGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
*J*>\{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695[9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#21303734ZcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731Y]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373
*U*&^GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&]{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
a}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}`}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q_]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
--4dcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731c]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373_b{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
\&g{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>f{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695e9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}j}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qi]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&hGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
MtM>m{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695_l{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182k}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111
*U*&oGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&n{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
r}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}q}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qp]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.tWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_s{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XT>w{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695v{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#uAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
*U*&yGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&x{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
|}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qz]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.~WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_}{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XTq]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
r_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192
!%!{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,
{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd*	mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217

}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
u_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd/mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
!%!{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd2mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
?8=?y{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966vgAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
ii. WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('#{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229"{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#!AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
uv'gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C&{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642,%{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd7$mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
){Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106y({yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966

er+V:eD8
d17d23e9f3e2cd89c98f84ba07345a6c51f1dc3d67f5d52d483e6f2ed2d93751D7
f63528cfd40b5a5fb0d1e92cd4b91403bab6d49b9bd38ad0aef9e293a98a4b2aD6
e1b83152038966e7b6a720ab0871b052fb0dc4df9c843243ac9f34f68ff8a58fD5
74c5d742dbaa75738c5c52f77416c65b88472bdd5eafe0c39fe63d1816522476D4
115dde7a103bd42e620ddd732d36ef609984603c7103f803f2d1d8bac1bef6c9D3
28d98e71d3a3f5bef8abd07f0acc8353279545bf2aee26db49d58baded52104eD2
4c5528d38245aa14b33d05948eb02c322e95528485c9970733d2e5a577774d6dD1
1699532891581ac8f26d0ec07605ccb1d294d5a52f3b72ac2d996d064199d55eD0
3391ca1aa9dc6a5e4ed248a618ad059946ec5c65625f2566cbe9773d60646f54D/
08f9a253bf2654c7f281ec675c59f7bd4bd0f06ed499e82831fcd79aef82e50bD.
4a40dbfa3e0e5c2e7457bda18c82a1c0d3f49f91b8d548c568fea520908bec6bD-
e49bddae5537553d4d5a78524aa8b60eccbdcb546e79e3e046c946ef9da09ef0D,
679e963c7906dde82f6ac27f545036d5c38c79be36b3c643018742f7c21953c3
II,,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd;+mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'*{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\0}=Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy/{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v.gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C-{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
}3{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106&2s[Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~1sAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
II,6{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd?5mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'4{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\:}=Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy9{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v8gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C7{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
n}n
>Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665P=#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665&<s[Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~;sAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
sOsDAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SCs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}B{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zAyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650@cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665z?yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
/</zIyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
HSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665PG#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665Fw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KEw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665bR}RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{HKNRUX\^adgjmo r!t"w#y$|%~&'()
+
,-.0134 5#6'8):,<0=3>6@:A>BDCIENFSGWH\IaJdKeLgMkNnOoPqQuRxSzT~UVWXYZ[\]#^'_+a/b3c7d;e?fCgGhKiOjSkWl[m^nbofpjqnrrsutzu~vwxyz{|
KLtNAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SMs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}L{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zKyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650JcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665
::SSs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}R{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zQyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665Pw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KOw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
}-
WwSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610Vw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KUw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665TAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665
|&{|}\{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665z[yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665&ZwWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]YwESeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sXiJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
'(U'
awSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610`w?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665K_w!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665^Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665S]s5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665
{&{&dwWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]cwESeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sbiJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
ggew3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff g;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pfQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#kAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#jAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?iyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907h7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{n{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970Im
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KlAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ggow3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff q;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907ppQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#uAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#tAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?syAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907r7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{x{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970Iw
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KvAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff z;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pyQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#~AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#}AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?|yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb{1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff ;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#19039077Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb{1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I

Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907K	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
+9+	}Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527
	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527
`X``{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082
dXE#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
RJR#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082	}Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082
d{#{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#"AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#!AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082 {5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228
d\#'AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#&AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811[%1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#1967811${5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
;;#+AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082{*{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395])5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^(7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811

er+V:eDE
a1c2e9d4603673b1df8482afca3dab078eea9124690469ef6dee7f9d4e663b29DD
e9036e2b707bcda2cefdab377479ae65cfc1d4f0da25dc54312d9786b65eb947DC
a11deef2840f7fe80ce1b946609ec3aa04069da0557383edb2dd88107312e356DB
8127547ec74cf787276b994c2f00085304d697481622d6712560f5c1fde57dd1DA
62bf471ba14072212be41f68548e536d8a022b8fffa4c7fdf94b4dc26c4d7d3aD@
cb1e709d6fc4d17df3ff827f54f59d30c0e4cb11b30652b60e0f1087d387bdd9D?
b5bacd96f28f126743bbc0807bcb665ff0c52ee4b0256b7bcffb9a10f8d18c68D>
7bfed40726a8044b0f0685487bd9f5131499f3c91242720ec1c55565601abd18D=
c441b3fe43905a4ba494377fd18f7afb8d59b3c95abfb93384cd0577b3568a5cD<
2117399e425ef95fb4a8b8d38c39a38d73b5e0ad8f8212f6e467901f5f05ca9cD;
31f1aea6422bc6b0072f7c26fc3200a90ac929108eee513f7452415171c8a9bdD:
ceb4699a86911fa2a032df43313a18847098f66921adb5fab1298f3791d1b144D9
4c7a4b1402ce62b471994dd364f3e883167ad5ba8ebba01d67f8ceee2f63d6a5
\XX\[/1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#1967811.{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{-{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#,AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082
X]35Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^27Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811#1AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#0AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811
zz7mSJiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{6{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]55Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811{4{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
?W:?W;)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936:{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19999369{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$8{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873
XX]?5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811 >{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{={}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#<AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936
\C{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$B{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873AmSJiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{@{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
]a]]{G{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#FAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WE)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936D{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936
[K{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936J{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$I{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873 H{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
WW O{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{N{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#MAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WL)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1$S{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873{R{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qQ]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JPwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#WAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WV)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936U{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936T{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[q[]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JZwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 Y{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{X{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
DD^{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936]{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936{\{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
WW b{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{a{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#`AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936W_)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1f{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{e{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qd]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JcwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#jAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Wi)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936h{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936g{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qn]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JmwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 l{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{k{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
^JrwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 q{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332p{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{o{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
u{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{t{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qs]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~Dz{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+y{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422zx{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#wAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531Vv'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
[{~{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q}]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810J|wJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 {{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
,^,+{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805
^v^{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422
D%}~D{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z
{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#	AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$
m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
^#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
Q$ m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422
;!{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
gBgV%'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531${AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{#{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366"{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
vXYv$*m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510){Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+({]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z'{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#&AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531
;+{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
Z$.m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510-{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422,{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512

er+V:eDR
6bcf5f3e89c2755d81da6331cde8d0f4c05fcdc2ce0250804be9609d9e125125DQ
483c0e526fee490fe5e387d8f466ba9336f13e99e38a22801656db9f0ef6fdbfDP
89988277f04bdfb0831030270ba38286c5de52d83e5c015250fa99a89d9f5a47DO
8ccfeff30f33569622e94d656bd899c28dec3d943fe48b0140ff2230c98cf112DN
40e235c4553d138143d79a740ff6929dacaa7d0bb99c84caf67b643e58c12a99DM
9c6296e27d68895aa9814be130a3a7bb16cd8fa2ec14d63699d1a6a1223dc662DL
e12fcfca359b3c38140cf59ead8a267ef1c024a4ed16d4250b7d14c94300a665DK
04ec871279754a00e7006a2f023b95ed305dc36a9ff23d65ed20cbf987b07ffdDJ
b9cbd1c4954833f2a8f3d68b1cc92407f3df064e044f0f7f335563bf1983963bDI
f6fbb6525d675cb023750b0e38502f6e9d30cb7ce70f98d75a7bc6a76d175598DH
8e0d749ba5b5f6a9925903f7cb854321aba39a3bc393c295fbbff22c33feb07cDG
7f699df3b1a5a03f46da8dc559615cdabf4c01094c12f89d7bbbbb93f3744af6DF
8244566af4a36c890bd6abe69ab5f9fd27a7847a32c6063c2ec5fb6de40b84fe
;/{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510

W43cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#213037312]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#21303730{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
d\d7{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422&6{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>5{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#213369549Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
W;9{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$8m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510

W4=cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731<]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373:{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&@{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>?{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695>9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373

W4DcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731C]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RBAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373A{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&G{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>F{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695E9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}J}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qI]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&HGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192

W4NcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731M]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RLAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373K{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&Q{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>P{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695O9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}T}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qS]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&RGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
*J*>X{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695W9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#21303734VcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731U]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373
*U*&ZGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&Y{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
]}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}\}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q[]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
--4`cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731_]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373_^{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
\&c{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>b{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695a9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}f}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qe]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&dGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
MtM>i{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695_h{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182g}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111
*U*&kGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&j{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
n}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}m}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192ql]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.pWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_o{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XT>s{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695r{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#qAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
*U*&uGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&t{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
x}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}w}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qv]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.zWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_y{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XTq}]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192|{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
r_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}~}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192
!%!{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
	}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_
{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229
{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
u_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
!%!{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
?8=?y{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966vgAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{~ !%*+./379=@DGJNQTXZ]`cfiknpsuxz}	#%(,/26:@EJOSX]Á`āaŁcƁgǁjȁkɁmʁqˁt́v́z΁~ρЁсҁӁԁՁցׁ#؁'ف+ځ/ہ3݁7ށ;߁?CၮGKのO䁮S偮W恮Z灮^聮b遮f
ii.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
uv#gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C"{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642,!{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
%{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106y${yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966
II,({_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd'mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'&{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\,}=Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy+{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v*gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C){
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
}/{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106&.s[Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~-sAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914

er+V:eD_
b346f29da69c21241a449decf0f47b1117502c6f136b70a23a24f1438e919766D^
2596d8e58b7977e350ac45b39a8c22507bf5f23a48e5c5af3025b81016622b58D]
a7cb9faf1648281d26c03a5952b9c015a6e302f5018328fa99f1cd9aafbf89c4D\
935642d829064a30780cd84c8e1ca654486d06cc675f9a06e246d6b366d333c5D[
58b23e3f8226650315902eba6ab9e2d2a81f816aa85d12cebf74af56a8504c16DZ
7efe56d9bcad9ff6dc145a50baf931d2125888da4d984a84fd14a509862f3751DY
4851da54ebe84600b0c7af372a59c38094992018f2ffe45bec040b2dd5d380bdDX
db00d954c05dbf5ebc5e47f7671980d64911b459229bc83c8dcd6c60c4ce0b90DW
d23dd2eb44577c74053a9b0d2df44d8fb4618ffcdc560bc60003b1393107baf1DV
b2017332dfd84aebbbfe8b857c333da3eb192f27956aa48ab410bc0ea011ca72DU
d297c29388bc4f582e226fb85070d6108bb21fb17acb88d7d2de900bfcc84423DT
c6835fc2dc5e5741781c97f0dd76cd871e82a83dded531a6ca44d9a58abd9a2aDS
b1fa6d1fdf39dbf8d3397fcaa156e0402d827e1c451d262b62c3899c837fc47a
II,2{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd1mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'0{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\6}=Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy5{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v4gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C3{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
n}n
:Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665P9#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665&8s[Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~7sAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
sOs@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665S?s5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}>{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665z=yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650<cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665z;yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
/</zEyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
DSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665PC#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665Bw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KAw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
KLtJAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SIs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}H{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zGyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650FcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665
::SOs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}N{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zMyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665Lw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KKw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
}-
SwSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610Rw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KQw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665PAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665
|&{|}X{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zWyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665&VwWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]UwESeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sTiJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
'(U'
]wSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610\w?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665K[w!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665ZAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SYs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665
{&{&`wWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]_wESeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275s^iJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
ggaw3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff c;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pbQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#gAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#fAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?eyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907d7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{j{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970Ii
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KhAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ggkw3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff m;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907plQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#qAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#pAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?oyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907n7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{t{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970Is
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KrAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff v;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907puQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#zAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#yAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?xyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907w7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb~{1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{}{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I|
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907K{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff ;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#19039077Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb{1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
+9+	}Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527		Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527
`X``{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#
AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082
dXE#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
RJR#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082	}Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082
d{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228
d\##AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#"AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811[!1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#1967811 {5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
;;#'AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082{&{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]%5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^$7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811
\XX\[+1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#1967811*{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{){}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#(AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082
X]/5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^.7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811#-AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#,AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811
zz3mSJiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{2{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]15Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811{0{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395

er+V:eDl
3bf5af40702f37c01b474763465e7acba66d1f9cca53e59538aa92a72f018a35Dk
208f92bb62fd7e69ec6decb3b63b18a2c7e51d8c1ea83099de63b56163c9d1d2Dj
25f4706211e06a217d7143f0aead6ea49f2a47344d314396d09e691a83a51848Di
7d5c7ed2663b8b4d93ccdce3e87fa7b84c42697397d9594170591871b706c60dDh
5ef7809b46025089f784a5c5eef97c5cb1c0ae4576bd7a05f04c657f2231d054Dg
14d75975f6b77789e102a09b3e0c65a16a5cd38e795fdb34c4f40cf970a67b93Df
f1896e8ffe63eff76d82b6ef313c62631fce45258dee3c4ac0e2ffe4b8e841e6De
b82ab048b9697892096528f61737d1713449b0dfdae049f4533ac7d1e469ad0eDd
83d5e8fcf034f22af47eccbbd1c693274a94cfc7afdec007e5cebcb5d3ed2a73Dc
25ac1048044afca67ce7c131d644b1fbf4661666b58a9bf482f289e5b1905c0fDb
12a2e4e010484b9e7bd30fc89af801f0e1e212a2faaaa5017acde6e83cd52964Da
b2ab719c45f136d393fa35fa34b5f7ce41406fba2c86e188fc3d3823aabe7688D`
1cbeca0135b7f2bc07c9bcd75fc0fe3f09797e00adfb9350ced9cd89eeb77a8e
?W:?W7)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#19999366{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19999365{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$4{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873
XX];5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811 :{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{9{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#8AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936
\?{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$>{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873=mSJiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{<{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
]a]]{C{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#BAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WA)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936@{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936
[G{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936F{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$E{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873 D{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
WW K{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{J{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#IAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WH)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1$O{OSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873{N{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qM]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JLwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#SAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WR)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936Q{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936P{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qW]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JVwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 U{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{T{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
DDZ{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936Y{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936{X{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
WW ^{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{]{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#\AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936W[)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1b{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{a{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q`]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810J_wJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#fAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936We)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936d{;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936c{7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qj]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JiwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 h{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{g{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
^JnwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 m{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332l{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{k{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
q{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{p{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qo]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~Dv{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+u{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422zt{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#sAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531Vr'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
[{z{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qy]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JxwJiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 w{GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
,^,+{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z~{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#}AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V|'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805
^v^{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422
D%}~D{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;
{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$	m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510

{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
^#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
Q$m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422
;{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
gBgV!'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531 {AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
vXYv$&m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510%{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+${]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z#{{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#"AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531
;'{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
Z$*m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510){Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422({5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
;+{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510

W4/cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731.]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373,{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
d\d3{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422&2{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>1{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#213369509Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373

er+V:eDy
447bf3552c5156b143306396c3569328e80baec97cb1a11315280cd2f3b38e0eDx
dc71096c57fc06718137b2f317d123ac81f3c58557e1d9e42b1d0cceaeb95d38Dw
f8d95a99893e9265f3f6125f684c56c23afa3834653a04d0e9dbe9360a6aaf5dDv
9a2538ebee1a09c61de1b04f3ce4e0727b75e499fc1cbe6df0a72d5507871c0eDu
639be57d983a29004b74a7f3b753de3e62c2aca8e576d15d3d5b4ca2b847507aDt
48b28be8658e81953a40daf5ae041fd07fe585facbf0a5c985d98cee88b3f0aaDs
0dfc6e8ea7cfb111b83da1e6ce7bfc3f5f3c353f61b25a21812ba01aed81cbedDr
981af71f35ff127f9a818e70105e8d4597de1eae244d22caa97ea246a29deee1Dq
0a8fa0a8748dd4667a74653e840521e8d0602e1f9210bb2b27d75c59318081c0Dp
dc7ff660e8cb322dcf0a071b2f556dfa57cc7a3c0a543524ae2c9b6a807d8262Do
248b6271c4100aa6ae97c9a74a7d3b0bf217ed7e074e51ff84d4eb50183ea9a5Dn
503b6775fa6993e20617e140090892909b171ba5cb9cf102f14e12e8e3722fbfDm
993ebb29f0261ce55c92629ffd652f5fd4b867dbb41765fad94a00716ec5e8b1
W;5{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$4m]Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510

W49cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#213037318]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#21303736{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&<{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>;{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695:9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373

W4@cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731?]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373={5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&C{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>B{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695A9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}F}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qE]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&DGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192

W4JcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731I]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RHAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373G{5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&M{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>L{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695K9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}P}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qO]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&NGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
*J*>T{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695S9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#21303734RcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731Q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373
*U*&VGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&U{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
Y}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}X}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qW]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
--4\cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731[]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373_Z{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
\&_{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>^{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695]9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}b}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qa]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&`GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
MtM>e{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695_d{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182c}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111
*U*&gGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&f{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
j}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}i}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qh]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.lWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_k{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XT>o{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695n{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#mAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
*U*&qGAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&p{SAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
t}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}s}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qr]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192bRVRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{끮n쁮q큮vz

!&'*+/359<@CFJM	P
TVY
\_begjloqtvy| 
!
#$&'()+!,$.(/+0.22365<6A7F8K9O:T;Y<\=]>_?c@fAgBiCmDpErFvGzH|IJKL
MNOPQ#R'S+T/U3
ii.vWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_u{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XTqy]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192x{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#wAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
r_|{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}z}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192
!%!{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#~AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.}WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q]Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('
{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229	{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
u_
{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd"mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
!%!{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd%mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
?8=?y{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966vgAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
ii.WAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
uvgAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642,{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd*mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
!{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106y {yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966
II,${_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd-#mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'"{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\(}=Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy'{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v&gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C%{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
}+{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106&*s[Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~)sAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
II,.{_Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd1-mAJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320',{UAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\2}=Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy1{yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v0gAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C/{
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
n}n
6Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665P5#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665&4s[Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~3sAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914

er+V:eD
6e91279c2c56161f7ffdfd5a8f8f361d282238b249859e57ac7e8d4b04a799e7D
c55fbad2b511346ebf2a848c75861a87c98b38738226ac74429144324281ef52D
f544bc64d6a690d2e5853b042cb5a8c7eb50879dacd1acf3c3eca69966d25370D
0cb228d7dc8544ea720f5503724f929baf79d69d2a7d1eb9dd47cf361620788eD
be2825be40e44e47e533b1d6e13b3145e41e073086a22147b77532548436e30dD
03861872c0b045970aa5d709fc96b48dc78114b5fe454d59dff316eb4753ec08D
fed1a25dff437173e5198969384d287e1c91872362d72445cda5bf8bc78201f5D
0bec8227df4692ec640eaf96154a87faa5a1ab3d9c37856f4f8e0c0a98c88525D~
8c2a340bb8e3487639e7851ddf9b80b263ca137dee7948eceddfd372f4b80882D}
6f89875815ef474fc2dd49d33fb56f30d070a424491a2ab970b04c4b3a36133eD|
8b27ff2d6ae464c9929368b71564984ac614007abaed4abfb490c301cdd341deD{
c43cc5c86cdd41a4e686f3173df2eca34068dc56d75a5a468786fc13989bd5fdDz
d5660d632b89221fe127f4475df5c34071486cde5540e458836be4a6b5ab6bcd
sOs<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665S;s5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}:{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665z9yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#187666508cAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665z7yAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
/</zAyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
@Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665P?#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665>w?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665K=w!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
KLtFAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SEs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}D{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zCyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650BcAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665
::SKs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}J{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zIyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665Hw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KGw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
}-
OwSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610Nw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KMw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665LAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665
|&{|}T{Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zSyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665&RwWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]QwESeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sPiJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
'(U'
YwSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610Xw?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KWw!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665VAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SUs5Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665
{&{&\wWAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530][wESeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sZiJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
gg]w3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff _;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907p^QAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#cAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#bAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?ayAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907`7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{f{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970Ie
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KdAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
gggw3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff i;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907phQAndrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#mAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#lAAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?kyAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907j7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{p{}Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970Io
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907KnAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff r;	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pqQ	Andrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#vA	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#uA	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?ty	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907s7	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bbz{1	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{y{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970Ix
	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907Kw	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff |;	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907p{Q	Andrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?~y	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907}7	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb{1	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I
	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907K	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
+9+	}	Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527		Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527
`X``{
{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#
A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#	A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082
dXE#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527		Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527{5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
RJR#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082	}	Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082
d{{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082{5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228
d\#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811[1	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#1967811{5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
;;##A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082{"{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]!5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^ 7	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811
\XX\['1	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#1967811&{5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{%{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#$A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082
X]+5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^*7	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811#)A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#(A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811
zz/mS	Jiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{.{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]-5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811{,{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
?W:?W3)	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#19999362{;	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#19999361{7	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$0{O	Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873
XX]75	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811 6{G	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{5{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#4A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936

er+V:eD
4b6626a337fe2141755d1e57f9afb5d1914f4b0d752fac9cb28cea90640d95d3D
e76b18f34fbbf2a1e7810ed95efd446420bc4ee561f16434445b97b5a0d466c4D
2b55d4f35dce819b798ee136c0dfb0c453985cfd824a8e839552fa2112ae4123D
649c2ee77e6ebe7b0ada06b4afab6acc21bb572fecb9b419d681640d40847bf0D
6cd18c7d7a47f7f1e42e63865172f463162be9c7697c5e7b1953c41099a4d25dD
39b2ee3cdead3a8fa94b2f7fb082014e56dc28992ac2740a46795004ac7dd6c0D

7541eb5333c72fe17aa8e0d7dc2f7f91d8769a57129608043af2b098b5741661D
20e9c59ba021cc9600dbade71b83e1e1b014eae44d6ba273d5fa6491d9508f08D
e3d2e4fe4672614c07f199cf8ea78ca12ec2e4c5bfee735cbffb6dca84ba91cdD

e2d9e1fc46982332f4c50e35b6e51f62edc6bd78156642b63e2553d404909efaD	
47005db64df1a2026edd49418e5714bd0cc4b55a22af61ad08162f38d849be23D
a2a0890a1bee535a6e50b46532778911b437fe971d72e228048964d8dd0f7550D
8b331529abc56930e532f91b8634eaa719301817f62a7a7fbbc720594baf85da
\;{7	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$:{O	Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#16988739mS	Jiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{8{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
]a]]{?{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#>A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936W=)	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936<{;	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936
[C{;	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936B{7	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$A{O	Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873 @{G	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
WW G{G	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{F{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#EA	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WD)	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1$K{O		Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873{J{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qI]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JHw	Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#OA		Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WN)		Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936M{;		Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936L{7		Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qS]		Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JRw		Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 Q{G		Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{P{}		Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
DDV{;	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936U{7	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936{T{}		Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
WW Z{G	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{Y{}	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#XA	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WW)	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1^{A	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{]{}	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q\]	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810J[w	
Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#bA	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936Wa)	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936`{;	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936_{7	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qf]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810Jew	Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 d{G	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{c{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
^Jjw	Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 i{G	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332h{A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{g{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
m{A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{l{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qk]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~Dr{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+q{]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422zp{{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#oA	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531Vn'	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
[{v{}	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qu]	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810Jtw	
Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 s{G	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
,^,+{{]	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422zz{{	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#yA	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531Vx'	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531w{A	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805
^v^{A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{~{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q}]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810|{	
Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422
D%}~D{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$m]	Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
	{A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+
{]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V
'	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$m]	Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
^#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
Q$m]	Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422
;{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
gBgV'	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366{5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
vXYv$"m]	Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510!{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+ {]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531
;#{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
Z$&m]	Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510%{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422${5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
;'{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510

W4+c	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731*]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R)	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373({5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
d\d/{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422&.{S	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>-{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695,9	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
W;1{}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$0m]	Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510

W45c	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#213037314]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R3	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#21303732{5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&8{S	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>7{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#213369569	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373

er+V:eD 
f251e57808a6960518cf05f98f4bed5c0b006b5a01550a68ebb9141c79f0a2ddD
fb53f898a944ec236a811663325ceef801af9d4d3e2c11522ee1bd7a77d9da79D
35254d0cedc9b7756462a8c23a1b9bbf476fefd2ec13b879640bcc09a53504b6D
5a103d4f3b121195638cf61cb91fbc034b9c2a6deee845296612dfb590ef0859D
dab70d9c3e9d60e9a4331d2ccb0d2d3dacfe1d41e355572961045f2ce2c22a34D
e5bf29d89efc9dcdf73e8e8b84b8aa41793d043e3bf944a0c3659d666a13bb4bD
2f740a705cf289cc730913827ebc04cd2b4e26e229696914ddce3e48bfee0552D
2095e4e98eb5962eb97eb3c3165dd036bf0cc42fbb1cfd2c138811047868000fD
f1844144d5a3c42025f3ef1788373858de7187d6dd96e9bcddac4b3fd027e5c9D
8477e56cf835d806a8f5345ebff218dfbceb351c7bca81b9aa806a2fa8930f02D
ce32d3269966c385c52153f1c95ee8578b768a8b69a1d2937f50ab40dc45e380D
a051479c689a04906459e0f87104834ea707b2ffeb1317695704b03edb4c8b2bD
47a66548a049d52ad8e7adcde0de98e6768596cb771d5b8ee590193dda421dd4

W4<c	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731;]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R:	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#21303739{5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&?{S	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>>{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695=9	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}B}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qA]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&@G	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192

W4Fc	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731E]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373RD	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373C{5	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&I{S	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>H{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695G9	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}L}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qK]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&JG	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
*J*>P{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695O9	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#21303734Nc	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731M]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{X;Y?ZC[G\K]O^S_V`Za^bbcfdjemfrgvh{ijkl	mnopqrs"t#u&v'w+x/y1z5{8}<~?BFILPRUX[^acfhkmprux{~	 $'*.28=BGKPUXY[_bceilnrvx|
*U*&RG	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&Q{S	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
U}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}T}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qS]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
--4Xc	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731W]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373_V{E	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
\&[{S	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>Z{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695Y9	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}^}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q]]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&\G	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
MtM>a{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695_`{E	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182_}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111
*U*&cG	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&b{S	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
f}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}e}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qd]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.hW	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_g{E	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XT>k{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695j{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#iA	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
*U*&mG	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&l{S	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
p}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}o}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qn]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.rW	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_q{E	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XTqu]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192t{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#sA	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
r_x{E	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182w}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}v}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192
!%!{{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#zA	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.yW	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,~{_	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd}mA	Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'|{U	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}}	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q]	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.W	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{E	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('{U	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
u_	{E	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182,{_	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmA	Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
!%!{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.
W	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,{_	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmA	Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'
{U	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
?8=?y{y	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966vg	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C{
	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
ii.W	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{E	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('{U	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
uvg	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C{
	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642,{_	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmA	Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106y{y	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966
II, {_	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmA	Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'{U	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\$}=	Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy#{y	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v"g	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C!{
	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
}'{	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106&&s[	Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~%s	Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
II,*{_	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd)mA	Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'({U	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\.}=	Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy-{y	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v,g	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C+{
	Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
n}n
2	 Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665P1#	 Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665&0s[	Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~/s	Anton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
sOs8	 Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665S7s5	 Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}6{	 Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665z5y	 Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#187666504c	 Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665z3y	 Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
/</z=y	!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
<	!Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665P;#	!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665:w?	 Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665K9w!	 Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665

er+V:eD-
7a01c8e4b4c1eaaf03f29bc31b1fe91b81c17591f2d6a358c7e57ae3b8103eb6D,
c0938d8860cf5e93761458738a21c3f5f505e71d1669169693c88f8471d51381D+
8319e904c4b86f6892579492778456a31dcdbb29d4f7b62060dba26486be2a85D*
8f21403b3615c8a3c67833bcb49d11b4c3b80d768a6bdba42abe5d2b299d9cb3D)
b22aa8999bea98b78e5fb8b2195a94bb82daa9f6c9469ec768b019d741e439dbD(
9592f2b746e7ef4c2e4fd13ac3fad913504fb720911df981e24b63bf2011a6e6D'
01b83fa31f2e2ed972aa491423479df2e3e026e54668e3933d3b8b1803fe208bD&
50a577d62eed91a0ed5c686f85830b3c9252dff331c94841f673d8f19924250dD%
2cee495ddd05e0808ca1e516d0b1ad02fcdf3e46ede1dadb81a285b96ab3648cD$
393806557640081ee6c9dd7dc6ee00e307d9ae676a1a267d20fb4793dda538d7D#
ba6f42672b28ba6a322e4daf6a3e3fc791a39cdd7e438b6d6954713e77022fa6D"
b9b371aa85a094ef9bf89ccec7f948b0f98488eac855ba41f5653f61941610e4D!
5c5cbbb79d474d8a08d41a7a9eab16454a6204f748c42ff97d2ca8776ea1fbc8
KLtB	!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SAs5	!Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}@{	!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665z?y	!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650>c	!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665
::SGs5	"Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}F{	"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zEy	"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665Dw?	!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KCw!	!Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
}-
Kw	"Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610Jw?	"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KIw!	"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665H	"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665
|&{|}P{	#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zOy	#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665&NwW	"Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]MwE	"Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sLi	"Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
'(U'
Uw	#Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610Tw?	#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KSw!	#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665R	#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SQs5	#Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665
{&{&XwW	#Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]WwE	#Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sVi	#Jiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
ggYw3	$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff [;	$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pZQ	$Andrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#_A	$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#^A	$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?]y	$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907\7	$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{b{}	$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970Ia
	$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907K`	$Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ggcw3	%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-5_@- Introduced ssbd_arches to denote architectures with SSBD mitigation (currently only x86_64)
- Introduced nm-based check to verify alt-java on ssbd_arches is patched, and no other alt-java or java binaries are patched
- RH1750419 patch amended to emit a warning on architectures where alt-java is the same as java
- Resolves: rhbz#1901695
ff e;	%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pdQ	%Andrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#iA	%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#hA	%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?gy	%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907f7	%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
b0bb{l{}	%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970Ik
	%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907Kj	%Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff n;	&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pmQ	&Andrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#rA	&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#qA	&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?py	&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907o7	&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bbv{1	&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{u{}	&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970It
	&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907Ks	&Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
ff x;	'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_@- Add new Harfbuzz library to package listing and _privatelibs
- Resolves: rhbz#1903907pwQ	'Andrew John Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.1-0.0.ea_- Update to jdk-11.0.10.0+1
- Update release notes to 11.0.10.0+1
- Use JEP-322 Time-Based Versioning so we can handle a future 11.0.9.1-like release correctly.
- Still use 11.0.x rather than 11.0.x.0 for file naming, as the trailing zero is omitted from tags.
- Revert configure and built_doc_archive hacks to build 11.0.9.1 from 11.0.9.0 sources, and synced with Fedora version.
- Cleanup debug package descriptions and version number placement.
- Switch to EA mode for 11.0.10 pre-release builds.
- Drop JDK-8222286 & JDK-8254177 as applied upstream
- Explicitly request bundled Harfbuzz (too risky to change this so late in the RHEL 7 lifecycle)
- Resolves: rhbz#1903907
q#|A	'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.4-0.0.ea_- Update to jdk-11.0.10.0+4
- Update release notes to 11.0.10.0+4
- Resolves: rhbz#1903907#{A	'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.3-0.0.ea_A- Update to jdk-11.0.10.0+3
- Update release notes to 11.0.10.0+3
- Resolves: rhbz#1903907?zy	'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_@- Completely revert hacks from previous release, using buildver in configure and tzdata 2020b
- Resolves: rhbz#1903907y7	'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.2-0.0.ea_=- Update to jdk-11.0.10.0+2
- Update release notes to 11.0.10.0+2
- Update tarball generation script to use PR3818 which handles JDK-8171279 changes
- Drop JDK-8250861 as applied upstream.
- Resolves: rhbz#1903907
0bb{1	'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-1`>(- Add backport of JDK-8258836 to fix -Xcheck:jni warnings
- Resolves: rhbz#1897602{{}	'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.9-0`- Update to jdk-11.0.10.0+9
- Update release notes to 11.0.10.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-01-19 @ 1pm PT.
- Resolves: rhbz#1908970I~
	'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.8-0.0.ea`2A- Update to jdk-11.0.10.0+8
- Update release notes to 11.0.10.0+8 and add missing JDK-8245051 from b04.
- Resolves: rhbz#1903907K}	'Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.10.0.5-0.0.ea`2@- Update to jdk-11.0.10.0+5
- Update release notes to 11.0.10.0+5
- Drop JDK-8222527 as applied upstream.
- Resolves: rhbz#1903907
+9+	}	(Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082#A	(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082	(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527		(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527
`X``{	{}	(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#A	(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#A	(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#A	(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#A	(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082
dXE#
A	)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.3-0.0.ea`_A- Update to jdk-11.0.11.0+3
- Update release notes to 11.0.11.0+3
- Resolves: rhbz#1938082	)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`_@- Debug builds need to find their documentation from the release build.
- RHEL 7 builds still include a doc package for debug builds, though debug builds do not build docs.
- Resolves: rhbz#1930527		)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.2-0.1.ea`\{@- Perform static library build on a separate source tree with bundled image libraries
- Make static library build optional
- Based on initial work by Severin Gehwolf
- Resolves: rhbz#1930527
{5	(Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
RJR#A	)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#A	)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082#A	)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.5-0.0.ea`lM@- Update to jdk-11.0.11.0+5
- Update release notes to 11.0.11.0+5
- Resolves: rhbz#1938082#A	)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.4-0.0.ea`aA- Update to jdk-11.0.11.0+4
- Update release notes to 11.0.11.0+4
- Resolves: rhbz#1938082	}	)Jayashree Huttanagoudar <jhuttana@redhat.com> - 1:11.0.11.0.3-0.1.ea`a@- Fix issue where CheckVendor.java test erroneously passes when it should fail.
- Add proper quoting so '&' is not treated as a special character by the shell.
- Resolves: rhbz#1938082
d{{}	*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228#A	*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082#A	*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082{5	)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{{}	)Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228
d\#A	*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#A	*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811[1	*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#1967811{5	*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736
;;#A	+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.6-0.0.ea`pA- Update to jdk-11.0.11.0+6
- Update release notes to 11.0.11.0+6
- Resolves: rhbz#1938082{{}	*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395]5	*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^7	*Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811
\XX\[#1	+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.1-0.0.ea`ٹ- Update to jdk-11.0.12.0+1
- Update release notes to 11.0.12.0+1
- Switch to EA mode for 11.0.12 pre-release builds.
- Update ECC patch following JDK-8226374 (bug ID yet to be confirmed)
- Remove local JDK-8187450 backport as now included upstream.
- Resolves: rhbz#1967811"{5	+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-1`u- Add backport of JDK-8187450 from 11.0.12 to fix RH1937736
- Resolves: rhbz#1937736{!{}	+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.9-0`t6@- Update to jdk-11.0.11.0+9
- Update release notes to 11.0.11.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-04-20 @ 1pm PT.
- Resolves: rhbz#1940228# A	+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.11.0.7-0.0.ea`r- Update to jdk-11.0.11.0+7
- Update release notes to 11.0.11.0+7
- Resolves: rhbz#1938082
X]'5	+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811^&7	+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.4-0.0.ea`- Update to jdk-11.0.12.0+4
- Update release notes to 11.0.12.0+4
- Correct bug ID JDK-8264846 to intended ID of JDK-8264848
- Resolves: rhbz#1967811#%A	+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.3-0.0.ea`@- Update to jdk-11.0.12.0+3
- Update release notes to 11.0.12.0+3
- Resolves: rhbz#1967811#$A	+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.2-0.0.ea`- Update to jdk-11.0.12.0+2
- Update release notes to 11.0.12.0+2
- Resolves: rhbz#1967811
zz+mS	,Jiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{*{}	,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395])5	,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811{({}	+Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
?W:?W/)	,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936.{;	,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936-{7	,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$,{O	,Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873
XX]35	-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.6-0.0.ea`- Update to jdk-11.0.12.0+6
- Update release notes to 11.0.12.0+6
- Skip 11.0.12.0+5 as 11.0.12.0+6 only adds a test change
- Resolves: rhbz#1967811 2{G	,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{1{}	,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#0A	,Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936
\7{7	-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$6{O	-Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#16988735mS	-Jiri Vanek <jvanek@redhat.com> - 1:11.0.12.0.7-1a0- Minor cosmetic improvements to make spec more comparable between variants
- Related: rhbz#1999936{4{}	-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-0`@- Update to jdk-11.0.12.0+7
- Update release notes to 11.0.12.0+7
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-07-20 @ 1pm PT.
- Resolves: rhbz#1972395
]a]]{;{}	-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#:A	-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936W9)	-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#19999368{;	-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936
[?{;	.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936>{7	.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936$={O	.Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873 <{G	-Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332

er+V:eD:
e1f96091d25298a2ba6942bf99057752361acd85a35af09192241146d47a7a08D9
48de10d35c7c78cda02151a71c35178d70d58dce2c1dc876ddabcacf02451fd3D8
d042e5b60af5791405d9b06cced6de982519177eed1cee3e7edb8c9002315ac6D7
724f57980c52e692722c8586a68fbb7ecfc81812bf1d923a920abbdb04014943D6
40085a6aba324cf85849d9d215ea0210e30299d2952b61e18b07e9bbd0256068D5
9dc6103c894580255acdaca6f10c631843d1f93573f2546118ae35826f597314D4
2128f5867b50e91bf6e0f43a02f4d16b03085189d8040f386c115ab75f5a842bD3
2ebb08ac7cb76c373713ca2bd23cc2232982bc402088afaa3c55fff250bb8869D2
33d81cf734e717eea6795c7c41a630b5e0eecbab4514f5859db6609e50ef0447D1
6b0e694fe0bd25769497d03ebe96ad15e93d707736bcee6eb8e89bae4d0f77c1D0
e0d5c3c3503d52c16cbaa1ee54130af69d4b939561a49a2a1591e2049fd69279D/
740cebdde7c6823d4f1beee23080215f1f12ef9577011c88461d3bf597d1931aD.
bf23abfbb52f27d2a18450e2bbc48bb65f02cee123b849b8e4fb9c07a0e91259
WW C{G	.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{B{}	.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#AA	.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936W@)	.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1$G{O	/Severin Gehwolf <sgehwolf@redhat.com> - 1:11.0.12.0.7-2aZ- Don't package lib/client and lib/client/classes.jsa which don't exist.
- Resolves: rhbz#1698873{F{}	.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qE]	.Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JDw	.Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#KA	/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WJ)	/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936I{;	/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936H{7	/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qO]	/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JNw	/Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 M{G	/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{L{}	/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
DDR{;	0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936Q{7	0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936{P{}	/Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
WW V{G	0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{U{}	0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332#TA	0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936WS)	0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936
1Z{A	0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{Y{}	0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qX]	0Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810JWw	0Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810
@D@#^A	1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.7-0.1.eaaex- Update to jdk-11.0.13.0+7
- Update release notes to 11.0.13.0+7
- Resolves: rhbz#1999936W])	1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.1-0.1.eaad'@- Update to jdk-11.0.13.0+1
- Update release notes to 11.0.13.0+1
- Update tarball generation script to use git following OpenJDK 11u's move to github
- Switch to EA mode for 11.0.13 pre-release builds.
- Remove non-Free test from source tarball.
- Related: rhbz#1999936\{;	1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-4ab- Reduce disk footprint by removing build artifacts by default.
- Related: rhbz#1999936[{7	1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.12.0.7-3ab- Restructure the build so a minimal initial build is then used for the final build (with docs)
- This reduces pressure on the system JDK and ensures the JDK being built can do a full build
- Related: rhbz#1999936
[qb]	1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810Jaw	1Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 `{G	1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1afA- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332{_{}	1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Update to jdk-11.0.12.0+8
- Update release notes to 11.0.12.0+8
- Switch to GA mode for final release.
- This tarball is embargoed until 2021-10-19 @ 1pm PT.
- Resolves: rhbz#2012332
^Jfw	2Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 e{G	2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332d{A	1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{c{}	1Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
i{A	2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{h{}	2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qg]	2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~Dn{	2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+m{]	2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422zl{{	2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#kA	2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531Vj'	2Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
[{r{}	3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qq]	3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810Jpw	3Jiri Vanek <jvanek@redhat.com> - 1:11.0.14.0.8-0.1.eaac- Replaced hardcoded 11 by featurever where appropriate
- Fixed comment of `for slowdebug` to correct `any debug`
- Related: rhbz#2022810 o{G	3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.13.0.8-1af@- Revert addition of libharfbuzz.so after its removal by JDK-8255790
- Resolves: rhbz#2012332
,^,+w{]	3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422zv{{	3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#uA	3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531Vt'	3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531s{A	3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805
^v^{{A	4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{z{}	4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366qy]	4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810x{	3Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422
D%}~D{	4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]	4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z~{{	4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#}A	4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V|'	4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;{}	4Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$m]	4Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
{A	5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}	5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366q]	5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.8-0.1.eaae- Update to jdk-11.0.14.0+8
- Update release notes to 11.0.14.0+8
- Switch to EA mode for 11.0.14 pre-release builds.
- Turn off bootstrapping for slow debug builds, which are particularly slow on ppc64le.
- Rename blacklisted.certs to blocked.certs following JDK-8253866
- Resolves: rhbz#2022810
D%}~D
{	5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+	{]	5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{	5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#A	5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'	5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531
W;{}	5Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$m]	5Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510
^#A	6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531V'	6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{A	6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{
{}	6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366
Q$m]	6Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510{	6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]	6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{	6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422
;{}	6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
gBgV'	7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.1-0.1.eabUi- Update to jdk-11.0.15.0+1
- Update release notes to 11.0.15.0+1
- Switch to EA mode for 11.0.15 pre-release builds.
- Related: rhbz#2047531{A	7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.1.1-1bO- Update to jdk-11.0.14.1+1
- Update release notes to 11.0.14.1+1
- Resolves: rhbz#2052805{{}	7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.14.0.9-1aZ@- Update to jdk-11.0.14.0+9
- Update release notes to 11.0.14.0+9
- Switch to GA mode for final release.
- This tarball is embargoed until 2022-01-18 @ 1pm PT.
- Resolves: rhbz#2039366{5	6Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
vXYv$m]	7Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510{	7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422+{]	7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bY^@- Remove security items from release notes that were only in 17u and N/A for 11u
- Related: rhbz#2073422z{{	7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-1bV@- Update to jdk-11.0.15.0+9
- Update release notes to 11.0.15.0+9
- Switch to GA mode for release
- ** This tarball is embargoed until 2022-04-19 @ 1pm PT. **
- Resolves: rhbz#2073422#A	7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.8-0.1.eabUi- Update to jdk-11.0.15.0+8
- Update release notes to 11.0.15.0+8
- Resolves: rhbz#2047531
;{}	7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510
Z$"m]	8Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510!{	8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422 {5	7Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
;#{}	8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510bR0RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{āŁ	Ɓ
ǁȁɁʁˁ#́'́+΁/ρ3Ё7с;ҁ?ԁCՁGցKׁO؁RفVځZہ^܁b݁fށi߁nrၴw⁴{ふ䁵偵恵
灵聵遵ꁵ끵쁵큵"#'+-148;>BEHLNQTWZ]_bdgi	l
nqt
wz}  !#"&$*%.&4'9(>)C+G,L-Q.V/]

W4'c	8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731&]	8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R%	8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373${5	8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
d\d+{	9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.15.0.9-2bZ- Add JDK-8284920 fix for XPath regression
- Related: rhbz#2073422&*{S	8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>){	8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695(9	8Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
W;-{}	9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.0.8-1bҨ@- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8284920 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use "git apply" with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Resolves: rhbz#2106510$,m]	9Jiri Vanek <jvanek@redhat.com> - 1:11.0.16.0.8-1b@- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106510

W41c	9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#213037310]	9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R/	9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373.{5	9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&4{S	9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>3{	9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#213369529	9Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373

W48c	:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#213037317]	:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R6	:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#21303735{5	:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&;{S	:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>:{	:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#213369599	:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}>}	:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q=]	:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&<G	:Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192

er+V:eDG
ec4e31145b2bd5c37f07b12786ef3f1a7f747d2b7545a8f2deb7ca4a1dee6692DF
374186860ba10d433ef1b2fc521d6b97c48570d7340740cbe2e83f73df0b05e4DE
a4b82389944cd83f755da0bd6b1b81d987f9dc5f28ee78bd23bde637a51321e2DD
ab078229f1b5a4b3faba2b28785c5ddc0ff1118b1a2b3480dd2d824f7201a9ceDC
1b6f592d463f10e592cc2b035e409be816bd6dc189d7457574d5641fdcf767bcDB
22b2f7582ba663c4bb9f008bce4f7a80e69654b30b05c0571864b3b8292f8ff5DA
dcd5ebbf96fa4b554ad2a5520ab76814b9eae044e649c9408139b2b07795d5f4D@
1bb75937417ce4c985d73d9cf214bfece58dd2abdf6c21d4b1cb0108f070e2ffD?
be203dd4714182fcfeef395bb57d7d5e9f418c603b87d6a5eb1ddb4db5253163D>
2141ba5b56fde898fffe70f5ebc0e8dd7ef3958b68e0cb81881c570fbfc2a0f2D=
8c2b3aa763d6d464e67be783b62d083cadc0aa9caf7fd24997ebcb514c44a4b2D<
b322d84f1b35af3ca899bf943ee67782b8ae449a4769e0b3d0b7f455085b669cD;
6f4bf52463b1c528e35abf3e53489d86f0214da06151240744c0ab18b50ab903

W4Bc	;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731A]	;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373R@	;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac6@- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373?{5	;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.16.1.1-1c- Update to jdk-11.0.16.1+1
- Update release notes to 11.0.16.1+1
- Add patch to provide translations for Europe/Kyiv added in tzdata2022b
- Add test to ensure timezones can be translated
- Resolves: rhbz#2119512
\&E{S	;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>D{	;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695C9	;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}H}	;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qG]	;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&FG	;Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
*J*>L{	<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695K9	<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#21303734Jc	<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731I]	<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373
*U*&NG	<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&M{S	<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
Q}	<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}P}	<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qO]	<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
--4Tc	=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< A- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#21303731S]	=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.1-0.1.eac< @- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373_R{E	<Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
\&W{S	=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695>V{	=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695U9	=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.7-0.1.eac=q- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373
]_]}Z}	=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qY]	=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192&XG	=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192
MtM>]{	>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695_\{E	=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182[}	=Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111
*U*&_G	>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&^{S	>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
b}	>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}a}	>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q`]	>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.dW	>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_c{E	>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XT>g{	?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-1cF@- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695f{	>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#eA	>Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
*U*&iG	?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.1-0.1.eac@- Update to jdk-11.0.18+1
- Update release notes to 11.0.18+1
- Switch to EA mode for 11.0.18 pre-release builds.
- Drop local copies of JDK-8294357 & JDK-8295173 now upstream contains tzdata 2022e
- Related: rhbz#2150192&h{S	?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.17.0.8-2cJ- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695
l}	?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}k}	?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192qj]	?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.nW	?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_m{E	?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
XTqq]	@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192p{	?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#oA	?Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
r_t{E	@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182s}	@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}r}	@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192
!%!w{	@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#vA	@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.uW	@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,z{_	@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdymA	@Jiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'x{U	@Andrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
}}	AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-2cG- Add missing release note for JDK-8295687
- Resolves: rhbz#2160111}|}	AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.10-1c- Update to jdk-11.0.18+10 (GA)
- Update release notes to 11.0.18+10
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-01-17 @ 1pm PT. **
- Related: rhbz#2150192q{]	AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.18.0.9-0.2.eac- Update to jdk-11.0.18+9
- Update release notes to 11.0.18+9
- Drop local copy of JDK-8293834 now this is upstream
- Require tzdata 2022g due to inclusion of JDK-8296108, JDK-8296715 & JDK-8297804
- Update TestTranslations.java to test the new America/Ciudad_Juarez zone
- Resolves: rhbz#2150192
ii.W	AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_~{E	AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('{U	AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229{	AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A	AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
u_{E	BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182,{_	AAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmA	AJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
!%!{	BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A	BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106.W	BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106
II,{_	BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd
mA	BJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'	{U	BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
?8=?y{y	BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v
g	BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C{
	BAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
ii.W	CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.1-0.1.ead- Update to jdk-11.0.20+1 (EA)
- Update release notes to 11.0.20+1
- Switch to EA mode
- Drop local inclusion of JDK-8274864 & JDK-8305113 as they are included in 11.0.20+1
- Add missing Swing release note
- Related: rhbz#2221106_{E	CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.19.0.7-1d9@@- Update to jdk-11.0.19.0+7
- Update release notes to 11.0.19.0+7
- Require tzdata 2023c due to local inclusion of JDK-8274864 & JDK-8305113
- Update generate_tarball.sh to add support for passing a boot JDK to the configure run
- Add POSIX-friendly error codes to generate_tarball.sh and fix whitespace
- Remove .jcheck and GitHub support when generating tarballs, as done in upstream release tarballs
- Rebase RH1750419 alt-java patch against 11.0.19+6
- ** This tarball is embargoed until 2023-04-18 @ 1pm PT. **
- Resolves: rhbz#2185182
(XT('{U	CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229{	CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106#A	CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.7-0.1.eadD@- Update to jdk-11.0.20+7 (EA)
- Update release notes to 11.0.20+7
- Related: rhbz#2221106
uvg	CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C{
	CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642,{_	CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmA	CJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
{	DAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106y{y	CAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966
II,{_	DAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- UpdmA	DJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'{U	DAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\ }=	DAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy{y	DAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966vg	DAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C{
	DAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
}#{	EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.0.8-1d- Update to jdk-11.0.20.0+8 (GA)
- Update release notes to 11.0.20.0+8
- Switch to GA mode for release
- ** This tarball is embargoed until 2023-07-18 @ 1pm PT. **
- Resolves: rhbz#2221106&"s[	DAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~!s	DAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
II,&{_	EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-1e)1A- Update to jdk-11.0.21+9 (GA)
- Upd#%mA	EJiri Vanek <jvanek@redhat.com> - 1:11.0.21.0.9-1e)1@- For non debug subpackages, ghosted all alternatives (rhbz1649776)
- For non system JDKs, if-outed versionless provides.
- Aligned versions to be %{epoch}:%{version}-%{release} instead of chaotic
- Related: RHEL-11320'${U	EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.20.1.1-1d@- Update to jdk-11.0.20.1+1 (GA)
- Update release notes to 11.0.20.1+1
- Add backport of JDK-8312489 already upstream in 11.0.22 (see OPENJDK-2095)
- Add backport of JDK-8243210 already upstream in 11.0.21 (see RH2229269)
- Update openjdk_news script to specify subdirectory last
- Add missing discover_trees script required by openjdk_news
- Synchronise runtime and buildtime tzdata requirements
- Update README.md to match the version in later RHEL releases
- Resolves: rhbz#2236229ate release notes to 11.0.21+9
- Remove system crypto policy patch which doesn't belong on RHEL 7 with no system policies
- Update generate_tarball.sh to be closer to upstream vanilla script inc. no more ECC removal
- Update bug URL for RHEL to point to the Red Hat customer portal
- Change top_level_dir_name to use the VCS tag, matching new upstream release style tarball
- Apply all patches using -p1
- Drop local backport of JDK-8243210 which is upstream from 11.0.21+2
- Add missing JFR alternative ghost
- Move jcmd to the headless package
- Replace -mstackrealign with -mincoming-stack-boundary=2 -mpreferred-stack-boundary=4 on x86_32 for stack alignment
- Disable the serviceability agent on Zero architectures even when the architecture itself is supported
- ** This tarball is embargoed until 2023-10-17 @ 1pm PT. **
- Resolves: RHEL-12217
- Resolves: RHEL-12910
- Resolves: RHEL-12913
- Resolves: RHEL-11320
- Resolves: RHEL-13227
- Resolves: RHEL-13217
^8=?^\*}=	EAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.1-0.1.eae!@- Update to jdk-11.0.23+1 (EA)
- Update release notes to 11.0.23+1
- Switch to EA mode
- Speed up PPC build by removing ppc64le --with-jobs=1 workaroundy){y	EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.7-1e- Update to jdk-11.0.22+7 (GA)
- Update release notes to 11.0.22+7
- Switch to GA mode for release
- ** This tarball is embargoed until 2024-01-16 @ 1pm PT. **
- Resolves: RHEL-20966v(g	EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.22.0.6-0.1.eae- Update to jdk-11.0.22+6 (EA)
- Update release notes to 11.0.22+6
- Switch to EA mode
- Drop local copy of JDK-8312489 which is now included upstream
- Resolves: RHEL-21031C'{
	EAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.21.0.9-2e}@- Restore %{epoch}:%{javaver} versioning to jre, java, jre-headless, java-headless, java-devel & java-sdk
- Resolves: RHEL-19642
n}n
.	FSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665P-#	FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#1876665&,s[	EAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-2f"@- Fix 11.0.22 release date in NEWS
- Restore ppc64le --with-jobs=1 workaround to avoid flaky ppc builds~+s	EAnton Bobrov <abobrov@redhat.com> - 1:11.0.23.0.9-1f@- Update to jdk-11.0.23+9 (GA)
- Update release notes to 11.0.23+9
- Switch to GA mode for release
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Resolves: RHEL-30914
sOs4	FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665S3s5	FJiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}2{	FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665z1y	FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#187666500c	FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665z/y	FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
/</z9y	GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.7-0.0.ea_B- Update to jdk-11.0.9+7 (EA)
- Resolves: rhbz#1876665
8	GSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.6-0.1.ea_A- Update static-libs packaging to new layout
- Resolves: rhbz#1876665P7#	GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.6-0.0.ea_@- Update to jdk-11.0.9+6 (EA)
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Resolves: rhbz#18766656w?	FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665K5w!	FAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665
KLt>	GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665S=s5	GJiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_F- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}<{	GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_E- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665z;y	GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_D- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#18766650:c	GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.8-0.0.ea_C- Update to jdk-11.0.9+8 (EA)
- Remove JDK-8252258/RH1868406 now applied upstream.
- Resolves: rhbz#1876665
::SCs5	HJiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665}B{	HAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zAy	HAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665@w?	GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665K?w!	GAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665

er+V:eDT
dd1acce44324d0f78c3fefe9d62e4f6b967b6a1f192ce18c8c0336a4c8adabd0DS
d837edc3c03b3b3e816e3578cfb0fb39a5018c0d8b79486829a91303a31fba95DR
4159fb078456195a5426e0c1b4c344097b8cea15b93d89a5b0edec624c3dfabaDQ
81fe53c540c2219cdfff5019d61db2306219389015797fa7f76cb1b9d772482aDP
a1ca7e4977e1aa55e582537db75040c395105cb35ed1d15da80d8a11e4a3f662DO
52427e37a69f9019c71338e82cb47b4093f49f6cbe7aaf6c7472b6ece216b3bdDN
da6113b8e3f60613882eeec8c8497c068bd46559042351e5cf030ec9ad382d41DM
d6beb9da905c4b24c2f8e52152046e20369cddd4a1f98e7babf6ac1658ced21bDL
ac4c10593aace7feb58b42351306016a0668d518b590587b3be6a1fabb94aabfDK
1aed659e1e3bce0de9d3874074bcf4fc4df05a8018e054fdb5ac7209dd8ffad7DJ
e95162c5ce19bdda8897921e19c340bcc15ab18c2627b6d8915c79b8754c1505DI
e601bbdfd361d5089be7cec55d69d6cc4b85d1c52963c2f8d004de14bd0ccde1DH
1ede1f94ef149ac05c9b87696792135237e12c4f7eb09ed33fcb232bee567817
}-
Gw	HSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610Fw?	HAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KEw!	HAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665D	HAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665
|&{|}L{	IAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.0.ea_A- Update to jdk-11.0.9+10 (EA)
- Resolves: rhbz#1876665zKy	IAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.9-0.0.ea_@- Update to jdk-11.0.9+9 (EA)
- Resolves: rhbz#1876665&JwW	HAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]IwE	HSeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sHi	HJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
'(U'
Qw	ISeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Fix directory ownership of static-libs package
- Resolves: rhbz#1896610Pw?	IAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Delay tzdata 2020b dependency until tzdata update has shipped.
- Resolves: rhbz#1876665KOw!	IAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-0_9- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665N	IAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.10-0.1.ea_9- Improve quoting of vendor name
- Resolves: rhbz#1876665SMs5	IJiri Vanek <jvanek@redhat.com> - 1:11.0.9.10-0.1.ea_B- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665
b&{b$VqY	JVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-8R@- Fix vlock doesn't perform PAM account management or credential reinitialization
  Resolves: #1032140lUqk	JVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-7Rz/@- Add PAM config for vlock
  Resolves: #1026819&TwW	IAndrew Hughes <gnu.andrew@redhat.com> - 1:11.0.9.11-2_#- Add backport of JDk-8222537 so the Host header is sent when using proxies.
- Resolves: rhbz#1869530]SwE	ISeverin Gehwolf <sgehwolf@redhat.com> - 1:11.0.9.11-1_- Update to jdk-11.0.9.1+1
- RPM version stays at 11.0.9.11 so as to not break upgrade path.
- Adds a single patch for JDK-8250861.
- Resolves: rhbz#1895275sRi	IJiri Vanek <jvanek@redhat.com> - 1:11.0.9.11-1_- Move all license files to NVR-specific JVM directory.
- This bad placement was killing parallel installability and thus having a bad impact on leapp, if used.
- Resolves: rhbz#1896609
P]JP]s5	JVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-15[qr- Add man page for kbdinfo, link open man page to openvt man page
  Related: #949015^\sK	JVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-14[(@- Replace CtrlL_Lock with Caps_Lock in generated us.map
  Resolves: #1441411
- Improve man pages and usage messages quality and consistency
  Resolves: #949015{[s	JVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-13X@- Add compose rules to generated cz.map
  Resolves: #1181581nZsm	JVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-12W- Add eurlatgr console font
  Resolves: #1310286YsG	JVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-11T$- Include xkb layouts from xkeyboard-config converted to console keymaps
  Resolves: #1122058NXa?	JDaniel Mach <dmach@redhat.com> - 1.15.5-10RU- Mass rebuild 2014-01-24MW_?	JDaniel Mach <dmach@redhat.com> - 1.15.5-9Rk- Mass rebuild 2013-12-27
"pW"{es	KVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-13X@- Add compose rules to generated cz.map
  Resolves: #1181581ndsm	KVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-12W- Add eurlatgr console font
  Resolves: #1310286csG	KVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-11T$- Include xkb layouts from xkeyboard-config converted to console keymaps
  Resolves: #1122058Nba?	KDaniel Mach <dmach@redhat.com> - 1.15.5-10RU- Mass rebuild 2014-01-24Ma_?	KDaniel Mach <dmach@redhat.com> - 1.15.5-9Rk- Mass rebuild 2013-12-27$`qY	KVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-8R@- Fix vlock doesn't perform PAM account management or credential reinitialization
  Resolves: #1032140l_qk	KVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-7Rz/@- Add PAM config for vlock
  Resolves: #1026819^s%	JVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-16aw- Fix vlock when console or terminal is closed abruptly
  Resolves: #1486233
99Nla?	LDaniel Mach <dmach@redhat.com> - 1.15.5-10RU- Mass rebuild 2014-01-24Mk_?	LDaniel Mach <dmach@redhat.com> - 1.15.5-9Rk- Mass rebuild 2013-12-27$jqY	LVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-8R@- Fix vlock doesn't perform PAM account management or credential reinitialization
  Resolves: #1032140liqk	LVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-7Rz/@- Add PAM config for vlock
  Resolves: #1026819hs%	KVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-16aw- Fix vlock when console or terminal is closed abruptly
  Resolves: #1486233gs5	KVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-15[qr- Add man page for kbdinfo, link open man page to openvt man page
  Related: #949015^fsK	KVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-14[(@- Replace CtrlL_Lock with Caps_Lock in generated us.map
  Resolves: #1441411
- Improve man pages and usage messages quality and consistency
  Resolves: #949015
c_ncrs%	LVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-16aw- Fix vlock when console or terminal is closed abruptly
  Resolves: #1486233qs5	LVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-15[qr- Add man page for kbdinfo, link open man page to openvt man page
  Related: #949015^psK	LVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-14[(@- Replace CtrlL_Lock with Caps_Lock in generated us.map
  Resolves: #1441411
- Improve man pages and usage messages quality and consistency
  Resolves: #949015{os	LVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-13X@- Add compose rules to generated cz.map
  Resolves: #1181581nnsm	LVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-12W- Add eurlatgr console font
  Resolves: #1310286msG	LVitezslav Crhonek <vcrhonek@redhat.com> - 1.15.5-11T$- Include xkb layouts from xkeyboard-config converted to console keymaps
  Resolves: #1122058
/&V/xiO	MJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560wi	MJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Kvi/	MJan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441ugA	MJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[tgQ	MJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^sgY	MJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129
NU:^}gY	NJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129|i	MJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159{i5	MJan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401tzi	MJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-yis	MJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
 1iO	NJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560i	NJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Ki/	NJan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441gA	NJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[~gQ	NJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
NU:^gY	OJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129i	NJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159i5	NJan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401ti	NJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-is	NJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
 1iO	OJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560i	OJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560K
i/	OJan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441	gA	OJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[gQ	OJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
NU:^gY	PJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129i	OJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159i5	OJan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401ti	OJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-
is	OJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
 1iO	PJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560i	PJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Ki/	PJan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441gA	PJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[gQ	PJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
NU:^gY	QJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129i	PJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159i5	PJan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401ti	PJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-is	PJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
 1 iO	QJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560i	QJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Ki/	QJan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441gA	QJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[gQ	QJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
NU:^%gY	RJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129$i	QJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159#i5	QJan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401t"i	QJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-!is	QJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
 1*iO	RJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560)i	RJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560K(i/	RJan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441'gA	RJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[&gQ	RJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
NU:^/gY	SJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129.i	RJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159-i5	RJan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401t,i	RJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-+is	RJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
 14iO	SJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#13425603i	SJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560K2i/	SJan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#13334411gA	SJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[0gQ	SJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
NU:^9gY	TJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#12601298i	SJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#18561597i5	SJan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401t6i	SJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-5is	SJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
 1>iO	TJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560=i	TJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560K<i/	TJan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441;gA	TJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[:gQ	TJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
NU:^CgY	UJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129Bi	TJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159Ai5	TJan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401t@i	TJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-?is	TJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762

er+V:eDa
80196e9f5cfeb1b79fee9a0c7fdadd992ab7aa207db374333f67dbda5f2fd14eD`
6964dd0077dc7a05fc63ad2b2e02aecba267ac20fdf80589b768e01146960b74D_
7b90cb8bc8d2c7faf537d5ae45a0a5a1723647451341f52d133cd54aed8e427cD^
33f93263c696ee536e808126745c9fa540fc61ef70ce1cffc4848d598c98eae1D]
0c8cc9217954e5b7e4fba72b8cac347c473caf377f918d06fdc3c2bb7e672917D\
8db5b248a66cb5ad1ed9c3264fe68eb2d2de4e9b3a5c7cc07f61bde703d26938D[
d4e1ed8394af297a574fede15b7e0b3dcc28d263998175257f45e728f22fca91DZ
d1b44c5bcb094399e0bce41de4218e28b8f69fb0c0a79c24411b5561978ec6b5DY
c95477083d786f35fe049b4cf228df007b60410ff81fc37b0e6dd8bd2124cdccDX
a3a9ea28c98e59589049fb7889c20c37771b190b44b92388c4e2aa7aafcb1a2eDW
e940311272fea2057047e571496ef2c682d234a1b3e10e8c505258a1cc20ae6bDV
b128da11799b79cddf1ef0419560127564929391ef662226704b79b39ab3bb98DU
c4848c6ee81a224b1eb505bb2bf5a9c8572e930973b92319a6e17e294d14310b
 1HiO	UJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560Gi	UJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560KFi/	UJan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441EgA	UJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[DgQ	UJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
NU:^MgY	VJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129Li	UJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159Ki5	UJan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401tJi	UJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-Iis	UJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
 1RiO	VJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560Qi	VJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560KPi/	VJan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441OgA	VJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[NgQ	VJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
.NU:.W
	WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]Vi	VJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159Ui5	VJan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401tTi	VJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-Sis	VJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
7?7KZ}	WJan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3Ye	WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]<Xw	WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t\g	WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i[Q	WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]I
-^W	WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M]	WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
<<Ka}	XJan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]`9	WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L_	WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tcg	XRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]ibQ	XRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]M
-eW	XRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]Md	XRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
g9	XRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]Lf	XRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
1i1	XRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fRJh	XRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<Mk	YRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}?j{	XRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
NLm	YRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}-lW	YRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]
p1	YRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fVJo	YRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)n9	YRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<<?q{	YRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
drE	YRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
p,p7tk	YRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]Os	YRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Pv	ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol[^u9	ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999xo	ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] pow^twe	ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command\erpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
yyz7	ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han`Xy-	ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
f{I	ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo|	ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
o}Y	ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q~]	ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{1l2r3x4}56789:; <%=*>/?4@9A>BCDHEMFRGWHZJ\K^LaNcOePgQiSkTmUpWqXrYtZv]x_za{b|c}d~fghijklmopqrtuv!w#y&{'|(})~*+-.02479;=@BCEGIJKLMNPQRSTUWYZ[\]^
dE	[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
o,po|u	[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]7k	[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]O	[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Y}w	[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B	[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"A	[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]
  ?{	[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.2.el7]ef@- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}4e	[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^9	[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
XB	\Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"
A	\Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]|	u	\Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]
}w	\Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]
4e	\Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^
9	\Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bA	\Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~y	\Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
%n%"A	]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]7	\Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]	\Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ensn
}w	]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B	]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}
4e	]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^9	]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bA	]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~y	]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
unu"A	^Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]+	M	]Radomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]7	]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]	]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Enss
}w	^Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B	^Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}
4!e	^Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^ 9	^Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
b#A	^Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~"y	^Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
n+&	M	^Radomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]%7	^Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]$	^Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ensxdle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
'7	_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Hanz
f(I	_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo)	_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
o*Y	_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q+]	_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
--R-	_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE^,7	_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
,,O.	_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]
'01	_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.2.el7]`	l- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]T/#	_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]
AA2s	`Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check J1s#	`Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCD4s	`Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o3sm	`Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbj7sc	`Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]6s1	`Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []5s7	`Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
59+	`Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]F8s	`Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
;s	aJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check ^:9	`Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCD=s	aJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o<sm	aJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbj@sc	aJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]?s1	aJan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []>s7	aJan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5B+	aAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]FAs	aJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
^C9	aAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]
ww^E7	bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]!D?	aAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.2.el7]_- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}

er+V:eDn
e7f2bf03392856717c1588ee1a77010b1537d1a678ed7dd1dad5ad7391cd4147Dm
82e182e512caa6c722313fe432c89e81a61b1c021c5fa0e223a163e77c95ce6eDl
f8613e068693df3d5e08f956697ae0b595071f7b8c8bbed307faf9dbadef2a8aDk
53452ad31f9655e8f71a0b4c49b118b9337855433c50f25a9f5a75b92ebb8a8aDj
645ff71bbd0c6801049154ee1c5338517839d23b8146501039a0a919dd696e33Di
a6fb96a295e675646b15c339c7b3d6070fefdec2a9d1b67402bcee35dc06bd72Dh
93f5058bbfe57b3134debfc599214a91d401380ef38ec57336a0d995704d9c26Dg
f181f4bc3868b84eb350197aee4e79d0466d5aaac0e0a70a37eb58aa7533e228Df
91d2cf4d7a40fe66ba14583d4d5f045850fefc8b26b7e0adc2634f5ec9f9a775De
3db35ae4792e6efe04cf89e50aeb71e9794589152c92cc1de54f2c92dc956b40Dd
9f794072765d2423d8dc156f9a676c6e2b29c90d2a6f4e58cb579073b02c4017Dc
996ee55268c9971d07d38c3217e0fb813a202d1b838963b6db16217069d193dbDb
b8c980b0d2eaf56affe69fde8c004c91dde7d83277578de4cfc8c06aaa322858RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
OG	bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]RF	bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE
?'?[I1	bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797TH#	bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bJ?	bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4Kc	bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11JL	bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11JM	bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
N	bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
?'?[P1	cAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797TO#	cAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bQ?	cAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4Rc	cAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11JS	cAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11JT	cAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
U	cAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
KK/WY	cAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|Vs	cAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
`H`[Y1	dAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [19017973Xa	cAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bZ?	dAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4[c	dAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J\	dAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J]	dAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
^	dAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
KK/`Y	dAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|_s	dAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3aa	dAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
AA:bo	dAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
KK/dY	eAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|cs	eAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3ea	eAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
4A4g	eAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.26.1.el7]`~@- selinux: fix deadlock in security_set_bools() (Ondrej Mosnacek) [1939091]
- md: fix md io stats accounting broken (Ming Lei) [1927106]
- redhat: Fix realtime_check for -private (Juri Lelli):fo	eAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
//i		eAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]@h{	eAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.27.1.el7]`N@- video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (Mohammed Gamal) [1941841]
- Drivers: hv: vmbus: enable VMBus protocol version 5.0 (Mohammed Gamal) [1941841]
- redhat: Add git suffix to realtime_check merge_tree (Juri Lelli)
==>jw	eAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
k#	eAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..Ml	eAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]
ttm		fAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]
==>nw	fAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
o#	fAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..Mp	fAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+r'	fAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}Hq	fAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 
SzS"t?	fAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]s}	fAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
,,v-	fAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.2.el7]`A- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]1u]	fAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+x'	gAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}Hw	gAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 
SzS"z?	gAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]y}	gAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
1{]	gAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
|	gAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
}	gAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2_	gAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]~'	gAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\}	hAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]9	gAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
"?	hAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
1]	hAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
	hAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
	hAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2_	hAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]'	hAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\
9	hAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"	?	hAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]9	hAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
	iAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
	iAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2_	iAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]
'	iAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\9	iAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"?	iAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]9	iAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
22I
	iAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm	iRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348
nn9	jAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]iQ	iRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
Y9	jAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"?	jAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]
22I
	jAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm	jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348
iQ	jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_=	jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7m	jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!A	jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7m	jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]bRARY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{abdegijklmnoprtvxz{|Á}āŁƁǁȁɁʁˁ
́́΁ρЁҁӁԁՁׁ؁فځہށ߁ !ၹ"⁹$べ&䁹)遹,.04679;=?ACDEFI	J
KLO
PQTUWZ\`bcghikn#q%r&t'w-y/z0|1789?@78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm	kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348
i Q	kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_!=	kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7"m	kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!$A	kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7#m	kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]
pepp&_	kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]%+	kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}
!)+	lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}n([	kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igZ'3	kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error reform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
,n,[	lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igZ+3	lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]p*_	lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error reform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
.	lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060-}	lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?0	lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}</w	lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
"Q"4s1	mJan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []3s7	mJan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]%2I	lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]1	lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}
F6s	mJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]j5sc	mJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]
7+	mAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]
P9	mAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol^89	mAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999;o	mAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powt:e	mAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commanderpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
33n=[	nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igX<-	mAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error reform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
?	nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060>}	nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?A	nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<@w	nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
QQ%CI	nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]B	nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\D7	nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT
PP+EU	nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((SF%	nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)

er+V:eD{
dd8b1af64f49b071bf8395d452ac0dd4a5272f3de913475a6e1158eba0bcf9a0Dz
4a74ed8e2ec25ff2f90a460ace450f1f5f9d8ec2388840ac54190eadc8a43575Dy
da8588048a3618261c5ce040bd0a4053c3a59f68de23dae234a757305ef02c43Dx
9e3c7f90c42ce49e7b713d239d0814692a9206c40398c880f541a2a12d8aa210Dw
6b93ef98f6a4d5466b5be6c353e9339237a7ee06b8879ce1e25290af5e63339cDv
c9bd64813e41abf55c807e7a4e61c62906d1c51817c09e583a7b4306568104a8Du
ea4070c75f7c99de5202445cbf44e188a168785685b3ee3a524f47abd2e476b2Dt
faf10a9ee4a6a84d4d3e47e83fc9b5e9820bc013e514a117737d79a517e0386aDs
10d9b8b27ee08f5090cf1a5d694548af27d8f6cdc826e69807773aeb28c9bd11Dr
f66887fb1f33b96e1102061d623623d7d06c2f8b951e00a16b5c6b4d260f7a75Dq
2a53fc6879935314c27af738cec3350d3ceb42d0ac3d7163f52ab94febb50deaDp
6f164909e08bae70614e499ae419c8240f745a3e5a7212281901e38d69a975d4Do
d407c748075b7355c9958eda5ff21771b816ee274b0d13adadeb34a3d3cb72ed
up%II	oRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]H	oRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}G	oRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\J7	oRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT
PP+KU	oRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((SL%	oRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpMO	oRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%NI	oRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}M	oRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77DP	oRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
((SQ%	pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpMT	pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%SI	pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}R	pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77DU	pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
%v%LW	pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]V		pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d
Z	pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]Y)	pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]X-	pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
%v%L\	qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408][		qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d&`K	qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
_	qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]^)	qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]]-	qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
xxb#	qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]laW	qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
Tc'	qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
3^O$3lgW	rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&fK	rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
e	rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]d9	qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
iih#	rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
Ti'	rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
G^Gk#	rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]j9	rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(Bn	rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]m	rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825+lU	rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 !CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227"] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
MMq#	sRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lpW	sRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&oK	sRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
Tr'	sRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for $
G^Gt#	sRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]s9	sRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(Bw	sRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]v	sRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825(+uU	sRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}) CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV*E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 +CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227,] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
y#	tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]Lx	sRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
Tz'	tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for .
G^G|#	tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]{9	tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B	tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]~	tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-238252+}U	tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}3 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV4E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 5CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [20902276] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
L	tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]
&&U)	tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
	uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825:	tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}; CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV<E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 =CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227>] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
hhL	uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]B	uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
&&U)	uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
iQ	uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]	uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@		uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7m	uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitcD
1	uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
wwL
	vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]3e	uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
&&U)	vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
iQ	vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]	vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@	vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7m	vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitcJ1	vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
E)E_=	vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3	vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3e	vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
iQ	wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]	wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@	wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7m	wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitcO1	wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
)E7	wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_=	wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3	wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3e	wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
WW!1	xRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485] 	wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
<e_%=	xRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]$3	xRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3#e	xRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]7"m	xRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitcR
_TH<)w	xRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}(
	xRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]'	xRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]&7	xRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]
Hd,7	yRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_+=	yRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3*e	xRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
((</w	yRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}.
	yRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]-	yRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]
HK1}	yJan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]30e	yRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t3g	yRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i2Q	yRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]X
6s	zJan Stancek <jstancek@redhat.com> [3.10.0-1152.el7]^- [nvmem] nvmem: properly handle returned value nvmem_reg_read (Vladis Drono\	5s!	zJan Stancek <jstancek@redhat.com> [3.10.0-1151.el7]^W@- [netdrv] qede: Fix multicast mac configuration (Michal Schmidt) [1740064]
- [scsi] sd_dif: avoid incorrect ref_tag errors on 4K devices larger than 2TB (Ewan Milne) [1833528]
- [hid] HID: hiddev: do clean[M4	yRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}up in failure of opening a device (Torez Smith) [1814257] {CVE-2019-19527}
- [hid] HID: hiddev: avoid opening a disconnected device (Torez Smith) [1814257] {CVE-2019-19527}
- [x86] x86: make mul_u64_u64_div_u64() "static inline" (Oleg Nesterov) [1845864]
- [mm] mm: page_isolation: fix potential warning from user (Rafael Aquini) [1845620]
- [s390] s390/mm: correct return value of pmd_pfn (Claudio Imbrenda) [1841106]
- [fs] fs/proc/vmcore.c:mmap_vmcore: skip non-ram pages reported by hypervisors (Lianbo Jiang) [1790799]
- [kernel] kernel/sysctl.c: ignore out-of-range taint bits introduced via kernel.tainted (Rafael Aquini) [1845356]
- [documentation] kernel: add panic_on_taint (Rafael Aquini) [1845356]
- [fs] ext4: Remove unwanted ext4_bread() from ext4_quota_write() (Lukas Czerner) [1845379]
- [scsi] scsi: sg: add sg_remove_request in sg_write ("Ewan D. Milne") [1840699] {CVE-2020-12770}
- [fs] fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (Donghai Qiao) [1832062] {CVE-2020-10732}]v) [1844409]
- [mailbox] PCC: fix dereference of ERR_PTR (Vladis Dronov) [1844409]
- [kernel] futex: Unlock hb->lock in futex_wait_requeue_pi() error path (Vladis Dronov) [1844409]
- [fs] aio: fix inconsistent ring state (Jeff Moyer) [1845326]
- [vfio] vfio/mdev: make create attribute static (Vladis Dronov) [1837549]
- [vfio] treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Synchronize device create/remove with parent removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid creating sysfs remove file on stale device removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Improve the create/remove sequence (Vladis Dronov) [1837549]
- [vfio] treewide: Add SPDX license identifier - Makefile/Kconfig (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid inline get and put parent helpers (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Fix aborting mdev child device removal if one fails (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Follow correct remove sequence (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid masking error code to EBUSY (Vladis Dronov) [1837549]
- [include] vfio/mdev: Drop redundant extern for exported symbols (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Removed unused kref (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid release parent reference during error path (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Add iommu related member in mdev_device (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: add static modifier to add_mdev_supported_type (Vladis Dronov) [1837549]
- [vfio] vfio: mdev: make a couple of functions and structure vfio_mdev_driver static (Vladis Dronov) [1837549]
- [char] tpm/tpm_tis: Free IRQ if probing fails (David Arcari) [1774698]
- [kernel] audit: fix a memleak caused by auditing load module (Richard Guy Briggs) [1843370]
- [kernel] audit: fix potential null dereference 'context->module.name' (Richard Guy Briggs) [1843370]
- [nvme] nvme: limit number of IO queues on Dell/Samsung config (David Milburn) [1837617]
AA8s	zJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check _J7s#	zJan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCD:s	zJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o9sm	zJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbj=sc	zJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]<s1	zJan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) [];s7	zJan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
h5)h<@w	{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}?
	{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]F>s	zJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
HKB}	{Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3Ae	{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tDg	{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iCQ	{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]d
-FW	{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]ME	{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
<<KI}	|Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]H9	{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]LG	{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}

er+V:eD
af4714a643e3d4a5fe7d6877aeec7cfc2047da0866e0c7feb3defa34e1c54b14D
5bea05b28dab5f6e5c851855e06049b7d5dcb569c591a728efd7ea42b4a9ac8eD
33b524d6eec3fc82a17df2220b596193025c1faf20c5939c4271809681f95803D
62db43a91b2c1f3cd0407729f5c13f51ea098fea0aa9b90e2444d92166d1817dD
bb9d06747ab519acfbcb5813fc1980b1af09ff804dab7cf685cf77230153ea1aD
95abbd8b6931c04aa8fdca6df2600bc37b23414c8395a75a4ef0a54d57357161D
804cbacad84b958748331da1bcd0479ae493f31fb8564a84104a6573e7aa7c81D
2f35a9c1bf11fa8350dfd2b02c990903292933bde6dd81da9a05921d0265d756D
085f001bc61a93bf23c68f240bd7b5c24aa41e4a9b6c5539dfe676b451ec102aD
18d2703d9432cd3d8353acf0fb1f852fe4c15301b3d49fffac3f0194c6a4aaa0D~
7804215d9e8fd6eaae4ae7d7fb360dd0ec85e87ed93ec488ef3d1cb1285ff33eD}
8cdf3d0ccf31842dffcd39b5f3b05819fc442a375c03a3212e7b51db17f53e29D|
7d4cedf119f33ca8dc827b0f6f2be910119d492bf48ad4b4fd46ee45c6094800
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tKg	|Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iJQ	|Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]i
-MW	|Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]ML	|Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
O9	|Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]LN	|Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
1Q1	|Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fnJP	|Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<MS	}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}?R{	|Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
NLU	}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}-TW	}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]
X1	}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_frJW	}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)V9	}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<<?Y{	}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
dZE	}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
p,p7\k	}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]O[	}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
P^	~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_holw^]9	~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999`o	~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powzt_e	~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commandxerpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
yyb7	~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han|Xa-	~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
fcI	~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
ood	~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{B	CE
FGHIKLMNPQ!S%T)U,V/W1Y3Z6^8`:a=b@cBeDfFgIjKkMlOmQoSpUqXsYtZu\v^y`{b}c~defgjmpstvx{}	 !#%'()*+,./01235789:;<>Á?
oeY	~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


qf]	~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
dgE	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
o,po|ju	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]7ik	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]Oh	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Y}mw	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]Bl	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"kA	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]
  ?p{	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.2.el7]ef@- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}4oe	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^n9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
XBs	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"rA	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]|qu	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]
}tw	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]
4ve	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^u9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bxA	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~wy	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
%n%"{A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]z7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]y	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens
}}w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B|	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}
4e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^~9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bA	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~y	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
n+	M	Radomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ensdle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han
fI	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
oY	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q	]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
--R	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE^
7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
,,O	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]
'1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.2.el7]`	l- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]T
#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]
AAs	Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check Js#	Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDs	Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}osm	Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjsc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]s1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5+	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]Fs	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
s	Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check ^9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDs	Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}osm	Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjsc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]s1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5 +	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]Fs	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
^!9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]
ww^#7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]!"?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.2.el7]_- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
O%	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]R$	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE
?'?['1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797T&#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b(?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4)c	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J*	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J+	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
,	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
?'?[.1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797T-#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b/?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
40c	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J2	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
3	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
KK/5Y	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|4s	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
`H`[71	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [190179736a	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b8?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
49c	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J:	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J;	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
<	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
KK/>Y	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|=s	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3?a	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
AA:@o	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
KK/BY	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|As	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3Ca	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
4A4E	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.26.1.el7]`~@- selinux: fix deadlock in security_set_bools() (Ondrej Mosnacek) [1939091]
- md: fix md io stats accounting broken (Ming Lei) [1927106]
- redhat: Fix realtime_check for -private (Juri Lelli):Do	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
//G		Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]@F{	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.27.1.el7]`N@- video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (Mohammed Gamal) [1941841]
- Drivers: hv: vmbus: enable VMBus protocol version 5.0 (Mohammed Gamal) [1941841]
- redhat: Add git suffix to realtime_check merge_tree (Juri Lelli)
==>Hw	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
I#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..MJ	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]

er+V:eD
b7d834f2cc5aa84ce95931ece2e31ba36b1622f5cf8408527a2a75727e975348D
572ff1fa3f621ad26e4183404533f0d373eee24c0a12955ab2ab39ca102d691eD
fd8e59feae40f80e38ab4a8de84b96325cd6b29832ce967fca67cb83405b1342D
de7f44e2c7986c23e352486d2894499d26f632330a153b346ea4363cdf0397cbD
dc90a5cca940b1f478ed520e28cd82492738bbb49889b2cd96a4cff2fbc503bcD
c540f6cbef4a78a050fb751882916735d1bd6054d8c177140c200cf31eaf923fD
563fbcd370477439a58af9940298f2c82a2b3a37e487abffaa7f2cc6dc359b31D
adf17c4b2070f73fe44e9fc11648947e83c86d37a4e3532c9d77d3d8e9ae50e5D

179d7e14905a53e3d09515993644464c53e8bf4c10bcd829502d153744fdf666D
a14db656a37e716de6fd51d331dc591f90b663382f88a483d40e8c847e506676D
2c64dd985521f02ada8ac0415b1d852ab79d87ebdf2950e421d8258a4d86d153D

a5f9b329bc1130ffe9bf6f2ced3317e2ad895c4559a82bdf804c8b85e4765b28D	
6ce4b480a292b7fa51c31777377a1711c2537597c5cf02d8aa14b345321b67bf
ttK		Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]
==>Lw	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
M#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..MN	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+P'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}HO	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 
SzS"R?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]Q}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
,,T-	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.2.el7]`A- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]1S]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+V'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}HU	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 
SzS"X?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]W}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
1Y]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
Z	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
[	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2]_	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]\'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\_}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]^9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
"`?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
1a]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
b	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
c	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2e_	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]d'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\h9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"g?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]f9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
i	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
j	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2l_	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]k'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\o9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"n?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]m9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
22Ip
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmq	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348
nns9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]irQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
Yu9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"t?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]
22Iv
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmw	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348
ixQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_y=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7zm	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!|A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7{m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm}	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348
i~Q	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]bRZRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{ŁBƁCǁEȁGɁHʁIˁJ́K΁LρMЁNҁPӁRԁTցVׁX؁YفZځ[ہ]܁_݁`ށa߁bcၻe⁻hほi䁻j偻l恻o灻p遻qꁻs끻u쁻vwxyz|}~
	
!"#$'( )!*"-#.$/%2&3'5(8):*>+@-A.E/F1G2I3L:O<P=R>UDWFXGZH]N^O_PaVcWdXfYg
_=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]
pepp_	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]+	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}
!+	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}n[	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igZ3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error reform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
,n
[	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igZ	3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]p_	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error reform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060}	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<
w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
"Q"s1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]%I	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}
Fs	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]jsc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]
+	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]
P	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol^9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999o	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powte	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command
erpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
33n[	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igX-	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error reform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060}	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
QQ%!I	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609] 	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\"7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT
PP+#U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S$%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
up%'I	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]&	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\(7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT
PP+)U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S*%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM-	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%,I	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}+	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D.	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
((S/%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM2	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%1I	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}0	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
%v%L5	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]4		Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d
8	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]7)	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]6-	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
%v%L:	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]9		Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d&>K	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]<)	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954];-	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
xx@#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]l?W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
TA'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for ,
3^O$3lEW	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&DK	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
C	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]B9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
iiF#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
TG'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 0
G^GI#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]H9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(BL	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]K	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-238254+JU	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}5 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV6E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 7CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [20902278] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}

er+V:eD"
fe01de01f7bcb863a54f276394f9ab097a0d29db56661a42eb33d27e4bef27f8D!
ea590d364a03624b219bdbcff4119983ab7a1bd31a6a7146afb0d4e684761056D 
3fd85597715ed99be96dcdbcfa10bedfcca32a7ad600f9ebf609b83a2c6d481aD
83282159f5c6971ea89b738532ec3620b616c1b9d90ff2a62527714e210cad05D
f2ec86971a1091e0bfe181b4363faea8e87a9b3e3559bb53f97966d8f02e97d2D
a40e6f107134f5d7997968a9ddc2ce1e7beb8cec4d869d04add1181bbf1653fdD
380017b2933fbc2a789cf7c1b00bb0fa298bf6b9cb61d88aaf52bd314eaa1efcD
29653969b83d43fd83befb74a89b5811c1b7b3d613637aa64efa39a1d4b2e76aD
2ac60b8088805d258f480005417e5958a86da93d764c9825c111401402c2b72dD
76b71b906c9f1af8e7860bcf78af0d724ef72c918767fb655b3ac9f2e0e6530bD
fe5bfef21df5d0e8252e7ac8804794d70a0db68230a14972077289f7d05e21e8D
38d054f054325006f87cc688b0f258c342122a6a0a76a8efb07f3c1ff8cd20dcD
a15acb72ee6adfbf7ace3b47300fda1914cad9d22e255326e32d3a93ce032670
MMO#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lNW	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&MK	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
TP'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for ;
G^GR#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]Q9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(BU	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]T	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825?+SU	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}@ CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVAE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 BCVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227C] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
W#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]LV	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
TX'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for E
G^GZ#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]Y9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B]	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]\	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825I+[U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}J CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVKE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 LCVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227M] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
L^	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]
&&U_)	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
a	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825Q`	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}R CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVSE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 TCVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227U] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
hhLc	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]Bb	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
&&Ud)	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
ifQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@g	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7im	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc[h1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
wwLk	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]3je	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
&&Ul)	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
inQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@o	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7qm	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitcap1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
E)E_t=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]s3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3re	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
ivQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]u	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7ym	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitcfx1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
)E}7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_|=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]{3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3ze	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
WW1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]~	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
<e_=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]7m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitci
_TH<w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]
Hd
7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_	=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
((<
w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]
HK}	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tg	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]o
s	Jan Stancek <jstancek@redhat.com> [3.10.0-1152.el7]^- [nvmem] nvmem: properly handle returned value nvmem_reg_read (Vladis Dronos	s!	Jan Stancek <jstancek@redhat.com> [3.10.0-1151.el7]^W@- [netdrv] qede: Fix multicast mac configuration (Michal Schmidt) [1740064]
- [scsi] sd_dif: avoid incorrect ref_tag errors on 4K devices larger than 2TB (Ewan Milne) [1833528]
- [hid] HID: hiddev: do cleanrM	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}up in failure of opening a device (Torez Smith) [1814257] {CVE-2019-19527}
- [hid] HID: hiddev: avoid opening a disconnected device (Torez Smith) [1814257] {CVE-2019-19527}
- [x86] x86: make mul_u64_u64_div_u64() "static inline" (Oleg Nesterov) [1845864]
- [mm] mm: page_isolation: fix potential warning from user (Rafael Aquini) [1845620]
- [s390] s390/mm: correct return value of pmd_pfn (Claudio Imbrenda) [1841106]
- [fs] fs/proc/vmcore.c:mmap_vmcore: skip non-ram pages reported by hypervisors (Lianbo Jiang) [1790799]
- [kernel] kernel/sysctl.c: ignore out-of-range taint bits introduced via kernel.tainted (Rafael Aquini) [1845356]
- [documentation] kernel: add panic_on_taint (Rafael Aquini) [1845356]
- [fs] ext4: Remove unwanted ext4_bread() from ext4_quota_write() (Lukas Czerner) [1845379]
- [scsi] scsi: sg: add sg_remove_request in sg_write ("Ewan D. Milne") [1840699] {CVE-2020-12770}
- [fs] fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (Donghai Qiao) [1832062] {CVE-2020-10732}tv) [1844409]
- [mailbox] PCC: fix dereference of ERR_PTR (Vladis Dronov) [1844409]
- [kernel] futex: Unlock hb->lock in futex_wait_requeue_pi() error path (Vladis Dronov) [1844409]
- [fs] aio: fix inconsistent ring state (Jeff Moyer) [1845326]
- [vfio] vfio/mdev: make create attribute static (Vladis Dronov) [1837549]
- [vfio] treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Synchronize device create/remove with parent removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid creating sysfs remove file on stale device removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Improve the create/remove sequence (Vladis Dronov) [1837549]
- [vfio] treewide: Add SPDX license identifier - Makefile/Kconfig (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid inline get and put parent helpers (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Fix aborting mdev child device removal if one fails (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Follow correct remove sequence (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid masking error code to EBUSY (Vladis Dronov) [1837549]
- [include] vfio/mdev: Drop redundant extern for exported symbols (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Removed unused kref (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid release parent reference during error path (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Add iommu related member in mdev_device (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: add static modifier to add_mdev_supported_type (Vladis Dronov) [1837549]
- [vfio] vfio: mdev: make a couple of functions and structure vfio_mdev_driver static (Vladis Dronov) [1837549]
- [char] tpm/tpm_tis: Free IRQ if probing fails (David Arcari) [1774698]
- [kernel] audit: fix a memleak caused by auditing load module (Richard Guy Briggs) [1843370]
- [kernel] audit: fix potential null dereference 'context->module.name' (Richard Guy Briggs) [1843370]
- [nvme] nvme: limit number of IO queues on Dell/Samsung config (David Milburn) [1837617]
AAs	Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check vJs#	Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDs	Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}osm	Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjsc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]s1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
h5)h<w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]Fs	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
HK }	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t"g	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i!Q	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]{
-$W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
<<K'}	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]&9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t)g	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i(Q	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
-+W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M*	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
-9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L,	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
1/1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fJ.	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<M1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}?0{	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
NL3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}-2W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]
61	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fJ5	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)49	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<<?7{	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
d8E	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
p,p7:k	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]O9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
P<	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol^;9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999>o	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powt=e	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commanderpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
yy@7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: HanX?-	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
fAI	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
ooB	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
oCY	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


qD]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{\k]l^n_o`qbtcvdweyg}hjkl
m
npquwxyz |"}$~')+-/13678:<>@ABCDEHKNQRTVY[]_bcdefgijlnpsuwy|~ÁāŁ	ǁ
ȁʁ
ˁ́́ρЁсӁԁՁց؁فځہ܁ 
dEE	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
o,po|Hu	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]7Gk	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]OF	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Y}Kw	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]BJ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"IA	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]
  ?N{	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.2.el7]ef@- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}4Me	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^L9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}

er+V:eD/
12eb69ce3ab02b67fd35247a607d73a70b5c657c3703598db21a9ebe26e45a42D.
39ce1d8d6ffa3efde898b475b2be150a92edca9d2aadf7ed8d5d69e6865175f9D-
22e7b5d6e46a23025f394d1dd9e25e4e5cfd1c5dbb00f74226f20929ee065bd9D,
1cd93bcccbab328b508e869ff3ceeaa30e1ab5ac781b7a6c3b91207832226025D+
315bb4f6a8cd60a7becf60b599198a41a19465d28cc706d98dfa3b927f357dadD*
404156845f116a61c9627f44cc1b924461c60e723c92dd3a152f2840e6e9003aD)
8764032443efee4dc7bfb0ee1a11749205880cd86b230ad538346b697120c5e7D(
b918eb715248bdb46d8f49387310a25030a9f4fe192d5ee0f69fabde9b84d42dD'
528d0642b5b6549b3084ad519bbeef6aa4048aa69d52903acce6a22132ac9303D&
97708bdbb05e028158319a2bcc0079feb219bc2cbe8d1b3c5b3861d43afd818fD%
3d08be30af99cb4e2248e149d75d36071c2dfd0806f511abe5c972b4051fe7d7D$
4d66ddd3b79ce560d9eab146d518f751de7e9ef4d667fa701a868a978f1342cbD#
211028daa1af91e1fc841cb5b76e2f4edf63f510630571253c89635fccd41209
XBQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"PA	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]|Ou	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]
}Rw	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]
4Te	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^S9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bVA	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~Uy	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
%n%"YA	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]X7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens
}[w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]BZ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}
4]e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^\9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
b_A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~^y	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
n+b	M	Radomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]a7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]`	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ensdle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
c7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han
fdI	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
ooe	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
ofY	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


qg]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
--Ri	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE^h7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
,,Oj	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]
'l1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.2.el7]`	l- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]Tk#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]
AAns	Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check Jms#	Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDps	Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}oosm	Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjssc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]rs1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []qs7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5u+	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]Fts	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
ws	Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check ^v9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDys	Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}oxsm	Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbj|sc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]{s1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []zs7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5~+	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]F}s	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
^9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]
ww^7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]!?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.2.el7]_- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
O	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]R	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE
?'?[1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797T#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4c	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J		Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]

	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
?'?[1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797ɅT#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b
?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4c	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
KK/Y	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|s	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
`H`[1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797҃3a	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4c	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
KK/Y	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|s	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3a	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
AA:o	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
KK/ Y	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|s	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3!a	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
4A4#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.26.1.el7]`~@- selinux: fix deadlock in security_set_bools() (Ondrej Mosnacek) [1939091]
- md: fix md io stats accounting broken (Ming Lei) [1927106]
- redhat: Fix realtime_check for -private (Juri Lelli):"o	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
//%		Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]@${	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.27.1.el7]`N@- video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (Mohammed Gamal) [1941841]
- Drivers: hv: vmbus: enable VMBus protocol version 5.0 (Mohammed Gamal) [1941841]
- redhat: Add git suffix to realtime_check merge_tree (Juri Lelli)
==>&w	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
'#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M(	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]
tt)		Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]
==>*w	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
+#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M,	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+.'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}H-	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 
SzS"0?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]/}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
,,2-	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.2.el7]`A- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]11]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+4'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}H3	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 
SzS"6?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]5}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
17]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
8	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2;_	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]:'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\=}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]<9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
">?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
1?]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
@	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
A	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2C_	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]B'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\F9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"E?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]D9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
G	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
H	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2J_	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]I'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\M9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"L?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]K9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
22IN
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmO	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348
nnQ9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]iPQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]

er+V:eD<
eeb0ed8d5fd30d98e3bef225ead945fafb2e3dbd8cea8e4b45565671473073d7D;
2111718d7572c52cddb1070151dd723808174e0f46528dd636ee9dd3afc41523D:
fe35603b7abe8e1540b93b5c81f16503aa0704fb2bffed7d863b738cf0cf67b4D9
3f9a0f21e2acc0ae5b83814ce830b1a500157b9c6b68efd957007ce368622288D8
1b481cd6a6df8a141bc7064b72ffee022095969d0a25a8b9a57bfdc1ec3af7beD7
a895efeb08422b537678146fb9329ca6a9b3238f9291a15d091a5a70273cfab3D6
c6b55809244b010e1d1dc344b9add936f4598f2be100373d25749f6d2da8522dD5
dbbb88d9eb3b101dd3369a46793946b7cefc449cb1c00dab5affc0a3c6adfad7D4
0a755493662be885a9d421b00ff08001a5d61a085bb86846d60072222530e672D3
03c6e9f83275661d1eb892af76411bc871b3f442dc65c95ad96dadbaffe84cf7D2
aa2c7472ee44f9db48646789dbda352a7399c0d9f9e2644db03345bfbf705395D1
6817bc65309730ab6a1f49ab977c2ea11a9cb5a2f623376008276eeda89f41daD0
2e997f7e17c861373d0fa5737eaf371bb9187d5db73e8c89cb03ef342029cfaa
YS9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"R?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]
22IT
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmU	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348
iVQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_W=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7Xm	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!ZA	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7Ym	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm[	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348

i\Q	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_]=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7^m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]bRsRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{ށ#߁%&ၾ'⁾(ま)䁾*偾+恾,聾.遾0ꁾ2쁾4큾6789;=>?@ACFGHJMNOQSTUVWX	Z[\
]^`behjlp r!s"u%w'y,{.}/12346789:;
<=>?@ABDE#F$H%I'J*P-R.S0T3Z5\6]8^;d<e=f?lAmBnDoEpGrI
!`A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7_m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]
peppb_	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]a+	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}
!e+	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}nd[	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igZc3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error reform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
,nh[	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igZg3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]pf_	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error reform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
j	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060i}	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?l	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<kw	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
"Q"ps1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []os7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]%nI	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}
Frs	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]jqsc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]
s+	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]
Pu	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol#^t9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999wo	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] pow&tve	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command$erpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
33ny[	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig(Xx-	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352})et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush *if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r+eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
{	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060-z}	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?}	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<|w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
QQ%I	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]~	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT0
PP+U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
up%I	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT5
PP+U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%
I	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}		Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
((S
%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%I	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
%v%L	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]		Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000])	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]-	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
%v%L	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]		Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d&K	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000])	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]-	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
xx#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lW	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for C
3^O$3l#W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&"K	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
!	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000] 9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
ii$#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T%'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for G
G^G'#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]&9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B*	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856])	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825K+(U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}L CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVME-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 NCVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227O] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
MM-#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]l,W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&+K	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T.'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for Q
G^G0#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]/9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]2	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825U+1U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}V CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVWE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 XCVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227Y] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
5#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]L4	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T6'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for [
G^G8#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]79	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B;	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]:	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825_+9U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}` CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVaE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 bCVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227c] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
L<	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]
&&U=)	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
?	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825g>	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}h CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CViE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 jCVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227k] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
hhLA	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]B@	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
&&UB)	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
iDQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]C	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@E	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7Gm	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitcqF1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
wwLI	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]3He	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
&&UJ)	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
iLQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]K	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@M	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7Om	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitcwN1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
E)E_R=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]Q3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3Pe	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]

er+V:eDI
6cfb6bf58c05c3d5623f5406c5e146a76aced8a97fef4153ef7d295cc5776298DH
d093869ed5878283193de6a764e7847674976671131c829603d9981e56660bfbDG
bf08078851ef715022279479446f3e390e30bd92cb15b2aed42318fb677e40a0DF
aed30d0de3bf0d71c9c9be43e3e4b5e8d6832a7e755e8cfd843a6bd7f735d310DE
cfde4230671763bf6a464de9ec8c191195c9ae864571afd92bc7bea8dfcbb11eDD
e3d2e5a0802cde0d09552d1bd3102383e1851a9aecf88fd83a5fb81baae6d53cDC
e357af06726c5602fad5542ef0502f94391737c732c9fbf6706f80fb6757f197DB
0eec836c027a565c281645294b192571bfe852631d94438627371cba58c380deDA
7eee4abf22678a8043377d3ff29621b20a1dbe6da04bb0918068ef07eacf23e7D@
ef3258341d0c757014a17a4cc94207f623282b6190b470f1517c29d8bb42218fD?
a663038e5d2fe0f26775744ace593a48c274a77a69c51d4592701ea604272ae1D>
610253d61d946788184230adb18227e8e92b245a2c2244a5d929b1b096fe7faaD=
3668549b1c43bc2b0dd420108f4ebcc8bff57ef08d4b839f3f8e6f9c4691f314
iTQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]S	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7Wm	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc}V1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
)E[7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_Z=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]Y3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3Xe	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
WW]1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]\	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
<e_a=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]`3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3_e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]7^m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc
_TH<ew	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}d
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]c	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]b7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]
Hdh7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_g=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3fe	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
((<kw	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}j
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]i	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]
HKm}	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3le	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tog	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]inQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
rs	Jan Stancek <jstancek@redhat.com> [3.10.0-1152.el7]^- [nvmem] nvmem: properly handle returned value nvmem_reg_read (Vladis Drono	qs!	Jan Stancek <jstancek@redhat.com> [3.10.0-1151.el7]^W@- [netdrv] qede: Fix multicast mac configuration (Michal Schmidt) [1740064]
- [scsi] sd_dif: avoid incorrect ref_tag errors on 4K devices larger than 2TB (Ewan Milne) [1833528]
- [hid] HID: hiddev: do cleanMp	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}up in failure of opening a device (Torez Smith) [1814257] {CVE-2019-19527}
- [hid] HID: hiddev: avoid opening a disconnected device (Torez Smith) [1814257] {CVE-2019-19527}
- [x86] x86: make mul_u64_u64_div_u64() "static inline" (Oleg Nesterov) [1845864]
- [mm] mm: page_isolation: fix potential warning from user (Rafael Aquini) [1845620]
- [s390] s390/mm: correct return value of pmd_pfn (Claudio Imbrenda) [1841106]
- [fs] fs/proc/vmcore.c:mmap_vmcore: skip non-ram pages reported by hypervisors (Lianbo Jiang) [1790799]
- [kernel] kernel/sysctl.c: ignore out-of-range taint bits introduced via kernel.tainted (Rafael Aquini) [1845356]
- [documentation] kernel: add panic_on_taint (Rafael Aquini) [1845356]
- [fs] ext4: Remove unwanted ext4_bread() from ext4_quota_write() (Lukas Czerner) [1845379]
- [scsi] scsi: sg: add sg_remove_request in sg_write ("Ewan D. Milne") [1840699] {CVE-2020-12770}
- [fs] fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (Donghai Qiao) [1832062] {CVE-2020-10732}v) [1844409]
- [mailbox] PCC: fix dereference of ERR_PTR (Vladis Dronov) [1844409]
- [kernel] futex: Unlock hb->lock in futex_wait_requeue_pi() error path (Vladis Dronov) [1844409]
- [fs] aio: fix inconsistent ring state (Jeff Moyer) [1845326]
- [vfio] vfio/mdev: make create attribute static (Vladis Dronov) [1837549]
- [vfio] treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Synchronize device create/remove with parent removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid creating sysfs remove file on stale device removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Improve the create/remove sequence (Vladis Dronov) [1837549]
- [vfio] treewide: Add SPDX license identifier - Makefile/Kconfig (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid inline get and put parent helpers (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Fix aborting mdev child device removal if one fails (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Follow correct remove sequence (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid masking error code to EBUSY (Vladis Dronov) [1837549]
- [include] vfio/mdev: Drop redundant extern for exported symbols (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Removed unused kref (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid release parent reference during error path (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Add iommu related member in mdev_device (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: add static modifier to add_mdev_supported_type (Vladis Dronov) [1837549]
- [vfio] vfio: mdev: make a couple of functions and structure vfio_mdev_driver static (Vladis Dronov) [1837549]
- [char] tpm/tpm_tis: Free IRQ if probing fails (David Arcari) [1774698]
- [kernel] audit: fix a memleak caused by auditing load module (Richard Guy Briggs) [1843370]
- [kernel] audit: fix potential null dereference 'context->module.name' (Richard Guy Briggs) [1843370]
- [nvme] nvme: limit number of IO queues on Dell/Samsung config (David Milburn) [1837617]
AAts	Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check Jss#	Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDvs	Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}ousm	Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjysc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]xs1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []ws7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
h5)h<|w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}{
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]Fzs	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
HK~}	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3}e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tg	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
-W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
<<K}	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tg	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
-	W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
1
1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fJ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<M	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}?{	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
NL	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}-W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]
1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fJ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<<?{	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
dE	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
p,p7k	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]O	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
P	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol^9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999o	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powte	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commanderpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
yy7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: HanX-	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
fI	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo 	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
o!Y	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q"]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
d#E	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
o,po|&u	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]7%k	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]O$	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{tLuMvOxRzT{U|W~[]aehkmortvy|~	
 !"#&),/02479;=@ABCDÁEāGƁHǁJȁLʁNˁQ́ŚUЁWсZҁ\Ӂ]ԁ_ցaׁcفdځeہf܁gށh߁jklmnoqstuvwxz{|~
Y})w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B(	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"'A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]
  ?,{	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.2.el7]ef@- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}4+e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^*9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
XB/	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}".A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]|-u	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]
}0w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]
42e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^19	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
b4A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~3y	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
%n%"7A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]67	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]5	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens
}9w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B8	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}
4;e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^:9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
b=A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~<y	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
n+@	M	Radomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]?7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]>	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ensdle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
A7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han
fBI	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
ooC	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
oDY	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


qE]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
--RG	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PEń^F7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
,,OH	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]
'J1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.2.el7]`	l- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]TI#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]
AALs	Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check ɆJKs#	Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDNs	Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}oMsm	Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjQsc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]Ps1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []Os7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5S+	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]FRs	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
Us	Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check υ^T9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]

er+V:eDV
66af09f68408482637e668b90619392a27fa21b7d4ed06f3c3cbc60d87ce1d78DU
c9c2a62c7fb170cc9007afb571d8b9beab632b42aaef2f1461f8ba0a2c5f6d9aDT
619978f4cd3319fc56335a010d227ac9446de3fe27758ad4f22319183b1a35bbDS
e1d60b061557e368c20da15e4517376a49df65648636bd09fa3baa81f162391dDR
2c612e423c3e3ace2108965f2996ecb1002eee8415cdce8e05c58aafa5f37306DQ
f066c4d77c32004d1843615beab2f59dce9664e5e79aaf6f5453d44d0d9e02feDP
72dc266e5da09e38d19f4c3904bdb983146af68adbe466120ff8bfecdb4567bfDO
5ec120d1c66453ab1a85e5107b0b4457686f595cf2e8dfc5ca04adcec4f0ade0DN
7d9fd10906d65ff1e5f7dc8aed453f9fa04ddb34ca3a6622b45b15bbf2b7dc66DM
ea73cbefe91a8c86fea9a227d19b9f36d68daa5f9e640d6d6acf7a6ad65c4297DL
e2b80fc90e80e10166a785ab1c718ed12380055d955ab295c5363ad6405fe815DK
3f77e8c91079e010fb161e28eaf613452e1c25d2d67b0367cb344f3141bf3cb9DJ
1a74fcb33103de74d5129a6eea3fe37137b7cbdc136b11a49f79822b8fbd6194to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDWs	Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}oVsm	Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjZsc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]Ys1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []Xs7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5\+	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]F[s	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
^]9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]
ww^_7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]!^?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.2.el7]_- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
Oa	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]R`	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE
?'?[c1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797؅Tb#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bd?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4ec	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11Jf	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11Jg	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
h	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
?'?[j1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797Ti#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bk?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4lc	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11Jm	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11Jn	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
o	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
KK/qY	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|ps	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
`H`[s1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [19017973ra	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bt?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4uc	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11Jv	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11Jw	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
x	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
KK/zY	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|ys	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3{a	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
AA:|o	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
KK/~Y	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|}s	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3a	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
4A4	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.26.1.el7]`~@- selinux: fix deadlock in security_set_bools() (Ondrej Mosnacek) [1939091]
- md: fix md io stats accounting broken (Ming Lei) [1927106]
- redhat: Fix realtime_check for -private (Juri Lelli):o	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
//		Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]@{	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.27.1.el7]`N@- video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (Mohammed Gamal) [1941841]
- Drivers: hv: vmbus: enable VMBus protocol version 5.0 (Mohammed Gamal) [1941841]
- redhat: Add git suffix to realtime_check merge_tree (Juri Lelli)
==>w	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]
tt		Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]
==>w	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
	#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}H	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 
SzS"?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
,,-	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.2.el7]`A- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]1]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}H	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 
SzS"?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
1]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2_	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
"?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
1]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2!_	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499] '	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\$9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"#?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]"9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
%	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
&	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2(_	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]''	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\+9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"*?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418])9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
22I,
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm-	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348
nn/9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]i.Q	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
Y19	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"0?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]
22I2
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348
i4Q	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_5=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD76m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!8A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]77m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348 
i:Q	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_;=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7<m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!>A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7=m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]
pepp@_	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]?+	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{	
	

!$%&(+,-/1234568!9":#;$<%>&@(C-F2H4J5N6P7Q8S;U=WCYE[F]H^I_J`KcMdNeOfPiQjRkSnToUqVtWvXzY|[}\]_`agijkqstu{|} "#%'(*
!C+	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}nB[	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig)ZA3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]*et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush +if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r,eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
,nF[	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig.ZE3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]pD_	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]/et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush 0if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r1eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
H	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030603G}	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?J	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<Iw	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
"Q"Ns1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []Ms7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]%LI	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]K	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}
FPs	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]jOsc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]
Q+	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]
PS	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol9^R9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999Uo	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] pow<tTe	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command:erpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
33nW[	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig?XV-	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}

er+V:eDc
8c51f1c38ad47d554e10f738e37c0bf122f76f4859f755e0449895448111fdfbDb
618bc94e003b50654a567449109303c221bd56c7f188de529a8d1ab1d8e20fd8Da
90add33a3f4cc834b9be91c4ccc12114abeee16aab262829030db0c9ce27fafeD`
61cfa80ff521cdee2ca184780c2e8e55454cba77894c18944b233eb145b6c262D_
8cd2d58f528256baddd73bebea799773f83bd54624d090696d0c2ca0cac8656dD^
9c8552ce4b79fef3a8e7b55a85b91bd83e2f2765635056bc7064ab7d071c6e1aD]
f5394565fcf1a20382bcdd1f64e77e587e222a4e135860c31a6a2b4f012e4691D\
f0308f6cab8d1b2a831f455e5c9950062be00908841b0a04d0555377c61e49caD[
c4dd18d9c01ea40a453a4a345bdb13d9ca5f3315e69e78ce7e1f9798972a5d47DZ
a219dbccfdca9ac57c9b9064dffadc0044870709a425252ba874f86cfa15084cDY
bae6332ef212f5e4fe0b1eada2f87ebde9f8d0ae3bc2bf1231463bddc7837af2DX
5b152b26c3cb00751f5faf6a0e5bf8cffab7cb953c9a7a44d5c064beadb2c64bDW
5b75d2143ffe291c5183924ee30ab08ceb34c6da47f540b55f39025c5123e419@et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush Aif write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error rBeform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
Y	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060DX}	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?[	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<Zw	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
QQ%]I	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]\	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\^7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUTG
PP+_U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S`%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
up%cI	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]b	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}a	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\d7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUTL
PP+eU	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((Sf%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpMi	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%hI	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}g	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77Dj	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
((Sk%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpMn	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%mI	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}l	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77Do	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
%v%Lq	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]p		Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d
t	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]s)	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]r-	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
%v%Lv	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]u		Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d&zK	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
y	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]x)	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]w-	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
xx|#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]l{W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T}'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for Z
3^O$3lW	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&K	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]~9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
ii#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for ^
G^G#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825b+U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}c CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVdE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 eCVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227f] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
MM#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]l
W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&	K	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for h
G^G#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]
9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825l+U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}m CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVnE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 oCVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227p] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]L	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for r
G^G#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825v+U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}w CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVxE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 yCVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227z] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
L	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]
&&U)	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825~	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
hhL	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]B	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
&&U )	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
i"Q	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]!	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7%m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc$1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
wwL'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]3&e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
&&U()	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
i*Q	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243])	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@+	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7-m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc,1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
E)E_0=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]/3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3.e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
i2Q	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b75m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc41	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
)E97	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_8=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]73	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}36e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
WW;1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]:	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
<e_?=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]>3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3=e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]7<m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc
_TH<Cw	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}B
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]@7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]
HdF7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_E=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3De	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
((<Iw	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}H
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]G	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]
HKK}	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3Je	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tMg	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iLQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
Ps	Jan Stancek <jstancek@redhat.com> [3.10.0-1152.el7]^- [nvmem] nvmem: properly handle returned value nvmem_reg_read (Vladis Drono	Os!	Jan Stancek <jstancek@redhat.com> [3.10.0-1151.el7]^W@- [netdrv] qede: Fix multicast mac configuration (Michal Schmidt) [1740064]
- [scsi] sd_dif: avoid incorrect ref_tag errors on 4K devices larger than 2TB (Ewan Milne) [1833528]
- [hid] HID: hiddev: do cleanMN	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}up in failure of opening a device (Torez Smith) [1814257] {CVE-2019-19527}
- [hid] HID: hiddev: avoid opening a disconnected device (Torez Smith) [1814257] {CVE-2019-19527}
- [x86] x86: make mul_u64_u64_div_u64() "static inline" (Oleg Nesterov) [1845864]
- [mm] mm: page_isolation: fix potential warning from user (Rafael Aquini) [1845620]
- [s390] s390/mm: correct return value of pmd_pfn (Claudio Imbrenda) [1841106]
- [fs] fs/proc/vmcore.c:mmap_vmcore: skip non-ram pages reported by hypervisors (Lianbo Jiang) [1790799]
- [kernel] kernel/sysctl.c: ignore out-of-range taint bits introduced via kernel.tainted (Rafael Aquini) [1845356]
- [documentation] kernel: add panic_on_taint (Rafael Aquini) [1845356]
- [fs] ext4: Remove unwanted ext4_bread() from ext4_quota_write() (Lukas Czerner) [1845379]
- [scsi] scsi: sg: add sg_remove_request in sg_write ("Ewan D. Milne") [1840699] {CVE-2020-12770}
- [fs] fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (Donghai Qiao) [1832062] {CVE-2020-10732}v) [1844409]
- [mailbox] PCC: fix dereference of ERR_PTR (Vladis Dronov) [1844409]
- [kernel] futex: Unlock hb->lock in futex_wait_requeue_pi() error path (Vladis Dronov) [1844409]
- [fs] aio: fix inconsistent ring state (Jeff Moyer) [1845326]
- [vfio] vfio/mdev: make create attribute static (Vladis Dronov) [1837549]
- [vfio] treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Synchronize device create/remove with parent removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid creating sysfs remove file on stale device removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Improve the create/remove sequence (Vladis Dronov) [1837549]
- [vfio] treewide: Add SPDX license identifier - Makefile/Kconfig (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid inline get and put parent helpers (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Fix aborting mdev child device removal if one fails (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Follow correct remove sequence (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid masking error code to EBUSY (Vladis Dronov) [1837549]
- [include] vfio/mdev: Drop redundant extern for exported symbols (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Removed unused kref (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid release parent reference during error path (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Add iommu related member in mdev_device (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: add static modifier to add_mdev_supported_type (Vladis Dronov) [1837549]
- [vfio] vfio: mdev: make a couple of functions and structure vfio_mdev_driver static (Vladis Dronov) [1837549]
- [char] tpm/tpm_tis: Free IRQ if probing fails (David Arcari) [1774698]
- [kernel] audit: fix a memleak caused by auditing load module (Richard Guy Briggs) [1843370]
- [kernel] audit: fix potential null dereference 'context->module.name' (Richard Guy Briggs) [1843370]
- [nvme] nvme: limit number of IO queues on Dell/Samsung config (David Milburn) [1837617]
AARs	Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check JQs#	Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDTs	Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}oSsm	Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjWsc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]Vs1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []Us7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
h5)h<Zw	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}Y
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]FXs	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]

er+V:eDp
ad7bce9b915192b7b549afd2ed6063d2ada93cb004d25d42dc82dd3313d82a37Do
52fc84afa30b500c79c2116a67a199c3eba6bbed1b7b171fc4fec483dc2c9f4cDn
4abf0ebc2127e7a5b5dfb595fa447cb44f339ff023ce88bb0a97992bba4cd3a9Dm
961c48cd798bb2acb18bcb4bd7ebd24f8752f021a87363745131dc5e83535165Dl
cd7d87fbf38e3d491a5a8b262d70dddd01ac00ec722b52c01b44e67f7d8c5a66Dk
e7e90b3e6ae85deb749d4071a5467a5a718a12808213ecd6657a9d70d12129ceDj
b1985dc9a05a3ffe2eac12dd0ba63fc7285e6ca29af03c0351ff2b6bcbd39822Di
c20dbccc7c4cc73173c89b3632eb2dbf33e22faaaf1b317279ecad8e2b1fe49bDh
74dfc146e5e4ab219dba838033e3a2a983e2ad796cee5a175fda1b6c17653193Dg
c59ce9d5e2b28c278b947391fce0c591d912b04727d6141c27262cf98fb99844Df
a2341873756b6756d7b18967c3dd2b6ce12fff550f0837ea9361171291c42397De
c4bc426d70f27932111cdba1edd2eb69526aef608fccde2da51a6282a479270cDd
6cf85cafbf0ed8b58696a680262f819d5ebbe64f5d4ce8010a037a47a9f1ae9f
HK\}	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3[e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t^g	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i]Q	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
-`W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M_	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
<<Kc}	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]b9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]La	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

teg	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]idQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
-gW	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]Mf	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
i9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]Lh	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
1k1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fJj	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<Mm	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}?l{	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
NLo	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}-nW	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]
r1	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fJq	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)p9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<<?s{	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
dtE	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
p,p7vk	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]Ou	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Px	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol^w9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999zo	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powtye	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commanderpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
yy|7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: HanX{-	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
f}I	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo~	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
oY	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
dE	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
o,po|u	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]7k	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]O	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Y}w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]
  ?
{	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.2.el7]ef@- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}4	e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{-02359;?CFIKMPRTWZ\^`cegikmorstvxz|}~ÁāŁƁǁȁ
ʁ
ˁ́́ρЁсҁԁցׁ ؁!ف"ځ#ہ%݁&ށ(߁*,/1358:;=?ABCDEFHIJKLMOQRSTUVXYZ
\]_
ab
XB
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]|u	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]
}w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]
4e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bA	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~y	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
%n%"A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens
}w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}
4e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bA	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~y	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
n+	M	Radomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ensdle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han
f I	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo!	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
o"Y	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q#]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
--R%	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE܄^$7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
,,O&	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]
'(1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.2.el7]`	l- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]T'#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]
AA*s	Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check J)s#	Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCD,s	Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o+sm	Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbj/sc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840].s1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []-s7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
51+	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]F0s	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
3s	Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check ^29	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCD5s	Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o4sm	Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbj8sc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]7s1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []6s7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5:+	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]F9s	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
^;9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]
ww^=7	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]!<?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.2.el7]_- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
O?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]R>	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE
?'?[A1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797T@#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bB?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4Cc	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11JD	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11JE	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
F	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
?'?[H1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797TG#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bI?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4Jc	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11JK	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11JL	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
M	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
KK/OY	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|Ns	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
`H`[Q1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [19017973Pa	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bR?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4Sc	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11JT	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11JU	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
V	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
KK/XY	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|Ws	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3Ya	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
AA:Zo	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]

er+V:eD}
d41b5d8b6192712bf36a8ca2a106db94ce0b4451ac3b212fd91ab7cb0ed75e82D|
9b3822948ac2fa18132b7f9d9a7d2a194615f396f5dc14dd0ecaa0ee2975470eD{
6ba3e0dd497e559f7b44eabac8136c12499febdb7526dbf3ba89a7b3627aed84Dz
376c21e2589fa7b033d3dbd7673defdb1d5e23c6ad32b112bddd31ae3915a582Dy
17401dca64ff03c547fb51c7e83d60963cc03409dbba4804272853959d2b9a21Dx
7e0b3e536d03b5890007813734653bd6fbc40e2af79d298e9448d84e81ea4734Dw
d2642493abe4c602af8bd00a8d0954219b93cb84fabd9870230cad39d45b9ee7Dv
b31602d66dc65e0bd7a5dac4f9770030528982795cfb1eb49b0cc1eea4786f27Du
3398d3a8a0f8d7273ef408e2922e3b985aab4a0398a30203ce247637331432d5Dt
07505d8e7877d8a5114d6db605a9dc9c2132c0d32d978e2df599fa2e69887780Ds
e888a6e4abc3928d95ec0b18f8a42febb63ba70ba0371c23615b8823209d9317Dr
ba5a53ea9bd2aff2765fd9fc38a3f75ecd5d3e617e1c2cb85f6a9a793063506cDq
506818895cd30b93e3417b8379f3afc7f80a2a69c7739886bc58648f153fb9e6
KK/\Y	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|[s	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3]a	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
4A4_	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.26.1.el7]`~@- selinux: fix deadlock in security_set_bools() (Ondrej Mosnacek) [1939091]
- md: fix md io stats accounting broken (Ming Lei) [1927106]
- redhat: Fix realtime_check for -private (Juri Lelli):^o	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
//a		Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]@`{	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.27.1.el7]`N@- video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (Mohammed Gamal) [1941841]
- Drivers: hv: vmbus: enable VMBus protocol version 5.0 (Mohammed Gamal) [1941841]
- redhat: Add git suffix to realtime_check merge_tree (Juri Lelli)
==>bw	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
c#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..Md	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]
tte		Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]
==>fw	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
g#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..Mh	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+j'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}Hi	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 
SzS"l?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]k}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
,,n-	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.2.el7]`A- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]1m]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+p'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}Ho	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 
SzS"r?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]q}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
1s]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
t	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
u	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2w_	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]v'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\y}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]x9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
"z?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
1{]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
|	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2_	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]~'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2_	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\	9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
22I

	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348,
nn
9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]iQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
Y9	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]
22I
	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [183481
iQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [183487
iQ	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_=	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!A	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7m	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]
pepp_	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]+	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}
!!+	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}n [	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig?Z3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]@et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush Aif write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error rBeform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
,n$[	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igEZ#3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]p"_	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{defghjlnprstuw y!z"{#|$}%&'()*	+
-.
/02345689:;<=>!C$I&K(L,M.N/O1R3T5Y7[9\;^<_=`>aAcBdCeDfGgHhIiLjMkOlRmTnXoZq[r_t`vawcxf~ijloqrtwxy{}~	Fet() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush Gif write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error rHeform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
&	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060J%}	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?(	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<'w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
"Q",s1	Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []+s7	Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]%*I	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609])	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}
F.s	Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]j-sc	Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]
/+	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]
P1	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_holP^09	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
9993o	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powSt2e	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commandQerpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
33n5[	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igUX4-	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}Vet() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush Wif write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error rXeform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060Z6}	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<8w	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
QQ%;I	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]:	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\<7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT]
PP+=U	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S>%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
up%AI	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]@	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}?	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\B7	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUTb
PP+CU	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((SD%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpMG	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%FI	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}E	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77DH	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
((SI%	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpML	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%KI	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}J	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77DM	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
%v%LO	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]N		Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d
R	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]Q)	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]P-	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
%v%LT	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]S		Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d&XK	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]V)	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]U-	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
xxZ#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lYW	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T['	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for p
3^O$3l_W	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&^K	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
]	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]\9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]

er+V:eD

81b2e85bd83c8dc868290121adb4b8821c2da304dd04a69ec5ea65031c46d351D	
2041fb62286ddc1875cdc0396db816edd188bd1beeb362b3e99a3166a7bf8179D
d209fc6a50302b35ffe0a948bce5c2b144f66af599a404ffd4a6771e24896130D
ab17047e6cd355e0a693ee5bd8cca6e51616257233f9e4991c609933559e5831D
361435b0149d64bce7ddd96522893346319af483ba71ff2f7d32c353614b224fD
4b1e28830cdeb09548b5fed9c3021450437dcf28952e709628dd86397bf78af4D
95328dc6ff974a63f71a020d2f75e367ec10635e3db3ece1c6894c07d22f40cdD
73b613dd48f531b02ef3e8b042c6bb5fa7f517faeedbd0883ebda2f46aca3135D
2a085ac87e43c3c43e031cb33170bfabf4fbeea917c6492d513aab56393104b5D
e73e80ff6eb4ad13c6cbb061fbc0b000631cf8e49449db648db76556adee995eD
5cf93be19fa91922ddc7ba9806b15e6fe9b422f89ed4b63465373a0a29b17e95D
39d478d2186cad86df1a7e0bcfb9ec33d5205653c9b51f111a67f541511da671D~
89fc26f9b9704d242bcd1974e846283609f11bf4dc47d614efae548b2b836ec9
ii`#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
Ta'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for u
G^Gc#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]b9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(Bf	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]e	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825y+dU	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}z CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV{E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 |CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227}] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
MMi#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lhW	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&gK	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
Tj'	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
G^Gl#	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]k9	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(Bo	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]n	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825+mU	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
q#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]Lp	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
Tr'
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
G^Gt#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]s9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(Bw
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]v
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825+uU
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
Lx
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]
&&Uy)
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
{
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825z
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
hhL}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]B|
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
&&U~)
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
iQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7m
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
wwL
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]3e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
&&U)
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
iQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@	
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7m
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc
1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
E)E_=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]
3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
iQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7m
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
)E7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
WW1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
<e_=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]7m
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc
_TH<!w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233} 
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]
Hd$7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_#=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3"e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
((<'w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}&
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]%
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]
HK)}
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3(e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t+g
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i*Q
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
.s
Jan Stancek <jstancek@redhat.com> [3.10.0-1152.el7]^- [nvmem] nvmem: properly handle returned value nvmem_reg_read (Vladis Drono	-s!
Jan Stancek <jstancek@redhat.com> [3.10.0-1151.el7]^W@- [netdrv] qede: Fix multicast mac configuration (Michal Schmidt) [1740064]
- [scsi] sd_dif: avoid incorrect ref_tag errors on 4K devices larger than 2TB (Ewan Milne) [1833528]
- [hid] HID: hiddev: do cleanM,
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}up in failure of opening a device (Torez Smith) [1814257] {CVE-2019-19527}
- [hid] HID: hiddev: avoid opening a disconnected device (Torez Smith) [1814257] {CVE-2019-19527}
- [x86] x86: make mul_u64_u64_div_u64() "static inline" (Oleg Nesterov) [1845864]
- [mm] mm: page_isolation: fix potential warning from user (Rafael Aquini) [1845620]
- [s390] s390/mm: correct return value of pmd_pfn (Claudio Imbrenda) [1841106]
- [fs] fs/proc/vmcore.c:mmap_vmcore: skip non-ram pages reported by hypervisors (Lianbo Jiang) [1790799]
- [kernel] kernel/sysctl.c: ignore out-of-range taint bits introduced via kernel.tainted (Rafael Aquini) [1845356]
- [documentation] kernel: add panic_on_taint (Rafael Aquini) [1845356]
- [fs] ext4: Remove unwanted ext4_bread() from ext4_quota_write() (Lukas Czerner) [1845379]
- [scsi] scsi: sg: add sg_remove_request in sg_write ("Ewan D. Milne") [1840699] {CVE-2020-12770}
- [fs] fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (Donghai Qiao) [1832062] {CVE-2020-10732}v) [1844409]
- [mailbox] PCC: fix dereference of ERR_PTR (Vladis Dronov) [1844409]
- [kernel] futex: Unlock hb->lock in futex_wait_requeue_pi() error path (Vladis Dronov) [1844409]
- [fs] aio: fix inconsistent ring state (Jeff Moyer) [1845326]
- [vfio] vfio/mdev: make create attribute static (Vladis Dronov) [1837549]
- [vfio] treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Synchronize device create/remove with parent removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid creating sysfs remove file on stale device removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Improve the create/remove sequence (Vladis Dronov) [1837549]
- [vfio] treewide: Add SPDX license identifier - Makefile/Kconfig (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid inline get and put parent helpers (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Fix aborting mdev child device removal if one fails (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Follow correct remove sequence (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid masking error code to EBUSY (Vladis Dronov) [1837549]
- [include] vfio/mdev: Drop redundant extern for exported symbols (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Removed unused kref (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid release parent reference during error path (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Add iommu related member in mdev_device (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: add static modifier to add_mdev_supported_type (Vladis Dronov) [1837549]
- [vfio] vfio: mdev: make a couple of functions and structure vfio_mdev_driver static (Vladis Dronov) [1837549]
- [char] tpm/tpm_tis: Free IRQ if probing fails (David Arcari) [1774698]
- [kernel] audit: fix a memleak caused by auditing load module (Richard Guy Briggs) [1843370]
- [kernel] audit: fix potential null dereference 'context->module.name' (Richard Guy Briggs) [1843370]
- [nvme] nvme: limit number of IO queues on Dell/Samsung config (David Milburn) [1837617]
AA0s
Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check J/s#
Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCD2s
Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o1sm
Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbj5sc
Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]4s1
Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []3s7
Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
h5)h<8w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]F6s
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
HK:}
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]39e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t<g
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i;Q
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
->W
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
<<KA}
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]@9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L?
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tCg
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iBQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
-EW
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]MD
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
G9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]LF
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
1I1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fȃJH
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<MK
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}?J{
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
NLM
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}-LW
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]
P1
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_f̃JO
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)N9
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<<?Q{
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
dRE
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
p,p7Tk
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]OS
	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
PV

Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_holх^U9

Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999Xo

Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powԉtWe

Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commanderpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
yyZ7

Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: HanքXY-

Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
f[I

Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo\

Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
o]Y

Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q^]

Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]

er+V:eD
d79bdff199cc5f9127f01f99ca4906b965b3c5fb198906c1ed16e725d5bbe25fD
5573691deaca712e1478b3d889fe322be138680d8955a04b75e3a0066e099ca2D
28f85ca5b6e7c2b1e3ab7c4b31675583e8a72c18188f86f288a9a9bc046a202cD
d561b43042ddb9d02a31ae81d1c4935a05988542719e259b277dfcc2995339cfD
4f26a49ed12aa41e17cd5c146486cc8db5796101704d7b492066007312935250D
cda402fcb291052201381d37c733af954d30e2e6e3f24e5b636ae67715e8c0d0D
29feb5e5f9922979d66fabe2aac8bd7fdd18f1915777acf5b360bb7e5cdb0109D
4eb98f8f58cf6cec17799f6df6cd52b55de57ac3aef90f330df1e07c1f8f3702D
82269d23d95a9f1e1e213464701f07feb1fb5233bc66364a7b39d1a25b4a7a72D
4684e767f94d3dbc6eaccc3037287d441ff4f9d0bda6586211a7181edd68f6a8D

289a95c54f089f8ce63931c0b1b113b2e0f6b74f859eb3900ce19534baafd6d4D
16a9d3e7ce759abfcc7721bbe369b46acd4b3c511910e0ac4f61445d857f52d8D
b5a460913216927a863650ccef6d332b05a92836c9647e73a369720e9156fe84
d_E
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
o,po|bu
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]7ak
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]O`
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Y}ew
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]Bd
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"cA
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]
  ?h{
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.2.el7]ef@- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}4ge
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^f9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
XBk
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"jA
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]|iu
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]
}lw
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]bR'RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{!$')+.0258:<>AāCŁEƁGǁIɁKʁMˁṔQ΁RρTЁVӁXՁZׁ[؁\ف]ځ^܁_݁bށe߁hklnpsuwy|}~

 !"	#$&'()*+-/01234678 :!;"=#?$@%A&B
4ne
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^m9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bpA
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~oy
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
%n%"sA

Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]r7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]q
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens
}uw

Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]Bt

Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}
4we

Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^v9

Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
byA

Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~xy

Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
n+|	M

Radomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]{7

Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]z

Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ensdle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
}7
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han
f~I
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
oY
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
--R
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE^7
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
,,O
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]
'1
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.2.el7]`	l- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]T#
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]
AAs
Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check Js#
Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCD
s
Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o	sm
Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbj
sc
Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]s1
Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7
Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5+
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]Fs
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
s
Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check ^9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDs
Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}osm
Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjsc
Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]s1
Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7
Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5+
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]Fs
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
^9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]
ww^7
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]!?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.2.el7]_- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
O
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]R
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE
?'?[1
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797T#
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b ?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4!c
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J"
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J#
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
$
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend

?'?[&1
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797
T%#
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b'?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4(c
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J)
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J*
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
+
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
KK/-Y
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|,s
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
`H`[/1
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [19017973.a
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b0?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
41c
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J2
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J3
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
4
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend
KK/6Y
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|5s
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH37a
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
AA:8o
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
KK/:Y
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|9s
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3;a
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
4A4=
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.26.1.el7]`~@- selinux: fix deadlock in security_set_bools() (Ondrej Mosnacek) [1939091]
- md: fix md io stats accounting broken (Ming Lei) [1927106]
- redhat: Fix realtime_check for -private (Juri Lelli):<o
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
//?	
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]@>{
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.27.1.el7]`N@- video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (Mohammed Gamal) [1941841]
- Drivers: hv: vmbus: enable VMBus protocol version 5.0 (Mohammed Gamal) [1941841]
- redhat: Add git suffix to realtime_check merge_tree (Juri Lelli)
==>@w
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
A#
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..MB
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]
ttC	
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]
==>Dw
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
E#
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..MF
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+H'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}HG
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP +
SzS"J?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]I}
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
,,L-
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.2.el7]`A- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]1K]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+N'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}HM
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP /
SzS"P?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]O}
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
1Q]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
R
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
S
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2U_
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]T'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\W}
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]V9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
"X?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
1Y]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
Z
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
[
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2]_
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]\'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\`9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"_?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]^9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]

er+V:eD$
53cc61153b028eb77eee99eb4b318593a92007ff036a6f6a823411e1ac986690D#
51f9017134f88118879ffbdb248450e3b3d9099bcd70dd6c20b9044df41ebaadD"
6f9c2eab5630c71a827f71ce416ea6cd0c6b2aba734a2d023f35f7af3d415da4D!
f7f4d9e5559f8b130d55ce0048a0976d08ca48b1e818df7319c89d168e26c14eD 
0b31fcea001c43db8cd9d635933b11a63756f99e56b454bbfd3b201a1ec4a077D
8a6c2691d1645347df9eff452b78fb18042623b1204c96aafae8161528c51327D
3ad9c854816cd51073279e25d66deb06e14c0f98f40cc6d468a2d1aee2d2c284D
34d206ee003d27edc3b435c9aecc9569a8efa0cebca782b60e595b2c78f06326D
f6c9684def9cd5c7f66fcd886ee8773d2b2f5ae9bdb6dfb6f71d2377b140d30dD
dc83e35a513a39a6511e6815dff7c318849b1e9ec3399ac8de14115dd8663f84D
a80e94c28a71146376496e2e9902a431fca968386feb3bcfc1a8b876f55f48ceD
bf636c3d1c7371276e6fcf8c17bb54ad4a7b3adb5b7ac282711c4d8559a5996bD
6a841f73df251cdd51f2173820d7aefd9cdad93e87f34531d4856379e80aebfc
a
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
b
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2d_
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]c'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\g9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"f?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]e9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
22Ih
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmi
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348C
nnk9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]ijQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
Ym9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"l?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]
22In
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmo
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348H
ipQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_q=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7rm
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!tA
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7sm
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmu
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348N
ivQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_w=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7xm
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!zA
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7ym
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]
pepp|_
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]{+
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}
!+
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}n~[
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igVZ}3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]Wet() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush Xif write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error rYeform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
,n[
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig[Z3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]p_
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]\et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush ]if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r^eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b

Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060`}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{(D)E*F,H-J.L0N1P2Q3R4S5U6W7X8Y9Z:[;]<`>a?b@dAgBhDiEkFmGnIoJpKqLrMtOuPvQwRxSzT|UZ_ac
de
fikprsuvwxz {!|"}%~&'*+-02689=>?ADGHJMOPRUVWY[\^_acdfgiln
"Q"
s1
Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []	s7
Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]%I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}
Fs
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]jsc
Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]

+
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]
P
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_holg^9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999o
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powjte
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commandherpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
33n[
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_iglX-
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}met() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush nif write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error roeform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b

Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060q}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
QQ%I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUTt
PP+U
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S%
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
up%I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\ 7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUTy
PP+!U
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S"%
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM%
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%$I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D&
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
((S'%
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM*
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%)I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}(
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D+
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
%v%L-
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408],	
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d
0
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]/)
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954].-
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
%v%L2
 Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]1	
 Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d&6K
 Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
5
 Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]4)
 Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]3-
 Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
xx8#
 Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]l7W
 Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T9'
 Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
3^O$3l=W
!Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&<K
!Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
;
!Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]:9
 Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
ii>#
!Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T?'
!Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
G^GA#
!Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]@9
!Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(BD
!Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]C
!Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825+BU
!Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
MMG#
"Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lFW
"Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&EK
"Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
TH'
"Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
G^GJ#
"Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]I9
"Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(BM
"Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]L
"Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825+KU
"Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
O#
#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]LN
"Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
TP'
#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
G^GR#
#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]Q9
#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(BU
#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]T
#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825+SU
#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
LV
#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]
&&UW)
#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
Y
$Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825X
#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
hhL[
$Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]BZ
$Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
&&U\)
$Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
i^Q
$Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]]
$Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@_
$Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7am
$Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc`1
$Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
wwLc
%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]3be
$Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]

er+V:eD1
0cdf4d5f9455b9e3e0eeca97fcb7fa4f7b76899970af7d0fa1bdc2c1ade16fe2D0
d81c62d59566998fb91a334f86a794e936a86dbd458bf3633b8ab3f2d471e581D/
bbfb59fb0bbbee9e6941d7531aa54e1719671ed000cfb77426d6cc19506cebe1D.
4aeb221b696dbe4b67c7b108b689cf26df6c7baa673fd4a529bd4df444eaf4fcD-
1bab4a2f960faa0a69de616785116c776e018a15bdc67d8f57416af2a12896dbD,
c1a6b5c7d510c383e4cd61ceed4ca28f3f378bc0b62830d40f4fcb14f147b555D+
43b8b70412f6c494314d9177182cfca0820391aec220e38ecf47b9fb9d4acd86D*
4d332cc4ff11d1dc4a0a7e039eb49da22510476539025c6d32b9a5a212c7cfc5D)
0bb28c9f68dfa70b3b78027fb8b42c4122bccb671f14d669ce89f85990ee5c7bD(
77eccc75e9f9bd1beac93212452f411060218b9f17289e0f6bd3b293aaeaf916D'
4f80068ba1aae1df0b1a343be00c4f8225667afd61a123bede56704529ab3f6cD&
5c75d507373106773899d8f085ed0c9921518de33190dfac20ba2aa951e5b2c2D%
ae7235d8eadd22bf19fca7e2a758e17a26c6d01caf6e81861e6bf603fe82cb51
&&Ud)
%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
ifQ
%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]e
%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@g
%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7im
%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitch1
%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
E)E_l=
%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]k3
%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3je
%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
inQ
&Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]m
&Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@o
&Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7qm
&Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitcp1
&Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
)Eu7
&Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_t=
&Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]s3
&Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3re
&Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
WWw1
'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]v
&Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
<e_{=
'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]z3
'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3ye
'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]7xm
'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc
_TH<w
'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}~
'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]}
'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]|7
'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]
Hd7
(Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_=
(Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3e
'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
((<w
(Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}
(Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]
(Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]
HK}
(Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3e
(Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t	g
(Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iQ
(Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
s
)Jan Stancek <jstancek@redhat.com> [3.10.0-1152.el7]^- [nvmem] nvmem: properly handle returned value nvmem_reg_read (Vladis DronoΊ	s!
)Jan Stancek <jstancek@redhat.com> [3.10.0-1151.el7]^W@- [netdrv] qede: Fix multicast mac configuration (Michal Schmidt) [1740064]
- [scsi] sd_dif: avoid incorrect ref_tag errors on 4K devices larger than 2TB (Ewan Milne) [1833528]
- [hid] HID: hiddev: do clean͂M

(Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}up in failure of opening a device (Torez Smith) [1814257] {CVE-2019-19527}
- [hid] HID: hiddev: avoid opening a disconnected device (Torez Smith) [1814257] {CVE-2019-19527}
- [x86] x86: make mul_u64_u64_div_u64() "static inline" (Oleg Nesterov) [1845864]
- [mm] mm: page_isolation: fix potential warning from user (Rafael Aquini) [1845620]
- [s390] s390/mm: correct return value of pmd_pfn (Claudio Imbrenda) [1841106]
- [fs] fs/proc/vmcore.c:mmap_vmcore: skip non-ram pages reported by hypervisors (Lianbo Jiang) [1790799]
- [kernel] kernel/sysctl.c: ignore out-of-range taint bits introduced via kernel.tainted (Rafael Aquini) [1845356]
- [documentation] kernel: add panic_on_taint (Rafael Aquini) [1845356]
- [fs] ext4: Remove unwanted ext4_bread() from ext4_quota_write() (Lukas Czerner) [1845379]
- [scsi] scsi: sg: add sg_remove_request in sg_write ("Ewan D. Milne") [1840699] {CVE-2020-12770}
- [fs] fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (Donghai Qiao) [1832062] {CVE-2020-10732}v) [1844409]
- [mailbox] PCC: fix dereference of ERR_PTR (Vladis Dronov) [1844409]
- [kernel] futex: Unlock hb->lock in futex_wait_requeue_pi() error path (Vladis Dronov) [1844409]
- [fs] aio: fix inconsistent ring state (Jeff Moyer) [1845326]
- [vfio] vfio/mdev: make create attribute static (Vladis Dronov) [1837549]
- [vfio] treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Synchronize device create/remove with parent removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid creating sysfs remove file on stale device removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Improve the create/remove sequence (Vladis Dronov) [1837549]
- [vfio] treewide: Add SPDX license identifier - Makefile/Kconfig (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid inline get and put parent helpers (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Fix aborting mdev child device removal if one fails (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Follow correct remove sequence (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid masking error code to EBUSY (Vladis Dronov) [1837549]
- [include] vfio/mdev: Drop redundant extern for exported symbols (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Removed unused kref (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid release parent reference during error path (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Add iommu related member in mdev_device (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: add static modifier to add_mdev_supported_type (Vladis Dronov) [1837549]
- [vfio] vfio: mdev: make a couple of functions and structure vfio_mdev_driver static (Vladis Dronov) [1837549]
- [char] tpm/tpm_tis: Free IRQ if probing fails (David Arcari) [1774698]
- [kernel] audit: fix a memleak caused by auditing load module (Richard Guy Briggs) [1843370]
- [kernel] audit: fix potential null dereference 'context->module.name' (Richard Guy Briggs) [1843370]
- [nvme] nvme: limit number of IO queues on Dell/Samsung config (David Milburn) [1837617]
AAs
)Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check цJ
s#
)Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDs
)Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}osm
)Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjsc
)Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]s1
)Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7
)Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
h5)h<w
*Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}
*Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]Fs
)Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
HK}
*Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3e
*Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tg
*Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iQ
*Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
-W
*Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M
*Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
<<K}
+Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]9
*Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L
*Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t!g
+Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i Q
+Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
-#W
+Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M"
+Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
%9
+Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L$
+Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
1'1
+Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_f߃J&
+Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<M)
,Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}?({
+Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
NL+
,Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}-*W
,Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]
.1
,Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fJ-
,Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko),9
,Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<<?/{
,Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
d0E
,Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
p,p72k
,Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]O1
,Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
P4
-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol^39
-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
9996o
-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powt5e
-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commanderpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
yy87
-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: HanX7-
-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
f9I
-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo:
-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
o;Y
-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q<]
-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
d=E
.Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
o,po|@u
.Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]7?k
.Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]O>
.Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Y}Cw
.Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]BB
.Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"AA
.Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]
  ?F{
.Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.2.el7]ef@- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}4Ee
.Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^D9
.Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
XBI
/Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"HA
/Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]|Gu
/Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]
}Jw
/Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]
4Le
/Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^K9
/Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bNA
/Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~My
/Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]bR@RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{quÁwŁ{ƁǁȁɁˁ	́ЁҁӁԁՁׁ؁فہ!܁#݁%ށ')+./024689:;<=@CFIJLNQSUWZ[\]^_a
bd
fhkmoqtvwy{}~ "#%&'(*	+,
./013456789:;<= >!?"ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
%n%"QA
0Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]P7
/Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]O
/Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens
}Sw
0Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]BR
0Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}
4Ue
0Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^T9
0Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bWA
0Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~Vy
0Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
n+Z	M
0Radomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]Y7
0Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]X
0Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ensdle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
[7
1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han
f\I
1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo]
1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
o^Y
1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q_]
1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
--Ra
1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE	^`7
1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
,,Ob
1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]
'd1
1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.2.el7]`	l- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]Tc#
1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]

er+V:eD>
4effc7564fc196a4c6411751bedca4e9e01367a459bcaff78bc6849dc7cf71f5D=
4fdc56dc0f2c90e2f3e04a9191f8f4da825b37f6ac25fe246820e255ce02e8a1D<
e6bb8a9138e3246eedff3c7522b5bdd6a006e9d47913ff4c10817c6036530510D;
2e6658df1cad274f8acd004adf1a98e57338b7aeae5ac65e2c25e78bfe0d2f99D:
2617375bbb0a52fe637164f0f40bbbc00ea29b150dd35ba0e0f79447454ad604D9
3c1d7d5a10b6bbb96820657c57af7a774ba60dd1acb011d623b218102b3251f3D8
68cfd2b5e2aa6b9bad7a4040def6ccec2aa6ca31c6acf4758e98b507e8efc105D7
e8c1f68569cc209cc9fa2df02ad4b7b0845192e6e74e5167c8cf3400acdc4c2bD6
2e4f169246c2ce1c02926c3021b68913f273ab5b7474087d761d93b81e98eedbD5
2a69b561a8c58b7ed126929ce0f305827b54da8604e8f662568fc8ec96090f26D4
21af3e26269599f29ef700b687a3e84539aa03ffc025f0794649d54f0a041582D3
454bbafafa2ed6a940377a73f755cc70525a8547533b1c20ff588842216101d0D2
4d236aaf4435c04e7eca7641052df2e7fe956b46c24fdf530db5d3367025b1f4
AAfs
2Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check Jes#
2Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDhs
2Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}ogsm
2Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjksc
2Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]js1
2Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []is7
2Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5m+
2Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]Fls
2Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
os
3Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check ^n9
2Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDqs
3Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}opsm
3Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjtsc
3Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]ss1
3Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []rs7
3Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5v+
3Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]Fus
3Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
^w9
3Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]
ww^y7
4Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]!x?
3Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.2.el7]_- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
O{
4Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]Rz
4Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE
?'?[}1
4Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797T|#
4Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b~?
4Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4c
4Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J
4Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J
4Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]

4Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend!
?'?[1
5Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797$T#
5Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b?
5Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4c
5Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J
5Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J
5Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
	
5Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend)
KK/Y
5Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|
s
5Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
`H`[
1
6Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797-3a
5Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b?
6Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4c
6Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J
6Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J
6Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]

6Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend2
KK/Y
6Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|s
6Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3a
6Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
AA:o
6Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
KK/Y
7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|s
7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3a
7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
4A4
7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.26.1.el7]`~@- selinux: fix deadlock in security_set_bools() (Ondrej Mosnacek) [1939091]
- md: fix md io stats accounting broken (Ming Lei) [1927106]
- redhat: Fix realtime_check for -private (Juri Lelli):o
7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
//	
7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]@{
7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.27.1.el7]`N@- video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (Mohammed Gamal) [1941841]
- Drivers: hv: vmbus: enable VMBus protocol version 5.0 (Mohammed Gamal) [1941841]
- redhat: Add git suffix to realtime_check merge_tree (Juri Lelli)
==>w
7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
#
7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M 
7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]
tt!	
8Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]
==>"w
8Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
##
8Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M$
8Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+&'
8Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}H%
8Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP B
SzS"(?
8Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]'}
8Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
,,*-
8Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.2.el7]`A- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]1)]
8Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+,'
9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}H+
9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP F
SzS".?
9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]-}
9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
1/]
9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
0
9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
1
9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..23_
9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]2'
9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\5}
:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]49
9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
"6?
:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
17]
:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
8
:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
9
:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2;_
:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]:'
:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\>9
:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"=?
:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]<9
:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
?
;Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
@
;Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2B_
;Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]A'
;Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\E9
;Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"D?
;Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]C9
;Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
22IF
;Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmG
;Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348Y
nnI9
<Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]iHQ
;Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
YK9
<Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"J?
<Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]
22IL
<Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmM
<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348^
iNQ
<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_O=
<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7Pm
<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!RA
<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7Qm
<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmS
=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348d
iTQ
=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_U=
=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7Vm
=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!XA
=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7Wm
=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]
peppZ_
=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]Y+
=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}
!]+
>Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}n\[
=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_iglZ[3
=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]met() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush nif write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error roeform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
,n`[
>Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igqZ_3
>Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]p^_
>Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]ret() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush sif write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error rteform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
b
>Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060va}
>Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?d
>Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<cw
>Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
"Q"hs1
?Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []gs7
?Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]%fI
>Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]e
>Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}

er+V:eDK
47a1d5d0a1ad064ec478ea6d44b259972b9111eefcf4ada7bbacbbe6aaf5a0beDJ
8251d9d6d6785ae0ed2231e5acd6b3d6b86a215d008b16ed8f78ea929cfc9c4dDI
79d78fa443907f0ca28a70215cf61c47f965c37ef5ad56c02db408bdd9e238c2DH
3103d16f84c636f0c9414dff8107cf8586ae75fbcb90a3f62b7eee6412a9b821DG
1824faf3f57ad70fa29640a76cd08c71a18f5f97c91c1117929ab588f9aa44dcDF
6cdebf9c4780af0f03b80b00c611402cb25855be68d159669e31cebcae14e948DE
508911ce79f98f5eed94b7cbd546f0c6e54fe284ef02edf721f6bdeea590659cDD
3b5672f51204c1617610ae8cd9b6f52811ce9c9fa0d5d33100995554e954e356DC
843def5f9cabf23dde3a6c7cc1d52f68406f3af88c42d2d84dfe7a35cca79197DB
6ad05aacb55ec137da2b221c99a490660a5f37778642d8b590d33d5fbb093262DA
0d768d1ea1cafc2aac35e0917a8c6e9184c802e60dc7add05251d7c940193f32D@
af4cb1545cd730fee8de02f39c8201ee8909319eb1b8d4e09b97227b67b961b8D?
02d776d9eabc5a1600b998782d8d36dfd9f654699fe0d5ed0fcea97a75b44ac1
Fjs
?Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]jisc
?Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{A$C&D(E*G,H.I/J0K1L3M5N6O7P8Q9R;S>T?U@VBWEXFZG[I\K]L_M`NaObPcReSfTgUhViXjZk]p`ubwdxhzj|k}moqsuwxyz}~	"%&(+-.03457ǁ9ȁ:Ɂ<ʁ=ˁ?́A΁BρDЁEсGӁJԁLՁMցO
k+
?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]
Pm
?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol~^l9
?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999oo
?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powtne
?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commanderpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
33nq[
@Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igXp-
?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error reform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
s
@Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060r}
@Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?u
@Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<tw
@Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
QQ%wI
@Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]v
@Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\x7
@Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT
PP+yU
@Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((Sz%
@Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
up%}I
ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]|
ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}{
ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\~7
ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT
PP+U
ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S%
ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM
ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%I
ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}
ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D
ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
((S%
BRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM
BRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%I
BRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}
BRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D	
BRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
%v%L
BRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]
	
BRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d

BRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]
)
BRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]-
BRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
%v%L
CRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]	
CRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d&K
CRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]

CRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000])
CRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]-
CRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
xx#
CRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lW
CRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T'
CRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
3^O$3lW
DRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&K
DRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]

DRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]9
CRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
ii#
DRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T'
DRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
G^G#
DRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]9
DRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B"
DRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]!
DRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825+ U
DRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
MM%#
ERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]l$W
ERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&#K
ERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T&'
ERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
G^G(#
ERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]'9
ERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B+
ERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]*
ERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825+)U
ERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
-#
FRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]L,
ERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T.'
FRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
G^G0#
FRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]/9
FRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B3
FRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]2
FRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825+1U
FRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
L4
FRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]
&&U5)
FRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
7
GRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825„6
FRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
hhL9
GRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]B8
GRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
&&U:)
GRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
i<Q
GRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243];
GRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@=
GRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7?m
GRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc̅>1
GRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
wwLA
HRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]3@e
GRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
&&UB)
HRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
iDQ
HRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]C
HRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@E
HRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7Gm
HRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc҅F1
HRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
E)E_J=
HRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]I3
HRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3He
HRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
iLQ
IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]K
IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@M
IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7Om
IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitcׅN1
IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
)ES7
IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_R=
IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]Q3
IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3Pe
IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
WWU1
JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]T
IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
<e_Y=
JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]X3
JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3We
JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]7Vm
JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc
_TH<]w
JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}\
JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338][
JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]Z7
JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]
Hd`7
KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]__=
KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3^e
JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
((<cw
KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}b
KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]a
KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]
HKe}
KJan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3de
KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tgg
KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]ifQ
KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
js
LJan Stancek <jstancek@redhat.com> [3.10.0-1152.el7]^- [nvmem] nvmem: properly handle returned value nvmem_reg_read (Vladis Drono	is!
LJan Stancek <jstancek@redhat.com> [3.10.0-1151.el7]^W@- [netdrv] qede: Fix multicast mac configuration (Michal Schmidt) [1740064]
- [scsi] sd_dif: avoid incorrect ref_tag errors on 4K devices larger than 2TB (Ewan Milne) [1833528]
- [hid] HID: hiddev: do cleanMh
KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}

er+V:eDX
150b5e83d6acc1e5a6e22bee18216d6c7e0c581dca489071a61aab70eb9b93fbDW
a133fe2fda391e345abde6444e57c6fbfb5ebcfe7720bc5b1ae1c3313bd38aedDV
94956f35cf998fadb6818b03bda0abd42d6bb6eaef56f6c880f239607a6b876aDU
c61d2053d483f06c16fe09b040f911571abd663498e0d24266d849b51fdb0479DT
e8c196f4e751026825afd99f7aaf6ab5d3234a2fba46b51b585338b80c837da0DS
f1fbcc04902985414df518ea977cb39390df37dc9fc617aeab23437cf6fe80e5DR
b6ef3e291bb25a5525d4b85ac8b4bad708a7f474d0baeb5ed6d75da8f0ff9c5eDQ
2ba740802cbbc7ff23957b8b2a38c06b773a113b40708d05815b6081f7eecb19DP
7eafe5ff654144eafe243a63bd26f5f8be857f9a6db277149949bba5f768b643DO
c29c2680928459b5247e613db52774e62b9696ce64b4b85f878cdfd4775a8f05DN
933451069f9fdd66cf5110ba003ce53bcfcee82260f53a69105373c07f77d5f0DM
049526fdb7a05153ccc486726ea5c75e9cbf7eb168e6d4eb673555e2a2ed8967DL
81b4e4f401d2402736ceba4627eaafd5b615c2cc45aa4d4f941ea79562045139up in failure of opening a device (Torez Smith) [1814257] {CVE-2019-19527}
- [hid] HID: hiddev: avoid opening a disconnected device (Torez Smith) [1814257] {CVE-2019-19527}
- [x86] x86: make mul_u64_u64_div_u64() "static inline" (Oleg Nesterov) [1845864]
- [mm] mm: page_isolation: fix potential warning from user (Rafael Aquini) [1845620]
- [s390] s390/mm: correct return value of pmd_pfn (Claudio Imbrenda) [1841106]
- [fs] fs/proc/vmcore.c:mmap_vmcore: skip non-ram pages reported by hypervisors (Lianbo Jiang) [1790799]
- [kernel] kernel/sysctl.c: ignore out-of-range taint bits introduced via kernel.tainted (Rafael Aquini) [1845356]
- [documentation] kernel: add panic_on_taint (Rafael Aquini) [1845356]
- [fs] ext4: Remove unwanted ext4_bread() from ext4_quota_write() (Lukas Czerner) [1845379]
- [scsi] scsi: sg: add sg_remove_request in sg_write ("Ewan D. Milne") [1840699] {CVE-2020-12770}
- [fs] fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (Donghai Qiao) [1832062] {CVE-2020-10732}v) [1844409]
- [mailbox] PCC: fix dereference of ERR_PTR (Vladis Dronov) [1844409]
- [kernel] futex: Unlock hb->lock in futex_wait_requeue_pi() error path (Vladis Dronov) [1844409]
- [fs] aio: fix inconsistent ring state (Jeff Moyer) [1845326]
- [vfio] vfio/mdev: make create attribute static (Vladis Dronov) [1837549]
- [vfio] treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Synchronize device create/remove with parent removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid creating sysfs remove file on stale device removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Improve the create/remove sequence (Vladis Dronov) [1837549]
- [vfio] treewide: Add SPDX license identifier - Makefile/Kconfig (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid inline get and put parent helpers (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Fix aborting mdev child device removal if one fails (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Follow correct remove sequence (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid masking error code to EBUSY (Vladis Dronov) [1837549]
- [include] vfio/mdev: Drop redundant extern for exported symbols (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Removed unused kref (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid release parent reference during error path (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Add iommu related member in mdev_device (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: add static modifier to add_mdev_supported_type (Vladis Dronov) [1837549]
- [vfio] vfio: mdev: make a couple of functions and structure vfio_mdev_driver static (Vladis Dronov) [1837549]
- [char] tpm/tpm_tis: Free IRQ if probing fails (David Arcari) [1774698]
- [kernel] audit: fix a memleak caused by auditing load module (Richard Guy Briggs) [1843370]
- [kernel] audit: fix potential null dereference 'context->module.name' (Richard Guy Briggs) [1843370]
- [nvme] nvme: limit number of IO queues on Dell/Samsung config (David Milburn) [1837617]
AAls
LJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check Jks#
LJan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDns
LJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}omsm
LJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjqsc
LJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]ps1
LJan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []os7
LJan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
h5)h<tw
MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}s
MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]Frs
LJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
HKv}
MJan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3ue
MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

txg
MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iwQ
MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
-zW
MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]My
MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
<<K}}
NJan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]|9
MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L{
MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tg
NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i~Q
NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
-W
NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M
NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
9
NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L
NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
11
NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fJ
NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<M
ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}?{
NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
NL	
ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}-W
ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]
1
ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_fJ
ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)
9
ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<<?
{
ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
dE
ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
p,p7k
ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]O
ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
P
PAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol^9
PAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999o
PAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powte
PAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commanderpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
yy7
PAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: HanX-
PAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
fI
PAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo
PAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
oY
PAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q]
PAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
dE
QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
o,po|u
QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]7k
QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]O
QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Y}!w
QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B 
QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"A
QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]
  ?${
QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.2.el7]ef@- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}4#e
QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^"9
QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
XB'
RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"&A
RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]|%u
RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]
}(w
RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]
4*e
RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^)9
RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
b,A
RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~+y
RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
%n%"/A
SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223].7
RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]-
RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens
}1w
SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B0
SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}bRZRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{فUہY܁]݁`ށc߁egjlnqtvxz}	
	
!$
'(*,/13589:;<=?!@"B#D%F&I'K(M*O+R,T-U.W0Y1[3\4]5^6_8`9b;c<d=e>f@gAiBkElFmGnHoJpKrLsMtNvOwPyQ{R|S}T~UVWX
43e
SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^29
SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
b5A
SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~4y
SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
n+8	M
SRadomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]77
SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]6
SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ensdle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
97
TAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han
f:I
TAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo;
TAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
o<Y
TAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q=]
TAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
--R?
TAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE ^>7
TAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
,,O@
TAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]
'B1
TAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.2.el7]`	l- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]TA#
TAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]
AADs
UJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check $JCs#
UJan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDFs
UJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}oEsm
UJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjIsc
UJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]Hs1
UJan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []Gs7
UJan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5K+
UAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]FJs
UJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
Ms
VJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check )^L9
UAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDOs
VJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}oNsm
VJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjRsc
VJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]Qs1
VJan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []Ps7
VJan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5T+
VAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]FSs
VJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
^U9
VAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]
ww^W7
WAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]!V?
VAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.2.el7]_- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
OY
WAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]RX
WAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE/
?'?[[1
WAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [19017972TZ#
WAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b\?
WAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4]c
WAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J^
WAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J_
WAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
`
WAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend7
?'?[b1
XAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797:Ta#
XAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bc?
XAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4dc
XAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11Je
XAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11Jf
XAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
g
XAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend?
KK/iY
XAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|hs
XAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
`H`[k1
YAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797D3ja
XAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)

er+V:eDe
40b62a1609bf1e6b7221ee088dfbf97f47ad76f2533474c46260a24ca3439cdfDd
89508e57764f6439d8043a9ae25c798163d3dc7e1ea5019bab2063d6eaafb9c3Dc
b38f765f577317761aaaf492c0a93c317974aef18e4e53fea2895acb530ec50eDb
3198edac074ce72829e22b3fc0c16b2361413759b0418cd6443a6a5394eaf84aDa
394db1fa5c7f0d2612ba1c758328abe415aa0a5677f936aeeb8f95543e5c4110D`
e107c061dd44f2966524c0a39c675a112e3f712a7f1b891c19bc27ddadc6d91bD_
5ff60c9fc8d59e0004f0a615c0b3b023014fe0ba062442fdf0449dd359e754b9D^
a9a7c7111b8132043c9c9351bdd7bf34051ae1eb9ab0c90e8e7582ca543c49d6D]
6ec6b4d2ab3c7cf65dceaadd6a13d91e6ca7e48b3d6bf5712f0c0bf3639015b0D\
3ce3178d47c0937ca4073ad24a4d21e17880a93c83bed7d7cdde515bda87c789D[
53ebea1b387c7333eb49334b5bf8e867d5307742f502d7d40091abe8eb42387bDZ
b3587c7ba2e0d12bead8a84ad8d8aad31b6a2da64b0de946850e55afd3787193DY
cb86f1399947fbb9131708d22997718ff926c00d9e0cdfa9ce37811fe7e47e4d]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bl?
YAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4mc
YAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11Jn
YAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11Jo
YAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
p
YAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extendI
KK/rY
YAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|qs
YAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3sa
YAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
AA:to
YAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
KK/vY
ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|us
ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3wa
ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
4A4y
ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.26.1.el7]`~@- selinux: fix deadlock in security_set_bools() (Ondrej Mosnacek) [1939091]
- md: fix md io stats accounting broken (Ming Lei) [1927106]
- redhat: Fix realtime_check for -private (Juri Lelli):xo
ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
//{	
ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]@z{
ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.27.1.el7]`N@- video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (Mohammed Gamal) [1941841]
- Drivers: hv: vmbus: enable VMBus protocol version 5.0 (Mohammed Gamal) [1941841]
- redhat: Add git suffix to realtime_check merge_tree (Juri Lelli)
==>|w
ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
}#
ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M~
ZAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]
tt	
[Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]
==>w
[Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
#
[Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M
[Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+'
[Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}H
[Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP Y
SzS"?
[Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]}
[Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
,,-
[Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.2.el7]`A- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]1]
[Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+
'
\Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}H	
\Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP ]
SzS"?
\Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]}
\Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
1
]
\Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)

\Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]

\Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2_
\Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]'
\Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\}
]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]9
\Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
"?
]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
1]
]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)

]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]

]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2_
]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]'
]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\9
]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"?
]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]9
]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]

^Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]

^Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2 _
^Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]'
^Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\#9
^Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]""?
^Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]!9
^Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
22I$
^Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm%
^Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348p
nn'9
_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]i&Q
^Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
Y)9
_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"(?
_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]
22I*
_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm+
_Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348u
i,Q
_Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_-=
_Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7.m
_Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!0A
_Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7/m
_Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm1
`Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348{
i2Q
`Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_3=
`Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD74m
`Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!6A
`Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]75m
`Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]
pepp8_
`Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]7+
`Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}
!;+
aRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}n:[
`Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igZ93
`Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error reform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
,n>[
aRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igZ=3
aRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]p<_
aRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error reform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
@
aRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060?}
aRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?B
aRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<Aw
aRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
"Q"Fs1
bJan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []Es7
bJan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]%DI
aRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]C
aRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}
FHs
bJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]jGsc
bJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]
I+
bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]
PK
bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol^J9
bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]bRRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{[\^
_`
abcdefghijklm n#o$q%r's)t*v+w,x-y.z0|1}2~3468;>@BFHIKMOQSUVWX[\]^abcfgilnrtuyz{}āŁƁ	́΁ρЁցׁ؁ށ߁ "#%(*+-13d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999Mo
bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] powtLe
bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_commanderpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
33nO[
cRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_igXN-
bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error reform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
Q
cRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060P}
cRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?S
cRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<Rw
cRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
QQ%UI
cRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]T
cRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\V7
cRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT
PP+WU
cRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((SX%
cRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
up%[I
dRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]Z
dRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}Y
dRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\\7
dRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT
PP+]U
dRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S^%
dRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpMa
dRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%`I
dRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}_
dRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77Db
dRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
((Sc%
eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpMf
eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%eI
eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}d
eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77Dg
eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
%v%Li
eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]h	
eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d
l
eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]k)
eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]j-
eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]

er+V:eDr
b59e577acfd79936a81667c77131d1327e4ad70bde597f697884a4eaf7e3a7ecDq
54ccdc7cf35a5a397da2776db1e3698403ddd8b7aaa89e9bd1156f4f0b376933Dp
5c3bcfc599ddd884790cbf5e2d8043339f4cd5b91ad9595afa0db6b779424c22Do
fd72ad4e19f26b5ab55c6b53a5824234f78c29cf3c20aca13156acea64a3346cDn
3598b7d61bba2f202c95efea45958f70f97c86c499e19042f49589dccbf233ceDm
f53cc1052d30f24f16353f3b8289baea8f6b5784241e361ca528cc3a0eaa3777Dl
76facf50f1b80b009a8db32a440b75f305a0ebb492bfd12472396c89645ad637Dk
b32b8584f13412301461463bde85e0fdc2dde858c115cd5ff1e7c299096a8d77Dj
88ec95b43c8491db9c18162f1e7fba8a23bdd4c936af58ebbc5e3ca5294bfb53Di
262dbb7f2a09156ec1388f48b84cdfae97e0c8a8a47a0eabf39d4db7348d2f88Dh
85883036219c6afb70af3efeedd40855b4513b05e5a5134abc56c4b95841a125Dg
6858b0825e7c10d48e4a834df4baf94b38ae7f99b036340669e3abf74bdfc689Df
57519dda2c881614316fc810027c0c66b31bab6e5e16dcd0d91cf84b6d63fc3a
%v%Ln
fRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]m	
fRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d&rK
fRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
q
fRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]p)
fRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]o-
fRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
xxt#
fRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lsW
fRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
Tu'
fRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
3^O$3lyW
gRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&xK
gRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
w
gRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]v9
fRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
iiz#
gRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T{'
gRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
G^G}#
gRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]|9
gRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B
gRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
gRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825+~U
gRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
MM#
hRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lW
hRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&K
hRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T'
hRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
G^G#
hRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]9
hRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B	
hRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
hRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825ǁ+U
hRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
#
iRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]L

hRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T'
iRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 
G^G#
iRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]
9
iRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B
iRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
iRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825с+U
iRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
L
iRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]
&&U)
iRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]

jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825ل
iRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401} CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
hhL
jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]B
jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
&&U)
jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
iQ
jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]
jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@
jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7m
jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc1
jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
wwL
kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]3e
jRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
&&U )
kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
i"Q
kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]!
kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@#
kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7%m
kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc$1
kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
E)E_(=
kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]'3
kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3&e
kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
i*Q
lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243])
lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@+
lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7-m
lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc,1
lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
)E17
lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_0=
lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]/3
lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3.e
lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
WW31
mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]2
lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
<e_7=
mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]63
mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}35e
mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]74m
mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc
_TH<;w
mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}:
mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]9
mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]87
mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]
Hd>7
nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_==
nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3<e
mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
((<Aw
nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}@
nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]?
nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]
HKC}
nJan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3Be
nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tEg
nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iDQ
nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]
Hs
oJan Stancek <jstancek@redhat.com> [3.10.0-1152.el7]^- [nvmem] nvmem: properly handle returned value nvmem_reg_read (Vladis Drono	Gs!
oJan Stancek <jstancek@redhat.com> [3.10.0-1151.el7]^W@- [netdrv] qede: Fix multicast mac configuration (Michal Schmidt) [1740064]
- [scsi] sd_dif: avoid incorrect ref_tag errors on 4K devices larger than 2TB (Ewan Milne) [1833528]
- [hid] HID: hiddev: do cleanMF
nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}up in failure of opening a device (Torez Smith) [1814257] {CVE-2019-19527}
- [hid] HID: hiddev: avoid opening a disconnected device (Torez Smith) [1814257] {CVE-2019-19527}
- [x86] x86: make mul_u64_u64_div_u64() "static inline" (Oleg Nesterov) [1845864]
- [mm] mm: page_isolation: fix potential warning from user (Rafael Aquini) [1845620]
- [s390] s390/mm: correct return value of pmd_pfn (Claudio Imbrenda) [1841106]
- [fs] fs/proc/vmcore.c:mmap_vmcore: skip non-ram pages reported by hypervisors (Lianbo Jiang) [1790799]
- [kernel] kernel/sysctl.c: ignore out-of-range taint bits introduced via kernel.tainted (Rafael Aquini) [1845356]
- [documentation] kernel: add panic_on_taint (Rafael Aquini) [1845356]
- [fs] ext4: Remove unwanted ext4_bread() from ext4_quota_write() (Lukas Czerner) [1845379]
- [scsi] scsi: sg: add sg_remove_request in sg_write ("Ewan D. Milne") [1840699] {CVE-2020-12770}
- [fs] fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (Donghai Qiao) [1832062] {CVE-2020-10732}v) [1844409]
- [mailbox] PCC: fix dereference of ERR_PTR (Vladis Dronov) [1844409]
- [kernel] futex: Unlock hb->lock in futex_wait_requeue_pi() error path (Vladis Dronov) [1844409]
- [fs] aio: fix inconsistent ring state (Jeff Moyer) [1845326]
- [vfio] vfio/mdev: make create attribute static (Vladis Dronov) [1837549]
- [vfio] treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Synchronize device create/remove with parent removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid creating sysfs remove file on stale device removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Improve the create/remove sequence (Vladis Dronov) [1837549]
- [vfio] treewide: Add SPDX license identifier - Makefile/Kconfig (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid inline get and put parent helpers (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Fix aborting mdev child device removal if one fails (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Follow correct remove sequence (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid masking error code to EBUSY (Vladis Dronov) [1837549]
- [include] vfio/mdev: Drop redundant extern for exported symbols (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Removed unused kref (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid release parent reference during error path (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Add iommu related member in mdev_device (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: add static modifier to add_mdev_supported_type (Vladis Dronov) [1837549]
- [vfio] vfio: mdev: make a couple of functions and structure vfio_mdev_driver static (Vladis Dronov) [1837549]
- [char] tpm/tpm_tis: Free IRQ if probing fails (David Arcari) [1774698]
- [kernel] audit: fix a memleak caused by auditing load module (Richard Guy Briggs) [1843370]
- [kernel] audit: fix potential null dereference 'context->module.name' (Richard Guy Briggs) [1843370]
- [nvme] nvme: limit number of IO queues on Dell/Samsung config (David Milburn) [1837617]
AAJs
oJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check JIs#
oJan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDLs
oJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}oKsm
oJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjOsc
oJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]Ns1
oJan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []Ms7
oJan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
h5)h<Rw
pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}Q
pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]FPs
oJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
HKT}
pJan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3Se
pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tVg
pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iUQ
pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262] 
-XW
pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]MW
pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
<<K[}
qJan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]Z9
pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]LY
pRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t]g
qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i\Q
qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262] 
-_W
qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M^
qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
a9
qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L`
qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
1c1
qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_f Jb
qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<Me
rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}?d{
qRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
NLg
rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}-fW
rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]
j1
rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_f Ji
rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)h9
rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<<?k{
rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
dlE
rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
p,p7nk
rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]Om
rRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}

er+V:eD
7c45ba29959e72ceece7bd3f48bcc0ce0a86ebce4677a50e9d95a46e172b5d3bD~
c3571b20ed80af5bcdad26c4ffded5902a413e69a9f36e66ea22eb7f0b7343beD}
73ae0d5fb6285b4b0077f98e47a68f4b9fece79c2d81f4ee0718940d27177616D|
56c9932aa2318a64e391b3f64c794e77737aeacd923b2b7d8e02b450cd58abd2D{
540ad2675ab792c4e347811b9c59c9dfa46be5932ed582b6b0748c7a27660973Dz
34255ef50bd9c16239a9a579c23a1bc1f046428a2aecf0fb06e04340b46af985Dy
5f9ffa10d0718dbd468c695dee255d77d9ba1a9b0d1b7e44a156806dcdca67a1Dx
d9305a12e977c57f2881d0d6b5d0a5c612d311bf062b22798ff09ce88469752cDw
4f125e807f2d9654af85653665201a2fb6833421172f030513ae09616ba3f069Dv
a3ef423198831cced03969fcb478cb2a5ee78ec107a8600aa98854d428fa7a96Du
c560870127d4c5652e42c74ffbb3cf96a864ca994702fffd84bfe5a6b5275464Dt
d4ce276deccf36c3cdff38a52ff6f73bd2c271d8df45463c61cc66cdd8dd7e18Ds
c91dc3bbc7593fb7442fa9ec947f30d95bad094d5b4180e4669380d535253bb7
Pp
sAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol ^o9
sAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999ro
sAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] pow tqe
sAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command erpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
yyt7
sAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han Xs-
sAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
fuI
sAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oov
sAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
owY
sAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


qx]
sAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
dyE
tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
o,po||u
tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]7{k
tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]Oz
tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Y}w
tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B~
tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"}A
tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]
  ?{
tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.2.el7]ef@- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}4e
tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^9
tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
XB
uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"A
uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]|u
uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]
}w
uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]
4e
uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^9
uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
b
A
uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~	y
uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
%n%"
A
vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]7
uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]
uRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens (
}w
vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B
vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}
4e
vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^9
vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bA
vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~y
vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]bR rRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{;>ACEHJL O R T V X [ ] 	_ 
a c 
e g j k l n p r t u v w x  y !| " # $ % & '
 )
 * + , / 1 2 3 4 5 6 8 9  :" <$ =' >) ?+ A- B0 C2 D3 E5 G7 H9 J: K; L< M= O> P@ RA SB TC UD WE XG YI [J \K ]L ^M `N aP bQ cR dT eU fW gY hZ i[ j\ k] l^ m_ n` pb qdure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
n+	M
vRadomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]7
vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]
vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens .dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
7
wAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han 0
fI
wAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo
wAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
oY
wAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q]
wAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
--R
wAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE 7^7
wAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
,,O
wAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]
' 1
wAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.2.el7]`	l- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]T#
wAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]
AA"s
xJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check  ;J!s#
xJan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCD$s
xJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o#sm
xJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbj'sc
xJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]&s1
xJan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []%s7
xJan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5)+
xAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]F(s
xJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
+s
yJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check  @^*9
xAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCD-s
yJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o,sm
yJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbj0sc
yJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]/s1
yJan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) [].s7
yJan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
52+
yAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]F1s
yJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
^39
yAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]
ww^57
zAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]!4?
yAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.2.el7]_- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
O7
zAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]R6
zAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE F
?'?[91
zAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797 IT8#
zAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b:?
zAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4;c
zAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J<
zAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J=
zAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
>
zAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend N
?'?[@1
{Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797 QT?#
{Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bA?
{Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4Bc
{Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11JC
{Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11JD
{Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
E
{Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend V
KK/GY
{Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|Fs
{Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
`H`[I1
|Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797 Z3Ha
{Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
bJ?
|Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4Kc
|Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11JL
|Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11JM
|Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
N
|Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend _
KK/PY
|Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|Os
|Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3Qa
|Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
AA:Ro
|Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
KK/TY
}Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|Ss
}Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3Ua
}Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
4A4W
}Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.26.1.el7]`~@- selinux: fix deadlock in security_set_bools() (Ondrej Mosnacek) [1939091]
- md: fix md io stats accounting broken (Ming Lei) [1927106]
- redhat: Fix realtime_check for -private (Juri Lelli):Vo
}Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
//Y	
}Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]@X{
}Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.27.1.el7]`N@- video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (Mohammed Gamal) [1941841]
- Drivers: hv: vmbus: enable VMBus protocol version 5.0 (Mohammed Gamal) [1941841]
- redhat: Add git suffix to realtime_check merge_tree (Juri Lelli)
==>Zw
}Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
[#
}Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M\
}Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]
tt]	
~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]
==>^w
~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
_#
~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M`
~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+b'
~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}Ha
~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP  o
SzS"d?
~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]c}
~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
,,f-
~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.2.el7]`A- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]1e]
~Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+h'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}Hg
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP  s
SzS"j?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]i}
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
1k]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
l
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
m
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2o_
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]n'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\q}
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]p9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]

er+V:eD
828e5f8c216c003561b21fac3ee1c2a2c2d556fe14b7f7eb5cecff383dcdcddeD
df51484667e5b744416e438fadb87d6b7f90ebd7deb4e6682c6fb5544b4824d9D

39e6418349394ca9bdce4ea754f217c46186d4d7ac6e256c57becbcf78cb2932D	
c5f291e7ee7a541358f9f6a3957b58ba61670f95010f0fbfb4d6b94d30857d5cD
84a70ceb4fc3a611fb4f2317063db48a3627bf5b481b3c89956e1f1e9fa9f5fcD
078d626065367dc1b0c00d308d8b5d9d69fe369a31b59dbf38747ea1e98647dfD
b89f6284503fe622422027e205df72fde54169ba290d768ca1952506a29792cbD
05cf4fd79bba0f69976ed978e39e96312e5c1ed1fc98158138579aa9d2b1ac01D
1427f803b91f38e23ae66e6fb49eb6363167e457e76054fcb63fee011d6763b3D
6f1bbacef1dc67ded3f5dae9926f3a9422cbb14531e25cbb1668f8ac69d00b8dD
0952cfe96c702aedc34ce0dcba4f7bde61e7ef84de1ad0057e39e6750b2c0bdaD
8debaae538b7c7704b4ad782c4f0a725f3c0977f97d9cde4eb6a1546e54f02e7D
d196c69e20dcc6a970af086c699d1d015396019ac8638386994deb8017fcc72b
"r?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
1s]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
t
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
u
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2w_
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]v'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\z9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"y?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]x9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
{
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
|
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2~_
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]}'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
22I
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348 
nn9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]iQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
Y9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]
22I
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm	
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348 
i
Q
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7m
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!A
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7
m
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348 
iQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7m
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!A
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7m
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]
pepp_
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]+
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}
!+
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}n[
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig Z3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246] et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush  if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
,n[
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig Z3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]p_
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932] et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush  if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b

Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060 }
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
? 
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
"Q"$s1
Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []#s7
Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]%"I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]!
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}
F&s
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]j%sc
Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]
'+
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]
P)
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol ^(9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999+o
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] pow t*e
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command erpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
33n-[
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig X,-
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}bR!RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{ th uj vk wl xm yo zq |r }s ~t u w z { | ~       	 
               $ & ' ) + - / 1 3 4 5 6 9 : ; < ? @ ÁA āD ŁE ƁG ǁJ ȁL ɁP ʁR ́S ́W ΁X ЁY с[ ҁ^ ؁a ځb ہd ܁g i j l o p q s u v x y { } ~   !!!	!!!!	!
 et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush  if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
/
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060 .}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<0w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
QQ%3I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]2
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\47
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT 
PP+5U
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S6%
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
up%9I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]8
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\:7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT 
PP+;U
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S<%
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM?
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%>I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D@
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
((SA%
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpMD
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%CI
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}B
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77DE
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
%v%LG
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]F	
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d
J
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]I)
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]H-
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
%v%LL
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]K	
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d&PK
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
O
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]N)
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]M-
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
xxR#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lQW
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
TS'
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for  
3^O$3lWW
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&VK
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
U
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]T9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
iiX#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
TY'
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for  
G^G[#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]Z9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B^
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 Ӂ+\U
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}  CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816  CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227 ] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
MMa#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]l`W
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&_K
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
Tb'
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for  
G^Gd#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]c9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(Bg
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]f
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 ݁+eU
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}  CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816  CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227 ] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
i#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]Lh
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
Tj'
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for  
G^Gl#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]k9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(Bo
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]n
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 +mU
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}  CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816  CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227 ] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
Lp
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]
&&Uq)
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
s
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 r
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}

er+V:eD
6a5cc17610dacd423285c7b8f0036b7cdcfbc9fb0e513eca14b1d7d5ea047f7fD
07bd35c3abbf6026fb0e99d204b230ccbed3b91ccbed6d0675f5dc885931ea62D
bee03f8565ac02484c05292876b9c0976e9334dad12bbf643dd9f59526e9eb6dD
97ca74d50cef86200eaedf11cbb46855b4d2c943de9de770a9b024fbbf90ce3dD
b1471a49f356e514174b94e92dfc8993323e25a2de938cda266f9cd7d5850665D
8359e9ef711ab7df3dd2ff2d776303381cb9569b28010fc635d1dc38c63d0a3cD
70b9436a659665181aa90524926ff7ebeebcbc15038624b5a49e0657dedfb584D
61f3ebaaeea6b7aa7f2cb2e4e49d7030e15a0242954617931c4ca2d74e49c807D
9d5c67e50f13bee074d4860c206d81b8461ec0b7593a7cf3b207abe9f1e6f815D
a6114fbcf7f5bf08c4c84d6d0e2551e1175af5cd5b08fe5fa1557b575e292d02D
36f13b26a3b985a2d5e41a86724a23f3387adf18ce34902378ed32345f865d1aD
ff0af5a6e3acbbdec8607cb8aa6f258edbb87c22d9e2e162b476d366c16a6372D

64f15baadb874e4dcc756fc50e0f361c704a78fb0c5c3e1dee25e51bd7bc0347  CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816  CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227 ] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
hhLu
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]Bt
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
&&Uv)
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
ixQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@y
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7{m
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc z1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
wwL}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]3|e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
&&U~)
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
iQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7m
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc!1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
E)E_=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
iQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@	
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7m
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc!
1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
)E7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]
3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
WW1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
<e_=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]7m
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc!
_TH<w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]
Hd7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
((<w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]
HK!}
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3 e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t#g
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i"Q
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]!
&s
Jan Stancek <jstancek@redhat.com> [3.10.0-1152.el7]^- [nvmem] nvmem: properly handle returned value nvmem_reg_read (Vladis Drono!	%s!
Jan Stancek <jstancek@redhat.com> [3.10.0-1151.el7]^W@- [netdrv] qede: Fix multicast mac configuration (Michal Schmidt) [1740064]
- [scsi] sd_dif: avoid incorrect ref_tag errors on 4K devices larger than 2TB (Ewan Milne) [1833528]
- [hid] HID: hiddev: do clean!M$
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}up in failure of opening a device (Torez Smith) [1814257] {CVE-2019-19527}
- [hid] HID: hiddev: avoid opening a disconnected device (Torez Smith) [1814257] {CVE-2019-19527}
- [x86] x86: make mul_u64_u64_div_u64() "static inline" (Oleg Nesterov) [1845864]
- [mm] mm: page_isolation: fix potential warning from user (Rafael Aquini) [1845620]
- [s390] s390/mm: correct return value of pmd_pfn (Claudio Imbrenda) [1841106]
- [fs] fs/proc/vmcore.c:mmap_vmcore: skip non-ram pages reported by hypervisors (Lianbo Jiang) [1790799]
- [kernel] kernel/sysctl.c: ignore out-of-range taint bits introduced via kernel.tainted (Rafael Aquini) [1845356]
- [documentation] kernel: add panic_on_taint (Rafael Aquini) [1845356]
- [fs] ext4: Remove unwanted ext4_bread() from ext4_quota_write() (Lukas Czerner) [1845379]
- [scsi] scsi: sg: add sg_remove_request in sg_write ("Ewan D. Milne") [1840699] {CVE-2020-12770}
- [fs] fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (Donghai Qiao) [1832062] {CVE-2020-10732}!v) [1844409]
- [mailbox] PCC: fix dereference of ERR_PTR (Vladis Dronov) [1844409]
- [kernel] futex: Unlock hb->lock in futex_wait_requeue_pi() error path (Vladis Dronov) [1844409]
- [fs] aio: fix inconsistent ring state (Jeff Moyer) [1845326]
- [vfio] vfio/mdev: make create attribute static (Vladis Dronov) [1837549]
- [vfio] treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Synchronize device create/remove with parent removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid creating sysfs remove file on stale device removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Improve the create/remove sequence (Vladis Dronov) [1837549]
- [vfio] treewide: Add SPDX license identifier - Makefile/Kconfig (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid inline get and put parent helpers (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Fix aborting mdev child device removal if one fails (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Follow correct remove sequence (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid masking error code to EBUSY (Vladis Dronov) [1837549]
- [include] vfio/mdev: Drop redundant extern for exported symbols (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Removed unused kref (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid release parent reference during error path (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Add iommu related member in mdev_device (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: add static modifier to add_mdev_supported_type (Vladis Dronov) [1837549]
- [vfio] vfio: mdev: make a couple of functions and structure vfio_mdev_driver static (Vladis Dronov) [1837549]
- [char] tpm/tpm_tis: Free IRQ if probing fails (David Arcari) [1774698]
- [kernel] audit: fix a memleak caused by auditing load module (Richard Guy Briggs) [1843370]
- [kernel] audit: fix potential null dereference 'context->module.name' (Richard Guy Briggs) [1843370]
- [nvme] nvme: limit number of IO queues on Dell/Samsung config (David Milburn) [1837617]
AA(s
Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check !J's#
Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCD*s
Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o)sm
Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbj-sc
Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840],s1
Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []+s7
Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
h5)h<0w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}/
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]F.s
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
HK2}
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]31e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t4g
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i3Q
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]!
-6W
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M5
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
<<K9}
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]89
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t;g
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i:Q
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]!
-=W
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M<
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
?9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L>
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
1A1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_f!#J@
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<MC
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}?B{
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
NLE
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}-DW
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]
H1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_f!'JG
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)F9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<<?I{
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
dJE
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
p,p7Lk
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]OK
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
PN
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol!,^M9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999Po
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] pow!/tOe
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command!-erpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
yyR7
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han!1XQ-
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
fSI
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
ooT
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
oUY
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


qV]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
dWE
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
o,po|Zu
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]7Yk
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]OX
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Y}]w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B\
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"[A
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]
  ?`{
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.2.el7]ef@- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}4_e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^^9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
XBc
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"bA
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]|au
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]
}dw
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]
4fe
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^e9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bhA
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~gy
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
%n%"kA
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]j7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]i
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens!>
}mw
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]Bl
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}
4oe
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^n9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bqA
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~py
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
n+t	M
Radomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]s7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]r
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens!C

er+V:eD&
48050d32a9ddb2c79d03c638c04cd306724f7ac310231a77812108d47d170a94D%
995f1138e1de2ec2b063d80c34f72c7c9580839633287baad40f5b5b23f9e258D$
6e241bf0dc50bd058f110b48194543b466e895d9ce51ae777aa7f7d34f994e08D#
02cbd7332b3ce796fb31c211ff00e807700217dbe4cbf3860f61c4a3bb69beb8D"
69c2b3156d7f7348e92c9b6d94a15da2b8f77e0597041944eb9741c941e07001D!
d0f3c1d37d812e6fbf2b4e853fb66fd0ffe2a908b0bd0749ea1f99b53198ad71D 
349059abdcb4206de241619b0a997e70897934335a8863a2070dccf45c49f019D
08d3a3571d95f12d505af7454de2dadabca497aa265dbce4ff86b0317462b5dbD
44904175313b13552ac962d42d456dc5d52bface994ef485f56c33f7f6971440D
6a47e214a36fc58ad9b00ab50073240c79076c8bd04a01dd01029f8ca43122bdD
9c1793d4db51f7f371d7e73208f169004d3aba5ed38b51d28f55cdcc8cb7f3c0D
84b8b611d8300bcaa1b8a5f55f2a12f6469df74e32e649b9b505e76925339810D
3b37792998533e55b2ebe20d10052f6104ae209a5db1a84826bfde614e6d7c44dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
u7
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han!FbR!RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{!!
!!#!&!(!*!-!0!2!4!6!9!;! =!!?!"A!$C!%E!&H!(I!)J!*L!+N!.P!0R!2S!3T!4U!5V!6W!7Z!8]!9`!:c!;d!<f!=h!?k!@m!Ao!Bq!Dt!Gu!Iv!Jw!Kx!Ly!M{!O|!P~!Q!S!T!U!V	!X!Y!Z![!\!^!_!a!b!c!d!f!g!i!j !k!!l"!n#!o%!p'!r(!s)!t*!u+!w,!x.!y/!z0!{2!|3!}5!~7!8!9!:!;!<!=!>!@!B!D!F
fvI
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oow
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
oxY
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


qy]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
--R{
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE!N^z7
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
,,O|
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]
'~1
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.2.el7]`	l- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]T}#
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]
AAs
Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check !RJs#
Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDs
Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}osm
Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjsc
Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]s1
Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7
Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5+
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]Fs
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
	s
Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check !W^9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDs
Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}o
sm
Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjsc
Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]
s1
Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7
Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5+
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]Fs
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
^9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]
ww^7
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]!?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.2.el7]_- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
O
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]R
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE!]
?'?[1
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797!`T#
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4c
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]

Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend!e
?'?[1
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797!hT#
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4 c
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J!
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J"
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
#
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend!m
KK/%Y
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|$s
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
`H`['1
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [1901797!q3&a
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b(?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4)c
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J*
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J+
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
,
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend!v
KK/.Y
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|-s
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3/a
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
AA:0o
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
KK/2Y
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|1s
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH33a
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
4A45
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.26.1.el7]`~@- selinux: fix deadlock in security_set_bools() (Ondrej Mosnacek) [1939091]
- md: fix md io stats accounting broken (Ming Lei) [1927106]
- redhat: Fix realtime_check for -private (Juri Lelli):4o
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
//7	
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]@6{
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.27.1.el7]`N@- video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (Mohammed Gamal) [1941841]
- Drivers: hv: vmbus: enable VMBus protocol version 5.0 (Mohammed Gamal) [1941841]
- redhat: Add git suffix to realtime_check merge_tree (Juri Lelli)
==>8w
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
9#
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M:
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]
tt;	
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]
==><w
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
=#
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M>
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+@'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}H?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP !
SzS"B?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]A}
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
,,D-
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.2.el7]`A- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]1C]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+F'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}HE
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP !
SzS"H?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]G}
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
1I]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
J
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
K
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2M_
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]L'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\O}
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]N9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
"P?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
1Q]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
R
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
S
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2U_
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]T'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\X9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"W?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]V9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
Y
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
Z
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2\_
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]['
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\_9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"^?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]]9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
22I`
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mma
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348!
nnc9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]ibQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
Ye9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"d?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]
22If
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmg
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348!
ihQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_i=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7jm
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!lA
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7km
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmm
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [18348!
inQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_o=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7pm
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!rA
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7qm
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]
peppt_
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]s+
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}
!w+
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}nv[
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig!Zu3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]!et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush !if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r!eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]

er+V:eD3
c09c4232be25f378a871198874931161c40b1ce864dffbd95137c1d37205669cD2
2b66b267a753255256f090bf87977338168b89d26c4ffd982c87cd2f91b93577D1
f7211e59a025b27356cfb06417188c0dd5e275b865c332da16611d69cbc3addbD0
256f88bd5667a9d5534690123098dcb92c0e72a1a20c14cfc7fc6f93d1c33891D/
94a821399c6834a9613024e8e79095fed47945651c6f3043fb698f645b47ea98D.
46160c3e8468e10ca76482b787522ad64e1f769900fb6947b4bc6690893303cbD-
b3e690b11cafa64b176ad1733771549c822362e0515190949a20dd95d397be58D,
3c1b09a234b987d0d6b7eeda50bfd65fdd56ba1cd18a3d7bfaf6c502e6a18295D+
ba86ad50d0caa853696fbf8bb669856b215fcf866bddf9a40a79e2097b6bdac7D*
b045612fcdf478362a31afe42cbcbfa3696fd627cd7125c30615831a7f9c7831D)
ba701cb5769f4b33298d989a3a2f322062b88774a949cc71f4d59c46e785f253D(
7359842aed62ed18b7e387856697f0a6cf8b16b27c7c68064ba6567b32c76b6bD'
b96b6f75231c9bd50c073462605d9aa5494f79623d07db42df2d505c858be737
,nz[
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig!Zy3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]px_
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]!et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush !if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r!eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
|
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060!{}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?~
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<}w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
"Q"s1
Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7
Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]%I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}
Fs
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]jsc
Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]
+
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]
P
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol!^9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999	o
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] pow!ĉte
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command!erpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
33n[
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig!ƄX
-
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}!et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush !if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r!eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b


Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [203060!˂}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}bR"$RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{!I!J!K!M!O!P!Q!R!S!U!X!Y!Z!\!_!`!a!c!e!f!g!h!i!j!l!m!n!o!p!r!t!w!z!|!~!!!!!Á	!Ł!ʁ
!́!΁!Ё!с!ҁ!Ӂ!Ձ!ց!ׁ!؁!ف!ځ!ہ"!܁#!݁%!ށ(!߁*!.!0!1!5!6!7!9!<!?!@!B!E!G!H!J!M"N"O"Q"S"T"
V"W"Y"["\"^"_"a"d"f"g"i"m"o"s" w"!z"#}
QQ%I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT!
PP+U
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S%
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
up%I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT!
PP+U
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S%
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
((S%
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM"
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%!I
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492} 
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
%v%L%
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]$	
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d
(
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]')
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]&-
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
%v%L*
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408])	
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d&.K
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
-
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000],)
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]+-
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
xx0#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]l/W
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T1'
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for !
3^O$3l5W
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&4K
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]29
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
ii6#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T7'
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for !
G^G9#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]89
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B<
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856];
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825!+:U
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}! CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV!E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 !CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227!] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
MM?#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]l>W
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&=K
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T@'
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for !
G^GB#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]A9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(BE
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]D
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825!+CU
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}! CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV!E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 !CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227!] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
G#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]LF
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
TH'
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for !
G^GJ#
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]I9
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(BM
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]L
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825!+KU
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}! CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV"E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 "CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227"] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
LN
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]
&&UO)
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
Q
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825"P
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}" CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV"E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 "	CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227"
] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
hhLS
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]BR
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
&&UT)
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
iVQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]U
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@W
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7Ym
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc"X1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
wwL[
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]3Ze
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
&&U\)
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
i^Q
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@_
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7am
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc"`1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
E)E_d=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]c3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3be
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
ifQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@g
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7im
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc"h1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
)Em7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_l=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]k3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3je
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
WWo1
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]n
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
<e_s=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]r3
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3qe
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]7pm
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc"
_TH<ww
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}v
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]u
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]t7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]
Hdz7
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_y=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3xe
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]

er+V:eD@
1e71ddbce6e19382bbeabad1c266e4c7cb09e2a56d99175af4ac9ac047af3945D?
20135be9052bd1b2d8da133fe7cc987b80d4dc2685146012968f6b8e78e0bfe9D>
9bfce694395b42428b130fade4131953efe8248a166cb9df74a2681d8de08ecbD=
49aab94d53d2b184f6a56304123436d4e5036e2f12df6e2e89bef3f8e09e48c5D<
f08e9ea6985102fff682040f9282a64d08ae60b52a53ac25a2ae2d14b381049eD;
3594f2b7367495aba0e2ad40d7aeabb3ec7bcd176bfa09127a9021573f936f66D:
93e83a7482939b72a1377200f3ba36de2f5a593ed72db969095bca9b712022f4D9
b46ce984b02b31bec731f80328c745600ec4e07a5c031e77dbb554e88ba7fcbbD8
e855f087b1b23b7efc6503e87350c4cca1ef6881dc97c31f1512bcda747a478bD7
4de0f5c0f1ddd055c4b4b2635e35081b0a75f314bbe5cb8978790bfc21cebbc8D6
44c119ffc1f4001f24a6905dc7a8b1db1b192babbc6e3390b81e54adfb63b7b8D5
e161fe668a338dbcc5fd4207138cf06b234756554c7b000fd5627366c98b5f3aD4
738ba060f72edaaec140a48f940f7fdf573a9f888afd244b937e86cefba2f1ca
((<}w
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}|
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]{
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]
HK}
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3~e
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tg
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]"%
s
Jan Stancek <jstancek@redhat.com> [3.10.0-1152.el7]^- [nvmem] nvmem: properly handle returned value nvmem_reg_read (Vladis Drono")	s!
Jan Stancek <jstancek@redhat.com> [3.10.0-1151.el7]^W@- [netdrv] qede: Fix multicast mac configuration (Michal Schmidt) [1740064]
- [scsi] sd_dif: avoid incorrect ref_tag errors on 4K devices larger than 2TB (Ewan Milne) [1833528]
- [hid] HID: hiddev: do clean"(M
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}up in failure of opening a device (Torez Smith) [1814257] {CVE-2019-19527}
- [hid] HID: hiddev: avoid opening a disconnected device (Torez Smith) [1814257] {CVE-2019-19527}
- [x86] x86: make mul_u64_u64_div_u64() "static inline" (Oleg Nesterov) [1845864]
- [mm] mm: page_isolation: fix potential warning from user (Rafael Aquini) [1845620]
- [s390] s390/mm: correct return value of pmd_pfn (Claudio Imbrenda) [1841106]
- [fs] fs/proc/vmcore.c:mmap_vmcore: skip non-ram pages reported by hypervisors (Lianbo Jiang) [1790799]
- [kernel] kernel/sysctl.c: ignore out-of-range taint bits introduced via kernel.tainted (Rafael Aquini) [1845356]
- [documentation] kernel: add panic_on_taint (Rafael Aquini) [1845356]
- [fs] ext4: Remove unwanted ext4_bread() from ext4_quota_write() (Lukas Czerner) [1845379]
- [scsi] scsi: sg: add sg_remove_request in sg_write ("Ewan D. Milne") [1840699] {CVE-2020-12770}
- [fs] fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (Donghai Qiao) [1832062] {CVE-2020-10732}"*v) [1844409]
- [mailbox] PCC: fix dereference of ERR_PTR (Vladis Dronov) [1844409]
- [kernel] futex: Unlock hb->lock in futex_wait_requeue_pi() error path (Vladis Dronov) [1844409]
- [fs] aio: fix inconsistent ring state (Jeff Moyer) [1845326]
- [vfio] vfio/mdev: make create attribute static (Vladis Dronov) [1837549]
- [vfio] treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Synchronize device create/remove with parent removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid creating sysfs remove file on stale device removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Improve the create/remove sequence (Vladis Dronov) [1837549]
- [vfio] treewide: Add SPDX license identifier - Makefile/Kconfig (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid inline get and put parent helpers (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Fix aborting mdev child device removal if one fails (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Follow correct remove sequence (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid masking error code to EBUSY (Vladis Dronov) [1837549]
- [include] vfio/mdev: Drop redundant extern for exported symbols (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Removed unused kref (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid release parent reference during error path (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Add iommu related member in mdev_device (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: add static modifier to add_mdev_supported_type (Vladis Dronov) [1837549]
- [vfio] vfio: mdev: make a couple of functions and structure vfio_mdev_driver static (Vladis Dronov) [1837549]
- [char] tpm/tpm_tis: Free IRQ if probing fails (David Arcari) [1774698]
- [kernel] audit: fix a memleak caused by auditing load module (Richard Guy Briggs) [1843370]
- [kernel] audit: fix potential null dereference 'context->module.name' (Richard Guy Briggs) [1843370]
- [nvme] nvme: limit number of IO queues on Dell/Samsung config (David Milburn) [1837617]
AAs
Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check ",Js#
Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDs
Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}osm
Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjsc
Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]
s1
Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []	s7
Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5}i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-45^r
@- mkdumprd: Use DUMP_TARGET which printing error message during sshti
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-44^f/- module-setup: Ensure eth devices get IP address for VLAN0
iy
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-43]@- module-setup: re-fix 99kdumpbase network dependency
- kdumpctl: bail out immediately if host key verification failedFs
Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
a~i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51^- Add a new option 'rd.znet_ifname' in order to use it in udev ruleswi
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-50^V@- Revert: Always set vm.zone_reclaim_mode = 3 in kdump kerneli
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-49^- dracut-module-setup.sh: fix breakage in get_pcs_fence_kdump_nodes().,iq
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-48^_- dracut-module-setup.sh: ensure cluster info is ready before query.
- dracut-module-setup.sh: improve get_alias()iQ
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-47^|@- mkdumprd: don't append noauto to mount option.
- Add NOTE about nr_cpus value on HyperV systems.iM
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-46^x- Always drop nofail or nobootwait options
- Always set vm.zone_reclaim_mode = 3 in kdump kernel
t{;,iq
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-48^_- dracut-module-setup.sh: ensure cluster info is ready before query.
- dracut-module-setup.sh: improve get_alias()iQ
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-47^|@- mkdumprd: don't append noauto to mount option.
- Add NOTE about nr_cpus value on HyperV systems.iM
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-46^x- Always drop nofail or nobootwait options
- Always set vm.zone_reclaim_mode = 3 in kdump kernel}i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-45^r
@- mkdumprd: Use DUMP_TARGET which printing error message during sshti
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-44^f/- module-setup: Ensure eth devices get IP address for VLANm#
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51.1_V - makedumpfile/sadump: Fix a KASLR problem of sadump while kdump is working
V{~vV"iM
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-46^x- Always drop nofail or nobootwait options
- Always set vm.zone_reclaim_mode = 3 in kdump kernel}!i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-45^r
@- mkdumprd: Use DUMP_TARGET which printing error message during sshx a
Pingfan Liu <piliu@redhat.com> 2.0.15-51.2`B@- kdumpctl: fix a variable expansion in check_fence_kdump_config()m#
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51.1_V - makedumpfile/sadump: Fix a KASLR problem of sadump while kdump is working~i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51^- Add a new option 'rd.znet_ifname' in order to use it in udev ruleswi
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-50^V@- Revert: Always set vm.zone_reclaim_mode = 3 in kdump kerneli
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-49^- dracut-module-setup.sh: fix breakage in get_pcs_fence_kdump_nodes().
$_),$x)a
Pingfan Liu <piliu@redhat.com> 2.0.15-51.2`B@- kdumpctl: fix a variable expansion in check_fence_kdump_config()(m#
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51.1_V - makedumpfile/sadump: Fix a KASLR problem of sadump while kdump is working~'i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51^- Add a new option 'rd.znet_ifname' in order to use it in udev rulesw&i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-50^V@- Revert: Always set vm.zone_reclaim_mode = 3 in kdump kernel%i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-49^- dracut-module-setup.sh: fix breakage in get_pcs_fence_kdump_nodes().,$iq
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-48^_- dracut-module-setup.sh: ensure cluster info is ready before query.
- dracut-module-setup.sh: improve get_alias()#iQ
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-47^|@- mkdumprd: don't append noauto to mount option.
- Add NOTE about nr_cpus value on HyperV systems.
cC/iQ
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-47^|@- mkdumprd: don't append noauto to mount option.
- Add NOTE about nr_cpus value on HyperV systems..iM
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-46^x- Always drop nofail or nobootwait options
- Always set vm.zone_reclaim_mode = 3 in kdump kernel}-i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-45^r
@- mkdumprd: Use DUMP_TARGET which printing error message during ssht,i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-44^f/- module-setup: Ensure eth devices get IP address for VLAN0+iy
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-43]@- module-setup: re-fix 99kdumpbase network dependency
- kdumpctl: bail out immediately if host key verification failedl*a{
Pingfan Liu <piliu@redhat.com> 2.0.15-51.3`e@- Throttle kdump reload request triggered by udev event
HOOAH}6i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-45^r
@- mkdumprd: Use DUMP_TARGET which printing error message during ssht5i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-44^f/- module-setup: Ensure eth devices get IP address for VLAN4m#
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51.1_V - makedumpfile/sadump: Fix a KASLR problem of sadump while kdump is working~3i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51^- Add a new option 'rd.znet_ifname' in order to use it in udev rulesw2i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-50^V@- Revert: Always set vm.zone_reclaim_mode = 3 in kdump kernel1i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-49^- dracut-module-setup.sh: fix breakage in get_pcs_fence_kdump_nodes().,0iq
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-48^_- dracut-module-setup.sh: ensure cluster info is ready before query.
- dracut-module-setup.sh: improve get_alias()
a~<i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51^- Add a new option 'rd.znet_ifname' in order to use it in udev rulesw;i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-50^V@- Revert: Always set vm.zone_reclaim_mode = 3 in kdump kernel:i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-49^- dracut-module-setup.sh: fix breakage in get_pcs_fence_kdump_nodes().,9iq
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-48^_- dracut-module-setup.sh: ensure cluster info is ready before query.
- dracut-module-setup.sh: improve get_alias()8iQ
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-47^|@- mkdumprd: don't append noauto to mount option.
- Add NOTE about nr_cpus value on HyperV systems.7iM
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-46^x- Always drop nofail or nobootwait options
- Always set vm.zone_reclaim_mode = 3 in kdump kernel
tw7,Biq
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-48^_- dracut-module-setup.sh: ensure cluster info is ready before query.
- dracut-module-setup.sh: improve get_alias()AiQ
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-47^|@- mkdumprd: don't append noauto to mount option.
- Add NOTE about nr_cpus value on HyperV systems.@iM
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-46^x- Always drop nofail or nobootwait options
- Always set vm.zone_reclaim_mode = 3 in kdump kernel}?i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-45^r
@- mkdumprd: Use DUMP_TARGET which printing error message during sshx>a
Pingfan Liu <piliu@redhat.com> 2.0.15-51.2`B@- kdumpctl: fix a variable expansion in check_fence_kdump_config()=m#
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51.1_V - makedumpfile/sadump: Fix a KASLR problem of sadump while kdump is working
Q{~vQ0Iiy
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-43]@- module-setup: re-fix 99kdumpbase network dependency
- kdumpctl: bail out immediately if host key verification failedlHa{
Pingfan Liu <piliu@redhat.com> 2.0.15-51.3`e@- Throttle kdump reload request triggered by udev eventxGa
Pingfan Liu <piliu@redhat.com> 2.0.15-51.2`B@- kdumpctl: fix a variable expansion in check_fence_kdump_config()Fm#
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51.1_V - makedumpfile/sadump: Fix a KASLR problem of sadump while kdump is working~Ei
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51^- Add a new option 'rd.znet_ifname' in order to use it in udev ruleswDi
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-50^V@- Revert: Always set vm.zone_reclaim_mode = 3 in kdump kernelCi
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-49^- dracut-module-setup.sh: fix breakage in get_pcs_fence_kdump_nodes().
hwPi
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-50^V@- Revert: Always set vm.zone_reclaim_mode = 3 in kdump kernelOi
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-49^- dracut-module-setup.sh: fix breakage in get_pcs_fence_kdump_nodes().,Niq
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-48^_- dracut-module-setup.sh: ensure cluster info is ready before query.
- dracut-module-setup.sh: improve get_alias()MiQ
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-47^|@- mkdumprd: don't append noauto to mount option.
- Add NOTE about nr_cpus value on HyperV systems.LiM
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-46^x- Always drop nofail or nobootwait options
- Always set vm.zone_reclaim_mode = 3 in kdump kernel}Ki
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-45^r
@- mkdumprd: Use DUMP_TARGET which printing error message during sshtJi
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-44^f/- module-setup: Ensure eth devices get IP address for VLAN
~zZViQ
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-47^|@- mkdumprd: don't append noauto to mount option.
- Add NOTE about nr_cpus value on HyperV systems.UiM
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-46^x- Always drop nofail or nobootwait options
- Always set vm.zone_reclaim_mode = 3 in kdump kernel}Ti
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-45^r
@- mkdumprd: Use DUMP_TARGET which printing error message during sshtSi
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-44^f/- module-setup: Ensure eth devices get IP address for VLANRm#
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51.1_V - makedumpfile/sadump: Fix a KASLR problem of sadump while kdump is working~Qi
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51^- Add a new option 'rd.znet_ifname' in order to use it in udev rules
DOOAD}]i
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-45^r
@- mkdumprd: Use DUMP_TARGET which printing error message during sshx\a
Pingfan Liu <piliu@redhat.com> 2.0.15-51.2`B@- kdumpctl: fix a variable expansion in check_fence_kdump_config()[m#
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51.1_V - makedumpfile/sadump: Fix a KASLR problem of sadump while kdump is working~Zi
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51^- Add a new option 'rd.znet_ifname' in order to use it in udev ruleswYi
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-50^V@- Revert: Always set vm.zone_reclaim_mode = 3 in kdump kernelXi
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-49^- dracut-module-setup.sh: fix breakage in get_pcs_fence_kdump_nodes().,Wiq
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-48^_- dracut-module-setup.sh: ensure cluster info is ready before query.
- dracut-module-setup.sh: improve get_alias()
a~ci
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51^- Add a new option 'rd.znet_ifname' in order to use it in udev ruleswbi
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-50^V@- Revert: Always set vm.zone_reclaim_mode = 3 in kdump kernelai
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-49^- dracut-module-setup.sh: fix breakage in get_pcs_fence_kdump_nodes().,`iq
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-48^_- dracut-module-setup.sh: ensure cluster info is ready before query.
- dracut-module-setup.sh: improve get_alias()_iQ
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-47^|@- mkdumprd: don't append noauto to mount option.
- Add NOTE about nr_cpus value on HyperV systems.^iM
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-46^x- Always drop nofail or nobootwait options
- Always set vm.zone_reclaim_mode = 3 in kdump kernel
t&FigA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[hgQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^ggY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129lfa{
Pingfan Liu <piliu@redhat.com> 2.0.15-51.3`e@- Throttle kdump reload request triggered by udev eventxea
Pingfan Liu <piliu@redhat.com> 2.0.15-51.2`B@- kdumpctl: fix a variable expansion in check_fence_kdump_config()dm#
Bhupesh Sharma <bhsharma@redhat.com> 2.0.15-51.1_V - makedumpfile/sadump: Fix a KASLR problem of sadump while kdump is working
^0	W^tni
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-mis
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762liO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560ki
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Kji/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441
;m;Kti/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441sgA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[rgQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^qgY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129pi
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159oi5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401
y'.yi5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401txi
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-wis
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762viO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560ui
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560
Gx6Gi
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560K~i/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441}gA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[|gQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^{gY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129zi
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159

er+V:eDM
6f455484f1eb5f3b6fb66db239a002b80058c5b1b96396b1f9845be413af51dfDL
f136bc0eecf5d5320db54998eac1c4599ab87a312d5ce7a2cefc841ab054b1eaDK
7bddd4fb53bfa9c6ecfb51584e6173525154d1432fdd23c18162b8a5428fd9c2DJ
ebe9101eafa195e97d5191257396d826d54a03212851b56130c2502068cb8f4cDI
0e46815b96448a8115c16703aeaeadf07680cb2172f0028f3a8ab4b9d6e6897dDH
1e050a70197e546f07c1f78ed2e33fa01d93756947ab17d6c3343eaf08eb2702DG
14290884418bd83ad4955aa6354b2113950b766239244a06bee2f2a364ba608fDF
f901d903838a840af4b07b7405171f08944a919391efff75f782b9d2c5a6a8a7DE
ca22627ed1921f923bf0d6590573bb115ae89ab16f2cd8439ca78680ac859464DD
3db947e6e862b89a0ca5b23880b8c910b68d3c16831d17f914d62706e4e337dbDC
f6eec5c1e694fd7e8232482c537de9cd0baf38de7afc7c99fee2ddf4b248488dDB
8d2234f4b3652ffa6caf553d843f040d43d53c10ec6156b8de9fbd3efb4aef2cDA
6a2fc5bcfdf2c8ed011976da11bfa2c4e64084e1f45d265f784bcd58fbece989
8`"8^gY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159i5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401ti
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-is
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762iO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560
 1
iO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560	i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Ki/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441gA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[gQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
NU:^gY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159
i5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401ti
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-is
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
 1iO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Ki/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441gA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[gQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
NU:^gY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159i5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401ti
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-is
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
 1iO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Ki/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441gA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[gQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
NU:#qK
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-125\d- Modify 0250-RHBZ-1610867-rescan-change.patch
  * Fix memory Leak
- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix NULL dereference
- Refresh 0252-RHBZ-1623595-cmd-error-status.patch
- Resolves: bz #1610867, #1638651"i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159!i5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401t i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-is
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
c%q'
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556$qA
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651
LL/&qo
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0)qq
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066(q}
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q'qs
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
 +> -qA
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651},q
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h+qa
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P*q1
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
pp.q'
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
LL//qo
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O02qq
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #171450661q}
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q0qs
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
"+>"6q=
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}5q
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h4qa
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P3q1
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
pp7q'
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
LL/8qo
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0;qq
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066:q}
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q9qs
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
+>"|Am
Robbie Harwood <rharwood@redhat.com> - 1.15.1-41]>- Update man pages to reference kerberos(7)
- Resolves: #1704726@q
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-136cG- Add 0274-UP-no-duplicate-command-keys.patch
- Resolves: bz #2134905?q=
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}>q
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h=qa
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P<q1
Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420bR"RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{"&"'"+"-"."/"0"1"2""3)"4/"56"6<"7B"8I"9P":V";]"<c"=i">n"?t"@y"A"C"D
"E"F"G"H"I#"J%"K&"L)"M-"N."O/"P2"Q6"R7"S8"T;"UA"WH"XO"YV"Z]"[d"\k"]r"^y"_"a"b"c"d"e#"f*"g1"h8"i?"jF"kM"lT"m["nb"oi"pp"qw"r~"t"u"v"w"x!"y("z/"{6"|="}D"~K"R"Y"`"g"n"u"|"""""" "%"*"/"4
v
Hm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Gm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oFmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126eEma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|Dm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506Cm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|Bm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927
}xneOma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|Nm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506Mm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|Lm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927|Km
Robbie Harwood <rharwood@redhat.com> - 1.15.1-41]>- Update man pages to reference kerberos(7)
- Resolves: #1704726Jm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492Im
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492
r|rVm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|Um
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927Tm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492Sm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Rm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Qm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oPmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126
]m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492\m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492[m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Zm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oYmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126eXma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|Wm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506
{g]t{dm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289ocmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126ebma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|am
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506`m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|_m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927^m=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599
}u\okmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126ejma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|im
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506hm=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599gm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492fm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492em
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492
9ztV9ri
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163qi;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319pm=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599om
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492nm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492mm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492lm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289
ym
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492xm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492wm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492vm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oumu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126etma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|sm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506
egJnem
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289o~mu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126e}ma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|i
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163{i;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319zm=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599

er+V:eDZ
79effda42d229dffeed9ec2dc1067ea15c3d1895c9bdfe9d24064abaa134d7a7DY
82f169e42c36e9579026a6d56d46f2cbe59221a611192fe96b613ff527e57a1cDX
8c1afba082bedaba9392d11b613759a65431711c73e71af2ca4c1d2710b71ac5DW
0b514834510f57ab09a2051d0b0c2be8a61777452ad125d1b3e5e90abeb6fa22DV
f7291bdf6020187d7cf5369c95f16faeef861f866ffc8c46c03116ea2adf9092DU
617fff79ce97ec5ee66c7f45cec546ea2429f9ce776263cf40a0b246665913e1DT
cf61322c3e87c6c21ad8be1051fa2d235337e2a97a9a894828a70e5cd12a2254DS
03cf1dde125c19d5d48038e69f3552a4973548aa09dc383debd850eec84fa1a4DR
56773da33ba948469db1f7ab9d9bc267d2e29b3458b2d1376573c09525ad4581DQ
f89d39e2f15a5f9de6ac154edd1ca68886b384c0e12ef5657eb722c92e9c0788DP
789245b54d2cc37181b3209ca55431722601a4544e987a98c0953c1b64660406DO
b3cdcec7059a05b036622e2b2326259602d28b19672e0fe8766f1b0c59537bc9DN
fbc2fabe0f2dd520e1af93518f0669fbb0c91b469d7508a7402404cbbea73b6d
J}_BJema
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726
i-
Julien Rische <jrische@redhat.com> - 1.15.1-55cjD- Fix integer overflows in PAC parsing (CVE-2022-42898)
- Resolves: rhbz#2140961i
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163i;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319m=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492
M|Mi;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319
m=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492
m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492	m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289omu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126
wyj`wema
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927|m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-41]>- Update man pages to reference kerberos(7)
- Resolves: #1704726
i-
Julien Rische <jrische@redhat.com> - 1.15.1-55cjD- Fix integer overflows in PAC parsing (CVE-2022-42898)
- Resolves: rhbz#2140961i
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163
||||m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927|m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-41]>- Update man pages to reference kerberos(7)
- Resolves: #1704726m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289omu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126
v#m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492"m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492!m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289o mu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126ema
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347
{q*m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289o)mu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126e(ma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|'m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506&m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|%m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927$m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492
R}u\R|1m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #16635060m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|/m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927.m=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599-m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492,m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492+m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492
z$z8m=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #19975997m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #17824926m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #17824925m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #17824924m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289o3mu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126e2ma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726
?m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492>m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492=m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492<m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289o;mu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126e:ma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|9m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506
hgJahFm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oEmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126eDma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|Cm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506Bi
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163Ai;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319@m=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599
V}uFVeMma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726Li
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163Ki;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319Jm=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599Im
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492Hm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Gm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492
M|MTi;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319Sm=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599Rm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492Qm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Pm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Om
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oNmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126
y[m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Zm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Ym
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oXmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126eWma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726
Vi-
Julien Rische <jrische@redhat.com> - 1.15.1-55cjD- Fix integer overflows in PAC parsing (CVE-2022-42898)
- Resolves: rhbz#2140961Ui
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163
6{L66|bm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927|am
Robbie Harwood <rharwood@redhat.com> - 1.15.1-41]>- Update man pages to reference kerberos(7)
- Resolves: #1704726
`i-
Julien Rische <jrische@redhat.com> - 1.15.1-55cjD- Fix integer overflows in PAC parsing (CVE-2022-42898)
- Resolves: rhbz#2140961_i
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163^i;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319]m=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599\m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492
vim
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492hm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492gm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289ofmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126eema
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|dm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506cm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347
{qpm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oomu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126enma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|mm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506lm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|km
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927jm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492
}u\owmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126evma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|um
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506tm=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599sm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492rm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492qm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492
9ztV9~i
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163}i;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319|m=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599{m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492zm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492ym
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492xm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289

er+V:eDg
caf7f0adf042b63657e0610f87dbb3aa3334f9a81292aa836ddc648117954f9dDf
81bcb4324bc25258c6e46c0bdc146842422c22344fda2af0164660b98db7c0dcDe
249e4941a5a5071a668ba290a7dc5e28013fd43206a9a9b2a2a236220aee04ddDd
8398bd6b079096f5128dc71162f6fb902418319a1f157c08cd55e55ea7b42815Dc
9f8bb077bbb9a1599bd7dfb6b7973517ca6a23674134edc3822c31d459a0fcf0Db
ea48b9fb3553584f758b7a3b5b3689740e4d04e82eb6d0359b8fecbde72b9b23Da
87aee3a9528b247730a778c50eab6e97da58d331049a063fa5f651d993db29d5D`
63c82c1e8917281adf931c995b90cce5c368fb95285f2659b691785c1fdd6a86D_
2da57e3f11f7feb8e50c18578d16794bb2a9a020b5c7c2a5ed12d4c49a0e597dD^
180fe822e8d8229970daac8f8d746b4a0b83877121f93490003022ee941544c1D]
9d8090a78aa40baa54d3800a01ae8e374a61c7be5587eb90bc2cf279a1c29e2eD\
196df95b9b19a08f79321b9b3709379e9fbdf71dd5cdc4d74bd313d84468f412D[
b64165d72cf869748c81b8e41581c93b8354747c22d548ae910ab54e118a90a5
z$zm=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289omu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126ema
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726
JjTTJ|m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|
m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927|	m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-41]>- Update man pages to reference kerberos(7)
- Resolves: #1704726
i-
Julien Rische <jrische@redhat.com> - 1.15.1-55cjD- Fix integer overflows in PAC parsing (CVE-2022-42898)
- Resolves: rhbz#2140961i
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163i;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319
$|m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289omu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126e
ma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726
vm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289omu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126ema
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347
}{b}!m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492 m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289omu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126ema
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506m=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492
f}_Bfo(mu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126e'ma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726&i
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163%i;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319$m=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599#m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492"m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492
9ztV9/i
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163.i;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319-m=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599,m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492+m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492*m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492)m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289
qqgo6mu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126e5ma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|4m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #16635063m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|2m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927|1m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-41]>- Update man pages to reference kerberos(7)
- Resolves: #1704726
0i-
Julien Rische <jrische@redhat.com> - 1.15.1-55cjD- Fix integer overflows in PAC parsing (CVE-2022-42898)
- Resolves: rhbz#2140961
eztoe|=m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506<m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|;m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927:m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #17824929m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #17824928m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #17824927m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289
z$zDm=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599Cm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492Bm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Am
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492@m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289o?mu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126e>ma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726
Km
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492Jm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Im
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Hm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oGmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126eFma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|Em
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506
egJneRm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Qm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oPmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126eOma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726Ni
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163Mi;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319Lm=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599
3}_B3|Ym
Robbie Harwood <rharwood@redhat.com> - 1.15.1-41]>- Update man pages to reference kerberos(7)
- Resolves: #1704726
Xi-
Julien Rische <jrische@redhat.com> - 1.15.1-55cjD- Fix integer overflows in PAC parsing (CVE-2022-42898)
- Resolves: rhbz#2140961Wi
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163Vi;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319Um=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599Tm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492Sm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492
v
`m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492_m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289o^mu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126e]ma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|\m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506[m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|Zm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927
}xnogmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126efma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|em
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506dm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|cm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927bm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492am
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492
mztVmenma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|mm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506lm=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599km
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492jm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492im
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492hm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289
M|Mui;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319tm=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599sm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492rm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492qm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492pm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oomu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126
y|m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492{m
Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492zm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492ym
Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oxmu
Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126ewma
Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726vi
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163
gJ:{C
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-36Y- Fix setting terminal foreground process group while resuming process
  Resolves: #1457990}{
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-35Y- Fix warning while creating kia file
  Resolves: #1438045
i-
Julien Rische <jrische@redhat.com> - 1.15.1-55cjD- Fix integer overflows in PAC parsing (CVE-2022-42898)
- Resolves: rhbz#2140961i
Julien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163~i;
Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319}m=
Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599

er+V:eDt
e377bae670c12638d474197ef518748c1e088342df7e30d7b48305b688397f86Ds
cadd165d38724eb665db004d9c8b750aecb7c5d88cafaecac40cf6bd136bc3b9Dr
61f2ce61f188dc44b4bac40752a37aceb51e5ab3ad31e9832585553728f1153aDq
5475ede3cff8776a20cbf47c4b3c85074267733ee7b25756385442d60aa680c8Dp
350bcc459207279a04b2e6c772304349c7c5d63b58f4b52efe0c5856681203c4Do
d83df69f3f8696e0c3baee4eb2d4a692612706bad980d06d71759195aefe28a4Dn
f51bb9d1fa63c5bb467fc5024de79c68a580bffb93e0ee00dad4ffd1edfb0dc6Dm
6e73c8cf692c96778253ff1dcfb1fa2fbff0c5bd4b3bb64b10dd7cc1b5edc4acDl
3bba9df9a126294f1b6d125afef0399b652648e92446de453d3f9aa966726dc7Dk
8717e76e453ff6da56721f14fb3f66a602f200c27eb0d7730ad11ad9f0e696c4Dj
7f527d338cce3e1cb86323b7257ae02c7e130d6c37bc6ff07f75a20ad82a2e25Di
86b8329276455f1ab7137f0bfbed2c18288a75bb75932393695583ae82613063Dh
09c46bafc8f7871f9037631642128c520e108bc7b90ffdfffbd477c7ea27543e
T+0'}S
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-141^0"@- Do not evaluate arithmetic expressions from environment variables at startup
  Resolves: #1790544{}}
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-140]S- Add virtual provides for /bin/ksh
  Resolves: #1690042x}w
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-139[@- Fix a crash caused by memcmp()
  Resolves: #1546749}
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-138[@- Fix a crash due to out of bounds write
  Resolves: #1506347iU
Kamil Dudka <kdudka@redhat.com> - 20120801-137Z- Increase the release number by 100 to make sure it stays higher than in RHEL-6
  Related: #1484937'{U
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-37Zhu@- Add configuration option to enable signal bubbling for backward compatibility
  Resolves: #1484937
*{,*x}w
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-139[@- Fix a crash caused by memcmp()
  Resolves: #1546749}
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-138[@- Fix a crash due to out of bounds write
  Resolves: #1506347
iU
Kamil Dudka <kdudka@redhat.com> - 20120801-137Z- Increase the release number by 100 to make sure it stays higher than in RHEL-6
  Related: #1484937'{U
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-37Zhu@- Add configuration option to enable signal bubbling for backward compatibility
  Resolves: #1484937{C
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-36Y- Fix setting terminal foreground process group while resuming process
  Resolves: #1457990n
{e
Vincent Mihalkovic <vmihalko@redhat.com> - 20120801-143aV@- Stack robustness fixes
  Related: #2007364l	}_
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-142^J@- Bump version number
  Related: #1790544
3eu3[gQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^gY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129z{}
Vincent Mihalkovic <vmihalko@redhat.com> - 20120801-144b
- Stack robustness additional fixes
  Resolves: #2053503n{e
Vincent Mihalkovic <vmihalko@redhat.com> - 20120801-143aV@- Stack robustness fixes
  Related: #2007364l}_
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-142^J@- Bump version number
  Related: #1790544'}S
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-141^0"@- Do not evaluate arithmetic expressions from environment variables at startup
  Resolves: #1790544{}}
Siteshwar Vashisht <svashisht@redhat.com> - 20120801-140]S- Add virtual provides for /bin/ksh
  Resolves: #1690042
hq-is
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762iO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Ki/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441gA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002
t[ gQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^gY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159i5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401ti
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048
hq-%is
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762$iO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560#i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560K"i/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441!gA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002
t[*gQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^)gY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129(i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159'i5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401t&i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048
hq-/is
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762.iO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560-i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560K,i/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441+gA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002
t[4gQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^3gY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#12601292i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#18561591i5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401t0i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048
hq-9is
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#16117628iO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#13425607i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560K6i/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#13334415gA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002
t[>gQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^=gY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129<i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159;i5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401t:i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048
hq-Cis
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762BiO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560Ai
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560K@i/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441?gA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002
t[HgQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^GgY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129Fi
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159Ei5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401tDi
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048
hq-Mis
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762LiO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560Ki
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560KJi/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441IgA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002
t[RgQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^QgY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129Pi
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159Oi5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401tNi
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048
hq-Wis
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762ViO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560Ui
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560KTi/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441SgA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002
t[\gQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^[gY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129Zi
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159Yi5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401tXi
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048
hq-ais
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762`iO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560_i
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560K^i/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441]gA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002
t[fgQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^egY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129di
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159ci5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401tbi
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048
hq-kis
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762jiO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560ii
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Khi/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441ggA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002
t[pgQ
Jan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^ogY
Jan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129ni
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159mi5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401tli
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048
hq-uis
Jan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762tiO
Jan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560si
Jan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Kri/
Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441qgA
Jan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002
#t(#d{ak
John Dennis <jdennis@redhat.com> - 2.5.1-1WYZ@- Rebase to upstream 2.5.1
  Resolves: #1310860zaQ
John Dennis <jdennis@redhat.com> - 2.5.0-1U6@- Rebase to upstream, now includes our ECP patches, no need to patch any more
  Resolves: #1205342?ya
John Dennis <jdennis@redhat.com> - 2.4.1-8U@- Add explicit minimum dependency on glib2 2.42,
  for some reason RPM is not automatically detecting the dependency
  Resolves: #1254989xi
Jan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159wi5
Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401tvi
Jan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048
MsM5~c	
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-4]6- Resolves: #1730009 - lasso includes "Destination" attribute in SAML
                       AuthnRequest populated with SP
                       AssertionConsumerServiceURL when ECP workflow
                       is used which leads to IdP-side errorsg}cm
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-3\`@- Resolves: #1634267 - ECP signature check fails with
                       LASSO_DS_ERROR_SIGNATURE_NOT_FOUND when assertion signed
                       instead of response|a1
John Dennis <jdennis@redhat.com> - 2.5.1-2Wc@- Rebase to upstream 2.5.1
  Resolves: #1310860
- add validate_idp_list_test patch
Iqc
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-7`r- Fix Coverity warning introduced by the previous patch
- Related: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                      vulnerability when parsing SAML responses;c
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-6`r- Resolves: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                       vulnerability when parsing SAML responses2c
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-5]Ik- Resolves: #1719014 - Expired certificate prevents tests from running
- Actually apply the patch file for the previous build
- Related: #1730009 - lasso includes "Destination" attribute in SAML
                       AuthnRequest populated with SP
                       AssertionConsumerServiceURL when ECP workflow
                       is used which leads to IdP-side errors

FAa1
John Dennis <jdennis@redhat.com> - 2.5.1-2Wc@- Rebase to upstream 2.5.1
  Resolves: #1310860
- add validate_idp_list_test patchdak
John Dennis <jdennis@redhat.com> - 2.5.1-1WYZ@- Rebase to upstream 2.5.1
  Resolves: #1310860aQ
John Dennis <jdennis@redhat.com> - 2.5.0-1U6@- Rebase to upstream, now includes our ECP patches, no need to patch any more
  Resolves: #1205342?a
John Dennis <jdennis@redhat.com> - 2.4.1-8U@- Add explicit minimum dependency on glib2 2.42,
  for some reason RPM is not automatically detecting the dependency
  Resolves: #1254989qc
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-8`r- Fix Coverity warning introduced by the previous patch
- Related: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                      vulnerability when parsing SAML responses

er+V:eD
9d8f852847d542b8ca3a8f7afddddd363dfd43bfa65cfbf6dfc8aa04498417daD
c053243ee1cb35d96150add59e7a1c0861276f5b2a3a9ca734501801a605c029D
fdbe2525e655b8cf975f2027191bcc9231946f75aa3196dd6bc68d144b98da20D~
a95d1f4bc03b57d5bf45411152deb77c11b8f7e7eea468e1ac9786e41c70b339D}
2a27d4cd848272f9c9e4251b28efc591660799054bcd62d321892c0a8a608f9dD|
232113158f29ca0be28b87fea599e2ceb671ea597d510b952fa9490d78950783D{
e08f5391f6f27a9c77207532b12000e6771dbbab3411de893ea6640343d7c557Dz
27258fffe6d62545a0a0c40b4e07b0f92e1a3b79588415f8f1242624918720bcDy
67364ca692de365478eee5a94879717c1fae2b7a4ba46d128ec04f0477c8c2b5Dx
0ff1974a6100b7f2cbd7eed090daafd948fcf3710a299e3b612fb23e609059deDw
82146c665ec6adb6b5a44f5163ac78834431f9d37ddbeee4cc990634d979481bDv
41389a794b7cc04dd2e3fd21ff891d278296ee4aefdfda8491c6075a8b52e2d7Du
dc77ee42e3378dfc1bde015704e9af335bd8e6829d547325da2fc62adc0db229
##2	c
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-5]Ik- Resolves: #1719014 - Expired certificate prevents tests from running
- Actually apply the patch file for the previous build
- Related: #1730009 - lasso includes "Destination" attribute in SAML
                       AuthnRequest populated with SP
                       AssertionConsumerServiceURL when ECP workflow
                       is used which leads to IdP-side errors5c	
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-4]6- Resolves: #1730009 - lasso includes "Destination" attribute in SAML
                       AuthnRequest populated with SP
                       AssertionConsumerServiceURL when ECP workflow
                       is used which leads to IdP-side errorsgcm
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-3\`@- Resolves: #1634267 - ECP signature check fails with
                       LASSO_DS_ERROR_SIGNATURE_NOT_FOUND when assertion signed
                       instead of response
@JT?
a
John Dennis <jdennis@redhat.com> - 2.4.1-8U@- Add explicit minimum dependency on glib2 2.42,
  for some reason RPM is not automatically detecting the dependency
  Resolves: #1254989qc
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-8`r- Fix Coverity warning introduced by the previous patch
- Related: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                      vulnerability when parsing SAML responsesqc
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-7`r- Fix Coverity warning introduced by the previous patch
- Related: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                      vulnerability when parsing SAML responses;
c
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-6`r- Resolves: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                       vulnerability when parsing SAML responses
HcnH5c	
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-4]6- Resolves: #1730009 - lasso includes "Destination" attribute in SAML
                       AuthnRequest populated with SP
                       AssertionConsumerServiceURL when ECP workflow
                       is used which leads to IdP-side errorsgcm
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-3\`@- Resolves: #1634267 - ECP signature check fails with
                       LASSO_DS_ERROR_SIGNATURE_NOT_FOUND when assertion signed
                       instead of responsea1
John Dennis <jdennis@redhat.com> - 2.5.1-2Wc@- Rebase to upstream 2.5.1
  Resolves: #1310860
- add validate_idp_list_test patchdak
John Dennis <jdennis@redhat.com> - 2.5.1-1WYZ@- Rebase to upstream 2.5.1
  Resolves: #1310860aQ
John Dennis <jdennis@redhat.com> - 2.5.0-1U6@- Rebase to upstream, now includes our ECP patches, no need to patch any more
  Resolves: #1205342
Iqc
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-7`r- Fix Coverity warning introduced by the previous patch
- Related: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                      vulnerability when parsing SAML responses;c
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-6`r- Resolves: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                       vulnerability when parsing SAML responses2c
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-5]Ik- Resolves: #1719014 - Expired certificate prevents tests from running
- Actually apply the patch file for the previous build
- Related: #1730009 - lasso includes "Destination" attribute in SAML
                       AuthnRequest populated with SP
                       AssertionConsumerServiceURL when ECP workflow
                       is used which leads to IdP-side errors

FAa1
John Dennis <jdennis@redhat.com> - 2.5.1-2Wc@- Rebase to upstream 2.5.1
  Resolves: #1310860
- add validate_idp_list_test patchdak
John Dennis <jdennis@redhat.com> - 2.5.1-1WYZ@- Rebase to upstream 2.5.1
  Resolves: #1310860aQ
John Dennis <jdennis@redhat.com> - 2.5.0-1U6@- Rebase to upstream, now includes our ECP patches, no need to patch any more
  Resolves: #1205342?a
John Dennis <jdennis@redhat.com> - 2.4.1-8U@- Add explicit minimum dependency on glib2 2.42,
  for some reason RPM is not automatically detecting the dependency
  Resolves: #1254989qc
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-8`r- Fix Coverity warning introduced by the previous patch
- Related: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                      vulnerability when parsing SAML responses
##2c
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-5]Ik- Resolves: #1719014 - Expired certificate prevents tests from running
- Actually apply the patch file for the previous build
- Related: #1730009 - lasso includes "Destination" attribute in SAML
                       AuthnRequest populated with SP
                       AssertionConsumerServiceURL when ECP workflow
                       is used which leads to IdP-side errors5c	
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-4]6- Resolves: #1730009 - lasso includes "Destination" attribute in SAML
                       AuthnRequest populated with SP
                       AssertionConsumerServiceURL when ECP workflow
                       is used which leads to IdP-side errorsgcm
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-3\`@- Resolves: #1634267 - ECP signature check fails with
                       LASSO_DS_ERROR_SIGNATURE_NOT_FOUND when assertion signed
                       instead of response
@JT?!a
John Dennis <jdennis@redhat.com> - 2.4.1-8U@- Add explicit minimum dependency on glib2 2.42,
  for some reason RPM is not automatically detecting the dependency
  Resolves: #1254989q c
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-8`r- Fix Coverity warning introduced by the previous patch
- Related: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                      vulnerability when parsing SAML responsesqc
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-7`r- Fix Coverity warning introduced by the previous patch
- Related: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                      vulnerability when parsing SAML responses;c
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-6`r- Resolves: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                       vulnerability when parsing SAML responses
HcnH5&c	
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-4]6- Resolves: #1730009 - lasso includes "Destination" attribute in SAML
                       AuthnRequest populated with SP
                       AssertionConsumerServiceURL when ECP workflow
                       is used which leads to IdP-side errorsg%cm
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-3\`@- Resolves: #1634267 - ECP signature check fails with
                       LASSO_DS_ERROR_SIGNATURE_NOT_FOUND when assertion signed
                       instead of response$a1
John Dennis <jdennis@redhat.com> - 2.5.1-2Wc@- Rebase to upstream 2.5.1
  Resolves: #1310860
- add validate_idp_list_test patchd#ak
John Dennis <jdennis@redhat.com> - 2.5.1-1WYZ@- Rebase to upstream 2.5.1
  Resolves: #1310860"aQ
John Dennis <jdennis@redhat.com> - 2.5.0-1U6@- Rebase to upstream, now includes our ECP patches, no need to patch any more
  Resolves: #1205342
Iq)c
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-7`r- Fix Coverity warning introduced by the previous patch
- Related: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                      vulnerability when parsing SAML responses;(c
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-6`r- Resolves: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                       vulnerability when parsing SAML responses2'c
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-5]Ik- Resolves: #1719014 - Expired certificate prevents tests from running
- Actually apply the patch file for the previous build
- Related: #1730009 - lasso includes "Destination" attribute in SAML
                       AuthnRequest populated with SP
                       AssertionConsumerServiceURL when ECP workflow
                       is used which leads to IdP-side errors
A

bAv/c
Jakub Hrozek <jhrozek@redhat.com> - 1.3.2-1Z̧@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebase".cc
Jakub Hrozek <jhrozek@redhat.com> - 1.2.2-1YM- Resolves: rhbz#1470056 - Rebase libldb to enable samba rebase to
                           version 4.7.x#-ec
Jakub Hrozek <jhrozek@redhat.com> - 1.1.29-1X@- Resolves: rhbz#1393810 - Rebase libldb to enable samba rebase to
                           version 4.6.xr,e
Jakub Hrozek <jhrozek@redhat.com> - 1.1.26-1WYZ@- Resolves: rhbz#1320253 - Rebase libldb to version 1.1.26+e'
Jakub Hrozek <jhrozek@redhat.com> - 1.1.25-1Vb- Rebase libldb to 1.1.25
- Remove upstreamed patches
- Related: rhbz#1322691q*c
Jakub Hrozek <jhrozek@redhat.com> - 2.5.1-8`r- Fix Coverity warning introduced by the previous patch
- Related: #1963855 - CVE-2021-28091 lasso: XML signature wrapping
                      vulnerability when parsing SAML responses
`6i5
Fridolin Pokorny <fpokorny@redhat.com> - 458-2Qf- Added gpg support to lesspipe.sh (#885122)
- Added ~/.lessfilter support (#885122)H5i+
Fridolin Pokorny <fpokorny@redhat.com> - 458-1Qf- Update to 458`4e_
Andreas Schneider <asn@redhat.com> - 1.5.4-2`Y@- resolves: #1941511 - Fix CVE-2021-20277z3c
Jakub Hrozek <jhrozek@redhat.com> - 1.5.4-1]B@- Resolves: rhbz#1736013 - Rebase libldb to version 1.5.4 for Sambaz2c
Jakub Hrozek <jhrozek@redhat.com> - 1.4.2-1\?- Resolves: rhbz#1658758 - Rebase libldb to version 1.4.2 for Sambav1c
Jakub Hrozek <jhrozek@redhat.com> - 1.3.4-1[3|@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasev0c
Jakub Hrozek <jhrozek@redhat.com> - 1.3.3-1Z- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebase
.(=[w
Jozef Mlich <jmlich@redhat.com> - 458-9U]- The --use-backslash option documented in the man page
  was missing from online help for less.
  Resolves: #11090907<[
Jozef Mlich <jmlich@redhat.com> - 458-8R- changes introduced in less-458-old-bot-in-help.patch
  wasn't compiled in. It is necessary to use mkhelp tool.
  Resolves: #948597J;Y?
Daniel Mach <dmach@redhat.com> - 458-7RU- Mass rebuild 2014-01-24J:Y?
Daniel Mach <dmach@redhat.com> - 458-6Rk- Mass rebuild 2013-12-2729[
Jozef Mlich <jmlich@redhat.com> - 458-5Rv@- fixing regression in 72dfd3f63594e1d4c9416180a95c47ae583934c6
  incorrect parsing of commandline arguments
- Resolves #948597X8]W
Ondrej Vasik <ovasik@redhat.com> - 458-4Qޞ@- apply the --old-bot patch (#983167)M7i3
Fridolin Pokorny <fpokorny@redhat.com> - 458-3Q- Expanded lessecho usage (#948597)
- Added lessfilter info to man (#948597)
- Expanded lesskey usage (#948597)
- Added --old-bot to help (#948597)
B'[B	C=W
Michal Ruprich - 4.4.8-9X l- Resolves: #1374653 -  File size decreases when synchronizing folders with a sftp account using lftpBk#
Luboš Uhliarik <luhliari@redhat.com> - 4.4.8-8W4p@- Resolves: #1285301 - lftp hangs after dowloading one file during a mirrorAk%
Luboš Uhliarik <luhliari@redhat.com> - 4.4.8-7U~@- Fixed issue with absolute URL locations in mirror mode
- Related: #1181580;@k
Luboš Uhliarik <luhliari@redhat.com> - 4.4.8-6US<- Fix lftp does not follow http redirect (302) in mirror mode (#1181580)
- Fix lftp exists randomly when "cmd:fail-exit" is set (#1193984)
- Added RFE - lftp configurations for restricting each SSL/TLS 
  version (#1182987)
- Fixed bogus dates of this SPECp?i{
Lubos Uhliarik <luhliari@redhat.com> - 4.4.8-5UQ@- Fix option xfer:auto-rename not documented (#1035229)a>cc
Matej Mužila <mmuzila@redhat.com> - 458-10f'- Fix CVE-2024-32487
- Resolves: RHEL-32802
M-RMHk-
Michal Ruprich <mruprich@redhat.com> - 4.4.8-14c:- Resolves: #2115215 - Request "--env-password" option for lftp 4.4.8 for RHEL 7;Gk
Michal Ruprich <mruprich@redhat.com> - 4.4.8-13^9\- Resolves: #1573296 - lftp with ssl gives error Fatal error: gnutls_record_recv: The TLS connection was non-properly terminated0Fkw
Michal Ruprich <mruprich@redhat.com> - 4.4.8-12]8H@- Resolves: #1611641 - CVE-2018-10916 lftp: particular remote file names may lead to current working directory erasedVEkC
Michal Ruprich <mruprich@redhat.com> - 4.4.8-11Z- Resolves: #1514815 - lftp doesn't seems to consider 'set net:max-retries'
- Resolves: #1556675 - "get" command with lftp does not fail on net:max-retriesND?_
Michal Ruprich - 4.4.8-10X)@- Related: #1374653 - File size decreases when synchronizing folders with a sftp account using lftp
                    - Patch edited so that it corresponds to upstream
L5	M=W
Michal Ruprich - 4.4.8-9X l- Resolves: #1374653 -  File size decreases when synchronizing folders with a sftp account using lftpLk#
Luboš Uhliarik <luhliari@redhat.com> - 4.4.8-8W4p@- Resolves: #1285301 - lftp hangs after dowloading one file during a mirrorKk%
Luboš Uhliarik <luhliari@redhat.com> - 4.4.8-7U~@- Fixed issue with absolute URL locations in mirror mode
- Related: #1181580;Jk
Luboš Uhliarik <luhliari@redhat.com> - 4.4.8-6US<- Fix lftp does not follow http redirect (302) in mirror mode (#1181580)
- Fix lftp exists randomly when "cmd:fail-exit" is set (#1193984)
- Added RFE - lftp configurations for restricting each SSL/TLS 
  version (#1182987)
- Fixed bogus dates of this SPECpIi{
Lubos Uhliarik <luhliari@redhat.com> - 4.4.8-5UQ@- Fix option xfer:auto-rename not documented (#1035229)
M-RMRk-
Michal Ruprich <mruprich@redhat.com> - 4.4.8-14c:- Resolves: #2115215 - Request "--env-password" option for lftp 4.4.8 for RHEL 7;Qk
Michal Ruprich <mruprich@redhat.com> - 4.4.8-13^9\- Resolves: #1573296 - lftp with ssl gives error Fatal error: gnutls_record_recv: The TLS connection was non-properly terminated0Pkw
Michal Ruprich <mruprich@redhat.com> - 4.4.8-12]8H@- Resolves: #1611641 - CVE-2018-10916 lftp: particular remote file names may lead to current working directory erasedVOkC
Michal Ruprich <mruprich@redhat.com> - 4.4.8-11Z- Resolves: #1514815 - lftp doesn't seems to consider 'set net:max-retries'
- Resolves: #1556675 - "get" command with lftp does not fail on net:max-retriesNN?_
Michal Ruprich - 4.4.8-10X)@- Related: #1374653 - File size decreases when synchronizing folders with a sftp account using lftp
                    - Patch edited so that it corresponds to upstream
L5	W=W
Michal Ruprich - 4.4.8-9X l- Resolves: #1374653 -  File size decreases when synchronizing folders with a sftp account using lftpVk#
Luboš Uhliarik <luhliari@redhat.com> - 4.4.8-8W4p@- Resolves: #1285301 - lftp hangs after dowloading one file during a mirrorUk%
Luboš Uhliarik <luhliari@redhat.com> - 4.4.8-7U~@- Fixed issue with absolute URL locations in mirror mode
- Related: #1181580;Tk
Luboš Uhliarik <luhliari@redhat.com> - 4.4.8-6US<- Fix lftp does not follow http redirect (302) in mirror mode (#1181580)
- Fix lftp exists randomly when "cmd:fail-exit" is set (#1193984)
- Added RFE - lftp configurations for restricting each SSL/TLS 
  version (#1182987)
- Fixed bogus dates of this SPECpSi{
Lubos Uhliarik <luhliari@redhat.com> - 4.4.8-5UQ@- Fix option xfer:auto-rename not documented (#1035229)
M-RM\k-
Michal Ruprich <mruprich@redhat.com> - 4.4.8-14c:- Resolves: #2115215 - Request "--env-password" option for lftp 4.4.8 for RHEL 7;[k
Michal Ruprich <mruprich@redhat.com> - 4.4.8-13^9\- Resolves: #1573296 - lftp with ssl gives error Fatal error: gnutls_record_recv: The TLS connection was non-properly terminated0Zkw
Michal Ruprich <mruprich@redhat.com> - 4.4.8-12]8H@- Resolves: #1611641 - CVE-2018-10916 lftp: particular remote file names may lead to current working directory erasedVYkC
Michal Ruprich <mruprich@redhat.com> - 4.4.8-11Z- Resolves: #1514815 - lftp doesn't seems to consider 'set net:max-retries'
- Resolves: #1556675 - "get" command with lftp does not fail on net:max-retriesNX?_
Michal Ruprich - 4.4.8-10X)@- Related: #1374653 - File size decreases when synchronizing folders with a sftp account using lftp
                    - Patch edited so that it corresponds to upstream

PV~9]PXfiK
Michel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)he]w
Adam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageAd])
Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7ec]q
Adam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingobqq
Peter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)Aa])
Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5d`q[
Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3l_qk
Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2a^qU
Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-2Xn5@- Plug a memory leak in XListFonts()A]])
Adam Jackson <ajax@redhat.com> - 1.6.4-1W@- libX11 1.6.4

PV~9]PXpiK
Michel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)ho]w
Adam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageAn])
Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7em]q
Adam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingolqq
Peter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)Ak])
Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5djq[
Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3liqk
Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2ahqU
Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-2Xn5@- Plug a memory leak in XListFonts()Ag])
Adam Jackson <ajax@redhat.com> - 1.6.4-1W@- libX11 1.6.4

?+~]?Rz]KAdam Jackson <ajax@redhat.com> - 1.6.7-4a- Fix CVE-2021-31535 (#1962438)XyiKMichel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)hx]wAdam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageAw])Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7ev]qAdam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingouqqPeter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)At])Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5dsq[Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3lrqkPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2aqqUPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-2Xn5@- Plug a memory leak in XListFonts()

?+~]?R]KAdam Jackson <ajax@redhat.com> - 1.6.7-4a- Fix CVE-2021-31535 (#1962438)XiKMichel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)h]wAdam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageA])Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7e]qAdam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingoqqPeter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)A~])Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5d}q[Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3l|qkPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2a{qUPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-2Xn5@- Plug a memory leak in XListFonts()

er+V:eD
de55e1ddb71f75f5b701d57786cf4b70fee1d92f72205d32c353fe0e17602361D

e5f76a4c5b41b3334ed3da7aa9bf17480ddf89e174661aaa2d61a1fe4efc7ad4D
374f721b5f41a11a081cd23537162130ab654a02ece3e8c55f3840ecd8f839a0D
1ef57080cad8889aa2a957bb771d161af38b61bf4aec83a7fcd19e2dfe510079D

938bca67aabbf5f68ed289ef571582f9e1c3c144f27c0cc38dc3b60c03bb184eD	
a11e1ecb8f7034384a2138c08abe5aa5f4f9996c624112e951eb5a42353bc197D
1cd870f8b1c30e2f168c6960a8dde4ac59970a62aca538042b33d37a679f1a3bD
e033e09baf35ab533a503e8e87c8e01aae28de712da982f5371673bf0567fa4aD
70bbd71ba6462d9f6702322739a79ddf57ab8a23f41a3ae1e2c47feacb60d0d1D
2c6eb5afea1c0a0fa2d5103b42a1dfd64c5d9d81d7974ab2bf5adbf20f29033aD
c5210f6bcc42e5949db2d2f133a369159d73a960cf7abe1a47a4248fe1d48491D
1f4f286b0441b2c508c416f72ee52c1b323a1ba12aae4579f986c007ecde653fD
3e22c1e91e6c946f60aaa437911042d67c7e9de92d77cf458a51d5660658186c

!(pV!kOlivier Fourdan <ofourdan@redhat.com> - 1.6.7-5e- Backport fix for Xlib lockups due to recursive XError (RHEL-23053)R
]KAdam Jackson <ajax@redhat.com> - 1.6.7-4a- Fix CVE-2021-31535 (#1962438)XiKMichel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)h]wAdam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageA
])Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7e	]qAdam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingoqqPeter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)A])Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5dq[Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3lqkPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2

!(pV!kOlivier Fourdan <ofourdan@redhat.com> - 1.6.7-5e- Backport fix for Xlib lockups due to recursive XError (RHEL-23053)R]KAdam Jackson <ajax@redhat.com> - 1.6.7-4a- Fix CVE-2021-31535 (#1962438)XiKMichel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)h]wAdam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageA])Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7e]qAdam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingoqqPeter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)A])Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5dq[Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3lqkPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2

PV~9]PX"iKMichel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)h!]wAdam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageA ])Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7e]qAdam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingoqqPeter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)A])Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5dq[Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3lqkPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2aqUPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-2Xn5@- Plug a memory leak in XListFonts()A])Adam Jackson <ajax@redhat.com> - 1.6.4-1W@- libX11 1.6.4

?+~]?R,]KAdam Jackson <ajax@redhat.com> - 1.6.7-4a- Fix CVE-2021-31535 (#1962438)X+iKMichel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)h*]wAdam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageA)])Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7e(]qAdam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingo'qqPeter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)A&])Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5d%q[Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3l$qkPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2a#qUPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-2Xn5@- Plug a memory leak in XListFonts()

!(pV!6kOlivier Fourdan <ofourdan@redhat.com> - 1.6.7-5e- Backport fix for Xlib lockups due to recursive XError (RHEL-23053)R5]KAdam Jackson <ajax@redhat.com> - 1.6.7-4a- Fix CVE-2021-31535 (#1962438)X4iKMichel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)h3]wAdam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageA2])Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7e1]qAdam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingo0qqPeter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)A/])Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5d.q[Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3l-qkPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2bR"RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{">"C"H"M"R"W"\"a"f"k"p"u"{"~"""	"
"""""!"&")"/"6"="C"H"M"R"W"\"f"p"z"""""","6"@"J"T"Á^"āh"Łr"Ɓy"ǁ"ȁ"ʁ"ˁ"́"́ "΁#"ρ("Ё+"с-"ҁ2"Ӂ5"ԁ7"Ձ<"ց?"ׁA"؁H"فQ"ځZ"ہc"܁k"݁q"ށv"߁~""	""""#"("/"4":"=">"A"E"G"H"K"O"P"Q"T"Y"Z"[

PV~9]PX@iKMichel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)h?]wAdam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageA>])Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7e=]qAdam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingo<qqPeter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)A;])Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5d:q[Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3l9qkPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2a8qUPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-2Xn5@- Plug a memory leak in XListFonts()A7])Adam Jackson <ajax@redhat.com> - 1.6.4-1W@- libX11 1.6.4

PV~9]PXJiKMichel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)hI]wAdam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageAH])Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7eG]qAdam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingoFqqPeter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)AE])Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5dDq[Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3lCqkPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2aBqUPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-2Xn5@- Plug a memory leak in XListFonts()AA])Adam Jackson <ajax@redhat.com> - 1.6.4-1W@- libX11 1.6.4

?+~]?RT]K	Adam Jackson <ajax@redhat.com> - 1.6.7-4a- Fix CVE-2021-31535 (#1962438)XSiK	Michel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)hR]w	Adam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageAQ])	Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7eP]q	Adam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingoOqq	Peter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)AN])	Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5dMq[	Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3lLqk	Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2aKqU	Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-2Xn5@- Plug a memory leak in XListFonts()

?+~]?R^]K
Adam Jackson <ajax@redhat.com> - 1.6.7-4a- Fix CVE-2021-31535 (#1962438)X]iK
Michel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)h\]w
Adam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageA[])
Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7eZ]q
Adam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingoYqq
Peter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)AX])
Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5dWq[
Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3lVqk
Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2aUqU
Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-2Xn5@- Plug a memory leak in XListFonts()

!(pV!hkOlivier Fourdan <ofourdan@redhat.com> - 1.6.7-5e- Backport fix for Xlib lockups due to recursive XError (RHEL-23053)Rg]KAdam Jackson <ajax@redhat.com> - 1.6.7-4a- Fix CVE-2021-31535 (#1962438)XfiKMichel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)he]wAdam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageAd])Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7ec]qAdam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingobqqPeter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)Aa])Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5d`q[Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3l_qkPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2

!(pV!rkOlivier Fourdan <ofourdan@redhat.com> - 1.6.7-5e- Backport fix for Xlib lockups due to recursive XError (RHEL-23053)Rq]KAdam Jackson <ajax@redhat.com> - 1.6.7-4a- Fix CVE-2021-31535 (#1962438)XpiKMichel Dänzer <mdaenzer@redhat.com> - 1.6.7-3_- Fix CVE-2020-14363 (#1873922)ho]wAdam Jackson <ajax@redhat.com> - 1.6.7-2\"- Restore the less-alarming server-disconnect messageAn])Adam Jackson <ajax@redhat.com> - 1.6.7-1\r@- libX11 1.6.7em]qAdam Jackson <ajax@redhat.com> - 1.6.5-3\y- Make the server-disconnect message less alarmingolqqPeter Hutterer <peter.hutterer@redhat.com> 1.6.5-2[GB- Rebuild to pick up new xproto keysyms (#1600147)Ak])Adam Jackson <ajax@redhat.com> - 1.6.5-1Y- libX11 1.6.5djq[Peter Hutterer <peter.hutterer@redhat.com> 1.6.4-4X- Actually apply the patch from 1.6.4-3liqkPeter Hutterer <peter.hutterer@redhat.com> 1.6.4-3Xs{@- Fix a bug in the memory leak fix from 1.6.4-2
'-y
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.11-2S- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_RebuildZx[]
Adam Jackson <ajax@redhat.com> 3.5.11-1Rb@- libXpm 3.5.11
- Drop pre-F18 changelogw
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.10-5Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_RebuildXvw=
Peter Hutterer <peter.hutterer@redhat.com> - 3.5.10-4Q8@- autoreconf for aarch64u
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.10-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuildt
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.10-2P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildAs[+
Adam Jackson <ajax@redhat.com> 3.5.10-1OX@- libXpm 3.5.10
a|7Xw=Peter Hutterer <peter.hutterer@redhat.com> - 3.5.10-4Q8@- autoreconf for aarch64Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.10-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild~Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.10-2P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildA}[+Adam Jackson <ajax@redhat.com> 3.5.10-1OX@- libXpm 3.5.10|w
Peter Hutterer <peter.hutterer@redhat.com> - 3.5.12-2c0- Fix CVE-2022-4883: compression commands depends on $PATH (#2161715)V{+
Benjamin Tissoires <benjamin.tissoires@redhat.com> 3.5.12-1X@- libXpm 3.5.12z
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.11-3S@- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
djqA[+Adam Jackson <ajax@redhat.com> 3.5.10-1OX@- libXpm 3.5.10wPeter Hutterer <peter.hutterer@redhat.com> - 3.5.12-2c0- Fix CVE-2022-4883: compression commands depends on $PATH (#2161715)V+Benjamin Tissoires <benjamin.tissoires@redhat.com> 3.5.12-1X@- libXpm 3.5.12Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.11-3S@- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_RebuildFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.11-2S- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_RebuildZ[]Adam Jackson <ajax@redhat.com> 3.5.11-1Rb@- libXpm 3.5.11
- Drop pre-F18 changelogFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.10-5Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild

er+V:eD
faea0d6adefaa474577c184f31a44469d13846a44412ea382dafc9f9ea6a3a77D
4ad0b71e3a6468fba1b43ab82fad024415b5296c7b77d1348fb9afa3f828f98eD
3054ca1c0cc8eef5f08ce1d3be56c7a39e97d92361e8bd265bea14d06f590219D
73952b31447b02abc10d1c2efafb6def58e9237532ddef9eb3a691baaa88a495D
6602351182c085c415d4c05b7e325611057898b48cdc1249a54c5106cd0735fdD
eeec2b53758cdbb0b3f3402b7117dddcf34c40e99612fc0ec69bb799b2a7b6beD
b9bc38488c309455bbf6f753ef1aaaa244614ec08a027b5ff58a7b234006eac1D
a687b481be7d8b127fe830b2c0840854683d1ac18a2c1799d5caac56e8891e8fD
ea09355eb6ee209c2b42e898475fc5462249ee3f27b0dd881ee2fd0db8245464D
0eda90367bc11ce10165853be705e1303b3ac2a0f5072131cbd8b2ea6ed2d1eaD
b856dd2cc821e1fa2cbc89c6901577691af284f98280ef05cc1a7c3826acae41D
938bb9ba7be38a8654b48fbbb34f5d8a3a6db6e2453cbe54b8b837c099acb52cD
26dd5513dd4b2211aa6f24f32382b86bafd5ff88c0d642448cc8725093a58146
7dlr7Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.11-3S@- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.11-2S- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_RebuildZ[]Adam Jackson <ajax@redhat.com> 3.5.11-1Rb@- libXpm 3.5.11
- Drop pre-F18 changelogFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.10-5Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_RebuildX
w=Peter Hutterer <peter.hutterer@redhat.com> - 3.5.10-4Q8@- autoreconf for aarch64	Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.10-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.10-2P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
H:BHZ[]Adam Jackson <ajax@redhat.com> 3.5.11-1Rb@- libXpm 3.5.11
- Drop pre-F18 changelogFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.10-5Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_RebuildXw=Peter Hutterer <peter.hutterer@redhat.com> - 3.5.10-4Q8@- autoreconf for aarch64Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.10-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.10-2P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildA[+Adam Jackson <ajax@redhat.com> 3.5.10-1OX@- libXpm 3.5.10wPeter Hutterer <peter.hutterer@redhat.com> - 3.5.12-2c0- Fix CVE-2022-4883: compression commands depends on $PATH (#2161715)V+Benjamin Tissoires <benjamin.tissoires@redhat.com> 3.5.12-1X@- libXpm 3.5.12
Ldk}L=W%Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedkWKarel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_WkKarel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)wPeter Hutterer <peter.hutterer@redhat.com> - 3.5.12-2c0- Fix CVE-2022-4883: compression commands depends on $PATH (#2161715)V+Benjamin Tissoires <benjamin.tissoires@redhat.com> 3.5.12-1X@- libXpm 3.5.12Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.11-3S@- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_RebuildFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.5.11-2S- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
,Sr,A W-Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\WcKarel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev(W{Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login
la#WmKarel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZ"W_Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit!WIKarel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.
vT#v((W{Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login='W%Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedk&WKarel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_%WkKarel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)D$g#Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
EE+WIKarel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.A*W-Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\)WcKarel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;a-WmKarel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZ,W_Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
vT#v(2W{Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=1W%Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedk0WKarel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_/WkKarel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)D.g#Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
EE5WIKarel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.A4W-Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\3WcKarel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;a7WmKarel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZ6W_Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
vT#v(<W{Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=;W%Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedk:WKarel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_9WkKarel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)D8g#Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
EE?WIKarel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.A>W-Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\=WcKarel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;aAWmKarel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZ@W_Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
[i[LH]?Daniel Mach <dmach@redhat.com> - 0.6.8-5RU- Mass rebuild 2014-01-24LG]?Daniel Mach <dmach@redhat.com> - 0.6.8-4Rk- Mass rebuild 2013-12-27FiMatthias Clasen <mclasen@redhat.com> - 0.6.8-3Q5- Disable strict aliasing, since the code is not strict-aliasing-cleanEFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.8-2Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildJDi/Kalev Lember <kalevlember@gmail.com> - 0.6.8-1P@- Update to 0.6.8JCi/Kalev Lember <kalevlember@gmail.com> - 0.6.7-1P}L@- Update to 0.6.7DBg#Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
	P:\%PLQ]?Daniel Mach <dmach@redhat.com> - 0.6.8-4Rk- Mass rebuild 2013-12-27PiMatthias Clasen <mclasen@redhat.com> - 0.6.8-3Q5- Disable strict aliasing, since the code is not strict-aliasing-cleanOFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.8-2Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildJNi/Kalev Lember <kalevlember@gmail.com> - 0.6.8-1P@- Update to 0.6.8JMi/Kalev Lember <kalevlember@gmail.com> - 0.6.7-1P}L@- Update to 0.6.7nLukMichael Catanzaro <mcatanzaro@redhat.com> - 0.6.12-6_'A- Rebuild with 7.9-z target
  Related: #1835951hKu_Michael Catanzaro <mcatanzaro@redhat.com> - 0.6.12-5_'@- Fix CVE-2020-12825
  Resolves: #1835951`Ji[Richard Hughes <rhughes@redhat.com> - 0.6.12-4X-- Update to 0.6.12
- Resolves: #1569991^Ie[Kalev Lember <klember@redhat.com> - 0.6.11-1Vr- Update to 0.6.11
- Resolves: #1386999
	PN~pPZiMatthias Clasen <mclasen@redhat.com> - 0.6.8-3Q5- Disable strict aliasing, since the code is not strict-aliasing-cleanYFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.8-2Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildJXi/Kalev Lember <kalevlember@gmail.com> - 0.6.8-1P@- Update to 0.6.8JWi/Kalev Lember <kalevlember@gmail.com> - 0.6.7-1P}L@- Update to 0.6.7nVukMichael Catanzaro <mcatanzaro@redhat.com> - 0.6.12-6_'A- Rebuild with 7.9-z target
  Related: #1835951hUu_Michael Catanzaro <mcatanzaro@redhat.com> - 0.6.12-5_'@- Fix CVE-2020-12825
  Resolves: #1835951`Ti[Richard Hughes <rhughes@redhat.com> - 0.6.12-4X-- Update to 0.6.12
- Resolves: #1569991^Se[Kalev Lember <klember@redhat.com> - 0.6.11-1Vr- Update to 0.6.11
- Resolves: #1386999LR]?Daniel Mach <dmach@redhat.com> - 0.6.8-5RU- Mass rebuild 2014-01-24
	`.n cFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.8-2Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildJbi/Kalev Lember <kalevlember@gmail.com> - 0.6.8-1P@- Update to 0.6.8Jai/Kalev Lember <kalevlember@gmail.com> - 0.6.7-1P}L@- Update to 0.6.7n`ukMichael Catanzaro <mcatanzaro@redhat.com> - 0.6.12-6_'A- Rebuild with 7.9-z target
  Related: #1835951h_u_Michael Catanzaro <mcatanzaro@redhat.com> - 0.6.12-5_'@- Fix CVE-2020-12825
  Resolves: #1835951`^i[Richard Hughes <rhughes@redhat.com> - 0.6.12-4X-- Update to 0.6.12
- Resolves: #1569991^]e[Kalev Lember <klember@redhat.com> - 0.6.11-1Vr- Update to 0.6.11
- Resolves: #1386999L\]?Daniel Mach <dmach@redhat.com> - 0.6.8-5RU- Mass rebuild 2014-01-24L[]?Daniel Mach <dmach@redhat.com> - 0.6.8-4Rk- Mass rebuild 2013-12-27
{+y7kc+Kamil Dudka <kdudka@redhat.com> - 7.29.0-51[j@- require a new enough version of nss-pem to avoid regression in yum (#1610998)njukMichael Catanzaro <mcatanzaro@redhat.com> - 0.6.12-6_'A- Rebuild with 7.9-z target
  Related: #1835951hiu_Michael Catanzaro <mcatanzaro@redhat.com> - 0.6.12-5_'@- Fix CVE-2020-12825
  Resolves: #1835951`hi[Richard Hughes <rhughes@redhat.com> - 0.6.12-4X-- Update to 0.6.12
- Resolves: #1569991^ge[Kalev Lember <klember@redhat.com> - 0.6.11-1Vr- Update to 0.6.11
- Resolves: #1386999Lf]?Daniel Mach <dmach@redhat.com> - 0.6.8-5RU- Mass rebuild 2014-01-24Le]?Daniel Mach <dmach@redhat.com> - 0.6.8-4Rk- Mass rebuild 2013-12-27diMatthias Clasen <mclasen@redhat.com> - 0.6.8-3Q5- Disable strict aliasing, since the code is not strict-aliasing-clean
+r+hqcqKamil Dudka <kdudka@redhat.com> - 7.29.0-57]e@- allow curl to POST from a char device (#1769307)|pcKamil Dudka <kdudka@redhat.com> - 7.29.0-56]?- fix auth failure with duplicated WWW-Authenticate header (#1754736)hocqKamil Dudka <kdudka@redhat.com> - 7.29.0-55]Ik- fix TFTP receive buffer overflow (CVE-2019-5436)jncuKamil Dudka <kdudka@redhat.com> - 7.29.0-54\- make `curl --tlsv1` backward compatible (#1672639)}mcKamil Dudka <kdudka@redhat.com> - 7.29.0-53\@- backport the --tls-max option of curl and TLS 1.3 ciphers (#1672639)	lc1Kamil Dudka <kdudka@redhat.com> - 7.29.0-52\y- prevent curl --rate-limit from hanging on file URLs (#1281969)
- fix NTLM password overflow via integer overflow (CVE-2018-14618)
- fix bad arithmetic when outputting warnings to stderr (CVE-2018-16842)
- backport options to force TLS 1.3 in curl and libcurl (#1672639)
- prevent curl --rate-limit from crashing on https URLs (#1683292)
\xu\	vc1Kamil Dudka <kdudka@redhat.com> - 7.29.0-52\y- prevent curl --rate-limit from hanging on file URLs (#1281969)
- fix NTLM password overflow via integer overflow (CVE-2018-14618)
- fix bad arithmetic when outputting warnings to stderr (CVE-2018-16842)
- backport options to force TLS 1.3 in curl and libcurl (#1672639)
- prevent curl --rate-limit from crashing on https URLs (#1683292)uc+Kamil Dudka <kdudka@redhat.com> - 7.29.0-51[j@- require a new enough version of nss-pem to avoid regression in yum (#1610998)vts}Kamil Dudka <kdudka@redhat.com> - 7.29.0-59.el7_9.1_ @- avoid overwriting a local file with -J (CVE-2020-8177)sc'Kamil Dudka <kdudka@redhat.com> - 7.29.0-59^?@- http: free protocol-specific struct in setup_connection callback (#1836773)rc%Kamil Dudka <kdudka@redhat.com> - 7.29.0-58^x- fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)
.%1.v~s}Kamil Dudka <kdudka@redhat.com> - 7.29.0-59.el7_9.1_ @- avoid overwriting a local file with -J (CVE-2020-8177)}c'Kamil Dudka <kdudka@redhat.com> - 7.29.0-59^?@- http: free protocol-specific struct in setup_connection callback (#1836773)|c%Kamil Dudka <kdudka@redhat.com> - 7.29.0-58^x- fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)h{cqKamil Dudka <kdudka@redhat.com> - 7.29.0-57]e@- allow curl to POST from a char device (#1769307)|zcKamil Dudka <kdudka@redhat.com> - 7.29.0-56]?- fix auth failure with duplicated WWW-Authenticate header (#1754736)hycqKamil Dudka <kdudka@redhat.com> - 7.29.0-55]Ik- fix TFTP receive buffer overflow (CVE-2019-5436)jxcuKamil Dudka <kdudka@redhat.com> - 7.29.0-54\- make `curl --tlsv1` backward compatible (#1672639)}wcKamil Dudka <kdudka@redhat.com> - 7.29.0-53\@- backport the --tls-max option of curl and TLS 1.3 ciphers (#1672639)
+r+hcqKamil Dudka <kdudka@redhat.com> - 7.29.0-57]e@- allow curl to POST from a char device (#1769307)|cKamil Dudka <kdudka@redhat.com> - 7.29.0-56]?- fix auth failure with duplicated WWW-Authenticate header (#1754736)hcqKamil Dudka <kdudka@redhat.com> - 7.29.0-55]Ik- fix TFTP receive buffer overflow (CVE-2019-5436)jcuKamil Dudka <kdudka@redhat.com> - 7.29.0-54\- make `curl --tlsv1` backward compatible (#1672639)}cKamil Dudka <kdudka@redhat.com> - 7.29.0-53\@- backport the --tls-max option of curl and TLS 1.3 ciphers (#1672639)	c1Kamil Dudka <kdudka@redhat.com> - 7.29.0-52\y- prevent curl --rate-limit from hanging on file URLs (#1281969)
- fix NTLM password overflow via integer overflow (CVE-2018-14618)
- fix bad arithmetic when outputting warnings to stderr (CVE-2018-16842)
- backport options to force TLS 1.3 in curl and libcurl (#1672639)
- prevent curl --rate-limit from crashing on https URLs (#1683292)
ExuE		c1Kamil Dudka <kdudka@redhat.com> - 7.29.0-52\y- prevent curl --rate-limit from hanging on file URLs (#1281969)
- fix NTLM password overflow via integer overflow (CVE-2018-14618)
- fix bad arithmetic when outputting warnings to stderr (CVE-2018-16842)
- backport options to force TLS 1.3 in curl and libcurl (#1672639)
- prevent curl --rate-limit from crashing on https URLs (#1683292)wEJacek Migacz <jmigacz@redhat.com> - 7.29.0-59.el7_9.2eJ&- fix HTTP proxy deny use after free (CVE-2022-43552)
- rebuild certs with 2048-bit RSA keysvs}Kamil Dudka <kdudka@redhat.com> - 7.29.0-59.el7_9.1_ @- avoid overwriting a local file with -J (CVE-2020-8177)c'Kamil Dudka <kdudka@redhat.com> - 7.29.0-59^?@- http: free protocol-specific struct in setup_connection callback (#1836773)c%Kamil Dudka <kdudka@redhat.com> - 7.29.0-58^x- fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)

er+V:eD(
d756103ebb5cdaa112e97017abdb37c31ccacc831f5042c1c0c423e446ab3b8fD'
d0c60cdd0430a434420ef3cbcd3cd9ebd0e4089f8059b3a3b7bc427c158c0505D&
cebe503265c9efa9afa036f10cf99ab4d5eeabe4c13950dc76ba50fc4304f4fcD%
c846a72195e654b76f0ca3467ec6a0e034d1907a307e6d797b1e4238ab8e1949D$
828fe4eb26915648840d50ea3daa571c3735822ed66eced81dd20b12dff3e10eD#
4c0432991858f896026445ef401636f12a857102f3329b8a5d034aa2e99e2bd4D"
059cd706e5668cb53ab32ca18815011ad932d1853567a29b3c7b2afca689e637D!
f3dc3c542749f94c4e3a601842a9a8d6311fb735a5d6ee8d3845ce5b137c43eeD 
2670e3582d71b9a17efc9c2892e66a3c54a3160c71fdf742693ca914289185fcD
aead54e95d1462dda834e3f40fcfcf9312670076f263f156c631a937038d3b00D
f92fde3f97c0034135796baa7cd55f87c0550a88ac79adbdcc9c7f64c595614bD
7ab4f1b0aa285d3773fdbd8bfc529969ca101a627d3ea88bea1f99a42093e132D
34e3369ca1560dc34b862cce4a9fb6a7939494ce15ee0f68fb76edaf5fb3ee53
.%1.vs}Kamil Dudka <kdudka@redhat.com> - 7.29.0-59.el7_9.1_ @- avoid overwriting a local file with -J (CVE-2020-8177)c'Kamil Dudka <kdudka@redhat.com> - 7.29.0-59^?@- http: free protocol-specific struct in setup_connection callback (#1836773)c%Kamil Dudka <kdudka@redhat.com> - 7.29.0-58^x- fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)hcqKamil Dudka <kdudka@redhat.com> - 7.29.0-57]e@- allow curl to POST from a char device (#1769307)|
cKamil Dudka <kdudka@redhat.com> - 7.29.0-56]?- fix auth failure with duplicated WWW-Authenticate header (#1754736)hcqKamil Dudka <kdudka@redhat.com> - 7.29.0-55]Ik- fix TFTP receive buffer overflow (CVE-2019-5436)jcuKamil Dudka <kdudka@redhat.com> - 7.29.0-54\- make `curl --tlsv1` backward compatible (#1672639)}
cKamil Dudka <kdudka@redhat.com> - 7.29.0-53\@- backport the --tls-max option of curl and TLS 1.3 ciphers (#1672639)
V^EVjcuKamil Dudka <kdudka@redhat.com> - 7.29.0-54\- make `curl --tlsv1` backward compatible (#1672639)}cKamil Dudka <kdudka@redhat.com> - 7.29.0-53\@- backport the --tls-max option of curl and TLS 1.3 ciphers (#1672639)	c1Kamil Dudka <kdudka@redhat.com> - 7.29.0-52\y- prevent curl --rate-limit from hanging on file URLs (#1281969)
- fix NTLM password overflow via integer overflow (CVE-2018-14618)
- fix bad arithmetic when outputting warnings to stderr (CVE-2018-16842)
- backport options to force TLS 1.3 in curl and libcurl (#1672639)
- prevent curl --rate-limit from crashing on https URLs (#1683292)c+Kamil Dudka <kdudka@redhat.com> - 7.29.0-51[j@- require a new enough version of nss-pem to avoid regression in yum (#1610998)wEJacek Migacz <jmigacz@redhat.com> - 7.29.0-59.el7_9.2eJ&- fix HTTP proxy deny use after free (CVE-2022-43552)
- rebuild certs with 2048-bit RSA keys
 c+Kamil Dudka <kdudka@redhat.com> - 7.29.0-51[j@- require a new enough version of nss-pem to avoid regression in yum (#1610998)vs}Kamil Dudka <kdudka@redhat.com> - 7.29.0-59.el7_9.1_ @- avoid overwriting a local file with -J (CVE-2020-8177)c'Kamil Dudka <kdudka@redhat.com> - 7.29.0-59^?@- http: free protocol-specific struct in setup_connection callback (#1836773)c%Kamil Dudka <kdudka@redhat.com> - 7.29.0-58^x- fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)hcqKamil Dudka <kdudka@redhat.com> - 7.29.0-57]e@- allow curl to POST from a char device (#1769307)|cKamil Dudka <kdudka@redhat.com> - 7.29.0-56]?- fix auth failure with duplicated WWW-Authenticate header (#1754736)hcqKamil Dudka <kdudka@redhat.com> - 7.29.0-55]Ik- fix TFTP receive buffer overflow (CVE-2019-5436)
+r+h#cqKamil Dudka <kdudka@redhat.com> - 7.29.0-57]e@- allow curl to POST from a char device (#1769307)|"cKamil Dudka <kdudka@redhat.com> - 7.29.0-56]?- fix auth failure with duplicated WWW-Authenticate header (#1754736)h!cqKamil Dudka <kdudka@redhat.com> - 7.29.0-55]Ik- fix TFTP receive buffer overflow (CVE-2019-5436)j cuKamil Dudka <kdudka@redhat.com> - 7.29.0-54\- make `curl --tlsv1` backward compatible (#1672639)}cKamil Dudka <kdudka@redhat.com> - 7.29.0-53\@- backport the --tls-max option of curl and TLS 1.3 ciphers (#1672639)	c1Kamil Dudka <kdudka@redhat.com> - 7.29.0-52\y- prevent curl --rate-limit from hanging on file URLs (#1281969)
- fix NTLM password overflow via integer overflow (CVE-2018-14618)
- fix bad arithmetic when outputting warnings to stderr (CVE-2018-16842)
- backport options to force TLS 1.3 in curl and libcurl (#1672639)
- prevent curl --rate-limit from crashing on https URLs (#1683292)
fxuf}(cKamil Dudka <kdudka@redhat.com> - 7.29.0-53\@- backport the --tls-max option of curl and TLS 1.3 ciphers (#1672639)	'c1Kamil Dudka <kdudka@redhat.com> - 7.29.0-52\y- prevent curl --rate-limit from hanging on file URLs (#1281969)
- fix NTLM password overflow via integer overflow (CVE-2018-14618)
- fix bad arithmetic when outputting warnings to stderr (CVE-2018-16842)
- backport options to force TLS 1.3 in curl and libcurl (#1672639)
- prevent curl --rate-limit from crashing on https URLs (#1683292)v&s}Kamil Dudka <kdudka@redhat.com> - 7.29.0-59.el7_9.1_ @- avoid overwriting a local file with -J (CVE-2020-8177)%c'Kamil Dudka <kdudka@redhat.com> - 7.29.0-59^?@- http: free protocol-specific struct in setup_connection callback (#1836773)$c%Kamil Dudka <kdudka@redhat.com> - 7.29.0-58^x- fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)
&:)v/s}Kamil Dudka <kdudka@redhat.com> - 7.29.0-59.el7_9.1_ @- avoid overwriting a local file with -J (CVE-2020-8177).c'Kamil Dudka <kdudka@redhat.com> - 7.29.0-59^?@- http: free protocol-specific struct in setup_connection callback (#1836773)-c%Kamil Dudka <kdudka@redhat.com> - 7.29.0-58^x- fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)h,cqKamil Dudka <kdudka@redhat.com> - 7.29.0-57]e@- allow curl to POST from a char device (#1769307)|+cKamil Dudka <kdudka@redhat.com> - 7.29.0-56]?- fix auth failure with duplicated WWW-Authenticate header (#1754736)h*cqKamil Dudka <kdudka@redhat.com> - 7.29.0-55]Ik- fix TFTP receive buffer overflow (CVE-2019-5436)j)cuKamil Dudka <kdudka@redhat.com> - 7.29.0-54\- make `curl --tlsv1` backward compatible (#1672639)
u^Ouh4cq Kamil Dudka <kdudka@redhat.com> - 7.29.0-55]Ik- fix TFTP receive buffer overflow (CVE-2019-5436)j3cu Kamil Dudka <kdudka@redhat.com> - 7.29.0-54\- make `curl --tlsv1` backward compatible (#1672639)}2c Kamil Dudka <kdudka@redhat.com> - 7.29.0-53\@- backport the --tls-max option of curl and TLS 1.3 ciphers (#1672639)	1c1 Kamil Dudka <kdudka@redhat.com> - 7.29.0-52\y- prevent curl --rate-limit from hanging on file URLs (#1281969)
- fix NTLM password overflow via integer overflow (CVE-2018-14618)
- fix bad arithmetic when outputting warnings to stderr (CVE-2018-16842)
- backport options to force TLS 1.3 in curl and libcurl (#1672639)
- prevent curl --rate-limit from crashing on https URLs (#1683292)0wEJacek Migacz <jmigacz@redhat.com> - 7.29.0-59.el7_9.2eJ&- fix HTTP proxy deny use after free (CVE-2022-43552)
- rebuild certs with 2048-bit RSA keys
:wE Jacek Migacz <jmigacz@redhat.com> - 7.29.0-59.el7_9.2eJ&- fix HTTP proxy deny use after free (CVE-2022-43552)
- rebuild certs with 2048-bit RSA keysv9s} Kamil Dudka <kdudka@redhat.com> - 7.29.0-59.el7_9.1_ @- avoid overwriting a local file with -J (CVE-2020-8177)8c' Kamil Dudka <kdudka@redhat.com> - 7.29.0-59^?@- http: free protocol-specific struct in setup_connection callback (#1836773)7c% Kamil Dudka <kdudka@redhat.com> - 7.29.0-58^x- fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)h6cq Kamil Dudka <kdudka@redhat.com> - 7.29.0-57]e@- allow curl to POST from a char device (#1769307)|5c Kamil Dudka <kdudka@redhat.com> - 7.29.0-56]?- fix auth failure with duplicated WWW-Authenticate header (#1754736)
A=q'!Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556<qA!Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651;qK!Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-125\d- Modify 0250-RHBZ-1610867-rescan-change.patch
  * Fix memory Leak
- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix NULL dereference
- Refresh 0252-RHBZ-1623595-cmd-error-status.patch
- Resolves: bz #1610867, #1638651
LL/>qo!Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0Aqq!Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066@q}!Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q?qs!Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
+>EqK"Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-125\d- Modify 0250-RHBZ-1610867-rescan-change.patch
  * Fix memory Leak
- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix NULL dereference
- Refresh 0252-RHBZ-1623595-cmd-error-status.patch
- Resolves: bz #1610867, #1638651}Dq!Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hCqa!Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197PBq1!Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
cGq'"Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556FqA"Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651
LL/Hqo"Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0Kqq"Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066Jq}"Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qIqs"Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
 +> OqA#Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651}Nq"Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hMqa"Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197PLq1"Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
ppPq'#Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
LL/Qqo#Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0Tqq#Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066Sq}#Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qRqs#Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
+>"YqA$Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651Xq=#Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}Wq#Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hVqa#Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197PUq1#Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
ppZq'$Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
LL/[qo$Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0^qq$Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066]q}$Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q\qs$Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
"+>"bq=$Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}aq$Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h`qa$Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P_q1$Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
ppcq'%Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
LL/dqo%Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0gqq%Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066fq}%Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qeqs%Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
+>"lq%Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-136cG- Add 0274-UP-no-duplicate-command-keys.patch
- Resolves: bz #2134905kq=%Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}jq%Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hiqa%Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197Phq1%Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
ppmq'&Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
LL/nqo&Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0qqq&Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066pq}&Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qoqs&Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
+>"vq&Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-136cG- Add 0274-UP-no-duplicate-command-keys.patch
- Resolves: bz #2134905uq=&Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}tq&Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hsqa&Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197Prq1&Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
Ayq''Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556xqA'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651wqK'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-125\d- Modify 0250-RHBZ-1610867-rescan-change.patch
  * Fix memory Leak
- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix NULL dereference
- Refresh 0252-RHBZ-1623595-cmd-error-status.patch
- Resolves: bz #1610867, #1638651
LL/zqo'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0}qq'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066|q}'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q{qs'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
+>qK(Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-125\d- Modify 0250-RHBZ-1610867-rescan-change.patch
  * Fix memory Leak
- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix NULL dereference
- Refresh 0252-RHBZ-1623595-cmd-error-status.patch
- Resolves: bz #1610867, #1638651}q'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hqa'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P~q1'Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
cq'(Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556qA(Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651
LL/qo(Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0qq(Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066q}(Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qqs(Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
 +> qA)Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651}
q(Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h	qa(Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197Pq1(Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420

er+V:eD5
693e3ce2908adefcc2bc524795b6cde949103c699866ca985fd42a827214dd0eD4
946b8442c4a0e72fe683a8d2c6b3ab7143aa27670b547b3ff7849aa236ae494bD3
aa74fc65a3e070d797d17ec1a51bec20f0c5a1f1ff74f20bd9459369a3b80568D2
18263e1b0a03802679269ba3b6efec82086ba491183c1ab84bd9de4e5a98c071D1
0c9cd97e333e5ea85907e92483ef91dbdb08349b7e29916dcf5c08061c74f836D0
618179611cd44ba685db172d3afd1dc0248e66533a35b8e46cdf118d812340d3D/
6dafcb9ecc7ca14a4ae5417e71c1fee10a7213e0ebf3d3750cbd23a8cacf5eefD.
49776569805f34f9417a664fb394e7bff8444fee386100309ce6306cba1c8b1aD-
3bb0da4f1c883b5aaa0ad687bcc2022ba9573d912ff906b6657bc7e96676c5d9D,
5c0bed31f5ed7d1cccaeb6276746900d9f0fe837b806759153ea696c3b33b423D+
6337008a1e944b28b17317dcde8003b1ccb848dc5a09a17a27903c4e32e60846D*
ab2e63b3fe04a633b718c47d41143f7ffa9fb32076d41cfdb01feaef74cd6158D)
a8bf325bc65d56d5cd74d8b007f3b2f09f0d1f6deccd0c0d0f56f515423fe6eb
ppq')Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
LL/
qo)Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0qq)Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066q})Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qqs)Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
+>"qA*Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-126\d- Modify 0255-RHBZ-1638651-marginal-path.patch
  * Fix memory leak
- Resolves: bz #1638651q=)Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}q)Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hqa)Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197Pq1)Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
ppq'*Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
LL/qo*Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0qq*Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066q}*Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855qqs*Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
"+>"q=*Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}q*Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901hqa*Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197Pq1*Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
ppq'+Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
LL/ qo+Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0#qq+Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066"q}+Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q!qs+Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
+>"(q+Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-136cG- Add 0274-UP-no-duplicate-command-keys.patch
- Resolves: bz #2134905'q=+Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}&q+Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h%qa+Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P$q1+Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
pp)q',Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-127\B@- Add 0256-RHBZ-1672175-retry-no-fd-paths.patch
  * retry adding paths if they couldn't be opened initially
- Add 0257-RHBZ-1679556-dont-check-dm-devices.patch
  * don't check if dm devices are multipath paths
- Add 0258-RHBZ-1634183-ANA-prioritizer.patch
  * Add NVMe ANA path prioritizer
- Resolves: bz #1634183, #1672175, #1679556
LL/*qo,Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-128]QT- Modify 0258-RHBZ-1634183-ANA-prioritizer.patch
  * minor change
- Add 0259-RHBZ-1701604-fix-nr-active.patch
  * recalculate the number of active paths whenever a path is checked
- Add 0260-RHBZ-1634183-prio-fixes.patch
- Add 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * ignore blacklisted paths in mpathpersist
- Add 0262-RHBZ-1699486-reload-with-failed-paths.patch
  * allow forced reloads even if there are no reusable paths
- Add 0263-RHBZ-1686708-nvme-hcil.patch
  * make nvme ids work like in upstream
- Add 0264-RHBZ-1699441-de-series-config.patch
- Resolves: bz #1686708, #1699441, #1699486, #1701604, #1714506

O0-qq,Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-131]- Modify 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * The fix for 1721855 broke 1714506.
- Resolves: bz #17145066,q},Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-130]i- Add 0268-RHBZ-1721855-mpathpersist-fixes.patch
  * Fix issues in the mpathpersist speedup code
- Resolves: bz #1721855q+qs,Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-129]g@- Add 0265-RHBZ-1721855-mpathpersist-speedup.patch
  * only grab path information from necessary devices, and allow batch files.
- Add 0266-RHBZ-1696817-fix-emc-checker.patch
  * fix detection of inactive snapshots
- Add 0267-RHBZ-1661156-powermax-config.patch
- Remove 0261-RHBZ-1714506-skip-blacklisted-paths.patch
  * This fix is superseded by 0265-RHBZ-1721855-mpathpersist-speedup.patch
- Resolves: bz #1661156, #1696817, #1721855
+>"2q,Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-136cG- Add 0274-UP-no-duplicate-command-keys.patch
- Resolves: bz #21349051q=,Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-135a- Add 0273-RHBZ-1988462-fix-disable-changed-wwids-segfault.patch
- Resolves: bz #1988462}0q,Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-134__[@- Add 0272-RHBZ-1855901-lenovo-de.patch
- Resolves: bz #1855901h/qa,Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-133^A- Add 0270-RHBZ-1775481-segfault-fix.patch
  * Fix segfault related to missing dm device tables
- 0271-RHBZ-1806197-mpathconf-typo.patch
- Resolves: bz #1775481, #1806197P.q1,Benjamin Marzinski <bmarzins@redhat.com> 0.4.9-132^@- Add 0269-RHBZ-1804420-remove-kpartx-limit.patch
  * Remove the 256 device limit, when searching loop devices with kpartx
- Resolves: bz #1804420
_T_7-Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.21-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild6-Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.21-2P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild5cW-Petr Šabata <contyk@redhat.com> - 0.6.21-1P
- 0.6.21 bump
- A security bugfixing release (CVE-2012-2812, CVE-2012-2813, CVE-2012-2814,
  CVE-2012-2836, CVE-2012-2837, CVE-2012-2840, CVE-2012-2841 & CVE-2012-2845)
- Drop the pre-generated docs and introduce a doc subpackage4-Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.20-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild'3cm-Petr Sabata <psabata@redhat.com> - 0.6.20-1MI@- 0.6.20 bump
- Repackaging prehistoric libexif-docs, introducing version string in filename
- Buildroot cleanup
Yh>.Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.20-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild'=cm.Petr Sabata <psabata@redhat.com> - 0.6.20-1MI@- 0.6.20 bump
- Repackaging prehistoric libexif-docs, introducing version string in filename
- Buildroot cleanup<i!-Richard Hughes <rhughes@redhat.com> - 0.6.22-2_@- Fix CVE-2020-0181, CVE-2020-0198, and CVE-2020-0452
- Resolves: #1902589g;u]-Michael Catanzaro <mcatanzaro@redhat.com> - 0.6.22-1^@- Upgrade to 0.6.22
- Resolves: #1841316M:_?-Daniel Mach <dmach@redhat.com> - 0.6.21-6RU- Mass rebuild 2014-01-24M9_?-Daniel Mach <dmach@redhat.com> - 0.6.21-5Rk- Mass rebuild 2013-12-27R8cE-Petr Šabata <contyk@redhat.com> - 0.6.21-4QR@- Run autoreconf for aarch64
DCQDgEu].Michael Catanzaro <mcatanzaro@redhat.com> - 0.6.22-1^@- Upgrade to 0.6.22
- Resolves: #1841316MD_?.Daniel Mach <dmach@redhat.com> - 0.6.21-6RU- Mass rebuild 2014-01-24MC_?.Daniel Mach <dmach@redhat.com> - 0.6.21-5Rk- Mass rebuild 2013-12-27RBcE.Petr Šabata <contyk@redhat.com> - 0.6.21-4QR@- Run autoreconf for aarch64A.Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.21-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild@.Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.21-2P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild?cW.Petr Šabata <contyk@redhat.com> - 0.6.21-1P
- 0.6.21 bump
- A security bugfixing release (CVE-2012-2812, CVE-2012-2813, CVE-2012-2814,
  CVE-2012-2836, CVE-2012-2837, CVE-2012-2840, CVE-2012-2841 & CVE-2012-2845)
- Drop the pre-generated docs and introduce a doc subpackage
rw/rJ/Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.21-2P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildIcW/Petr Šabata <contyk@redhat.com> - 0.6.21-1P
- 0.6.21 bump
- A security bugfixing release (CVE-2012-2812, CVE-2012-2813, CVE-2012-2814,
  CVE-2012-2836, CVE-2012-2837, CVE-2012-2840, CVE-2012-2841 & CVE-2012-2845)
- Drop the pre-generated docs and introduce a doc subpackageH/Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.20-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild'Gcm/Petr Sabata <psabata@redhat.com> - 0.6.20-1MI@- 0.6.20 bump
- Repackaging prehistoric libexif-docs, introducing version string in filename
- Buildroot cleanupFi!.Richard Hughes <rhughes@redhat.com> - 0.6.22-2_@- Fix CVE-2020-0181, CVE-2020-0198, and CVE-2020-0452
- Resolves: #1902589
0dlx0R0Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.20-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild'Qcm0Petr Sabata <psabata@redhat.com> - 0.6.20-1MI@- 0.6.20 bump
- Repackaging prehistoric libexif-docs, introducing version string in filename
- Buildroot cleanupPi!/Richard Hughes <rhughes@redhat.com> - 0.6.22-2_@- Fix CVE-2020-0181, CVE-2020-0198, and CVE-2020-0452
- Resolves: #1902589gOu]/Michael Catanzaro <mcatanzaro@redhat.com> - 0.6.22-1^@- Upgrade to 0.6.22
- Resolves: #1841316MN_?/Daniel Mach <dmach@redhat.com> - 0.6.21-6RU- Mass rebuild 2014-01-24MM_?/Daniel Mach <dmach@redhat.com> - 0.6.21-5Rk- Mass rebuild 2013-12-27RLcE/Petr Šabata <contyk@redhat.com> - 0.6.21-4QR@- Run autoreconf for aarch64K/Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.21-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
DCQDgYu]0Michael Catanzaro <mcatanzaro@redhat.com> - 0.6.22-1^@- Upgrade to 0.6.22
- Resolves: #1841316MX_?0Daniel Mach <dmach@redhat.com> - 0.6.21-6RU- Mass rebuild 2014-01-24MW_?0Daniel Mach <dmach@redhat.com> - 0.6.21-5Rk- Mass rebuild 2013-12-27RVcE0Petr Šabata <contyk@redhat.com> - 0.6.21-4QR@- Run autoreconf for aarch64U0Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.21-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildT0Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.21-2P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildScW0Petr Šabata <contyk@redhat.com> - 0.6.21-1P
- 0.6.21 bump
- A security bugfixing release (CVE-2012-2812, CVE-2012-2813, CVE-2012-2814,
  CVE-2012-2836, CVE-2012-2837, CVE-2012-2840, CVE-2012-2841 & CVE-2012-2845)
- Drop the pre-generated docs and introduce a doc subpackage
rw/r^1Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.21-2P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild]cW1Petr Šabata <contyk@redhat.com> - 0.6.21-1P
- 0.6.21 bump
- A security bugfixing release (CVE-2012-2812, CVE-2012-2813, CVE-2012-2814,
  CVE-2012-2836, CVE-2012-2837, CVE-2012-2840, CVE-2012-2841 & CVE-2012-2845)
- Drop the pre-generated docs and introduce a doc subpackage\1Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.20-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild'[cm1Petr Sabata <psabata@redhat.com> - 0.6.20-1MI@- 0.6.20 bump
- Repackaging prehistoric libexif-docs, introducing version string in filename
- Buildroot cleanupZi!0Richard Hughes <rhughes@redhat.com> - 0.6.22-2_@- Fix CVE-2020-0181, CVE-2020-0198, and CVE-2020-0452
- Resolves: #1902589
dlx
ee12Lukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)di!1Richard Hughes <rhughes@redhat.com> - 0.6.22-2_@- Fix CVE-2020-0181, CVE-2020-0198, and CVE-2020-0452
- Resolves: #1902589gcu]1Michael Catanzaro <mcatanzaro@redhat.com> - 0.6.22-1^@- Upgrade to 0.6.22
- Resolves: #1841316Mb_?1Daniel Mach <dmach@redhat.com> - 0.6.21-6RU- Mass rebuild 2014-01-24Ma_?1Daniel Mach <dmach@redhat.com> - 0.6.21-5Rk- Mass rebuild 2013-12-27R`cE1Petr Šabata <contyk@redhat.com> - 0.6.21-4QR@- Run autoreconf for aarch64_1Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.6.21-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
<g	/2systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?f	u2systemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)#&57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9km2systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qj2systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)miW2systemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);hq2systemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17#%bR#xRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{"b"c"d"g"l"m#n#q#v#y#z#}####	#
##

######## ###(#)#*#-#2#7#>#E#J# R#!Y#"^##e#$g#'k#)o#*q#-u#.x#/z#2~#3#4#7#8#<#=#>#A#B#C$#D'#E-#F0#G5#H8#I=#JA#KF#LJ#MN#PR#QU#TY#U\#V^#Yb#Zf#[h#^l#_p#bt#cx#d{#g#h#i#j#k#m#n#o#p!#q%#r*#s2#t;#uD#vM#wU
.
oe13Lukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)n	2systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)Xm	'2systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)flI2systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<q	/3systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?p	u3systemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)#,57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9um3systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qt3systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)msW3systemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);rq3systemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17#+
..x	3systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)Xw	'3systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fvI3systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<z	/4systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?y	u4systemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)#157704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9~m4systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q}4systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m|W4systemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);{q4systemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17#0
.
	4systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	4systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'4systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fI4systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<	/5systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?	u5systemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)#657704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9m5systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q5systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mW5systemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);q5systemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17#5
.
	5systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	5systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X
	'5systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f	I5systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)

er+V:eDB
80b9e73c5db5a194278ac3415303dcf5c49c780dae020e15b55a65a9e02f2a56DA
c5512bfc8f5d17195d34252e20dd34ef75e390d9bb8a38b30ba8be4e5c0904adD@
dcccb19275e44c98b220ff45b313949c6d1e421f5326c9e3d8f568c1ae986c15D?
894926755bf0b5caaf2195043acd56dcc5dc992c1c51411a5e923a6e2e1d55cbD>
a8d6b71da3251c0921f8f1c9a527fe6468bab3f326f472567681e24f3f9bbd61D=
02f065f8fc1a7dad64b3db9dce1c2acf7f0fdb727133ffef1c209fa011adbcd6D<
841781e279649ca9fced8e74583d9a30e6d5e96023b689f339cd0c6814f8a746D;
30f73d4f8a1abd8421100fbb68de1f107a838a542bb020b5e22316b330a1560cD:
f111af81b1171cde02cdf42152cd2cf0b250c9a755cff39952df38908f7a55f8D9
126385b940d5f6f201b6b30130139b0125b1d44dc7842c59cc7cbba5a9a4404dD8
3aa88d01f6198efa435e94380ac7bb30d03f89a522b7860137a566276cea51c9D7
1ee43730cfd6c1751ff45f321c91c0f0965e683e47cb52b91f87ac210ed93c1aD6
de11efb648c50dca4022b29c14b4bc06fdcb8f36be5009d20018c917583af9bc#;57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9m6systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q6systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mW6systemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);
q6systemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17#:
.
	6systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	6systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'6systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fI6systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
\(\;q7systemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17#?.	S6systemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) 	76systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)#@57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
X	'7systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fI7systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9m7systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q7systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mW7systemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744)
u 	77systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)
rMwOrX$	'8systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f#I8systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9"m8systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q!8systemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291). 	S7systemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361)
u '	78systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
&	8systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)%	8systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)
0M.X0f-I9systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9,m9systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q+9systemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)
*	8systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544))	
8systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).(	S8systemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361)
#
0	9systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)/	9systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X.	'9systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
(	f5I:systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
4	9systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)3	
9systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).2	S9systemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) 1	79systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
8	:systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)7	:systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X6	':systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
u(	u=	:systemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
<	:systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544);	
:systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).:	S:systemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) 9	7:systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
bA	;systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X@	';systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f?I;systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)>	):systemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)
wnIw
F	;systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)E	
;systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).D	S;systemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) C	7;systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
B	;systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)
{l?{?J	u<systemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)
Ie1<Lukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)H	);systemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)G	;systemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
L_"LQN<systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mMW<systemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);Lq<systemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17#NK	/<systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)#O57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
pBpR	<systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)XQ	'<systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fPI<systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9Om<systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)
qU	/=systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?T	u=systemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)
Se1=Lukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)#S57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9Ym=systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)QX=systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mWW=systemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);Vq=systemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17#R
..\	=systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X[	'=systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fZI=systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<^	/>systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?]	u>systemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)#X57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9bm>systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qa>systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m`W>systemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);_q>systemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17#W
.
f	>systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)e	>systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)Xd	'>systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fcI>systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<h	/?systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?g	u?systemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)#]57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9lm?systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qk?systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mjW?systemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);iq?systemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17#\
.
p	?systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)o	?systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)Xn	'?systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fmI?systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)#a57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9tm@systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qs@systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mrW@systemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);qq@systemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17#`
.
x	@systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)w	@systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)Xv	'@systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fuI@systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
\(\;{qAsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17#e.z	S@systemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) y	7@systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)#f57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
X	'Asystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fIAsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9~mAsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q}Asystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m|WAsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744)
u 	7Asystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
	Asystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	Asystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)
rMwOrX	'Bsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fIBsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9mBsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)QBsystemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291).	SAsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361)
u 	7Bsystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
	Bsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)		Bsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)
0M.X0fICsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9mCsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)QCsystemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)
	Bsystemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)
	
Bsystemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).	SBsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361)

er+V:eDO
1db80fc0b7ec4ad66d1f7b86e831c3ed4d4386b1db1558cc7afcecf08ff5184eDN
5cf5d9d1af4c78ca14d14daa45c998d5f75484a3ab878d4a4e8caae845ff0c1dDM
551d2065c265d1e53d4bec46b49874d3aff2ccc0e5b50f98b64fb49c31c77700DL
54d67315041544440edcdc1a784b786f749cce152edd23d3ed953826b64a5b3bDK
7ae732734ae47230b9ee78bd90d72d963f85df5663e2f2ce2377f9f040e2ced7DJ
d91245d56499e00006afb5caef9f595c26917df6d3112f9952a0e2b928994342DI
565a99b9e94164785e21e6c316bc072e35df5c03df3267601461e2b96157b0f9DH
fc6296617d74745ac75f51e708264f5e77144e1a594d2ddfaadc84e9d9d9624dDG
ca42c81542be47ee686bcb3662bdb26e91f2fa0041534bf807e0b9294dcae15aDF
1409a93de8f33913e0adaf61bf58a25d2d2e6253e503e532e910519107835c33DE
df76a933cd54ed2e60e4eacb34639d343d8e273926033d63c3e9f0090215673eDD
c7963550f0e18a7fdd4139bb7942c93b0a9cffc5bec4e5833552b722e442120fDC
0d7fa70d37741c62bde710cf842f10260cf261673a4a7408c061b0e28d2bc955
#
	Csystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	Csystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'Csystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
(	fIDsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
	Csystemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)	
Csystemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).	SCsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) 	7Csystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
	Dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	Dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'Dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
u(	u!	Dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
 	Dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)	
Dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).	SDsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) 	7Dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
b%	Esystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X$	'Esystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f#IEsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)"	)Dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)
wnIw
*	Esystemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544))	
Esystemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).(	SEsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) '	7Esystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
&	Esystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)
Ilf*I{2iFRichard Hughes <rhughes@redhat.com> - 3.28.1-2[#@- Backport a patch to fix a gnome-shell crash
- Related: #1569295^1e[FKalev Lember <klember@redhat.com> - 3.28.1-1Z- Update to 3.28.1
- Resolves: #1569295c0qYFFlorian Müllner <fmuellner@redhat.com> - 3.26.0-1Y- Update to 3.26.0
- Related: #1481381^/e[FKalev Lember <klember@redhat.com> - 3.20.4-1XbW- Update to 3.20.4
- Resolves: #1387009o.e}FKalev Lember <klember@redhat.com> - 3.14.1-3W- Switch to new METAR data provider
- Resolves: #1371550d-kaFMatthias Clasen <mclasen@redhat.com> - 3.14.1-2Wv[@- Update translations
  Resolves: #1304249,	)Esystemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)+	Esystemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
	;Af;^;e[GKalev Lember <klember@redhat.com> - 3.28.1-1Z- Update to 3.28.1
- Resolves: #1569295c:qYGFlorian Müllner <fmuellner@redhat.com> - 3.26.0-1Y- Update to 3.26.0
- Related: #1481381^9e[GKalev Lember <klember@redhat.com> - 3.20.4-1XbW- Update to 3.20.4
- Resolves: #1387009o8e}GKalev Lember <klember@redhat.com> - 3.14.1-3W- Switch to new METAR data provider
- Resolves: #1371550d7kaGMatthias Clasen <mclasen@redhat.com> - 3.14.1-2Wv[@- Update translations
  Resolves: #1304249s6uuFMichael Catanzaro <mcatanzaro@redhat.com> - 3.28.2-4`Y@- Fix no weather data available
- Resolves: #1938275c5]mFDavid King <dking@redhat.com> - 3.28.2-3]>- Fix multilib conflict in subpackage (#1623538){4o	FDebarshi Ray <rishi@fedoraproject.org> - 3.28.2-2[l,- Fix dangling symbolic link to README.md
- Resolves: #1569295^3e[FKalev Lember <klember@redhat.com> - 3.28.2-1[a- Update to 3.28.2
- Resolves: #1569295
	9ZcDqYHFlorian Müllner <fmuellner@redhat.com> - 3.26.0-1Y- Update to 3.26.0
- Related: #1481381^Ce[HKalev Lember <klember@redhat.com> - 3.20.4-1XbW- Update to 3.20.4
- Resolves: #1387009oBe}HKalev Lember <klember@redhat.com> - 3.14.1-3W- Switch to new METAR data provider
- Resolves: #1371550dAkaHMatthias Clasen <mclasen@redhat.com> - 3.14.1-2Wv[@- Update translations
  Resolves: #1304249s@uuGMichael Catanzaro <mcatanzaro@redhat.com> - 3.28.2-4`Y@- Fix no weather data available
- Resolves: #1938275c?]mGDavid King <dking@redhat.com> - 3.28.2-3]>- Fix multilib conflict in subpackage (#1623538){>o	GDebarshi Ray <rishi@fedoraproject.org> - 3.28.2-2[l,- Fix dangling symbolic link to README.md
- Resolves: #1569295^=e[GKalev Lember <klember@redhat.com> - 3.28.2-1[a- Update to 3.28.2
- Resolves: #1569295{<iGRichard Hughes <rhughes@redhat.com> - 3.28.1-2[#@- Backport a patch to fix a gnome-shell crash
- Related: #1569295
	#>`#^Me[IKalev Lember <klember@redhat.com> - 3.20.4-1XbW- Update to 3.20.4
- Resolves: #1387009oLe}IKalev Lember <klember@redhat.com> - 3.14.1-3W- Switch to new METAR data provider
- Resolves: #1371550dKkaIMatthias Clasen <mclasen@redhat.com> - 3.14.1-2Wv[@- Update translations
  Resolves: #1304249sJuuHMichael Catanzaro <mcatanzaro@redhat.com> - 3.28.2-4`Y@- Fix no weather data available
- Resolves: #1938275cI]mHDavid King <dking@redhat.com> - 3.28.2-3]>- Fix multilib conflict in subpackage (#1623538){Ho	HDebarshi Ray <rishi@fedoraproject.org> - 3.28.2-2[l,- Fix dangling symbolic link to README.md
- Resolves: #1569295^Ge[HKalev Lember <klember@redhat.com> - 3.28.2-1[a- Update to 3.28.2
- Resolves: #1569295{FiHRichard Hughes <rhughes@redhat.com> - 3.28.1-2[#@- Backport a patch to fix a gnome-shell crash
- Related: #1569295^Ee[HKalev Lember <klember@redhat.com> - 3.28.1-1Z- Update to 3.28.1
- Resolves: #1569295
<7Vp<8UYJJarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274sTuuIMichael Catanzaro <mcatanzaro@redhat.com> - 3.28.2-4`Y@- Fix no weather data available
- Resolves: #1938275cS]mIDavid King <dking@redhat.com> - 3.28.2-3]>- Fix multilib conflict in subpackage (#1623538){Ro	IDebarshi Ray <rishi@fedoraproject.org> - 3.28.2-2[l,- Fix dangling symbolic link to README.md
- Resolves: #1569295^Qe[IKalev Lember <klember@redhat.com> - 3.28.2-1[a- Update to 3.28.2
- Resolves: #1569295{PiIRichard Hughes <rhughes@redhat.com> - 3.28.1-2[#@- Backport a patch to fix a gnome-shell crash
- Related: #1569295^Oe[IKalev Lember <klember@redhat.com> - 3.28.1-1Z- Update to 3.28.1
- Resolves: #1569295cNqYIFlorian Müllner <fmuellner@redhat.com> - 3.26.0-1Y- Update to 3.26.0
- Related: #1481381
pob[[mJHonggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
Z[;JHonggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585VYYUJJarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296XY)JJarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541xWYJJarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426VY?JJarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#1687426
|qE|xaYKJarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426`Y?KJarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#16874268_YKJarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274^[OJHonggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699][CJHonggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
\[;JHonggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482
{g[CKHonggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
f[;KHonggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482be[mKHonggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
d[;KHonggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585VcYUKJarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296bY)KJarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541
>g>VmYULJarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296lY)LJarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541xkYLJarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426jY?LJarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#16874268iYLJarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274h[OKHonggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699
q|P8sYMJarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274r[OLHonggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699q[CLHonggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
p[;LHonggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482bo[mLHonggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
n[;LHonggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585
poby[mMHonggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
x[;MHonggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585VwYUMJarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296vY)MJarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541xuYMJarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426tY?MJarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#1687426
|qE|xYNJarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426~Y?NJarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#16874268}YNJarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274|[OMHonggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699{[CMHonggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
z[;MHonggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482
{[CNHonggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
[;NHonggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482b[mNHonggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
[;NHonggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585VYUNJarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296Y)NJarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541
g
o'OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTo;OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z][ONHonggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699
2owOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|
oOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t	o{OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoEOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A
oOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
|To;PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]qOOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]

er+V:eD\
ecf00639a05e5928c699eb7451b91c04ef62ea4e3ada1c96ee6c9ba35c065f28D[
388aba1b0bdea4684f1db472cbd84cc4331e3d51543a84e076c8c8209113539eDZ
6b59b214e1d648dd6450ccf97a6e02143f15dcb331b6d520b32e3390c35df31eDY
3be8775407bc08f4fe54e5628c556d5472f9d4ef0d5b89d29c9c9b634121cb07DX
a48861f8b0007e766c5886a948e293f97eb2f45c90d1afc5373722cf5a163b72DW
0cad55db6dba2a060d78d5cd109fe110b948f6008192e29b843fe591ffec7fc2DV
dbd4fcb28f8cbfd9fb540e8d37c4b83f661fd5b856fa728606339a61f95f4513DU
0b0f6b7bf49772aa7d4525fb75fddff1ff77a08c6c3cf4c990c7fcb0fd59a2b9DT
a4ed3b8d30ed584009accf96a7436d098f14e555ae10c804f398816146a347e6DS
1e9ecb13d56ad5c7fa67acece7a0f89c452b11bad3fc66a7589eb57a67fdb766DR
00dbfd02a12975ec58e646015d21c1697f304b58353b1372310d96c80b2903aeDQ
4c0fe67802024d085939269a1da54ef7d9c6feea27bc2b6b94c3c64d18835d38DP
7bb7db4c0e3b5dbb711a2589b4e752e8fe25c9b73185eaa3eecc00450d613c21
wqxw|oPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
o'QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetqOPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2owQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoEQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A oQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-!omQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?$q9QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)#qOQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down"oQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|'oRAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t&o{RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
%o'RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2(owRAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y)oERAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A*oRAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-+omRAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?.q9RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)-qORAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down,oRAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
21owSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|0oSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t/o{SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y2oESAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A3oSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-4omSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?7q9SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)6qOSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down5oSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|:oTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t9o{TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)h8qaSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2;owTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y<oETAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A=oTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN->omTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Aq9TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)@qOTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down?oTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2DowUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|CoUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hBqaTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YEoEUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]bR#RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{#ya#zg#{m#|s#}y#~#####
########### #!#$#'#(#)#*#+#.#1#2#3#4#7#:#;#<#=#>#A#D#E#F#G#J#M#N#O#P#Q#T#W#X#Y#Z#]#`#a#b#c#d#g#j#k#l#m#p#s#t#u#v#Áw#āz#Ł}#Ɓ#ǁ#ȁ#Ɂ#ʁ	#ˁ
#́
#́#΁#Ё#с#ҁ#Ӂ#ԁ #Ձ"#ց%#ׁ(#؁+#ف.#ځ/#ہ0#܁3#݁5
::AFoUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-GomUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Jq9UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)IqOUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downHoUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|MoVAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))|Lq	UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hKqaUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2NowVAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YOoEVAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::APoVAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-QomVAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Tq9VAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)SqOVAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downRoVAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2WowWAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Vq	VAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hUqaVAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YXoEWAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AYoWAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-ZomWAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?]q9WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)\qOWAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down[oWAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm `qQWAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|_q	WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h^qaWAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2aowXAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YboEXAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AcoXAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-domXAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?gq9XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)fqOXAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downeoXAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm jqQXAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|iq	XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hhqaXAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YkoEYAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AloYAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-momYAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?pq9YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)oqOYAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downnoYAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm sqQYAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|rq	YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqqaYAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
=tqYAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
""YuoEZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AvoZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-womZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?zq9ZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)yqOZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downxoZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm }qQZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]||q	ZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h{qaZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
Ao[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=~qZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-om[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQ[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
//A	o\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]D}
[Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=q[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-
om\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?
q9\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQ\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.a}]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD}
\Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=q\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]

er+V:eDi
b4bb4d388af0708a559cf09c5a7fc75ab89a349115729620b72c790f28e7422eDh
9ebd06e0dbe03a1b81d2bb45598fa8b2a8423c754eb01c2dc19009b37889af7dDg
ac082581e82346ea696427fe38a4a1ad08c1a2f428d21c026da32d80aa0c4cfeDf
79b1198c3958d0c5aaf003eb2c5f482ad658aac62e3b7fe05127e6498153d891De
9ddb3989f547bec0175c3f866ce77a6ac4742203e5567fcd03af76e451568f49Dd
6e22c4b0aee7e9979b7f739d1db74f8609f8f27a72d28c139c4b20648516c712Dc
3cfc9f52a00f0406e2e427948342a30ca2cd4762712b56ebee9d8bf24018e163Db
720ce08cb7d09fef55e566296d6985f0a465fbdb1a66bfda747f53f178f67f3aDa
4168f549a1eed91719335c29e0efff79a7747ffbbdf777b56e435e5123a039a7D`
0f725b790a384924e7b95b0b06d3009171c8060554b98e9cc285dabe9c324930D_
75cdb68690a46ab40f6949579f2ea4df2f3e811398a7dcefb77813e87272e899D^
d787f263d801d560eb3933a597fbdb2f4eb89a55b5cd49730ab0dc795715c028D]
9c3d41d6041f9bdd8e0938ed6e0638aa29653f13b1631dd40dfbcc0dce9adc28
Tta	]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)as]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).ya]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pg;]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_c]]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxg]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pg{]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)g']Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
ya^Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..a}^Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen.gw]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
Rt a	^Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)as^Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
P"g;^Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_!c]^Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux%g^Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p$g{^Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)#g'^Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-(is_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}'i_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..&gw^Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT+o;_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c*k]_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex)i	_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|.o_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t-o{_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
,o'_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2/ow_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y0oE_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Lx3i	`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-2is`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}1i`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
T5o;`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c4k]`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|8o`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t7o{`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
6o'`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
29ow`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y:oE`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nx<i	aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-;isaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
T>o;aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c=k]aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|AoaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t@o{aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
?o'aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2BowaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YCoEaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:-EisbAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).ADoaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
CCTHo;bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cGk]bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is FalsexFi	bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|KobAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tJo{bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Io'bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2LowbAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YMoEbAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xOi	cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationANobAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
TQo;cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cPk]cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|TocAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tSo{cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Ro'cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2UowcAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YVoEcAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AWocAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NxYi	dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-XomcAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
T[o;dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cZk]dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|^odAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t]o{dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
\o'dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2_owdAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y`oEdAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AaodAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-bomdAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
teo{eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
do'eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTco;eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2goweAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|foeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YhoEeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AioeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-jomeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
|Tmo;fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]lqOeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downkoeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|pofAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))too{fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
no'fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2qowfAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YroEfAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AsofAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-tomfAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
wo'gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetvqOfAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downuofAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2zowgAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|yogAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))txo{gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y{oEgAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A|ogAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-}omgAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOgAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down~ogAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|ohAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{hAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'hAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetbR$CRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{#߁9#:#<#>#A#B#C#E#H#K#L#M#O#Q#T#U#V#W#Y#[#^#_#`#a#b#e#g#h#i#j#m#p#q$r$s$t$w$z${$|$}$$	$$$
$$
$
$$$$$$$$$$$ $!$"$#$ &$!)$"*$#+$$,$%-$&0$'3$(4$)5$*6$+9$,<$-=$.>$/?$0@$1C$2F$3G$4H$5I$6L$7O$8P$9Q$:R$;S$<V$=Y$>[$?\$@_$Ab$Be
2owhAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEhAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AohAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omhAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?
q9hAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)	qOhAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downohAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2
owiAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oiAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoEiAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoiAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omiAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOiAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoiAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|ojAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)hqaiAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update

er+V:eDv
33522ef6344e2c23c9585439f96860fbac64c8059e3fafe85e39f00d654826beDu
676257fa89a2415e1fed624878b0d5c3f3c334c139f75c44938d08415b9e8b3fDt
9c9453260d66b8957dc7fb411913d40ce90346035eda2b58c2f9c759b2125cf7Ds
0f791fdbdca1788b246815a870b316c43b536133a58c0b7483e09cce243dbf52Dr
beeb913c932963a0d8888e51c12b07a6993454a38f7ef567a5a56da4208e5949Dq
f035504bb52e167428211e66d8d1e6057ea84e13f5eb03edf9c7d58b26a52b99Dp
5df1a4e83ab5135939c23e1037e6d05b3b83a60b3b4a06fb6e85e91959657cbdDo
c942cd6a2b252aa88c37729e5753a20d63376cc0d329bdcbc5265806440a4f46Dn
b1a437d314e4c8a0e5d1e099a8fdbcdb1ff51d9795ce9c175c3bce0b7e4ca564Dm
4483963c33f057bfcd4b6120dbcefdc634413263eea9af2c988563522cfa5127Dl
0136b7f5a2716c2969f4dc132e19b7819af04e2aa0c5ba9bd9774ccf09c14e9fDk
9b4b4560b2485d70634ad393bde40d05f38c2ecce03135964bdc3876bf556570Dj
07b1856027333bf98a662c1c5c7b92d2391deb1108f57f3ca5b27d6ee192f7a0
2owjAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEjAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AojAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omjAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOjAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downojAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2 owkAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|okAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hqajAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y!oEkAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A"okAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-#omkAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?&q9kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)%qOkAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down$okAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|)olAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))|(q	kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h'qakAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2*owlAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y+oElAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A,olAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN--omlAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?0q9lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)/qOlAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down.olAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[23owmAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|2q	lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h1qalAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y4oEmAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A5omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-6ommAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?9q9mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)8qOmAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down7omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm <qQmAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|;q	mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h:qamAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2=ownAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y>oEnAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A?onAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-@omnAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Cq9nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)BqOnAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downAonAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm FqQnAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Eq	nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hDqanAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YGoEoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AHooAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-IomoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Lq9oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)KqOoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downJooAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm OqQoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Nq	oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hMqaoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
=PqoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
""YQoEpAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ARopAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-SompAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Vq9pAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)UqOpAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downTopAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm YqQpAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Xq	pAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hWqapAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
A[oqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=ZqpAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-\omqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?_q9qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)^qOqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down]oqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm bqQqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|aq	qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h`qaqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
//AeorAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]Dd}
qEduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=cqqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-fomrAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?iq9rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)hqOrAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downgorAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm lqQrAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|kq	rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hjqarAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.oa}sAlexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenDn}
rEduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=mqrAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Ttra	sAlexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)qassAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).ypasAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Ptg;sAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_sc]sAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxwgsAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pvg{sAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)ug'sAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
yzatAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..ya}tAlexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen.xgwsAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
Rt|a	tAlexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization){astAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
P~g;tAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_}c]tAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxgtAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pg{tAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)g'tAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-isuAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}iuAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..gwtAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTo;uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexi	uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|
ouAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t	o{uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owuAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEuAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Lxi	vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-isvAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}
ivAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
To;vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|ovAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owvAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEvAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]

er+V:eD
1a363c8575a8323b1e1cbafa08ba87655572c3b032a755bcf5cf957927fb9a70D
ec1b22bbbd65cf0d8ac4abc748b4d4e1721149c816440d123ce3d707e25059a8D
8f22a24548ec519571fd7dcc4779339bb29955be70e289533d286d4069cdfe23D
3c4ec0f5afdd9b9d8e623857335cfd73d8e86540fe7c74886a0fc678fbf926acD
b410c0490c2af4f7e5e57b126535f682c43747b4f65ab0c3b8b86259df169293D~
2d79f11c74a72adcef4f3407e674947b25332958c8d3722a976ffc2d712fb812D}
ca2534fe257e28c069b648a161fddd50d841f1df267a98ca33d8ceea488d83c7D|
868a84b5cfeae8a5e75edd91fc853a5ed3490b4de3805f6ff0020f5483875122D{
ad1b306ed16dae044e07261f88e7b3e1846b160926009eba1eb3b872ad1d6443Dz
03701d6e0d843fdfb34d5135af97796623145817df79fabb6a8fb6eed7cfb552Dy
fb317c790c7775a8cd2becc6286e6028a33743078585cef6e150d0614e34aa17Dx
4aeb4ec586ae68b258e3a26e5bf455914a1bef9bf96ce52ea53b74decb9d1176Dw
31f46b22cd82ef4ccbb472cae30cc13508b35a42fe8d5807a5d9fc45b18a830a
Nxi	wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-iswAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
To;wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owwAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEwAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:-!isxAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).A owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
CCT$o;xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c#k]xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex"i	xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|'oxAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t&o{xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
%o'xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2(owxAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y)oExAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:x+i	yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationA*oxAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
T-o;yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c,k]yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|0oyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t/o{yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
.o'yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
21owyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y2oEyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A3oyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
Nx5i	zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-4omyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
T7o;zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c6k]zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|:ozAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t9o{zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
8o'zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2;owzAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y<oEzAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A=ozAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NNN|@m
{Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927|?m
{Robbie Harwood <rharwood@redhat.com> - 1.15.1-41]>- Update man pages to reference kerberos(7)
- Resolves: #1704726->omzAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]bR$RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{$Di$El$Fo$Gr$Ht$Iw$Jz$K|$L~$M$N$O$P
$Q$R$S$T$U$V$W$Y$Z$[$\$]$^!$_$$`'$a($b)$c+$d-$e0$f1$g2$h3$i5$j7$k:$l;$m<$n=$o@$qG$rN$sU$t\$uc$vj$wq$xx$y$z${
$|$}$'$0$9$B$K$T$]$c$i$n$t${$$	$$$$!$#$($+$-$2$5$7$<$?$A$E$L$R$X$_$d$k$q$w$}$$	$$
vGm{Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Fm{Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Em{Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oDmu{Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126eCma{Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|Bm
{Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506Am{Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347
{{qoNmu|Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126eMma|Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|Lm
|Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506Km|Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|Jm
|Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927|Im
|Robbie Harwood <rharwood@redhat.com> - 1.15.1-41]>- Update man pages to reference kerberos(7)
- Resolves: #1704726Hm{Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492
eztoe|Um
}Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506Tm}Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|Sm
}Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927Rm|Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492Qm|Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Pm|Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Om|Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289
z$z\m=}Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599[m}Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492Zm}Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Ym}Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492Xm}Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oWmu}Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126eVma}Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726
v
cm~Robbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492bm~Robbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oamu~Robbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126e`ma~Robbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|_m
~Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506^m~Robbie Harwood <rharwood@redhat.com> - 1.15.1-43]>- Correct kpasswd_server description in krb5.conf(5)
- Resolves: #1498347|]m
~Robbie Harwood <rharwood@redhat.com> - 1.15.1-42]>- Log when non-root ksu authorization fails
- Resolves: #1270927
}}_v}jmRobbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289oimuRobbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126ehmaRobbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726|gm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506fm=~Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599em~Robbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492dm~Robbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492
?}uF?|qm
Robbie Harwood <rharwood@redhat.com> - 1.15.1-44]>- Address some optimized-out memset() calls
- Resolves: #1663506piJulien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163oi;Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319nm=Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599mmRobbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492lmRobbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492kmRobbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492
z$zxm=Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599wmRobbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492vmRobbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492umRobbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492tmRobbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289osmuRobbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126ermaRobbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726
{jz{mRobbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492~mRobbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492}mRobbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289o|muRobbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126e{maRobbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726ziJulien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163yi;Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319
Z{L6ZomuRobbie Harwood <rharwood@redhat.com> - 1.15.1-46]>- Add pkinit_cert_match support
- Resolves: #1656126emaRobbie Harwood <rharwood@redhat.com> - 1.15.1-45]>- Install kerberos(7)
- Resolves: #1704726
i-Julien Rische <jrische@redhat.com> - 1.15.1-55cjD- Fix integer overflows in PAC parsing (CVE-2022-42898)
- Resolves: rhbz#2140961iJulien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163i;Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319m=Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599mRobbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492
9ztV9
iJulien Rische <jrische@redhat.com> - 1.15.1-54bi0@- Try harder to avoid password change replay errors
- Resolves: #2063163i;Julien Rische <jrische@redhat.com> - 1.15.1-53bN@- Backport usage of SHA-256 instead of SHA-1 for PKINIT CMS digest
- Resolves: #2066319m=Antonio Torres <antorres@redhat.com> - 1.15.1-51ap- Fix KDC null deref on TGS inner body null server (CVE-2021-37750)
- Resolves: #1997599
mRobbie Harwood <rharwood@redhat.com> - 1.15.1-50^- Disable smoke tests on s390x and remove sleep
- Resolves: #1782492	mRobbie Harwood <rharwood@redhat.com> - 1.15.1-49^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492mRobbie Harwood <rharwood@redhat.com> - 1.15.1-48^- Fix LDAP policy enforcement of pw_expiration
- Resolves: #1782492mRobbie Harwood <rharwood@redhat.com> - 1.15.1-47^- Do expiration warnings for all init_creds APIs
- Resolves: #1733289
Aq	";AFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild[[_Tomas Mraz <tmraz@redhat.com> - 1.3.0-2P@- fix multilib conflict in libksba-configH[9Tomas Mraz <tmraz@redhat.com> - 1.3.0-1P@- new upstream versionFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-3P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_RebuildH[9Tomas Mraz <tmraz@redhat.com> - 1.2.0-1NJ[- new upstream versiondicRex Dieter <rdieter@fedoraproject.org> 1.0.8-3M{@- libksba-devel multilib conflict (#601976)
i-Julien Rische <jrische@redhat.com> - 1.15.1-55cjD- Fix integer overflows in PAC parsing (CVE-2022-42898)
- Resolves: rhbz#2140961
	q`Rq[[_Tomas Mraz <tmraz@redhat.com> - 1.3.0-2P@- fix multilib conflict in libksba-configH[9Tomas Mraz <tmraz@redhat.com> - 1.3.0-1P@- new upstream versionFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-3P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_RebuildH[9Tomas Mraz <tmraz@redhat.com> - 1.2.0-1NJ[- new upstream versiondicRex Dieter <rdieter@fedoraproject.org> 1.0.8-3M{@- libksba-devel multilib conflict (#601976)V_QJakub Jelen <jjelen@redhat.com> - 1.3.0-6cO- Fix for CVE-2022-3515 (#2135695)L]?Daniel Mach <dmach@redhat.com> - 1.3.0-5RU- Mass rebuild 2014-01-24L]?Daniel Mach <dmach@redhat.com> - 1.3.0-4Rk- Mass rebuild 2013-12-27

er+V:eD
4d0e360eff9294623b345353bcf2cb4623c50a3e2bf31ace6ba05141150d85fdD
359852ce38e0555b23e78c945070ef67c0599138eac0c52de77a819e8fdebce9D
cec370a7441899c3ffcd47f783a0437d9d649fd4a1252c6c317561f431e537c4D

36ad5a43df60889dd9c1134cb0e042317befa64f7293f44bc91271fddbbfc7e6D
d5b31f13f3b46bf5b0b92ae49a2422fef7d5c0ecefccc27c7b96a0aae7f7ce31D
0c8fa4695663226154eeb62875404c38ac8f61913460fe2e8036ae8e76cad75eD

082abb4e91620918c0d5d1da8dfb191f950c793d112a4ac3ec4f2055ca594c68D	
d66f8f50f89a80ba6132ad39773812f3a9b5d598db35a63de6e8465c3c7137d8D
ee580eaecadcceeb9560a23a48c376d9c012f5fee8623d0f10419c273b744065D
46064f76c45b401ff1197bbdcd32585b704afcef86d2dad3fb76250749b3ef7dD
b93825bf103f570b5e1032748e404b0d685f2025279cdfd1efbd0506671dd269D
09f2614aeded0a8d1f7454f0270fe81a129ba048470ed9851001049d758c2a0fD
02d7a80b905c4425a04fb580f2e9cedea180c37a12f4aebcc804d768f6a12ffd
	>ek>['[_Tomas Mraz <tmraz@redhat.com> - 1.3.0-2P@- fix multilib conflict in libksba-configH&[9Tomas Mraz <tmraz@redhat.com> - 1.3.0-1P@- new upstream version%Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-3P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild$Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_RebuildH#[9Tomas Mraz <tmraz@redhat.com> - 1.2.0-1NJ[- new upstream versionV"_QJakub Jelen <jjelen@redhat.com> - 1.3.0-6cO- Fix for CVE-2022-3515 (#2135695)L!]?Daniel Mach <dmach@redhat.com> - 1.3.0-5RU- Mass rebuild 2014-01-24L ]?Daniel Mach <dmach@redhat.com> - 1.3.0-4Rk- Mass rebuild 2013-12-27Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
	Bek)BH0[9Tomas Mraz <tmraz@redhat.com> - 1.3.0-1P@- new upstream version/Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-3P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild.Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_RebuildH-[9Tomas Mraz <tmraz@redhat.com> - 1.2.0-1NJ[- new upstream versionW,_SJakub Jelen <jjelen@redhat.com> - 1.3.0-7c- Fix for CVE-2022-47629 (#2161571)V+_QJakub Jelen <jjelen@redhat.com> - 1.3.0-6cO- Fix for CVE-2022-3515 (#2135695)L*]?Daniel Mach <dmach@redhat.com> - 1.3.0-5RU- Mass rebuild 2014-01-24L)]?Daniel Mach <dmach@redhat.com> - 1.3.0-4Rk- Mass rebuild 2013-12-27(Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
	bfIb9Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_RebuildH8[9Tomas Mraz <tmraz@redhat.com> - 1.2.0-1NJ[- new upstream versiond7icRex Dieter <rdieter@fedoraproject.org> 1.0.8-3M{@- libksba-devel multilib conflict (#601976)W6_SJakub Jelen <jjelen@redhat.com> - 1.3.0-7c- Fix for CVE-2022-47629 (#2161571)V5_QJakub Jelen <jjelen@redhat.com> - 1.3.0-6cO- Fix for CVE-2022-3515 (#2135695)L4]?Daniel Mach <dmach@redhat.com> - 1.3.0-5RU- Mass rebuild 2014-01-24L3]?Daniel Mach <dmach@redhat.com> - 1.3.0-4Rk- Mass rebuild 2013-12-272Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild[1[_Tomas Mraz <tmraz@redhat.com> - 1.3.0-2P@- fix multilib conflict in libksba-config
	qe%qHB[9Tomas Mraz <tmraz@redhat.com> - 1.2.0-1NJ[- new upstream versiondAicRex Dieter <rdieter@fedoraproject.org> 1.0.8-3M{@- libksba-devel multilib conflict (#601976)V@_QJakub Jelen <jjelen@redhat.com> - 1.3.0-6cO- Fix for CVE-2022-3515 (#2135695)L?]?Daniel Mach <dmach@redhat.com> - 1.3.0-5RU- Mass rebuild 2014-01-24L>]?Daniel Mach <dmach@redhat.com> - 1.3.0-4Rk- Mass rebuild 2013-12-27=Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild[<[_Tomas Mraz <tmraz@redhat.com> - 1.3.0-2P@- fix multilib conflict in libksba-configH;[9Tomas Mraz <tmraz@redhat.com> - 1.3.0-1P@- new upstream version:Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-3P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
	>e~4>HK[9Tomas Mraz <tmraz@redhat.com> - 1.2.0-1NJ[- new upstream versionVJ_QJakub Jelen <jjelen@redhat.com> - 1.3.0-6cO- Fix for CVE-2022-3515 (#2135695)LI]?Daniel Mach <dmach@redhat.com> - 1.3.0-5RU- Mass rebuild 2014-01-24LH]?Daniel Mach <dmach@redhat.com> - 1.3.0-4Rk- Mass rebuild 2013-12-27GFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild[F[_Tomas Mraz <tmraz@redhat.com> - 1.3.0-2P@- fix multilib conflict in libksba-configHE[9Tomas Mraz <tmraz@redhat.com> - 1.3.0-1P@- new upstream versionDFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-3P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildCFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
	/e~4/WT_SJakub Jelen <jjelen@redhat.com> - 1.3.0-7c- Fix for CVE-2022-47629 (#2161571)VS_QJakub Jelen <jjelen@redhat.com> - 1.3.0-6cO- Fix for CVE-2022-3515 (#2135695)LR]?Daniel Mach <dmach@redhat.com> - 1.3.0-5RU- Mass rebuild 2014-01-24LQ]?Daniel Mach <dmach@redhat.com> - 1.3.0-4Rk- Mass rebuild 2013-12-27PFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild[O[_Tomas Mraz <tmraz@redhat.com> - 1.3.0-2P@- fix multilib conflict in libksba-configHN[9Tomas Mraz <tmraz@redhat.com> - 1.3.0-1P@- new upstream versionMFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-3P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildLFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
	>~28>V]_QJakub Jelen <jjelen@redhat.com> - 1.3.0-6cO- Fix for CVE-2022-3515 (#2135695)L\]?Daniel Mach <dmach@redhat.com> - 1.3.0-5RU- Mass rebuild 2014-01-24L[]?Daniel Mach <dmach@redhat.com> - 1.3.0-4Rk- Mass rebuild 2013-12-27ZFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.0-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild[Y[_Tomas Mraz <tmraz@redhat.com> - 1.3.0-2P@- fix multilib conflict in libksba-configHX[9Tomas Mraz <tmraz@redhat.com> - 1.3.0-1P@- new upstream versionWFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-3P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildVFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.0-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_RebuildHU[9Tomas Mraz <tmraz@redhat.com> - 1.2.0-1NJ[- new upstream version
tCctciJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Kbi/Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441agAJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[`gQJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^_gYJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129W^_SJakub Jelen <jjelen@redhat.com> - 1.3.0-7c- Fix for CVE-2022-47629 (#2161571)
8`"8^igYJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129hiJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159gi5Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401tfiJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-eisJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762diOJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560
 1niOJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560miJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Kli/Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441kgAJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[jgQJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
:NU::rteJakub Hrozek <jhrozek@redhat.com> - 1.1.26-1WYZ@- Resolves: rhbz#1320253 - Rebase libldb to version 1.1.26se'Jakub Hrozek <jhrozek@redhat.com> - 1.1.25-1Vb- Rebase libldb to 1.1.25
- Remove upstreamed patches
- Related: rhbz#1322691riJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159qi5Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401tpiJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-oisJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
GX7CGz{cJakub Hrozek <jhrozek@redhat.com> - 1.5.4-1]B@- Resolves: rhbz#1736013 - Rebase libldb to version 1.5.4 for SambazzcJakub Hrozek <jhrozek@redhat.com> - 1.4.2-1\?- Resolves: rhbz#1658758 - Rebase libldb to version 1.4.2 for SambavycJakub Hrozek <jhrozek@redhat.com> - 1.3.4-1[3|@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasevxcJakub Hrozek <jhrozek@redhat.com> - 1.3.3-1Z- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasevwcJakub Hrozek <jhrozek@redhat.com> - 1.3.2-1Z̧@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebase"vccJakub Hrozek <jhrozek@redhat.com> - 1.2.2-1YM- Resolves: rhbz#1470056 - Rebase libldb to enable samba rebase to
                           version 4.7.x#uecJakub Hrozek <jhrozek@redhat.com> - 1.1.29-1X@- Resolves: rhbz#1393810 - Rebase libldb to enable samba rebase to
                           version 4.6.x
YMYvcJakub Hrozek <jhrozek@redhat.com> - 1.3.3-1Z- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasevcJakub Hrozek <jhrozek@redhat.com> - 1.3.2-1Z̧@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebase"ccJakub Hrozek <jhrozek@redhat.com> - 1.2.2-1YM- Resolves: rhbz#1470056 - Rebase libldb to enable samba rebase to
                           version 4.7.x#ecJakub Hrozek <jhrozek@redhat.com> - 1.1.29-1X@- Resolves: rhbz#1393810 - Rebase libldb to enable samba rebase to
                           version 4.6.xr~eJakub Hrozek <jhrozek@redhat.com> - 1.1.26-1WYZ@- Resolves: rhbz#1320253 - Rebase libldb to version 1.1.26}e'Jakub Hrozek <jhrozek@redhat.com> - 1.1.25-1Vb- Rebase libldb to 1.1.25
- Remove upstreamed patches
- Related: rhbz#1322691`|e_Andreas Schneider <asn@redhat.com> - 1.5.4-2`Y@- resolves: #1941511 - Fix CVE-2021-20277
~&&~#	ecJakub Hrozek <jhrozek@redhat.com> - 1.1.29-1X@- Resolves: rhbz#1393810 - Rebase libldb to enable samba rebase to
                           version 4.6.xreJakub Hrozek <jhrozek@redhat.com> - 1.1.26-1WYZ@- Resolves: rhbz#1320253 - Rebase libldb to version 1.1.26e'Jakub Hrozek <jhrozek@redhat.com> - 1.1.25-1Vb- Rebase libldb to 1.1.25
- Remove upstreamed patches
- Related: rhbz#1322691`e_Andreas Schneider <asn@redhat.com> - 1.5.4-2`Y@- resolves: #1941511 - Fix CVE-2021-20277zcJakub Hrozek <jhrozek@redhat.com> - 1.5.4-1]B@- Resolves: rhbz#1736013 - Rebase libldb to version 1.5.4 for SambazcJakub Hrozek <jhrozek@redhat.com> - 1.4.2-1\?- Resolves: rhbz#1658758 - Rebase libldb to version 1.4.2 for SambavcJakub Hrozek <jhrozek@redhat.com> - 1.3.4-1[3|@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebase
Yem`e_Andreas Schneider <asn@redhat.com> - 1.5.4-2`Y@- resolves: #1941511 - Fix CVE-2021-20277zcJakub Hrozek <jhrozek@redhat.com> - 1.5.4-1]B@- Resolves: rhbz#1736013 - Rebase libldb to version 1.5.4 for SambazcJakub Hrozek <jhrozek@redhat.com> - 1.4.2-1\?- Resolves: rhbz#1658758 - Rebase libldb to version 1.4.2 for Sambav
cJakub Hrozek <jhrozek@redhat.com> - 1.3.4-1[3|@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasevcJakub Hrozek <jhrozek@redhat.com> - 1.3.3-1Z- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasevcJakub Hrozek <jhrozek@redhat.com> - 1.3.2-1Z̧@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebase"
ccJakub Hrozek <jhrozek@redhat.com> - 1.2.2-1YM- Resolves: rhbz#1470056 - Rebase libldb to enable samba rebase to
                           version 4.7.x
CvX7CvcJakub Hrozek <jhrozek@redhat.com> - 1.3.4-1[3|@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasevcJakub Hrozek <jhrozek@redhat.com> - 1.3.3-1Z- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasevcJakub Hrozek <jhrozek@redhat.com> - 1.3.2-1Z̧@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebase"ccJakub Hrozek <jhrozek@redhat.com> - 1.2.2-1YM- Resolves: rhbz#1470056 - Rebase libldb to enable samba rebase to
                           version 4.7.x#ecJakub Hrozek <jhrozek@redhat.com> - 1.1.29-1X@- Resolves: rhbz#1393810 - Rebase libldb to enable samba rebase to
                           version 4.6.xreJakub Hrozek <jhrozek@redhat.com> - 1.1.26-1WYZ@- Resolves: rhbz#1320253 - Rebase libldb to version 1.1.26e'Jakub Hrozek <jhrozek@redhat.com> - 1.1.25-1Vb- Rebase libldb to 1.1.25
- Remove upstreamed patches
- Related: rhbz#1322691
_=_(W{Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=W%Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedkWKarel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_WkKarel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)`e_Andreas Schneider <asn@redhat.com> - 1.5.4-2`Y@- resolves: #1941511 - Fix CVE-2021-20277zcJakub Hrozek <jhrozek@redhat.com> - 1.5.4-1]B@- Resolves: rhbz#1736013 - Rebase libldb to version 1.5.4 for SambazcJakub Hrozek <jhrozek@redhat.com> - 1.4.2-1\?- Resolves: rhbz#1658758 - Rebase libldb to version 1.4.2 for Samba

er+V:eD
1a91953e84dbe2c03ef4d9284debe9f3fd29f808a721e032346b19d8191151ccD
199c200e85ae57dc217530a09f2172f136c763583a9869d518e3dd7c2a2f3c24D
b64c66f5d35425a886b1afbcf898922915a06a253e4ec2f2efb169f42dea7125D
09936061a18c7bf3b0903e9e1994dca141d245478064ada19312d0d78abe44aeD
ca36fb0f490cdd14f4ed8b6ecf0440998542eaeed3c3985f7357025964231df6D
7631dec5bfc4f885319322ddf28a8c174bd735138c0021a996ea89b80e010ec4D
c0a963a27f23cc436b7364ce694e6afe9a0e8d26be17bc8dc816b46fc2e0f261D
0cff7abce034e9ae5e89bd1f5c50241356dd38507e0c53e17d563453b7923822D
c10cbe426290ea35692c88e6f4393bef89f510b20d8587b123e03a419891e2a3D
13f0a70db8c30427ac5dcfc998ed9c2ea98da56b6c4439d62d54bc51fca0c198D
776a13c05abec92b93e26a3e73b33106410100566b5e395d5a22469f660365abD
74ba5dbc31e8d072aad83ccc34e693990c0625ce81a367690bc1cc6bbdbdc121D
2d1f2caacc8bdd289ec4d9a21bbe90c08d63cc088bec34c32f2acb2df58d2761
EE!WIKarel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.A W-Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\WcKarel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;a#WmKarel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZ"W_Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
vT#v((W{Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login='W%Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedk&WKarel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_%WkKarel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)D$g#Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
EE+WIKarel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.A*W-Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\)WcKarel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;a-WmKarel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZ,W_Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
vT#v(2W{Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=1W%Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedk0WKarel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_/WkKarel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)D.g#Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
EE5WIKarel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.A4W-Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\3WcKarel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;a7WmKarel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZ6W_Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
vT#v(<W{Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=;W%Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedk:WKarel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_9WkKarel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)D8g#Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
EE?WIKarel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.A>W-Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\=WcKarel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;aAWmKarel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZ@W_Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
^^/EqoMichal Sekletar <msekleta@redhat.com> - 14:1.5.3-6U- libpcap now correctly recognizes Netlink datalink type (#1031974)
- fix vlan tagged packet filtering (#1079525)uDq{Michal Sekletar <msekleta@redhat.com> - 14:1.5.3-5U@- display also first packet when capturing in cooked mode (#1176612)
- make sure that userland bpf filter interpreter is given snaplen such that size of
  cooked header is account for&Cq]Michal Sekletar <msekleta@redhat.com> - 14:1.5.3-4T}- disable TPACKET_V3 memory mapped packet capture on AF_PACKET socket, use TPACKET_V2 instead (#1085096)DBg#Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
_(% LqQMichal Ruprich <mruprich@redhat.com> - 14:1.5.3-13b\@- Resolves: #2027937 - libpcap 1.5.3 with distro patch applied writes pcap file with broken pkthdrKqMichal Ruprich <mruprich@redhat.com> - 14:1.5.3-12]8H@- Resolves: #1596834 - Re-enable TPACKET_V3 to fix silent packet dropsvJE)Michal Ruprich - 14:1.5.3-11Y- Resolves: #1427251 - tcpdump incorrectly shows 0x8100 tag for 802.1ad framesYIuAMartin Sehnoutka <msehnout@redhat.com> - 14:1.5.3-10Y@- Add support for AF_VSOCKXHsAMartin Sehnoutka <msehnout@redhat.com> - 14:1.5.3-9Y,
@- Bound packet size to 64kzGqMichal Sekletar <msekleta@redhat.com> - 14:1.5.3-8U@- make sure that sll header size is accounted for (#1176612)FqIMichal Sekletar <msekleta@redhat.com> - 14:1.5.3-7U- make sure that netlink monitor interfaces are also properly recognized by tcpdump (#1031974)
,U[,XRsAMartin Sehnoutka <msehnout@redhat.com> - 14:1.5.3-9Y,
@- Bound packet size to 64kzQqMichal Sekletar <msekleta@redhat.com> - 14:1.5.3-8U@- make sure that sll header size is accounted for (#1176612)PqIMichal Sekletar <msekleta@redhat.com> - 14:1.5.3-7U- make sure that netlink monitor interfaces are also properly recognized by tcpdump (#1031974)/OqoMichal Sekletar <msekleta@redhat.com> - 14:1.5.3-6U- libpcap now correctly recognizes Netlink datalink type (#1031974)
- fix vlan tagged packet filtering (#1079525)uNq{Michal Sekletar <msekleta@redhat.com> - 14:1.5.3-5U@- display also first packet when capturing in cooked mode (#1176612)
- make sure that userland bpf filter interpreter is given snaplen such that size of
  cooked header is account for&Mq]Michal Sekletar <msekleta@redhat.com> - 14:1.5.3-4T}- disable TPACKET_V3 memory mapped packet capture on AF_PACKET socket, use TPACKET_V2 instead (#1085096)
V)PVuXq{Michal Sekletar <msekleta@redhat.com> - 14:1.5.3-5U@- display also first packet when capturing in cooked mode (#1176612)
- make sure that userland bpf filter interpreter is given snaplen such that size of
  cooked header is account for&Wq]Michal Sekletar <msekleta@redhat.com> - 14:1.5.3-4T}- disable TPACKET_V3 memory mapped packet capture on AF_PACKET socket, use TPACKET_V2 instead (#1085096) VqQMichal Ruprich <mruprich@redhat.com> - 14:1.5.3-13b\@- Resolves: #2027937 - libpcap 1.5.3 with distro patch applied writes pcap file with broken pkthdrUqMichal Ruprich <mruprich@redhat.com> - 14:1.5.3-12]8H@- Resolves: #1596834 - Re-enable TPACKET_V3 to fix silent packet dropsvTE)Michal Ruprich - 14:1.5.3-11Y- Resolves: #1427251 - tcpdump incorrectly shows 0x8100 tag for 802.1ad framesYSuAMartin Sehnoutka <msehnout@redhat.com> - 14:1.5.3-10Y@- Add support for AF_VSOCK
qL-tq_qMichal Ruprich <mruprich@redhat.com> - 14:1.5.3-12]8H@- Resolves: #1596834 - Re-enable TPACKET_V3 to fix silent packet dropsv^E)Michal Ruprich - 14:1.5.3-11Y- Resolves: #1427251 - tcpdump incorrectly shows 0x8100 tag for 802.1ad framesY]uAMartin Sehnoutka <msehnout@redhat.com> - 14:1.5.3-10Y@- Add support for AF_VSOCKX\sAMartin Sehnoutka <msehnout@redhat.com> - 14:1.5.3-9Y,
@- Bound packet size to 64kz[qMichal Sekletar <msekleta@redhat.com> - 14:1.5.3-8U@- make sure that sll header size is accounted for (#1176612)ZqIMichal Sekletar <msekleta@redhat.com> - 14:1.5.3-7U- make sure that netlink monitor interfaces are also properly recognized by tcpdump (#1031974)/YqoMichal Sekletar <msekleta@redhat.com> - 14:1.5.3-6U- libpcap now correctly recognizes Netlink datalink type (#1031974)
- fix vlan tagged packet filtering (#1079525)
a[adqIMichal Sekletar <msekleta@redhat.com> - 14:1.5.3-7U- make sure that netlink monitor interfaces are also properly recognized by tcpdump (#1031974)/cqoMichal Sekletar <msekleta@redhat.com> - 14:1.5.3-6U- libpcap now correctly recognizes Netlink datalink type (#1031974)
- fix vlan tagged packet filtering (#1079525)ubq{Michal Sekletar <msekleta@redhat.com> - 14:1.5.3-5U@- display also first packet when capturing in cooked mode (#1176612)
- make sure that userland bpf filter interpreter is given snaplen such that size of
  cooked header is account for&aq]Michal Sekletar <msekleta@redhat.com> - 14:1.5.3-4T}- disable TPACKET_V3 memory mapped packet capture on AF_PACKET socket, use TPACKET_V2 instead (#1085096) `qQMichal Ruprich <mruprich@redhat.com> - 14:1.5.3-13b\@- Resolves: #2027937 - libpcap 1.5.3 with distro patch applied writes pcap file with broken pkthdr
d&O!d8kYJarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274 jqQMichal Ruprich <mruprich@redhat.com> - 14:1.5.3-13b\@- Resolves: #2027937 - libpcap 1.5.3 with distro patch applied writes pcap file with broken pkthdriqMichal Ruprich <mruprich@redhat.com> - 14:1.5.3-12]8H@- Resolves: #1596834 - Re-enable TPACKET_V3 to fix silent packet dropsvhE)Michal Ruprich - 14:1.5.3-11Y- Resolves: #1427251 - tcpdump incorrectly shows 0x8100 tag for 802.1ad framesYguAMartin Sehnoutka <msehnout@redhat.com> - 14:1.5.3-10Y@- Add support for AF_VSOCKXfsAMartin Sehnoutka <msehnout@redhat.com> - 14:1.5.3-9Y,
@- Bound packet size to 64kzeqMichal Sekletar <msekleta@redhat.com> - 14:1.5.3-8U@- make sure that sll header size is accounted for (#1176612)
pobq[mHonggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
p[;Honggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585VoYUJarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296nY)Jarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541xmYJarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426lY?Jarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#1687426
|qE|xwYJarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426vY?Jarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#16874268uYJarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274t[OHonggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699s[CHonggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
r[;Honggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482
{}[CHonggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
|[;Honggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482b{[mHonggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
z[;Honggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585VyYUJarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296xY)Jarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541
>g>VYUJarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296Y)Jarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541xYJarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426Y?Jarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#16874268YJarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274~[OHonggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699
q|P	u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode[OHonggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699[CHonggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
[;Honggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482b[mHonggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
[;Honggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf
u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU
w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849

er+V:eD*
bc430ed0cfd4a663b76358074912057f989f4af493a6909136e70731ba2358deD)
730a731598f675b1827b85e2f2a963fb1c75d82ea0eb61e2b544a1c868517c7aD(
694e41c94c00e68912502d5f6c5bfde8a366987f5381e5d31b889a6b3928fdf0D'
09f598da7d3fbe1d2b05e159dc8f3d04792678621bf6d1f87c0edb4896d550a3D&
5a66d5d5dc478ed425ac3150ca54707625780a2e26284391fb1ebfb7924f88e9D%
ff496670decb17b290f032a8854f0420ac2848d6b92e9e0df99491a13901a396D$
31f3f35c713ad4fecb47ca4bfcba6b22a99a0311e91687edac989c0a717ba2ecD#
17cb2cf3a7524082c239fd29082b6e294757fdb6175dc11ee0f7a52fb4e3fd76D"
443c9cfc06a5f4f00f7780823a1f4d236782b838c05109edde4737cba50357cbD!
2c8b6a3c06bbaf16efe5dda84ccb23687cd29b2f04bf1f640024f805be0dc23bD 
0f7c4de217d674dd4adcc5ec84c9df840a974061fb940697d0f1d2c3317bca7dD
564ac561fd3290312c3e833edb5ea883a24d202539893cdb0482247a743750b5D
8129ad43222a6a88ffa26b7ed5f36d10b1edede7d67aa145c0880eb6d3058828
*&%C*$uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
#u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t"uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf!u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858 uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt+uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf*u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858)uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt(uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU'w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~&wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm%uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC1u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode0gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~/wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm.uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black-uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
,u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*8uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
7u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t6uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf5u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168584uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt3uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU2w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt?uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf>u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858=uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt<uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU;w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~:wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm9uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCEu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeDgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~CwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormBuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackAuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
@u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*LuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Ku'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tJuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfIu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858HuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStGuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUFw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtSuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfRu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858QuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStPuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUOw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~NwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormMuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCYu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeXgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~WwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormVuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackUuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Tu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*`uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
_u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t^uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf]u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858\uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt[uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUZw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtguwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresffu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858euCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStduwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUcw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~bwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormauiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCmu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modelgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~kwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormjuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackiuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
hu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*tuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
su'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849truwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfqu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858puCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStouwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUnw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt{uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfzu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858yuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStxuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUww5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~vwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm~uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black}uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
|u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858
uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~
wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm	uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt#uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf"u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858!uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black

er+V:eD7
c1965ea7b6eac21676014e538803935d779938ef7971d74668df9e5d24b9f56dD6
9b8eaf39c60cfcb55b3c1b2bca5d0dd535225e1dcedf7eeb80d3c1241b9c0478D5
61f9945c76bfd6399739a4cfc42c3e9b350ca70cec8aab0875d6618d3f45ceceD4
f6a468589dc2d68540fefdc5fe28df4e741f1d5c46a396376cd5787d8170a88aD3
79d0f0c2a70577d228a2c71fdc289b4a2944b4681bf3f5d79f9b04862f3af683D2
3fd5a3ec93bfb1ba9a34a9f68433573b2a39224e618b9e9c02aed4cb89de5c48D1
82a64c4e305a429be421cace128685a29a5971da0cb54ac1d883f150b1f92460D0
617e115047b71db008189f9a914bce3674313e8fcd3e3ce40564fe69f65c44e1D/
9fe65bb70a192bc16ad246fb03daefa211650e429f9834845e0a048fb42253d3D.
681f9ded8847701dec6bf5ba7ebdeed4dc1b38b39177a2f1e148695f5ee1b1aaD-
6f4280fe77b168975f638489aefbd874e08a1bcc00b9b43792472c51d7f9fb1cD,
d0502f4f4281f85dbdfa765998b7f3281933945c8291d40a49d1ba948c4c59c6D+
664ee953022453c5e78fe8b0d4d06dc2c1ec406c0d52a232f631aca0f1032abc
CnvC)u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode(gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~'wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm&uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black%uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
$u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*0uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
/u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t.uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf-u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858,uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt+uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU*w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt7uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf6u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168585uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt4uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU3w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~2wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm1uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC=u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode<gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~;wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm:uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black9uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
8u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*DuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Cu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tBuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfAu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858@uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt?uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU>w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtKuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfJu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858IuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStHuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUGw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~FwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormEuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCQu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modePgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~OwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormNuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackMuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Lu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*XuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Wu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tVuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfUu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858TuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStSuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorURw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt_uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf^u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858]uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt\uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU[w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~ZwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormYuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCeu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modedgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~cwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormbuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackauCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
`u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*luCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
ku'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tjuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfiu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858huCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStguwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUfw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtsuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfru[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858quCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStpuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUow5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~nwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormmuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCyu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modexgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormvuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
tu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t~uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf}u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858|uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt{uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUzw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC
u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm
uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black	uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC!u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849

er+V:eDD
20865c1814ad86f27c05f9c958a9ea1303c9b5b7762952f4c5f8da12d65f4cceDC
207aade4092c5ae2176b6a08df041bef38194b9beb887c0eecd8a4934aecb6c7DB
06027d118bc6eda893d13e73a13e75851e1f01cc10ad76d87de54aa42810f00eDA
aa3dd48f76695ea199491a446126a20084e82d91243a36c7d1bc1bb4c386dde8D@
3f8e4829e35974784aa21e86171e8782ae787788130e87d8098084937f4a1a3bD?
e438b29905ef5550f7c5d07e807e9f7f882272fce7c62fc02d8dd31abdf3e759D>
b508e84aaf73a34f2d109602c78e906df8eb37fed7c853749929b1c52770464fD=
21074e40c8578a4e4a866f138184265b3827027519d1d1574e83df6ea2d30c71D<
8a462bdff8ebc77ce5f8cf6eb1d98625e34218cd0b64485d9b9e6e7837d422f7D;
6a2860de3c6856a89ddef7db26248c1132d0358c047f0d29f64cddea617e46a6D:
c5f6d5239e70240eea7d64dfafd3bbd553f7681f7d2bec1a8ab1298d606ef9d2D9
b18f3f7901340c38120aa1a6fa30010d2c8689dacd4c2609ff225ceed2672899D8
a2fb51336df10bfeae88e811816e04967399b366dd70cde5a7202cbabb4d0a7f
*&%C*(uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
'u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t&uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf%u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858$uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt#uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU"w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt/uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf.u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858-uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt,uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU+w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~*wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm)uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC5u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode4gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~3wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm2uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black1uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
0u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*<uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
;u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t:uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf9u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168588uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt7uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU6w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogbR%RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{$$$+$1$8$?$E$L$S$Y$`$g$m$t${$$$$$$#$)$0$Á7$ā=$ŁD$ƁK$ǁQ$ȁX$Ɂ_$ʁe$ˁl$́s$́y$΁$ρ$Ё
$с$ҁ$Ӂ!$Ձ($ց/$ׁ5$؁<$ځC$ہI$܁P$݁W$ށ]$߁d$k$q$x$$$$$$ $'$-$4$;$A$H$O$U$\$c$i$p$w$}$$$$$$%$,%3%9%@%G%M%T%[%a%h%	o%
u%|%%
	%%%%$%+
P
32PtCuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfBu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858AuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt@uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU?w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~>wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm=uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCIu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeHgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~GwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormFuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackEuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Du'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*PuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Ou'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tNuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfMu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858LuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStKuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUJw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtWuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfVu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858UuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStTuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUSw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~RwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormQuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC]u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode\gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~[wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormZuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackYuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Xu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*duCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
cu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tbuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfau[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858`uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt_uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU^w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtkuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfju[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858iuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSthuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUgw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~fwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormeuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCqu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modepgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~owStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormnuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackmuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
lu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*xuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
wu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tvuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfuu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858tuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStsuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUrw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf~u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858}uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt|uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU{w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~zwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormyuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t
uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf	u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm
uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C* uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt'uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf&u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858%uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt$uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU#w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~"wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm!uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black

er+V:eDQ
9e5cbf00ba9abdeb4b79e3b7688f06eb0cba3600861f6ba1b8e7589195f4cefeDP
0b16a6ff0f8a8988e02b31ad560630c7d2fdc9e63b234cc9a39273f3fc61e146DO
e5b7423528cbf9cc19e9723b53e3944ec1bccf375eed6cd5d975ed01325ecce3DN
73a913f2c7fb75a15cc3b74e08df90f3afc8fe8e36e918044a3fb407b7cf85e4DM
5a559d47a300848514e0aa63937e0ec7ba4d9c80c12f1947a494d7511dac89dcDL
bdbf6d455da867729477ffe919b5a9f8f2c11626c5047e6dfe129589a1d1ae99DK
5ab6cab7d848d0f73216a7e9da6f5e67da62be1a0f2777afc4314eabbcd350fdDJ
6fb636bf5fc99a0e0e7c9660b447ddb3de9d1e93eab0350986882884d02c9a69DI
d858f3c88588d0a0006133a7b6f5d5b77ff58e2705465cf0c43a798850d97b18DH
446b4bb7e11daeccdf09a55cd6a749365497b1d1ce2addc86246a46f9de47af4DG
1b815a5f718f4c8aa2b5ff3b119fa6fe64709eeed08150a007a61a3d9d4c50eeDF
c76608ef79bd1a9fa553bc282e40bd895ee744ac0f6b7a570796bd2bef414ce2DE
39839baa55b7d0e9b82004503792fd5f8c0608ae6d937d375d2febb11a92f830
CnvC-u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode,gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~+wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm*uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black)uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
(u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*4uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
3u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t2uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf1u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168580uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt/uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU.w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt;uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf:u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168589uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt8uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU7w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~6wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm5uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCAu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode@gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~?wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm>uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black=uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
<u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*HuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Gu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tFuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfEu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858DuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStCuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUBw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtOuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfNu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858MuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStLuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUKw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~JwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormIuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCUu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeTgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~SwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormRuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackQuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Pu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*\uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
[u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tZuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfYu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858XuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStWuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUVw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtcuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfbu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858auCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt`uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU_w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~^wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm]uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCiu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modehgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~gwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormfuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackeuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
du'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*puCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
ou'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tnuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfmu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858luCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStkuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUjw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtwuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfvu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSttuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUsw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~rwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormquiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC}u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode|gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~{wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormzuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackyuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
xu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU~w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf
u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858	uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC%u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode$gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~#wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm"uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black!uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
 u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849

er+V:eD^
d95478aaa9369b4b49b219aa8aa09278b47ea7f04a2b46280915968e638d861bD]
6f13f12c50ed9a62d92967f246f2c8b9f5260a7546412f06126b024aedc1789fD\
3cfeeda763854fb5e06228183bd5e587f1bed1e4d625590a6b4ac06187c951b4D[
3039329a21200cbbf7463db4cd240372bb1bbd52f6a2f4db0f5c59e224b39a1eDZ
4e2af30c8cdafabdbbd71cf0b42194118f3297380446e1e39471402c1358b840DY
21b8e6781d07f056a511706388aa4397ee3bf2578eb1f6455af17956f29b8a3cDX
d9319fe4e9861108bb5cec23bad9875cac3e057b9ed2a069db7213681942b7d1DW
b0d2ba1dfd6121490fde31684dfddf6d147c4889a36ef69028e8d42e1f5d7ee5DV
3a9691f067f58e1bce93011bcff272d08b255c1d950fccd1a5aa734d7f8b7050DU
33da9fcfa473611ac5db46a1be964f5a878cd46aa94bc51035801bdb2ee4b266DT
6f58c9c348a9dafbd677a7e56cd3f98765ae140f59756077d92d757199b1200aDS
a963852de3c08dce84508ca7b9b33ea8adeca40e1239dde2ce1a103e2fe560c2DR
7cca95dd2bd890021e0f9bf2eaab7788beef2dbb9ef929b7da82f9d98d4b10fe
*&%C*,uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
+u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t*uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf)u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858(uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt'uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU&w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt3uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf2u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168581uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt0uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU/w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~.wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm-uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC9u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode8gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~7wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm6uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black5uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
4u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*@uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
?u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t>uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf=u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858<uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt;uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU:w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtGuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfFu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858EuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStDuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUCw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~BwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormAuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCMu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeLgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~KwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormJuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackIuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Hu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*TuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Su'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tRuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfQu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858PuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStOuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUNw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt[uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfZu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858YuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStXuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUWw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~VwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormUuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCau-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode`gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~_wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm^uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black]uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
\u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*huCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
gu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tfuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfeu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858duCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStcuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUbw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtouwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfnu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858muCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStluwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUkw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~jwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormiuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCuu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modetgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~swStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormruiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackquCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
pu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*|uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
{u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tzuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfyu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858xuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStwuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUvw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm}uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC	u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf
u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU
w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*$uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
#u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t"uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf!u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858 uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt+uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf*u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858)uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt(uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU'w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~&wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm%uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black

er+V:eDk
0546c6b078f73199e92d47749bd83c92594960b191bb14c1adc5fd5996219b74Dj
dc3a05b48786ae7763cd0966fcd06703e3d056abc82ba14fd98bdd54152fb214Di
09de0197c6db452f0fd3f28c21887416beca324b835bd991b0385a41cd819f52Dh
7cc876a75a07e0764ab0c3b780afa6d07f9464d369cde9a0a7fa0d5514a397e9Dg
3b6d9c55ef22a3afc1250d7b0a6f4d5e8599880d7982a85aafde17fdd2e4ebeeDf
06f1bb2af6f2c2c3b74476a6919d97cc43a92d7d43132345b87af3a3a4aede4bDe
3ed9d0bcbc1cf0d2a450b8b6e598051e1c685e052cdab05aeab562c3fbd1094fDd
b3ef87449f22bbc11d2c424b6a59ffecab688a083fb9da993f6d7f4994ad29f6Dc
e248caabcf1382b1871901dc2504fe1b16e85e748d76553c646487a5ac907f1fDb
8bc7d7a6d1b39eee668c11eb933d1cb38ebd708d11b2c0b2b1a7891e74af0cfbDa
2c6107fda911499372be453221b095232c40415491b307e4b96667feea7e85d8D`
4d32b8be0b3416b8c7b225709e77847f3eb420ac65b6a5a1c9c5f7bf13033407D_
e40e9974b84165100cfd49afdff81253e38049ca2ba3d57dcdf352538fe84014
CnvC1u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode0gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~/wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm.uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black-uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
,u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*8uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
7u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t6uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf5u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168584uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt3uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU2w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt?uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf>u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858=uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt<uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU;w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~:wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm9uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCEu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeDgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~CwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormBuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackAuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
@u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*LuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Ku'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tJuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfIu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858HuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStGuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUFw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtSuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfRu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858QuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStPuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUOw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~NwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormMuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCYu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeXgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~WwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormVuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackUuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Tu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*`uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
_u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t^uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf]u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858\uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt[uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUZw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtguwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresffu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858euCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStduwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUcw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~bwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormauiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCmu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modelgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~kwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormjuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackiuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
hu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*tuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
su'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849truwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfqu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858puCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStouwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUnw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt{uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfzu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858yuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStxuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUww5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~vwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm~uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black}uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
|u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858
uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~
wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm	uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt#uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf"u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858!uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC)u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode(gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~'wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm&uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black%uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
$u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849

er+V:eDx
1a4b2811d9710ab0cbee6c14d0d65efdfcbc1fb050caa3686160958d16c06337Dw
41d3b70e19103a25ac6a0a877859dcc9105adf2602d4dea078e3220d5fdcb007Dv
b4a38f14218c431d03e34c26a134c609d688ef2c83f268f6867bfb1003efcf2bDu
a005198937d77a556b2d5c86b03b36028c5cdf485f869c8f661e5bdaeca48381Dt
3b84e45c8f431e6aced2faecb97912cb424f0373293013c739154621f571ced8Ds
2db01b2d2f442ec2b3ab438e94ca56bfd13bc67b07ac74f28b1b9d2435418aa5Dr
a2f70fbdd27181bcd656bbd6bb28222e80496a2d4cef2918f74b66e887b0ad68Dq
9194142e9ca71c44cbdedac14b2fbe14b54b0a0893096cf32b9783f204b7da87Dp
851583dc78e98a516586667fe472405624392dbb850b366aac5e87fde83e922eDo
c6ee2dc7f4859cf7e741172a64ed8a91fa20379d8b50ae273712fdc3b54f8d59Dn
6de667e5382d2e35f18b69390c3e03a9e718d8bc403a5db6c6f6072e6bf683c2Dm
a5dc184a11c5ee57f55ab4b8abbcf391aa3b6bac3960c6f35615716c35d18da3Dl
4fb46ce209b71d1437ce790ff6339784632c86ff1c34dc42c88780ecc894575d
*&%C*0uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
/u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t.uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf-u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858,uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt+uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU*w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt7uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf6u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168585uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt4uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU3w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~2wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm1uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC=u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode<gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~;wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm:uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black9uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
8u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*DuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Cu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tBuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfAu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858@uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt?uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU>w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtKuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfJu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858IuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStHuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUGw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~FwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormEuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCQu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modePgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~OwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormNuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackMuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Lu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*XuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Wu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tVuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfUu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858TuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStSuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorURw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt_uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf^u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858]uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt\uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU[w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~ZwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormYuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCeu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modedgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~cwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormbuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackauCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
`u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*luCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
ku'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tjuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfiu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858huCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStguwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUfw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtsuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfru[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858quCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStpuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUow5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~nwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormmuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCyu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modexgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormvuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
tu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t~uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf}u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858|uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt{uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUzw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC
u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm
uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black	uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC!u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*(uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
'u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t&uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf%u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858$uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt#uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU"w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt/uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf.u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858-uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt,uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU+w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~*wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm)uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black

er+V:eD
5c171ad6a96c5f3feec12d0ec56fecf45cb0e8859deeb78966c227cc21a25217D
91b3059cb08a4f72259c6d15febbed4bf315c966b9b48ef63e56b900babbfcbcD
bad44aa372dd71ae7305ec77706bf7df2edd9e52a618230db1ac76a6fb0f5545D
4b8be9f1166188e6844902fa02e3822fd56edbfd5e5043d22efd3d39bd199f57D
6eb6b0f0d64dd44ca445beb920426e0a8262e18d4611f37af0bcf266a49e7ba1D
04eb35414e82fe2433c837b70edc142805f7455f68f171ad1ea43e534a94de83D
50dd826f883ca6e83a5520159702919e8640813f0006c32d9ce6531b4f92818bD~
b66da86b2643b46bd5d193eebb6f236cfdf753506a9c50caf4ed52fc5bce7172D}
d828d76b49cd8eef2060250c9dc6bd5cb60ff05970adf2e0352cdffb341700ebD|
51c0c235f8ee720c1949dd34f66d66bf7f5b50fe1c37d366fe724ce644b3bee5D{
e329f4af5a2d9e0b4ba62a957f0696c7fa7fd5a4fb911f99a4f9f7fc965b46b8Dz
c636f7b1ee487e382b84fc78e7079b3cdcbe8a18b64dbec20379bad79eb119ddDy
423fbdf1d86a2b10618e98f380c62c9e34640a2c7aae29c80960b34008181a8a
CnvC5u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode4gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~3wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm2uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black1uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
0u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*<uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
;u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t:uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf9u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168588uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt7uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU6w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtCuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfBu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858AuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt@uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU?w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~>wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm=uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCIu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeHgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~GwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormFuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackEuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Du'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*PuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Ou'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tNuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfMu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858LuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStKuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUJw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogbR%}RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{%8%?%E%L%S%Y%`%g%m%t%{% %!%"%#%$%%#%&)%(0%)7%*=%+D%,K%-Q%.X%/_%0e%1l%2s%3y%4%5%6
%7%8%9!%:(%;/%=5%><%?C%@I%AP%CW%D]%Ed%Fk%Gq%Hx%I%J%K%L%M%N %O'%P-%R4%S;%TA%UH%VO%WU%X\%Yc%Zi%[p%\w%]}%^%_%`%a%b%c%%d,%e3%g9%h@%iG%jM%kT%l[%ma%nh%oo%pu%q|%r%s	%t%u%v%w$%x+%y1%{8%|?
P
32PtWuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfVu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858UuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStTuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUSw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~RwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormQuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC]u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode\gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~[wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormZuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackYuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Xu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*duCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
cu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tbuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfau[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858`uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt_uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU^w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtkuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfju[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858iuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSthuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUgw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~fwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormeuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCqu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modepgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~owStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormnuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackmuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
lu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*xuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
wu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tvuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfuu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858tuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStsuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUrw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf~u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858}uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt|uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU{w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~zwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormyuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t
uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf	u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm
uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C* uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt'uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf&u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858%uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt$uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU#w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~"wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm!uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC-u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode,gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~+wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm*uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black)uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
(u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849

er+V:eD
725f41aabdbe0d99f4ff043c8413b75aec1da746d9c27e7540b090a7120002f3D
a3ef6e35d2238c250f6554c30556a80122488a92f64edf3c23c04158556120ecD
324eaa8a27d384658ffb3045f886fe533acdd20ff60a9dad14007b9f07a43205D
dc4b5c4bfb6d4b6fd4006830469bd40d093d6938603f2fc413c3ff2d54ceaaacD
8a7f53c7e5c8a77fc603887cb200d840cb724658ff8f2439c41293131f94be82D

3a846ba46e8a41f29b08fc2e10e3f6ea6459d1d57fbe6c19523bf1269d7754ffD
735a91bac6263309ccf5145f1e264cf16d27bec4da5fc2e9ab42e3b055fc46c5D
d38a715f8c0b25a49a238ed3f75475a44586f7371a1cb8df82caad826f4dad72D

017388e17ae8a0342ff3283f483c0f92172ac1005e8e97a4c40390e55f78d063D	
67dceb0f183dc4e838b1ec1b27236a59cfa08a537707ff6eda2a10c5c9601421D
d9ee541fc64d9aeaa99ba6171d9a8585ba8c37d8e288b3c6b029f4a1aa292beeD
74f6bb5bbf891159807474196fe08baee6d2ef51b9508b2bcec100949f6a756bD
f7f083c13947185b5768e1f009aec9585e1938f2f714b6fe2248b509babb5dbd
*&%C*4uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
3u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t2uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf1u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168580uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt/uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU.w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt;uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf:u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168589uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt8uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU7w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~6wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm5uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCAu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode@gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~?wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm>uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black=uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
<u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*HuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Gu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tFuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfEu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858DuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStCuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUBw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtOuw	Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfNu[	Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858Mu	Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStLuw	Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUKw5	Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~JwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormIuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCUu-
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeTgI	Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~Sw	Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormRui	Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackQu	Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Pu'	Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*\u
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
[u'
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tZuw
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfYu[
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858Xu
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStWuw
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUVw5
Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtcuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfbu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858auCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt`uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU_w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~^w
Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm]ui
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCiu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modehgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~gwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormfuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackeuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
du'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*puCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
ou'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tnuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfmu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858luCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStkuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUjw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Ptwuw
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfvu[
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uu
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSttuw
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUsw5
Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~rwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormquiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC}u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode|gI
Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~{w
Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormzui
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackyu
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
xu'
Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU~w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf
u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858	uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC%u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode$gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~#wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm"uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black!uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
 u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*,uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
+u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t*uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf)u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858(uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt'uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU&w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt3uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf2u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168581uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt0uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU/w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~.wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm-uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black

er+V:eD
c81589b411d434da5e3ce899b20f0ec5f0d89e805bb98654a0220574a6567a5eD
1fa785144303de32e2279da8e40942e02967bad3724f4de700446c1ac09a1b64D
bf7de5cc417bd99213c10e8ad8c5772cf6317388fcd795f4c584548f0e6b9c7bD
9a48d9a5c8ba240b00760f5cdc0080f6ea8fb38b0f044469b34b8ced3f0be6e9D
5e35c68daaac093d3beb1bdd57551b4b11d68962192494ead3ec78504bd924e9D
2e69eeedc5aed03c46ec6f8fd3d7d75c65c5f88aef5cacb89a4b23aa19c92d1dD
c79764e439db44bf5b1a2d07e42ed27562693784744a529c9d1f300ee54145d2D
26284ef9814e9eefa37f15d0dfb0ddab775cc08083594ba1bd43d0b652f61680D
8dc48d5e4e60131ad36fe3003497d6d355365e66c85a79b791c2245839838f72D
0fd4e46db83e6ecf64c063a8c953be3ba857eec99d069a0824fbc7cb3181c25fD
eb9adb9f6d4141d4d82fd9f2740d41d0ed32fde5148d9e4a3d952f1aedb10a52D
61e6d58d8d1b2b2be1f5bb1731c99cf450b81b29303d4f3e1c8772d9b04d2bbdD
79ac9fe0cf39a64255d82fbb10c0d150d68cd88753359d4d13150cbb094c9674
CnvC9u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode8gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~7wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm6uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black5uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
4u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*@uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
?u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t>uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf=u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858<uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt;uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU:w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtGuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfFu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858EuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStDuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUCw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~BwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormAuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCMu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeLgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~KwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormJuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackIuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Hu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*TuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Su'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tRuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfQu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858PuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStOuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUNw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt[uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfZu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858YuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStXuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUWw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~VwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormUuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCau-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode`gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~_wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm^uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black]uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
\u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*huCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
gu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tfuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfeu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858duCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStcuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUbw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtouwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfnu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858muCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStluwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUkw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~jwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormiuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCuu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modetgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~swStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormruiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackquCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
pu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*|uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
{u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tzuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfyu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858xuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStwuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUvw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm}uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC	u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf
u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU
w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*$uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
#u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t"uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf!u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858 uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt+uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf*u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858)uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt(uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU'w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~&wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm%uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC1u- Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode0gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~/wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm.uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black-uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
,u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849

er+V:eD,
4016c342a85401eac37beabfbb025c514e077802555e329f3f4a77d1a835864fD+
656975f5968fdbaba0a643e24529b3b0762ebabec0f92509a22f96017cfcb03eD*
a6fbfa63c8d1fd4dd8cfecfeb29858434215394a4e58af6c4ba12e2f82e2a61dD)
39769e7385d3d8eb28ca268acbedfd9c29363613ab7fa8b641d5ad4a91230f51D(
3268b7dcf19f5e3720d65d039632fa15991336537a37e486e37ed194609102b2D'
83b0eba9581758f02b5754034154c3a6a53b89674d90775b537b093b6d1abebfD&
2f096012ac594da690f66f1e3c46720188e409c2af7f791c49395822c50dfb6cD%
75989f565f1e52c44012dd4948e788f9b6b90cf9a5a649233e43f199a47b4e44D$
f138db80a257cdee37382222b7317f2f922c13efffd8d47716c4daff0fb11d68D#
af95baddeac54f485e8299cc7cd2301b5e659e0a3c22ea98291b012c8a427d49D"
92b645cab65928cc0f32fe9883d7068564a4040ac0faf35c3ee1790142b461a1D!
40a0c734dea8e1bcdc12a1fa49951322a06ea7216cf06631e2528d597a596fd7D 
f69f263757a6c7fcfc52b278211fe2c2f78f053dfb157200b4e1e1a874b400c2
*&%C*8u Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
7u' Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t6uw Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf5u[ Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168584u Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt3uw Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU2w5 Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt?uw!Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf>u[!Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858=u!Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt<uw!Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU;w5!Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~:w Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm9ui Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCEu-"Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeDgI!Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~Cw!Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormBui!Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackAu!Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
@u'!Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*Lu"Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Ku'"Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tJuw"Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfIu["Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858Hu"Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStGuw"Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUFw5"Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtSuw#Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfRu[#Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858Qu#Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStPuw#Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUOw5#Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~Nw"Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormMui"Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCYu-$Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeXgI#Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~Ww#Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormVui#Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackUu#Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Tu'#Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*`u$Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
_u'$Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t^uw$Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf]u[$Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858\u$Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt[uw$Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUZw5$Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Ptguw%Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresffu[%Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858eu%Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStduw%Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUcw5%Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~bw$Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormaui$Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCmu-&Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modelgI%Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~kw%Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormjui%Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackiu%Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
hu'%Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*tu&Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
su'&Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849truw&Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfqu[&Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858pu&Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStouw&Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUnw5&Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt{uw'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfzu['Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858yu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStxuw'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUww5'Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~vw&Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuui&Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-(Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegI'Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~w'Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm~ui'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black}u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
|u''Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*u(Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'(Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuw(Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[(Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858u(Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuw(Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5(Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Ptuw)Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[)Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858
u)Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuw)Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5)Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~
w(Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm	ui(Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-*Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegI)Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~w)Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormui)Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blacku)Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u')Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*u*Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'*Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuw*Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[*Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858u*Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuw*Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5*Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt#uw+Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf"u[+Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858!u+Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt uw+Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5+Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~w*Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormui*Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC)u-,Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode(gI+Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~'w+Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm&ui+Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black%u+Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
$u'+Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*0u,Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
/u',Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t.uw,Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf-u[,Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858,u,Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt+uw,Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU*w5,Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt7uw-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf6u[-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168585u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt4uw-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU3w5-Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~2w,Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm1ui,Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black

er+V:eD9
7c7eaf7933e4baf3cf7625220da22e524fe3ed89a2e6b6796e753638c6af6de5D8
27630533e7ce471a5218ba93882e15e857abb3262a57b550aa04a27de283e57aD7
fc069c671947a77de565e36b545682f1a73f32c53725d79715125c1c12e518d0D6
fc0d3c5609c739acc6d67bf0bff0c3ce7d1a05383836701bcb21e55aea34acefD5
61dc6bb4a8a0afa5abfca5dbd6cc89799609dd46cb583de0e51dde496c7b2a30D4
e964887b330c27510a0b5b1eb8c31a8c5eda05bde74e42a145bea54bb240d335D3
48733bcb59a63cace889d40e1387badbc9621da7fad0ddcd0d198e83f214e41fD2
f6f4af57d47fdebdd0de45acce2777a89181f31063e8511ded23c672de57fe99D1
757cbedb5a1d0d38a9479759f8661ec2fc0853efaf4ef184a79a5f96ef5b7a8eD0
22218edd785c94ee6fbbe5ded89195ece5e0450abc17b7afb225b4677b79f3f1D/
e311decc49b7ee2360283ef4b0704bc4c8dc2c2628d70e47cfff25b1e8583f72D.
1c826c2145a30350f476ab5a9a6151bd349415c6cab19956813fffb3b864a331D-
e17a8027f3820da82d6b20358ef0d2e8fb3c334ec7632d5262a93004b4cf2fbf
CnvC=u-.Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode<gI-Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~;w-Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm:ui-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black9u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
8u'-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*Du.Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Cu'.Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tBuw.Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfAu[.Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858@u.Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt?uw.Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU>w5.Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtKuw/Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfJu[/Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858Iu/Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStHuw/Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUGw5/Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~Fw.Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormEui.Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCQu-0Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modePgI/Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~Ow/Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormNui/Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackMu/Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Lu'/Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*Xu0Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Wu'0Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tVuw0Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfUu[0Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858Tu0Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStSuw0Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorURw50Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt_uw1Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf^u[1Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858]u1Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt\uw1Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU[w51Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~Zw0Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormYui0Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCeu-2Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modedgI1Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~cw1Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormbui1Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackau1Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
`u'1Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*lu2Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
ku'2Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tjuw2Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfiu[2Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858hu2Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStguw2Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUfw52Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Ptsuw3Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfru[3Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858qu3Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStpuw3Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUow53Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~nw2Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormmui2Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCyu-4Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modexgI3Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~ww3Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormvui3Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuu3Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
tu'3Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*u4Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'4Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t~uw4Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf}u[4Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858|u4Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt{uw4Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUzw54Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Ptuw5Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[5Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858u5Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuw5Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw55Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~w4Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormui4Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC
u-6Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegI5Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm
ui5Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black	u5Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'5Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*u6Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'6Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuw6Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[6Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858u6Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuw6Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw56Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Ptuw7Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[7Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858u7Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuw7Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw57Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~w6Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormui6Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC!u-8Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode gI7Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~w7Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormui7Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blacku7Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'7Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*(u8Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
'u'8Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t&uw8Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf%u[8Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858$u8Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt#uw8Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU"w58Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt/uw9Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf.u[9Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858-u9Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt,uw9Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU+w59Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~*w8Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm)ui8Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC5u-:Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode4gI9Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~3w9Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm2ui9Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black1u9Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
0u'9Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849

er+V:eDF
b6052b91db5ed4e063fd850d975d05689cc9b1996c06638c4d251659b128c9acDE
d4fd0adcfbd04fb5365175b9d356f5d3f697870607c655b2853cc010c8514ce7DD
5b93e870e57b80682109021a45ee40d59a50ca460b054a2fdff648fe118c7ec0DC
07e3f6b9b256a115590234dc0183bcf39f3cd1e274bd4d7506c4ae4992f8adedDB
9d8f6d50998e1ddcbcad83e5a929b89aebdccffb0d09afca0a5d451591034494DA
8bcc89f7bef113e056e226e9e5c3e3be2396e0d1fa312a4a061ee85ad8c52a3aD@
6db6194f7a398d0d7abc7755a2f9fc2b6887cd20921eaa12f12ae087c8d48816D?
97de078974c76f22114377981f82fac9312b4ce5e781ef81172b4cf2d22a8cf2D>
8c834bac2f30be752f112c1cc6098fa621dd2400df835b51ee13e22bd5c05807D=
3d48adfd65237fbd521c95fe26d5d4f17e03f7af968c2b5cd036e099d635d188D<
61679ab7934366aedce5be340b71089ee0a1460bac5c95cb884fc6059f1bb7a1D;
5578da34b6bdd59f584a7e2baf29876c99b00d2684ede1967f37ca2d95b787a3D:
a056997b96782b4b457a7404dada83836f46133ac10579459e04c22a64697b3f
*&%C*<u:Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
;u':Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t:uw:Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf9u[:Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168588u:Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt7uw:Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU6w5:Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtCuw;Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfBu[;Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858Au;Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt@uw;Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU?w5;Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~>w:Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm=ui:Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCIu-<Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeHgI;Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~Gw;Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormFui;Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackEu;Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Du';Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*Pu<Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Ou'<Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tNuw<Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfMu[<Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858Lu<Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStKuw<Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUJw5<Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtWuw=Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfVu[=Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858Uu=Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStTuw=Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUSw5=Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~Rw<Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormQui<Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC]u->Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode\gI=Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~[w=Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormZui=Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackYu=Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Xu'=Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*du>Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
cu'>Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tbuw>Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfau[>Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858`u>Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt_uw>Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU^w5>Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogbR%RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{%~L%S%Y%`%g%m%t%{%%%%%%#%)%0%7%=%D%K%Q%X%_%e%l%s%y%%%
%%%!%(%/%5%<%C%I%P%W%]%d%k%q%x%%%%%% %'%-%4%;%A%H%O%U%\%c%i%p%w%Á}%ā%Ł%Ɓ%ǁ%ȁ%Ɂ%%ʁ,%ˁ3%́9%΁@%ρG%ЁM%сT%ҁ[%Ӂa%ԁh%Ձo%ցu%ׁ|%؁%ف	%ځ%ہ%܁%݁$%ށ+%߁1%8%?%E%L%S
P
32Ptkuw?Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfju[?Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858iu?Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSthuw?Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUgw5?Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~fw>Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormeui>Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCqu-@Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modepgI?Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~ow?Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormnui?Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackmu?Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
lu'?Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*xu@Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
wu'@Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tvuw@Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfuu[@Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858tu@Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStsuw@Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUrw5@Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwACaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf~u[ACaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858}uACaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt|uwACaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU{w5AStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~zw@Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormyui@Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-BCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIAEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wAStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiACaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuACaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'ACaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uBCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'BCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t
uwBCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf	u[BCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uBCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwBCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5BStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[CCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5CStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wBStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm
uiBCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-DCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegICEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wCStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'CCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C* uDCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'DCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwDCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[DCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uDCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwDCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5DStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt'uwECaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf&u[ECaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858%uECaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt$uwECaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU#w5EStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~"wDStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm!uiDCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC-u-FCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode,gIEEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~+wEStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm*uiECaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black)uECaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
(u'ECaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*4uFCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
3u'FCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t2uwFCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf1u[FCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168580uFCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt/uwFCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU.w5FStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt;uwGCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf:u[GCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168589uGCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt8uwGCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU7w5GStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~6wFStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm5uiFCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black

er+V:eDS
058ac0bdef709238810c53bb5fa0fcf0b4843e91d77920ccea506da4114aed3cDR
1563224cd55060ababda0629baf763138a4b5c22b82b6494721b272e3e38a000DQ
d93864058f944550d1b6bcace4755bf6917cc80f773596ac1296ac0c13f00336DP
c1d7e786bf4c095d0ce6ba44863e3fa1e5626c2c14307901e7bcd56c8a589876DO
f74b0b973f9171904ea286136bf82b4154a2d8121fb7508c2e3a8285485f2f48DN
36100cd15f92cdafbc93a99d22267147437baa08033156354f656dfc64b59e9eDM
390e0d90e7a686457526470783a48fb4b4555c09798e0576afd065c0488356b9DL
30d47ccf8c6af77d81b8e9bb9bbeb51114e301cd9a47a8f37a3077a6b1bb08a8DK
6889ca4b0900ba23876bca7cf204adce1bfd41a09d82a67b81254773908cb5d0DJ
6251257e2c5253fdfcba671ae6cb37b06e73d7cd02051442ae5fe2d66a63df83DI
0b115d54c14e78f3f59d84b00407c9b0d58b5c274afa2b7f993667bb66f3f8e8DH
bd4f5d655ba5a25030d453a042ac28a2d723812f5dde3bd8ab1a817e87237f97DG
12b6c2912b246899401394c661b0f6d550c810ec67c1a013c5686bebca186c0a
CnvCAu-HCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode@gIGEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~?wGStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm>uiGCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black=uGCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
<u'GCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*HuHCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Gu'HCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tFuwHCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfEu[HCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858DuHCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStCuwHCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUBw5HStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtOuwICaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfNu[ICaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858MuICaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStLuwICaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUKw5IStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~JwHStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormIuiHCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCUu-JCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeTgIIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~SwIStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormRuiICaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackQuICaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Pu'ICaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*\uJCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
[u'JCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tZuwJCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfYu[JCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858XuJCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStWuwJCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUVw5JStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtcuwKCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfbu[KCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858auKCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt`uwKCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU_w5KStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~^wJStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm]uiJCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCiu-LCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modehgIKEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~gwKStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormfuiKCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackeuKCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
du'KCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*puLCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
ou'LCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tnuwLCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfmu[LCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858luLCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStkuwLCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUjw5LStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtwuwMCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfvu[MCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uuMCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSttuwMCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUsw5MStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~rwLStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormquiLCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC}u-NCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode|gIMEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~{wMStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormzuiMCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackyuMCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
xu'MCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uNCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'NCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwNCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[NCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uNCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwNCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU~w5NStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwOCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf
u[OCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858	uOCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwOCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5OStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wNStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiNCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-PCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIOEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wOStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiOCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
uOCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'OCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uPCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'PCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwPCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[PCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uPCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwPCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5PStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwQCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[QCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uQCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwQCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5QStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wPStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiPCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC%u-RCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode$gIQEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~#wQStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm"uiQCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black!uQCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
 u'QCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*,uRCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
+u'RCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t*uwRCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf)u[RCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858(uRCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt'uwRCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU&w5RStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt3uwSCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf2u[SCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168581uSCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt0uwSCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU/w5SStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~.wRStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm-uiRCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC9u-TCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode8gISEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~7wSStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm6uiSCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black5uSCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
4u'SCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849

er+V:eD`
0f9b27fa945a2929eef54b26fe1fa8010d7cbd461cd3c645fb8cc62de85d5a8bD_
cbdf552514fc3c8f3e787e174fe5b17897007c1d1e76bf0565f3c48969b03d86D^
a03be94a199377cb1c5614368a415c0540f04e2d6bc74e7bfbe1a1dd0c525128D]
afb7e36e5aaec8646bbdfa039bbfe6972eb157211104d1286ea36f29c07af0fbD\
dc5b0b3c78dcae2b3bf5f5c9dcbcf24534372b9e13c9464c300a0017948eaf99D[
0dc167d2f05541662cc1bfe1773d78ea0566b4fae06130399f47b0f01f34e177DZ
2663e6a78d254c25af0632b96caa6ae85c1a93cf308dc522b9e8bfaa334d9f2eDY
6597772d1fa9bdcbb982220b4e56bd13fb3a65b1ccdee0a911f8e5af3f58d188DX
1cb47e9ddc0c4d017161325b321b5a50d4645ac07758b0d9cc09ce6180bce014DW
4bd28dce0b162f8a2da3d74b80a28f0bed475feb3b13bc07076dbd9447d2deaaDV
15dbef5a2991f085e58a23e6a7047ea54e528a6f93b07a28839c0b6e3ed48c5eDU
e53316518deaff6343f609e95cac017e8bde5012d97256307e5dfb033e102c0fDT
f062b9d33e6eee164c17233ffc747844edad4fb3865de2b1c409d81837aff544
*&%C*@uTCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
?u'TCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t>uwTCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf=u[TCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858<uTCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt;uwTCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU:w5TStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtGuwUCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfFu[UCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858EuUCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStDuwUCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUCw5UStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~BwTStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormAuiTCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCMu-VCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeLgIUEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~KwUStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormJuiUCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackIuUCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Hu'UCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*TuVCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Su'VCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tRuwVCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfQu[VCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858PuVCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStOuwVCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUNw5VStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt[uwWCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfZu[WCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858YuWCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStXuwWCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUWw5WStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~VwVStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormUuiVCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCau-XCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode`gIWEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~_wWStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm^uiWCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black]uWCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
\u'WCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*huXCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
gu'XCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tfuwXCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfeu[XCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858duXCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStcuwXCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUbw5XStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtouwYCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfnu[YCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858muYCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStluwYCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUkw5YStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~jwXStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormiuiXCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCuu-ZCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modetgIYEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~swYStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormruiYCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackquYCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
pu'YCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*|uZCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
{u'ZCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tzuwZCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfyu[ZCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858xuZCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStwuwZCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUvw5ZStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Ptuw[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuw[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5[Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~~wZStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm}uiZCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC	u-\Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegI[Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~w[Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormui[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blacku[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*u\Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'\Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuw\Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf
u[\Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858u\Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuw\Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU
w5\Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Ptuw]Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[]Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858u]Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuw]Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5]Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~w\Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormui\Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-^Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegI]Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~w]Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormui]Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blacku]Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u']Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*$u^Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
#u'^Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t"uw^Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf!u[^Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858 u^Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuw^Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5^Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt+uw_Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf*u[_Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858)u_Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt(uw_Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU'w5_Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~&w^Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm%ui^Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC1u-`Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode0gI_Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~/w_Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm.ui_Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black-u_Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
,u'_Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*8u`Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
7u'`Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t6uw`Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf5u[`Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168584u`Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt3uw`Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU2w5`Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt?uwaCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf>u[aCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858=uaCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt<uwaCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU;w5aStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~:w`Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm9ui`Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black

er+V:eDm
11803c3ea95efe8e996c12cad83271ef43838dbf25dae72ab9afc3954d65639bDl
8090afe9c1843d71bfe8d10d6b4076aea3559e86d8fa4c232dee54817c5b76fbDk
63bb7c514d317f810847e161cd7afb196f824e9b410a73c8e0ce05df376c310aDj
3650ca3ecdb13198b3e14e49b52b7dd911c3839ba77826f5b2dbd315026cc82fDi
ad6e6798e24fe8a37ac1aed9a3116bcf96b19cb797d6e59a4cbc7979cc334522Dh
cdfa438ee0d5eaf9ebf066c879fea0ad0e14ef3381353d9d8a8f249ff220b2afDg
3fe9c9d1c5627efcbd130b935885968a811be55b5028953a858e8517243e5d5aDf
08fe4123c9f2d5699c800a7e884d1f8f6958f6ec8448ac152f214735fd9ba5f9De
25e553164777a8317ea8977d7a80cabc995d717d2c470f08b6c043bdce419cd6Dd
4598ab08f211c59a2ee7f9d85a2e2c7a4f7b8845e0d7ac7dbfbb570230111cf0Dc
beef6f9a15afb17e466001549c5ab96b1b00d12812239114ab0ee733cba615f3Db
d04f4f2c802e659ebc50e30c425e08c36096ac47223dc795afdd8d19c31aeed9Da
f6c41df4e2079f35e9de7d6585897bf99e364b1eb18aa9ec79d9e20b9766f5e4
CnvCEu-bCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeDgIaEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~CwaStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormBuiaCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackAuaCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
@u'aCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*LubCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Ku'bCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tJuwbCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfIu[bCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858HubCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStGuwbCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUFw5bStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtSuwcCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfRu[cCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858QucCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStPuwcCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUOw5cStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~NwbStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormMuibCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCYu-dCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeXgIcEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~WwcStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormVuicCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackUucCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Tu'cCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*`udCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
_u'dCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t^uwdCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf]u[dCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858\udCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt[uwdCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUZw5dStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtguweCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresffu[eCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858eueCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStduweCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUcw5eStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~bwdStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormauidCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCmu-fCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modelgIeEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~kweStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormjuieCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackiueCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
hu'eCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*tufCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
su'fCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849truwfCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfqu[fCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858pufCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStouwfCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUnw5fStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt{uwgCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfzu[gCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858yugCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStxuwgCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUww5gStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~vwfStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuuifCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-hCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIgEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wgStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm~uigCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black}ugCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
|u'gCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uhCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'hCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwhCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[hCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uhCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwhCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5hStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[iCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858
uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5iStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~
whStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm	uihCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-jCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIiEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wiStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'iCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*ujCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'jCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwjCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[jCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858ujCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwjCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5jStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt#uwkCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf"u[kCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858!ukCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt uwkCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5kStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wjStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuijCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC)u-lCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode(gIkEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~'wkStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm&uikCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black%ukCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
$u'kCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*0ulCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
/u'lCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t.uwlCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf-u[lCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858,ulCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt+uwlCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU*w5lStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt7uwmCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf6u[mCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168585umCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt4uwmCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU3w5mStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~2wlStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm1uilCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC=u-nCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode<gImEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~;wmStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm:uimCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black9umCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
8u'mCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849

er+V:eDz
34269e92e56a1ed2e47570b48ed01530719dca4cb561baa301db389d679afdb1Dy
b909289acabf305cfeb8f77f4351ab4fa67c1a023c392ae4e326c32ba911376bDx
946e0d4202b53b3b065d23a43e6a5a0a32f61836c1b7305ec2a65d63b2fa48d0Dw
767a5d433dc92613d0cab0185b37f0fa6590e1823a9bc7f2ece1abc592069bd5Dv
400558346b5b54b33a80390a5849a1a330722cdff9436c07acf3e168b477330eDu
237720a4e9199e2738ab3196d8e7c59b9fa4ba4d4dfc2395b09b8670e45f802cDt
fb54396129c15361020a0307c4dd42f46da87f1c0a0841e0d0ee3ee404ce59bdDs
687ed68537f2f9b2bc7c1f4aa45d061f8e36a38d93c1b7144cf2b6e35157001eDr
353fc523cad5efc4cbbcfc1283eb522f0f97dcaeacf8fed02b5b71b895fe4f26Dq
637d3a56cc4d58c44384c03a0e5fd138ce60d2aafd7d584dd7f66e53cbeb3049Dp
80390bf3a08ba0f650c404d34722110ba6e30e0aa373d82bb1bc2d8d2d7d31baDo
b3c269833837e02c07b59ed5f8a0595794f5ae6d92b3d90ba420bd82eed56ffcDn
1dcf380a319a132c90457bf82f10d67e9fb2f0795535e4a430c15eba981edeef
*&%C*DunCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Cu'nCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tBuwnCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfAu[nCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858@unCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt?uwnCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU>w5nStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtKuwoCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfJu[oCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858IuoCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStHuwoCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUGw5oStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~FwnStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormEuinCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCQu-pCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modePgIoEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~OwoStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormNuioCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackMuoCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Lu'oCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*XupCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Wu'pCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tVuwpCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfUu[pCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858TupCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStSuwpCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorURw5pStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt_uwqCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf^u[qCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858]uqCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt\uwqCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU[w5qStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~ZwpStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormYuipCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCeu-rCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modedgIqEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~cwqStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormbuiqCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackauqCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
`u'qCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*lurCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
ku'rCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tjuwrCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfiu[rCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858hurCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStguwrCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUfw5rStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtsuwsCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfru[sCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858qusCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStpuwsCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUow5sStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~nwrStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormmuirCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCyu-tCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modexgIsEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wwsStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormvuisCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuusCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
tu'sCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*utCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'tCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t~uwtCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf}u[tCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858|utCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt{uwtCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUzw5tStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5uStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wtStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuitCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC
u-vCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIuEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wuStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm
uiuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black	uuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uvCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'vCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwvCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[vCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uvCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwvCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5vStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[wCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wvStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuivCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC!u-xCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode gIwEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'wCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*(uxCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
'u'xCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t&uwxCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf%u[xCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858$uxCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt#uwxCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU"w5xStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt/uwyCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf.u[yCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858-uyCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt,uwyCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU+w5yStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~*wxStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm)uixCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC5u-zCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode4gIyEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~3wyStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm2uiyCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black1uyCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
0u'yCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*<uzCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
;u'zCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t:uwzCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf9u[zCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168588uzCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt7uwzCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU6w5zStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtCuw{Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfBu[{Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858Au{Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt@uw{Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU?w5{Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~>wzStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm=uizCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black

er+V:eD
55ad97e23070c92807ae6019da970533404496ea9c55b2581bb34f2be3b54cd0D
beaba5748ba50e7e5eb175940f2356990aa23d1176560268068ee630c38f3953D
7a0d7cf0562ad8c11ff90029a2c2cd9fd83de148afbd1a8db3fb79e0d11ffbfaD
e71a307c1ef8b62e83a97e331815cedb4e6c75a9c53468d64a42013fc4038c08D
16e1a4a30424173e656cc48c68ae55bac63aeb586b1cd0e94eca634d8e1f153eD
70ab660529559dbc0857824877d03fb7953ba5e86fde837ba44bd5f6d5ee3adfD
93506197bcd7012844761bc83df82a2fa27d417449b0cc8377a4f2fa84277d60D
95534a4322ef4fc7dfa9b623b1de5cd5d0d72c43f81f18b07d085100fc928858D
61ec12fb0832b09ad331cdf362aebd011e7d319697b112abc7430ee0ffc4bcdbD~
e81e2d49de42c4084b831416da43610e82111f1e2bf57b09c2cfecdedc32e6d9D}
bb264f253989b30cd12094f3d2e34773de2ffb9f77472b7bd12673eb092157aeD|
033cc5d8ff989f638033f0a6af82cb11c2d68d26fc602668a0a4c9673a09ef9cD{
a8415679884139db5b73792b19bc658a4e15f201e4f2b05c40f0e3f88e5e9a96
CnvCIu-|Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeHgI{Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~Gw{Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormFui{Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackEu{Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Du'{Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*Pu|Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Ou'|Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tNuw|Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfMu[|Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858Lu|Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStKuw|Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUJw5|Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtWuw}Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfVu[}Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858Uu}Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStTuw}Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUSw5}Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~Rw|Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormQui|Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC]u-~Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode\gI}Eike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~[w}Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormZui}Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackYu}Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Xu'}Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*du~Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
cu'~Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tbuw~Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfau[~Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858`u~Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt_uw~Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU^w5~Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtkuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfju[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858iuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSthuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUgw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~fw~Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormeui~Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCqu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modepgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~owStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormnuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackmuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
lu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*xuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
wu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tvuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfuu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858tuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStsuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUrw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogbR&ORY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{%`%g%m%t%{%%%%%%#%)%0%7%=%D%K%Q%X%_%e%l%s%y&&&
&&&!&(&/&5&	<&
C&I&
P&W&]&d&k&q&x&&&&&& &'&-&4&;&A&!H&"O&#U&$\&%c&&i&'p&(w&)}&*&+&,&-&.&/%&0,&13&29&3@&4G&6M&7T&8[&9a&:h&;o&<u&=|&>&?	&@&A&B&C$&D+&E1&F8&G?&HE&JL&KS&LY&M`&Ng
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf~u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858}uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt|uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU{w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~zwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormyuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t
uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf	u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm
uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C* uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt'uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf&u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858%uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt$uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU#w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~"wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm!uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC-u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode,gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~+wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm*uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black)uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
(u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*4uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
3u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t2uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf1u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168580uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt/uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU.w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt;uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf:u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168589uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt8uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU7w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~6wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm5uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCAu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode@gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~?wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm>uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black=uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
<u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849

er+V:eD
545b84aca9e92f936ab9998e50b8f869519ed25a9b0ab3b228ca86046f34160eD
266ee44dc28b8838740a524e7e79e747a4f52b1e9c6c56a1fbda8f8ac816cf0cD
9a8b2db0e1457c3d413a7d5db0d2a07fe70d2fe34918a818a9527c1bd851cf8eD
101fd2608e35308dceb00d10e0a0521748cb0223084821b2a0bfdf550b1dbb11D
af747123a2f728bd5d30f3f31cf5d5124a9fa4ba4105764cf89594dde7453727D
c43c6671ab2d1c670d0abc37f1638ba2ea5bc99bfcf4092458d4f333b9d6e8a0D
d60af5df8c01a193097c36e1ec5c7d66f470b5c9f4400ee4e1e714397de12e81D

79da3fae5743d2c375b344832b875293be6e093e0f5535dbfd33978c82e7d095D
f818d743b3ac159c87610d03230aad3b70743afe5fc38d30a3aac4ab50db977eD
c388ede56e4bc34aa4c415c55b4aacfaecac0e8ac63e3aafb72c8678c87d2b5eD

ff32b3ca928a0d84d11d5efe9433ba05d661f2a1df648fe6eee586eb09c24ac6D	
5dd24758d5e830a0fbbb424ad112abfec1537db1194a06f3d33d97dbc8be9831D
72598a2a7205cad8abd1c6adb36033bebbb72e0537e83288ff0a562511b5e061
*&%C*HuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Gu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tFuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfEu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858DuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStCuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUBw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtOuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfNu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858MuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStLuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUKw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~JwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormIuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCUu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeTgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~SwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormRuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackQuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Pu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*\uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
[u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tZuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfYu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858XuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStWuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUVw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtcuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfbu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858auCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt`uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU_w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~^wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm]uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCiu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modehgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~gwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormfuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackeuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
du'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*puCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
ou'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tnuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfmu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858luCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStkuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUjw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtwuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfvu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSttuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUsw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~rwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormquiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC}u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode|gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~{wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormzuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackyuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
xu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU~w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf
u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858	uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC%u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode$gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~#wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm"uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black!uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
 u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*,uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
+u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t*uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf)u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858(uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt'uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU&w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt3uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf2u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168581uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt0uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU/w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~.wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm-uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC9u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode8gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~7wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm6uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black5uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
4u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*@uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
?u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t>uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf=u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858<uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt;uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU:w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtGuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfFu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858EuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStDuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUCw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~BwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormAuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black

er+V:eD!
38f6f38400a02dfd304ef361c147ae8587357a50cec7a0113047ebd33cf7c5e3D 
73e6c1345f450c5929eb00e5f4f97abca74086756ad6e3bd8c36e85d989c8283D
b1e13bff131933637fb9b843f0d5f4c6cb81232f5b53ac058376a71010948f6bD
4a1f2f949b103bdfe54eebc6b4963f047de93b1a0cc47cfa795070d2edcf457dD
42cd49e0abb9c9f367848467f27274693443d3037a447b74cde10b94706c4a80D
73e7e5f1dff51614ddae5538cafc528cb724c6dcfb3a9b9459be4d82230e5160D
73d0fdb5a95bdec295481af2bf2057fc8d78d8110d2f95f3bb7c85577a034eb7D
f1f8e68da43d3543c537c23e696bea84b8c7e225d2a8e638f1d3e6b4c768f286D
db7d1e186c2ae291d66b611f4323aa29b919d87a3e6ea1478b9cb9b642e60f17D
ecb37964581de31750352b4a0c77e2efd6f71b55d33d488cc7d2460a0a00d744D
6ac785b4fd5c3fbb3f1b4107b21e46b2cbdc7e63216e249d74bdbc43d05c70c5D
cd9f701311cf726c8b434a5ee4f0f2cb6e0df53b5a843c3ce0633217921b81dbD
b4f762ba7ffb9fcb803ea8da5868bfe7d15e7777c60e6f0f4f2f4a4d3f90cb50
CnvCMu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeLgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~KwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormJuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackIuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Hu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*TuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Su'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tRuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfQu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858PuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStOuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUNw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt[uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfZu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858YuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStXuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUWw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~VwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormUuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCau-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode`gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~_wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm^uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black]uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
\u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*huCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
gu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tfuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfeu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858duCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStcuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUbw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtouwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfnu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858muCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStluwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUkw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~jwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormiuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCuu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modetgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~swStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormruiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackquCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
pu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*|uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
{u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tzuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfyu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858xuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStwuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUvw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm}uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC	u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf
u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU
w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*$uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
#u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t"uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf!u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858 uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt+uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf*u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858)uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt(uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU'w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~&wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm%uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC1u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode0gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~/wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm.uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black-uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
,u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*8uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
7u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t6uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf5u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168584uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt3uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU2w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt?uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf>u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858=uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt<uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU;w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~:wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm9uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCEu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeDgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~CwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormBuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackAuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
@u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849

er+V:eD.
11476c0df825b8cf64558132ab6c00817fd04a45533f011c2784f1a0df797631D-
7eebede496a10ef7610a306704e8b7a5ad7104bef3763ae5d089c514d1656a99D,
9313b35402e85897b582429f4df8f344b42d30cec4731079c2c5f5a680fcc839D+
7ae117b77c126ac691263ef8d207cc3c2dd9ed5f34f138e411d09ae4a6122407D*
ec25d05d782c32b42db9e24ba4c9449d7fc9c689e3d0fa711ce8f94c261ce6b7D)
044fa462d51c4d22a5eb8db06de4ed95a23b6e26336c54e16ea3417cd87a5981D(
2c6bfa0e8aa6838cc1b81537932ca579cbd93cc93d440a8a7c84b5342ca0a123D'
598ff4789a5b089a81ead99e67555f293c41e08b2771cb5d1eb4868f669d0894D&
598f5c1de287046f5cbd57cfaf3cc1d9daa8acbbcfe94363eda1070339b435a8D%
604d0dced14a23f9e7eefa1abb0d32242d50b5ad9b6bc699114284e55ffc288fD$
73a833b69925445587e5e902cf5b0432e6cdf5d8c184064ea6f735ed11d28452D#
ede6fc896f82acb407c88ed425d1c7fa8420645aae77c5aaea694f1c692cbc45D"
5df62ba637b7f77964da2d97a25f63cdec28f90a8dfa76b05a4080f7aa03b3a2
*&%C*LuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Ku'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tJuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfIu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858HuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStGuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUFw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtSuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfRu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858QuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStPuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUOw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~NwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormMuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCYu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeXgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~WwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormVuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackUuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Tu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*`uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
_u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t^uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf]u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858\uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt[uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUZw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtguwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresffu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858euCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStduwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUcw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~bwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormauiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCmu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modelgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~kwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormjuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackiuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
hu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*tuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
su'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849truwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfqu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858puCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStouwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUnw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt{uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfzu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858yuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStxuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUww5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~vwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm~uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black}uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
|u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858
uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~
wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm	uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt#uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf"u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858!uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC)u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode(gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~'wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm&uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black%uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
$u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*0uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
/u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t.uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf-u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858,uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt+uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU*w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt7uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf6u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168585uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt4uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU3w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~2wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm1uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC=u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode<gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~;wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm:uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black9uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
8u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*DuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Cu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tBuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfAu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858@uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt?uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU>w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtKuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfJu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858IuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStHuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUGw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~FwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormEuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black

er+V:eD;
9e499430d2fb2c6cb68c3ee8c7e80022d612bdba43e98c21c6cead204a19aee1D:
614857c396c65004fd986e7b0b3b669ea5f8880fc93c655a69ea8ff5177d58fbD9
75518cc294a25dd2bf8e7d7c0883cc13f46fbe3694ee431b5e7ac646eae722b4D8
cd15c26fb1146a5e8fc006618f54a1857a651b59524ad0b43e2de55f2ecdf4adD7
d21a1f7149813805ef3c6537ab7c9dee0567804a8f9983618aef692ed579f292D6
1627c36660c246a28b1b4c12b7bb6265a2948ecc122efd459f7d3a78959935e7D5
4d706aab7c08c3071b31ae66919573e924ce2400aa7bf07fb5eeea3a69a8bb73D4
d00284a41b68e575da476321841fba290849066dcd50949ee1f46e5984294f6aD3
e19a3d190b4be2dfd6bf0e58eb5017d6235b6dc0bc5b12d4b5d07c5dfdf34eecD2
b5962c01ec97042d7aa371253ae592a53b11214605721063be11027949cd9ee6D1
e5bed7d18f1cb03d90274c85c7eb780577a158e85aa2ac2af3e174486ae52f9dD0
b47475049748725638cfe057a54b45b2386eb621ed65e7dc441b3f6dff971e60D/
25eda2d5ea8c705770886b5cf7cf2643b509f198fe1feae97607f96210343f0f
CnvCQu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modePgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~OwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormNuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackMuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Lu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*XuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Wu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tVuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfUu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858TuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStSuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorURw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt_uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf^u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858]uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt\uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU[w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~ZwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormYuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCeu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modedgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~cwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormbuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackauCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
`u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*luCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
ku'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tjuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfiu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858huCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStguwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUfw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtsuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfru[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858quCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStpuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUow5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~nwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormmuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCyu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modexgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormvuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
tu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t~uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf}u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858|uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt{uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUzw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC
u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm
uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black	uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC!u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*(uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
'u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t&uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf%u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858$uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt#uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU"w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32Pt/uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf.u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858-uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt,uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU+w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~*wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm)uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC5u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode4gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~3wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm2uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black1uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
0u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*<uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
;u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t:uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf9u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-168588uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt7uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU6w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtCuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfBu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858AuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt@uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU?w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~>wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm=uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCIu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modeHgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~GwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormFuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackEuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Du'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849

er+V:eDH
c205e6c8f267b531e6cb7cdabe53c2b3cda12f1afd4735ece2a55f5c116d0159DG
dd5402f5bb60ada1db63c1305e3650e8804adcacfb1557affb8623621fd83155DF
6263d570ddf0f6cf0247a3e7266a7aa7caae795462727dbb4d747261bc4aa1beDE
1eb2e0f2ab532fc7491714b9d8dae34bf6977843c4b9649fe0509d2fc7dc3b59DD
8a0bacc73339833881bc5ae7fa62eafa7a9c0011b40065f3a69fb02d298f29d6DC
3f87a8a259dcf40c961dfad59240eff08fc35580ae718952a8849e7b5926cfb4DB
8ba208735c422fc7201d30c4eee2567d7d1db7cfe28590c93e563015db58818bDA
49f444eb43979988b55286bf011d39ef639f814d68348b633249b8d4d229e0f3D@
b4a0638e6c66b83b32396e053b68f71ce9f9c0846f117e75c3223af733c923b9D?
1a8201b73f71ee44efe72426328fc48ad33413143a7f40a898fb7b926034487fD>
08d1d1cc28a0a4caf172ffb26c59f35532cb13b37543dc1b44895666f5c4d486D=
93b059a3da417ccc61646327c6d1ed94b3a83a59eea67aeb8419f44ebb5522d3D<
2cc2e0d90af5e45dd0446328fe940a605fcb5aeaa3c115959be8469b6f134c83
*&%C*PuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Ou'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tNuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfMu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858LuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStKuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUJw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtWuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfVu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858UuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStTuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUSw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~RwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormQuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvC]u-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation mode\gIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~[wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormZuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackYuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
Xu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*duCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
cu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tbuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfau[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858`uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt_uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU^w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtkuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfju[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858iuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSthuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUgw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~fwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormeuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCqu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modepgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~owStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormnuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackmuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
lu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*xuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
wu'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849tvuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfuu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858tuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStsuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUrw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf~u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858}uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPSt|uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorU{w5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~zwStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormyuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
CnvCu-Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-16[d@- Resolves: rhbz#1589029 impress not showing text-highlight in presentation modegIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
*&%C*uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849t
uwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresf	u[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialogbR&RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{&Pt&Q{&R&S&T&U&V&W#&X)&Y0&Z7&[=&\D&]K&_Q&`X&a_&be&cl&ds&ey&f&g&h
&i&j&k!&l(&m/&n5&o<&pC&qI&sP&tW&u]&vd&wk&xq&yx&z&{&|&~&&&&& &"&%&'&)&*&,&/&1&3&4&6&9&;&=&>&@&D&F&L&O&R&W&Z&]&b&e&g&l&o&q&w&{&&&
&&&&&%&)&.&2&7&;&A&F&K&Q
P
32PtuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-21\n- Resolves: rhbz#1066844 drop libreofficekit requiresfu[Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-20\X)@- Resolves: rhbz#1672003 CVE-2018-16858uCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-19[m~@- Resolves: rhbz#1614419 detect PK11_ImportSymKey failure under FIPStuwCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-18[dC- Resolves: rhbz#1610904 draw glitches in drag cursorUw5Stephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-17[a- Resolves: rhbz#1545262 Workaround for spurious ppc64le automated testing crash
- Resolves: rhbz#1610692 silence console warnings from print dialog~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendorm
uiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is black
nvTkATomas Mlcoch <tmlcoch at redhat.com> - 1.7.11-2T- Make tests port agnosticgIEike Rathke <erack@redhat.com> - 1:5.3.6.1-26fGF- Fix CVE-2022-38745 Empty entry in Java class path
- Fix CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing
- Fix CVE-2023-1183 libreoffice: Arbitrary File Write
- Fix CVE-2023-6185 escape url passed to gstreamer~wStephan Bergmann <sbergman@redhat.com> - 1:5.3.6.1-25_0@- Resolves: rhbz#1900004 Support Red Hat, Inc. as Java vendormuiCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-24])- Resolves: rhbz#1728763 bg of blocks is blackuCaolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-23]v>- Resolves: rhbz#1601372 libreoffice fails to build with --nocheck
u'Caolán McNamara <caolanm@redhat.com> - 1:5.3.6.1-22]rJ@- Resolves: rhbz#1743962 CVE-2019-9848
- Resolves: rhbz#1743954 CVE-2019-9849
tkTomas Mlcoch <tmlcoch at redhat.com> - 1.7.13-1T7- Fix ABI compatibility (RhBug: 1185180)
- fastestmirror: Add LRO_FASTESTMIRRORTIMEOUT option
- downloader: Move broken mirror at the end of the list of mirrors (RhBug: 1183998)
- Make building tests and docs optional
- librepo: Don't download remote mirrorlist/metalink when LRO_LOCAL is specified (Resolves #41)ikiTomas Mlcoch <tmlcoch at redhat.com> - 1.7.12-1T@- downloader: Allow max one resume + nicer message if xattr cannot be set (RhBug: 1130685)
- downloader: Resume only files that were originaly downloaded by Librepo (RhBug: 1130685)
- downloader: Show also calculated checksums in error message about bad checksum
- Python: Return all strings in unicode
aajkmTomas Mlcoch <tmlcoch at redhat.com> - 1.7.14-2TA- compat: fix ck_assert_msg() segfault in rhel-7,koTomas Mlcoch <tmlcoch at redhat.com> - 1.7.14-1T@- tests: Use g_assert_cmpuint instead of ck_assert_uint_eq (Pullrequest #43)
- Add LRO_OFFLINE
- Python: Handle: Raise ValueError instead of TypeError when an unknown option is specified
- Python: Result: Use ValueError instead of TypeError when an unknown option value is specified
- Add LR_VERSION constant with version string
- python: Import contants from C librepo module in a loop
- repoconf: Add support for failover and skip_if_unavailable options
- handle: Change of LRO_LOCAL causes invalidation of internal mirrorlist (related to RhBug: 1188600)
- Load local mirrorlists when LRO_LOCAL is on (related to RhBug: 1188600)
- util: Add lr_is_local_path()
- New module repoconf for reading *.repo files
- Add LRO_HTTPHEADER option (RhBug: 1181123)
gCColin Walters <walters@redhat.com> - 1.7.15-2UQ@- Disable tests and drop python-flask build dependency on RHEL7, as
  it is not in the coresk}Tomas Mlcoch <tmlcoch at redhat.com> - 1.7.15-1U-@- Do not inlude header in the body output (RhBug: 1207685)
- metalink: Proper error handling
- New LRR_RPMMD_* contants
- Support for client certificates
- Use 'metadata in the rpm-md format' instead of 'yum metadata' (Issue #51)
- CMakeLists.txt: do not check for CXX
- build: Use solely pkg-config to find glib
..M g5Colin Walters <tmlcoch@redhat.com> - 1.7.16-1UhT- Add LRI_LOWSPEEDTIME and LRI_LOWSPEEDLIMIT
- downloader: Don't consider CURLE_RECV_ERROR and CURLE_SEND_ERROR as fatal errors (RhBug: 1219817)
- test_repoconf: Fix SIGSEGV in repoconf_assert_na (RhBug: 1222471)
- repoconf: Proper handling of gint64 and guint64 types
- build: Be compatible with cmake 2.8
- handle: Do not free temporary error msg if there is no one (RhBug: 1219822)
- utils/make_rpm.sh: Accept rpmbuild options as second argument (Issue #49)
- Python: call lr_global_init() during module initialization
- Add global function log_set_file that allow user to set a file where logs will be written (Issue #53)
- util: Honor RFC 3986 (Issue #55)
JJi"]yAles Matej <amatej@redhat.com> - 1.8.1-8_5+@- Validate paths read from repomd.xml (RhBug: 1866500)D!_+Marek Blaha <mblaha@redhat.com> - 1.8.1-1[o- Add yumrecord substitution mechanism (mluscon)
- Fix a memory leak in signature verification (cwalters)
- Add new option LRO_FTPUSEEPSV
- downloader prepare_next_transfer(): simplify long line
- downloader prepare_next_transfer(): add missing error check
- downloader prepare_next_transfer(): cleanup error path
- downloader prepare_next_transfer() - fix memory leak on error path (Alan Jenkins)
- handle: Don't use proxy cache for downloads of metalink/mirrorlist
- handle: Don't set CURLOPT_HTTPHEADER into curl handle immediately when specified
- downloader: Implement logic for no_cache param in LrDownloadTarget (RhBug: 1297762)
- Add no_cache param to LrDownloadTarget and lr_downloadtarget_new()
- New test: always try to download from the fastest mirror (Alexander Todorov)
:t%kTomas Mlcoch <tmlcoch at redhat.com> - 1.7.13-1T7- Fix ABI compatibility (RhBug: 1185180)
- fastestmirror: Add LRO_FASTESTMIRRORTIMEOUT option
- downloader: Move broken mirror at the end of the list of mirrors (RhBug: 1183998)
- Make building tests and docs optional
- librepo: Don't download remote mirrorlist/metalink when LRO_LOCAL is specified (Resolves #41)i$kiTomas Mlcoch <tmlcoch at redhat.com> - 1.7.12-1T@- downloader: Allow max one resume + nicer message if xattr cannot be set (RhBug: 1130685)
- downloader: Resume only files that were originaly downloaded by Librepo (RhBug: 1130685)
- downloader: Show also calculated checksums in error message about bad checksum
- Python: Return all strings in unicodeT#kATomas Mlcoch <tmlcoch at redhat.com> - 1.7.11-2T- Make tests port agnostic
aaj'kmTomas Mlcoch <tmlcoch at redhat.com> - 1.7.14-2TA- compat: fix ck_assert_msg() segfault in rhel-7,&koTomas Mlcoch <tmlcoch at redhat.com> - 1.7.14-1T@- tests: Use g_assert_cmpuint instead of ck_assert_uint_eq (Pullrequest #43)
- Add LRO_OFFLINE
- Python: Handle: Raise ValueError instead of TypeError when an unknown option is specified
- Python: Result: Use ValueError instead of TypeError when an unknown option value is specified
- Add LR_VERSION constant with version string
- python: Import contants from C librepo module in a loop
- repoconf: Add support for failover and skip_if_unavailable options
- handle: Change of LRO_LOCAL causes invalidation of internal mirrorlist (related to RhBug: 1188600)
- Load local mirrorlists when LRO_LOCAL is on (related to RhBug: 1188600)
- util: Add lr_is_local_path()
- New module repoconf for reading *.repo files
- Add LRO_HTTPHEADER option (RhBug: 1181123)
)gCColin Walters <walters@redhat.com> - 1.7.15-2UQ@- Disable tests and drop python-flask build dependency on RHEL7, as
  it is not in the cores(k}Tomas Mlcoch <tmlcoch at redhat.com> - 1.7.15-1U-@- Do not inlude header in the body output (RhBug: 1207685)
- metalink: Proper error handling
- New LRR_RPMMD_* contants
- Support for client certificates
- Use 'metadata in the rpm-md format' instead of 'yum metadata' (Issue #51)
- CMakeLists.txt: do not check for CXX
- build: Use solely pkg-config to find glib
..M*g5Colin Walters <tmlcoch@redhat.com> - 1.7.16-1UhT- Add LRI_LOWSPEEDTIME and LRI_LOWSPEEDLIMIT
- downloader: Don't consider CURLE_RECV_ERROR and CURLE_SEND_ERROR as fatal errors (RhBug: 1219817)
- test_repoconf: Fix SIGSEGV in repoconf_assert_na (RhBug: 1222471)
- repoconf: Proper handling of gint64 and guint64 types
- build: Be compatible with cmake 2.8
- handle: Do not free temporary error msg if there is no one (RhBug: 1219822)
- utils/make_rpm.sh: Accept rpmbuild options as second argument (Issue #49)
- Python: call lr_global_init() during module initialization
- Add global function log_set_file that allow user to set a file where logs will be written (Issue #53)
- util: Honor RFC 3986 (Issue #55)
JJi,]yAles Matej <amatej@redhat.com> - 1.8.1-8_5+@- Validate paths read from repomd.xml (RhBug: 1866500)D+_+Marek Blaha <mblaha@redhat.com> - 1.8.1-1[o- Add yumrecord substitution mechanism (mluscon)
- Fix a memory leak in signature verification (cwalters)
- Add new option LRO_FTPUSEEPSV
- downloader prepare_next_transfer(): simplify long line
- downloader prepare_next_transfer(): add missing error check
- downloader prepare_next_transfer(): cleanup error path
- downloader prepare_next_transfer() - fix memory leak on error path (Alan Jenkins)
- handle: Don't use proxy cache for downloads of metalink/mirrorlist
- handle: Don't set CURLOPT_HTTPHEADER into curl handle immediately when specified
- downloader: Implement logic for no_cache param in LrDownloadTarget (RhBug: 1297762)
- Add no_cache param to LrDownloadTarget and lr_downloadtarget_new()
- New test: always try to download from the fastest mirror (Alexander Todorov)
:t/kTomas Mlcoch <tmlcoch at redhat.com> - 1.7.13-1T7- Fix ABI compatibility (RhBug: 1185180)
- fastestmirror: Add LRO_FASTESTMIRRORTIMEOUT option
- downloader: Move broken mirror at the end of the list of mirrors (RhBug: 1183998)
- Make building tests and docs optional
- librepo: Don't download remote mirrorlist/metalink when LRO_LOCAL is specified (Resolves #41)i.kiTomas Mlcoch <tmlcoch at redhat.com> - 1.7.12-1T@- downloader: Allow max one resume + nicer message if xattr cannot be set (RhBug: 1130685)
- downloader: Resume only files that were originaly downloaded by Librepo (RhBug: 1130685)
- downloader: Show also calculated checksums in error message about bad checksum
- Python: Return all strings in unicodeT-kATomas Mlcoch <tmlcoch at redhat.com> - 1.7.11-2T- Make tests port agnostic
aaj1kmTomas Mlcoch <tmlcoch at redhat.com> - 1.7.14-2TA- compat: fix ck_assert_msg() segfault in rhel-7,0koTomas Mlcoch <tmlcoch at redhat.com> - 1.7.14-1T@- tests: Use g_assert_cmpuint instead of ck_assert_uint_eq (Pullrequest #43)
- Add LRO_OFFLINE
- Python: Handle: Raise ValueError instead of TypeError when an unknown option is specified
- Python: Result: Use ValueError instead of TypeError when an unknown option value is specified
- Add LR_VERSION constant with version string
- python: Import contants from C librepo module in a loop
- repoconf: Add support for failover and skip_if_unavailable options
- handle: Change of LRO_LOCAL causes invalidation of internal mirrorlist (related to RhBug: 1188600)
- Load local mirrorlists when LRO_LOCAL is on (related to RhBug: 1188600)
- util: Add lr_is_local_path()
- New module repoconf for reading *.repo files
- Add LRO_HTTPHEADER option (RhBug: 1181123)
3gCColin Walters <walters@redhat.com> - 1.7.15-2UQ@- Disable tests and drop python-flask build dependency on RHEL7, as
  it is not in the cores2k}Tomas Mlcoch <tmlcoch at redhat.com> - 1.7.15-1U-@- Do not inlude header in the body output (RhBug: 1207685)
- metalink: Proper error handling
- New LRR_RPMMD_* contants
- Support for client certificates
- Use 'metadata in the rpm-md format' instead of 'yum metadata' (Issue #51)
- CMakeLists.txt: do not check for CXX
- build: Use solely pkg-config to find glib
..M4g5Colin Walters <tmlcoch@redhat.com> - 1.7.16-1UhT- Add LRI_LOWSPEEDTIME and LRI_LOWSPEEDLIMIT
- downloader: Don't consider CURLE_RECV_ERROR and CURLE_SEND_ERROR as fatal errors (RhBug: 1219817)
- test_repoconf: Fix SIGSEGV in repoconf_assert_na (RhBug: 1222471)
- repoconf: Proper handling of gint64 and guint64 types
- build: Be compatible with cmake 2.8
- handle: Do not free temporary error msg if there is no one (RhBug: 1219822)
- utils/make_rpm.sh: Accept rpmbuild options as second argument (Issue #49)
- Python: call lr_global_init() during module initialization
- Add global function log_set_file that allow user to set a file where logs will be written (Issue #53)
- util: Honor RFC 3986 (Issue #55)
JJi6]yAles Matej <amatej@redhat.com> - 1.8.1-8_5+@- Validate paths read from repomd.xml (RhBug: 1866500)D5_+Marek Blaha <mblaha@redhat.com> - 1.8.1-1[o- Add yumrecord substitution mechanism (mluscon)
- Fix a memory leak in signature verification (cwalters)
- Add new option LRO_FTPUSEEPSV
- downloader prepare_next_transfer(): simplify long line
- downloader prepare_next_transfer(): add missing error check
- downloader prepare_next_transfer(): cleanup error path
- downloader prepare_next_transfer() - fix memory leak on error path (Alan Jenkins)
- handle: Don't use proxy cache for downloads of metalink/mirrorlist
- handle: Don't set CURLOPT_HTTPHEADER into curl handle immediately when specified
- downloader: Implement logic for no_cache param in LrDownloadTarget (RhBug: 1297762)
- Add no_cache param to LrDownloadTarget and lr_downloadtarget_new()
- New test: always try to download from the fastest mirror (Alexander Todorov)
:t9kTomas Mlcoch <tmlcoch at redhat.com> - 1.7.13-1T7- Fix ABI compatibility (RhBug: 1185180)
- fastestmirror: Add LRO_FASTESTMIRRORTIMEOUT option
- downloader: Move broken mirror at the end of the list of mirrors (RhBug: 1183998)
- Make building tests and docs optional
- librepo: Don't download remote mirrorlist/metalink when LRO_LOCAL is specified (Resolves #41)i8kiTomas Mlcoch <tmlcoch at redhat.com> - 1.7.12-1T@- downloader: Allow max one resume + nicer message if xattr cannot be set (RhBug: 1130685)
- downloader: Resume only files that were originaly downloaded by Librepo (RhBug: 1130685)
- downloader: Show also calculated checksums in error message about bad checksum
- Python: Return all strings in unicodeT7kATomas Mlcoch <tmlcoch at redhat.com> - 1.7.11-2T- Make tests port agnostic
aaj;kmTomas Mlcoch <tmlcoch at redhat.com> - 1.7.14-2TA- compat: fix ck_assert_msg() segfault in rhel-7,:koTomas Mlcoch <tmlcoch at redhat.com> - 1.7.14-1T@- tests: Use g_assert_cmpuint instead of ck_assert_uint_eq (Pullrequest #43)
- Add LRO_OFFLINE
- Python: Handle: Raise ValueError instead of TypeError when an unknown option is specified
- Python: Result: Use ValueError instead of TypeError when an unknown option value is specified
- Add LR_VERSION constant with version string
- python: Import contants from C librepo module in a loop
- repoconf: Add support for failover and skip_if_unavailable options
- handle: Change of LRO_LOCAL causes invalidation of internal mirrorlist (related to RhBug: 1188600)
- Load local mirrorlists when LRO_LOCAL is on (related to RhBug: 1188600)
- util: Add lr_is_local_path()
- New module repoconf for reading *.repo files
- Add LRO_HTTPHEADER option (RhBug: 1181123)
=gCColin Walters <walters@redhat.com> - 1.7.15-2UQ@- Disable tests and drop python-flask build dependency on RHEL7, as
  it is not in the cores<k}Tomas Mlcoch <tmlcoch at redhat.com> - 1.7.15-1U-@- Do not inlude header in the body output (RhBug: 1207685)
- metalink: Proper error handling
- New LRR_RPMMD_* contants
- Support for client certificates
- Use 'metadata in the rpm-md format' instead of 'yum metadata' (Issue #51)
- CMakeLists.txt: do not check for CXX
- build: Use solely pkg-config to find glib
..M>g5Colin Walters <tmlcoch@redhat.com> - 1.7.16-1UhT- Add LRI_LOWSPEEDTIME and LRI_LOWSPEEDLIMIT
- downloader: Don't consider CURLE_RECV_ERROR and CURLE_SEND_ERROR as fatal errors (RhBug: 1219817)
- test_repoconf: Fix SIGSEGV in repoconf_assert_na (RhBug: 1222471)
- repoconf: Proper handling of gint64 and guint64 types
- build: Be compatible with cmake 2.8
- handle: Do not free temporary error msg if there is no one (RhBug: 1219822)
- utils/make_rpm.sh: Accept rpmbuild options as second argument (Issue #49)
- Python: call lr_global_init() during module initialization
- Add global function log_set_file that allow user to set a file where logs will be written (Issue #53)
- util: Honor RFC 3986 (Issue #55)
JJi@]yAles Matej <amatej@redhat.com> - 1.8.1-8_5+@- Validate paths read from repomd.xml (RhBug: 1866500)D?_+Marek Blaha <mblaha@redhat.com> - 1.8.1-1[o- Add yumrecord substitution mechanism (mluscon)
- Fix a memory leak in signature verification (cwalters)
- Add new option LRO_FTPUSEEPSV
- downloader prepare_next_transfer(): simplify long line
- downloader prepare_next_transfer(): add missing error check
- downloader prepare_next_transfer(): cleanup error path
- downloader prepare_next_transfer() - fix memory leak on error path (Alan Jenkins)
- handle: Don't use proxy cache for downloads of metalink/mirrorlist
- handle: Don't set CURLOPT_HTTPHEADER into curl handle immediately when specified
- downloader: Implement logic for no_cache param in LrDownloadTarget (RhBug: 1297762)
- Add no_cache param to LrDownloadTarget and lr_downloadtarget_new()
- New test: always try to download from the fastest mirror (Alexander Todorov)
+l&++DcuPaul Wouters <pwouters@redhat.com> - 3.25-2[:- Resolves: rhbz#1597322 Relax deleting IKE SA's and IPsec SA's to avoid interop issues with third party VPN vendorsFCc+Paul Wouters <pwouters@redhat.com> - 3.25-1[3|@- Resolves: rhbz#1591817 rebase libreswan to 3.25
- Resolves: rhbz#1536404 CERT_PKCS7_WRAPPED_X509 error
- Resolves: rhbz#1544143 ipsec newhostkey fails in FIPS mode when RSA key is generated
- Resolves: rhbz#1574011 libreswan is missing a Requires: unbound-libs >= 1.6.6ABc!Paul Wouters <pwouters@redhat.com> - 3.23-4Z- Resolves: rhbz#1544143 ipsec newhostkey fails in FIPS mode when RSA key is generated
- Resolves: rhbz#1553406 IKEv2 liveness false positive on IKEv2 idle connections causes tunnel to be restarted
- Resolves: rhbz#1572425 shared IKE SA leads to rekey interop issuesAc=Paul Wouters <pwouters@redhat.com> - 3.23-3Zz@- Resolves: rhbz#1471553 libreswan postquantum preshared key (PPK) support [IANA update]
0T0Fc]Paul Wouters <pwouters@redhat.com> - 3.25-6\X)@- Resolves: rhbz#1630355 Libreswan crash upon receiving ISAKMP_NEXT_D with appended ISAKMP_NEXT_N [updated]
- Resolves: rhbz#1679735 libreswan using NSS IPsec profiles regresses when critical flags are set causing validation failure'EcmPaul Wouters <pwouters@redhat.com> - 3.25-5\@- Resolves: rhbz#1639404 Unable to verify certificate with non-empty Extended Key Usage which does not include serverAuth or clientAuth
- Resolves: rhbz#1630355 Libreswan crash upon receiving ISAKMP_NEXT_D with appended ISAKMP_NEXT_N
- Resolves: rhbz#1629902 libreswan assertion failed when OAKLEY_KEY_LENGTH is zero for IKE using AES_CBC
- Resolves: rhbz#1623279 [abrt] [faf] libreswan: strncpy(): /usr/libexec/ipsec/pluto killed by 11
- Resolves: rhbz#1625303 config: recursive include check doesn't work
- Resolves: rhbz#1664521 libreswan 3.25 in FIPS mode is incorrectly rejecting X.509 public keys that are >= 3072 bits
PrkLWKarel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_KWkKarel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)xJgPaul Wouters <pwouters@redhat.com> - 3.25-9.1^@- Resolves: rhbz#1844621 Backport FIPS keysize fixes from RHEL80IcPaul Wouters <pwouters@redhat.com> - 3.25-9]c- Resolves: rhbz#1724200 libreswan: XFRM policy for OE/32 peer is deleted when shunts for previous half-open state expire(HcoPaul Wouters <pwouters@redhat.com> - 3.25-8\s@- Resolves: rhbz#1686991 IKEv1 traffic interruption when responder deletes SAs 60 seconds before EVENT_SA_REPLACE+GcuPaul Wouters <pwouters@redhat.com> - 3.25-7\v{- Resolves: rhbz#1673105 Opportunistic IPsec instances of /32 groups or auto=start that receive delete won't restart

er+V:eDU
e7aab445dd74ec3ddd4f7504b5e00f8b2f7024c95448fb6ee6de759e0517cac4DT
c57edeef8ad80c1218e8f3c5f03298b8e4c78de794ef89153d213f767d7e76e8DS
51a15a1f28637adcdf2f0d13e8d6a81017809612ab5a6a46dda8025be6f4aeecDR
e28f306d4893ec7a68589345b053be93e9d807543f263f0bbfd81eacefbc4c10DQ
07502ee4563c4bdc09b8d0b67eba7577aae0d6c871501af53b038aad8812d391DP
71f4e4bdc94d32ca413c40fe3666b5b8b0a092fc42d58ea96801a440297da553DO
7c1cc6ce8c70a7a3b07d877d8ba90c49382b8945d6695e986df3f69e3b59cc32DN
25fa10449317511df1bc80c25c0cc1e7bede87a02929b5c0676ce9957353a8d9DM
baa1991d1849681ae5e74f8eeb2d213f69221f0c76cbe0018df32bd8f5ec1cb6DL
0d2b3fa57c857e63e2bc038eba8140a308abe22d4261989634084fe5e9eb73bdDK
b0ddff8c5c64edbfff1b2f8f18cc330688586e6a01207ad39c6c30bbeffe82fbDJ
8bb27e3133d87750b1501993b54e0bc9006242f30c7f46e98b7e0bc0a450cf2fDI
a9491aa4d8fe481a24a189a9849cfe530d5eaeb3550b1364284bf6b8b7a5a76b
>\OWcKarel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev(NW{Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=MW%Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failed
G&GZRW_Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bitQWIKarel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.APW-Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information
=n==WW%Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedkVWKarel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_UWkKarel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)DTg#Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]aSWmKarel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directory
,Sr,AZW-Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\YWcKarel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev(XW{Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login
la]WmKarel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZ\W_Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit[WIKarel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.
vT#v(bW{Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=aW%Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedk`WKarel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area__WkKarel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)D^g#Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
EEeWIKarel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.AdW-Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\cWcKarel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;agWmKarel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZfW_Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
vT#v(lW{Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=kW%Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedkjWKarel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_iWkKarel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)Dhg#Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
EEoWIKarel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.AnW-Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\mWcKarel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;aqWmKarel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZpW_Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
3K(3wwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCguiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3tk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhsikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16Drg#Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
{kAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockzk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskyiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspxiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zVqwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3~k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh}ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16|kAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%p
iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew	kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequireskAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
1~1giiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requiresck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DC
ywkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
PzIPw%kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagz$kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP#k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc"k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p!kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
)kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock(k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk'iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp&iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz.kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP-k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc,k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p+kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services*kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
2kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock1k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk0iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp/iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz7kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP6k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc5k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p4kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services3kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
;k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk:iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp9iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage{8k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
DyDzAkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP@k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc?k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p>kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services=kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock<kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
~FkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockEkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockDk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskCiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{Bk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{Kk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zJkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePIk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcHk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pGkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
IFK>IpQkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesPkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockOkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockNk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskMiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks5LkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict

er+V:eDb
51eac9ff71e53c4175eb210efa8bffca4476cc9cd86104293d1ca7f714062a4eDa
9ce18db0c7edcdf3961e7086a8438b700e7bb5f91d89a4bca5049729c6b02228D`
862a87260cad27824364c01e25cd821b1fc2a084f3522fee0b5654d684839796D_
6d16c50325196936545ac4cbb31f743a7fdab2589124f05cedf47845149e1035D^
c072f12110aa95c982d941e51b30f703d3010b75f805ba9c70e921f74a87e54fD]
51252d279ae23e76f0eab56a60f8b34948a2cb91859a5ebcb4dd70f5b140ade0D\
374238fd13c46caa7cbfc40bb0504875bf89695119fdc6cdbf33ab47bd195079D[
431b22149fa33a26bb336eee9700dbf64d3ec3c03e9604c4203a06a8e35aab3cDZ
948dd58b9aa2d3fe20747516b2640cf6b85bdabed1557859baee0cec0fa8a25cDY
10b16b350ee16d3d6b97cb71b8b4c1f23359036277bb481e4ccc7cd698d26ed4DX
6c72e414ed7ca2608725b7230e3820171e7ceca0b47d1c5a4623b22e410f9c5eDW
9f70940adeedfa2ad404110adcb36a268faa97569dc2fc32c100eab4368a9c54DV
a941b5ad075b2f47806bea28420794a24bc7fb5373b6712a5d0b500ee6118759
FF5VkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Uk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zTkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePSk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcRk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
6tgr6P\k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc[k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pZkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesYkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockXkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockWk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
@S@bkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockak%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesq`k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5_kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{^k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z]kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
zIzgkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePfk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcek_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pdkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesckAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
VFKVplkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockqjk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5ikAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{hk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
FFqrk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5qkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{pk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zokAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePnk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcmk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
d9dPxk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcwk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pvkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesukAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockztkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023csk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023
nSnz~kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c}k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q|k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5{kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{zk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zykAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
QQQ{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
Fjvc
k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p	kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesrk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023ck_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
+~ck_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{
k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
Z8ZmiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|kIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHELviAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023
q|viAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directorieswkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16
@'I%@v%kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg$iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3#k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh"ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m!iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|kIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*Ev-kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg,iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3+k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh*ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m)iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi(imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU'iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057w&kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
[![i2imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU1iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057k0iqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp/iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew.kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
#kw8kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv7kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg6iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires35k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh4ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m3iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal users
x0x3<k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh;ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16k:iqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp9iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
<<kAiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp@iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew?kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv>kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg=iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires
^tgC^vHkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgGiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Fk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhEikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16DkAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lockCkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockBk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
!Lk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskKiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspJiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewIkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
ywQkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvPkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgOiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequiresNkAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lockMkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock

er+V:eDo
56f09419cecb436d408500ec34950196ee1969ca1d67a1140bc4453bdc7db16dDn
5b8e30bc61877d67eb0781546eda037e3125af2d61226ff947eae46d951dea87Dm
83d237d121542e1a8974ca5404efc06ebabca5aa5ab1f7f036ed16f3396c2445Dl
2ed0b9cb14b8c09ea2a369592a8ae716f4f5a0d7a288dbb4a4fa9e6089e40760Dk
76499affa56e11ce8cb0b60296dc990f3d6d2f235f5edeb8261ed147ff7a3323Dj
1d90c0cbed34ba8bd0787832d1c7deb1024fe2c25a4f9accea2b95c7fa1c152aDi
3ba1c872bc9e60330b7b4b28cf7a36bdd1618d3c55d034ccc2f1b537590a34b8Dh
f7faa6dc9e93209b28d0cf6a0ef6f0697ece6387cbb402f2554016b1db3192a5Dg
ad24252031ea8c0e12e7acf23ebf80586b5162f12ce5e4eac8273966928e89d0Df
36410412b59ca22b5708b34c6f8dafdb38024efff345c20c4dc28c75a7eb8a0aDe
b3350c79767fa9a0a0ac49e9e26cb2d6f221c594bddb72ca5a870a8d7661e0f1Dd
8c78bd9be20532927c0a937e33b0befaa0f49afcab1f09654f5004054cf179b0Dc
b57c33a0b61dc0b3c7c8b1c2fc69d8106f19978caed12eb3547f80ac41328a7a
UkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockTk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskSiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspRiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
z9w[kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvZkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgYiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequirescXk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pWkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesVkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
_kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock^k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk]iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp\iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zwckIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagcbk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pakwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services`kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
gkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockfk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskeiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspdiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
PzIPwmkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagzlkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePkk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcjk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pikwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceshkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
qkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockpk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskoiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspniyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzvkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePuk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlctk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pskwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesrkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
zkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockyk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskxiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspwiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP~k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc}k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p|kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services{kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
DyDz	kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
~kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{
k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
IFK>IpkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
FF5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
6tgr6P$k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc#k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p"kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services!kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
@S@*kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock)k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesq(k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5'kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{&k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z%kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
zIz/kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP.k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc-k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p,kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services+kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
VFKVp4kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services3kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockq2k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind51kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{0k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
FFq:k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind59kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{8k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z7kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP6k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc5k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
d9dP@k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc?k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p>kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services=kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockz<kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c;k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023bR'RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{&\&b&g&l&r&x&~&&
&&&Á&ā%&Ł-&Ɓ2&ǁ8&ȁ<&ɁA&ʁH&ˁL&́Q&΁U&ρ[&Ё_&сc&ҁg&Ӂm&ԁq&Ձv&ցz&ׁ&؁&ف	&ځ&ہ&܁&݁&ށ$&߁*&/&4&:&@&F&K&R&X&_&e&m&u&z&&&&&&!&)&1&7&:&=&D&G&N&Q&X'['b'e'h'k'l'm'n'	q'
t'u'v'
w'z'}'~'''''''	'''''''
nSnzFkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cEk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qDk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5CkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Bk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zAkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
QQQ{Kk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zJkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePIk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcHk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pGkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
FjvcRk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pQkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesrPk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zOkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cNk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qMk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5LkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict

er+V:eD|
ba22fffa8b12afc9653dd3d202c1f25ea68005dc24e14085ecfbecab982605c8D{
2f2fef32bd829834efcff997a91ea78ebad9913aec9b94421efa69579be8f39cDz
6085603dfc592d80718a8fb07a369da5c47fe019535a490c02e8e0eeac89b9c2Dy
4d2980f737ca5c15f4f33e1a43a82d6b00ca06a5c6d284643ea2f0b2e7928f76Dx
c18739f0ff30069eb1e908fc713e8ef1e7fa3a75c981a8b45cd1383597e8a1e9Dw
7e6cf4cf5a25112c185e8d9c2750ce650787af37ded646d8d3923984a1868673Dv
1b3f8f389416ac835d75a09fd6027e44daad1e8447c349cac349b674506ce80fDu
d161a8ffe0e1f9856548b6a48619295b25351949a76f0c3447034360be168304Dt
126e1f4ba7b91116dc2de61216743f423ed250ef44140f20c97de01055c2374aDs
1aa4d5a6ea319219e3813cc9caf102cd6341fa2aebfa9e4b9096e4e1df7854d2Dr
a4f8b4717015fbf8177d95a8a84a98b233c1bb9171ffa261d3b9bfff69345e5dDq
bc009c7bfbbc8f4c90f5bb2715b2f88462acdb617db354d01214ce91bf2aab13Dp
bd0d1c4bba8882d3e5bbeb0d58b3e9677c33d9fcf22226207d7f43f0540af0d3
+~cXk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qWk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5VkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Uk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zTkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePSk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
Z8Zm_iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi^imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU]iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|\kIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHELv[iAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrZk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zYkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023
q|veiAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directorieswdkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvckIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgbiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3ak}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh`ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16
@'I%@vmkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgliiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3kk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhjikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16miiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersihimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUgiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|fkIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*EvukIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgtiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3sk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhrikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mqiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersipimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUoiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wnkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
[![izimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUyiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057kxiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspwiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
#kwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg~iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3}k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh|ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m{iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal users
ddFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.25-5Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.25-4P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildkiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
*.g*'s]Michal Hlavinka <mhlavink@redhat.com> - 1.0.25-12.1aF- a crafted wav file could cause heap buffer overflow that allowed an arbitrary code execution(#1985024)o+Michal Hlavinka <mhlavink@redhat.com> - 1.0.25-12^h- fix CVE-2018-19662 - buffer over-read in the function i2alaw_array (#1673086)
oGMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-11])- fix CVE-2018-13139 - stack-based buffer overflow in sndfile-deinterleave utility (#1598577)	mPeter Robinson <pbrobinson@redhat.com> 1.0.25-10S- Generic 32/64 bit platform detection - fix ppc64le build (#1126140)M_?Daniel Mach <dmach@redhat.com> - 1.0.25-9RU- Mass rebuild 2014-01-24M_?Daniel Mach <dmach@redhat.com> - 1.0.25-8Rk- Mass rebuild 2013-12-27lmoMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-7Q@- fix support for aarch64, another part (#969831)^mSMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-6QR@- fix support for aarch64 (#925887)
/dfT/oGMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-11])- fix CVE-2018-13139 - stack-based buffer overflow in sndfile-deinterleave utility (#1598577)mPeter Robinson <pbrobinson@redhat.com> 1.0.25-10S- Generic 32/64 bit platform detection - fix ppc64le build (#1126140)M_?Daniel Mach <dmach@redhat.com> - 1.0.25-9RU- Mass rebuild 2014-01-24M_?Daniel Mach <dmach@redhat.com> - 1.0.25-8Rk- Mass rebuild 2013-12-27lmoMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-7Q@- fix support for aarch64, another part (#969831)^mSMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-6QR@- fix support for aarch64 (#925887)Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.25-5Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.25-4P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
ho')hM_?Daniel Mach <dmach@redhat.com> - 1.0.25-8Rk- Mass rebuild 2013-12-27lmoMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-7Q@- fix support for aarch64, another part (#969831)^mSMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-6QR@- fix support for aarch64 (#925887)Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.25-5Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.25-4P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild's]Michal Hlavinka <mhlavink@redhat.com> - 1.0.25-12.1aF- a crafted wav file could cause heap buffer overflow that allowed an arbitrary code execution(#1985024)o+Michal Hlavinka <mhlavink@redhat.com> - 1.0.25-12^h- fix CVE-2018-19662 - buffer over-read in the function i2alaw_array (#1673086)
)M!Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.25-4P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild' s]Michal Hlavinka <mhlavink@redhat.com> - 1.0.25-12.1aF- a crafted wav file could cause heap buffer overflow that allowed an arbitrary code execution(#1985024)o+Michal Hlavinka <mhlavink@redhat.com> - 1.0.25-12^h- fix CVE-2018-19662 - buffer over-read in the function i2alaw_array (#1673086)oGMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-11])- fix CVE-2018-13139 - stack-based buffer overflow in sndfile-deinterleave utility (#1598577)mPeter Robinson <pbrobinson@redhat.com> 1.0.25-10S- Generic 32/64 bit platform detection - fix ppc64le build (#1126140)M_?Daniel Mach <dmach@redhat.com> - 1.0.25-9RU- Mass rebuild 2014-01-24
:dAj:)o+Michal Hlavinka <mhlavink@redhat.com> - 1.0.25-12^h- fix CVE-2018-19662 - buffer over-read in the function i2alaw_array (#1673086)(oGMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-11])- fix CVE-2018-13139 - stack-based buffer overflow in sndfile-deinterleave utility (#1598577)'mPeter Robinson <pbrobinson@redhat.com> 1.0.25-10S- Generic 32/64 bit platform detection - fix ppc64le build (#1126140)M&_?Daniel Mach <dmach@redhat.com> - 1.0.25-9RU- Mass rebuild 2014-01-24M%_?Daniel Mach <dmach@redhat.com> - 1.0.25-8Rk- Mass rebuild 2013-12-27l$moMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-7Q@- fix support for aarch64, another part (#969831)^#mSMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-6QR@- fix support for aarch64 (#925887)"Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.25-5Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
"TJ"1mPeter Robinson <pbrobinson@redhat.com> 1.0.25-10S- Generic 32/64 bit platform detection - fix ppc64le build (#1126140)M0_?Daniel Mach <dmach@redhat.com> - 1.0.25-9RU- Mass rebuild 2014-01-24M/_?Daniel Mach <dmach@redhat.com> - 1.0.25-8Rk- Mass rebuild 2013-12-27l.moMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-7Q@- fix support for aarch64, another part (#969831)^-mSMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-6QR@- fix support for aarch64 (#925887),Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.25-5Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild+Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.25-4P- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild'*s]Michal Hlavinka <mhlavink@redhat.com> - 1.0.25-12.1aF- a crafted wav file could cause heap buffer overflow that allowed an arbitrary code execution(#1985024)
a$ 7]-Kamil Dudka <kdudka@redhat.com> 1.4.3-10UlI@- check length of data extracted from the SSH_MSG_KEXINIT packet (CVE-2015-1782)/6[Kamil Dudka <kdudka@redhat.com> 1.4.3-9UH- curl consumes too much memory during scp download (#1080459)
- prevent a not-connected agent from closing STDIN (#1147717)L5]?Daniel Mach <dmach@redhat.com> - 1.4.3-8RU- Mass rebuild 2014-01-24'4s]Michal Hlavinka <mhlavink@redhat.com> - 1.0.25-12.1aF- a crafted wav file could cause heap buffer overflow that allowed an arbitrary code execution(#1985024)3o+Michal Hlavinka <mhlavink@redhat.com> - 1.0.25-12^h- fix CVE-2018-19662 - buffer over-read in the function i2alaw_array (#1673086)2oGMichal Hlavinka <mhlavink@redhat.com> - 1.0.25-11])- fix CVE-2018-13139 - stack-based buffer overflow in sndfile-deinterleave utility (#1598577)
z~zN:[EKamil Dudka <kdudka@redhat.com> 1.8.0-1[H- rebase to 1.8.0 (#1592784)-9]Kamil Dudka <kdudka@redhat.com> 1.4.3-12YA@- session: avoid printing misleading debug messages (#1503294)
- scp: send valid commands for remote execution (#1489733)~8]!Kamil Dudka <kdudka@redhat.com> 1.4.3-11V- use secrects of the appropriate length in Diffie-Hellman (CVE-2016-0787)
88x=_Kamil Dudka <kdudka@redhat.com> - 1.8.0-4]{@- fix integer overflow in SSH_MSG_DISCONNECT logic (CVE-2019-17498)e<[sKamil Dudka <kdudka@redhat.com> 1.8.0-3\+@- sanitize public header file (detected by rpmdiff)^;[cKamil Dudka <kdudka@redhat.com> 1.8.0-2\- fix integer overflow in keyboard interactive handling that allows out-of-bounds writes (CVE-2019-3863)
- fix out-of-bounds memory comparison with specially crafted message channel request (CVE-2019-3862)
- fix out-of-bounds reads with specially crafted SSH packets (CVE-2019-3861)
- fix zero-byte allocation in SFTP packet processing resulting in out-of-bounds read (CVE-2019-3858)
- fix integer overflow in SSH packet processing channel resulting in out of bounds write (CVE-2019-3857)
- fix integer overflow in keyboard interactive handling resulting in out of bounds write (CVE-2019-3856)
- fix integer overflow in transport read resulting in out of bounds write (CVE-2019-3855)
x;|xND[EKamil Dudka <kdudka@redhat.com> 1.8.0-1[H- rebase to 1.8.0 (#1592784)-C]Kamil Dudka <kdudka@redhat.com> 1.4.3-12YA@- session: avoid printing misleading debug messages (#1503294)
- scp: send valid commands for remote execution (#1489733)~B]!Kamil Dudka <kdudka@redhat.com> 1.4.3-11V- use secrects of the appropriate length in Diffie-Hellman (CVE-2016-0787)A]-Kamil Dudka <kdudka@redhat.com> 1.4.3-10UlI@- check length of data extracted from the SSH_MSG_KEXINIT packet (CVE-2015-1782)/@[Kamil Dudka <kdudka@redhat.com> 1.4.3-9UH- curl consumes too much memory during scp download (#1080459)
- prevent a not-connected agent from closing STDIN (#1147717)L?]?Daniel Mach <dmach@redhat.com> - 1.4.3-8RU- Mass rebuild 2014-01-24q>woTripp Waldrop <trwaldro@redhat.com> - 1.8.0-4.el7_9.1e
- fix use-of-uninitialized-value (CVE-2020-22218)
88xG_Kamil Dudka <kdudka@redhat.com> - 1.8.0-4]{@- fix integer overflow in SSH_MSG_DISCONNECT logic (CVE-2019-17498)eF[sKamil Dudka <kdudka@redhat.com> 1.8.0-3\+@- sanitize public header file (detected by rpmdiff)^E[cKamil Dudka <kdudka@redhat.com> 1.8.0-2\- fix integer overflow in keyboard interactive handling that allows out-of-bounds writes (CVE-2019-3863)
- fix out-of-bounds memory comparison with specially crafted message channel request (CVE-2019-3862)
- fix out-of-bounds reads with specially crafted SSH packets (CVE-2019-3861)
- fix zero-byte allocation in SFTP packet processing resulting in out-of-bounds read (CVE-2019-3858)
- fix integer overflow in SSH packet processing channel resulting in out of bounds write (CVE-2019-3857)
- fix integer overflow in keyboard interactive handling resulting in out of bounds write (CVE-2019-3856)
- fix integer overflow in transport read resulting in out of bounds write (CVE-2019-3855)
x;|xNN[EKamil Dudka <kdudka@redhat.com> 1.8.0-1[H- rebase to 1.8.0 (#1592784)-M]Kamil Dudka <kdudka@redhat.com> 1.4.3-12YA@- session: avoid printing misleading debug messages (#1503294)
- scp: send valid commands for remote execution (#1489733)~L]!Kamil Dudka <kdudka@redhat.com> 1.4.3-11V- use secrects of the appropriate length in Diffie-Hellman (CVE-2016-0787)K]-Kamil Dudka <kdudka@redhat.com> 1.4.3-10UlI@- check length of data extracted from the SSH_MSG_KEXINIT packet (CVE-2015-1782)/J[Kamil Dudka <kdudka@redhat.com> 1.4.3-9UH- curl consumes too much memory during scp download (#1080459)
- prevent a not-connected agent from closing STDIN (#1147717)LI]?Daniel Mach <dmach@redhat.com> - 1.4.3-8RU- Mass rebuild 2014-01-24qHwoTripp Waldrop <trwaldro@redhat.com> - 1.8.0-4.el7_9.1e
- fix use-of-uninitialized-value (CVE-2020-22218)
88xQ_Kamil Dudka <kdudka@redhat.com> - 1.8.0-4]{@- fix integer overflow in SSH_MSG_DISCONNECT logic (CVE-2019-17498)eP[sKamil Dudka <kdudka@redhat.com> 1.8.0-3\+@- sanitize public header file (detected by rpmdiff)^O[cKamil Dudka <kdudka@redhat.com> 1.8.0-2\- fix integer overflow in keyboard interactive handling that allows out-of-bounds writes (CVE-2019-3863)
- fix out-of-bounds memory comparison with specially crafted message channel request (CVE-2019-3862)
- fix out-of-bounds reads with specially crafted SSH packets (CVE-2019-3861)
- fix zero-byte allocation in SFTP packet processing resulting in out-of-bounds read (CVE-2019-3858)
- fix integer overflow in SSH packet processing channel resulting in out of bounds write (CVE-2019-3857)
- fix integer overflow in keyboard interactive handling resulting in out of bounds write (CVE-2019-3856)
- fix integer overflow in transport read resulting in out of bounds write (CVE-2019-3855)
x;|xNX[EKamil Dudka <kdudka@redhat.com> 1.8.0-1[H- rebase to 1.8.0 (#1592784)-W]Kamil Dudka <kdudka@redhat.com> 1.4.3-12YA@- session: avoid printing misleading debug messages (#1503294)
- scp: send valid commands for remote execution (#1489733)~V]!Kamil Dudka <kdudka@redhat.com> 1.4.3-11V- use secrects of the appropriate length in Diffie-Hellman (CVE-2016-0787)U]-Kamil Dudka <kdudka@redhat.com> 1.4.3-10UlI@- check length of data extracted from the SSH_MSG_KEXINIT packet (CVE-2015-1782)/T[Kamil Dudka <kdudka@redhat.com> 1.4.3-9UH- curl consumes too much memory during scp download (#1080459)
- prevent a not-connected agent from closing STDIN (#1147717)LS]?Daniel Mach <dmach@redhat.com> - 1.4.3-8RU- Mass rebuild 2014-01-24qRwoTripp Waldrop <trwaldro@redhat.com> - 1.8.0-4.el7_9.1e
- fix use-of-uninitialized-value (CVE-2020-22218)

er+V:eD	
f595ada1902e66bf4b5ae1c8ad3bf1f1092dee59bd392f2519b518dd24fc8e33D
eb952f256def8d9b5c0ecaab67593927376bd7ec33819298399c3542e974f47bD
3ab460e6bd274b4d17b8de62c56e1c66dc26fda6159f4e9f57be04e8bb94bc1aD
2719ebeaea38face0d4ce2a92221526737bef4b1a797d1c4a93a640ef5251600D
a271a288a9e5d486a7d0633c7bc2cacdc437a5653257949d7aea3b6090eebd74D
ca1ec435ed2ce96fee64276f36654333806f220fe770817ae10d14688f42be20D
576b6cc00210001f9cced4b7f0a9cce611a7ec4e4294bb24f514f685685d994dD
e0a695f230a608e0bfdeba85a6146080546349b0d23836b272a5c44012b9fa09D
5acff1ca859e33437e5bba88b3f8e1335360828b81bf51c413327aa84347242dD
2ecaf9207562dd4f4767c7e478f1e8c603b1b90864ef3d2b0d210d4f60a1d9edD
f5d9885773ed21397aa08232737d51af6803c1358395a2168b6820ce496d927fD~
b86b07e982db65a9de92fc9c7aa93f0d88b01391a29985f36ccf1ef735a3d904D}
7a692eca430d652a3cc0c216034cbd84562dbf07b12cc646e4c6e4d5ab7c2fe7x0806<BHNTZ`flrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|%<%Q%f%z,%9%F%S%͘`%m%z&& &5!&I.&^;&rH&U&b&͙o&|&	'='#'͚0(=(\J(W(d).q)t~)**M%*2*כ?+L+@Y+Uf+s++ڜ
,,3',`4,A,N,ٜ[,h-
u-"-7-m-)-6-C-ǝP-؝]-j-w..ž./+/08/FE/aR/|_/l/y/ß/ҟ/ /-0:0G00T0Da0Tn0c{000Ԡ"0/1<1I19V1Pc1kp1}1
11$2	12,>2PK2uX2e2r233~3&4349@4VM4ۢZ5cg5t6u677(758B8$O88\8Ji8\v8o8
88x[_Kamil Dudka <kdudka@redhat.com> - 1.8.0-4]{@- fix integer overflow in SSH_MSG_DISCONNECT logic (CVE-2019-17498)eZ[sKamil Dudka <kdudka@redhat.com> 1.8.0-3\+@- sanitize public header file (detected by rpmdiff)^Y[cKamil Dudka <kdudka@redhat.com> 1.8.0-2\- fix integer overflow in keyboard interactive handling that allows out-of-bounds writes (CVE-2019-3863)
- fix out-of-bounds memory comparison with specially crafted message channel request (CVE-2019-3862)
- fix out-of-bounds reads with specially crafted SSH packets (CVE-2019-3861)
- fix zero-byte allocation in SFTP packet processing resulting in out-of-bounds read (CVE-2019-3858)
- fix integer overflow in SSH packet processing channel resulting in out of bounds write (CVE-2019-3857)
- fix integer overflow in keyboard interactive handling resulting in out of bounds write (CVE-2019-3856)
- fix integer overflow in transport read resulting in out of bounds write (CVE-2019-3855)
x;|xNb[EKamil Dudka <kdudka@redhat.com> 1.8.0-1[H- rebase to 1.8.0 (#1592784)-a]Kamil Dudka <kdudka@redhat.com> 1.4.3-12YA@- session: avoid printing misleading debug messages (#1503294)
- scp: send valid commands for remote execution (#1489733)~`]!Kamil Dudka <kdudka@redhat.com> 1.4.3-11V- use secrects of the appropriate length in Diffie-Hellman (CVE-2016-0787)_]-Kamil Dudka <kdudka@redhat.com> 1.4.3-10UlI@- check length of data extracted from the SSH_MSG_KEXINIT packet (CVE-2015-1782)/^[Kamil Dudka <kdudka@redhat.com> 1.4.3-9UH- curl consumes too much memory during scp download (#1080459)
- prevent a not-connected agent from closing STDIN (#1147717)L]]?Daniel Mach <dmach@redhat.com> - 1.4.3-8RU- Mass rebuild 2014-01-24q\woTripp Waldrop <trwaldro@redhat.com> - 1.8.0-4.el7_9.1e
- fix use-of-uninitialized-value (CVE-2020-22218)
88xe_Kamil Dudka <kdudka@redhat.com> - 1.8.0-4]{@- fix integer overflow in SSH_MSG_DISCONNECT logic (CVE-2019-17498)ed[sKamil Dudka <kdudka@redhat.com> 1.8.0-3\+@- sanitize public header file (detected by rpmdiff)^c[cKamil Dudka <kdudka@redhat.com> 1.8.0-2\- fix integer overflow in keyboard interactive handling that allows out-of-bounds writes (CVE-2019-3863)
- fix out-of-bounds memory comparison with specially crafted message channel request (CVE-2019-3862)
- fix out-of-bounds reads with specially crafted SSH packets (CVE-2019-3861)
- fix zero-byte allocation in SFTP packet processing resulting in out-of-bounds read (CVE-2019-3858)
- fix integer overflow in SSH packet processing channel resulting in out of bounds write (CVE-2019-3857)
- fix integer overflow in keyboard interactive handling resulting in out of bounds write (CVE-2019-3856)
- fix integer overflow in transport read resulting in out of bounds write (CVE-2019-3855)
2
ho'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTgo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]qfwoTripp Waldrop <trwaldro@redhat.com> - 1.8.0-4.el7_9.1e
- fix use-of-uninitialized-value (CVE-2020-22218)
2kowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|joAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tio{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YloEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AmoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-nomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
qo'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetpqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downooAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2tow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|so
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tro{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YuoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Avo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-wom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?zq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)yqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downxo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2}ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target||o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t{o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y~oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-	om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down
o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h
qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm !qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]| q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
A#o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]="q
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-$om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?'q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)&qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down%o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm *qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|)q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h(qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.-a}
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD,}

Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=+q
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tt0a	
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)/as
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).y.a
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
P2g;
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_1c]
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux5g
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p4g{
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)3g'
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-8is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}7i
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..6gw
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT;o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c:k]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex9i	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|>o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t=o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
<o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2?ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y@oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
NxBi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-Ais
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
TDo;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cCk]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|Go
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tFo{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Eo'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2How
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YIoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xKi	
	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAJo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
TMo;
	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cLk]
	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|Po
	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tOo{
	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
No'
	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2Qow
	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YRoE
	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ASo
	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Tom
	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]

er+V:eD
11b4c218357ae653cc94b8f934d6cb161e9887b9f18ebd5184628d644e2ec02fD
95c0d1a3ba0c09becb41fdca9e7a82ee4f169e2c6bd810f7883f9414d007e4c3D
e41dee63d125e890be93881d99ae457aaebbcaa795e8a90597fa3babf9dd5a67D
ca7df206b32aa8f478b9a3751e1c7049c9f5302ca5417f2e0531f4bacadcf5dcD
f6b96a84dad57397afdccb0873c1927936c50a3c80b0b8e632763ea46c6bd495D
33cb91f162bf1272cbef0f8ac3f812a3af2b586d5be6e77a0a773db69590044bD
94640be31162fbff22a0573cb0d7212f9516ed92f67a3553e720fa125d332b1fD
7d44f440dcfa707ff7ed627fb7b3fb3254742dcf60373b386105ea09f4e14293D
8d73e99ddd2060604e1a2bddc4b10b1b92cf6f81b0d2a05a103cebd6d052a316D

4846ff9c3501bdbb24a3b5c855a6e385c608a7387446302cb070e7c305b0a087D
f868ce40374cc82b06433374fe4cf3bba215a30f1d27cc97037f1c1d746e0c33D
e668a6070cd6a22b4de750baa84e146e8e064e1a05849a958600f9b2d6b51c0dD

905b3f686bda411e8b1469cccabec8ed3ae99a60153880597dd656cabc81a501
tWo{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Vo'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTUo;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2Yow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Xo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YZoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A[o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-\om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
|T_o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]^qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down]o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|bo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tao{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
`o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2cow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YdoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Aeo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-fom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
io'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targethqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downgo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2low
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|ko
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tjo{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YmoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]bR'RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{' '!'"'#!'$#'%$'&'''*'(-')0'*2'+5',8'-;'.>'/?'0@'1B'2D'3G'4H'5I'6K'7M'8P'9Q':R';S'<T'>W'?Y'@Z'A['B\'C_'Db'Ec'Fd'Ge'Hf'Ii'Jl'Km'Mn'No'Or'Pu'Qv'Rw'Sx'Ty'U|'V'W'X'Y'Z'['\	']
'^'_'`'a'b'c'd'e'f'g'h'i'j'k"'l%'m&'n''o('p+'q.'r/'s0't1'u2'v5'w8'x9'y:'z;'{>'|A'}B'~C'D'E'H'K'M
::Ano
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-oom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?rq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downpo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|uo

Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tto{

Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
so'

Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2vow

Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YwoE

Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Axo

Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-yom

Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?|q9

Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains){qO

Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downzo

Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|~o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t}o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)hqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2	ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y
oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down
o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))|q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?"q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)!qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2%ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|$q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h#qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y&oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A'o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-(om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?+q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)*qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down)o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm .qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|-q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h,qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2/ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y0oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A1o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-2om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?5q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)4qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down3o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 8qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|7q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h6qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y9oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A:o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-;om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?>q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)=qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down<o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm AqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|@q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h?qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
=Bq
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
""YCoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ADo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Eom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Hq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)GqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downFo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm KqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Jq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hIqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
AMo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=Lq
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-Nom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Qq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)PqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downOo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm TqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Sq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hRqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
//AWo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]DV}

Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=Uq
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]

er+V:eD#
820ba4ad8ead8e86f08c52f1683fb89e78daca198b5a3d010ccbda6eeb6afeedD"
b29691f0851773e177dbf1022fdd7407ebdb0329a1fb62e66ecd797a49de36deD!
b16a84b46233f40caa0d30fca524f23408cdf7301cecddbe17cc7b23be9336c9D 
d2d65f2dde15fdba0abf08f0eba0a75c42ca7a41d64da706060132398e03a472D
7813e68c7a683514d7f3a5da05d9e10253ff77a5a4efb99321ccd3176db9dd97D
fb633afcbec86339bf68947e27f45d0baba732bf9a5f35de6dd47472c02091a8D
6323899c2cf49904753b9b4050225498b3bce1cc5ae2893977e1201c90220e64D
2f0b2cb6eb70e8325b1e26082c9f953fa3bbe383a04e9bad22161bf475931cd5D
3119a1efea41b19b200e56173924d777ef2edb1f4cb0722d9c9d99b5001de9b2D
6cd37a431fbb8cf1ad0ee95e2fbef2ca533dd95e28fed9e9845a74acd29cccbeD
5005ebdd55f4e6e5ffc6888045041951f173c1227a635bb776b918e888efdfbaD
878c505e878a659e3fe83b051ba1014e223ab1130afed6d39765703c451945b3D
41f4c18963dcef2f45ef879ee1b029b4d4e655031847de4f3052176ca15d7892
NN-Xom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?[q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)ZqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downYo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm ^qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|]q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h\qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.aa}
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD`}

Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=_q
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Ttda	
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)cas
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yba
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pfg;
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_ec]
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxig
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))phg{
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)gg'
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
yla
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..ka}
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen.jgw
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
Rtna	
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)mas
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
Ppg;
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_oc]
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxsg
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))prg{
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)qg'
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-vis
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}ui
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..tgw
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTyo;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cxk]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexwi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw||o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t{o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
zo'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2}ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y~oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Lxi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}i
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
To;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nx
i	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-	is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
To;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)

o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:-is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
CCTo;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
To;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|"o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t!o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
 o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2#ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y$oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A%o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
Nx'i	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-&om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
T)o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c(k]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|,o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t+o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
*o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetbR'RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{'Q'T'W'X'['^'a'd'f'i'l'n'p's'v'y'|'}'~''''''
''''''''''''"'#'$'%''')','-'.'/'0'3'5'6'7'8';'>'?'@'A'B'E'‚H'ÂI'ĂJ'łK'ƂN'ǂQ'ȂR'ɂS'ʂT'˂U'̂X'΂['ς\'Ђ]'т^'҂a'ӂd'Ԃe'Ղf'ւg'ׂh'؂k'قn'ڂo'ۂp'܂q'݂t'ނw'߂x'y'ႃz'₃{'ゃ~'䂄'傄'悄'炄'肄'還

2-ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y.oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A/o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-0om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
t3o{
 Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
2o'
 Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetT1o;
 Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
25ow
 Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|4o
 Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""Y6oE
 Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A7o
 Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-8om
 Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
|T;o;
!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]:qO
 Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down9o
 Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|>o
!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t=o{
!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
<o'
!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2?ow
!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y@oE
!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AAo
!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Bom
!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
Eo'
"Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetDqO
!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downCo
!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2How
"Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Go
"Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tFo{
"Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YIoE
"Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AJo
"Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Kom
"Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Nq9
"Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)MqO
"Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downLo
"Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|Qo
#Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tPo{
#Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Oo'
#Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2Row
#Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YSoE
#Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ATo
#Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Uom
#Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Xq9
#Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)WqO
#Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downVo
#Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]

er+V:eD0
232b24511b4ca567b436255eb6fe7f9fe68d66f2514a25334fc5cc4097d48238D/
d7bfd9d26185d5c9bbb6d7f10f8dfc69f1ef41dccd5f719b912299bbc532252fD.
f21d363926810e31889a7fa98205382c0b8de58aa4f45928c27d9e67046b9482D-
d9a010b778f886239f2f727be22f6e054b2c499ecf8ad2846b7837ce3764547bD,
8faaf8f128a420775ca80ce1a715e9558ae61ebfead1106052e080d3192d7162D+
ef8ede3695ebb9829a9403065f243ab8acef8f14316aabcc9b26c4255ee93bbeD*
f6b017a1e5d505f7794845950a247b12ba961e8bd6ea366098a0ca5e83e7acecD)
cb1bac17d8c7b1c7813cfbc4a050c0bd153b06a08874a369c55a1597e25d5a52D(
b181a29e8b480e5cdb16c69bd46f0085d124c0cf817f9faa339ebe447295beabD'
6123edb3ca2fb4af89e0aafdcc06a518dc2adf261f69c5208d7e0dcf72996887D&
2031956532e4c86af01a9e7885660b200d3432a40e8aa1938e571e99424f7b1dD%
13c6b2ac5e5019a9debc589efedb039c95513584922436476bdc65f0fa84b5e8D$
b9cdab2c69719f6bbf7b533475859fb6f47e37976e9c3f8dc8235fb67f98c995
2[ow
$Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Zo
$Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tYo{
$Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y\oE
$Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A]o
$Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-^om
$Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?aq9
$Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)`qO
$Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down_o
$Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|do
%Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tco{
%Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)hbqa
$Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2eow
%Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YfoE
%Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ago
%Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-hom
%Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?kq9
%Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)jqO
%Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downio
%Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2now
&Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|mo
&Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hlqa
%Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YooE
&Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Apo
&Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-qom
&Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?tq9
&Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)sqO
&Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downro
&Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|wo
'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))|vq	
&Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]huqa
&Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2xow
'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YyoE
'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Azo
'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-{om
'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?~q9
'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)}qO
'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down|o
'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2ow
(Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|q	
'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoE
(Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
(Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
(Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
(Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
(Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
(Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 
qQ
(Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|	q	
(Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
(Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2ow
)Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
)Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A
o
)Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
)Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
)Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
)Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
)Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQ
)Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	
)Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
)Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoE
*Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
*Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
*Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
*Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
*Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
*Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQ
*Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	
*Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
*Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
=q
*Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
""YoE
+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A o
+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-!om
+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?$q9
+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)#qO
+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down"o
+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 'qQ
+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|&q	
+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h%qa
+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
A)o
,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=(q
+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-*om
,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?-q9
,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains),qO
,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down+o
,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 0qQ
,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|/q	
,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h.qa
,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
//A3o
-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]D2}

,Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=1q
,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-4om
-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?7q9
-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)6qO
-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down5o
-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm :qQ
-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|9q	
-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h8qa
-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.=a}
.Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD<}

-Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=;q
-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tt@a	
.Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)?as
.Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).y>a
.Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
PBg;
.Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_Ac]
.Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxEg
.Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pDg{
.Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)Cg'
.Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
yHa
/Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..Ga}
/Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen.Fgw
.Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
RtJa	
/Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)Ias
/Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
PLg;
/Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_Kc]
/Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxOg
/Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pNg{
/Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)Mg'
/Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-Ris
0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}Qi
0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..Pgw
/Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTUo;
0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cTk]
0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is FalsexSi	
0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|Xo
0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tWo{
0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Vo'
0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2Yow
0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YZoE
0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]

er+V:eD=
445c2d91fe49788941d409448267b19e014c9f6354238fdee408aa1d585cfd01D<
496ee19b0bed3aa542d3fe7473b517f0eca004f3306333e343b200c30cdad5c7D;
a28c0efdadc06bf5a7278211745c542df980210b991db1532357b48d09b0e233D:
4eb469f0ca30f89921cee1b76ff6dd7b1c0025256c9be1d13e2d2c4dfbb1b927D9
dcac6f9cfc56c02c04c7a838dc97614858baaa53286986731947f8d1e57c98acD8
932effd782396fd543e9119dfb730e5009b85100c4e34c453d8c4079975172a7D7
a06df499751c88597c0ff2c9e3571f888ef5f4c900179b21dd22799ec89b624aD6
3c2c5a9be0e4c30b02e5553db78d0a3f434bf544273422faeab125baf392165eD5
5bba5c2f7eb1e8689b410449cc9ad15917af4897477ab8f44972e6e8c0298324D4
0ed0c68541bccf9732065a361a46692699a4a2ce01c4a502809c2c7c16a1d213D3
88ac00911754d4623eae65cfa475ed5082d7d2b0f2ed678b1b27991079abf58cD2
8e8d757181381eff83e8b40078f2dd69e053551b72a94cd397d0ddcad18a61eeD1
2d829e46da9b44d01cec2e07cdfb10a09d198cb3c3c5b5bb26d4f5db8f2a7853
Lx]i	
1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-\is
1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}[i
1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
T_o;
1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c^k]
1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|bo
1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tao{
1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
`o'
1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2cow
1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YdoE
1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nxfi	
2Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-eis
2Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).bR(ORY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{'낄'삄
'킄'''''''''' '!'$''')'*'-'0'3(4(7(:(=(@(B(E(H(J(	L(
O(R(U(
X(Y(Z(](_(b(c(d(f(h(k(l(m(o(r(u(v( w(!y("{(#~($(%(&('((()(*	(+
(,(-(.(/(0(1(2(3(4(5(6(7(8(9!(:$(;%(<&(='(>*(?-(@.(A/(B0(C1(D4(E7(F8(G9(H:(I=(J@(KA(LB(MC(ND
Tho;
2Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cgk]
2Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|ko
2Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tjo{
2Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
io'
2Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2low
2Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YmoE
2Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:-ois
3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).Ano
2Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
CCTro;
3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cqk]
3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexpi	
3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|uo
3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tto{
3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
so'
3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2vow
3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YwoE
3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xyi	
4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAxo
3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
T{o;
4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]czk]
4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|~o
4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t}o{
4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
|o'
4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
Nxi	
5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-om
4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
To;
5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|o
5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2	ow
5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y
oE
5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
to{
6Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
6Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetT
o;
6Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2ow
6Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|o
6Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YoE
6Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
6Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
6Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
|To;
7Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]qO
6Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
6Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|o
7Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
7Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
7Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
7Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
7Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
7Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
7Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
!o'
8Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target qO
7Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
7Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2$ow
8Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|#o
8Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t"o{
8Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y%oE
8Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A&o
8Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-'om
8Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?*q9
8Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains))qO
8Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down(o
8Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|-o
9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t,o{
9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
+o'
9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2.ow
9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y/oE
9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A0o
9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-1om
9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?4q9
9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)3qO
9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down2o
9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
27ow
:Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|6o
:Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t5o{
:Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y8oE
:Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A9o
:Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-:om
:Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?=q9
:Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)<qO
:Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down;o
:Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|@o
;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t?o{
;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)h>qa
:Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2Aow
;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YBoE
;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ACo
;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Dom
;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Gq9
;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)FqO
;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downEo
;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2Jow
<Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Io
<Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hHqa
;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YKoE
<Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ALo
<Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Mom
<Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Pq9
<Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)OqO
<Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downNo
<Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|So
=Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))|Rq	
<Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hQqa
<Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2Tow
=Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YUoE
=Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AVo
=Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Wom
=Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Zq9
=Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)YqO
=Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downXo
=Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2]ow
>Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|\q	
=Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h[qa
=Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update

er+V:eDJ
168bff58938382034bb054ff55ce6aa5b0976326389d6260fbc85840fe154bd8DI
ca86ae6d34c40dee72606cee1e52e0dc9ab807fce4ecf71c5fbd47ec447bfbc9DH
820151304111db2bd87d6e5ae6446b11a958a081a44feb85b88cf0ec6c550aedDG
7744a295fd69e27c223298b284d7c8853f441d6b08e8333049ec0bbc9e32287cDF
2f36d8b2e3ff73bf61ed280b55eab167ae99178b23f186fbf6d4721158eb5a5aDE
ce07814a85fabc6115195714ab5d8670ba930a5369258eadf917f899881058b0DD
af9cf3acff909c4085ae929a3f5506bf2bed9dda37507802c11ad79e8d903390DC
263b13ff1007ce0f1a2b919dcc679eaee72fb8105b37c94235f23c5f710eb42dDB
ee029bb52291786cac00074d77fa338a3cdf2968607a5e85ffd05a69b46ebcddDA
9c0edeaeecaf19ea413db53d573ef306f6f69adbc4a87d9e0c522e0a6385b8d6D@
ccd6b1145000587fc43fbba493221eba1716a9183d64796c8e42beecbbad5afcD?
12944ec5810169ac73652bcbd5cc441c1d5a084cd3877df22452e21f63a8b978D>
94e1c0f560a6748a67411c8d4a86f1e3f8f7528cf1614061076e85844e120007
""Y^oE
>Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A_o
>Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-`om
>Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?cq9
>Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)bqO
>Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downao
>Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm fqQ
>Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|eq	
>Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hdqa
>Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2gow
?Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YhoE
?Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Aio
?Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-jom
?Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?mq9
?Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)lqO
?Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downko
?Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm pqQ
?Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|oq	
?Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hnqa
?Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YqoE
@Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Aro
@Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-som
@Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?vq9
@Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)uqO
@Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downto
@Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm yqQ
@Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|xq	
@Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hwqa
@Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
=zq
@Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
""Y{oE
AAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A|o
AAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-}om
AAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
AAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
AAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down~o
AAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQ
AAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	
AAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
AAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
Ao
BAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=q
AAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-om
BAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?	q9
BAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
BAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
BAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQ
BAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	
BAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h
qa
BAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
//Ao
CAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]D}

BEduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=
q
BAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-om
CAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
CAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
CAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
CAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQ
CAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	
CAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
CAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.a}
DAlexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD}

CEduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=q
CAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]bR(RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{(PJ(QK(RL(SM(TP(US(VT(WU(XV(YW(ZZ([](]^(^_(_`(`c(af(bg(ch(di(ej(fm(gp(hq(ir(js(kv(ly(mz(n{(o|(p}(q(r(s(t(u	(v(w(x(y(z({(}(~(!($(&(((+(.(1(4(5(6(9(;(>(?(@(B(D(G(H(I(K(N(Q(R(S(U(W(Z([(\(](_(a(d(e(f(g(h(k(m(n(o(p(s(v(w(x(y(z(}(((
Tta	
DAlexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)as
DAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).ya
DAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pg;
DAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_c]
DAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux!g
DAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p g{
DAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)g'
DAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
y$a
EAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..#a}
EAlexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen."gw
DAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
Rt&a	
EAlexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)%as
EAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
P(g;
EAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_'c]
EAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux+g
EAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p*g{
EAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete))g'
EAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-.is
FAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}-i
FAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..,gw
EAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT1o;
FAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c0k]
FAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex/i	
FAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|4o
FAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t3o{
FAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
2o'
FAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
25ow
FAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y6oE
FAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Lx9i	
GAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-8is
GAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}7i
GAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
T;o;
GAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c:k]
GAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|>o
GAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t=o{
GAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
<o'
GAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2?ow
GAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y@oE
GAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
NxBi	
HAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-Ais
HAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
TDo;
HAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cCk]
HAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|Go
HAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tFo{
HAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Eo'
HAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2How
HAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YIoE
HAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:-Kis
IAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).AJo
HAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
CCTNo;
IAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cMk]
IAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is FalsexLi	
IAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|Qo
IAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tPo{
IAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Oo'
IAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2Row
IAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YSoE
IAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xUi	
JAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationATo
IAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
TWo;
JAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cVk]
JAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|Zo
JAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tYo{
JAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Xo'
JAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2[ow
JAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y\oE
JAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A]o
JAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
Nx_i	
KAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-^om
JAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]

er+V:eDW
b31b9cf432a59766c6b5f9c8b9dfb6791a76a37c136babc439b16abef4d2ae11DV
bc42b202db19ddd70b5c8192eb30b148f6a3229d05aa0eaa7757cdfab321184eDU
a68751d71e847954a2206eba95e8947850efa80cb938416951ff10e842a23580DT
7c83aac8738db8a2cfb8c54ae4ea010d008959520d9078ac174ef677f712c83dDS
afa6cc1c77134d47d632ccdb524207f5d3993077790a943141d1dbd8cf0b211cDR
cbca2af9e05f80103f7d418c99cb1e8808a0b5b2aeb348a19e6ec009ccfe7972DQ
bd426d0e03bbd097435638bf127e0f1c2cd5e3fbaa1161378173491fadba6adbDP
08eccef6a2ce6a06f95c7ad30f3fdd7db91e89b3991bbe05cc786dee1ccc9074DO
823e82a094d45f0cabd438920e6e33584712ea5e4c9e767ad9d3d1a34b4ee0e2DN
ace47954cb2fb4fba9ee4f0144a123a7fcd2343db0c8f16037bd3439f3b38736DM
f7bd069d04d994e785e1883f97be7c9af76091600cb13d99b634f878bb79c5e0DL
21c9f734ac2660b9ca8602966521796728c6e3830a5aa75fda5d6c6674d2f5d3DK
3990236c7fd1972169692ed6297dee2d25331fe73bf38ac66bd45bb990ed139a
Tao;
KAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c`k]
KAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|do
KAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tco{
KAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
bo'
KAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2eow
KAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YfoE
KAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ago
KAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-hom
KAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
tko{
LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
jo'
LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTio;
LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2mow
LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|lo
LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YnoE
LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Aoo
LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-pom
LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
|Tso;
MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]rqO
LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downqo
LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|vo
MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tuo{
MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
to'
MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2wow
MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YxoE
MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ayo
MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-zom
MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
}o'
NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target|qO
MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down{o
MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2ow
NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|o
NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t~o{
NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoE
NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|	o
OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2
ow
OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-
om
OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2ow
PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|o
PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoE
PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|o
QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)hqa
PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2ow
QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN- om
QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?#q9
QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)"qO
QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down!o
QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2&ow
RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|%o
RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))h$qa
QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y'oE
RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A(o
RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-)om
RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?,q9
RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)+qO
RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down*o
RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|/o
SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))|.q	
RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h-qa
RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
20ow
SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y1oE
SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A2o
SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-3om
SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?6q9
SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)5qO
SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down4o
SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[29ow
TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|8q	
SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h7qa
SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y:oE
TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A;o
TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-<om
TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|??q9
TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)>qO
TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down=o
TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm BqQ
TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Aq	
TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h@qa
TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2Cow
UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YDoE
UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AEo
UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Fom
UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Iq9
UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)HqO
UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downGo
UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm LqQ
UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Kq	
UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hJqa
UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YMoE
VAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ANo
VAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]bR)RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{((	(
(((
(((((((‚(Â(Ă(ł(Ƃ (ǂ#(Ȃ&(ɂ'(ʂ((˂)(̂,(͂/(΂0(ς1(Ђ2(т3(҂6(ӂ9(Ԃ:(Ղ;(ւ<(ׂ?(؂B(قC(ڂD(ۂE(܂F(݂I(ނL(߂M(N(₇O(ょR(䂇U(傇V(悇W(炇X(肇Y(邇\(ꂇ_(낇a(킇b(e(h(k(l(o(r(u(x(z(}(((((
(
(()))))))) )#)	$)
%)')*)
-).)/)1)3)6)7)8)9);)=)@)A
NN-Oom
VAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Rq9
VAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)QqO
VAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downPo
VAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm UqQ
VAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Tq	
VAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hSqa
VAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
=Vq
VAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
""YWoE
WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AXo
WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Yom
WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?\q9
WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)[qO
WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downZo
WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm _qQ
WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|^q	
WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h]qa
WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
Aao
XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=`q
WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]

er+V:eDd
e96f88c3dd68cba08085ab79ac4207e040e7c65ade70b55699f2e7ff5fa8e7bfDc
d41f2ba7244ea561f95aae87e10fc0d097ee72ed2f5cf1cb1e7455374f1add83Db
da23c291f94eaf3fa1751e0812449824e582ca5853fa7e71e730f6f1fb2e0327Da
84ff86ac505c0857bbf75916d7ef4b6be65454e5dd5ec6ed67ec662a819c10e0D`
e75e5f7dc4aac557d9b274de60d58b81f3549dd86073ed6505512e434de72884D_
b1e85cc0f0d7b4783c129d2855d494d189e1974a9dfc0cafeac3f27cae0d79deD^
7003e053072c0715532264432024d1fce948f74d5ed2f2cef63aee418dfd47a5D]
5544075a70cc259a73eb5555c11efef72bbad8385da2d376a511efce351ff5dfD\
cc04b6fd7a53d6566cf64cd227d959dc95f522bc3b6e773b8a1346ff987aedd2D[
d4f34dceeada317c1daa9f144ef934ddb2e8268f3b1e5ea56ff174ca96919479DZ
681f16ea3fafb50e4f8583381026ef08759cc8c327b923cb4b822515b1d02144DY
97b86b131c407c89d83051cf1a4f98e0807a3198b30346ee90104748242d3bc2DX
1b9318b477ed42cea383e924a42367b049b54e29451b58ab4f7761a1c26052d4
NN-bom
XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?eq9
XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)dqO
XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downco
XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm hqQ
XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|gq	
XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hfqa
XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
//Ako
YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]Dj}

XEduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=iq
XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-lom
YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?oq9
YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)nqO
YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downmo
YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm rqQ
YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|qq	
YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hpqa
YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.ua}
ZAlexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenDt}

YEduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=sq
YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Ttxa	
ZAlexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)was
ZAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yva
ZAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pzg;
ZAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_yc]
ZAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux}g
ZAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p|g{
ZAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete){g'
ZAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
ya
[Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..a}
[Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen.~gw
ZAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
Rta	
[Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)as
[Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
Pg;
[Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_c]
[Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxg
[Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pg{
[Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)g'
[Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-
is
\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}	i
\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..gw
[Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT
o;
\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexi	
\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|o
\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Lxi	
]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-is
]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}i
]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
To;
]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|o
]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nxi	
^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-is
^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
T o;
^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|#o
^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t"o{
^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
!o'
^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2$ow
^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y%oE
^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:-'is
_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).A&o
^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
CCT*o;
_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c)k]
_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex(i	
_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|-o
_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t,o{
_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
+o'
_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2.ow
_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y/oE
_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:x1i	
`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationA0o
_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
T3o;
`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c2k]
`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|6o
`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t5o{
`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
4o'
`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
27ow
`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y8oE
`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A9o
`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
Nx;i	
aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-:om
`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
T=o;
aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c<k]
aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|@o
aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t?o{
aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
>o'
aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2Aow
aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YBoE
aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ACo
aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Dom
aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
tGo{
bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Fo'
bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTEo;
bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2Iow
bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Ho
bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YJoE
bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AKo
bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Lom
bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
|TOo;
cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]NqO
bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downMo
bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|Ro
cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tQo{
cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Po'
cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2Sow
cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YToE
cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AUo
cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Vom
cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
Yo'
dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetXqO
cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downWo
cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2\ow
dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|[o
dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tZo{
dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y]oE
dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A^o
dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-_om
dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?bq9
dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)aqO
dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down`o
dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]

er+V:eDq
dbdc73fdef9098f3a36034a34baac0fea56523a9d5f32161ee961570387e2ab1Dp
841d060e918275386a6f0807073b7dfbf1d8b8ef4e46c4ac35317a6f61457d8eDo
4aca2e6c6e4faa4ced065ea161be76f436ab64e5f16cd84c5a0378ab451f1d80Dn
dd26f40a18d45abe032d5e12209ca47ece3291fb0c9b2777688d685549c62407Dm
0fcf726d57a4432750417154846f7c22cecf1bd6d6e09cbccc91d48290d7d69fDl
18ff9230e89f660287403152d255b18ab93e778ca6eb16560d9f2a33b716775fDk
a4f562d2bfa43893cbae16d48549de733cb308300b8e00392e586a0a8337ba28Dj
2945d0d59bd61b57919da46f45e6437971f4b5d914e30049df9465e3f9159275Di
5c8c85c382c8ac22f1c5330ee708bcb6604c6ac08bd86bb0cecc265c1123d786Dh
b9f7953bb8ad08f44b13f7946b99015a8a305f7022e1575b7243c15e252d3cfdDg
bc347437d264c256ccfc842e7dd7fc5bfc2649f300c61c63b59dc2676631e404Df
26e499c5c940c85a9dc99a8198b266b67825eeb218071c6b6d0848d7e3ba9b92De
f8321c847bc9b5ba2834eb175db280c4c1ab904ea8bbe5ce080e0e4a7f8e9536
wqxw|eo
eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tdo{
eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
co'
eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2fow
eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YgoE
eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Aho
eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-iom
eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?lq9
eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)kqO
eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downjo
eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2oow
fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|no
fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tmo{
fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YpoE
fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Aqo
fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-rom
fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?uq9
fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)tqO
fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downso
fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|xo
gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))two{
gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)hvqa
fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2yow
gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YzoE
gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A{o
gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-|om
gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)~qO
gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down}o
gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2ow
hAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|o
hAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hqa
gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoE
hAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
hAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
hAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
hAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
hAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
hAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|o
iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))|
q	
hAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h	qa
hAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2ow
iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper targetbR)RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{)C)D)G)I)J) K)!L)"O)#R)$S)%T)&U)'V)(Y))\)*])+^),_)-b)/e)0f)1g)2h)3i)4l)5o)6p)7q)8r)9u):x);y)<z)={)>|)?)@)A)B)C)D)E)F)H
)I)J)K)L)M)N)O)P)Q)R)S )T!)U")V%)W()X))Y*)Z+)[.)\1)]2)^3)_4)`5)a8)b;)c=)d>)eA)fD)gG)hH)iK)jN)kQ)lT)mV)nY)o\)p^)q`)rc)sf)ui)vl)wm)xn)yq)zs){v)|w)}x)~z)|
""Y
oE
iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2ow
jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|q	
iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoE
jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQ
jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	
jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2ow
kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y oE
kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A!o
kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-"om
kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?%q9
kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)$qO
kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down#o
kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm (qQ
kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|'q	
kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h&qa
kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y)oE
lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A*o
lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-+om
lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?.q9
lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)-qO
lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down,o
lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 1qQ
lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|0q	
lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h/qa
lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
=2q
lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
""Y3oE
mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A4o
mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-5om
mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?8q9
mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)7qO
mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down6o
mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm ;qQ
mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|:q	
mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h9qa
mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
A=o
nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=<q
mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN->om
nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Aq9
nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)@qO
nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down?o
nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm DqQ
nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Cq	
nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hBqa
nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
//AGo
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]DF}

nEduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=Eq
nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-Hom
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Kq9
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)JqO
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downIo
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm NqQ
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Mq	
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hLqa
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.Qa}
pAlexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenDP}

oEduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=Oq
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
TtTa	
pAlexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)Sas
pAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yRa
pAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
PVg;
pAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_Uc]
pAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxYg
pAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pXg{
pAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)Wg'
pAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
y\a
qAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..[a}
qAlexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen.Zgw
pAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
Rt^a	
qAlexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)]as
qAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
P`g;
qAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]__c]
qAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxcg
qAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pbg{
qAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)ag'
qAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-fis
rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}ei
rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..dgw
qAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target

er+V:eD~
2ab47339de73a640409073095dc5c6953e2918938b772d47f1402c12c8954584D}
cb8ea18480b29a851f5294a367ac6b15344338149139ef7f7230a7888c960c7dD|
4110581b81ae9c5b81888451ef2d92b364bd02c2919a96ed2f541d4b690b1932D{
d3025de9185bb10743b56de3b1a535e26b438db0b43bb7d1b8859d2681a8a2c4Dz
d31bb4f7fa204fe5abb6eb2d32b3dbf61485358f507f608be3bec49ef46e3e5eDy
5016630a65d39bcfb9fe686d8dda94e2b896afc8b8c41f7c29a6bc5d3305884eDx
40fbdb5955ea06836fc5cd49841d43c8ca177c4a345a3731b7fdcb0e482fcde0Dw
6c6c39f0c94adba5ee8c50460abf33d8b6c2d1741b4e3882ed1436af7ced0d88Dv
eb03c3bd51b0bec375b458b8d72953391f35f59d1ffa7969433da6b1fecf8867Du
55556c4993ccacf2204ccfa733c8e105f1bc1cd4accc50b36960aa8c6a339aeaDt
027f9ce824c240ccb21c3c503958433eb772483c1fe803ce30f44f232c06eaf4Ds
baf17e426a993485d612c72f85e502e6494151b0c2a6581a932bb3bddd9a2d65Dr
a1b2bb66bfc18162bd1422b81f7e29c65df69760c35e15b769b04c93743d3fd9
CCTio;
rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]chk]
rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexgi	
rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|lo
rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tko{
rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
jo'
rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2mow
rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YnoE
rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Lxqi	
sAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-pis
sAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}oi
sAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Tso;
sAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]crk]
sAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|vo
sAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tuo{
sAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
to'
sAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2wow
sAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YxoE
sAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nxzi	
tAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-yis
tAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
T|o;
tAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c{k]
tAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|o
tAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t~o{
tAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
}o'
tAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
tAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
tAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:-is
uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).Ao
tAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
CCTo;
uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexi	
uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|	o
uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2
ow
uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:x
i	
vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAo
uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
To;
vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|o
vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
Nxi	
wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-om
vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
To;
wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|o
wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN- om
wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
t#o{
xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
"o'
xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetT!o;
xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2%ow
xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|$o
xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""Y&oE
xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A'o
xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-(om
xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
|T+o;
yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]*qO
xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down)o
xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|.o
yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t-o{
yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
,o'
yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2/ow
yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y0oE
yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A1o
yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-2om
yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
5o'
zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target4qO
yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down3o
yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
28ow
zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|7o
zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t6o{
zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y9oE
zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A:o
zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-;om
zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?>q9
zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)=qO
zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down<o
zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|Ao
{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t@o{
{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
?o'
{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2Bow
{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YCoE
{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ADo
{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Eom
{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Hq9
{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)GqO
{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downFo
{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]bR)RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{)))))	)
))
)))))))))))) )#)%)&)')()+).)/)0)1)2)5)8)9):);)>)A)B)C)D)E)H)K)L)M)N)Q)T)U)V)W)X)[)^)_)`)a)d)g)h)i)j)‚k)Ân)Ăq)łr)Ƃs)ǂt)Ȃw)ɂz)ʂ{)˂|)̂})͂~)΂)ς)Ђ)т)҂)ӂ
)Ԃ
)Ղ)ւ)ׂ)؂)ق)ڂ)ۂ)܂)݂)ނ )߂#)$)ႋ')₋*)る-)䂋0
2Kow
|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Jo
|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tIo{
|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YLoE
|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AMo
|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Nom
|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Qq9
|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)PqO
|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downOo
|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|To
}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tSo{
}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)hRqa
|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2Uow
}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YVoE
}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AWo
}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Xom
}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?[q9
}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)ZqO
}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downYo
}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2^ow
~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|]o
~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))h\qa
}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y_oE
~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A`o
~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-aom
~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?dq9
~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)cqO
~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downbo
~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|go
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))|fq	
~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]heqa
~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update

er+V:eD
59502bb5d4a7b0894afa700c66752b3529c815f645f28c3b1c2b321d7ddd2629D

7e8e536933fb7b0d5a5fc7670bcd56337af338f221f564415328864f937088adD	
ddcaa350e33d1c8dbffab5d04b8b98a223178542f0bbbc0bffdae33e41b18241D
8c178f2dd6153d2d3dcfef1a3398ac4285de7accb9561c9a03366def1b7c2aa3D
f6d493768ae9d25baa9e023ca6cee4fb1666c5cbd53f8c18631342dc3e38f221D
684dee15b7f2949d1127299fe87e939137acab9c8ab3a3b6ad0e0604573ea8a2D
6bd554a06d2cacb7334035a74ef3a0a10379a000a628cc964aba4a5a4c8d82e8D
7db76247917b09c13f39c3f19f3ecbd478e5c46584b6d8ff68a51268b0251871D
c03dc4d5e3cc2cadf7460b3f8fd8f02f0716c8e9ab44b6c38b6ac28113d2f65dD
be758c7001ddef751029603c28bb7e9f4c05b54b45fdf3ce79e59de8ae0d7426D
8747532845b7b53c68c46cbd4ae380333a36f007a086d57f8e04ec356181bc5dD
e7dfe1246a7bc34d021885e09adac136307a97c7a0acc867665ed6f71b091d48D
2b1dab8460db8d4ed73a10ff93169013dc92d4a6925455ed9bafce32fb719ae7
2how
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YioE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ajo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-kom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?nq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)mqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downlo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2qow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|pq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hoqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YroE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Aso
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-tom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?wq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)vqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downuo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm zqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|yq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hxqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2{ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y|oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A}o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-~om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?
q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)	qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 
qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
=q
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=q
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm  qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
//A#o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]D"}

Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=!q
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-$om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?'q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)&qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down%o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm *qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|)q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h(qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.-a}
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD,}

Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=+q
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tt0a	
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)/as
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).y.a
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
P2g;
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_1c]
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux5g
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p4g{
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)3g'
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
y8a
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..7a}
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen.6gw
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
Rt:a	
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)9as
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
P<g;
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_;c]
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux?g
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p>g{
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)=g'
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-Bis
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}Ai
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..@gw
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTEo;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cDk]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is FalsexCi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|Ho
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tGo{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Fo'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2Iow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YJoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
LxMi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-Lis
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}Ki
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
TOo;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cNk]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|Ro
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tQo{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Po'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2Sow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YToE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
NxVi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-Uis
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
TXo;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cWk]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|[o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tZo{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Yo'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2\ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y]oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:-_is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).A^o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
CCTbo;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cak]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex`i	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|eo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tdo{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
co'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2fow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YgoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xii	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAho
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]

er+V:eD
c48a58dcffbae76ac3c3c2d01d36951eb5a8df91ec715371c54637f6cdeb4f19D
1bf8bba46b2c5ea348a5a25ac9f2104263ce970c23bc3860e64178099e215f79D
1de65c5f5091d176efefe324dee42e11290463e4e9d6a45c2bafe24ff7a3a8e7D
105a6b516b3b76e51de1f49c194fc9e35f3a871f57878abbb5b6a53bc54dbc8cD
9a1fd5f559898dbaf4d03b56d97b096c2b79fc34289877bfec44204cca9aa895D
87fe3fb7cde1d8eee7a0811446e9f57ce979666bc9e6e29ac3cc9efc60d86d02D
57060ad1d840d5c5b714fe83a3d14486758cf9d186bea54eeb40b00a53427f02D
1be054e17c50261a454bf852731c5ce00520ff292c6811df3d49ab473f540a41D
4b4af671ab41596e55314e4e7f8cb70452287460fc44b844405f9035b7823f84D
5d59acc61e4c24682f9a5b9b41b1c5f8974de87c4a1fb4e029e9131a51888c38D
82615b5f75a4fb89fd8a9662bc57f478e82e61656145912b4cf6dc7349a9b42dD

2735ed4ad4e07e41a6e6b59da981af90e90b0bb1e85343189ce011e147af53ccD
d16ae7c3c974cef652ff9b87037d3450587a3df6ff7e04c65cade8d7bdebe945
Tko;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cjk]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|no
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tmo{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
lo'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2oow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YpoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Aqo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
Nxsi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-rom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
Tuo;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ctk]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|xo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))two{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
vo'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2yow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YzoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A{o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-|om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
~o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetT}o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]bR*JRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{)悋5)炋8)肋:)邋<)ꂋ?)낋B)삋E)킋H)I)J)M)O)R)S)T)V)X)[)\)])_)b)e)f)g)i*k*n*o*p*q*s*u*x*	y*
z*{*|*
******
***
********* *!*" *#!*$$*%'*&(*')*(**)-**0*+1*,2*-3*.4*/7*0:*1;*2<*3=*4@*5C*6D*7E*8F*9G*:J*;M*<N*=O*>P*?S*@V*AW*BX*CY*DZ*E]*F`*Ga*Hb*Ic
|To;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|
o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t	o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A
o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-!om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?$q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)#qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down"o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2'ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|&o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t%o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y(oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A)o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-*om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?-q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains),qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down+o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|0o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t/o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)h.qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
21ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y2oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A3o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-4om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?7q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)6qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down5o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2:ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|9o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))h8qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y;oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A<o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-=om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?@q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)?qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down>o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|Co
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))|Bq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hAqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2Dow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YEoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AFo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Gom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Jq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)IqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downHo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2Mow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Lq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hKqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YNoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AOo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Pom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Sq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)RqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downQo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm VqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Uq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hTqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2Wow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YXoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AYo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Zom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?]q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)\qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down[o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm `qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|_q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h^qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YaoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Abo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-com
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?fq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)eqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downdo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm iqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|hq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hgqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
=jq
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]

er+V:eD%
7fdb130eab949bc403e1c3601e83e6c3cbc7954955279ba1bea21124e1e5de38D$
5ee8683f8c93ce6cd407d16531478f99660fed0dd9f582ce317a1aeb518e6484D#
f8276a4628fde1b9537d7805763e64371f666ae7c100b439e3e89016471525d9D"
ebfa2d89f68f1f01852d54bde30581583c8843675d4c7bd6d2d5474a0d29fc5aD!
f94a030f57e0305ea48372f1b189a3297e92fb634475062f758ad5de5eec967eD 
45ea6e4e3244ee8c391939ed27d9667af07cbcf7e683b8241c444b5dc4340f93D
caf6cf5af9791e8fd3e3612202b1fe3208956e0f50b7add46fc8761ba8265cc3D
b77480a5bbcbb658aa18aaa138438f5924d6978f45f40b09f5958c6479004c18D
c43dc5cc0d5557e10da9f67c4460ea748ef4efdd5608a73b33c14113ebe7dd76D
225dcf54b58bc05175127f8b4645952fb99ba04b377f788b193dd25888a029efD
e70fc2d0e61c7e1f8c65da239c406fae5141f1efae29ff4e2ded90e4f2271ac7D
5b9aa9d2efdec945a27722458f45fc65a0105bf5378594552fe8bc991a4e86e1D
970bcc7ec1c59c73d7a05a3364494e66e1a3bc0882edd7eb63d85aebcd8c059f
""YkoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Alo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-mom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?pq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)oqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downno
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm sqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|rq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
Auo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=tq
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-vom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?yq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)xqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downwo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm |qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|{q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hzqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
//Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]D~}

Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=}q
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.	a}
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD}

Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=q
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tta	
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)as
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).y
a
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pg;
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_
c]
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxg
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pg{
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)g'
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
ya
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..a}
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen.gw
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
Rta	
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)as
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
Pg;
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_c]
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxg
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pg{
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)g'
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}i
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..gw
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT!o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c k]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|$o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t#o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
"o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2%ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y&oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Lx)i	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-(is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}'i
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
T+o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c*k]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|.o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t-o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
,o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2/ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y0oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nx2i	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-1is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
T4o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c3k]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|7o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t6o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
5o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
28ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y9oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:-;is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).A:o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
CCT>o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c=k]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex<i	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t@o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
?o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2Bow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YCoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]bR*RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{*Ki*Lj*Nk*Ol*Pm*Qp*Rs*Su*Tv*Uy*V|*W*X*Y*Z*[	*\*]*^*_*`*a*b*c*d!*e$*f%*g&*h)*i+*j.*k/*l0*m2*n4*o7*p8*q9*r;*s>*tA*uB*vC*xE*yG*zJ*{K*|L*}M*~O*Q*T*U*V*W*X*[*]*^*_*`*c*f*g*h*i*j*m*p*q*r*s*v*y*z*{*|*}******	**
*********** *!
:xEi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationADo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
TGo;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cFk]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|Jo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tIo{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Ho'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2Kow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YLoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AMo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NxOi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-Nom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
TQo;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cPk]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|To
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tSo{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Ro'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2Uow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YVoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AWo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Xom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
t[o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Zo'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTYo;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2]ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|\o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""Y^oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A_o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-`om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
|Tco;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]bqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|fo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))teo{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
do'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2gow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YhoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Aio
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-jom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
mo'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetlqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downko
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]

er+V:eD2
b7e3524e3d408eca2c519e323f8b8841358c3ee89c7362d30b856ed807a0cad7D1
32f371a2fb734b59d724e7f158a6b7786a4e7608c6e9200aacc4b1624c2d55feD0
053bab8c7482789ca2a4d26eacb17ea07e87c7b88691ebeea4df085b8ee8b0c4D/
6d3e0ab4e00db4dbaa9adaaeda6959ba06c02854163d2f14ce6376153c971409D.
6167999a4aa9b0b7fd775e20f7868e663374c2934e84072c1c95adbb617120f3D-
ec526953368001477a55a50c3cc2a5d51c651ebf782ccc4a61d9c0cd7dd37edaD,
219e0773f6cf831ca0c2983c48e45797cf1ed6150a23e416cebe02b6c43d5d35D+
0575f05deb1df2512ee0e962ca3a090704d98dca573c138f4280f758c83cc88aD*
94700baa2330493c2173bb7d59f922ff0cf174e02a7abbada312d73458b2870fD)
c5cb7460760e2885f04cef6e4c190e295bc38c25d8654fc325e8b08c5f835ffdD(
3494247306924b94b55f3da45af759539e2b9710c85996ca25ee2b838ccaf8d9D'
0bbfce2dd7e12ca5610015aba9f167cbc4cc29d360a77f3801b7508618bb17fbD&
28a4508ffc1c1668b23b1b346fa1d8f6999482b63898c282fcc25247623bd55e
2pow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tno{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YqoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Aro
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-som
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?vq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)uqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downto
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|yo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))txo{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
wo'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2zow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y{oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-}om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down~o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?	q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)h
qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2
ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))|q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2 ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y!oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A"o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-#om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?&q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)%qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down$o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2)ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|(q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h'qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y*oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A+o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-,om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?/q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains).qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down-o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 2qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|1q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h0qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
23ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y4oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A5o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-6om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?9q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)8qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down7o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm <qQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|;q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h:qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y=oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A>o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-?om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Bq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)AqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down@o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm EqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Dq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hCqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
=Fq
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
""YGoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AHo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Iom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Lq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)KqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downJo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm OqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Nq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hMqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
AQo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=Pq
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-Rom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Uq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)TqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downSo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm XqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Wq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hVqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
//A[o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]DZ}

Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=Yq
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-\om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?_q9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)^qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down]o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm bqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|aq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h`qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.ea}
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenDd}

Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=cq
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Ttha	
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)gas
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yfa
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pjg;
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_ic]
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxmg
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))plg{
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)kg'
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
ypa
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..oa}
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen.ngw
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target

er+V:eD?
f547d5c45db4604dbe0d39eae1befa3f083f7d65e124d7458ba4032e3ab8a287D>
9a702b71630a1f6857d6968df97b744cb45fd56fec8f16edbef0148661381390D=
d39bb4b8585a8c347658eb0e4b8c573ecb73f3bbb4c1b07af1b30a7d8cacce0cD<
7d581bf8155fdcfdd7570ca3bd524e4ab64b42a8bcbfe776cc2d97ca9fd25264D;
5cdfe7f1d4c546122d7808d352018750bdf5bdc270398c9f41c3414349e3f861D:
fc910dd4afd1311d8be1bdce2147613448f4162c19797bb345c5b725efff1d08D9
f3aa08ddf57c680c2b4642a22c261e11569a25f83c746d38afc1173fef7580f0D8
1cd646bb6272d044e00b987d196c13c7541d1e953946dd96356956e301fda53fD7
cfcfe9d9ae37170dc134b041696f09f451bb92f77ec37a8f19b080810bd0f006D6
4d7007f3cf68064e511dec0623843f0d41c7dee3f69d1b581ca0a6e9069cf098D5
5b750b8f5db8f4ebe68335063aeb85fc0c687063ea49ab0c7ba1275baf6245c9D4
b3cd6ec6014704060af86c8caa9a9ecbd7c3c5c0ca064b886bda0a31117ad014D3
82f985084dd4473e97f352c4919005eac36a824d8c9490c80095912a2f94e3c5
Rtra	
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)qas
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
Ptg;
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_sc]
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxwg
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pvg{
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)ug'
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-zis
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}yi
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..xgw
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT}o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c|k]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex{i	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationbR+RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{*#*&*)***+*,*/*2*3*4*5*6*9*<*=*>*?*‚B*ÂE*ĂF*łG*ƂH*ǂI*ȂL*ɂO*ʂQ*˂R*̂U*͂X*΂[*ς\*Ђ_*тb*҂e*ӂh*Ԃj*Ղm*ւp*؂r*قt*ڂw*ۂz*܂}*ނ*߂**ႏ*₏*わ
*䂏*傏*悏*炏*肏*邏*ꂏ*낏*삏*킏***!*#*&*'*(*)*+*-*0*1*2*3*4*7*9*:+;+<+?+B+C+D+E+H+K+	L+
M+N+Q+
T+U+V+W+Z+]+^+_
wqxw|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
~o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Lxi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}i
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
To;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|
o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t	o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nxi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-
is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
To;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:-is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
CCTo;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:x!i	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationA o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
T#o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c"k]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|&o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t%o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
$o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2'ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y(oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A)o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
Nx+i	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-*om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
T-o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c,k]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|0o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t/o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
.o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
21ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y2oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A3o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-4om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
t7o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
6o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetT5o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
29ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|8o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""Y:oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A;o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-<om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
?o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target>qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down=o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2Bow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Ao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t@o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YCoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ADo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Eom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Hq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)GqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downFo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2Kow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Jo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tIo{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YLoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AMo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Nom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Qq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)PqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downOo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2Tow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|So
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hRqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YUoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AVo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Wom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Zq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)YqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downXo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2]ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|\q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h[qa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y^oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A_o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-`om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?cq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)bqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downao
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm fqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|eq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hdqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YgoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Aho
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-iom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?lq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)kqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downjo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm oqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|nq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hmqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
Aqo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=pq
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]

er+V:eDL
a2e16e3449f1d216456cce32c996514ef5ca92cbe8e4e01823b44edb2054748fDK
f8d5011b3c0674720d0b3957a9b73860210ff186379452e0225431f7619a349fDJ
00ee764e0982d01d4e6bb4be901fe9d45e00ba81aada6ca3196a2f4c6a633f63DI
5e7c13e7ca9ceba3ee4769206f16397f62fe367684d347573b551f0ff2c8fd6dDH
124996a9073a9ca8c3f0c37ffc32039a2cdb8a8eb5ae0de982fc65de11708c2cDG
5cdd011988bd5f786fd69bb2f85ee35ad72937f71784e3c1b95f7eaad14b4e71DF
cc499773d5b8e2ef0f1585f8f54cda5bdf26720005e766f1ad4fa13b420b5f7aDE
a2747777a7c3d1ef8019b71132c4a6eb6e5a8363b7b085140da95747f86c10afDD
4705cdec550031f6ee8f3f2c0c78c72c88ec88a70a3c20ebb27eea168bfdd9afDC
405c83aec688febd1c01afeb7dcce3417c406be86016fef5342ad46668393522DB
9454700c32cd463eb0cc88eb843acc8c9da791accd71ed786c92357f2403b784DA
4ff26a4c002984d75b6bf2b0150de3b528864e2ce86be2ab94743d10ddef1544D@
f424072382650daa052fcb9ac01eb3fc0209eb1d8f2bc0d18f3bf1bebd42dc39
NN-rom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?uq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)tqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downso
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm xqQ
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|wq	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hvqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.{a}
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenDz}

Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=yq
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tt~a	
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)}as
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).y|a
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pg;
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_c]
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxg
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pg{
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)g'
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}i
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..gw
Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT	o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)

o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2
ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nxi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-is
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
To;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xi	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
To;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A!o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
EN
Eh%M
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.X$Mg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=#M1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2-"om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
	DAdDX.Mg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=-M1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#,ec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665g+em
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.l*ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678l)ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735i(eq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3I'e1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2n&Q

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)
	4"hu4=7M1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#6ec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665g5em
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.l4ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678l3ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735i2eq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3I1e1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2n0Q

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)h/M
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.
8y,g?em
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.l>ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678l=ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735i<eq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3I;e1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2n:Q

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)h9M
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.X8Mg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)
	CXO#ClHew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678lGew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735iFeq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3IEe1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2nDQ

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)hCM
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.XBMg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=AM1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#@ec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665
	HPr%HlQew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735iPeq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3IOe1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2nNQ

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)hMM
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.XLMg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=KM1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#Jec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665gIem
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.
	H%}<tHiZeq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3IYe1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2nXQ

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)hWM
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.XVMg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=UM1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#Tec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665gSem
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.lRew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678
	E 
pEIce1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2nbQ

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)haM
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.X`Mg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=_M1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#^ec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665g]em
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.l\ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678l[ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735
	%#H_%nlQ

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)hkM
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.XjMg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=iM1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#hec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665ggem
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.lfew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678leew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735ideq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3
	JFfSJhuM
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.XtMg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=sM1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#rec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665gqem
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.lpew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678loew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735ineq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3Ime1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2

er+V:eDY
4f723648476309de9070d25c30df94bf8d0ec5cc665cf947714768e3903e6677DX
7007758347481b5bd5b486012d4105aaa620968a412da55bf70e5eb5ee4ea52fDW
a59b71df5f20f5b5cbdbc96ff9c1388cc6a2ae20c74c5c924f364b4150653748DV
1a901043d59b38297076c304b82d8cf36fa295747a7273a0009f8566a93e0988DU
a44afb9ad79ce59c97899e5be3660c4d4dbd20f0aa44417e9f820995db76c42bDT
5eaba3f50062813592c389ebb343e248af7f03caee550d7cab3599bd3e6847d4DS
16cc8bcd9289899b14393eedecdb5d31b11e6a4d0c504f593037804de5878fceDR
c4ae76d7c6a23e9345f969ab95acd6dee04900b227f0de925cc539ffeb60c2e7DQ
7c5dcd2035ff3f4503debbaeecc9659798c5a4cc8626f9cb089451584f53fefcDP
b18eeaf97c8e575f6c91cac0852221503010783f1b05f5c71ba0566e0569c473DO
c3e8755371c95986d3d9b24ce2a85e7158f92f26160148570b73b95ab7cc341cDN
22a2f90a540cd9a8330a6a4c96da322865926757812e4c0fdfea538a351e6f5aDM
02f39c31f6b85c556cb651767e2383c2bac89bab5627ec18df62fd758577a348
	DAdDX~Mg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=}M1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#|ec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665g{em
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.lzew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678lyew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735ixeq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3Iwe1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2nvQ

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)
	4"hu4=M1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#ec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665gem
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.lew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678lew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735ieq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3Ie1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2nQ

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)hM
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.bR+|RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{+c+f+g+h+i+l+o+q+r+ u+!x+"{+#~+$+%+&+'	+(+)
+*+++,+-+.+/+0+1+2+3+4 +5!+6%+7.+87+9?+:H+;Q+<Z+=c+>l+?u+A~+B+D+E+F!+G*+H3+I<+JC+KI+LN+MT+NZ+O`+Pg+Ql+Ro+Sr+Tw+Vz+W}+X+Y+Z+[+\+]+^+_+`+a+b!+c#+d&+e)+f++g.+h0+i5+j8+k<+l?+mA+nD+oG+pI+qL+rN+sS+tV+uZ+v]+w_+xb+ye+zg+{j
8y,gem
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.lew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678l
ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735ieq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3Ie1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2n
Q

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)h	M
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.XMg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)
	CXO#Clew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678lew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735ieq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3Ie1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2nQ

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)hM
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.XMg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=M1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#ec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665
	HPr%Hl!ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735i eq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3Ie1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2nQ

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)hM
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.XMg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=M1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#ec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665gem
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.
	H%}<tHi*eq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3I)e1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2n(Q

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)h'M
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.X&Mg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=%M1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#$ec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665g#em
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.l"ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678
	E 
pEI3e1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2n2Q

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)h1M
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.X0Mg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=/M1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#.ec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665g-em
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.l,ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678l+ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735
	%#H_%n<Q

Gris Ge <fge@redhat.com> - 1.6.2-4[-- Fix FHS problem of find_unused_lun.py and etc, (RHBZ #1623515)h;M
Gris Ge <fge@redhat.com> 1.6.2-3[GB- Fix rpm runtime dependency of libstoragemgmt-local-plugin.X:Mg
Gris Ge <fge@redhat.com> 1.6.2-2[2*- Silence socket EPIPE error. (RHBZ #1582458)=9M1
Gris Ge <fge@redhat.com> 1.6.2-1Z- Upgrade to 1.6.2#8ec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665g7em
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.l6ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678l5ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735i4eq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3
FfSVC[U
David Shea <dshea@redhat.com> - 0.4.1-3R- Added a glade catalog file (dshea)#Bec
Tony Asleson <tasleson@redhat.com> - 1.8.1-2`- https://bugzilla.redhat.com/show_bug.cgi?id=1872745
- https://bugzilla.redhat.com/show_bug.cgi?id=1903665gAem
Tony Asleson <tasleson@redhat.com> - 1.8.1-1]R@- Upgrade to 1.8.1
- Obsolete the netapp plugin.l@ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-3\@* https://bugzilla.redhat.com/show_bug.cgi?id=1693678l?ew
Tony Asleson <tasleson@redhat.com> - 1.7.3-2\g@* https://bugzilla.redhat.com/show_bug.cgi?id=1629735i>eq
Tony Asleson <tasleson@redhat.com> - 1.7.3-1\f- Add nfs-utils as a dependency
- Upgrade to 1.7.3I=e1
Tony Asleson <tasleson@redhat.com> - 1.7.2-1\2- Upgrade to 1.7.2
}{RI[M
David Shea <dshea@redhat.com> - 0.4.2-5T@- Use GPLv3 for the license fileH
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.4.2-4S@- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_RebuildcGia
Kalev Lember <kalevlember@gmail.com> - 0.4.2-3SR@- Rebuilt for gobject-introspection 1.41.4F
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.4.2-2S- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild]E[c
David Shea <dshea@redhat.com> - 0.4.2-1Sc- New upstream release libtimezonemap-0.4.2D[a
David Shea <dshea@redhat.com> - 0.4.1-4Rv@- Merge fixes from lp:timezonemap
- Add cc-timezone-location.h to timezonemapincludes_HEADERS so it gets installed (iain.lane)
- Set en_name correctly (iain.lane)
- Don't call g_type_init() on glib >= 2.35; it's deprecated (iain.lane)
;N[a
David Shea <dshea@redhat.com> - 0.4.1-4Rv@- Merge fixes from lp:timezonemap
- Add cc-timezone-location.h to timezonemapincludes_HEADERS so it gets installed (iain.lane)
- Set en_name correctly (iain.lane)
- Don't call g_type_init() on glib >= 2.35; it's deprecated (iain.lane)VM[U
David Shea <dshea@redhat.com> - 0.4.1-3R- Added a glade catalog file (dshea)mLey
Jiri Konecny <jkonecny@redhat.com> - 0.4.4-2b- Remove regions from the map
  Resolves: rhbz#2098126nK[
David Shea <dshea@redhat.com> - 0.4.4-1UL@- Fixes for LP#1440157:
  Port to libsoup directly for geoname results
  Fix some memory leaks
  Do not reuse GCancellables
- Upstream merges of SVG update and constrained location cyclesJ[+
David Shea <dshea@redhat.com> - 0.4.2-6UCj- Updated the time zone map images
- Updated the city data from geonames.org
- Fix a memory leak and potential crash with the locations list
- Cycle through a smaller list of map locations on repeated clicks
T[+
David Shea <dshea@redhat.com> - 0.4.2-6UCj- Updated the time zone map images
- Updated the city data from geonames.org
- Fix a memory leak and potential crash with the locations list
- Cycle through a smaller list of map locations on repeated clicksRS[M
David Shea <dshea@redhat.com> - 0.4.2-5T@- Use GPLv3 for the license fileR
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.4.2-4S@- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_RebuildcQia
Kalev Lember <kalevlember@gmail.com> - 0.4.2-3SR@- Rebuilt for gobject-introspection 1.41.4P
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.4.2-2S- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild]O[c
David Shea <dshea@redhat.com> - 0.4.2-1Sc- New upstream release libtimezonemap-0.4.2
$
B $Z
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.4.2-2S- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild]Y[c
David Shea <dshea@redhat.com> - 0.4.2-1Sc- New upstream release libtimezonemap-0.4.2X[a
David Shea <dshea@redhat.com> - 0.4.1-4Rv@- Merge fixes from lp:timezonemap
- Add cc-timezone-location.h to timezonemapincludes_HEADERS so it gets installed (iain.lane)
- Set en_name correctly (iain.lane)
- Don't call g_type_init() on glib >= 2.35; it's deprecated (iain.lane)VW[U
David Shea <dshea@redhat.com> - 0.4.1-3R- Added a glade catalog file (dshea)mVey
Jiri Konecny <jkonecny@redhat.com> - 0.4.4-2b- Remove regions from the map
  Resolves: rhbz#2098126nU[
David Shea <dshea@redhat.com> - 0.4.4-1UL@- Fixes for LP#1440157:
  Port to libsoup directly for geoname results
  Fix some memory leaks
  Do not reuse GCancellables
- Upstream merges of SVG update and constrained location cycles
::m`ey
Jiri Konecny <jkonecny@redhat.com> - 0.4.4-2b- Remove regions from the map
  Resolves: rhbz#2098126n_[
David Shea <dshea@redhat.com> - 0.4.4-1UL@- Fixes for LP#1440157:
  Port to libsoup directly for geoname results
  Fix some memory leaks
  Do not reuse GCancellables
- Upstream merges of SVG update and constrained location cycles^[+
David Shea <dshea@redhat.com> - 0.4.2-6UCj- Updated the time zone map images
- Updated the city data from geonames.org
- Fix a memory leak and potential crash with the locations list
- Cycle through a smaller list of map locations on repeated clicksR][M
David Shea <dshea@redhat.com> - 0.4.2-5T@- Use GPLv3 for the license file\
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.4.2-4S@- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuildc[ia
Kalev Lember <kalevlember@gmail.com> - 0.4.2-3SR@- Rebuilt for gobject-introspection 1.41.4
-#!-Rg[M
David Shea <dshea@redhat.com> - 0.4.2-5T@- Use GPLv3 for the license filef
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.4.2-4S@- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuildceia
Kalev Lember <kalevlember@gmail.com> - 0.4.2-3SR@- Rebuilt for gobject-introspection 1.41.4d
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.4.2-2S- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild]c[c
David Shea <dshea@redhat.com> - 0.4.2-1Sc- New upstream release libtimezonemap-0.4.2b[a
David Shea <dshea@redhat.com> - 0.4.1-4Rv@- Merge fixes from lp:timezonemap
- Add cc-timezone-location.h to timezonemapincludes_HEADERS so it gets installed (iain.lane)
- Set en_name correctly (iain.lane)
- Don't call g_type_init() on glib >= 2.35; it's deprecated (iain.lane)Va[U
David Shea <dshea@redhat.com> - 0.4.1-3R- Added a glade catalog file (dshea)
2klW
Karel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_kWk
Karel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)mjey
Jiri Konecny <jkonecny@redhat.com> - 0.4.4-2b- Remove regions from the map
  Resolves: rhbz#2098126ni[
David Shea <dshea@redhat.com> - 0.4.4-1UL@- Fixes for LP#1440157:
  Port to libsoup directly for geoname results
  Fix some memory leaks
  Do not reuse GCancellables
- Upstream merges of SVG update and constrained location cyclesh[+
David Shea <dshea@redhat.com> - 0.4.2-6UCj- Updated the time zone map images
- Updated the city data from geonames.org
- Fix a memory leak and potential crash with the locations list
- Cycle through a smaller list of map locations on repeated clicks
>\oWc
Karel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev(nW{
Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=mW%
Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failed
G&GZrW_
Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bitqWI
Karel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.ApW-
Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information
=n==wW%
Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedkvW
Karel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_uWk
Karel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)Dtg#
Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]asWm
Karel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directory

er+V:eDf
b8df7b9911c734e2423d1ebb0116de9bc8b43bfbad024df88e3441f422aa93ffDe
592f30134c5a086d2102c5e64047ef6d7c337e0cc5d5350cc6f763992cdde4a1Dd
cd00145bb9ec1111aeeef6a3549e8186d773009d553f2c6ed0b608e4fbd9adcfDc
d90d150799643440c4a06c356693a216dd240f7c4b21d95255e233cae0b23fe0Db
2f6df5451338232fc54158e957a6c5e4c1ed718d22490cc1d0031abf1ddb128eDa
7702850f4e2e80c04e6c3466c990e0b651afe9da7ec148a25504e6539b25fcfaD`
05a1afac9166ad0a6bd4d12f5586743519b206e5f4bb4ce59ee057b9dff7d92fD_
1430b03046652a896ccac617100d4beab44c1c13c0d245b9bffbfe91817ea027D^
fb649db85a7fa03afc98ca05e61011b3c7d2d0ddfa11c9e025af979339542a81D]
fdb87f18d9c02219b23bb7f3233d128374d7e17e958892065ed687a59f5aad38D\
edc0594488f23ae7a46857065d3cd4d74e61a711b96dd5b99713419b033816a4D[
2eaa174ec4232e07070ccd4b7aee3cc74f51b5f55922176ea0fe278584f8dfdeDZ
f530a65c0efca53f618f63e02801129283b12266fbf21ac221e35617a45b0d4b
,Sr,AzW-
Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\yWc
Karel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev(xW{
Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login
la}Wm
Karel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZ|W_
Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit{WI
Karel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.
vT#v(W{
Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=W%
Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedkW
Karel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_Wk
Karel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)D~g#
Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
EEWI
Karel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.AW-
Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\Wc
Karel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;aWm
Karel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZW_
Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
vT#v(W{
Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=W%
Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedk
W
Karel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_	Wk
Karel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)Dg#
Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
EEWI
Karel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.AW-
Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\
Wc
Karel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;aWm
Karel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZW_
Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
[[:i

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Li1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)Dg#
Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
C8C:i

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
!i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572) i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l#iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q"i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88&yy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f%yW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC$y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
)i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)(i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d'ia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l+iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q*i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88.yy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f-yW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC,y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`0y/
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)/y?
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.5i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d4ia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):3i

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G2i'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L1i1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
l8iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q7i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)6i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:<i

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G;i'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)f:yW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC9y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
?i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)>i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d=ia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lAiq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q@i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88Dyy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fCyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCBy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
Gi!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Fi)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dEia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lIiq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qHi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88Lyy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fKyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCJy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`Ny/
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)My?
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.Si)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dRia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):Qi

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)GPi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)LOi1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
lViq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qUi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)Ti!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:Zi

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)GYi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fXyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCWy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
]i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)\i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d[ia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l_iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q^i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88byy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fayW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC`y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
ei!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)di)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dcia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lgiq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qfi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88jyy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fiyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagChy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`ly/
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)ky?
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.qi)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dpia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):oi

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gni'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Lmi1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
ltiq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qsi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)ri!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
181Gxi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Lwi1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)fvyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCuy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)

er+V:eDs
7742bb9e3b59162a644886a0fa900fa88dfa7012386ae583ac5a8bd6c5ac79f4Dr
fbc75db0004b4f2ffa063eb646e4714cfa1fa34ce927f4cdac02ed19920adcc8Dq
30da7f395230fa024303c27e46e2a5133d77edaece70586694945a12275a23f2Dp
6907d4d091a1107f3bf16ccdbf5e24663641bba18bd965f06812680002457959Do
dba6657dac2be85cbc8f4e111f952c8a9b31b95116671a599320b57503781a49Dn
79f1fedc8c8be3af6f1d989940ed7d956d779d3f488f821b4f08032ed83b1f3bDm
06bc77dd6c2f2125c8f8ccb6b4e685a71d97e6defb84eb1d696ee180ac974e06Dl
d1afd88393ffa5ac982a19f815f212f48fb963ea78add0832a9de497411e2322Dk
03e1baf0c1c94f364478eb3cd7d75ad83408dfe993ea8a69481c7f963ebb1cc3Dj
146ca869c5ba405509685e617aa2689cda961f933ee72947d61013803f3d5fb8Di
faf0e74d26792022e70a474776f33b0d995899e1d6150d742af9199b9cce5376Dh
6aef55f22ccae6cb279470d28bd97b90a8ac51e8d3c01f08c9363be80465a5edDg
cbb9fd109a25fe1c52b74144b6c1416666fbfd38ad1fd70a31ad0f95e9ded252
AX|i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572){i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dzia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):yi

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)

l~iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q}i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
C8C:i

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88
yy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f	yW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
4ui)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d
ia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):i

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)
liq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
88yy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`y/
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)y?
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
!i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572) i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l#iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q"i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88&yy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f%yW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC$y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`(y/
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)'y?
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.-i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d,ia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):+i

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G*i'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L)i1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
l0iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q/i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703).i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:4i

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G3i'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)f2yW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC1y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
7i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)6i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d5ia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l9iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q8i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88<yy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f;yW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC:y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
?i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)>i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d=ia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lAiq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q@i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88Dyy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fCyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCBy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`Fy/
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)Ey?
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.Ki)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dJia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):Ii

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)GHi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)LGi1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
lNiq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qMi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)Li!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:Ri

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)GQi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fPyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCOy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
Ui!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Ti)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dSia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lWiq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qVi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88Zyy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fYyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCXy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
]i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)\i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d[ia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l_iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q^i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88byy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fayW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC`y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`dy/
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)cy?
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.ii)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dhia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):gi

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gfi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Lei1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
lliq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qki{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)ji!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:pi

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Goi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fnyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCmy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)bR+RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{+}q+~t+x+|+~++++
++++++++!+#+&+(+-+0+4+7+9+<+?+A+D+F+K+N+R+U+W+Z+]+_+b+d+i+l+p+s+u+x+{+}++++
++++++++ +%+(+,+/+1+4+‚7+Â9+Ă<+ł>+ƂC+ǂF+ȂJ+ɂM+ʂO+˂R+̂U+͂W+΂Z+ς\+Ђa+тd+҂h+ӂk+Ԃm+Ղp+ւs+ׂu+؂x+قz+ۂ+܂+݂+ނ	+߂++႕+ₕ
si!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)ri)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dqia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

luiq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qti{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88xyy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fwyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCvy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)

er+V:eD
8667cee91ed1aa014f71555f076cfab5dd62a042d3dc7ea1d86ef30655b038ddD
523d10d80eca952ef1884acfb524e844fed7f5ba15040c03fb8bfd7e54beaed3D~
e84cbc56cc8d3cad5fbc8fdb06739cfdecf9f15a7df56f7d2af53fbc4308d0c3D}
2ea0d8ddefec1030824b74aedac593962bb24222add6f70b3b00533ed8993995D|
18a2c3ea2e2d5c5ae12660bf9eb03c2d3889e23de31d9b4ab4402b973dc2b813D{
8509c76026145b29ba6f1b8ae37a82d1ed82aae0b7d56716d065d753c42837f3Dz
feaa19dbb1f49048b7c247b0f07eca95e4c1ec3e3553221a73e356227d399654Dy
00063f470db329bdbf0defd2b9622d72db94830b9c0a108b7646f6acb3316563Dx
3d1213d433cc4f76de4bc1d38f0920c5716b596dcc3ced3dfff4e9e143ba5b59Dw
5bf6f0344add69eb5397aa58808fbb3f7473db3d8ebc8a33268d40b93fcfe0ccDv
b922b23c5579da9d7a1a127a1d46f32b941981d9a61ac309ffa1ca688fda5a47Du
1988a7c1f3496679d0f5155d1ccdb326d4c38efbb8e673eb67c29ca61004a3daDt
aff30e07efab7028b05be02c4bbb2921b2c5a2e7a4db5788137073e27ba4e2a7
{i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)zi)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dyia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l}iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q|i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC~y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`y/
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)y?
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):i

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Li1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
l
iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q	i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:i

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G
i'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
` y/
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)y?
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.%i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d$ia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):#i

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G"i'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L!i1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
l(iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q'i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)&i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:,i

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G+i'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)f*yW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC)y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
/i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572).i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d-ia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l1iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q0i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
884yy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f3yW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC2y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
7i!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)6i)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d5ia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l9iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q8i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88<yy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f;yW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC:y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`>y/
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)=y?
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.Ci)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dBia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):Ai

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G@i'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L?i1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
lFiq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qEi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)Di!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:Ji

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)GIi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fHyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCGy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
Mi!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Li)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dKia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lOiq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qNi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88Ryy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fQyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCPy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
Ui!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Ti)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dSia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lWiq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qVi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88Zyy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fYyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCXy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`\y/
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)[y?
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.ai)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d`ia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):_i

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G^i'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L]i1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
ldiq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qci{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)bi!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:hi

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Ggi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)ffyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCey
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
ki!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)ji)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lmiq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qli{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88pyy
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)foyW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCny
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
si!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)ri)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dqiaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

luiqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qti{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88xyyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fwyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCvyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`zy/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)yy?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)

er+V:eD

ebd82b5546583e76abeafb233879f04f1488a96c1f1823eac177889b8218328dD
afad00b6a6e0787361c27df8bba184168f6a8317833bb2188bd1f6c3ec7c9997D
836e44d1bc907b9e41d6d905730da4fdf18d002f62676006795789a1aaa6084cD

96abdf65e00da59857928e4d3001835a9e548fe6b84ef391015153d2fcd5ca97D	
0718ec7a648c76821e1117532667414db4883898fdd43d3e8a631827814422faD
7397d7ada85a990118fbb29a019e0229dcc123eb73b3d901e8a68ca2b7f2da53D
7c6aa8cfb40e021ce2fd6990bdd23916f3ceda1eb1455e49f09d1d0fb41d0f7aD
ff7bd67ed63db8e85a6f69944e947f3a58d239a5e418b671d1eea3c8271d0777D
8f8cfe9eb61a9f25ca7e0e1a0141cb8189a5465ea0cb8dd6c524a2ef72866ea8D
fb019a858ec470c37fb4514a9c501552516bfe09f3c57ab59409c560d2a46ca9D
adf453caa95445c3a99ca102ec42c7d67b44d897aee8925bb4a1da3f07940c49D
84217b8ac653dfecde5e7761d967ffab45d9ea928e22a4a2cd5a502719a1a0b2D
8682aa231a96b16cfd29d6bcb965dc552b13f5ce5e91dc71b4cb0725eb72bf7b
./c.i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d~iaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):}i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G|i'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L{i1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
liqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
	i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q
i{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f
yWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`y/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)y?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Li1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
l iqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:$i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G#i'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)f"yWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC!yJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
'i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)&i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d%iaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l)iqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q(i{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88,yyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f+yWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC*yJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
/i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572).i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d-iaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l1iqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q0i{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
884yyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f3yWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC2yJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`6y/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)5y?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.;i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d:iaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):9i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G8i'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L7i1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
l>iqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q=i{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)<i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:Bi
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)GAi'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)f@yWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC?yJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
Ei!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Di)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dCiaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lGiqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qFi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88JyyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fIyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCHyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
Mi!	Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Li)	Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dKia	Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lOiq	Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qNi{	Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88Ryy	Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fQyW	Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCPy	Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`Ty/	Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)Sy?	Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.Yi)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dXia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):Wi

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)GVi'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)LUi1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
l\iq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q[i{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)Zi!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:`i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G_i'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)f^yW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC]y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
ci!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)bi)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)daiaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

leiqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qdi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88hyyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fgyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCfyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
ki!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)ji)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diiaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lmiqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qli{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88pyyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)foyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCnyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`ry/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)qy?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.wi)
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dvia
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):ui

Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gti'
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Lsi1
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
lziq
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qyi{
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)xi!
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:~i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G}i'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)f|yW
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC{y
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)

er+V:eD
9b60f16bb0b8c4049fe3746ef82af738dea6d843c9a10278ae65a56e0f643543D
cc9292399132346f75bd097e7ee2df57581d949a9ca4f74d5d800c7565f777ecD
9fbd7c60ba0ef653dfcf59169cc19e74805f8e102bab5c4d038d343782872528D
6da0086ed5fcfe18e8f92777f56bc0561f7b8a591eb03c6f38ba815464fbbdd1D
de277490ec2359c7396f0b7c4d39dfa4426e563ea8cc9defdaad322dd0c42a48D
278b669b053892a784bbbac57d1b11be6496d6c624a0350a7d5628bcc2cba7a9D
ddfdb301a369e390465e7fed07a523d49328f34568875ece4041374ce5341b09D
a5af318efcf06316076e95b5e88893eb108d829611813c7fc493ba3ebc5a1e32D
0b666836eac572662e426b0b815d751ae62dd8422c5ab5c6d910f8bf94ad1141D
49d7fd7bc99dd196b6ad0b23effba028c00ec83384e764f0625ec4d1a888a932D
2e4ef0b59e648eed97f857dbb868a2e14afec888dc7074820f587738e8085781D
6a232fa9ad8c17cfa5cf5fefe213336bbd9160948ed66031dfd0a65edc56190aD
08b4dee7a9b26d0de63eb7b9be7383288a1d179be539eb61df3c1d005566ba5f
i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
	i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q
i{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f
yWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`y/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)y?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Li1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
liqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)bR,IRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{+䂕+傕+悕 +炕$+肕'+邕)+ꂕ,+낕/+삕1+킕4+6+;+>+B+E+G+J+M+O+R+T+Y+\+`+c+e+h+k,m,p,r,w,z,~,,,	,
	,,,
,,,,,!,$,',),,,.,3,6,:,=,?,B,E, G,!J,"L,#Q,$T,%X,&[,'],(`,)c,*e,+h,,j,-o,.r,/v,0y,1{,2~,4,5,6,7,8
,9,:,;,<,=,>,?!,@$,A&,B+,C.,D2,E5,F7,G:,H=
C8C:i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l!iqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q i{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88$yyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f#yWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC"yJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
'i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)&i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d%iaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l)iqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q(i{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88,yyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f+yWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC*yJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`.y/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)-y?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.3i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d2iaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):1i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G0i'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L/i1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
l6iqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q5i{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)4i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C::i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G9i'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)f8yWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC7yJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
=i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)<i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d;iaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l?iqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q>i{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88ByyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fAyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC@yJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
Ei!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Di)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dCiaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lGiqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qFi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88JyyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fIyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCHyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`Ly/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)Ky?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.Qi)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dPiaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):Oi
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)GNi'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)LMi1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
lTiqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qSi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)Ri!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:Xi
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)GWi'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fVyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCUyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
[i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Zi)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dYiaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l]iqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q\i{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88`yyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f_yWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC^yJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
ci!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)bi)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)daiaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

leiqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qdi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88hyyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fgyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCfyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`jy/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)iy?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.oi)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dniaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):mi
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gli'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Lki1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
lriqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qqi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)pi!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:vi
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gui'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)ftyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCsyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
yi!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)xi)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dwiaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l{iqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qzi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88~yyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f}yWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC|yJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)

er+V:eD'
7423f22c87721f8d9e25856620d67f6482cedf0716640fcf8f7e8f609797cb2eD&
ddafb1e92f08f922d622d8426b42ea6cd1ddf7090da44abf0678b4cfd67cd2d3D%
76bc9b2f317ca1734d3d4a20a64af355a4fdf864a86b43797f7bf7ef506f5b34D$
49c9854872e8bc5ea2a45b52e2667a2d8a44dc7c1e42f73a3ed483d4ed29ddacD#
64d308b2273fa36c403e5a4ed7c61854903e74760d31d9b214f1bf89fe0393e6D"
38926b3705d3995333fb2ea6d22cd0d4590578927040ef0006aa35db2898e209D!
9fabfd6e48f2b62acf53b7c1041c0ca9cb1dc4ad4136784de7d73bae29b118c0D 
2762293f4b83a93a76a349d261bacbdf67469071936e8daeaa3979de38b05145D
b23b467a1a7c8028c65449557a6f6a8354bf652726aadf062e125ab59dd4db0fD
27fa8705d3dff1a9ead8a72326edbe7713a85aef397c766654dc88099acc1354D
22368115a8dd7ef1ec13ecc12ebfa7ea254651f0f7e10223b188155bfd2552f9D
3cf860317663bddc14b4af70586d0e219e8532bba47638fb4b72460e2bac69b3D
b278fb80905868e72a398c821811d157b927969735ff0b93fcd631121d772538
i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`y/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)y?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.
i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G
i'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L	i1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
liqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l!iqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q i{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88$yyJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f#yWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC"yJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`&y/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)%y?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.+i)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d*iaJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):)i
Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G(i'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L'i1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
l.iqJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q-i{Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703),i!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:2i
 Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G1i' Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)f0yWJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC/yJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
5i! Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)4i) Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d3ia Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l7iq Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q6i{ Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88:yy Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f9yW Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC8y Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
=i!!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)<i)!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d;ia!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l?iq!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q>i{!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88Byy!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fAyW!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC@y!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`Dy/!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)Cy?!Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.Ii)"Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dHia"Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):Gi
"Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)GFi'"Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)LEi1"Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
lLiq"Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qKi{"Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)Ji!"Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:Pi
#Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)GOi'#Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fNyW"Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCMy"Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
Si!#Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Ri)#Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dQia#Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lUiq#Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qTi{#Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88Xyy#Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fWyW#Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCVy#Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
[i!$Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Zi)$Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dYia$Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l]iq$Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q\i{$Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88`yy$Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f_yW$Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC^y$Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`by/$Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)ay?$Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.gi)%Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dfia%Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):ei
%Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gdi'%Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Lci1%Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
ljiq%Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qii{%Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)hi!%Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:ni
&Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gmi'&Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)flyW%Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCky%Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
qi!&Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)pi)&Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)doia&Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lsiq&Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qri{&Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88vyy&Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fuyW&Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCty&Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
yi!'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)xi)'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dwia'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l{iq'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qzi{'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88~yy'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f}yW'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC|y'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`y/'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)y?'Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)

er+V:eD4
b390b91a21665b3ff2a03ee9f7c6bdb30c06442a9b46e609048d87d28973909dD3
2acff987d578fb2dc7aa7309391c70d97bcea8f1a44ee74b888c44fae2062777D2
747801d0d750e872620c71b8849522e592cbf713a0e5acaafe2579d358550d24D1
0710224c0e98852a70afc4e528bd026d4d46bf8fa6d68af8b7944e41683ae5cfD0
e1e650013a118dcd257d99f632eaaa7d97ca8ff95832c08b76f5f19daaa2c830D/
3d8ff28a1b05b9697b82489f71fd9ccdb0c088f4ca37c35263925511db5f5c7bD.
aef77f3e427a8c93fb45d754ebe7752c844902b2b146a2e674ead9a54c577645D-
27f2bd3c549d96fc721458ba0085c54f33b57ffc368dc6a0cb33627d326ab37bD,
00f6b15c036cb61966264e2a9c7ef1815399b860c29455f9b7b85bd59958ee0bD+
dbfc7031b1cd09899c676d6ca513c824c52747913d402f85f2e22b0b8baac066D*
43931a5196450e67afee8e240f59257098e4480d715afddd7ca69d04c9af6240D)
751fbd8677147721988c4cec90747030a077b3dd3211d87dabcce6357d612e7aD(
49c62aad693f852c4a093519a3b829f4e69ae106375d2be0eae07159b97d4d48
./c.i)(Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dia(Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):i
(Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'(Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Li1(Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
liq(Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{(Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)i!(Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:i
)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi')Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)f
yW(Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC	y(Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
i!)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i))Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d
ia)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liq)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yy)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyW)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy)Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
i!*Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)*Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dia*Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liq*Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{*Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yy*Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyW*Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy*Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`y/*Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)y?*Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.#i)+Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d"ia+Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):!i
+Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G i'+Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Li1+Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
l&iq+Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q%i{+Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)$i!+Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
181G*i',Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L)i1,Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)f(yW+Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC'y+Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
AX.i!,Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)-i),Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d,ia,Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):+i
,Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)

l0iq,Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q/i{,Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
C8C:4i
-Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G3i'-Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)f2yW,Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC1y,Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
7i!-Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)6i)-Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d5ia-Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l9iq-Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q8i{-Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88<yy-Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f;yW-Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC:y-Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
4u@i).Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d?ia.Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):>i
.Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G=i'.Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)
lCiq.Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qBi{.Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)Ai!.Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)bR,RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{,JB,KD,LI,ML,NP,OS,PU,QX,R[,S],T`,Ub,Vg,Wj,Xn,Yq,Zs,[v,\y,]{,^~,_,a,b,c,d,e,f,g,h,i,j,k#,l&,m*,n.,o0,p4,q7,r9,s<,t@,uC,wF,xI,yK,zN,{P,|S,}U,~X,Z,_,b,f,i,k,n,q,s,v,x,},,,,
,,,,,,, ,#,%,(,*,-,/,2,4,9,<,@,C,E,H,K,M,P,R,W,Z,^,a,c,f
88Fyy.Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fEyW.Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCDy.Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
Ii!/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Hi)/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dGia/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lKiq/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qJi{/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88Nyy/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fMyW/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCLy/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`Py//Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)Oy?/Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
Si!0Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Ri)0Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dQia0Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lUiq0Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qTi{0Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88Xyy0Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fWyW0Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCVy0Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`Zy/0Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)Yy?0Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c._i)1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d^ia1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):]i
1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G\i'1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L[i11Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
lbiq1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qai{1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)`i!1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:fi
2Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gei'2Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fdyW1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCcy1Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
ii!2Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)hi)2Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dgia2Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lkiq2Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qji{2Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88nyy2Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fmyW2Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCly2Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
qi!3Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)pi)3Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)doia3Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lsiq3Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qri{3Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88vyy3Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fuyW3Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCty3Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`xy/3Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)wy?3Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.}i)4Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d|ia4Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):{i
4Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gzi'4Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Lyi14Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
liq4Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{4Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)~i!4Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
181Gi'5Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Li15Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)fyW4Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy4Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)

er+V:eDA
5056d3b14c1c47acae89cc110be58d13ce5c372f2467505049cf09faeef3f7b3D@
f8c57e980b49a9dd5b43aabb9b590741efe9dc8ac4e8fe1955f4ffa5f0bb2399D?
5ceaceb75d9c3e12ea45d4a97b594b8085dcedb0037193817a44a30fe9ff98adD>
9b034f31b9d2ed3c7e58e6a93b911b9f49b07b0808de96a2e2e691263e14e0faD=
84ee79c0b96353a8ac5b4d46b6624e17ed80e67fe48583aac6c73b9b4deea759D<
c36162f22f8c779d80318cc08d286cb53edb4aefee5789af29a4838a219d9350D;
7bc141e86767fb1aded5e84e27ba2b03fae8eba8456610294def618a96028c69D:
b0d102765a6254ba3124a2f0696551cdf5095c030aa9fcee435cd4fa3f06d423D9
57975bf3b85630da395b3a5f46aa15caed57803b4508f1391c84aeb4ba95541aD8
7336707319b5f28ace3e7bf0ea8751a0ba448a98bfa2b4875c2d08c7207b3bc0D7
b3bdc6e767be75bd2d9600181faa4ca87a0e88beb73a43bfc5fc4a5c8956a80fD6
758b5cae55b3ac82f5e0a21bdf123b49f2e3ddee46a47f58c99a1c2e02d78f54D5
2244aba731b0cc66db6a9b851a8fa413e9243bdd8fded42aa81fcb9d5c9beabc
AXi!5Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)5Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dia5Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):i
5Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)

l
iq5Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q	i{5Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
C8C:i
6Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G
i'6Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fyW5Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy5Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
i!6Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)6Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dia6Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liq6Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{6Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yy6Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyW6Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy6Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
4ui)7Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dia7Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):i
7Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'7Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)
liq7Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{7Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)i!7Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
88 yy7Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyW7Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCy7Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
#i!8Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)"i)8Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d!ia8Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l%iq8Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q$i{8Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88(yy8Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f'yW8Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC&y8Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`*y/8Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557))y?8Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
-i!9Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572),i)9Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d+ia9Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l/iq9Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q.i{9Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
882yy9Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f1yW9Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC0y9Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`4y/9Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)3y?9Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.9i):Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d8ia:Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):7i
:Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G6i':Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L5i1:Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
l<iq:Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q;i{:Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703):i!:Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:@i
;Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G?i';Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)f>yW:Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC=y:Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
Ci!;Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Bi);Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dAia;Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lEiq;Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qDi{;Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88Hyy;Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fGyW;Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCFy;Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
Ki!<Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)Ji)<Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dIia<Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lMiq<Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qLi{<Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88Pyy<Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fOyW<Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCNy<Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`Ry/<Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)Qy?<Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.Wi)=Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dVia=Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):Ui
=Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)GTi'=Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)LSi1=Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
lZiq=Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qYi{=Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)Xi!=Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
C8C:^i
>Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)G]i'>Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)f\yW=Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC[y=Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
ai!>Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)`i)>Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d_ia>Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lciq>Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qbi{>Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88fyy>Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)feyW>Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCdy>Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
ii!?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)hi)?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dgia?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

lkiq?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qji{?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88nyy?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fmyW?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCly?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`py/?Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)oy??Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
./c.ui)@Jiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)dtia@Jiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):si
@Jiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gri'@Jiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)Lqi1@Jiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)
lxiq@Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qwi{@Jiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)vi!@Jiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
181G|i'AJiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)L{i1AJiri Denemark <jdenemar@redhat.com> - 4.5.0-29]߶- qemu: Forcibly mknod() even if it exists (rhbz#1752978)
- qemu_process: fix starting VMs if machine group has limited cpuset.cpus (rhbz#1746517)fzyW@Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyy@Jiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
AXi!AJiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)AJiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d~iaAJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):}i
AJiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)

liqAJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{AJiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
C8C:i
BJiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'BJiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)fyWAJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyAJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)

er+V:eDN
fe31962a7aaae275d7dcbf9efe7364a94ada762b968513d3d783f9e763f8441bDM
f857d70721c9f191d7cebc1993d75fc3dbb29bc7c08b3b8e0044ba4d2205446aDL
59c66abe57e107fb07bfa33cca0326a2a7dfae6183e42d0d806de55598f76776DK
6fbcfd20152fd53029a53f360639d892f5a3daa9485dc2be94c27eed6cf2df64DJ
bc63c8bfc930293da3e922e892186113cc420688e28a4ef936bbae8372240055DI
2b6dd64d39816de5f6fd5330c2e6b95ae66fa3c853d61272092b0a027fbd1da3DH
27fd50136804eda5f0c7bfe32a61dcd680349725916fcebde89f0c8a2e549767DG
cc9eef61c95aebbc7a432d58f5f85fbab25f19ee777834f671bc23fa94964d57DF
6e3bb564a139de89aa75082746181d125ed4c599326591693741010469bbd88eDE
a2241dadf6e520288ff5e0285cd20102eb24c34f0045337577928089b0ff4d79DD
aca23e962d5b30b4147e2f0e756d929facad88ca94e488463a87261a6a8c0302DC
f91b2363933aa9f88629048ee0d497b9541689ada66a07709b03177f3d709470DB
ff72d842591430311c483b93233f526b1dd34e953a34c084885d68d786f0aeba
	i!BJiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)BJiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaBJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liqBJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q
i{BJiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88yyBJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f
yWBJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyBJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
4ui)CJiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaCJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831):i
CJiri Denemark <jdenemar@redhat.com> - 4.5.0-31]@- process: wait longer on kill per assigned Hostdev (rhbz#1771204)
- process: wait longer 5->30s on hard shutdown (rhbz#1771204)Gi'CJiri Denemark <jdenemar@redhat.com> - 4.5.0-30]- nwfilter: Remove redundant check if object exists (rhbz#1766475)
- RHEL: qemu: Enable virt-ssbd for host-model with old QEMU (rhbz#1745181)
liqCJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{CJiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)i!CJiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)
88yyCJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyWCJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyCJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
i!DJiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)i)DJiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)diaDJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

liqDJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)qi{DJiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88 yyDJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)fyWDJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagCyDJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
`"y/DJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)!y?DJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
%i!EJiri Denemark <jdenemar@redhat.com> - 4.5.0-34^- vmx: shortcut earlier few 'ignore' cases in virVMXParseDisk() (rhbz#1815269)
- vmx: make 'fileName' optional for CD-ROMs (rhbz#1815269)
- RHEL: Fix migration on AMD hosts with old QEMU (rhbz#1815572)$i)EJiri Denemark <jdenemar@redhat.com> - 4.5.0-33^F- RHEL: qemuCheckUnprivSGIO: use @sysfs_path to get unpriv_sgio (rhbz#1801139)d#iaEJiri Denemark <jdenemar@redhat.com> - 4.5.0-32^2@- qemu: Don't emit SUSPENDED_POSTCOPY event on destination (rhbz#1791886)
- node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (rhbz#1792831)

l'iqEJiri Denemark <jdenemar@redhat.com> - 4.5.0-36^@- virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976)q&i{EJiri Denemark <jdenemar@redhat.com> - 4.5.0-35^@- qemu: don't take agent and monitor job for shutdown (CVE-2019-20485)
- qemu: don't hold a monitor and agent job for reboot (CVE-2019-20485)
- qemu: don't hold monitor and agent job when setting time (CVE-2019-20485)
- qemu: remove use of qemuDomainObjBeginJobWithAgent() (CVE-2019-20485)
- qemu: remove qemuDomainObjBegin/EndJobWithAgent() (CVE-2019-20485)
- storage: Fix daemon crash on lookup storagepool by targetpath (CVE-2020-10703)
88*yyEJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.3_@- rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549)f)yWEJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.2_*@- Rebuild to correct invalid dist tagC(yEJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.1_A@- qemu: end the agent job in qemuDomainSetTimeAgent (rhbz#1844952)
- util: string: Introduce macro for automatic string lists (rhbz#1839992)
- util: Rework virStringListAdd (rhbz#1839992)
- qemu: Create multipath targets for PRs (rhbz#1839992)
- util: Move virIsDevMapperDevice() to virdevmapper.c (rhbz#1839992)
- virDevMapperGetTargetsImpl: Check for dm major properly (rhbz#1839992)
{`{I-a5FDaniel Mach <dmach@redhat.com> - 0.9.9-7.1Qb@- Rebuild for gnutls,y/EJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.5`T@- RHEL: virdevmapper: Don't leak DIR on OOM in virDMSanitizepath() (rhbz#1933557)+y?EJiri Denemark <jdenemar@redhat.com> - 4.5.0-36.el7_9.4`S@- virdevmapper.c: Join two WITH_DEVMAPPER sections together (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use VIR_AUTOSTRINGLIST (rhbz#1933557)
- virdevmapper: Don't use libdevmapper to obtain dependencies (rhbz#1933557)
- virdevmapper: Don't cache device-mapper major (rhbz#1933557)
- virdevmapper: Handle kernel without device-mapper support (rhbz#1933557)
- virdevmapper: Ignore all errors when opening /dev/mapper/control (rhbz#1933557)
- virdevmapper: fix stat comparison in virDMSanitizepath (rhbz#1933557)
- virDevMapperGetTargetsImpl: Use correct length when copying into dm.name (rhbz#1933557)
%:%D2_+FPetr Pisar <ppisar@redhat.com> - 0.9.9-11Y- Fix a crash in the VNC server library on connecting an IPv4 client if the
  server could not start listening on an IPv6 socket (bug #1314814)w1_FPetr Pisar <ppisar@redhat.com> - 0.9.9-10TSy- Fix CVE-2014-6051 (integer overflow in screen size handling) (bug #1157671)
- Fix CVE-2014-6052 (NULL pointer dereference in framebuffer setup)
  (bug #1157671)
- Fix CVE-2014-6053 (NULL pointer dereference in ClientCutText message
  handling) (bug #1157671)
- Fix CVE-2014-6054 (server divide-by-zero in scaling factor handling)
  (bug #1157671)
- Fix CVE-2014-6055 (server stacked-based buffer overflow in file transfer
  handling) (bug #1157671)L0]?FDaniel Mach <dmach@redhat.com> - 0.9.9-9RU- Mass rebuild 2014-01-24L/]?FDaniel Mach <dmach@redhat.com> - 0.9.9-8Rk- Mass rebuild 2013-12-27r.aFPetr Pisar <ppisar@redhat.com> - 0.9.9-7.2Qp@- Specify dependencies on libpng and libgcrypt (bug #852660)
`u1v`L:]?GDaniel Mach <dmach@redhat.com> - 0.9.9-9RU- Mass rebuild 2014-01-24L9]?GDaniel Mach <dmach@redhat.com> - 0.9.9-8Rk- Mass rebuild 2013-12-27r8aGPetr Pisar <ppisar@redhat.com> - 0.9.9-7.2Qp@- Specify dependencies on libpng and libgcrypt (bug #852660)I7a5GDaniel Mach <dmach@redhat.com> - 0.9.9-7.1Qb@- Rebuild for gnutlsj6y_FMichael Catanzaro <mcatanzaro@redhat.com> - 0.9.9-14.1_!d- Fix CVE-2017-18922
  Resolves: #18525095_IFPetr Pisar <ppisar@redhat.com> - 0.9.9-14^r
@- Fix CVE-2019-15690 (an integer overflow in HandleCursorShape() in a client)
  (bug #1814745)'4_qFPetr Pisar <ppisar@redhat.com> - 0.9.9-13\73- Fix CVE-2018-15127 (Heap out-of-bounds write in
  rfbserver.c:rfbProcessFileTransferReadBuffer()) (bug #1662996)3_/FPetr Pisar <ppisar@redhat.com> - 0.9.9-12Z- Fix CVE-2018-7225 (improper client cut text length sanitization) (bug #1548441)
;=_/GPetr Pisar <ppisar@redhat.com> - 0.9.9-12Z- Fix CVE-2018-7225 (improper client cut text length sanitization) (bug #1548441)D<_+GPetr Pisar <ppisar@redhat.com> - 0.9.9-11Y- Fix a crash in the VNC server library on connecting an IPv4 client if the
  server could not start listening on an IPv6 socket (bug #1314814)w;_GPetr Pisar <ppisar@redhat.com> - 0.9.9-10TSy- Fix CVE-2014-6051 (integer overflow in screen size handling) (bug #1157671)
- Fix CVE-2014-6052 (NULL pointer dereference in framebuffer setup)
  (bug #1157671)
- Fix CVE-2014-6053 (NULL pointer dereference in ClientCutText message
  handling) (bug #1157671)
- Fix CVE-2014-6054 (server divide-by-zero in scaling factor handling)
  (bug #1157671)
- Fix CVE-2014-6055 (server stacked-based buffer overflow in file transfer
  handling) (bug #1157671)
TN;LD]?HDaniel Mach <dmach@redhat.com> - 0.9.9-9RU- Mass rebuild 2014-01-24LC]?HDaniel Mach <dmach@redhat.com> - 0.9.9-8Rk- Mass rebuild 2013-12-27rBaHPetr Pisar <ppisar@redhat.com> - 0.9.9-7.2Qp@- Specify dependencies on libpng and libgcrypt (bug #852660)IAa5HDaniel Mach <dmach@redhat.com> - 0.9.9-7.1Qb@- Rebuild for gnutlsj@y_GMichael Catanzaro <mcatanzaro@redhat.com> - 0.9.9-14.1_!d- Fix CVE-2017-18922
  Resolves: #1852509?_IGPetr Pisar <ppisar@redhat.com> - 0.9.9-14^r
@- Fix CVE-2019-15690 (an integer overflow in HandleCursorShape() in a client)
  (bug #1814745)'>_qGPetr Pisar <ppisar@redhat.com> - 0.9.9-13\73- Fix CVE-2018-15127 (Heap out-of-bounds write in
  rfbserver.c:rfbProcessFileTransferReadBuffer()) (bug #1662996)
;G_/HPetr Pisar <ppisar@redhat.com> - 0.9.9-12Z- Fix CVE-2018-7225 (improper client cut text length sanitization) (bug #1548441)DF_+HPetr Pisar <ppisar@redhat.com> - 0.9.9-11Y- Fix a crash in the VNC server library on connecting an IPv4 client if the
  server could not start listening on an IPv6 socket (bug #1314814)wE_HPetr Pisar <ppisar@redhat.com> - 0.9.9-10TSy- Fix CVE-2014-6051 (integer overflow in screen size handling) (bug #1157671)
- Fix CVE-2014-6052 (NULL pointer dereference in framebuffer setup)
  (bug #1157671)
- Fix CVE-2014-6053 (NULL pointer dereference in ClientCutText message
  handling) (bug #1157671)
- Fix CVE-2014-6054 (server divide-by-zero in scaling factor handling)
  (bug #1157671)
- Fix CVE-2014-6055 (server stacked-based buffer overflow in file transfer
  handling) (bug #1157671)
TN;LN]?IDaniel Mach <dmach@redhat.com> - 0.9.9-9RU- Mass rebuild 2014-01-24LM]?IDaniel Mach <dmach@redhat.com> - 0.9.9-8Rk- Mass rebuild 2013-12-27rLaIPetr Pisar <ppisar@redhat.com> - 0.9.9-7.2Qp@- Specify dependencies on libpng and libgcrypt (bug #852660)IKa5IDaniel Mach <dmach@redhat.com> - 0.9.9-7.1Qb@- Rebuild for gnutlsjJy_HMichael Catanzaro <mcatanzaro@redhat.com> - 0.9.9-14.1_!d- Fix CVE-2017-18922
  Resolves: #1852509I_IHPetr Pisar <ppisar@redhat.com> - 0.9.9-14^r
@- Fix CVE-2019-15690 (an integer overflow in HandleCursorShape() in a client)
  (bug #1814745)'H_qHPetr Pisar <ppisar@redhat.com> - 0.9.9-13\73- Fix CVE-2018-15127 (Heap out-of-bounds write in
  rfbserver.c:rfbProcessFileTransferReadBuffer()) (bug #1662996)
;Q_/IPetr Pisar <ppisar@redhat.com> - 0.9.9-12Z- Fix CVE-2018-7225 (improper client cut text length sanitization) (bug #1548441)DP_+IPetr Pisar <ppisar@redhat.com> - 0.9.9-11Y- Fix a crash in the VNC server library on connecting an IPv4 client if the
  server could not start listening on an IPv6 socket (bug #1314814)wO_IPetr Pisar <ppisar@redhat.com> - 0.9.9-10TSy- Fix CVE-2014-6051 (integer overflow in screen size handling) (bug #1157671)
- Fix CVE-2014-6052 (NULL pointer dereference in framebuffer setup)
  (bug #1157671)
- Fix CVE-2014-6053 (NULL pointer dereference in ClientCutText message
  handling) (bug #1157671)
- Fix CVE-2014-6054 (server divide-by-zero in scaling factor handling)
  (bug #1157671)
- Fix CVE-2014-6055 (server stacked-based buffer overflow in file transfer
  handling) (bug #1157671)
ETN*EvXkJIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgWiiJAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Vk}JIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhUikJAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16jTy_IMichael Catanzaro <mcatanzaro@redhat.com> - 0.9.9-14.1_!d- Fix CVE-2017-18922
  Resolves: #1852509S_IIPetr Pisar <ppisar@redhat.com> - 0.9.9-14^r
@- Fix CVE-2019-15690 (an integer overflow in HandleCursorShape() in a client)
  (bug #1814745)'R_qIPetr Pisar <ppisar@redhat.com> - 0.9.9-13\73- Fix CVE-2018-15127 (Heap out-of-bounds write in
  rfbserver.c:rfbProcessFileTransferReadBuffer()) (bug #1662996)
!\k%JAndreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk[iqJAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspZiyJAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewYkJIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
oydowckKIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvbkKIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgaiiKAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3`k}KIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh_ikKAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16^kJAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock]kJAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
gkKAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockfk%KAndreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskeiqKAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspdiyKAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%pliyLAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewkkLIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvjkLIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiiLAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequireshkKAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
1~1gsiiMAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requirescrk_LAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pqkwLAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicespkLAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockokLAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode locknk%LAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskmiqLAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
xk%MAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskwiqMAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspviyMAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewukMIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvtkMIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DC
yw}kNIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagc|k_MAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p{kwMAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceszkMAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockykMAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
kNAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%NAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqNAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp~iyNAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
PzIPwkOIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagzkNAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7NAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_NAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwNAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskNAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock

er+V:eD[
08fdefbdb8f11e74afa450cfe88c2d98b1e9caee0e6a213c4b67db47d4ca1dc5DZ
a95af012a17347465a1f54e59f082ac490eff08433bede126e69f5fccf682f37DY
9ec3b65cf753a77c4da092b4e68ecba78c87b41489cc86c51a071e27221c1008DX
40d5b25bdbe536d2fd38b5b64869d82f574e42b8d756e38bc4d749bdf8f6ffe6DW
5c42cdde11e5b38683d6da4d90fd10c1431b5c27c563bd4b7bdcf251800b7272DV
7ffe1e93feefa9f0a3fb660a77c95541359f3947d165e16a808a69bd327b5ca9DU
e5f77930d5fc1f574da19410b3b247527067731d9fcb73c1449994d5079c56cbDT
fa3eac9fbdec92e915947210c7b62dd3bc17f62bd80edc537b07d378a58418d5DS
10da91e17808a066fabc928e609db5fd20fe65299ed6b8fa0337fe213a70cb21DR
283e32e5ae51636ccebdf22a1c2c394d89be5d20c981cb3d22cd9353e90c3fbaDQ
4d7880fbe60e6c8b83c4e01347b5e9ad274f8eee38feee4a3d7c3f8410c561aeDP
7a5d98b836fb6cbb743996d5dd4c13cd9fe0b108498811fbc5ccf1dafa7797efDO
3fc9b311cc6984896d03711ca684b967577d4370b4c5b037efe81245cfc9a5f2
kOAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
k%OAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk	iqOAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyOAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzkOAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7OAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_OAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p
kwOAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskOAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kPAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%PAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqPAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyPAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagebR-RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{,k,n,p,u,x,|,,,,	,,,,,,,,‚ ,Â",Ă%,ł',Ƃ*,ǂ-,Ȃ2,ɂ:,ʂ=,˂D,̂G,͂N,΂Q,ςX,Ђ\,тc,҂g,ӂl,Ԃs,Ղx,ւ},ׂ,؂,ڂ,ۂ,܂,ނ,߂,#,ႛ(,ₛ-,゛3,䂛8,傛>,悛D,炛I,肛N,邛T,ꂛZ,낛`,삛e,킛l,r,y,,,,,,,#,*,.,3,7,=,A,E,I-O-S-X-\-a-e-k-p-u-	{-
------"-(---4-:-A
zIzkPAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7PAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_PAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwPAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskPAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
k%QAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqQAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyQAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage{k
PAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
DyDz#kQAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP"k7QAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc!k_QAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p kwQAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskQAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkQAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
~(kRAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock'kRAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock&k%RAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk%iqRAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{$k
QAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{-k
RAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z,kRAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP+k7RAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc*k_RAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p)kwRAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
IFK>Ip3kwSAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services2kSAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock1kSAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock0k%SAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk/iqSAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks5.kRAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
FF58kSAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{7k
SAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z6kSAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP5k7SAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc4k_SAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
6tgr6P>k7TAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc=k_TAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p<kwTAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services;kTAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock:kTAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock9k%TAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
@S@DkUAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockCk%UAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesqBk{TAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5AkTAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{@k
TAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z?kTAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
zIzIkUAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePHk7UAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcGk_UAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pFkwUAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesEkUAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
VFKVpNkwVAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesMkVAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockqLk{UAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5KkUAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Jk
UAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
FFqTk{VAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5SkVAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Rk
VAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zQkVAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePPk7VAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcOk_VAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
d9dPZk7WAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcYk_WAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pXkwWAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesWkWAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockzVkVAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cUk_VAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023
nSnz`kWAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c_k_WAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q^k{WAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5]kWAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{\k
WAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z[kWAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
QQQ{ek
XAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zdkXAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePck7XAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcbk_XAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pakwXAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
Fjvclk_YAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkkwYAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesrjk}XAndreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zikXAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023chk_XAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qgk{XAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5fkXAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
+~crk_YAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qqk{YAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5pkYAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{ok
YAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142znkYAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePmk7YAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
Z8ZmyiuZAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiximZAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUwiEZAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|vkZIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHELvuiZAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrtk}YAndreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zskYAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023
q|vi[Andreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesw~kZIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv}kZIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg|iiZAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3{k}ZIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhzikZAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16
@'I%@vk[Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgii[Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}[Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhik[Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16miu[Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiim[Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiE[Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|k[Isaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*Evk\Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgii\Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3
k}\Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhik\Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16miu\Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi
im\Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU	iE\Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wk[Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag

er+V:eDh
54284e0ce96588259af1165cabdb431f59b260e11eaa00817d54fe6be8d00a8cDg
ae30c015a383c2eb423b88776090420304ae65174ef0ecf4eb34bd608148c79cDf
0f50b27c447626e536dd1b872545c9247a7634a66cb5763f417cbc9eea4790d8De
b9c8fac8c6b10a87a024279c0ecef2ddf68ea3c55076d9478ee93b3ba8bfc5c0Dd
092200d5b5dde09d6818651bad72eaf924bc014da7f290860fa9416ca5d80c29Dc
39b34f1245a4dd4e09703d7a8fa93bb27414f909eb7514764f934e9248878ee3Db
09cd4a65244763f9c5d860969f9294414316cc0b7472539300921b5021a3a048Da
0106c00d777327c471f8f9e676017d61dd0e5e5b4fe97750869b7857f0838ba2D`
9d699056a31b7a651cd7680f41d92d78ae727215dd9dce336447373fd00a7bc6D_
8134bb4793d96d74f2db411ef17a6b86bcdf3847073ba2f4a8d8e89bc0d849c6D^
b534be5ce2fdd42fba4271d4bfc8275f8788cc729ebeb59920e58209b92fbf2eD]
d8ad0a7ee2c7b587dabb291d73d00b779874822a850485d9db4e31f1e20bc562D\
5471f87193fdfe4646e6c6f388c9c498da8ede8ccdcade0353ee7503e8299e9c
[![iim]Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiE]Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057kiq\Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiy\Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewk\Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
#kwk]Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvk]Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgii]Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}]Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhik]Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16miu]Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal users
x0x3k}^Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhik^Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kiq]Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiy]Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
<<k#iq^Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp"iy^Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew!k^Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv k^Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgii^Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires
^tgC^v*k_Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg)ii_Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3(k}_Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh'ik_Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16&k^Andreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock%k^Andreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock$k%^Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
!.k%_Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk-iq_Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp,iy_Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew+k_Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
yw3k`Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv2k`Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg1ii`Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires0k_Andreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock/k_Andreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
7k`Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock6k%`Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk5iq`Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp4iy`Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
z9w=kaIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv<kaIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg;iiaAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requiresc:k_`Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p9kw`Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services8k`Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
AkaAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock@k%aAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk?iqaAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp>iyaAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zwEkbIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagcDk_aAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pCkwaAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesBkaAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
IkbAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockHk%bAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskGiqbAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspFiybAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
PzIPwOkcIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagzNkbAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePMk7bAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcLk_bAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pKkwbAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesJkbAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
SkcAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockRk%cAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskQiqcAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspPiycAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzXkcAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePWk7cAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcVk_cAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pUkwcAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesTkcAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
\kdAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock[k%dAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskZiqdAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspYiydAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzakdAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP`k7dAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc_k_dAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p^kwdAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services]kdAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
ek%eAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskdiqeAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspciyeAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage{bk
dAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
DyDzkkeAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePjk7eAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcik_eAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254phkweAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesgkeAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockfkeAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
~pkfAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockokfAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode locknk%fAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskmiqfAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{lk
eAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{uk
fAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142ztkfAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePsk7fAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcrk_fAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pqkwfAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
IFK>Ip{kwgAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceszkgAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockykgAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockxk%gAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskwiqgAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks5vkfAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
FF5kgAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
gAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z~kgAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP}k7gAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc|k_gAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
6tgr6Pk7hAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_hAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwhAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskhAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkhAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%hAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
@S@kiAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%iAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesq
k{hAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5	khAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
hAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkhAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role

er+V:eDu
d06f004563a6bdeb574cc83ae16bbfda190879efa994a9182b24e45eafe5a039Dt
8050b0ef335b05d786d15521243cec669562d6625e4d80db07c84aec1e66d0a3Ds
6b870279912b279a310ff11d1024fd1270f6693d8f6ed22ad211f11ac56455c6Dr
bf010b9168523d32bd2cae3bab71cda19cb9e2d00bbb861630c256f5c6b49d70Dq
a68ecf7a99623031de79e1da0b60b7029a5516edf54ccc1462cf363187b5fb3aDp
fd640f5804c8bb45a16b7f00fef1ce4a1ec58f5ce9fb6650e9d98fa6c316fcd7Do
bcaf6c4cc70c53cf9b6f0220af4a968ffc131c6372bbda67e1ad799972341b5dDn
6b2d3f3ea7403045cab9e0c8644c832cd7c229b54f24e41a1e5e35eebd699e08Dm
1c92e98be2e233ea55c194d01aa73ed4184d0ef0f92f289e7070396b6ea55cf5Dl
5bc9838767e0c9e764e7008304015cb982d5e4e37860284948034ef17d6c3b41Dk
e84733a2c4b6d0f60e70451f27a7c82164f2fa899abad53af1c69553175d5411Dj
8b7baa93242958102343838092c3c8f2c9699b186e25f62b224a2810946a81d4Di
b444f8f9031836d93018190b4da5a39d69dff36187e399dfc8ea308d2398757c
zIzkiAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7iAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_iAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwiAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
kiAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
VFKVpkwjAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskjAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockqk{iAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kiAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
iAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
FFqk{jAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kjAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
jAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkjAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7jAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_jAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
d9dP"k7kAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc!k_kAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p kwkAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockzkjAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023ck_jAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023
nSnz(kkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c'k_kAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q&k{kAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5%kkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{$k
kAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z#kkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
QQQ{-k
lAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z,klAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP+k7lAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc*k_lAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p)kwlAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
Fjvc4k_mAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p3kwmAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesr2k}lAndreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z1klAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c0k_lAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q/k{lAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5.klAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
+~c:k_mAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q9k{mAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind58kmAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{7k
mAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z6kmAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP5k7mAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
Z8ZmAiunAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi@imnAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU?iEnAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|>knIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHELv=inAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesr<k}mAndreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z;kmAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023
q|vGioAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directorieswFknIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvEknIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgDiinAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Ck}nIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhBiknAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16
@'I%@vOkoIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgNiioAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Mk}oIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhLikoAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mKiuoAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiJimoAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUIiEoAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|HkoIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*EvWkpIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgViipAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Uk}pIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhTikpAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mSiupAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiRimpAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUQiEpAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wPkoIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
[![i\imqAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU[iEqAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057kZiqpAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspYiypAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewXkpIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
#kwbkqIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvakqIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg`iiqAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3_k}qIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh^ikqAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m]iuqAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal users
>frFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.1-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildZeY_rAdam Tkac <atkac redhat com> - 0.2.1-2P9@- rebuild due to "jpeg8-ABI" feature dropkdiqqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspciyqAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
Xw';XvnmrMartin Stransky <stransky@redhat.com> - 0.3.0-10`Z- Added fixes for rhbz#1956829, rhbz#1956843, rhbz#1956919emkcrMartin Stransky <stransky@redhat.com> - 0.3.0-7X+- Added libwebp dependency to libwebp-toolsClkrMartin Stransky <stransky@redhat.com> - 0.3.0-6X+- Rebuilt kc_rJaromir Capik <jcapik@redhat.com> - 0.3.0-5T;- Removing __PPC__ macro conflicting with __BYTE_ORDER__ endian check (#1127230)
- Resolves: rhbz#1127230Lji3rPeter Robinson <pbrobinson@redhat.com> 0.3.0-4S- Fix ppc64le buildLi]?rDaniel Mach <dmach@redhat.com> - 0.3.0-3RU- Mass rebuild 2014-01-24Lh]?rDaniel Mach <dmach@redhat.com> - 0.3.0-2Rk- Mass rebuild 2013-12-27dgwSrRahul Sundaram <sundaram@fedoraproject.org> - 0.3.0-1Q- upstream release 0.3.0
- enable gif2webp
- add build requires on giflib-devel and libtiff-devel
- use make_install and hardened macros
- list binaries explicitly
B~.BCvksMartin Stransky <stransky@redhat.com> - 0.3.0-6X+- Rebuilt uc_sJaromir Capik <jcapik@redhat.com> - 0.3.0-5T;- Removing __PPC__ macro conflicting with __BYTE_ORDER__ endian check (#1127230)
- Resolves: rhbz#1127230Lti3sPeter Robinson <pbrobinson@redhat.com> 0.3.0-4S- Fix ppc64le buildLs]?sDaniel Mach <dmach@redhat.com> - 0.3.0-3RU- Mass rebuild 2014-01-24Lr]?sDaniel Mach <dmach@redhat.com> - 0.3.0-2Rk- Mass rebuild 2013-12-27dqwSsRahul Sundaram <sundaram@fedoraproject.org> - 0.3.0-1Q- upstream release 0.3.0
- enable gif2webp
- add build requires on giflib-devel and libtiff-devel
- use make_install and hardened macros
- list binaries explicitlypsFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.1-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildZoY_sAdam Tkac <atkac redhat com> - 0.2.1-2P9@- rebuild due to "jpeg8-ABI" feature drop
IL}i3tPeter Robinson <pbrobinson@redhat.com> 0.3.0-4S- Fix ppc64le buildL|]?tDaniel Mach <dmach@redhat.com> - 0.3.0-3RU- Mass rebuild 2014-01-24L{]?tDaniel Mach <dmach@redhat.com> - 0.3.0-2Rk- Mass rebuild 2013-12-27dzwStRahul Sundaram <sundaram@fedoraproject.org> - 0.3.0-1Q- upstream release 0.3.0
- enable gif2webp
- add build requires on giflib-devel and libtiff-devel
- use make_install and hardened macros
- list binaries explicitlyytFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.1-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildvxmsMartin Stransky <stransky@redhat.com> - 0.3.0-10`Z- Added fixes for rhbz#1956829, rhbz#1956843, rhbz#1956919ewkcsMartin Stransky <stransky@redhat.com> - 0.3.0-7X+- Added libwebp dependency to libwebp-tools
R[1;RdwSuRahul Sundaram <sundaram@fedoraproject.org> - 0.3.0-1Q- upstream release 0.3.0
- enable gif2webp
- add build requires on giflib-devel and libtiff-devel
- use make_install and hardened macros
- list binaries explicitlyuFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.1-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildWmEtMartin Stransky <stransky@redhat.com> - 0.3.0-11dI@- Added fix for mzbz#1819244vmtMartin Stransky <stransky@redhat.com> - 0.3.0-10`Z- Added fixes for rhbz#1956829, rhbz#1956843, rhbz#1956919ekctMartin Stransky <stransky@redhat.com> - 0.3.0-7X+- Added libwebp dependency to libwebp-toolsCktMartin Stransky <stransky@redhat.com> - 0.3.0-6X+- Rebuilt ~c_tJaromir Capik <jcapik@redhat.com> - 0.3.0-5T;- Removing __PPC__ macro conflicting with __BYTE_ORDER__ endian check (#1127230)
- Resolves: rhbz#1127230
	`k$AZ
Y_vAdam Tkac <atkac redhat com> - 0.2.1-2P9@- rebuild due to "jpeg8-ABI" feature dropWmEuMartin Stransky <stransky@redhat.com> - 0.3.0-11dI@- Added fix for mzbz#1819244vmuMartin Stransky <stransky@redhat.com> - 0.3.0-10`Z- Added fixes for rhbz#1956829, rhbz#1956843, rhbz#1956919e
kcuMartin Stransky <stransky@redhat.com> - 0.3.0-7X+- Added libwebp dependency to libwebp-toolsC	kuMartin Stransky <stransky@redhat.com> - 0.3.0-6X+- Rebuilt c_uJaromir Capik <jcapik@redhat.com> - 0.3.0-5T;- Removing __PPC__ macro conflicting with __BYTE_ORDER__ endian check (#1127230)
- Resolves: rhbz#1127230Li3uPeter Robinson <pbrobinson@redhat.com> 0.3.0-4S- Fix ppc64le buildL]?uDaniel Mach <dmach@redhat.com> - 0.3.0-3RU- Mass rebuild 2014-01-24L]?uDaniel Mach <dmach@redhat.com> - 0.3.0-2Rk- Mass rebuild 2013-12-27

er+V:eD
6e1413f213a7c818dc679fc121435a30906e97b4db03211f3cd23acf9e35b88bD
36fd57be259185c71e4768b2cd69c293e89e53afca9359f3a04c397ebb715d25D
2ba1457373a2cd07d465b437c0f82ad35d9f1c92a7e5ea5465b0e3d4ea9a3c0dD
bf786f7803813a8167ec504e8216dcf9372e8a7df9b4c38050d1db3b93509cd7D~
1f886544574d6a8eab00de815966c7ca8a7292ab3a2ac66dcb19ce07dcdf04e0D}
f057ce5463bca14d6bab2c699782e32341b1b37571dc5466905db2fca2c1b392D|
45e9a1e7f70a5fd4ccd35c605d9412dad9cba3c4602e350da0bd341a6d217b42D{
722b0dc706f7600d25c378ec61ab127376170d2f1df9446acfb02d438beb9e18Dz
0c7bc243b0e57280cd7bdd324734b2af9b6ea05f5309af24c0897ceb134b9ffeDy
2f075ce3d7df67323ba3022b428490fb252d7a5759a81d0f53e6570ba24dd777Dx
18e4458c6be87d024a157c9233b2f318b21378e4939151e17d4d302d944b059bDw
59270b3d96c02888cb8fd34bca5e596de497c24051804658439170f2d9e36fdaDv
3d78c1d5498c9bcf2b022b55d7e3cace4f911eb0bf74758e0eaf4a756e5f831b
7e|,7ekcvMartin Stransky <stransky@redhat.com> - 0.3.0-7X+- Added libwebp dependency to libwebp-toolsCkvMartin Stransky <stransky@redhat.com> - 0.3.0-6X+- Rebuilt c_vJaromir Capik <jcapik@redhat.com> - 0.3.0-5T;- Removing __PPC__ macro conflicting with __BYTE_ORDER__ endian check (#1127230)
- Resolves: rhbz#1127230Li3vPeter Robinson <pbrobinson@redhat.com> 0.3.0-4S- Fix ppc64le buildL]?vDaniel Mach <dmach@redhat.com> - 0.3.0-3RU- Mass rebuild 2014-01-24L]?vDaniel Mach <dmach@redhat.com> - 0.3.0-2Rk- Mass rebuild 2013-12-27dwSvRahul Sundaram <sundaram@fedoraproject.org> - 0.3.0-1Q- upstream release 0.3.0
- enable gif2webp
- add build requires on giflib-devel and libtiff-devel
- use make_install and hardened macros
- list binaries explicitlyvFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.1-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
(TLi3wPeter Robinson <pbrobinson@redhat.com> 0.3.0-4S- Fix ppc64le buildL]?wDaniel Mach <dmach@redhat.com> - 0.3.0-3RU- Mass rebuild 2014-01-24L]?wDaniel Mach <dmach@redhat.com> - 0.3.0-2Rk- Mass rebuild 2013-12-27dwSwRahul Sundaram <sundaram@fedoraproject.org> - 0.3.0-1Q- upstream release 0.3.0
- enable gif2webp
- add build requires on giflib-devel and libtiff-devel
- use make_install and hardened macros
- list binaries explicitlywFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.1-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildZY_wAdam Tkac <atkac redhat com> - 0.2.1-2P9@- rebuild due to "jpeg8-ABI" feature dropvmvMartin Stransky <stransky@redhat.com> - 0.3.0-10`Z- Added fixes for rhbz#1956829, rhbz#1956843, rhbz#1956919
][1]L#]?xDaniel Mach <dmach@redhat.com> - 0.3.0-2Rk- Mass rebuild 2013-12-27d"wSxRahul Sundaram <sundaram@fedoraproject.org> - 0.3.0-1Q- upstream release 0.3.0
- enable gif2webp
- add build requires on giflib-devel and libtiff-devel
- use make_install and hardened macros
- list binaries explicitly!xFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.1-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuildv mwMartin Stransky <stransky@redhat.com> - 0.3.0-10`Z- Added fixes for rhbz#1956829, rhbz#1956843, rhbz#1956919ekcwMartin Stransky <stransky@redhat.com> - 0.3.0-7X+- Added libwebp dependency to libwebp-toolsCkwMartin Stransky <stransky@redhat.com> - 0.3.0-6X+- Rebuilt c_wJaromir Capik <jcapik@redhat.com> - 0.3.0-5T;- Removing __PPC__ macro conflicting with __BYTE_ORDER__ endian check (#1127230)
- Resolves: rhbz#1127230
`t6+yFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.1-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildW*mExMartin Stransky <stransky@redhat.com> - 0.3.0-11dI@- Added fix for mzbz#1819244v)mxMartin Stransky <stransky@redhat.com> - 0.3.0-10`Z- Added fixes for rhbz#1956829, rhbz#1956843, rhbz#1956919e(kcxMartin Stransky <stransky@redhat.com> - 0.3.0-7X+- Added libwebp dependency to libwebp-toolsC'kxMartin Stransky <stransky@redhat.com> - 0.3.0-6X+- Rebuilt &c_xJaromir Capik <jcapik@redhat.com> - 0.3.0-5T;- Removing __PPC__ macro conflicting with __BYTE_ORDER__ endian check (#1127230)
- Resolves: rhbz#1127230L%i3xPeter Robinson <pbrobinson@redhat.com> 0.3.0-4S- Fix ppc64le buildL$]?xDaniel Mach <dmach@redhat.com> - 0.3.0-3RU- Mass rebuild 2014-01-24
Xw';Xv3myMartin Stransky <stransky@redhat.com> - 0.3.0-10`Z- Added fixes for rhbz#1956829, rhbz#1956843, rhbz#1956919e2kcyMartin Stransky <stransky@redhat.com> - 0.3.0-7X+- Added libwebp dependency to libwebp-toolsC1kyMartin Stransky <stransky@redhat.com> - 0.3.0-6X+- Rebuilt 0c_yJaromir Capik <jcapik@redhat.com> - 0.3.0-5T;- Removing __PPC__ macro conflicting with __BYTE_ORDER__ endian check (#1127230)
- Resolves: rhbz#1127230L/i3yPeter Robinson <pbrobinson@redhat.com> 0.3.0-4S- Fix ppc64le buildL.]?yDaniel Mach <dmach@redhat.com> - 0.3.0-3RU- Mass rebuild 2014-01-24L-]?yDaniel Mach <dmach@redhat.com> - 0.3.0-2Rk- Mass rebuild 2013-12-27d,wSyRahul Sundaram <sundaram@fedoraproject.org> - 0.3.0-1Q- upstream release 0.3.0
- enable gif2webp
- add build requires on giflib-devel and libtiff-devel
- use make_install and hardened macros
- list binaries explicitly
.Gs#. ;c_zJaromir Capik <jcapik@redhat.com> - 0.3.0-5T;- Removing __PPC__ macro conflicting with __BYTE_ORDER__ endian check (#1127230)
- Resolves: rhbz#1127230L:i3zPeter Robinson <pbrobinson@redhat.com> 0.3.0-4S- Fix ppc64le buildL9]?zDaniel Mach <dmach@redhat.com> - 0.3.0-3RU- Mass rebuild 2014-01-24L8]?zDaniel Mach <dmach@redhat.com> - 0.3.0-2Rk- Mass rebuild 2013-12-27d7wSzRahul Sundaram <sundaram@fedoraproject.org> - 0.3.0-1Q- upstream release 0.3.0
- enable gif2webp
- add build requires on giflib-devel and libtiff-devel
- use make_install and hardened macros
- list binaries explicitly6zFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.1-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildZ5Y_zAdam Tkac <atkac redhat com> - 0.2.1-2P9@- rebuild due to "jpeg8-ABI" feature dropW4mEyMartin Stransky <stransky@redhat.com> - 0.3.0-11dI@- Added fix for mzbz#1819244
bP;RbLCi3{Peter Robinson <pbrobinson@redhat.com> 0.3.0-4S- Fix ppc64le buildLB]?{Daniel Mach <dmach@redhat.com> - 0.3.0-3RU- Mass rebuild 2014-01-24LA]?{Daniel Mach <dmach@redhat.com> - 0.3.0-2Rk- Mass rebuild 2013-12-27d@wS{Rahul Sundaram <sundaram@fedoraproject.org> - 0.3.0-1Q- upstream release 0.3.0
- enable gif2webp
- add build requires on giflib-devel and libtiff-devel
- use make_install and hardened macros
- list binaries explicitly?{Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.1-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuildv>mzMartin Stransky <stransky@redhat.com> - 0.3.0-10`Z- Added fixes for rhbz#1956829, rhbz#1956843, rhbz#1956919e=kczMartin Stransky <stransky@redhat.com> - 0.3.0-7X+- Added libwebp dependency to libwebp-toolsC<kzMartin Stransky <stransky@redhat.com> - 0.3.0-6X+- Rebuilt
[1xJ|Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.1-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildZIY_|Adam Tkac <atkac redhat com> - 0.2.1-2P9@- rebuild due to "jpeg8-ABI" feature dropWHmE{Martin Stransky <stransky@redhat.com> - 0.3.0-11dI@- Added fix for mzbz#1819244vGm{Martin Stransky <stransky@redhat.com> - 0.3.0-10`Z- Added fixes for rhbz#1956829, rhbz#1956843, rhbz#1956919eFkc{Martin Stransky <stransky@redhat.com> - 0.3.0-7X+- Added libwebp dependency to libwebp-toolsCEk{Martin Stransky <stransky@redhat.com> - 0.3.0-6X+- Rebuilt Dc_{Jaromir Capik <jcapik@redhat.com> - 0.3.0-5T;- Removing __PPC__ macro conflicting with __BYTE_ORDER__ endian check (#1127230)
- Resolves: rhbz#1127230
Xw';XvRm|Martin Stransky <stransky@redhat.com> - 0.3.0-10`Z- Added fixes for rhbz#1956829, rhbz#1956843, rhbz#1956919eQkc|Martin Stransky <stransky@redhat.com> - 0.3.0-7X+- Added libwebp dependency to libwebp-toolsCPk|Martin Stransky <stransky@redhat.com> - 0.3.0-6X+- Rebuilt Oc_|Jaromir Capik <jcapik@redhat.com> - 0.3.0-5T;- Removing __PPC__ macro conflicting with __BYTE_ORDER__ endian check (#1127230)
- Resolves: rhbz#1127230LNi3|Peter Robinson <pbrobinson@redhat.com> 0.3.0-4S- Fix ppc64le buildLM]?|Daniel Mach <dmach@redhat.com> - 0.3.0-3RU- Mass rebuild 2014-01-24LL]?|Daniel Mach <dmach@redhat.com> - 0.3.0-2Rk- Mass rebuild 2013-12-27dKwS|Rahul Sundaram <sundaram@fedoraproject.org> - 0.3.0-1Q- upstream release 0.3.0
- enable gif2webp
- add build requires on giflib-devel and libtiff-devel
- use make_install and hardened macros
- list binaries explicitly
7e|,7eZkc}Martin Stransky <stransky@redhat.com> - 0.3.0-7X+- Added libwebp dependency to libwebp-toolsCYk}Martin Stransky <stransky@redhat.com> - 0.3.0-6X+- Rebuilt Xc_}Jaromir Capik <jcapik@redhat.com> - 0.3.0-5T;- Removing __PPC__ macro conflicting with __BYTE_ORDER__ endian check (#1127230)
- Resolves: rhbz#1127230LWi3}Peter Robinson <pbrobinson@redhat.com> 0.3.0-4S- Fix ppc64le buildLV]?}Daniel Mach <dmach@redhat.com> - 0.3.0-3RU- Mass rebuild 2014-01-24LU]?}Daniel Mach <dmach@redhat.com> - 0.3.0-2Rk- Mass rebuild 2013-12-27dTwS}Rahul Sundaram <sundaram@fedoraproject.org> - 0.3.0-1Q- upstream release 0.3.0
- enable gif2webp
- add build requires on giflib-devel and libtiff-devel
- use make_install and hardened macros
- list binaries explicitlyS}Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.2.1-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
%+O&%|be~Ondrej Holy <oholy@redhat.com> - 2.0.0-4.rc4^- CVE-2020-11521: Fix out-of-bounds write in planar.c (#1837621)
- CVE-2020-11523: Fix integer overflow in region.c (#1837622)
- CVE-2020-11524: Fix out-of-bounds write in interleaved.c (#1837623)gaem~Ondrej Holy <oholy@redhat.com> - 2.0.0-2.rc4^@- Fix SCARD_INSUFFICIENT_BUFFER error (#1765199)W`eM~Ondrej Holy <oholy@redhat.com> - 2.0.0-1.rc4\mA@- Update to 2.0.0-rc4 (#1291254)___c~Ondrej Holy <oholy@redhat.com> - 1.0.2-15Zq- Fix smartcard usage in manpage (#1428041)V^_Q~Ondrej Holy <oholy@redhat.com> - 1.0.2-14Z@- Add FIPS mode support (#1363811)~]_~Ondrej Holy <oholy@redhat.com> - 1.0.2-13Y- Fix NTLM on big endian (#1204742)
- Fix colors on big endian (#1308810)W\mE}Martin Stransky <stransky@redhat.com> - 0.3.0-11dI@- Added fix for mzbz#1819244v[m}Martin Stransky <stransky@redhat.com> - 0.3.0-10`Z- Added fixes for rhbz#1956829, rhbz#1956843, rhbz#1956919
	$,)M$gkemOndrej Holy <oholy@redhat.com> - 2.0.0-2.rc4^@- Fix SCARD_INSUFFICIENT_BUFFER error (#1765199)WjeMOndrej Holy <oholy@redhat.com> - 2.0.0-1.rc4\mA@- Update to 2.0.0-rc4 (#1291254)_i_cOndrej Holy <oholy@redhat.com> - 1.0.2-15Zq- Fix smartcard usage in manpage (#1428041)Vh_QOndrej Holy <oholy@redhat.com> - 1.0.2-14Z@- Add FIPS mode support (#1363811)~g_Ondrej Holy <oholy@redhat.com> - 1.0.2-13Y- Fix NTLM on big endian (#1204742)
- Fix colors on big endian (#1308810)fgC~Jan Grulich <jgrulich@redhat.com> - 2:2.2.0-5ab- Update: Refactored RPC gateway parser (rhbz#2017944)
  + fix issues discovered by Covscanfegi~Jan Grulich <jgrulich@redhat.com> - 2:2.2.0-4a@- Refactored RPC gateway parser (rhbz#2017944)}dg~Felipe Borges <feborges@redhat.com> - 2.1.1-3a- Add checks for bitmap and glyph width/heigth values (rhbz#2017951)Oc]E~Ondrej Holy <oholy@redhat.com> - 2.1.1-2^˳@- Update to 2.1.1 (#1834286)
L+(LVr_QOndrej Holy <oholy@redhat.com> - 1.0.2-14Z@- Add FIPS mode support (#1363811)~q_Ondrej Holy <oholy@redhat.com> - 1.0.2-13Y- Fix NTLM on big endian (#1204742)
- Fix colors on big endian (#1308810)pgCJan Grulich <jgrulich@redhat.com> - 2:2.2.0-5ab- Update: Refactored RPC gateway parser (rhbz#2017944)
  + fix issues discovered by CovscanfogiJan Grulich <jgrulich@redhat.com> - 2:2.2.0-4a@- Refactored RPC gateway parser (rhbz#2017944)}ngFelipe Borges <feborges@redhat.com> - 2.1.1-3a- Add checks for bitmap and glyph width/heigth values (rhbz#2017951)Om]EOndrej Holy <oholy@redhat.com> - 2.1.1-2^˳@- Update to 2.1.1 (#1834286)|leOndrej Holy <oholy@redhat.com> - 2.0.0-4.rc4^- CVE-2020-11521: Fix out-of-bounds write in planar.c (#1837621)
- CVE-2020-11523: Fix integer overflow in region.c (#1837622)
- CVE-2020-11524: Fix out-of-bounds write in interleaved.c (#1837623)
BfygiJan Grulich <jgrulich@redhat.com> - 2:2.2.0-4a@- Refactored RPC gateway parser (rhbz#2017944)}xgFelipe Borges <feborges@redhat.com> - 2.1.1-3a- Add checks for bitmap and glyph width/heigth values (rhbz#2017951)Ow]EOndrej Holy <oholy@redhat.com> - 2.1.1-2^˳@- Update to 2.1.1 (#1834286)|veOndrej Holy <oholy@redhat.com> - 2.0.0-4.rc4^- CVE-2020-11521: Fix out-of-bounds write in planar.c (#1837621)
- CVE-2020-11523: Fix integer overflow in region.c (#1837622)
- CVE-2020-11524: Fix out-of-bounds write in interleaved.c (#1837623)guemOndrej Holy <oholy@redhat.com> - 2.0.0-2.rc4^@- Fix SCARD_INSUFFICIENT_BUFFER error (#1765199)WteMOndrej Holy <oholy@redhat.com> - 2.0.0-1.rc4\mA@- Update to 2.0.0-rc4 (#1291254)_s_cOndrej Holy <oholy@redhat.com> - 1.0.2-15Zq- Fix smartcard usage in manpage (#1428041)
ag(ba|eOndrej Holy <oholy@redhat.com> - 2.0.0-4.rc4^- CVE-2020-11521: Fix out-of-bounds write in planar.c (#1837621)
- CVE-2020-11523: Fix integer overflow in region.c (#1837622)
- CVE-2020-11524: Fix out-of-bounds write in interleaved.c (#1837623)gemOndrej Holy <oholy@redhat.com> - 2.0.0-2.rc4^@- Fix SCARD_INSUFFICIENT_BUFFER error (#1765199)W~eMOndrej Holy <oholy@redhat.com> - 2.0.0-1.rc4\mA@- Update to 2.0.0-rc4 (#1291254)_}_cOndrej Holy <oholy@redhat.com> - 1.0.2-15Zq- Fix smartcard usage in manpage (#1428041)V|_QOndrej Holy <oholy@redhat.com> - 1.0.2-14Z@- Add FIPS mode support (#1363811)~{_Ondrej Holy <oholy@redhat.com> - 1.0.2-13Y- Fix NTLM on big endian (#1204742)
- Fix colors on big endian (#1308810)zgCJan Grulich <jgrulich@redhat.com> - 2:2.2.0-5ab- Update: Refactored RPC gateway parser (rhbz#2017944)
  + fix issues discovered by Covscan
,)bL]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24ikkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068L]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27skDaniel Veillard <veillard@redhat.com> - 2.9.1-2R- Fix a regression in xmlGetDocCompressMode() rhbz#963716gCJan Grulich <jgrulich@redhat.com> - 2:2.2.0-5ab- Update: Refactored RPC gateway parser (rhbz#2017944)
  + fix issues discovered by CovscanfgiJan Grulich <jgrulich@redhat.com> - 2:2.2.0-4a@- Refactored RPC gateway parser (rhbz#2017944)}gFelipe Borges <feborges@redhat.com> - 2.1.1-3a- Add checks for bitmap and glyph width/heigth values (rhbz#2017951)O]EOndrej Holy <oholy@redhat.com> - 2.1.1-2^˳@- Update to 2.1.1 (#1834286)
oe
kaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patch	o+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)
//Lo+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memoryad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
*Zd*skDaniel Veillard <veillard@redhat.com> - 2.9.1-2R- Fix a regression in xmlGetDocCompressMode() rhbz#963716>_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)q
_David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715)5Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre-5

er+V:eD
88425ec1660289732da5de1bf61433d763b6a1dd261bd1f618a21bbad1e482ebD
84429c34c87f336378bdb26019944d56abac80c14e6c4ee130584e9a6b1042d3D

c62e34aa51c1c89400b007376b014e42f551c284ffea7d077883fb2cf5673bd8D
24b248d1220fef75f61061cd2400aad329970e06b2f254507cdd35348d968aa0D
0448f0190f604f767981ff4c96e3e9210bc3ec57cf905b9c65ce31bcbdb59db6D

a0c3a8dbbc209a90df3f8f2185925585b61c9809b9f26c087201f7c8d64a1f05D	
e5f363f81639b222cd478b35c882cd06eecb2b8e8876f3e80dd3d85c8a6198a2D
fffcdd496e8017e9a7bb4fdc0e4a0d7e1b98c54d5f9dabf43b01870bbb14d79eD
d424fac47526dc6b037adfd66b2ff2ba1e1395086399d34a1b862222e961c079D
bede65036dfee6105ded35adb1c299002018a1016e9efd4163446d8e6a92bfccD
ffdb0e908ca8cc9013d59da38b6a5d9d04ea15e6af25a38508bc92e04af68500D
9c739eecd603856d78884d350c8dd6ede946fc361bbe142177f439da852cc952D
865bb89dcd4d8816e485ab34a083b55c7d4056ac265766974695a87da62d8aee
xCbxekaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patcho+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)L]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24ikkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068L]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27
//Lo+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memoryad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
QZdQL]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27>_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)q_David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715)5Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre-:
CekaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patcho+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)L]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24ikkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068
//Lo+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memoryad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
KZdKR"_IDavid King <dking@redhat.com> - 2.9.1-6.6aQ@- Fix CVE-2016-4658 (#1966916)>!_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)q _David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715)5Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre->
xCbxe'kaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patch&o+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)L%]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24i$kkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068L#]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27
//L(o+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memoryad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
KZdKR,_IDavid King <dking@redhat.com> - 2.9.1-6.6aQ@- Fix CVE-2016-4658 (#1966916)>+_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)q*_David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715))5Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre-B
9|e2kaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patch1o+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)L0]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24i/kkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068L.]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27s-kDaniel Veillard <veillard@redhat.com> - 2.9.1-2R- Fix a regression in xmlGetDocCompressMode() rhbz#963716
//L3o+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memoryad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
*Zd*s7kDaniel Veillard <veillard@redhat.com> - 2.9.1-2R- Fix a regression in xmlGetDocCompressMode() rhbz#963716>6_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)q5_David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715)45Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre-F
xCbxe<kaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patch;o+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)L:]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24i9kkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068L8]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27
//L=o+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memorybR-RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{-O-W-\-b-f-n-v-}- -!
-#-$-%#-&+-'3-(;-)C-*J-+R-,Z--b-.k-/r-0y-1-2-3
-4-6-8-9-;-<-=-?"-@'-A(-C,-D2-E3-G7-H<-I=-LA-ME-NF-PJ-QO-RP-TT-UZ-V[-X_-Yc-Zd-\h-]n-^o-`s-ax-by-d}-e-f-h-i-j-l-n-o-p-q#-r'-s--t3-u8-v>-wC-xJ-yQ-zY-{`-|h-}n-~s-x-}------- -%-,-4-:ad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
QZdQLA]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27>@_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)q?_David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715)>5Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre-K
CeEkaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patchDo+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)LC]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24iBkkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068
//LFo+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memoryad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
KZdKRJ_IDavid King <dking@redhat.com> - 2.9.1-6.6aQ@- Fix CVE-2016-4658 (#1966916)>I_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)qH_David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715)G5Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre-O
xCbxeOkaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patchNo+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)LM]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24iLkkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068LK]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27
//LPo+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memoryad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
KZdKRT_IDavid King <dking@redhat.com> - 2.9.1-6.6aQ@- Fix CVE-2016-4658 (#1966916)>S_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)qR_David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715)Q5Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre-S
9|eZkaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patchYo+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)LX]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24iWkkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068LV]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27sUkDaniel Veillard <veillard@redhat.com> - 2.9.1-2R- Fix a regression in xmlGetDocCompressMode() rhbz#963716
//L[o+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memoryad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
QZdQL_]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27>^_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)q]_David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715)\5Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre-W
CeckaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patchbo+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)La]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24i`kkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068
//Ldo+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memoryad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
KZdKRh_IDavid King <dking@redhat.com> - 2.9.1-6.6aQ@- Fix CVE-2016-4658 (#1966916)>g_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)qf_David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715)e5Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre-[
9|enkaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patchmo+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)Ll]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24ikkkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068Lj]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27sikDaniel Veillard <veillard@redhat.com> - 2.9.1-2R- Fix a regression in xmlGetDocCompressMode() rhbz#963716
//Loo+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memoryad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
*Zd*sskDaniel Veillard <veillard@redhat.com> - 2.9.1-2R- Fix a regression in xmlGetDocCompressMode() rhbz#963716>r_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)qq_David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715)p5Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre-_
xCbxexkaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patchwo+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)Lv]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24iukkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068Lt]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27
//Lyo+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memoryad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
QZdQL}]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27>|_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)q{_David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715)z5Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre-c
CekaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patcho+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)L]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24i~kkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068
//Lo+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memoryad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
KZdKR_IDavid King <dking@redhat.com> - 2.9.1-6.6aQ@- Fix CVE-2016-4658 (#1966916)>_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)q_David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715)5Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre-g
xCbxekaDaniel Veillard <veillard@redhat.com> - 2.9.1-6U@- Fix missing entities after CVE-2014-3660 fix
- CVE-2014-0191 Do not fetch external parameter entities (rhbz#1195650)
- Fix regressions introduced by CVE-2014-0191 patch
o+Daniel Veillard <veillard@redhat.com> - 2.9.1-5.1T9- CVE-2014-3660 denial of service via recursive entity expansion (rhbz#1149087)L	]?Daniel Mach <dmach@redhat.com> - 2.9.1-5RU- Mass rebuild 2014-01-24ikkDaniel Veillard <veillard@redhat.com> - 2.9.1-4Rx@- rebuild to activate -O3 on ppc64 rhbz#1051068L]?Daniel Mach <dmach@redhat.com> - 2.9.1-3Rk- Mass rebuild 2013-12-27
//Lo+Daniel Veillard <veillard@redhat.com> - 2.9.1-6.2V\:@- Fix a series of CVEs (rhbz#1286496)
- CVE-2015-7941 Stop parsing on entities boundaries errors
- CVE-2015-7941 Cleanup conditional section error handling
- CVE-2015-8317 Fail parsing early on if encoding conversion failed
- CVE-2015-7942 Another variation of overflow in Conditional sections
- CVE-2015-7942 Fix an error in previous Conditional section patch
- Fix parsing short unclosed comment uninitialized access
- CVE-2015-7498 Avoid processing entities after encoding conversion failures
- CVE-2015-7497 Avoid an heap buffer overflow in xmlDictComputeFastQKey
- CVE-2015-5312 Another entity expansion issue
- CVE-2015-7499 Add xmlHaltParser() to stop the parser
- CVE-2015-7499 Detect incoherency on GROW
- CVE-2015-7500 Fix memory access error due to incorrect entities boundaries
- CVE-2015-8242 Buffer overead with HTML parser in push mode
- CVE-2015-1819 Enforce the reader to run in constant memoryad in xmlParserPrintFileContextInternal <https://bugzilla.gnome.org/show_bug.cgi?id=758588> (CVE-2016-1838)
- Bug 758605: Heap-based buffer overread in xmlDictAddString <https://bugzilla.gnome.org/show_bug.cgi?id=758605> (CVE-2016-1839)
- Bug 759398: Heap use-after-free in xmlDictComputeFastKey <https://bugzilla.gnome.org/show_bug.cgi?id=759398> (CVE-2016-1836)
- Fix inappropriate fetch of entities content (CVE-2016-4449)
- Heap use-after-free in htmlParsePubidLiteral and htmlParseSystemiteral (CVE-2016-1837)
- Heap use-after-free in xmlSAX2AttributeNs (CVE-2016-1835)
- Heap-based buffer-underreads due to xmlParseName (CVE-2016-4447)
- Heap-based buffer overread in htmlCurrentChar (CVE-2016-1833)
- Add missing increments of recursion depth counter to XML parser. (CVE-2016-3705)
- Avoid building recursive entities (CVE-2016-3627)
- Fix some format string warnings with possible format string vulnerability (CVE-2016-4448)
- More format string warnings with possible format string vulnerability (CVE-2016-4448)
KZdKR_IDavid King <dking@redhat.com> - 2.9.1-6.6aQ@- Fix CVE-2016-4658 (#1966916)>_David King <dking@redhat.com> - 2.9.1-6.5^1- Fix CVE-2019-19956 (#1793000)
- Fix CVE-2019-20388 (#1810057)
- Fix CVE-2020-7595 (#1810073)
- Fix xsd:any schema validation (#1812145)q_David King <dking@redhat.com> - 2.9.1-6.4]@- Fix CVE-2015-8035 (#1595697)
- Fix CVE-2018-14404 (#1602817)
- Fix CVE-2017-15412 (#1729857)
- Fix CVE-2016-5131 (#1714050)
- Fix CVE-2017-18258 (#1579211)
- Fix CVE-2018-1456 (#1622715)
5Daniel Veillard <veillard@redhat.com> - libxml2-2.9.1-6.3WUe- Heap-based buffer overread in xmlNextChar (CVE-2016-1762)
- Bug 763071: Heap-buffer-overflow in xmlStrncat <https://bugzilla.gnome.org/show_bug.cgi?id=763071> (CVE-2016-1834)
- Bug 757711: Heap-buffer-overflow in xmlFAParsePosCharGroup <https://bugzilla.gnome.org/show_bug.cgi?id=757711> (CVE-2016-1840)
- Bug 758588: Heap-based buffer overre-k

er+V:eD
189cab5bc603286773946e73c42d38c539c7a0de2d36fdb6fa6aba0763c86a44D
552d8f1a349abd352ed882be0cfbe9423589f98f6621627e58afa84d6c83599dD
95d76c0c65f9a62fc846a490f4d2b19a993d7bfe3b29c8f5435e619d31f10fe5D
be4cfd2a6f6ccca83e063fb2eccc0c3e16716ba370638be5de4deda72c80848aD
af27db711b76e9af2239a13ace9776ebce5fd5642631930f1b9ad66c9bc391f0D
fdad65275349657bbcdf47559eea430b65c4e7b72549cbc6960987457bc53c5bD
1c5b7d04128c901ef27ab4d83ef677d205b161991be8f9d8b1210a92bde8b3abD
14b5a03ea26d2ce50c3b85067c66d70c255d308324891750f4deb390e7a68518D
5d92d36050c5d7174cd65358882ce23f7eab51af6a02070c42917f77f9dcb3feD
02153be2996d05b396970b128ff1c8411eb8c6920328c7f2bb84271d28caeff7D
8a8a993d640a917f86f781a7b6f422fb2bc8f0cdeafa9a8b16d5205c76f2a164D
12c0315c9a306dde2cbcb74039dc11f2dfc2490f50ccf2ab16411ba4c3093b63D
6f4c1e2f1a4962df4b746e55c425cf5ae75b8d5b8768adede04c96f2e00ddffe
*(OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438)QBruno E. O. Meneguele <bmeneg@redhat.com> - 20190318-71.git283373f\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.3.0 (rhbz 1642422)
35\D35Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)FJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)
f^1fFJan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-package+Bruno E. O. Meneguele <bmeneg@redhat.com> - 20190429-72.gitddde598\@- Update to latest upstream linux-firmware image for assorted updates
- cxgb4: update firmware to revision 1.23.4.0 (rhbz 1690727)
- linux-firmware: Add firmware file for Intel Bluetooth 22161 (rhbz 1622438){	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)
'{#	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)"5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m![Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410) 5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)tiJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)
].6]T''Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F&Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)(%OJan Stancek <jstancek@redhat.com> - 20190815-73.git07b925b]V- Update to latest upstream linux-firmware image for assorted updates (rhbz 1741356)
- iwlwifi- Update to support the Cyclone Peak Dual Band 2x2 802.11ax
- iwl7265-firmware sub-package merged into iwl7260-firmware sub-packageM$Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250)
wXM-Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){,	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)+5Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)m*[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410))5Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t(iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)
J.m3[Jan Stancek <jstancek@redhat.com> - 20200323-78.git8eb0b28^k@- Set higher compression (rhbz 1817410)25Jan Stancek <jstancek@redhat.com> - 20200323-77.git8eb0b28^x- Update to latest upstream linux-firmware image for assorted updates (rhbz 1813818)t1iJan Stancek <jstancek@redhat.com> - 20191203-76.gite8a0f4c]@- Fix missing firmware symlinks (rhbz 1783196)T0'Jan Stancek <jstancek@redhat.com> - 20191203-75.gite8a0f4c]N@- Update to latest upstream linux-firmware image for assorted updates
- Update qed zipped/unzipped firmware to latest upstream (rhbz 1720385)F/Jan Stancek <jstancek@redhat.com> - 20190918-74.git6c6918a]@- Update to latest upstream linux-firmware image for assorted updates
- Update bnx2x firmware to latest upstream (rhbz 1720386)1.]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-80.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)
v`Yv^85Denys Vlasenko <dvlasenk@redhat.com> - 20200421-83.git78c0348fXj@- hw: intel: Fix protection mechanism failure for some Intel(R) PROSet/Wireless WiFi
Resolves: RHEL-4010, RHEL-4013, RHEL-4016, RHEL-4018, RHEL-402117]Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-82.git78c0348e- AMD: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem (RHEL-13985)M6Rado Vrbovsky <rvrbovsk@redhat.com> - 20200421-81.git78c0348e:T- Cross-Process Information Leak (RHEL-8938)
- Return Address Predictor velunerability leading to information disclosure (RHEL-9250){5	oAugusto Caringi <acaringi@redhat.com> - 20200421-80.git78c0348_԰- Update Intel Bluetooth firmwares (rhbz 1895787)45Jan Stancek <jstancek@redhat.com> - 20200421-79.git78c0348^U@- Update to latest upstream linux-firmware image for assorted updates (rhbz 1828390)
E)g>ekMiroslav Lichvar <mlichvar@redhat.com> 1.8-5Y+@- add support for active-backup bonding (#1002657)
- add support for IP over InfiniBand (#1472880)
- fix handling of unknown/invalid management TLVs in pmc (#1459446 #1459449)g=emMichal Ruprich <mruprich@redhat.com> - 1.8-4Y4- Resolves: #1487522 - Race condition in phc2sysW<eMMiroslav Lichvar <mlichvar@redhat.com> 1.8-3X,- fix backport of linkdown patch_;e]Miroslav Lichvar <mlichvar@redhat.com> 1.8-2X@- force BMC election when link goes downZ:eSMiroslav Lichvar <mlichvar@redhat.com> 1.8-1X- update to 1.8 (#1359311 #1353336)69	cMiroslav Lichvar <mlichvar@redhat.com> 1.4-3.20140718gitbdb6a3Tto@- fix resetting of linreg servo (#1165045)
- fix phc2sys automatic mode with multiple interfaces (#1108795)
1+1|CcPetr Šabata <contyk@redhat.com> - 0.9.46-8S)- Ignore supplied PG configuration if PG is being disabled (#1067261)vBu{Miroslav Lichvar <mlichvar@redhat.com> 2.0-2.el7_9.1`s- validate length of forwarded messages (CVE-2021-3570)Ae)Miroslav Lichvar <mlichvar@redhat.com> 2.0-2\@- fix comparing of unicast addresses
- don't leak memory when allocation fails@e9Miroslav Lichvar <mlichvar@redhat.com> 2.0-1\|- update to 2.0 (#1623919)
- add support for more accurate synchronization to phc2sys (#1643977)
- add support for active-backup team interface (#1650672)
- limit unicast message rate per address and grant duration2?eMiroslav Lichvar <mlichvar@redhat.com> 1.8-6[@- add support for bonding to timemaster (#1549015)
- improve timemaster to restart terminated processes (#1527170)
- start ptp4l, timemaster and phc2sys after network-online target (#1541991)
- don't forward management requests to UDS port (#1520366)
:7nJygAaron Conole <aconole@redhat.com> - 1.0.1-5.git036e314\u*@- Fix memory leak on TLV reception (#1196320)jIy_Aaron Conole <aconole@redhat.com> - 1.0.1-4.git036e314[j@- fix the OID printing routine (#1551623)(Hu]Chris Leech <cleech@redhat.com> - 1.0.1-3.git036e314W|- 1273663 sync with upstream v1.0.1-26-g036e314
  system capability incorrect advertised as station onlyGuChris Leech <cleech@redhat.com> - 1.0.1-2.git986eb2eU5@- convert from sysv shm to posix, to allow selinux restorecon (#1080287)rFusChris Leech <cleech@redhat.com> - 1.0.1-1.git986eb2eU- rebased to upstream v1.0.1-23-g986eb2e (#1175802)jEcuChris Leech <cleech@redhat.com> - 0.9.46-10TFJ- Sync with upstream v0.9.46-123-g48a5f38 (#1087096)TDaKChris Leech <cleech@redhat.com> - 0.9.46-9S\- Fix IEEE mode DCBX (#1102886)
Y(DQuChris Leech <cleech@redhat.com> - 1.0.1-2.git986eb2eU5@- convert from sysv shm to posix, to allow selinux restorecon (#1080287)rPusChris Leech <cleech@redhat.com> - 1.0.1-1.git986eb2eU- rebased to upstream v1.0.1-23-g986eb2e (#1175802)jOcuChris Leech <cleech@redhat.com> - 0.9.46-10TFJ- Sync with upstream v0.9.46-123-g48a5f38 (#1087096)TNaKChris Leech <cleech@redhat.com> - 0.9.46-9S\- Fix IEEE mode DCBX (#1102886)|McPetr Šabata <contyk@redhat.com> - 0.9.46-8S)- Ignore supplied PG configuration if PG is being disabled (#1067261)ULy5Aaron Conole <aconole@redhat.com> - 1.0.1-7.git036e314b'- Fix compiler guard"KyMAaron Conole <aconole@redhat.com> - 1.0.1-6.git036e314]rJ@- Fix lldpad dereference NULL (#1513337)
- Fix ecp22_start() failure to create object (#1510945)
-Sss-jYcuChris Leech <cleech@redhat.com> - 0.9.46-10TFJ- Sync with upstream v0.9.46-123-g48a5f38 (#1087096)TXaKChris Leech <cleech@redhat.com> - 0.9.46-9S\- Fix IEEE mode DCBX (#1102886)|WcPetr Šabata <contyk@redhat.com> - 0.9.46-8S)- Ignore supplied PG configuration if PG is being disabled (#1067261)UVy5Aaron Conole <aconole@redhat.com> - 1.0.1-7.git036e314b'- Fix compiler guard"UyMAaron Conole <aconole@redhat.com> - 1.0.1-6.git036e314]rJ@- Fix lldpad dereference NULL (#1513337)
- Fix ecp22_start() failure to create object (#1510945)nTygAaron Conole <aconole@redhat.com> - 1.0.1-5.git036e314\u*@- Fix memory leak on TLV reception (#1196320)jSy_Aaron Conole <aconole@redhat.com> - 1.0.1-4.git036e314[j@- fix the OID printing routine (#1551623)(Ru]Chris Leech <cleech@redhat.com> - 1.0.1-3.git036e314W|- 1273663 sync with upstream v1.0.1-26-g036e314
  system capability incorrect advertised as station only
pPppU`y5Aaron Conole <aconole@redhat.com> - 1.0.1-7.git036e314b'- Fix compiler guard"_yMAaron Conole <aconole@redhat.com> - 1.0.1-6.git036e314]rJ@- Fix lldpad dereference NULL (#1513337)
- Fix ecp22_start() failure to create object (#1510945)n^ygAaron Conole <aconole@redhat.com> - 1.0.1-5.git036e314\u*@- Fix memory leak on TLV reception (#1196320)j]y_Aaron Conole <aconole@redhat.com> - 1.0.1-4.git036e314[j@- fix the OID printing routine (#1551623)(\u]Chris Leech <cleech@redhat.com> - 1.0.1-3.git036e314W|- 1273663 sync with upstream v1.0.1-26-g036e314
  system capability incorrect advertised as station only[uChris Leech <cleech@redhat.com> - 1.0.1-2.git986eb2eU5@- convert from sysv shm to posix, to allow selinux restorecon (#1080287)rZusChris Leech <cleech@redhat.com> - 1.0.1-1.git986eb2eU- rebased to upstream v1.0.1-23-g986eb2e (#1175802)
*(D
*nhygAaron Conole <aconole@redhat.com> - 1.0.1-5.git036e314\u*@- Fix memory leak on TLV reception (#1196320)jgy_Aaron Conole <aconole@redhat.com> - 1.0.1-4.git036e314[j@- fix the OID printing routine (#1551623)(fu]Chris Leech <cleech@redhat.com> - 1.0.1-3.git036e314W|- 1273663 sync with upstream v1.0.1-26-g036e314
  system capability incorrect advertised as station onlyeuChris Leech <cleech@redhat.com> - 1.0.1-2.git986eb2eU5@- convert from sysv shm to posix, to allow selinux restorecon (#1080287)rdusChris Leech <cleech@redhat.com> - 1.0.1-1.git986eb2eU- rebased to upstream v1.0.1-23-g986eb2e (#1175802)jccuChris Leech <cleech@redhat.com> - 0.9.46-10TFJ- Sync with upstream v0.9.46-123-g48a5f38 (#1087096)TbaKChris Leech <cleech@redhat.com> - 0.9.46-9S\- Fix IEEE mode DCBX (#1102886)|acPetr Šabata <contyk@redhat.com> - 0.9.46-8S)- Ignore supplied PG configuration if PG is being disabled (#1067261)
Y1nMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-3.20160601gitf9185e5W@- Replace Revision string with release and date. Resolves: #1362658zmcMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-2.20160601gitf9185e5WaC@- Add explicit package version requirement.XlMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-0.20160601gitf9185e5.1WN@- New upstream release
- Drop patches that are already present in upstream
- Apply upstream fix for systemd paths
- Resolves: #1297795pkeJaromir Capik <jcapik@redhat.com> - 3.3.4-11T+- Hardening the build (#1092536)
- Resolves: rhbz#1092536Ujy5Aaron Conole <aconole@redhat.com> - 1.0.1-7.git036e314b'- Fix compiler guard"iyMAaron Conole <aconole@redhat.com> - 1.0.1-6.git036e314]rJ@- Fix lldpad dereference NULL (#1513337)
- Fix ecp22_start() failure to create object (#1510945)
Qs	Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-8.20160601gitf9185e5\e- Fixed stale links and outdated info
- Resolves: rhbz#1356253rOndřej Lysoněk <olysonek@redhat.com> - 3.4.0-7.20160601gitf9185e5\=@- Detect AMD Rome - Family 17h model 30h
- Resolves: rhbz#1650199qOndřej Lysoněk <olysonek@redhat.com> - 3.4.0-6.20160601gitf9185e5Z- Fix License field capitalization
- Resolves: rhbz#1577175
- Add detection of AMD Ryzen w/ Vega graphics
- Resolves: rhbz#1569542
- Fix issues found by Coverity Scan
- Resolves: rhbz#1578007p
Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-5.20160601gitf9185e5Z@- Detect AMD Family 17h thermal sensors
- Resolves: rhbz#1569542*oAMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-4.20160601gitf9185e5W:- Print warning message when running on an alternative architecture. 
- Resolves: #1362664
@xMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-3.20160601gitf9185e5W@- Replace Revision string with release and date. Resolves: #1362658zwcMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-2.20160601gitf9185e5WaC@- Add explicit package version requirement.XvMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-0.20160601gitf9185e5.1WN@- New upstream release
- Drop patches that are already present in upstream
- Apply upstream fix for systemd paths
- Resolves: #1297795pueJaromir Capik <jcapik@redhat.com> - 3.3.4-11T+- Hardening the build (#1092536)
- Resolves: rhbz#1092536ltCBryan Mason <bmason@redhat.com> - 3.4.0-8.20160601gitf9185e5.el7_9.1eu@- New flag for no sensors added. This flag is used in VM environment
  to make sensors binaries not fail if no sensors was detected.
- Resolves: RHEL-17699
Q}	Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-8.20160601gitf9185e5\e- Fixed stale links and outdated info
- Resolves: rhbz#1356253|Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-7.20160601gitf9185e5\=@- Detect AMD Rome - Family 17h model 30h
- Resolves: rhbz#1650199{Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-6.20160601gitf9185e5Z- Fix License field capitalization
- Resolves: rhbz#1577175
- Add detection of AMD Ryzen w/ Vega graphics
- Resolves: rhbz#1569542
- Fix issues found by Coverity Scan
- Resolves: rhbz#1578007z
Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-5.20160601gitf9185e5Z@- Detect AMD Family 17h thermal sensors
- Resolves: rhbz#1569542*yAMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-4.20160601gitf9185e5W:- Print warning message when running on an alternative architecture. 
- Resolves: #1362664
@Martin Sehnoutka <msehnout@redhat.com> - 3.4.0-3.20160601gitf9185e5W@- Replace Revision string with release and date. Resolves: #1362658zcMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-2.20160601gitf9185e5WaC@- Add explicit package version requirement.XMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-0.20160601gitf9185e5.1WN@- New upstream release
- Drop patches that are already present in upstream
- Apply upstream fix for systemd paths
- Resolves: #1297795peJaromir Capik <jcapik@redhat.com> - 3.3.4-11T+- Hardening the build (#1092536)
- Resolves: rhbz#1092536l~CBryan Mason <bmason@redhat.com> - 3.4.0-8.20160601gitf9185e5.el7_9.1eu@- New flag for no sensors added. This flag is used in VM environment
  to make sensors binaries not fail if no sensors was detected.
- Resolves: RHEL-17699
Q	Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-8.20160601gitf9185e5\e- Fixed stale links and outdated info
- Resolves: rhbz#1356253Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-7.20160601gitf9185e5\=@- Detect AMD Rome - Family 17h model 30h
- Resolves: rhbz#1650199Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-6.20160601gitf9185e5Z- Fix License field capitalization
- Resolves: rhbz#1577175
- Add detection of AMD Ryzen w/ Vega graphics
- Resolves: rhbz#1569542
- Fix issues found by Coverity Scan
- Resolves: rhbz#1578007
Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-5.20160601gitf9185e5Z@- Detect AMD Family 17h thermal sensors
- Resolves: rhbz#1569542*AMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-4.20160601gitf9185e5W:- Print warning message when running on an alternative architecture. 
- Resolves: #1362664
@Martin Sehnoutka <msehnout@redhat.com> - 3.4.0-3.20160601gitf9185e5W@- Replace Revision string with release and date. Resolves: #1362658zcMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-2.20160601gitf9185e5WaC@- Add explicit package version requirement.X
Martin Sehnoutka <msehnout@redhat.com> - 3.4.0-0.20160601gitf9185e5.1WN@- New upstream release
- Drop patches that are already present in upstream
- Apply upstream fix for systemd paths
- Resolves: #1297795p	eJaromir Capik <jcapik@redhat.com> - 3.3.4-11T+- Hardening the build (#1092536)
- Resolves: rhbz#1092536lCBryan Mason <bmason@redhat.com> - 3.4.0-8.20160601gitf9185e5.el7_9.1eu@- New flag for no sensors added. This flag is used in VM environment
  to make sensors binaries not fail if no sensors was detected.
- Resolves: RHEL-17699
Q	Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-8.20160601gitf9185e5\e- Fixed stale links and outdated info
- Resolves: rhbz#1356253Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-7.20160601gitf9185e5\=@- Detect AMD Rome - Family 17h model 30h
- Resolves: rhbz#1650199Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-6.20160601gitf9185e5Z- Fix License field capitalization
- Resolves: rhbz#1577175
- Add detection of AMD Ryzen w/ Vega graphics
- Resolves: rhbz#1569542
- Fix issues found by Coverity Scan
- Resolves: rhbz#1578007
Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-5.20160601gitf9185e5Z@- Detect AMD Family 17h thermal sensors
- Resolves: rhbz#1569542*
AMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-4.20160601gitf9185e5W:- Print warning message when running on an alternative architecture. 
- Resolves: #1362664
@Martin Sehnoutka <msehnout@redhat.com> - 3.4.0-3.20160601gitf9185e5W@- Replace Revision string with release and date. Resolves: #1362658zcMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-2.20160601gitf9185e5WaC@- Add explicit package version requirement.XMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-0.20160601gitf9185e5.1WN@- New upstream release
- Drop patches that are already present in upstream
- Apply upstream fix for systemd paths
- Resolves: #1297795peJaromir Capik <jcapik@redhat.com> - 3.3.4-11T+- Hardening the build (#1092536)
- Resolves: rhbz#1092536lCBryan Mason <bmason@redhat.com> - 3.4.0-8.20160601gitf9185e5.el7_9.1eu@- New flag for no sensors added. This flag is used in VM environment
  to make sensors binaries not fail if no sensors was detected.
- Resolves: RHEL-17699

er+V:eD)
14b4703549cb70dba8871814b76da451a63a067a0c48cbf78c90a94b528e8071D(
4a27bc911920120ba55850208fce562c36cd54a517a88cc8a4b4adde165bdbc5D'
40a9bbf97909feac9fdb52ebe77bd0ec92e96ff00529d4803ce6c56086f78337D&
9d34ca3784c0b623e48bc95dca03187a3404a69dd41baa19138db561f25be0f9D%
90f9bcfc03ace81b54541dfb0892bbacaabcc873c597d5c78bd3e56e91a2cd80D$
7bbf77456d5e310210c4bd541fee70097c26568f34f44184c878e5874e2b57f1D#
6f168ecee0a2bbae92e0564565c3d22e1bae72f64557c32569a7bffd94b76ca4D"
e4950b148639895cb3ed78b8a00c0708abe4685bd380e0003ebeb947ea1edc42D!
9c006d26a3fc490337a403596c661c5f56ddf827bc6cbd0f2da8d9f0c325eeb9D 
1b461b4e217ac5f51d8990aad583c7f189e73fd3220a54053124772b83c42ebaD
cbc27f39937173e8134e59deb6baac91cea3e9497f76d2e139b4eb64bc1aade3D
60f10f4641f2dac4d689ad5b1ee25cc224768eadce58b7f0d64c3eecf32b94ffD
0af4fa113704a011a3594459a6619542c384a68bce85aa250f90448e347431fe
Q	Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-8.20160601gitf9185e5\e- Fixed stale links and outdated info
- Resolves: rhbz#1356253Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-7.20160601gitf9185e5\=@- Detect AMD Rome - Family 17h model 30h
- Resolves: rhbz#1650199Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-6.20160601gitf9185e5Z- Fix License field capitalization
- Resolves: rhbz#1577175
- Add detection of AMD Ryzen w/ Vega graphics
- Resolves: rhbz#1569542
- Fix issues found by Coverity Scan
- Resolves: rhbz#1578007
Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-5.20160601gitf9185e5Z@- Detect AMD Family 17h thermal sensors
- Resolves: rhbz#1569542*AMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-4.20160601gitf9185e5W:- Print warning message when running on an alternative architecture. 
- Resolves: #1362664
@ Martin Sehnoutka <msehnout@redhat.com> - 3.4.0-3.20160601gitf9185e5W@- Replace Revision string with release and date. Resolves: #1362658zcMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-2.20160601gitf9185e5WaC@- Add explicit package version requirement.XMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-0.20160601gitf9185e5.1WN@- New upstream release
- Drop patches that are already present in upstream
- Apply upstream fix for systemd paths
- Resolves: #1297795peJaromir Capik <jcapik@redhat.com> - 3.3.4-11T+- Hardening the build (#1092536)
- Resolves: rhbz#1092536lCBryan Mason <bmason@redhat.com> - 3.4.0-8.20160601gitf9185e5.el7_9.1eu@- New flag for no sensors added. This flag is used in VM environment
  to make sensors binaries not fail if no sensors was detected.
- Resolves: RHEL-17699
Q%	Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-8.20160601gitf9185e5\e- Fixed stale links and outdated info
- Resolves: rhbz#1356253$Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-7.20160601gitf9185e5\=@- Detect AMD Rome - Family 17h model 30h
- Resolves: rhbz#1650199#Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-6.20160601gitf9185e5Z- Fix License field capitalization
- Resolves: rhbz#1577175
- Add detection of AMD Ryzen w/ Vega graphics
- Resolves: rhbz#1569542
- Fix issues found by Coverity Scan
- Resolves: rhbz#1578007"
Ondřej Lysoněk <olysonek@redhat.com> - 3.4.0-5.20160601gitf9185e5Z@- Detect AMD Family 17h thermal sensors
- Resolves: rhbz#1569542*!AMartin Sehnoutka <msehnout@redhat.com> - 3.4.0-4.20160601gitf9185e5W:- Print warning message when running on an alternative architecture. 
- Resolves: #1362664
<qc<L,a;Michal Srb <msrb@redhat.com> - 0:1.2.17-13Qޞ@- Enable tests
- Fix BRi+ogVille Skyttä <ville.skytta@iki.fi> - 0:1.2.17-12Q'@- Add DTD public id to XML and SGML catalogs.f*u[Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-11Q~`- Remove unneeded BR: maven-idea-pluginv)u{Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-10Qf- Fix manpage names, thanks to Michal Srb for reporting(s-Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-9Qb@- Reindex sources in more sensible way
- Add manual pages; resolves: rhbz#949413'Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0:1.2.17-8Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuildl&CBryan Mason <bmason@redhat.com> - 3.4.0-8.20160601gitf9185e5.el7_9.1eu@- New flag for no sensors added. This flag is used in VM environment
  to make sensors binaries not fail if no sensors was detected.
- Resolves: RHEL-17699
UT:,Ui4ogVille Skyttä <ville.skytta@iki.fi> - 0:1.2.17-12Q'@- Add DTD public id to XML and SGML catalogs.f3u[Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-11Q~`- Remove unneeded BR: maven-idea-pluginv2u{Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-10Qf- Fix manpage names, thanks to Michal Srb for reporting1s-Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-9Qb@- Reindex sources in more sensible way
- Add manual pages; resolves: rhbz#9494130uMikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-17a- Fix remote code execution vulnerability
- Resolves: CVE-2021-4104
/u'Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-16Yd- Fix socket receiver deserialization vulnerability
- Resolves: CVE-2017-5645O.c?Daniel Mach <dmach@redhat.com> - 01.2.17-15Rk- Mass rebuild 2013-12-27U-u9Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-14Ri- Remove desktop files
WrD:uMikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-18ar@- Fix Unsafe deserialization flaw in Chainsaw log viewer
- Fix SQL injection when application is configured to use JDBCAppender
- Fix remote code execution when application is configured to use JMSSink
- Resolves: CVE-2022-23307, CVE-2022-23305, CVE-2022-233029uMikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-17a- Fix remote code execution vulnerability
- Resolves: CVE-2021-4104
8u'Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-16Yd- Fix socket receiver deserialization vulnerability
- Resolves: CVE-2017-5645O7c?Daniel Mach <dmach@redhat.com> - 01.2.17-15Rk- Mass rebuild 2013-12-27U6u9Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-14Ri- Remove desktop filesL5a;Michal Srb <msrb@redhat.com> - 0:1.2.17-13Qޞ@- Enable tests
- Fix BR
bT}-OBc?Daniel Mach <dmach@redhat.com> - 01.2.17-15Rk- Mass rebuild 2013-12-27UAu9Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-14Ri- Remove desktop filesL@a;Michal Srb <msrb@redhat.com> - 0:1.2.17-13Qޞ@- Enable tests
- Fix BRi?ogVille Skyttä <ville.skytta@iki.fi> - 0:1.2.17-12Q'@- Add DTD public id to XML and SGML catalogs.f>u[Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-11Q~`- Remove unneeded BR: maven-idea-pluginv=u{Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-10Qf- Fix manpage names, thanks to Michal Srb for reporting<s-Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-9Qb@- Reindex sources in more sensible way
- Add manual pages; resolves: rhbz#949413;Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0:1.2.17-8Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
XnRnXUJu9Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-14Ri- Remove desktop filesLIa;Michal Srb <msrb@redhat.com> - 0:1.2.17-13Qޞ@- Enable tests
- Fix BRiHogVille Skyttä <ville.skytta@iki.fi> - 0:1.2.17-12Q'@- Add DTD public id to XML and SGML catalogs.fGu[Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-11Q~`- Remove unneeded BR: maven-idea-pluginvFu{Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-10Qf- Fix manpage names, thanks to Michal Srb for reportingEs-Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-9Qb@- Reindex sources in more sensible way
- Add manual pages; resolves: rhbz#949413DuMikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-17a- Fix remote code execution vulnerability
- Resolves: CVE-2021-4104
Cu'Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-16Yd- Fix socket receiver deserialization vulnerability
- Resolves: CVE-2017-5645
JPs-Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-9Qb@- Reindex sources in more sensible way
- Add manual pages; resolves: rhbz#949413OFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0:1.2.17-8Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildDNuMikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-18ar@- Fix Unsafe deserialization flaw in Chainsaw log viewer
- Fix SQL injection when application is configured to use JDBCAppender
- Fix remote code execution when application is configured to use JMSSink
- Resolves: CVE-2022-23307, CVE-2022-23305, CVE-2022-23302MuMikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-17a- Fix remote code execution vulnerability
- Resolves: CVE-2021-4104
Lu'Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-16Yd- Fix socket receiver deserialization vulnerability
- Resolves: CVE-2017-5645OKc?Daniel Mach <dmach@redhat.com> - 01.2.17-15Rk- Mass rebuild 2013-12-27
_!XuMikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-17a- Fix remote code execution vulnerability
- Resolves: CVE-2021-4104
Wu'Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-16Yd- Fix socket receiver deserialization vulnerability
- Resolves: CVE-2017-5645OVc?Daniel Mach <dmach@redhat.com> - 01.2.17-15Rk- Mass rebuild 2013-12-27UUu9Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-14Ri- Remove desktop filesLTa;Michal Srb <msrb@redhat.com> - 0:1.2.17-13Qޞ@- Enable tests
- Fix BRiSogVille Skyttä <ville.skytta@iki.fi> - 0:1.2.17-12Q'@- Add DTD public id to XML and SGML catalogs.fRu[Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-11Q~`- Remove unneeded BR: maven-idea-pluginvQu{Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-10Qf- Fix manpage names, thanks to Michal Srb for reporting
lr
`u'Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-16Yd- Fix socket receiver deserialization vulnerability
- Resolves: CVE-2017-5645O_c?Daniel Mach <dmach@redhat.com> - 01.2.17-15Rk- Mass rebuild 2013-12-27U^u9Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-14Ri- Remove desktop filesL]a;Michal Srb <msrb@redhat.com> - 0:1.2.17-13Qޞ@- Enable tests
- Fix BRi\ogVille Skyttä <ville.skytta@iki.fi> - 0:1.2.17-12Q'@- Add DTD public id to XML and SGML catalogs.f[u[Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-11Q~`- Remove unneeded BR: maven-idea-pluginvZu{Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-10Qf- Fix manpage names, thanks to Michal Srb for reportingYs-Mikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-9Qb@- Reindex sources in more sensible way
- Add manual pages; resolves: rhbz#949413
x/H	fs!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.esIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rdsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.mcYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.DbuMikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-18ar@- Fix Unsafe deserialization flaw in Chainsaw log viewer
- Fix SQL injection when application is configured to use JDBCAppender
- Fix remote code execution when application is configured to use JMSSink
- Resolves: CVE-2022-23307, CVE-2022-23305, CVE-2022-23302auMikolaj Izdebski <mizdebsk@redhat.com> - 0:1.2.17-17a- Fix remote code execution vulnerability
- Resolves: CVE-2021-4104
fp
lMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QkMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.jMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
is#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.chsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.gs9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
>ZY>sMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
rs#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cqsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.ps9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	os!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.nsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rmsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
Y*#Yys9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	xs!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.wsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.tvgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
uMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QtMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.

~tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
~Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q}Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.|Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
{s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.czsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.
 8Q! csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.mYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.CMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.
hq
hsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.

Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q	Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.
rqVQMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	
s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.
9qW/9
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.

er+V:eD6
7d80d5c3223ee7166a1d09374bac557258cbea615497efbd575aaf673d58b321D5
40ff738de8c90ab572f7f1b75bd512df524c5b0251c9fbf54e4d81783f7d5a34D4
fdbf4bfe28188e74649c64f6a210cdce1aec37dafe82324cc4a7403e012e4c4fD3
bd945872965d8eeb4accc4fc087400341b7ecfd21918499fa21ff68810cb4194D2
0202fe311e75a00ac449bf922bf22eacbdfcbc62ea3fb9eca5285643347ec389D1
92b1ec3eeccc76ef95cbdf3336b545c2ded469e9d6ebaa81b98312b0ef0cc80aD0
3687a70548cbd4d02fcf7f26b82c06330dc5e341e67504643b30e20c257b33a3D/
7954c520b09dc7bfb10b62124f03b0340cfc571dc7d61d91873543f3a413149bD.
06d86e24f67250850372882170efd7d12d041a90b28a72fb952a0f3d10141825D-
75f984b4cdee8c054416401d8e1a4f00cb8d0fa104e54d12456f8884c58d7db5D,
05b66ae9aef06d6c9d64f8dd5f1ffb50591c5686b5d538f6a698b5725f8a5b12D+
45664af56e8ecd30d4df0d0ca03b53d10f0840e2da053735655a3283b7b1fb6dD*
252358bff773a45f41c33ac5e89717fa9768dccf112a04337a33f37cc5737ac4
^t^mYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.CMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
>ZY>&Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
%s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c$sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.#s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	"s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.!sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
**	,s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.+sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r*suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.m)YMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.
(Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q'Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
fp
2Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q1Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.0Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
/s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c.sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.-s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
>ZY>9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
8s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c7sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.6s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	5s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.4sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r3suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
}*#}	?s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.>sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r=suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.t<gMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
;Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q:Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
fp
EMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QDMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.CMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
Bs#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cAsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.@s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
<XW<LMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
Ks#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cJsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.Is9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	Hs!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.GsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.tFgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
+*#[+	Rs!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.QsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.CPMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.tOgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
NMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
fp
XMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.VMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
Us#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cTsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.Ss9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
O7	^s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.]sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r\suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.m[YMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.CZMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.tYgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
fp
dMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QcMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.bMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
as#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c`sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2._s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
YwOY
ks#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cjsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.is9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	hs!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.gsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rfsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.meYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.
iti	qs!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.psIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rosuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
nMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QmMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.lMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
fp
wMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QvMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.uMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
ts#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cssWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.rs9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
RpHR
~s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c}sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.|s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	{s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.zsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rysuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.txgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
gtg	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
fp

Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q	Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.
sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.CMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
@q@CMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.

er+V:eDC
c990d11d35716ef252caf3630273bd9502a4f8556105b0ee8005c3164ce118dfDB
56fdfe56e71473fc17bdd4e12e6ff4713e56fd02c7595517593f0cabc98308f9DA
76398082a1500552d12445932d6e5689e02b1ebdced0a38e4003a7fa56871ce1D@
81f4f035197f26565bfc9caddcd8374921d1e73e9c89c65d4769e9daf437a158D?
6856b6c454d9ab38557feb769e9f6ad01dab3cef1e61417d841eb5c243932401D>
c3b133e5f06890f86c2c918c35177dfe1000500cfee3fc5ff248faab874324f1D=
80fba5d63f2251d74b40f2d94f3fa1ea15c4abee2772339081238b1d17a44eb3D<
38375293dabf1abf54765991dcbdc6f2a1cd8c3ebe3d7fabc2405e566a16c5f0D;
bff2adfbc894a60df24055ab573b81c8128737c5d8b2530955f48d64f1c121b5D:
a8011f7c5d7ee7b597856c9c2ae5e2c6fc7ae896c60e16be78780dc6f09a5babD9
88ee54419e99f4dacae891d93199c6fed6512d9a534c7d923a9477877d953d6aD8
a1e667c441a340c5ac1f0544c4a3d934fde4bf968688af42f5d33e773f092b5bD7
cedf74bcc18ccfbbe277b033c31b3a65c6fae8135a0c90fadef65c35b5da0d1c
YwOY
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.rsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.mYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.
iti	#s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1."sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r!suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
 Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
fp
)Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q(Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.'Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
&s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c%sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.$s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.
<XW<0Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
/s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c.sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.-s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	,s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.+sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.t*gMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
t*#[tr6suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.m5YMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.C4Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.t3gMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
2Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q1Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
^6@<Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
;s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.c:sWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.9s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	8s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.7sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.
[*%[Bs9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	As!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.@sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r?suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
>Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q=Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.

~tHgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
GMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QFMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.EMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
Ds#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cCsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.
^6@NMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
Ms#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cLsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.Ks9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	Js!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.IsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.
t*#[trTsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.mSYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.CRMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.tQgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
PMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QOMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.bR-RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{-J-P-X-`-f-l-s-y-------&-,-2-9-?-E-L-R-X-^-d-k-q-w-~--
----#-)-0-6-<-B-H-N-T-Z-`-f-l-r-x-‚~-Â-Ă
-ł-Ƃ-Ȃ -ɂ(-ʂ0-˂9-̂A-͂I-΂R-ς[-Ђd-тm-҂v-ӂ-Ԃ-Ղ-ւ-ׂ!-ق*-ڂ3-ۂ<-܂E-݂M-ނU-߂^-g-Ⴅp-₥y-ウ-䂦-傦-悦-炦$-邦--ꂦ6-낦?-삦H-킦Q-Y-a-j-s-|---
^6@ZMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
Ys#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cXsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.Ws9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	Vs!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.UsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.
[*%[`s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	_s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.^sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r]suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
\Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.Q[Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.

~tfgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
eMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QdMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.cMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
bs#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.casWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.
^6@lMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
ks#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cjsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.is9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	hs!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.gsIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.
t*#[trrsuMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.mqYMarian Csontos <mcsontos@redhat.com> - 7:2.02.186-7.el7_8.1^j$@- Fix failing pvs with locking_type 4.CpMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.togMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
nMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QmMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
^6@xMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
ws#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.cvsWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.us9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	ts!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.ssIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.
[*%[~s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	}s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.|sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.r{suMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-1^y@- Bug fix release.
- See WHATS_NEW file for details.
zMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QyMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.

~tgMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.
^6@
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.1_- Fix conversion to mirrored mirror log with larger regionsize.
	s#Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6^- Fix pvs/lvs/vgs failing due empty VG spotted in metadata when under load.csWMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-5^- Update boom to bug fix release 1.2.s9Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-4^- boom: Fix traceback in error path.
- boom: Improve error path handling with --debug.	s!Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-3^@- Add allow_mixed_block_sizes into lvm.conf.
- Update boom to version 1.1.sIMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-2^H- No validation for thin pools not used by lvm,
- Add support for VDO in blkdeactivate script.
'*#['qPavel Šimerda <psimerda@redhat.com> - 3:2.1.15-24X}A- Resolves: #1232737 - Fix instances of #!/usr/bin/env python in mailman$qYPavel Šimerda <psimerda@redhat.com> - 3:2.1.15-23X}@- Resolves: #1232749 - fix bad subject of the welcome email when creating list
  using newlist commandCMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.5`J@- Fix fsadm failure due to accessing unbound variable.
- Fix segfault in vgextend when a PV is missing in the processed VG.t
gMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.4`!'- Fix fsadm behavior with missing parameters.
Marian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.3_- Fix lvresize handling of fsck exit code 1 - FS errors corrected.QMarian Csontos <mcsontos@redhat.com> - 7:2.02.187-6.el7_9.2_@- Fix dmeventd crash with modified reserved_stack configuration option.
- Fix lvm crashing when .cache file is changed by external tools.
jqgMartin Osvald <mosvald@redhat.com> - 3:2.1.15-30.2ao@- Fix for CVE-2021-44227
- Resolves: #2026866
q+Martin Osvald <mosvald@redhat.com> - 3:2.1.15-30.1ab- Fix for CVE-2016-6893
- Fix for CVE-2021-42097
- Resolves: #2024884, #2020688kPavel Zhukov <pzhukov@redhat.com> - 3:2.1.15-30]A- Resolves: #1599692 - Sanitize input on listinfo page (CVE-2018-0618)|kPavel Zhukov <pzhukov@redhat.com> - 3:2.1.15-29]A- Resolves: #1611689 -  Trim long text in "no such list" messagespkyPavel Zhukov <pzhukov@redhat.com> - 3:2.1.15-28]5@- Resolves: #1718180 - Try to decode member name first~kPavel Zhukov <pzhukov@redhat.com> - 3:2.1.15-27Z- Related : #1545973 -  Bump release to override rhel-7.4.z versionrk}Pavel Zhukov <pzhukov@redhat.com> - 3:2.1.15-26Z<- Resolves: #1545973 -  Add sanitizer for XSS mitigationqk{Pavel Zhukov <pzhukov@redhat.com> - 3:2.1.15-25Z- Resolves: #1545973 -  Fix XSS vulnerability in web UI

er+V:eDP
c48cdbee47b50246eeff421099d33fa4c714820624f898dd7b17a6940d7ea5b9DO
298d464e537220ee820bd7139581301c828d6e60d9deb0f490ea21510f3a7884DN
8c61ae91b0b15370cc12465214b2a97e5f414aec4feb6af550ac11024416aaa4DM
9ffa36744512a13fc23ae4541bafd054b58dfcecb57c59e6cbe9575f74e20809DL
8862c2d66552b96db725de231e282bb308785e3aceaa1a3373dd4a21a3279f14DK
537f6ca06c1c64b8b443ddea71e5ed3c2e491cdc767579a7e3a42473aced25b0DJ
1e1f0a4ca49b831262ecfe3ac11e0eaf955da130a0d8c2a9887d17d6514fad7eDI
ed62288ee271d53bb3c81742a33a6fe77f2edda3206814cfbd782ea0e9a2983bDH
4555608cef90da4d409d7d09f1176fc6cc4348f516c64411e318379a54137083DG
de0f021707bee4c5aaee236900b154d83bb1e1fb6cf13faf8ff2b8f68fd04dcbDF
222af4af29ee9e4dea368547514867dd1734fdc205d9dc9b484dd99e567f4d75DE
9253408f51b5e89b9beb8bfd7b35383d55a86420ea8834e2d54d161be9d81233DD
8f63c53cfad328c376db111c9f46d7f6c7de014b98eb16dd9bbcf62583303adb
l"0Xlv M!Xiao Ni <xni@redhat.com> - 4.1.5^%@- mdcheck continue/start service has grammer error
- Resolves rhbz#1774354nMXiao Ni <xni@redhat.com> - 4.1.4^C- Innorrect UUID reported in volume detail
- Resolves rhbz#1789816ZMkXiao Ni <xni@redhat.com> - 4.1.3]@- Fix CI building error
- Resolves rhbz#1773607vM!Xiao Ni <xni@redhat.com> - 4.1.2]- imsm: fix spare activation for old matrix arrays
- Resolves rhbz#1773607~M1Xiao Ni <xni@redhat.com> - 4.1.1\M- Update to upstream 4.1 and backport 21 patches after 4.1
- Resolves rhbz#1641473lUXiao Ni <xni@redhat.com> - 4.1-rc1-2[b@- Fix two IMSM bugs
- Resolves rhbz#1602362 and rhbz#1602358kUXiao Ni <xni@redhat.com> - 4.1-rc1-1[,- Upgrade to upstream mdadm-4.1-rc1
- Resolves rhbz#1494472kO	Xiao Ni <xni@redhat.com> - 4.0-13Zz@- stop previous reshape process first 
- Resolves rhbz#1507415
:[_n(MXiao Ni <xni@redhat.com> - 4.1.4^C- Innorrect UUID reported in volume detail
- Resolves rhbz#1789816Z'MkXiao Ni <xni@redhat.com> - 4.1.3]@- Fix CI building error
- Resolves rhbz#1773607v&M!Xiao Ni <xni@redhat.com> - 4.1.2]- imsm: fix spare activation for old matrix arrays
- Resolves rhbz#1773607~%M1Xiao Ni <xni@redhat.com> - 4.1.1\M- Update to upstream 4.1 and backport 21 patches after 4.1
- Resolves rhbz#1641473l$UXiao Ni <xni@redhat.com> - 4.1-rc1-2[b@- Fix two IMSM bugs
- Resolves rhbz#1602362 and rhbz#1602358k#UXiao Ni <xni@redhat.com> - 4.1-rc1-1[,- Upgrade to upstream mdadm-4.1-rc1
- Resolves rhbz#1494472Z"MkXiao Ni <xni@redhat.com> - 4.1.7_h- Disable raid5 journal
- Resolves rhbz#1875457d!MXiao Ni <xni@redhat.com> - 4.1.6^@- Update mdadm to latest upstream
- Resolves rhbz#1801605
TbZ0MkXiao Ni <xni@redhat.com> - 4.1.3]@- Fix CI building error
- Resolves rhbz#1773607v/M!Xiao Ni <xni@redhat.com> - 4.1.2]- imsm: fix spare activation for old matrix arrays
- Resolves rhbz#1773607~.M1Xiao Ni <xni@redhat.com> - 4.1.1\M- Update to upstream 4.1 and backport 21 patches after 4.1
- Resolves rhbz#1641473l-UXiao Ni <xni@redhat.com> - 4.1-rc1-2[b@- Fix two IMSM bugs
- Resolves rhbz#1602362 and rhbz#1602358h,MXiao Ni <xni@redhat.com> - 4.1.8aM- mdcheck start timer starts failure
- Resolves rhbz#1830736Z+MkXiao Ni <xni@redhat.com> - 4.1.7_h- Disable raid5 journal
- Resolves rhbz#1875457d*MXiao Ni <xni@redhat.com> - 4.1.6^@- Update mdadm to latest upstream
- Resolves rhbz#1801605v)M!Xiao Ni <xni@redhat.com> - 4.1.5^%@- mdcheck continue/start service has grammer error
- Resolves rhbz#1774354
	]N]]L9c9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchb8ceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsF7c-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shm6M5Xiao Ni <xni@redhat.com> - 4.1.9a@- imsm: After reboot put spare devices into right container.
- Resolves rhbz#2005306h5MXiao Ni <xni@redhat.com> - 4.1.8aM- mdcheck start timer starts failure
- Resolves rhbz#1830736Z4MkXiao Ni <xni@redhat.com> - 4.1.7_h- Disable raid5 journal
- Resolves rhbz#1875457d3MXiao Ni <xni@redhat.com> - 4.1.6^@- Update mdadm to latest upstream
- Resolves rhbz#1801605v2M!Xiao Ni <xni@redhat.com> - 4.1.5^%@- mdcheck continue/start service has grammer error
- Resolves rhbz#1774354n1MXiao Ni <xni@redhat.com> - 4.1.4^C- Innorrect UUID reported in volume detail
- Resolves rhbz#1789816
nx!-nFAc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmq@myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)q?myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){>aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h=_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965d<ciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699);aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572):e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)
wJ?kwqImyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){HaAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.hG_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dFciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)EaTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)De#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)LCc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbBceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit apps
	-A-{RaAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.hQ_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dPciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)OaTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)Ne#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)LMc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbLceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFKc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqJmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)
	7f7h[_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dZciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)YaTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)Xe#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)LWc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbVceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFUc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqTmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qSmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811)
	$M$ddciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)caTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)be#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Lac9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchb`ceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsF_c-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmq^myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)q]myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){\aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.
	 +{+ maTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)le#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Lkc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbjceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFic-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqhmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qgmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){faAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.he_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965
	;,8y;ve#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Luc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbtceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFsc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqrmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qqmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){paAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.ho_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dnciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)
	@}*@@Lc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchb~ceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsF}c-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmq|myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)q{myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){zaAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.hy_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dxciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)waTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)
nx!-nFc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)
wJ?kwqmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h
_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)
e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)L	c9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit apps
	-A-{aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Lc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)
	7f7h!_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965d ciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Lc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811)

er+V:eD]
e185e29258de4ab6f27caaedc2002626f5e10ca9ec0c4c0d9b98007fb617fa6fD\
aa52ec63113bfbe6468d7f69cefadbc170784e01175f841608614bc4443b6eb9D[
8799ebab64d83170ce71b98732944e96f18743f83950b9452d4ca10c21d7455aDZ
4709ece2740b527335e0d4d46746a1f8ddcdfbb92aef8389bef8e6944d560ee5DY
976cd3979b04d952ae4511353b7a157eff7733234abb279a441ad447656af9feDX
59f3e6ecf2f05648af5bd7cf1479e1cb010929f1310143f5e007725c4773c36cDW
0a804c07144041c1bb5d619535096838e17f54b6d6c4295d4b1551f45f7031bfDV
129ffba6bb846528ce31e13c3c411fca71678d07fa6e0e112e5862ec25ba2827DU
754f6af1bc5302dd16280e706cba386ac96e7198be4530e907559fe08ab098e3DT
de8317deebc44e01bffee751beab8a8a0e35efa4cccd2d3dd442f02026778754DS
da05a8dcff76310419bb1fc12a7598dd9d24206d8f1a6db041a8900ce84de810DR
792164299f57de7fad013d1cbb4d0847d3228f6a89e6ed330af88b4f95b4e458DQ
8f33285bb25298291523ef6f04cb95fa5815d34f7b05d4efa5f5308614c6a8db
	$M$d*ciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699))aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)(e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)L'c9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchb&ceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsF%c-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmq$myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)q#myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){"aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.
	 +{+ 3aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)2e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)L1c9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchb0ceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsF/c-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmq.myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)q-myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){,aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h+_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965
	;,8y;<e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)L;c9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchb:ceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsF9c-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmq8myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)q7myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){6aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h5_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965d4ciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)
	@}*@@LEc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbDceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFCc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqBmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qAmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){@aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h?_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965d>ciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)=aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)
nx!-nFMc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqLmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qKmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){JaAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.hI_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dHciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)GaTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)Fe#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)
wJ?kwqUmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){TaAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.hS_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dRciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)QaTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)Pe#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)LOc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbNceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit apps
	-A-{^aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h]_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965d\ciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)[aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)Ze#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)LYc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbXceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFWc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqVmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)
	7f7hg_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dfciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)eaTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)de#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Lcc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbbceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFac-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmq`myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)q_myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811)
	$M$dpciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)oaTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)ne#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Lmc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchblceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFkc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqjmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qimyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){haAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.
	 +{+ yaTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)xe#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Lwc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbvceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFuc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqtmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qsmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){raAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.hq_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965
	;,8y;e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Lc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmq~myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)q}myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){|aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h{_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dzciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)
	@}*@@Lc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchb
ceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsF	c-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)
nx!-nFc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)
aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)
wJ?kwqmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Lc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit apps
	-A-{$aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h#_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965d"ciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)!aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572) e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Lc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)

er+V:eDj
8a3167ab075b7b5fb344b2c1a8b338bb5fe197f76d476082cb8f2c3ab6e464d3Di
b9b66cac17e884fd31966a5fd2874494926a1a8d4408b6ceb84dd898b05ce3f9Dh
2f18acc2929e31dcc316b54ca1bb28829287b1d12176f94d365d38d1a1ef23c9Dg
c6531fa5a214fb87e4f247ba04ec04f2330a77311ac144e58229390092eac77cDf
4a8faacf86955f2abf551cdb070907bfb67ba8d81e0df1c694adb79e873aa809De
f4deeab3c5a75216ce3af70b11f8d415b9ca7db8bbbabd522ec02ba360b945c4Dd
d67f32510e94c118c64283659db64d073108bebd5993b1c728d0d366e4aad1bdDc
4331d246086138c76b626867bfe7e22ada968505bcd02d526951cb2236da0d31Db
c756565e383627d473b483efbba85ad5704019846d85a5578c515082ff9cf44cDa
d892760dbed5cfbe821c1f743b05a838bb1a8e646c36fc267a6ce003baac6d8bD`
8e6626556734c046cef5124024bb71c2d64d98b0563d3b93b4769c8f47380342D_
b30805264689335b37e185dca416f299366d9a6516f7c7a10cbafad4f800f432D^
df3f90935ef976e235c93ee9f86af7d2ce39b33df6bbfbd00b0187a2a6055b4f
	7f7h-_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965d,ciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)+aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)*e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)L)c9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchb(ceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsF'c-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmq&myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)q%myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811)
	$M$d6ciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)5aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)4e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)L3c9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchb2ceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsF1c-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmq0myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)q/myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){.aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.
	 +{+ ?aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)>e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)L=c9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchb<ceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsF;c-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmq:myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)q9myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){8aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h7_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965
	;,8y;He#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)LGc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbFceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFEc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqDmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qCmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){BaAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.hA_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965d@ciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)
	@}*@@LQc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbPceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFOc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqNmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qMmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){LaAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.hK_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dJciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)IaTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)
nx!-nFYc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqXmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qWmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){VaAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.hU_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dTciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)SaTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)Re#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)
wJ?kwqamyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){`aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h__uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965d^ciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)]aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)\e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)L[c9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbZceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit apps
	-A-{jaAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.hi_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dhciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)gaTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)fe#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Lec9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbdceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFcc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqbmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)
	7f7hs_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965drciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)qaTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)pe#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Loc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbnceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFmc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqlmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qkmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811)
	$M$d|ciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699){aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)ze#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Lyc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbxceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFwc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqvmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qumyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){taAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.
	 +{+ aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)Lc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){~aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h}_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965
	;,8y;e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)L
c9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmq
myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)q	myMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)
	@}*@@Lc9Dave Airlie <airlied@redhat.com> - 18.3.4-5\- fix remote shm patchbceDave Airlie <airlied@redhat.com> - 18.3.4-4\e- Enable i686 vulkan drivers for 32-bit appsFc-Dave Airlie <airlied@redhat.com> - 18.3.4-3\@- fix remote shmqmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)
x!-qmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-12_- Fix for defect reported by Coverity/clang (#1803811)qmyMichel Dänzer <mdaenzer@redhat.com> - 18.3.4-11_- Backport upstream i965 multi-screen fixes (#1803811){aAdam Jackson <ajax@redhat.com> - 18.3.4-10^W@- Revert the previous fix due to regressions in Firefox, Chrome, etc.h_uAdam Jackson <ajax@redhat.com> - 18.3.4-9^- Fix context sharing with multiple screens for i965dciDave Airlie <airlied@redhat.com> - 18.3.4-8^ku- Backport put/get shm fixes to EL7 (#1749699)aTomas Pelka <tpelka@redhat.com> - 18.3.4-7^)- bump version and rebuild to avoind conflict with 7.7.z build (#1543572)e#Ben Crocker <bcrocker@redhat.com> - 18.3.4-6^!@- Patch to require Large CodeModel for llvmpipe on ppc64/ppc64le (#1543572)

er+V:eDw
bddae66326cff2ad3bae20dfe8698be8546b0620b72acfdd23feb708989d5e53Dv
5d5db220e9130b6d2c5d13730c7f90b5554b0201e7fbeb60cfed67b092ebed44Du
ce7d925a850e5e2f13538931031755559aff5bd0677306a69a885cc9bdc20822Dt
db3908bf5643d267bcfaa924ae478da8414a6179e1b83c3700e7f99f75d8164aDs
0cf6bb4e5beb49f3a45a5171babb25685cf72156e8666dc2a57f9fef6af67838Dr
c39f22a6884386aa2ab755116305a2ebdc6ae0a68f0992d56e87e8772c8dc240Dq
52e08c5707423c423c562574e04e5f1da46c6b67f3ef38f30e4725f991a49a12Dp
09b0a412ef431cf5907e6d41f5bf960d051927c73b0a292dea9a52585f306e01Do
fb38f857551fb354a5eed747d7a1167588232589a2bfc88abc3f695d37b7e705Dn
02cae02000e8b7bc7519aaeb70ed3f09854a6bd0cb622de6b22e75aa2c644230Dm
10ba9a38035d22f8a1ee9eb610447ad60ca74948c3e82cb712eb09cf97eeecebDl
b2fbef479f23da380eafd4aa77e97d08cb7415937a751ac477c8dd39371379baDk
68b647f3d90f5828c04a513b4561ba0866363b42452fbf73668418e2faa06983-UP4 B1) microcode at revision 0x68;
  - Addition of 06-a5-02/0x20 (CML-H R1) microcode at revision 0xe0;
  - Addition of 06-a5-03/0x22 (CML-S 6+2 G1) microcode at revision 0xe0;
  - Addition of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode at revision 0xe0;
  - Addition of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode at revision
    0xe0;
  - Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xdc up to 0xe2;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006906 up
    to 0x2006a08;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xdc up to 0xe2;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) -from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xd6 up
    to 0xe0;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xd6 up to 0xde;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xd6 up
    to 0xde;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x43 up to 0x44;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000157
    up to 0x1000159;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4002f01
    up to 0x4003003;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5002f01 up to 0x5003003;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x38 up
    to 0x40;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x16 up
    to 0x1e;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x16 up
    to 0x18;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0x78
    up to 0xa0;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xca
    up to 0xe0.
K"s%Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.5__@- Do not use "grep -q" in a pipe in check_caveats.
- Add 06-55-04/06-55-06/06-55-07 (SKX-SP/CLX-SP) microcode-20201110 caveats
  (#1905111).0!soEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.4_uA- Update Intel CPU microcode to microcode-20201112 release:
  - Addition of 06-8a-01/0x10 (LKF B2/B3) microcode at revision 0x28;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x32 up
    to 0x34;
  - Updated releasenote file. s
Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.3_u@- Disable 06-8c-01 (TGL-UP3/UP4 B1) microcode update by default.Js#Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.2_@- Update Intel CPU microcode to microcode-20201027 release, addresses
  CVE-2020-8694, CVE-2020-8695, CVE-2020-8696, CVE-2020-8698
  (#1893261, #1893249, #1893229):
  - Addition of 06-55-0b/0xbf (CPX-SP A1) microcode at revision 0x700001e;
  - Addition of 06-8c-01/0x80 (TGL-UP3/-
ff&sEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.9`- Update Intel CPU microcode to microcode-20210525 release, addresses
  CVE-2020-24489, CVE-2-e%sYEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.8`-A- Update Intel CPU microcode to microcode-20210216 release (#1905111):
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006a08 up
    to 0x2006a0a;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003003
    up to 0x4003006;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003003 up to 0x5003006.$s+Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.7`-@- Remove 06-55-04/06-55-06/06-55-07 (SKX-SP/CLX-SP) microcode-20201110 caveats.t#syEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.6`%@- Backport check_dmi_val to check_caveats from RHEL 8.-020-24511, CVE-2020-24512, and CVE-2020-24513
  (#1962659, #1962709, #1962729, #1962675):
  - Addition of 06-55-05/0xb7 (CLX-SP A0) microcode at revision 0x3000010;
  - Addition of 06-6a-05/0x87 (ICX-SP C0) microcode at revision 0xc0002f0;
  - Addition of 06-6a-06/0x87 (ICX-SP D0) microcode at revision 0xd0002a0;
  - Addition of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f;
  - Addition of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04)
    at revision 0xb00000f;
  - Addition of 06-86-04/0x01 (SNR B0) microcode (in intel-ucode/06-86-05)
    at revision 0xb00000f;
  - Addition of 06-86-05/0x01 (SNR B1) microcode at revision 0xb00000f;
  - Addition of 06-8c-02/0xc2 (TGL-R C0) microcode at revision 0x16;
  - Addition of 06-8d-01/0xc2 (TGL-H R0) microcode at revision 0x2c;
  - Addition of 06-96-01/0x01 (EHL B1) microcode at revision 0x11;
  - Addition of 06-9c-00/0x01 (JSL A0/A1) microcode at revision 0x1d;
  - Addition of 06-a7-01/0x02 (RKL-S B0) microcode at revision 0x40;
  - Update of- 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xe2 up to 0xea;
  - Update of 06-4f-01/0xef (BDX-E/EP/EX/ML B0/M0/R0) microcode (in
    intel-06-4f-01/intel-ucode/06-4f-01) from revision 0xb000038 up
    to 0xb00003e;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006a0a up
    to 0x2006b06;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xe2 up to 0xea;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x68 up to 0x88;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xde up
    to 0xea;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xde up
    to 0xea;
  - Update of 06-8e-0a/0x.c0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xe0 up
    to 0xea;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) from revision 0xde up
    to 0xea;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xde up to 0xea;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xde up
    to 0xea;
  - Upd.ate of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xde up
    to 0xea;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x44 up to 0x46;
  - Update of 06-3f-04/0x80 (HSX-EX E0) microcode from revision 0x16 up
    to 0x19;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000159
    up to 0x100015b;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003006
    up to 0x4003102;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003006 up to 0x5003102;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x700001e
    up to 0x7002302;
  - Update of 06-56-03/0x10 (BDX-DE V2/V3) microcode from revision
    0x7000019 up to 0x700001b;
  - Update of 06-56-04/0x10 (BDX-DE Y0) microcode from revision 0xf000017
    up to 0xf000019;
  - Update of 06-56-05/0x10 (BDX-NS A0/A1, HWL A1) microcode from revision
    0xe00000f up to 0xe000012;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x40 up
    to 0x44;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x1e up
    to 0x20;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x2e up
    to 0x34;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x34 up
    to 0x36;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x18 up
    to 0x1a;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa0
    up to 0xa6;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x28 up
    to 0x2a;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xe0 up
    to 0xea;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xe0
    up to 0xea;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xe0
    up to 0xec;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xe0
    up to 0xe8;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode from revision
    0xe0 up to 0xea.
0)soEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.4_u@- Update Intel CPU microcode to microcode-20201112 release:
  - Addition of 06-8a-01/0x10 (LKF B2/B3) microcode at revision 0x28;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x32 up
    to 0x34;
  - Updated releasenote file.(uGEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.11`A- Update Intel CPU microcode to microcode-20210608 release:
  - Fixes in releasenote.md file.i'u_Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.10`@- Make intel-06-2d-07, intel-06-4e-03, intel-06-4f-01, intel-06-55-04,
  intel-06-5e-03, intel-06-8c-01, intel-06-8e-9e-0x-0xca,
  and intel-06-8e-9e-0x-dell caveats dependent on intel caveat.
- Enable 06-8c-01 microcode update by default.
- Enable 06-5e-03 microcode update by default (#1897684).
;0%;e-sYEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.8`-A- Update Intel CPU microcode to microcode-20210216 release (#1905111):
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006a08 up
    to 0x2006a0a;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003003
    up to 0x4003006;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003003 up to 0x5003006.,s+Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.7`-@- Remove 06-55-04/06-55-06/06-55-07 (SKX-SP/CLX-SP) microcode-20201110 caveats.t+syEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.6`%@- Backport check_dmi_val to check_caveats from RHEL 8.K*s%Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.5__@- Do not use "grep -q" in a pipe in check_caveats.
- Add 06-55-04/06-55-06/06-55-07 (SKX-SP/CLX-SP) microcode-20201110 caveats
  (#1905111)..020-24511, CVE-2020-24512, and CVE-2020-24513
  (#1962659, #1962709, #1962729, #1962675):
  - Addition of 06-55-05/0xb7 (CLX-SP A0) microcode at revision 0x3000010;
  - Addition of 06-6a-05/0x87 (ICX-SP C0) microcode at revision 0xc0002f0;
  - Addition of 06-6a-06/0x87 (ICX-SP D0) microcode at revision 0xd0002a0;
  - Addition of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f;
  - Addition of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04)
    at revision 0xb00000f;
  - Addition of 06-86-04/0x01 (SNR B0) microcode (in intel-ucode/06-86-05)
    at revision 0xb00000f;
  - Addition of 06-86-05/0x01 (SNR B1) microcode at revision 0xb00000f;
  - Addition of 06-8c-02/0xc2 (TGL-R C0) microcode at revision 0x16;
  - Addition of 06-8d-01/0xc2 (TGL-H R0) microcode at revision 0x2c;
  - Addition of 06-96-01/0x01 (EHL B1) microcode at revision 0x11;
  - Addition of 06-9c-00/0x01 (JSL A0/A1) microcode at revision 0x1d;
  - Addition of 06-a7-01/0x02 (RKL-S B0) microcode at revision 0x40;
  - Update of. 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xe2 up to 0xea;
  - Update of 06-4f-01/0xef (BDX-E/EP/EX/ML B0/M0/R0) microcode (in
    intel-06-4f-01/intel-ucode/06-4f-01) from revision 0xb000038 up
    to 0xb00003e;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006a0a up
    to 0x2006b06;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xe2 up to 0xea;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x68 up to 0x88;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xde up
    to 0xea;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xde up
    to 0xea;
  - Update of 06-8e-0a/0x.c0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xe0 up
    to 0xea;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) from revision 0xde up
    to 0xea;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xde up to 0xea;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xde up
    to 0xea;
  - Upd.ate of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xde up
    to 0xea;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x44 up to 0x46;
  - Update of 06-3f-04/0x80 (HSX-EX E0) microcode from revision 0x16 up
    to 0x19;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000159
    up to 0x100015b;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003006
    up to 0x4003102;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003006 up to 0x5003102;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x700001e
    up to 0x7002302;
  - Update of 06-56-03/0x10 (BDX-DE V2/V3) microcode from revision
    0x7000019 up to 0x700001b;
  - Update of 06-56-04/0x10 (BDX-DE Y0) microcode from revision 0xf000017
    up to 0xf000019;
  - Update of 06-56-05/0x10 (BDX-NS A0/A1, HWL A1) microcode from revision
    0xe00000f up to 0xe000012;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x40 up
    to 0x44;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x1e up
    to 0x20;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x2e up
    to 0x34;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x34 up
    to 0x36;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x18 up
    to 0x1a;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa0
    up to 0xa6;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x28 up
    to 0x2a;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xe0 up
    to 0xea;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xe0
    up to 0xea;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xe0
    up to 0xec;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xe0
    up to 0xe8;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode from revision
    0xe0 up to 0xea.
K[K0uGEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.11`A- Update Intel CPU microcode to microcode-20210608 release:
  - Fixes in releasenote.md file.i/u_Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.10`@- Make intel-06-2d-07, intel-06-4e-03, intel-06-4f-01, intel-06-55-04,
  intel-06-5e-03, intel-06-8c-01, intel-06-8e-9e-0x-0xca,
  and intel-06-8e-9e-0x-dell caveats dependent on intel caveat.
- Enable 06-8c-01 microcode update by default.
- Enable 06-5e-03 microcode update by default (#1897684)..sEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.9`- Update Intel CPU microcode to microcode-20210525 release, addresses
  CVE-2020-24489, CVE-2.. Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xea up to 0xec;
  - Update of 06-4f-01/0xef (BDX-E/EP/EX/ML B0/M0/R0) microcode (in
    intel-06-4f-01/intel-ucode/06-4f-01) from revision 0xb00003e up
    to 0xb000040;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006b06 up
    to 0x2006c0a;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xea up to 0xec;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x88 up to 0x9a;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x46 up to 0x49;
  - Update of 06-3f-04/0x80 (HSX-EX E0) microcode from revision 0x19 up
    to 0x1a;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x100015b
    up to 0x100015c;
  - Update of 06-55-.06/0xbf (CLX-SP B0) microcode from revision 0x4003102
    up to 0x400320a;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003102 up to 0x500320a;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002302
    up to 0x7002402;
  - Update of 06-56-03/0x10 (BDX-DE V2/V3) microcode from revision
    0x700001b up to 0x700001c;
  - Update of 06-56-04/0x10 (BDX-DE Y0) microcode from revision 0xf000019
    up to 0xf00001a;
  - Update of 06-56-05/0x10 (BDX-NS A0/A1, HWL A1) microcode from revision
    0xe000012 up to 0xe000014;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x44 up
    to 0x46;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x20 up
    to 0x24;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x34 up
    to 0x36;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd0002a0
    up to 0xd000331;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x36 up
    to 0x38;
  - Update of 06-7a-08/.
0x01 (GLK-R R0) microcode from revision 0x1a up
    to 0x1c;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa6
    up to 0xa8;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x2a up
    to 0x2d;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x16 up
    to 0x22;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x2c up
    to 0x3c;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode from revision 0xea
    up to 0xec;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode from revision
    0xea up to 0xec;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode from
    revision 0xea up to 0xec;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode from revision 0xea up
    to 0xec;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode from revision 0xea up to 0xec;
  - Update of 06-96-01/0x01 (EHL B1) microcode from revision 0x11 up
    to 0x15;
  - Update of 06-9c-00/0x01 (JSL A0/A1) microcode from revision 0x1d up
    to 0x2400001f;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode from
    revision 0xea up to 0xec;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode from revision
    0xea up to 0xec;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode from revision 0xea
    up to 0xec;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode from revision
    0xea up to 0xec;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode from revision
    0xea up to 0xec;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xea up
    to 0xec;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xea
    up to 0xec;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xec
    up to 0xee;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xe8
    up to 0xea;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K1) microcode from revision
    0xea up to 0xec;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x40 up
    to 0x50.
U%UK3s%Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.5__@- Do not use "grep -q" in a pipe in check_caveats.
- Add 06-55-04/06-55-06/06-55-07 (SKX-SP/CLX-SP) microcode-20201110 caveats
  (#1905111).2uGEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.13b@- Update Intel CPU microcode to microcode-20220207 release:
  - Fixes in releasenote.md file. 1uMEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.12b	- Update Intel CPU microcode to microcode-20220204 release, addresses
  CVE-2021-0127, CVE-2021-0145, CVE-2021-33120 (#2051547, #2049549, #2049566):
  - Removal of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f;
  - Removal of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04)
    at revision 0xb00000f;
  - Removal of 06-86-04/0x01 (SNR B0) microcode (in intel-ucode/06-86-05)
    at revision 0xb00000f;
  - Removal of 06-86-05/0x01 (SNR B1) microcode at revision 0xb00000f;
  -.

ff7sEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.9`- Update Intel CPU microcode to microcode-20210525 release, addresses
  CVE-2020-24489, CVE-2.e6sYEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.8`-A- Update Intel CPU microcode to microcode-20210216 release (#1905111):
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006a08 up
    to 0x2006a0a;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003003
    up to 0x4003006;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003003 up to 0x5003006.5s+Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.7`-@- Remove 06-55-04/06-55-06/06-55-07 (SKX-SP/CLX-SP) microcode-20201110 caveats.t4syEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.6`%@- Backport check_dmi_val to check_caveats from RHEL 8..020-24511, CVE-2020-24512, and CVE-2020-24513
  (#1962659, #1962709, #1962729, #1962675):
  - Addition of 06-55-05/0xb7 (CLX-SP A0) microcode at revision 0x3000010;
  - Addition of 06-6a-05/0x87 (ICX-SP C0) microcode at revision 0xc0002f0;
  - Addition of 06-6a-06/0x87 (ICX-SP D0) microcode at revision 0xd0002a0;
  - Addition of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f;
  - Addition of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04)
    at revision 0xb00000f;
  - Addition of 06-86-04/0x01 (SNR B0) microcode (in intel-ucode/06-86-05)
    at revision 0xb00000f;
  - Addition of 06-86-05/0x01 (SNR B1) microcode at revision 0xb00000f;
  - Addition of 06-8c-02/0xc2 (TGL-R C0) microcode at revision 0x16;
  - Addition of 06-8d-01/0xc2 (TGL-H R0) microcode at revision 0x2c;
  - Addition of 06-96-01/0x01 (EHL B1) microcode at revision 0x11;
  - Addition of 06-9c-00/0x01 (JSL A0/A1) microcode at revision 0x1d;
  - Addition of 06-a7-01/0x02 (RKL-S B0) microcode at revision 0x40;
  - Update of. 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xe2 up to 0xea;
  - Update of 06-4f-01/0xef (BDX-E/EP/EX/ML B0/M0/R0) microcode (in
    intel-06-4f-01/intel-ucode/06-4f-01) from revision 0xb000038 up
    to 0xb00003e;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006a0a up
    to 0x2006b06;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xe2 up to 0xea;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x68 up to 0x88;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xde up
    to 0xea;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xde up
    to 0xea;
  - Update of 06-8e-0a/0x.c0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xe0 up
    to 0xea;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) from revision 0xde up
    to 0xea;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xde up to 0xea;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xde up
    to 0xea;
  - Upd.ate of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xde up
    to 0xea;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x44 up to 0x46;
  - Update of 06-3f-04/0x80 (HSX-EX E0) microcode from revision 0x16 up
    to 0x19;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000159
    up to 0x100015b;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003006
    up to 0x4003102;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003006 up to 0x5003102;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x700001e
    up to 0x7002302;
  - Update of 06-56-03/0x10 (BDX-DE V2/V3) microcode from revision
    0x7000019 up to 0x700001b;
  - Update of 06-56-04/0x10 (BDX-DE Y0) microcode from revision 0xf000017
    up to 0xf000019;
  - Update of 06-56-05/0x10 (BDX-NS A0/A1, HWL A1) microcode from revision
    0xe00000f up to 0xe000012;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x40 up
    to 0x44;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x1e up
    to 0x20;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x2e up
    to 0x34;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x34 up
    to 0x36;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x18 up
    to 0x1a;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa0
    up to 0xa6;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x28 up
    to 0x2a;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xe0 up
    to 0xea;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xe0
    up to 0xea;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xe0
    up to 0xec;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xe0
    up to 0xe8;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode from revision
    0xe0 up to 0xea.
9uGEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.11`A- Update Intel CPU microcode to microcode-20210608 release:
  - Fixes in releasenote.md file.i8u_Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.10`@- Make intel-06-2d-07, intel-06-4e-03, intel-06-4f-01, intel-06-55-04,
  intel-06-5e-03, intel-06-8c-01, intel-06-8e-9e-0x-0xca,
  and intel-06-8e-9e-0x-dell caveats dependent on intel caveat.
- Enable 06-8c-01 microcode update by default.
- Enable 06-5e-03 microcode update by default (#1897684).. Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xea up to 0xec;
  - Update of 06-4f-01/0xef (BDX-E/EP/EX/ML B0/M0/R0) microcode (in
    intel-06-4f-01/intel-ucode/06-4f-01) from revision 0xb00003e up
    to 0xb000040;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006b06 up
    to 0x2006c0a;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xea up to 0xec;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x88 up to 0x9a;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x46 up to 0x49;
  - Update of 06-3f-04/0x80 (HSX-EX E0) microcode from revision 0x19 up
    to 0x1a;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x100015b
    up to 0x100015c;
  - Update of 06-55-.06/0xbf (CLX-SP B0) microcode from revision 0x4003102
    up to 0x400320a;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003102 up to 0x500320a;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002302
    up to 0x7002402;
  - Update of 06-56-03/0x10 (BDX-DE V2/V3) microcode from revision
    0x700001b up to 0x700001c;
  - Update of 06-56-04/0x10 (BDX-DE Y0) microcode from revision 0xf000019
    up to 0xf00001a;
  - Update of 06-56-05/0x10 (BDX-NS A0/A1, HWL A1) microcode from revision
    0xe000012 up to 0xe000014;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x44 up
    to 0x46;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x20 up
    to 0x24;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x34 up
    to 0x36;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd0002a0
    up to 0xd000331;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x36 up
    to 0x38;
  - Update of 06-7a-08/.0x01 (GLK-R R0) microcode from revision 0x1a up
    to 0x1c;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa6
    up to 0xa8;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x2a up
    to 0x2d;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x16 up
    to 0x22;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x2c up
    to 0x3c;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode from revision 0xea
    up to 0xec;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode from revision
    0xea up to 0xec;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode from
    revision 0xea up to 0xec;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode from revision 0xea up
    to 0xec;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode from revision 0xea up to 0xec;
  - Update of 06-96-01/0x01 (EHL B1) microcode from revision 0x11 up
    to 0x15;
  - Update of 06-9c-00/0x01 (JSL A0/A1) microcode from revision 0x1d up
    to 0x2400001f;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode from
    revision 0xea up to 0xec;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode from revision
    0xea up to 0xec;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode from revision 0xea
    up to 0xec;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode from revision
    0xea up to 0xec;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode from revision
    0xea up to 0xec;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xea up
    to 0xec;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xea
    up to 0xec;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xec
    up to 0xee;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xe8
    up to 0xea;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K1) microcode from revision
    0xea up to 0xec;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x40 up
    to 0x50.
=%=t=syEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.6`%@- Backport check_dmi_val to check_caveats from RHEL 8.c<uSEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.14bzS- Update Intel CPU microcode to microco.;uGEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.13b@- Update Intel CPU microcode to microcode-20220207 release:
  - Fixes in releasenote.md file. :uMEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.12b	- Update Intel CPU microcode to microcode-20220204 release, addresses
  CVE-2021-0127, CVE-2021-0145, CVE-2021-33120 (#2051547, #2049549, #2049566):
  - Removal of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f;
  - Removal of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04)
    at revision 0xb00000f;
  - Removal of 06-86-04/0x01 (SNR B0) microcode (in intel-ucode/06-86-05)
    at revision 0xb00000f;
  - Removal of 06-86-05/0x01 (SNR B1) microcode at revision 0xb00000f;
  -..de-20220510 release, addresses
  CVE-2022-0005, CVE-2022-21131, CVE-2022-21136, CVE-2022-21151 (#2090246,
    - Addition of 06-97-02/0x03 (ADL-HX C0) microcode at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-97-02) at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    at revision 0x1f;
  - Addition of 06-97-02/0x03 (ADL-HX C0) microcode (in
    intel-ucode/06-97-05) at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    at revision 0x1f;
  - Addition of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode at
    revision 0x41c;
  - Addition of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode (in
    intel-ucode/06-9a-03) at revi.sion 0x41c;
  - Addition of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode (in
    intel-ucode/06-9a-04) at revision 0x41c;
  - Addition of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode at revision 0x41c;
  - Addition of 06-97-02/0x03 (ADL-HX C0) microcode (in
    intel-ucode/06-bf-02) at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-02) at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-bf-02)
    at revision 0x1f;
  - Addition of 06-97-02/0x03 (ADL-HX C0) microcode (in
    intel-ucode/06-bf-05) at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-05) at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-bf-05)
    at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode at revision 0x1f;
  - Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/inte.l-ucode/06-4e-03) from revision 0xec up to 0xf0;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006c0a up
    to 0x2006d05;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xec up to 0xf0;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x9a up to 0xa4;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xec up
    to 0xf0;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xec up
    to 0xf0;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xec up
    to 0xf0;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) .from revision 0xec up
    to 0xf0;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xec up to 0xf0;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xec up
    to 0xf0;
  - Update of 06-37-09/0x0f (VLV D0) microcode from revision 0x90c up
    to 0x90d;
  - Up. date of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x100015c
    up to 0x100015d;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x400320a
    up to 0x4003302;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x500320a up to 0x5003302;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002402
    up to 0x7002501;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x46 up
    to 0x48;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x24 up
    to 0x28;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x36 up
    to 0x38;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd000331
    up to 0xd000363;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x38 up
    to 0x3a;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x1c up
    to 0x1e;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa8
    up to 0xb0;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x2d up
    to 0x31;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x22 up
    to 0x26;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x3c up
    to 0x3e;
  - Update of 06-96-01/0x01 (EHL B1) microcode from revision 0x15 up
    to 0x16;
  - Update of 06-9c-00/0x01 (JSL A0/A1) microcode from revision 0x2400001f
    up to 0x24000023;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xec up
    to 0xf0;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xec
    up to 0xf0;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xee
    up to 0xf0;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xea
    up to 0xf0;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K1) microcode from revision
    0xec up to 0xf0;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x50 up
    to 0x53.
m@sEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.9`- Update Intel CPU microcode to microcode-20210525 release, addresses
  CVE-2020-24489, CVE-2."e?sYEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.8`-A- Update Intel CPU microcode to microcode-20210216 release (#1905111):
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006a08 up
    to 0x2006a0a;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003003
    up to 0x4003006;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003003 up to 0x5003006.>s+Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.7`-@- Remove 06-55-04/06-55-06/06-55-07 (SKX-SP/CLX-SP) microcode-20201110 caveats..#020-24511, CVE-2020-24512, and CVE-2020-24513
  (#1962659, #1962709, #1962729, #1962675):
  - Addition of 06-55-05/0xb7 (CLX-SP A0) microcode at revision 0x3000010;
  - Addition of 06-6a-05/0x87 (ICX-SP C0) microcode at revision 0xc0002f0;
  - Addition of 06-6a-06/0x87 (ICX-SP D0) microcode at revision 0xd0002a0;
  - Addition of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f;
  - Addition of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04)
    at revision 0xb00000f;
  - Addition of 06-86-04/0x01 (SNR B0) microcode (in intel-ucode/06-86-05)
    at revision 0xb00000f;
  - Addition of 06-86-05/0x01 (SNR B1) microcode at revision 0xb00000f;
  - Addition of 06-8c-02/0xc2 (TGL-R C0) microcode at revision 0x16;
  - Addition of 06-8d-01/0xc2 (TGL-H R0) microcode at revision 0x2c;
  - Addition of 06-96-01/0x01 (EHL B1) microcode at revision 0x11;
  - Addition of 06-9c-00/0x01 (JSL A0/A1) microcode at revision 0x1d;
  - Addition of 06-a7-01/0x02 (RKL-S B0) microcode at revision 0x40;
  - Update of.$ 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xe2 up to 0xea;
  - Update of 06-4f-01/0xef (BDX-E/EP/EX/ML B0/M0/R0) microcode (in
    intel-06-4f-01/intel-ucode/06-4f-01) from revision 0xb000038 up
    to 0xb00003e;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006a0a up
    to 0x2006b06;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xe2 up to 0xea;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x68 up to 0x88;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xde up
    to 0xea;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xde up
    to 0xea;
  - Update of 06-8e-0a/0x.%c0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xe0 up
    to 0xea;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) from revision 0xde up
    to 0xea;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xde up to 0xea;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xde up
    to 0xea;
  - Upd.&ate of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xde up
    to 0xea;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x44 up to 0x46;
  - Update of 06-3f-04/0x80 (HSX-EX E0) microcode from revision 0x16 up
    to 0x19;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000159
    up to 0x100015b;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003006
    up to 0x4003102;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003006 up to 0x5003102;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x700001e
    up to 0x7002302;
  - Update of 06-56-03/0x10 (BDX-DE V2/V3) microcode from revision
    0x7000019 up to 0x700001b;
  - Update of 06-56-04/0x10 (BDX-DE Y0) microcode from revision 0xf000017
    up to 0xf000019;
  - Update of 06-56-05/0x10 (BDX-NS A0/A1, HWL A1) microcode from revision
    0xe00000f up to 0xe000012;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x40 up
    to 0x44;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x1e up
    to 0x20;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x2e up
    to 0x34;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x34 up
    to 0x36;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x18 up
    to 0x1a;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa0
    up to 0xa6;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x28 up
    to 0x2a;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xe0 up
    to 0xea;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xe0
    up to 0xea;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xe0
    up to 0xec;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xe0
    up to 0xe8;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode from revision
    0xe0 up to 0xea.
BuGEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.11`A- Update Intel CPU microcode to microcode-20210608 release:
  - Fixes in releasenote.md file.iAu_Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.10`@- Make intel-06-2d-07, intel-06-4e-03, intel-06-4f-01, intel-06-55-04,
  intel-06-5e-03, intel-06-8c-01, intel-06-8e-9e-0x-0xca,
  and intel-06-8e-9e-0x-dell caveats dependent on intel caveat.
- Enable 06-8c-01 microcode update by default.
- Enable 06-5e-03 microcode update by default (#1897684)..) Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xea up to 0xec;
  - Update of 06-4f-01/0xef (BDX-E/EP/EX/ML B0/M0/R0) microcode (in
    intel-06-4f-01/intel-ucode/06-4f-01) from revision 0xb00003e up
    to 0xb000040;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006b06 up
    to 0x2006c0a;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xea up to 0xec;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x88 up to 0x9a;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x46 up to 0x49;
  - Update of 06-3f-04/0x80 (HSX-EX E0) microcode from revision 0x19 up
    to 0x1a;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x100015b
    up to 0x100015c;
  - Update of 06-55-.*06/0xbf (CLX-SP B0) microcode from revision 0x4003102
    up to 0x400320a;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003102 up to 0x500320a;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002302
    up to 0x7002402;
  - Update of 06-56-03/0x10 (BDX-DE V2/V3) microcode from revision
    0x700001b up to 0x700001c;
  - Update of 06-56-04/0x10 (BDX-DE Y0) microcode from revision 0xf000019
    up to 0xf00001a;
  - Update of 06-56-05/0x10 (BDX-NS A0/A1, HWL A1) microcode from revision
    0xe000012 up to 0xe000014;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x44 up
    to 0x46;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x20 up
    to 0x24;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x34 up
    to 0x36;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd0002a0
    up to 0xd000331;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x36 up
    to 0x38;
  - Update of 06-7a-08/.+0x01 (GLK-R R0) microcode from revision 0x1a up
    to 0x1c;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa6
    up to 0xa8;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x2a up
    to 0x2d;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x16 up
    to 0x22;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x2c up
    to 0x3c;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode from revision 0xea
    up to 0xec;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode from revision
    0xea up to 0xec;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode from
    revision 0xea up to 0xec;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode from revision 0xea up
    to 0xec;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode from revision 0xea up to 0xec;
  - Update of 06-96-01/0x01 (EHL B1) microcode from revision 0x11 up
    to 0x15;
  - Update of 06-9c-00/0x01 (JSL A0/A1) microcode from revision 0x1d up
    to 0x2400001f;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode from
    revision 0xea up to 0xec;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode from revision
    0xea up to 0xec;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode from revision 0xea
    up to 0xec;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode from revision
    0xea up to 0xec;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode from revision
    0xea up to 0xec;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xea up
    to 0xec;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xea
    up to 0xec;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xec
    up to 0xee;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xe8
    up to 0xea;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K1) microcode from revision
    0xea up to 0xec;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x40 up
    to 0x50.
E%E3FusEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.15bL@- Update Intel CPU microcode to microco.3cEuSEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.14bzS- Update Intel CPU microcode to microco.-DuGEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.13b@- Update Intel CPU microcode to microcode-20220207 release:
  - Fixes in releasenote.md file. CuMEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.12b	- Update Intel CPU microcode to microcode-20220204 release, addresses
  CVE-2021-0127, CVE-2021-0145, CVE-2021-33120 (#2051547, #2049549, #2049566):
  - Removal of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f;
  - Removal of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04)
    at revision 0xb00000f;
  - Removal of 06-86-04/0x01 (SNR B0) microcode (in intel-ucode/06-86-05)
    at revision 0xb00000f;
  - Removal of 06-86-05/0x01 (SNR B1) microcode at revision 0xb00000f;
  -.(..de-20220510 release, addresses
  CVE-2022-0005, CVE-2022-21131, CVE-2022-21136, CVE-2022-21151 (#2090246,
    - Addition of 06-97-02/0x03 (ADL-HX C0) microcode at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-97-02) at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    at revision 0x1f;
  - Addition of 06-97-02/0x03 (ADL-HX C0) microcode (in
    intel-ucode/06-97-05) at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    at revision 0x1f;
  - Addition of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode at
    revision 0x41c;
  - Addition of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode (in
    intel-ucode/06-9a-03) at revi./sion 0x41c;
  - Addition of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode (in
    intel-ucode/06-9a-04) at revision 0x41c;
  - Addition of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode at revision 0x41c;
  - Addition of 06-97-02/0x03 (ADL-HX C0) microcode (in
    intel-ucode/06-bf-02) at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-02) at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-bf-02)
    at revision 0x1f;
  - Addition of 06-97-02/0x03 (ADL-HX C0) microcode (in
    intel-ucode/06-bf-05) at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-05) at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-bf-05)
    at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode at revision 0x1f;
  - Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/inte.0l-ucode/06-4e-03) from revision 0xec up to 0xf0;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006c0a up
    to 0x2006d05;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xec up to 0xf0;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x9a up to 0xa4;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xec up
    to 0xf0;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xec up
    to 0xf0;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xec up
    to 0xf0;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) .1from revision 0xec up
    to 0xf0;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xec up to 0xf0;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xec up
    to 0xf0;
  - Update of 06-37-09/0x0f (VLV D0) microcode from revision 0x90c up
    to 0x90d;
  - Up.2date of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x100015c
    up to 0x100015d;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x400320a
    up to 0x4003302;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x500320a up to 0x5003302;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002402
    up to 0x7002501;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x46 up
    to 0x48;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x24 up
    to 0x28;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x36 up
    to 0x38;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd000331
    up to 0xd000363;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x38 up
    to 0x3a;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x1c up
    to 0x1e;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa8
    up to 0xb0;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x2d up
    to 0x31;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x22 up
    to 0x26;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x3c up
    to 0x3e;
  - Update of 06-96-01/0x01 (EHL B1) microcode from revision 0x15 up
    to 0x16;
  - Update of 06-9c-00/0x01 (JSL A0/A1) microcode from revision 0x2400001f
    up to 0x24000023;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xec up
    to 0xf0;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xec
    up to 0xf0;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xee
    up to 0xf0;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xea
    up to 0xf0;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K1) microcode from revision
    0xec up to 0xf0;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x50 up
    to 0x53..4de-20220510 release, addresses
  CVE-2022-21233 (#2119080):
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006d05 up
    to 0x2006e05;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x100015d
    up to 0x100015e;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd000363
    up to 0xd000375;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x3a up
    to 0x3c;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x1e up
    to 0x20;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xb0
    up to 0xb2;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x26 up
    to 0x28;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x3e up
    to 0x40;
  - Update of 06-97-02/0x03 (ADL-HX/S 8+8 C0) microcode from revision
    0x1f up to 0x22;
  - Update of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-97-02) from revision 0x1f up.5 to 0x22;
  - Update of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x1f up to 0x22;
  - Update of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x1f up to 0x22;
  - Update of 06-97-02/0x03 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-97-05) from revision 0x1f up to 0x22;
  - Update of 06-97-05/0x03 (ADL-S 6+0 K0) microcode from revision 0x1f
    up to 0x22;
  - Update of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    from revision 0x1f up to 0x22;
  - Update of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    from revision 0x1f up to 0x22;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode from revision
    0x41c up to 0x421;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode (in
    intel-ucode/06-9a-03) from revision 0x41c up to 0x421;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode (in
    intel-ucode/06-9a-04) from revision 0x41c up to 0x421;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode from revision 0x41c
    up to 0x421;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x53 up
    to 0x54;
  - Update of 06-97-02/0x03 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-02) from revision 0x1f up to 0x22;
  - Update of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-02) from revision 0x1f up to 0x22;
  - Update of 06-bf-02/0x03 (ADL C0) microcode from revision 0x1f up
    to 0x22;
  - Update of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-bf-02)
    from revision 0x1f up to 0x22;
  - Update of 06-97-02/0x03 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-05) from revision 0x1f up to 0x22;
  - Update of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-05) from revision 0x1f up to 0x22;
  - Update of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-bf-05)
    from revision 0x1f up to 0x22;
  - Update of 06-bf-05/0x03 (ADL C0) microcode from revision 0x1f up
    to 0x22.
mIsEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.9`- Update Intel CPU microcode to microcode-20210525 release, addresses
  CVE-2020-24489, CVE-2.7eHsYEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.8`-A- Update Intel CPU microcode to microcode-20210216 release (#1905111):
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006a08 up
    to 0x2006a0a;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003003
    up to 0x4003006;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003003 up to 0x5003006.Gs+Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.7`-@- Remove 06-55-04/06-55-06/06-55-07 (SKX-SP/CLX-SP) microcode-20201110 caveats..8020-24511, CVE-2020-24512, and CVE-2020-24513
  (#1962659, #1962709, #1962729, #1962675):
  - Addition of 06-55-05/0xb7 (CLX-SP A0) microcode at revision 0x3000010;
  - Addition of 06-6a-05/0x87 (ICX-SP C0) microcode at revision 0xc0002f0;
  - Addition of 06-6a-06/0x87 (ICX-SP D0) microcode at revision 0xd0002a0;
  - Addition of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f;
  - Addition of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04)
    at revision 0xb00000f;
  - Addition of 06-86-04/0x01 (SNR B0) microcode (in intel-ucode/06-86-05)
    at revision 0xb00000f;
  - Addition of 06-86-05/0x01 (SNR B1) microcode at revision 0xb00000f;
  - Addition of 06-8c-02/0xc2 (TGL-R C0) microcode at revision 0x16;
  - Addition of 06-8d-01/0xc2 (TGL-H R0) microcode at revision 0x2c;
  - Addition of 06-96-01/0x01 (EHL B1) microcode at revision 0x11;
  - Addition of 06-9c-00/0x01 (JSL A0/A1) microcode at revision 0x1d;
  - Addition of 06-a7-01/0x02 (RKL-S B0) microcode at revision 0x40;
  - Update of.9 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xe2 up to 0xea;
  - Update of 06-4f-01/0xef (BDX-E/EP/EX/ML B0/M0/R0) microcode (in
    intel-06-4f-01/intel-ucode/06-4f-01) from revision 0xb000038 up
    to 0xb00003e;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006a0a up
    to 0x2006b06;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xe2 up to 0xea;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x68 up to 0x88;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xde up
    to 0xea;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xde up
    to 0xea;
  - Update of 06-8e-0a/0x.:c0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xe0 up
    to 0xea;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) from revision 0xde up
    to 0xea;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xde up to 0xea;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xde up
    to 0xea;
  - Upd.;ate of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xde up
    to 0xea;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x44 up to 0x46;
  - Update of 06-3f-04/0x80 (HSX-EX E0) microcode from revision 0x16 up
    to 0x19;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000159
    up to 0x100015b;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003006
    up to 0x4003102;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003006 up to 0x5003102;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x700001e
    up to 0x7002302;
  - Update of 06-56-03/0x10 (BDX-DE V2/V3) microcode from revision
    0x7000019 up to 0x700001b;
  - Update of 06-56-04/0x10 (BDX-DE Y0) microcode from revision 0xf000017
    up to 0xf000019;
  - Update of 06-56-05/0x10 (BDX-NS A0/A1, HWL A1) microcode from revision
    0xe00000f up to 0xe000012;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x40 up
    to 0x44;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x1e up
    to 0x20;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x2e up
    to 0x34;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x34 up
    to 0x36;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x18 up
    to 0x1a;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa0
    up to 0xa6;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x28 up
    to 0x2a;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xe0 up
    to 0xea;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xe0
    up to 0xea;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xe0
    up to 0xec;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xe0
    up to 0xe8;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode from revision
    0xe0 up to 0xea.
KuGEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.11`A- Update Intel CPU microcode to microcode-20210608 release:
  - Fixes in releasenote.md file.iJu_Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.10`@- Make intel-06-2d-07, intel-06-4e-03, intel-06-4f-01, intel-06-55-04,
  intel-06-5e-03, intel-06-8c-01, intel-06-8e-9e-0x-0xca,
  and intel-06-8e-9e-0x-dell caveats dependent on intel caveat.
- Enable 06-8c-01 microcode update by default.
- Enable 06-5e-03 microcode update by default (#1897684)..> Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xea up to 0xec;
  - Update of 06-4f-01/0xef (BDX-E/EP/EX/ML B0/M0/R0) microcode (in
    intel-06-4f-01/intel-ucode/06-4f-01) from revision 0xb00003e up
    to 0xb000040;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006b06 up
    to 0x2006c0a;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xea up to 0xec;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x88 up to 0x9a;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x46 up to 0x49;
  - Update of 06-3f-04/0x80 (HSX-EX E0) microcode from revision 0x19 up
    to 0x1a;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x100015b
    up to 0x100015c;
  - Update of 06-55-.?06/0xbf (CLX-SP B0) microcode from revision 0x4003102
    up to 0x400320a;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003102 up to 0x500320a;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002302
    up to 0x7002402;
  - Update of 06-56-03/0x10 (BDX-DE V2/V3) microcode from revision
    0x700001b up to 0x700001c;
  - Update of 06-56-04/0x10 (BDX-DE Y0) microcode from revision 0xf000019
    up to 0xf00001a;
  - Update of 06-56-05/0x10 (BDX-NS A0/A1, HWL A1) microcode from revision
    0xe000012 up to 0xe000014;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x44 up
    to 0x46;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x20 up
    to 0x24;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x34 up
    to 0x36;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd0002a0
    up to 0xd000331;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x36 up
    to 0x38;
  - Update of 06-7a-08/.@0x01 (GLK-R R0) microcode from revision 0x1a up
    to 0x1c;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa6
    up to 0xa8;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x2a up
    to 0x2d;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x16 up
    to 0x22;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x2c up
    to 0x3c;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode from revision 0xea
    up to 0xec;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode from revision
    0xea up to 0xec;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode from
    revision 0xea up to 0xec;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode from revision 0xea up
    to 0xec;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode from revision 0xea up to 0xec;
  - Update of 06-96-01/0x01 (EHL B1) microcode from revision 0x11 up
    to 0x15;
  - Update of 06-9c-00/0x01 (JSL A0/A1) microcode from revision 0x1d up
    to 0x2400001f;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode from
    revision 0xea up to 0xec;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode from revision
    0xea up to 0xec;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode from revision 0xea
    up to 0xec;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode from revision
    0xea up to 0xec;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode from revision
    0xea up to 0xec;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xea up
    to 0xec;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xea
    up to 0xec;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xec
    up to 0xee;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xe8
    up to 0xea;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K1) microcode from revision
    0xea up to 0xec;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x40 up
    to 0x50.
E%E3OusEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.15bL@- Update Intel CPU microcode to microco.HcNuSEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.14bzS- Update Intel CPU microcode to microco.BMuGEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.13b@- Update Intel CPU microcode to microcode-20220207 release:
  - Fixes in releasenote.md file. LuMEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.12b	- Update Intel CPU microcode to microcode-20220204 release, addresses
  CVE-2021-0127, CVE-2021-0145, CVE-2021-33120 (#2051547, #2049549, #2049566):
  - Removal of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f;
  - Removal of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04)
    at revision 0xb00000f;
  - Removal of 06-86-04/0x01 (SNR B0) microcode (in intel-ucode/06-86-05)
    at revision 0xb00000f;
  - Removal of 06-86-05/0x01 (SNR B1) microcode at revision 0xb00000f;
  -.=.Cde-20220510 release, addresses
  CVE-2022-0005, CVE-2022-21131, CVE-2022-21136, CVE-2022-21151 (#2090246,
    - Addition of 06-97-02/0x03 (ADL-HX C0) microcode at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-97-02) at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    at revision 0x1f;
  - Addition of 06-97-02/0x03 (ADL-HX C0) microcode (in
    intel-ucode/06-97-05) at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    at revision 0x1f;
  - Addition of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode at
    revision 0x41c;
  - Addition of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode (in
    intel-ucode/06-9a-03) at revi.Dsion 0x41c;
  - Addition of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode (in
    intel-ucode/06-9a-04) at revision 0x41c;
  - Addition of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode at revision 0x41c;
  - Addition of 06-97-02/0x03 (ADL-HX C0) microcode (in
    intel-ucode/06-bf-02) at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-02) at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-bf-02)
    at revision 0x1f;
  - Addition of 06-97-02/0x03 (ADL-HX C0) microcode (in
    intel-ucode/06-bf-05) at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-05) at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-bf-05)
    at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode at revision 0x1f;
  - Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/inte.El-ucode/06-4e-03) from revision 0xec up to 0xf0;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006c0a up
    to 0x2006d05;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xec up to 0xf0;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x9a up to 0xa4;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xec up
    to 0xf0;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xec up
    to 0xf0;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xec up
    to 0xf0;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) .Ffrom revision 0xec up
    to 0xf0;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xec up to 0xf0;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xec up
    to 0xf0;
  - Update of 06-37-09/0x0f (VLV D0) microcode from revision 0x90c up
    to 0x90d;
  - Up.Gdate of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x100015c
    up to 0x100015d;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x400320a
    up to 0x4003302;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x500320a up to 0x5003302;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002402
    up to 0x7002501;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x46 up
    to 0x48;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x24 up
    to 0x28;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x36 up
    to 0x38;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd000331
    up to 0xd000363;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x38 up
    to 0x3a;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x1c up
    to 0x1e;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa8
    up to 0xb0;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x2d up
    to 0x31;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x22 up
    to 0x26;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x3c up
    to 0x3e;
  - Update of 06-96-01/0x01 (EHL B1) microcode from revision 0x15 up
    to 0x16;
  - Update of 06-9c-00/0x01 (JSL A0/A1) microcode from revision 0x2400001f
    up to 0x24000023;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xec up
    to 0xf0;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xec
    up to 0xf0;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xee
    up to 0xf0;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xea
    up to 0xf0;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K1) microcode from revision
    0xec up to 0xf0;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x50 up
    to 0x53..Ide-20220510 release, addresses
  CVE-2022-21233 (#2119080):
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006d05 up
    to 0x2006e05;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x100015d
    up to 0x100015e;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd000363
    up to 0xd000375;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x3a up
    to 0x3c;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x1e up
    to 0x20;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xb0
    up to 0xb2;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x26 up
    to 0x28;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x3e up
    to 0x40;
  - Update of 06-97-02/0x03 (ADL-HX/S 8+8 C0) microcode from revision
    0x1f up to 0x22;
  - Update of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-97-02) from revision 0x1f up.J to 0x22;
  - Update of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x1f up to 0x22;
  - Update of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x1f up to 0x22;
  - Update of 06-97-02/0x03 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-97-05) from revision 0x1f up to 0x22;
  - Update of 06-97-05/0x03 (ADL-S 6+0 K0) microcode from revision 0x1f
    up to 0x22;
  - Update of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    from revision 0x1f up to 0x22;
  - Update of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    from revision 0x1f up to 0x22;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode from revision
    0x41c up to 0x421;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode (in
    intel-ucode/06-9a-03) from revision 0x41c up to 0x421;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode (in
    intel-ucode/06-9a-04) from revision 0x41c up to 0x421;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode from revision 0x41c
    up to 0x421;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x53 up
    to 0x54;
  - Update of 06-97-02/0x03 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-02) from revision 0x1f up to 0x22;
  - Update of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-02) from revision 0x1f up to 0x22;
  - Update of 06-bf-02/0x03 (ADL C0) microcode from revision 0x1f up
    to 0x22;
  - Update of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-bf-02)
    from revision 0x1f up to 0x22;
  - Update of 06-97-02/0x03 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-05) from revision 0x1f up to 0x22;
  - Update of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-05) from revision 0x1f up to 0x22;
  - Update of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-bf-05)
    from revision 0x1f up to 0x22;
  - Update of 06-bf-05/0x03 (ADL C0) microcode from revision 0x1f up
    to 0x22..Lode-20230214 release, addresses
  CVE-2022-21216, CVE-2022-33196, CVE-2022-33972, CVE-2022-38090 (#2171238,
    - Addition of 06-6c-01/0x10 (ICL-D B0) microcode at revision 0x1000211;
  - Addition of 06-8f-04/0x87 (SPR-SP E0/S1) microcode at revision
    0x2b000181;
  - Addition of 06-8f-04/0x10 microcode at revision 0x2c000170;
  - Addition of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-04) at revision 0x2b000181;
  - Addition of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-04) at revision 0x2c000170;
  - Addition of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-04) at revision 0x2b000181;
  - Addition of 06-8f-06/0x10 microcode (in intel-ucode/06-8f-04) at
    revision 0x2c000170;
  - Addition of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-04) at revision 0x2b000181;
  - Addition of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-04) at revision 0x2b000181;
  - Addition of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
 .M   intel-ucode/06-8f-04) at revision 0x2c000170;
  - Addition of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-05) at revision 0x2b000181;
  - Addition of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-05) at
    revision 0x2c000170;
  - Addition of 06-8f-05/0x87 (SPR-SP E2) microcode at revision
    0x2b000181;
  - Addition of 06-8f-05/0x10 (SPR-HBM B1) microcode at revision
    0x2c000170;
  - Addition of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-05) at revision 0x2b000181;
  - Addition of 06-8f-06/0x10 microcode (in intel-ucode/06-8f-05) at
    revision 0x2c000170;
  - Addition of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-05) at revision 0x2b000181;
  - Addition of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-05) at revision 0x2b000181;
  - Addition of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
    intel-ucode/06-8f-05) at revision 0x2c000170;
  - Addition of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-0.N6) at revision 0x2b000181;
  - Addition of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-06) at
    revision 0x2c000170;
  - Addition of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-06) at revision 0x2b000181;
  - Addition of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-06) at revision 0x2c000170;
  - Addition of 06-8f-06/0x87 (SPR-SP E3) microcode at revision
    0x2b000181;
  - Addition of 06-8f-06/0x10 microcode at revision 0x2c000170;
  - Addition of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-06) at revision 0x2b000181;
  - Addition of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-06) at revision 0x2b000181;
  - Addition of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
    intel-ucode/06-8f-06) at revision 0x2c000170;
  - Addition of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-07) at revision 0x2b000181;
  - Addition of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-07) at revision 0x2b000181;
  .O- Addition of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-07) at revision 0x2b000181;
  - Addition of 06-8f-07/0x87 (SPR-SP E4/S2) microcode at revision
    0x2b000181;
  - Addition of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-07) at revision 0x2b000181;
  - Addition of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-08) at revision 0x2b000181;
  - Addition of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-08) at
    revision 0x2c000170;
  - Addition of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-08) at revision 0x2b000181;
  - Addition of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-08) at revision 0x2c000170;
  - Addition of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-08) at revision 0x2b000181;
  - Addition of 06-8f-06/0x10 microcode (in intel-ucode/06-8f-08) at
    revision 0x2c000170;
  - Addition of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-08) at revision 0x2b000181;.P
  - Addition of 06-8f-08/0x87 (SPR-SP E5/S3) microcode at revision
    0x2b000181;
  - Addition of 06-8f-08/0x10 (SPR-HBM B3) microcode at revision
    0x2c000170;
  - Addition of 06-b7-01/0x32 (RPL-S S0) microcode at revision 0x112;
  - Addition of 06-ba-02/0xc0 microcode at revision 0x410e;
  - Addition of 06-ba-03/0xc0 microcode (in intel-ucode/06-ba-02) at
    revision 0x410e;
  - Addition of 06-ba-02/0xc0 microcode (in intel-ucode/06-ba-03) at
    revision 0x410e;
  - Addition of 06-ba-03/0xc0 microcode at revision 0x410e;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0xa4 up to 0xa6;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xf0 up to 0xf4;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xf0 up
    to 0xf4;
  - Update of 06-55-03/0x97 (SKX-SP B1) mic.Qrocode from revision 0x100015e
    up to 0x1000161;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003302
    up to 0x4003303;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003302 up to 0x5003303;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002501
    up to 0x7002503;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd000375
    up to 0xd000389;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x3c up
    to 0x3e;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x20 up
    to 0x22;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xb2
    up to 0xb8;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x31 up
    to 0x32;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x40 up
    to 0x42;
  - Update of 06-96-01/0x01 (EHL B1) microcode from revision 0x16 up
    to 0x17;
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode from revision
    0x22.R up to 0x2c (old pf 0x3);
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-97-02) from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-bf-02/0x07 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-bf-05/0x07 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-97-05) from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode from revision 0x22
    up to 0x2c (old pf 0x3);
  - Update of 06-bf-02/0x07 (ADL C0) microcode (in intel-ucode/06-97-05)
    from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-bf-05/0x07 (ADL C0) microcode (in intel-ucode/06-97-05)
    from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode from revision
    0x421 up to 0x429;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode (.Sin
    intel-ucode/06-9a-03) from revision 0x421 up to 0x429;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode (in
    intel-ucode/06-9a-04) from revision 0x421 up to 0x429;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode from revision 0x421
    up to 0x429;
  - Update of 06-9c-00/0x01 (JSL A0/A1) microcode from revision 0x24000023
    up to 0x24000024;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xf0 up
    to 0xf4;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xf0
    up to 0xf4;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xf0
    up to 0xf4;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xf0
    up to 0xf4;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K1) microcode from revision
    0xf0 up to 0xf4;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x54 up
    to 0x57;
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-02) from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-02) from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-bf-02/0x07 (ADL C0) microcode from revision 0x22 up to
    0x2c (old pf 0x3);
  - Update of 06-bf-05/0x07 (ADL C0) microcode (in intel-ucode/06-bf-02)
    from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-05) from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-05) from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-bf-02/0x07 (ADL C0) microcode (in intel-ucode/06-bf-05)
    from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-bf-05/0x07 (ADL C0) microcode from revision 0x22 up to
    0x2c (old pf 0x3).
- Change the logger severity level to warning to align with the kmsg one.
PP^SoOEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-68^א- Update Intel CPU microcode to microcode-.UARoEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-67^Ǿ- Update Intel CPU microcode to microcode-20200520 release (#1783103):
  - Update of 06-2d-06/0x6d (SNB-E/EN/EP C1/M0) microcode from revision 0x61f
    up to 0x621;
  - Update of 06-2d-07/0x6d (SNB-E/EN/EP C2/M1) microcode from revision 0x718
    up to 0x71a.QoEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-66^2- Update Intel CPU microcode to microcode-20200508 release (#1835549):
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0x46
    up to 0x78.
- Change the URL in the intel-microcode2ucode.8 to point to the GitHub
  repository since the microcode download section at Intel Download Center
  does not exist anymore.GPuEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.16c@- Update Intel CPU microcode to microc.K.V20200602 release, addresses
  CVE-2020-0543, CVE-2020-0548, CVE-2020-0549 (#1795352, #1795355, #1827190):
  - Update of 06-3c-03/0x32 (HSW C0) microcode from revision 0x27 up to 0x28;
  - Update of 06-3d-04/0xc0 (BDW-U/Y E0/F0) microcode from revision 0x2e
    up to 0x2f;
  - Update of 06-45-01/0x72 (HSW-U C0/D0) microcode from revision 0x25
    up to 0x26;
  - Update of 06-46-01/0x32 (HSW-H C0) microcode from revision 0x1b up to 0x1c;
  - Update of 06-47-01/0x22 (BDW-H/Xeon E3 E0/G0) microcode from revision 0x21
    up to 0x22;
  - Update of 06-4e-03/0xc0 (SKL-U/Y D0) microcode from revision 0xd6
    up to 0xdc;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000151
    up to 0x1000157;
  - Update of 06-55-04/0xb7 (SKX-SP H0/M0/U0, SKX-D M1) microcode
    (in intel-06-55-04/intel-ucode/06-55-04) from revision 0x2000065
    up to 0x2006906;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x400002c
    up to 0x4002f01;
  - Update of 06-55-07/0xbf (CLX-SP B1) microcode from revision 0x500002c
    up to 0x5002f01;
  - Update of 06-5e-03/0x36 (SKL-H/S R0/N0) microcode from revision 0xd6
    up to 0xdc;
  - Update of 06-8e-09/0x10 (AML-Y22 H0) microcode from revision 0xca
    up to 0xd6;
  - Update of 06-8e-09/0xc0 (KBL-U/Y H0) microcode from revision 0xca
    up to 0xd6;
  - Update of 06-8e-0a/0xc0 (CFL-U43e D0) microcode from revision 0xca
    up to 0xd6;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode from revision 0xca
    up to 0xd6;
  - Update of 06-8e-0c/0x94 (AML-Y42 V0, CML-Y42 V0, WHL-U V0) microcode
    from revision 0xca up to 0xd6;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode from revision
    0xca up to 0xd6;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E3 U0) microcode from revision 0xca
    up to 0xd6;
  - Update of 06-9e-0b/0x02 (CFL-S B0) microcode from revision 0xca up to 0xd6;
  - Update of 06-9e-0c/0x22 (CFL-H/S P0) microcode from revision 0xca
    up to 0xd6;
  - Update of 06-9e-0d/0x22 (CFL-H R0) microcode from revision 0xca up to 0xd6.
tL.XooEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73^b- Update Intel CPU microcode to microcode-20200609 release (#1826589):
  - Fixed a typo in the release note file.zWoEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-72^b- Enable 06-2d-07 (SNB-E/EN/EP) caveat by default (#1846023).jVoiEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-71^b- Enable 06-55-04 (SKL-X/W) caveat by default.5Uo}Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-70^@- Do not update 06-4e-03 (SKL-U/Y) and 06-5e-03 (SKL-H/S/Xeon E3 v5) to revision
  0xdc, use 0xd6 by default (#1846133).To!Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-69^@- Avoid temporary file creation, used for here-documents in check_caveats.
I[uGEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.11`@- Update Intel CPU microcode to microcode-20210608 release:
  - Fixes in releasenote.md file.JZs#Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.2_A- Update Intel CPU microcode to microcode-20201027 release, addresses
  CVE-2020-8694, CVE-2020-8695, CVE-2020-8696, CVE-2020-8698
  (#1893261, #1893249, #1893229):
  - Addition of 06-55-0b/0xbf (CPX-SP A1) microcode at revision 0x700001e;
  - Addition of 06-8c-01/0x80 (TGL-UP3/.YSYs5Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.1_@- Add README file to the documentation directory.
- Add publicly-sourced codenames list to supply to gen_provides.sh; update
  the latter to handle the somewhat different format.
- Add SUMMARY.intel-ucode file containing metadata information from
  the microcode file headers..ZUP4 B1) microcode at revision 0x68;
  - Addition of 06-a5-02/0x20 (CML-H R1) microcode at revision 0xe0;
  - Addition of 06-a5-03/0x22 (CML-S 6+2 G1) microcode at revision 0xe0;
  - Addition of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode at revision 0xe0;
  - Addition of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode at revision
    0xe0;
  - Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xdc up to 0xe2;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006906 up
    to 0x2006a08;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xdc up to 0xe2;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) .[from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xd6 up
    to 0xe0;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xd6 up to 0xde;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xd6 up
    to 0xde;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x43 up to 0x44;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000157
    up to 0x1000159;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4002f01
    up to 0x4003003;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5002f01 up to 0x5003003;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x38 up
    to 0x40;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x16 up
    to 0x1e;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x16 up
    to 0x18;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0x78
    up to 0xa0;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xca
    up to 0xe0..] Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xea up to 0xec;
  - Update of 06-4f-01/0xef (BDX-E/EP/EX/ML B0/M0/R0) microcode (in
    intel-06-4f-01/intel-ucode/06-4f-01) from revision 0xb00003e up
    to 0xb000040;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006b06 up
    to 0x2006c0a;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xea up to 0xec;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x88 up to 0x9a;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x46 up to 0x49;
  - Update of 06-3f-04/0x80 (HSX-EX E0) microcode from revision 0x19 up
    to 0x1a;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x100015b
    up to 0x100015c;
  - Update of 06-55-.^06/0xbf (CLX-SP B0) microcode from revision 0x4003102
    up to 0x400320a;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003102 up to 0x500320a;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002302
    up to 0x7002402;
  - Update of 06-56-03/0x10 (BDX-DE V2/V3) microcode from revision
    0x700001b up to 0x700001c;
  - Update of 06-56-04/0x10 (BDX-DE Y0) microcode from revision 0xf000019
    up to 0xf00001a;
  - Update of 06-56-05/0x10 (BDX-NS A0/A1, HWL A1) microcode from revision
    0xe000012 up to 0xe000014;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x44 up
    to 0x46;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x20 up
    to 0x24;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x34 up
    to 0x36;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd0002a0
    up to 0xd000331;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x36 up
    to 0x38;
  - Update of 06-7a-08/._0x01 (GLK-R R0) microcode from revision 0x1a up
    to 0x1c;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa6
    up to 0xa8;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x2a up
    to 0x2d;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x16 up
    to 0x22;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x2c up
    to 0x3c;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode from revision 0xea
    up to 0xec;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode from revision
    0xea up to 0xec;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode from
    revision 0xea up to 0xec;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode from revision 0xea up
    to 0xec;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode from revision 0xea up to 0xec;
  - Update of 06-96-01/0x01 (EHL B1) microcode from revision 0x11 up
    to 0x15;
  - Update of 06-9c-00/0x01 (JSL A0/A1) microcode from revision 0x1d up
    to 0x2400001f;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode from
    revision 0xea up to 0xec;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode from revision
    0xea up to 0xec;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode from revision 0xea
    up to 0xec;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode from revision
    0xea up to 0xec;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode from revision
    0xea up to 0xec;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xea up
    to 0xec;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xea
    up to 0xec;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xec
    up to 0xee;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xe8
    up to 0xea;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K1) microcode from revision
    0xea up to 0xec;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x40 up
    to 0x50.
E%E3_usEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.15bL@- Update Intel CPU microcode to microco.gc^uSEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.14bzS- Update Intel CPU microcode to microco.a]uGEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.13b@- Update Intel CPU microcode to microcode-20220207 release:
  - Fixes in releasenote.md file. \uMEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.12b	- Update Intel CPU microcode to microcode-20220204 release, addresses
  CVE-2021-0127, CVE-2021-0145, CVE-2021-33120 (#2051547, #2049549, #2049566):
  - Removal of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f;
  - Removal of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04)
    at revision 0xb00000f;
  - Removal of 06-86-04/0x01 (SNR B0) microcode (in intel-ucode/06-86-05)
    at revision 0xb00000f;
  - Removal of 06-86-05/0x01 (SNR B1) microcode at revision 0xb00000f;
  -.\.bde-20220510 release, addresses
  CVE-2022-0005, CVE-2022-21131, CVE-2022-21136, CVE-2022-21151 (#2090246,
    - Addition of 06-97-02/0x03 (ADL-HX C0) microcode at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-97-02) at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    at revision 0x1f;
  - Addition of 06-97-02/0x03 (ADL-HX C0) microcode (in
    intel-ucode/06-97-05) at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    at revision 0x1f;
  - Addition of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode at
    revision 0x41c;
  - Addition of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode (in
    intel-ucode/06-9a-03) at revi.csion 0x41c;
  - Addition of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode (in
    intel-ucode/06-9a-04) at revision 0x41c;
  - Addition of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode at revision 0x41c;
  - Addition of 06-97-02/0x03 (ADL-HX C0) microcode (in
    intel-ucode/06-bf-02) at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-02) at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-bf-02)
    at revision 0x1f;
  - Addition of 06-97-02/0x03 (ADL-HX C0) microcode (in
    intel-ucode/06-bf-05) at revision 0x1f;
  - Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-05) at revision 0x1f;
  - Addition of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-bf-05)
    at revision 0x1f;
  - Addition of 06-bf-05/0x03 (ADL C0) microcode at revision 0x1f;
  - Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/inte.dl-ucode/06-4e-03) from revision 0xec up to 0xf0;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006c0a up
    to 0x2006d05;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xec up to 0xf0;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x9a up to 0xa4;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xec up
    to 0xf0;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xec up
    to 0xf0;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xec up
    to 0xf0;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) .efrom revision 0xec up
    to 0xf0;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xec up to 0xf0;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xec up
    to 0xf0;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xec up
    to 0xf0;
  - Update of 06-37-09/0x0f (VLV D0) microcode from revision 0x90c up
    to 0x90d;
  - Up.fdate of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x100015c
    up to 0x100015d;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x400320a
    up to 0x4003302;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x500320a up to 0x5003302;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002402
    up to 0x7002501;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x46 up
    to 0x48;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x24 up
    to 0x28;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x36 up
    to 0x38;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd000331
    up to 0xd000363;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x38 up
    to 0x3a;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x1c up
    to 0x1e;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa8
    up to 0xb0;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x2d up
    to 0x31;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x22 up
    to 0x26;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x3c up
    to 0x3e;
  - Update of 06-96-01/0x01 (EHL B1) microcode from revision 0x15 up
    to 0x16;
  - Update of 06-9c-00/0x01 (JSL A0/A1) microcode from revision 0x2400001f
    up to 0x24000023;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xec up
    to 0xf0;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xec
    up to 0xf0;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xee
    up to 0xf0;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xea
    up to 0xf0;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K1) microcode from revision
    0xec up to 0xf0;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x50 up
    to 0x53..hde-20220510 release, addresses
  CVE-2022-21233 (#2119080):
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006d05 up
    to 0x2006e05;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x100015d
    up to 0x100015e;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd000363
    up to 0xd000375;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x3a up
    to 0x3c;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x1e up
    to 0x20;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xb0
    up to 0xb2;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x26 up
    to 0x28;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x3e up
    to 0x40;
  - Update of 06-97-02/0x03 (ADL-HX/S 8+8 C0) microcode from revision
    0x1f up to 0x22;
  - Update of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-97-02) from revision 0x1f up.i to 0x22;
  - Update of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x1f up to 0x22;
  - Update of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x1f up to 0x22;
  - Update of 06-97-02/0x03 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-97-05) from revision 0x1f up to 0x22;
  - Update of 06-97-05/0x03 (ADL-S 6+0 K0) microcode from revision 0x1f
    up to 0x22;
  - Update of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    from revision 0x1f up to 0x22;
  - Update of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-97-05)
    from revision 0x1f up to 0x22;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode from revision
    0x41c up to 0x421;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode (in
    intel-ucode/06-9a-03) from revision 0x41c up to 0x421;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode (in
    intel-ucode/06-9a-04) from revision 0x41c up to 0x421;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode from revision 0x41c
    up to 0x421;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x53 up
    to 0x54;
  - Update of 06-97-02/0x03 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-02) from revision 0x1f up to 0x22;
  - Update of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-02) from revision 0x1f up to 0x22;
  - Update of 06-bf-02/0x03 (ADL C0) microcode from revision 0x1f up
    to 0x22;
  - Update of 06-bf-05/0x03 (ADL C0) microcode (in intel-ucode/06-bf-02)
    from revision 0x1f up to 0x22;
  - Update of 06-97-02/0x03 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-05) from revision 0x1f up to 0x22;
  - Update of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-05) from revision 0x1f up to 0x22;
  - Update of 06-bf-02/0x03 (ADL C0) microcode (in intel-ucode/06-bf-05)
    from revision 0x1f up to 0x22;
  - Update of 06-bf-05/0x03 (ADL C0) microcode from revision 0x1f up
    to 0x22..kode-20230214 release, addresses
  CVE-2022-21216, CVE-2022-33196, CVE-2022-33972, CVE-2022-38090 (#2171238,
    - Addition of 06-6c-01/0x10 (ICL-D B0) microcode at revision 0x1000211;
  - Addition of 06-8f-04/0x87 (SPR-SP E0/S1) microcode at revision
    0x2b000181;
  - Addition of 06-8f-04/0x10 microcode at revision 0x2c000170;
  - Addition of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-04) at revision 0x2b000181;
  - Addition of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-04) at revision 0x2c000170;
  - Addition of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-04) at revision 0x2b000181;
  - Addition of 06-8f-06/0x10 microcode (in intel-ucode/06-8f-04) at
    revision 0x2c000170;
  - Addition of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-04) at revision 0x2b000181;
  - Addition of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-04) at revision 0x2b000181;
  - Addition of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
 .l   intel-ucode/06-8f-04) at revision 0x2c000170;
  - Addition of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-05) at revision 0x2b000181;
  - Addition of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-05) at
    revision 0x2c000170;
  - Addition of 06-8f-05/0x87 (SPR-SP E2) microcode at revision
    0x2b000181;
  - Addition of 06-8f-05/0x10 (SPR-HBM B1) microcode at revision
    0x2c000170;
  - Addition of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-05) at revision 0x2b000181;
  - Addition of 06-8f-06/0x10 microcode (in intel-ucode/06-8f-05) at
    revision 0x2c000170;
  - Addition of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-05) at revision 0x2b000181;
  - Addition of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-05) at revision 0x2b000181;
  - Addition of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
    intel-ucode/06-8f-05) at revision 0x2c000170;
  - Addition of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-0.m6) at revision 0x2b000181;
  - Addition of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-06) at
    revision 0x2c000170;
  - Addition of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-06) at revision 0x2b000181;
  - Addition of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-06) at revision 0x2c000170;
  - Addition of 06-8f-06/0x87 (SPR-SP E3) microcode at revision
    0x2b000181;
  - Addition of 06-8f-06/0x10 microcode at revision 0x2c000170;
  - Addition of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-06) at revision 0x2b000181;
  - Addition of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-06) at revision 0x2b000181;
  - Addition of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
    intel-ucode/06-8f-06) at revision 0x2c000170;
  - Addition of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-07) at revision 0x2b000181;
  - Addition of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-07) at revision 0x2b000181;
  .n- Addition of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-07) at revision 0x2b000181;
  - Addition of 06-8f-07/0x87 (SPR-SP E4/S2) microcode at revision
    0x2b000181;
  - Addition of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-07) at revision 0x2b000181;
  - Addition of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-08) at revision 0x2b000181;
  - Addition of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-08) at
    revision 0x2c000170;
  - Addition of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-08) at revision 0x2b000181;
  - Addition of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-08) at revision 0x2c000170;
  - Addition of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-08) at revision 0x2b000181;
  - Addition of 06-8f-06/0x10 microcode (in intel-ucode/06-8f-08) at
    revision 0x2c000170;
  - Addition of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-08) at revision 0x2b000181;.o
  - Addition of 06-8f-08/0x87 (SPR-SP E5/S3) microcode at revision
    0x2b000181;
  - Addition of 06-8f-08/0x10 (SPR-HBM B3) microcode at revision
    0x2c000170;
  - Addition of 06-b7-01/0x32 (RPL-S S0) microcode at revision 0x112;
  - Addition of 06-ba-02/0xc0 microcode at revision 0x410e;
  - Addition of 06-ba-03/0xc0 microcode (in intel-ucode/06-ba-02) at
    revision 0x410e;
  - Addition of 06-ba-02/0xc0 microcode (in intel-ucode/06-ba-03) at
    revision 0x410e;
  - Addition of 06-ba-03/0xc0 microcode at revision 0x410e;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0xa4 up to 0xa6;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xf0 up to 0xf4;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xf0 up
    to 0xf4;
  - Update of 06-55-03/0x97 (SKX-SP B1) mic.procode from revision 0x100015e
    up to 0x1000161;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003302
    up to 0x4003303;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003302 up to 0x5003303;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002501
    up to 0x7002503;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd000375
    up to 0xd000389;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x3c up
    to 0x3e;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x20 up
    to 0x22;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xb2
    up to 0xb8;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x31 up
    to 0x32;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x40 up
    to 0x42;
  - Update of 06-96-01/0x01 (EHL B1) microcode from revision 0x16 up
    to 0x17;
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode from revision
    0x22.q up to 0x2c (old pf 0x3);
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-97-02) from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-bf-02/0x07 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-bf-05/0x07 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-97-05) from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode from revision 0x22
    up to 0x2c (old pf 0x3);
  - Update of 06-bf-02/0x07 (ADL C0) microcode (in intel-ucode/06-97-05)
    from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-bf-05/0x07 (ADL C0) microcode (in intel-ucode/06-97-05)
    from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode from revision
    0x421 up to 0x429;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode (.rin
    intel-ucode/06-9a-03) from revision 0x421 up to 0x429;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode (in
    intel-ucode/06-9a-04) from revision 0x421 up to 0x429;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode from revision 0x421
    up to 0x429;
  - Update of 06-9c-00/0x01 (JSL A0/A1) microcode from revision 0x24000023
    up to 0x24000024;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xf0 up
    to 0xf4;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xf0
    up to 0xf4;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xf0
    up to 0xf4;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xf0
    up to 0xf4;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K1) microcode from revision
    0xf0 up to 0xf4;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x54 up
    to 0x57;
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-02) from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-02) from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-bf-02/0x07 (ADL C0) microcode from revision 0x22 up to
    0x2c (old pf 0x3);
  - Update of 06-bf-05/0x07 (ADL C0) microcode (in intel-ucode/06-bf-02)
    from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-05) from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-05) from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-bf-02/0x07 (ADL C0) microcode (in intel-ucode/06-bf-05)
    from revision 0x22 up to 0x2c (old pf 0x3);
  - Update of 06-bf-05/0x07 (ADL C0) microcode from revision 0x22 up to
    0x2c (old pf 0x3).
- Change the logger severity level to warning to align with the kmsg one.
au;Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.17d- Force locale to C in check_caveats, reload_microcode, and update_ucode.
- Cleanup the dangling symlinks in update_ucode.
- Avoid spurious find failures due to calls on directories that may not exist.
- Add support for the new, more correct, variant of dracut's default
  $fw_dir path in dracut_99microcode_ctl-fw_dir_override_module_init.sh.G`uEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.16c@- Update Intel CPU microcode to microc.j.utel-06-8c-01/intel-ucode/06-8c-01) from revision 0xa6 up to 0xaa;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000161
    up to 0x1000171;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003303
    up to 0x4003501;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003303 up to 0x5003501;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002503
    up to 0x7002601;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd000389
    up to 0xd000390;
  - Update of 06-6c-01/0x10 (ICL-D B0) microcode from revision 0x1000211
    up to 0x1000230;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xb8
    up to 0xba;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x32 up
    to 0x33;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x28 up
    to 0x2a;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x42 up
    to 0x44;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 .vH0) microcode from revision 0xf0
    up to 0xf2;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode from revision
    0xf0 up to 0xf2;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode from
    revision 0xf0 up to 0xf2;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode from revision 0xf0 up
    to 0xf2;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode from revision 0xf4 up to 0xf6;
  - Update of 06-8f-04/0x10 microcode from revision 0x2c000170 up to
    0x2c0001d1;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode from revision
    0x2b000181 up to 0x2b000461;
  - Update of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-04) from revision 0x2c000170 up to 0x2c0001d1;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-04) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-06/0x10 microcode (in intel-ucode/06-8f-04) from
    revision 0x2c000170 up to 0x2c0001d1;
  - Update of 06-8f-06/0x87 (SPR-SP E.w3) microcode (in
    intel-ucode/06-8f-04) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-04) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
    intel-ucode/06-8f-04) from revision 0x2c000170 up to 0x2c0001d1;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-04) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-05) from
    revision 0x2c000170 up to 0x2c0001d1;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-05) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-05/0x10 (SPR-HBM B1) microcode from revision
    0x2c000170 up to 0x2c0001d1;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode from revision 0x2b000181
    up to 0x2b000461;
  - Update of 06-8f-06/0x10 microcode (in intel-ucode/06-8f-05) from
    revision 0x2c000170 up to 0x2c0001d1;
  - Update of 0.x6-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-05) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-05) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
    intel-ucode/06-8f-05) from revision 0x2c000170 up to 0x2c0001d1;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-05) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-06) from
    revision 0x2c000170 up to 0x2c0001d1;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-06) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-06) from revision 0x2c000170 up to 0x2c0001d1;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-06) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-06/0x10 microcode from revision .y0x2c000170 up to
    0x2c0001d1;
  - Update of 06-8f-06/0x87 (SPR-SP E3) microcode from revision 0x2b000181
    up to 0x2b000461;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-06) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
    intel-ucode/06-8f-06) from revision 0x2c000170 up to 0x2c0001d1;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-06) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-07) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-07) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-07) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode from revision
    0x2b000181 up to 0x2b000461;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3).z microcode (in
    intel-ucode/06-8f-07) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-08) from
    revision 0x2c000170 up to 0x2c0001d1;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-08) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-08) from revision 0x2c000170 up to 0x2c0001d1;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-08) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-06/0x10 microcode (in intel-ucode/06-8f-08) from
    revision 0x2c000170 up to 0x2c0001d1;
  - Update of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-08) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-08) from revision 0x2b000181 up to 0x2b000461;
  - Update of 06-8f-08/0x10 (SPR-HBM B3) microcode from revision
    0x2c000170 up to 0x2c00.{01d1;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode from revision
    0x2b000181 up to 0x2b000461;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode from revision
    0x429 up to 0x42a;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode (in
    intel-ucode/06-9a-03) from revision 0x429 up to 0x42a;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode (in
    intel-ucode/06-9a-04) from revision 0x429 up to 0x42a;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode from revision 0x429
    up to 0x42a;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode from
    revision 0xf0 up to 0xf2;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode from revision
    0xf0 up to 0xf2;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode from revision 0xf0
    up to 0xf2;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode from revision
    0xf0 up to 0xf2;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode from revision
    0xf4 up to 0xf8;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xf4 up
    to 0xf6;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xf4
    up to 0xf6;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xf4
    up to 0xf6;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xf4
    up to 0xf6;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K1) microcode from revision
    0xf4 up to 0xf6;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x57 up
    to 0x58;
  - Update of 06-b7-01/0x32 (RPL-S B0) microcode from revision 0x112 up
    to 0x113;
  - Update of 06-ba-02/0xc0 (RPL-H 6+8/P 6+8 J0) microcode from revision
    0x410e up to 0x4112;
  - Update of 06-ba-03/0xc0 (RPL-U 2+8 Q0) microcode (in
    intel-ucode/06-ba-02) from revision 0x410e up to 0x4112;
  - Update of 06-ba-02/0xc0 (RPL-H 6+8/P 6+8 J0) microcode (in
    intel-ucode/06-ba-03) from revision 0x410e up to 0x4112;
  - Update of 06-ba-03/0xc0 (RPL-U 2+8 Q0) microcode from revision 0x410e
    up to 0x4112.
PP^eoOEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-68^א- Update Intel CPU microcode to microcode-.>duEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.20eB=- Update Intel CPU microcode to microcode-20231009 release, addresses
  CVE-2023-23583 (RHEL-3920):
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (i.zcuEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.19d@- Update Intel CPU microcode to microc.}@buEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.18d- Update Intel CPU microcode to microcode-20230516 release:
  - Addition of 06-be-00/0x01 (ADL-N A0) microcode at revision 0x10;
  - Addition of 06-9a-04/0x40 (AZB A0) microcode at revision 0x4;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006e05 up
    to 0x2006f05;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    in.t.~ode-20230808 release, addresses
  CVE-2022-40982, CVE-2022-41804, CVE-2023-23908 (#2223994):
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006f05 up
    to 0x2007006;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0xaa up to 0xac;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000171
    up to 0x1000181;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003501
    up to 0x4003604;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003501 up to 0x5003604;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002601
    up to 0x7002703;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd000390
    up to 0xd0003a5;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xba
    up to 0xbc;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x2a up
  .  to 0x2c;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x44 up
    to 0x46;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode from revision
    0xf2 up to 0xf4;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode from revision 0xf2
    up to 0xf4;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode from
    revision 0xf2 up to 0xf4;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode from revision 0xf2 up
    to 0xf4;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode from revision 0xf6 up to 0xf8;
  - Update of 06-8f-04/0x10 microcode from revision 0x2c0001d1 up to
    0x2c000271;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode from revision
    0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-04) from revision 0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-04) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of .06-8f-06/0x10 microcode (in intel-ucode/06-8f-04) from
    revision 0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-04) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-04) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
    intel-ucode/06-8f-04) from revision 0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-04) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-05) from
    revision 0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-05) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-05/0x10 (SPR-HBM B1) microcode from revision
    0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode from revision 0x2b000461
    up to 0x2b.0004b1;
  - Update of 06-8f-06/0x10 microcode (in intel-ucode/06-8f-05) from
    revision 0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-05) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-05) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
    intel-ucode/06-8f-05) from revision 0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-05) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-06) from
    revision 0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-06) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-06) from revision 0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-05/0x87 (SPR-SP E2) m.icrocode (in
    intel-ucode/06-8f-06) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-06/0x10 microcode from revision 0x2c0001d1 up to
    0x2c000271;
  - Update of 06-8f-06/0x87 (SPR-SP E3) microcode from revision 0x2b000461
    up to 0x2b0004b1;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-06) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
    intel-ucode/06-8f-06) from revision 0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-06) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-07) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-07) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-07) from revision 0x2b000461 up to 0x2b0004b1;
  - Upda.te of 06-8f-07/0x87 (SPR-SP E4/S2) microcode from revision
    0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-07) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-08) from
    revision 0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-08) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-08) from revision 0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-08) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-06/0x10 microcode (in intel-ucode/06-8f-08) from
    revision 0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-08) from revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-08) f.rom revision 0x2b000461 up to 0x2b0004b1;
  - Update of 06-8f-08/0x10 (SPR-HBM B3) microcode from revision
    0x2c0001d1 up to 0x2c000271;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode from revision
    0x2b000461 up to 0x2b0004b1;
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode from revision
    0x2c up to 0x2e;
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-97-02) from revision 0x2c up to 0x2e;
  - Update of 06-bf-02/0x07 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x2c up to 0x2e;
  - Update of 06-bf-05/0x07 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x2c up to 0x2e;
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-97-05) from revision 0x2c up to 0x2e;
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode from revision 0x2c
    up to 0x2e;
  - Update of 06-bf-02/0x07 (ADL C0) microcode (in intel-ucode/06-97-05)
    from revision 0x2c up to 0x2e;
  - Update of 06-bf-05/0x07 (ADL C0) microcode. (in intel-ucode/06-97-05)
    from revision 0x2c up to 0x2e;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode from revision
    0x42a up to 0x42c;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode (in
    intel-ucode/06-9a-03) from revision 0x42a up to 0x42c;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode (in
    intel-ucode/06-9a-04) from revision 0x42a up to 0x42c;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode from revision 0x42a
    up to 0x42c;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode from
    revision 0xf2 up to 0xf4;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode from revision
    0xf2 up to 0xf4;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode from revision 0xf2
    up to 0xf4;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode from revision
    0xf2 up to 0xf4;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode from revision
    0xf8 up to 0xfa;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0x.f6 up
    to 0xf8;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xf6
    up to 0xf8;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xf6
    up to 0xf8;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xf6
    up to 0xf8;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K1) microcode from revision
    0xf6 up to 0xf8;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x58 up
    to 0x59;
  - Update of 06-b7-01/0x32 (RPL-S B0) microcode from revision 0x113 up
    to 0x119;
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-02) from revision 0x2c up to 0x2e;
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-02) from revision 0x2c up to 0x2e;
  - Update of 06-bf-02/0x07 (ADL C0) microcode from revision 0x2c up
    to 0x2e;
  - Update of 06-bf-05/0x07 (ADL C0) microcode (in intel-ucode/06-bf-02)
    from revision 0x2c up to 0x2e;
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-05) from revision 0x2c up to 0x2e;
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-05) from revision 0x2c up to 0x2e;
  - Update of 06-bf-02/0x07 (ADL C0) microcode (in intel-ucode/06-bf-05)
    from revision 0x2c up to 0x2e;
  - Update of 06-bf-05/0x07 (ADL C0) microcode from revision 0x2c up
    to 0x2e;
  - Update of 06-ba-02/0xe0 (RPL-H 6+8/P 6+8 J0) microcode from revision
    0x4112 up to 0x4119 (old pf 0xc0);
  - Update of 06-ba-03/0xe0 (RPL-U 2+8 Q0) microcode (in
    intel-ucode/06-ba-02) from revision 0x4112 up to 0x4119 (old pf 0xc0);
  - Update of 06-ba-02/0xe0 (RPL-H 6+8/P 6+8 J0) microcode (in
    intel-ucode/06-ba-03) from revision 0x4112 up to 0x4119 (old pf 0xc0);
  - Update of 06-ba-03/0xe0 (RPL-U 2+8 Q0) microcode from revision 0x4112
    up to 0x4119 (old pf 0xc0);
  - Update of 06-be-00/0x11 (ADL-N A0) microcode from revision 0x10 up
    to 0x11 (old pf 0x1)..n
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0xac up to 0xb4;
  - Update of 06-6a-06/0x87 (ICX-SP D0) microcode from revision 0xd0003a5
    up to 0xd0003b9;
  - Update of 06-6c-01/0x10 (ICL-D B0) microcode from revision 0x1000230
    up to 0x1000268;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xbc
    up to 0xc2;
  - Update of 06-8c-02/0xc2 (TGL-R C0) microcode from revision 0x2c up
    to 0x34;
  - Update of 06-8d-01/0xc2 (TGL-H R0) microcode from revision 0x46 up
    to 0x4e;
  - Update of 06-8f-04/0x10 microcode from revision 0x2c000271 up to
    0x2c000290;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode from revision
    0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-04) from revision 0x2c000271 up to 0x2c000290;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-04) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-06/0x10 microcode (in intel-ucode/06-8f-04) from
  .  revision 0x2c000271 up to 0x2c000290;
  - Update of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-04) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-04) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
    intel-ucode/06-8f-04) from revision 0x2c000271 up to 0x2c000290;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-04) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-05) from
    revision 0x2c000271 up to 0x2c000290;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-05) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-05/0x10 (SPR-HBM B1) microcode from revision
    0x2c000271 up to 0x2c000290;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode from revision 0x2b0004b1
    up to 0x2b0004d0;
  - Update of 06-8f-06/0x10 microcode (in intel-u.code/06-8f-05) from
    revision 0x2c000271 up to 0x2c000290;
  - Update of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-05) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-05) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
    intel-ucode/06-8f-05) from revision 0x2c000271 up to 0x2c000290;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-05) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-06) from
    revision 0x2c000271 up to 0x2c000290;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-06) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-06) from revision 0x2c000271 up to 0x2c000290;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-06) from revision 0x2b.0004b1 up to 0x2b0004d0;
  - Update of 06-8f-06/0x10 microcode from revision 0x2c000271 up to
    0x2c000290;
  - Update of 06-8f-06/0x87 (SPR-SP E3) microcode from revision 0x2b0004b1
    up to 0x2b0004d0;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-06) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-08/0x10 (SPR-HBM B3) microcode (in
    intel-ucode/06-8f-06) from revision 0x2c000271 up to 0x2c000290;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-06) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-07) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-07) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-07) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode from revisio.n
    0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode (in
    intel-ucode/06-8f-07) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-04/0x10 microcode (in intel-ucode/06-8f-08) from
    revision 0x2c000271 up to 0x2c000290;
  - Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
    intel-ucode/06-8f-08) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-05/0x10 (SPR-HBM B1) microcode (in
    intel-ucode/06-8f-08) from revision 0x2c000271 up to 0x2c000290;
  - Update of 06-8f-05/0x87 (SPR-SP E2) microcode (in
    intel-ucode/06-8f-08) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-06/0x10 microcode (in intel-ucode/06-8f-08) from
    revision 0x2c000271 up to 0x2c000290;
  - Update of 06-8f-06/0x87 (SPR-SP E3) microcode (in
    intel-ucode/06-8f-08) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-8f-07/0x87 (SPR-SP E4/S2) microcode (in
    intel-ucode/06-8f-08) from revision 0x2b0004b1 up to 0x2b0004d0;
  - Update of 0.6-8f-08/0x10 (SPR-HBM B3) microcode from revision
    0x2c000271 up to 0x2c000290;
  - Update of 06-8f-08/0x87 (SPR-SP E5/S3) microcode from revision
    0x2b0004b1 up to 0x2b0004d0;
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode from revision
    0x2e up to 0x32;
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-97-02) from revision 0x2e up to 0x32;
  - Update of 06-bf-02/0x07 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x2e up to 0x32;
  - Update of 06-bf-05/0x07 (ADL C0) microcode (in intel-ucode/06-97-02)
    from revision 0x2e up to 0x32;
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-97-05) from revision 0x2e up to 0x32;
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode from revision 0x2e
    up to 0x32;
  - Update of 06-bf-02/0x07 (ADL C0) microcode (in intel-ucode/06-97-05)
    from revision 0x2e up to 0x32;
  - Update of 06-bf-05/0x07 (ADL C0) microcode (in intel-ucode/06-97-05)
    from revision 0x2e up to 0.x32;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode from revision
    0x42c up to 0x430;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode (in
    intel-ucode/06-9a-03) from revision 0x42c up to 0x430;
  - Update of 06-9a-03/0x80 (ADL-P 6+8/U 9W L0/R0) microcode (in
    intel-ucode/06-9a-04) from revision 0x42c up to 0x430;
  - Update of 06-9a-04/0x80 (ADL-P 2+8 R0) microcode from revision 0x42c
    up to 0x430;
  - Update of 06-9a-04/0x40 (AZB A0) microcode from revision 0x4 up
    to 0x5;
  - Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x59 up
    to 0x5d;
  - Update of 06-b7-01/0x32 (RPL-S B0) microcode from revision 0x119 up
    to 0x11d;
  - Update of 06-ba-02/0xe0 (RPL-H 6+8/P 6+8 J0) microcode from revision
    0x4119 up to 0x411c;
  - Update of 06-ba-03/0xe0 (RPL-U 2+8 Q0) microcode (in
    intel-ucode/06-ba-02) from revision 0x4119 up to 0x411c;
  - Update of 06-ba-02/0xe0 (RPL-H 6+8/P 6+8 J0) microcode (in
    intel-ucode/06-ba-03) from revision 0x4119 up to 0x411c;
  - Update of 06-ba-03/0xe0 (RPL-U 2+8 Q0) microcode from revision 0x4119
    up to 0x411c;
  - Update of 06-be-00/0x11 (ADL-N A0) microcode from revision 0x11 up
    to 0x12;
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-02) from revision 0x2e up to 0x32;
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-02) from revision 0x2e up to 0x32;
  - Update of 06-bf-02/0x07 (ADL C0) microcode from revision 0x2e up
    to 0x32;
  - Update of 06-bf-05/0x07 (ADL C0) microcode (in intel-ucode/06-bf-02)
    from revision 0x2e up to 0x32;
  - Update of 06-97-02/0x07 (ADL-HX/S 8+8 C0) microcode (in
    intel-ucode/06-bf-05) from revision 0x2e up to 0x32;
  - Update of 06-97-05/0x07 (ADL-S 6+0 K0) microcode (in
    intel-ucode/06-bf-05) from revision 0x2e up to 0x32;
  - Update of 06-bf-02/0x07 (ADL C0) microcode (in intel-ucode/06-bf-05)
    from revision 0x2e up to 0x32;
  - Update of 06-bf-05/0x07 (ADL C0) microcode from revision 0x2e up
    to 0x32..20200602 release, addresses
  CVE-2020-0543, CVE-2020-0548, CVE-2020-0549 (#1795352, #1795355, #1827190):
  - Update of 06-3c-03/0x32 (HSW C0) microcode from revision 0x27 up to 0x28;
  - Update of 06-3d-04/0xc0 (BDW-U/Y E0/F0) microcode from revision 0x2e
    up to 0x2f;
  - Update of 06-45-01/0x72 (HSW-U C0/D0) microcode from revision 0x25
    up to 0x26;
  - Update of 06-46-01/0x32 (HSW-H C0) microcode from revision 0x1b up to 0x1c;
  - Update of 06-47-01/0x22 (BDW-H/Xeon E3 E0/G0) microcode from revision 0x21
    up to 0x22;
  - Update of 06-4e-03/0xc0 (SKL-U/Y D0) microcode from revision 0xd6
    up to 0xdc;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000151
    up to 0x1000157;
  - Update of 06-55-04/0xb7 (SKX-SP H0/M0/U0, SKX-D M1) microcode
    (in intel-06-55-04/intel-ucode/06-55-04) from revision 0x2000065
    up to 0x2006906;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x400002c
    up to 0x4002f01;
  - Update of 06-55-07/0xbf (CLX-SP B1) microcode from revision 0x500002c
    up to 0x5002f01;
  - Update of 06-5e-03/0x36 (SKL-H/S R0/N0) microcode from revision 0xd6
    up to 0xdc;
  - Update of 06-8e-09/0x10 (AML-Y22 H0) microcode from revision 0xca
    up to 0xd6;
  - Update of 06-8e-09/0xc0 (KBL-U/Y H0) microcode from revision 0xca
    up to 0xd6;
  - Update of 06-8e-0a/0xc0 (CFL-U43e D0) microcode from revision 0xca
    up to 0xd6;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode from revision 0xca
    up to 0xd6;
  - Update of 06-8e-0c/0x94 (AML-Y42 V0, CML-Y42 V0, WHL-U V0) microcode
    from revision 0xca up to 0xd6;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode from revision
    0xca up to 0xd6;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E3 U0) microcode from revision 0xca
    up to 0xd6;
  - Update of 06-9e-0b/0x02 (CFL-S B0) microcode from revision 0xca up to 0xd6;
  - Update of 06-9e-0c/0x22 (CFL-H/S P0) microcode from revision 0xca
    up to 0xd6;
  - Update of 06-9e-0d/0x22 (CFL-H R0) microcode from revision 0xca up to 0xd6.
tL.jooEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73^b- Update Intel CPU microcode to microcode-20200609 release (#1826589):
  - Fixed a typo in the release note file.zioEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-72^b- Enable 06-2d-07 (SNB-E/EN/EP) caveat by default (#1846023).jhoiEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-71^b- Enable 06-55-04 (SKL-X/W) caveat by default.5go}Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-70^@- Do not update 06-4e-03 (SKL-U/Y) and 06-5e-03 (SKL-H/S/Xeon E3 v5) to revision
  0xdc, use 0xd6 by default (#1846133).fo!Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-69^@- Avoid temporary file creation, used for here-documents in check_caveats.
Ims
Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.3_u@- Disable 06-8c-01 (TGL-UP3/UP4 B1) microcode update by default.Jls#Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.2_A- Update Intel CPU microcode to microcode-20201027 release, addresses
  CVE-2020-8694, CVE-2020-8695, CVE-2020-8696, CVE-2020-8698
  (#1893261, #1893249, #1893229):
  - Addition of 06-55-0b/0xbf (CPX-SP A1) microcode at revision 0x700001e;
  - Addition of 06-8c-01/0x80 (TGL-UP3/.Sks5Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.1_@- Add README file to the documentation directory.
- Add publicly-sourced codenames list to supply to gen_provides.sh; update
  the latter to handle the somewhat different format.
- Add SUMMARY.intel-ucode file containing metadata information from
  the microcode file headers..UP4 B1) microcode at revision 0x68;
  - Addition of 06-a5-02/0x20 (CML-H R1) microcode at revision 0xe0;
  - Addition of 06-a5-03/0x22 (CML-S 6+2 G1) microcode at revision 0xe0;
  - Addition of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode at revision 0xe0;
  - Addition of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode at revision
    0xe0;
  - Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xdc up to 0xe2;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006906 up
    to 0x2006a08;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xdc up to 0xe2;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) .from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xd6 up
    to 0xe0;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xd6 up to 0xde;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xd6 up
    to 0xde;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x43 up to 0x44;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000157
    up to 0x1000159;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4002f01
    up to 0x4003003;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5002f01 up to 0x5003003;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x38 up
    to 0x40;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x16 up
    to 0x1e;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x16 up
    to 0x18;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0x78
    up to 0xa0;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xca
    up to 0xe0.
BMBSqs5Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.1_@- Add README file to the documentation directory.
- Add publicly-sourced codenames list to supply to gen_provides.sh; update
  the latter to handle the somewhat different format.
- Add SUMMARY.intel-ucode file containing metadata information from
  the microcode file headers..pooEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73^b- Update Intel CPU microcode to microcode-20200609 release (#1826589):
  - Fixed a typo in the release note file.zooEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-72^b- Enable 06-2d-07 (SNB-E/EN/EP) caveat by default (#1846023).0nsoEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.4_uA- Update Intel CPU microcode to microcode-20201112 release:
  - Addition of 06-8a-01/0x10 (LKF B2/B3) microcode at revision 0x28;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x32 up
    to 0x34;
  - Updated releasenote file..UP4 B1) microcode at revision 0x68;
  - Addition of 06-a5-02/0x20 (CML-H R1) microcode at revision 0xe0;
  - Addition of 06-a5-03/0x22 (CML-S 6+2 G1) microcode at revision 0xe0;
  - Addition of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode at revision 0xe0;
  - Addition of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode at revision
    0xe0;
  - Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xdc up to 0xe2;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006906 up
    to 0x2006a08;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xdc up to 0xe2;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) .from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xd6 up
    to 0xe0;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xd6 up to 0xde;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xd6 up
    to 0xde;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x43 up to 0x44;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000157
    up to 0x1000159;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4002f01
    up to 0x4003003;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5002f01 up to 0x5003003;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x38 up
    to 0x40;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x16 up
    to 0x1e;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x16 up
    to 0x18;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0x78
    up to 0xa0;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xca
    up to 0xe0.
Kus%Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.5__@- Do not use "grep -q" in a pipe in check_caveats.
- Add 06-55-04/06-55-06/06-55-07 (SKX-SP/CLX-SP) microcode-20201110 caveats
  (#1905111).0tsoEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.4_uA- Update Intel CPU microcode to microcode-20201112 release:
  - Addition of 06-8a-01/0x10 (LKF B2/B3) microcode at revision 0x28;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x32 up
    to 0x34;
  - Updated releasenote file.ss
Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.3_u@- Disable 06-8c-01 (TGL-UP3/UP4 B1) microcode update by default.Jrs#Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.2_A- Update Intel CPU microcode to microcode-20201027 release, addresses
  CVE-2020-8694, CVE-2020-8695, CVE-2020-8696, CVE-2020-8698
  (#1893261, #1893249, #1893229):
  - Addition of 06-55-0b/0xbf (CPX-SP A1) microcode at revision 0x700001e;
  - Addition of 06-8c-01/0x80 (TGL-UP3/.
XX.yooEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73^b- Update Intel CPU microcode to microcode-20200609 release (#1826589):
  - Fixed a typo in the release note file.exsYEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.8`-A- Update Intel CPU microcode to microcode-20210216 release (#1905111):
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006a08 up
    to 0x2006a0a;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003003
    up to 0x4003006;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003003 up to 0x5003006.ws+Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.7`-@- Remove 06-55-04/06-55-06/06-55-07 (SKX-SP/CLX-SP) microcode-20201110 caveats.tvsyEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.6`%@- Backport check_dmi_val to check_caveats from RHEL 8.
I|s
Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.3_u@- Disable 06-8c-01 (TGL-UP3/UP4 B1) microcode update by default.J{s#Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.2_A- Update Intel CPU microcode to microcode-20201027 release, addresses
  CVE-2020-8694, CVE-2020-8695, CVE-2020-8696, CVE-2020-8698
  (#1893261, #1893249, #1893229):
  - Addition of 06-55-0b/0xbf (CPX-SP A1) microcode at revision 0x700001e;
  - Addition of 06-8c-01/0x80 (TGL-UP3/.Szs5Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.1_@- Add README file to the documentation directory.
- Add publicly-sourced codenames list to supply to gen_provides.sh; update
  the latter to handle the somewhat different format.
- Add SUMMARY.intel-ucode file containing metadata information from
  the microcode file headers..UP4 B1) microcode at revision 0x68;
  - Addition of 06-a5-02/0x20 (CML-H R1) microcode at revision 0xe0;
  - Addition of 06-a5-03/0x22 (CML-S 6+2 G1) microcode at revision 0xe0;
  - Addition of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode at revision 0xe0;
  - Addition of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode at revision
    0xe0;
  - Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xdc up to 0xe2;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006906 up
    to 0x2006a08;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xdc up to 0xe2;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) .from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xd6 up
    to 0xe0;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) from revision 0xd6 up
    to 0xde;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xd6 up to 0xde;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xd6 up
    to 0xde;
  - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xd6 up
    to 0xde;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x43 up to 0x44;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000157
    up to 0x1000159;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4002f01
    up to 0x4003003;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5002f01 up to 0x5003003;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x38 up
    to 0x40;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x16 up
    to 0x1e;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x16 up
    to 0x18;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0x78
    up to 0xa0;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xca
    up to 0xe0.
s+Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.7`-@- Remove 06-55-04/06-55-06/06-55-07 (SKX-SP/CLX-SP) microcode-20201110 caveats.tsyEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.6`%@- Backport check_dmi_val to check_caveats from RHEL 8.K~s%Eugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.5__@- Do not use "grep -q" in a pipe in check_caveats.
- Add 06-55-04/06-55-06/06-55-07 (SKX-SP/CLX-SP) microcode-20201110 caveats
  (#1905111).0}soEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.4_uA- Update Intel CPU microcode to microcode-20201112 release:
  - Addition of 06-8a-01/0x10 (LKF B2/B3) microcode at revision 0x28;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x32 up
    to 0x34;
  - Updated releasenote file.
qM_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.7-10Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildsEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.9`- Update Intel CPU microcode to microcode-20210525 release, addresses
  CVE-2020-24489, CVE-2.esYEugene Syromiatnikov <esyr@redhat.com> - 2:2.1-73.8`-A- Update Intel CPU microcode to microcode-20210216 release (#1905111):
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006a08 up
    to 0x2006a0a;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003003
    up to 0x4003006;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003003 up to 0x5003006..020-24511, CVE-2020-24512, and CVE-2020-24513
  (#1962659, #1962709, #1962729, #1962675):
  - Addition of 06-55-05/0xb7 (CLX-SP A0) microcode at revision 0x3000010;
  - Addition of 06-6a-05/0x87 (ICX-SP C0) microcode at revision 0xc0002f0;
  - Addition of 06-6a-06/0x87 (ICX-SP D0) microcode at revision 0xd0002a0;
  - Addition of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f;
  - Addition of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04)
    at revision 0xb00000f;
  - Addition of 06-86-04/0x01 (SNR B0) microcode (in intel-ucode/06-86-05)
    at revision 0xb00000f;
  - Addition of 06-86-05/0x01 (SNR B1) microcode at revision 0xb00000f;
  - Addition of 06-8c-02/0xc2 (TGL-R C0) microcode at revision 0x16;
  - Addition of 06-8d-01/0xc2 (TGL-H R0) microcode at revision 0x2c;
  - Addition of 06-96-01/0x01 (EHL B1) microcode at revision 0x11;
  - Addition of 06-9c-00/0x01 (JSL A0/A1) microcode at revision 0x1d;
  - Addition of 06-a7-01/0x02 (RKL-S B0) microcode at revision 0x40;
  - Update of. 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in
    intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xe2 up to 0xea;
  - Update of 06-4f-01/0xef (BDX-E/EP/EX/ML B0/M0/R0) microcode (in
    intel-06-4f-01/intel-ucode/06-4f-01) from revision 0xb000038 up
    to 0xb00003e;
  - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
    intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006a0a up
    to 0x2006b06;
  - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in
    intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xe2 up to 0xea;
  - Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
    intel-06-8c-01/intel-ucode/06-8c-01) from revision 0x68 up to 0x88;
  - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xde up
    to 0xea;
  - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xde up
    to 0xea;
  - Update of 06-8e-0a/0x.c0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xe0 up
    to 0xea;
  - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) from revision 0xde up
    to 0xea;
  - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0)
    microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from
    revision 0xde up to 0xea;
  - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xde up
    to 0xea;
  - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xde up
    to 0xea;
  - Upd.ate of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in
    intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xde up
    to 0xea;
  - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode
    from revision 0x44 up to 0x46;
  - Update of 06-3f-04/0x80 (HSX-EX E0) microcode from revision 0x16 up
    to 0x19;
  - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000159
    up to 0x100015b;
  - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4003006
    up to 0x4003102;
  - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision
    0x5003006 up to 0x5003102;
  - Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x700001e
    up to 0x7002302;
  - Update of 06-56-03/0x10 (BDX-DE V2/V3) microcode from revision
    0x7000019 up to 0x700001b;
  - Update of 06-56-04/0x10 (BDX-DE Y0) microcode from revision 0xf000017
    up to 0xf000019;
  - Update of 06-56-05/0x10 (BDX-NS A0/A1, HWL A1) microcode from revision
    0xe00000f up to 0xe000012;
  - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x40 up
    to 0x44;
  - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x1e up
    to 0x20;
  - Update of 06-5f-01/0x01 (DNV B0) microcode from revision 0x2e up
    to 0x34;
  - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x34 up
    to 0x36;
  - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x18 up
    to 0x1a;
  - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0xa0
    up to 0xa6;
  - Update of 06-8a-01/0x10 (LKF B2/B3) microcode from revision 0x28 up
    to 0x2a;
  - Update of 06-a5-02/0x20 (CML-H R1) microcode from revision 0xe0 up
    to 0xea;
  - Update of 06-a5-03/0x22 (CML-S 6+2 G1) microcode from revision 0xe0
    up to 0xea;
  - Update of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode from revision 0xe0
    up to 0xec;
  - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xe0
    up to 0xe8;
  - Update of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode from revision
    0xe0 up to 0xea.
e2`HecOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROy
_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441	_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archM_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 arch
[dEs[y_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archM_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archM_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.7-10Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
O,_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archM_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archM_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELRO
	Y%J|+YU%kCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u$_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archM#_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24y"k	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archM!_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27R gAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROy_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441

er+V:eD
9bb37ac3924384d007bdead158f96496ee81fe8eefecab3416f0f81800604648D
04343e0c734f4810fb43a53773019eae05e21428fa5cf05b99db8582265dc3d9D
658e256dc2a855fce160722fd0be5cc972233fe8bec6cca01cba74d0e6277a43D
82822855575f68931a78cb69d0b2b66a872fb63e31213c05cb77147946c29c41D
16a8541fcf4b2cd339c282e65bbae76ff488caf5eed0840a759841b6e56ff912D
2cb819274f11f736ace2eed931cc816e6c1833a96ebefa661cf5f185432be991D~
d7d37b96a50496b4afbe1af4b21e18430fd0714fe31b3d770dbee2da882cb98aD}
b0f845b17a6abdd7948335a2e03ef8bdbbf9e61bc00af3b2e543ed8708781374D|
9b7811c33c17c0451385a23f2766da783639500821e5bdd7fbea74b07f73a5f0D{
c77668ed49c6336ca11d1c0025def5d4583d666b6ee85808328364fc1fdd0a96Dz
656525e1205096365c3f08ea7899826e736d536330910a13a0d12adff683e362Dy
b960b52aab1348559908af3d4bae59cf32f1543cfd052b3e2d9fcd3edcfd2353Dx
b40ba100ed5ee8ae86882af45ded185b07a11fcfe03cc9c0e8481bbe5a89278b
he2hu-_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archM,_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24y+k	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archR*gAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032)cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)Z(iOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROy'_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441&_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330
21V2y5k	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 arch"4k[Lukas Javorsky <ljavorsk@redhat.com> - 1.2.7-21cױ@- Fix heap-based buffer over-read or buffer overflow in inflate in inflate.c
- Resolves: CVE-2022-37434R3gAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-250322cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)Z1iOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROy0_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441/_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330U.kCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500
6BgR=gAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032<cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)Z;iOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROy:_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #13374419_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330U8kCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u7_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archM6_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24
1Yl%1E_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UDkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500uC_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archMB_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yAk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archM@_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27?Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.7-10Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild">k[Lukas Javorsky <ljavorsk@redhat.com> - 1.2.7-21cױ@- Fix heap-based buffer over-read or buffer overflow in inflate in inflate.c
- Resolves: CVE-2022-37434
l%6luM_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archML_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yKk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archMJ_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27IFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.7-10Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildHcOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZGiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyF_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441
1[MU_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yTk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archMS_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27RcOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZQiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyP_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441O_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UNkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500
.3M]_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27R\gAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032[cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZZiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyY_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441X_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UWkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500uV_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le arch
e2`HeecOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZdiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyc_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441b_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UakCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u`_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archM__?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24y^k	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 arch
-c
oZmiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyl_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441k_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UjkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500ui_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archMh_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24ygk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archRfgAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032
C{%~7Cu_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UtkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500us_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archMr_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yqk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 arch"pk[Lukas Javorsky <ljavorsk@redhat.com> - 1.2.7-21cױ@- Fix heap-based buffer over-read or buffer overflow in inflate in inflate.c
- Resolves: CVE-2022-37434RogAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032ncOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)bR.RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{-"-&.).-.	0.3.7.9.=.!@.'B.,F.6I.<K.AO.TS.WX.X[.`_.sa.|e.j.m.q.u.y.|......%.-.5.=.E.M.U.].e.m.u.|...	.
......!.Â#.Ă&.ł*.Ƃ-.ǂ/.Ȃ3.ɂ6.ʂ8.˂<.̂@.͂B.΂E.ςG.ЂI.тK.҂O.ӂS.ԂX.Ղ].ւb.ׂf.؂i.قl.ڂn.ۂq.܂s.݂v.ނz.߂}..Ⴊ.₪.オ.䂪.傪.悪.炪.肪.邪.ꂪ.낪.삪#.(.-
)%J)h|K<jdennis@redhat.com> - 0.14.0-1[5@- Resolves: rhbz#1553885
- Rebase to current upstream release	{c1John Dennis <jdennis@redhat.com> - 0.13.1-2Z@- Resolves: rhbz#1481330 Add diagnostic logging
- Resolves: rhbz#1295472 Add MellonSignatureMethod config option to set
  signature method used to sign SAML messages sent by Mellon.
  Defaults to original sha1."zk[Lukas Javorsky <ljavorsk@redhat.com> - 1.2.7-21cױ@- Fix heap-based buffer over-read or buffer overflow in inflate in inflate.c
- Resolves: CVE-2022-37434RygAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032xcOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZwiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyv_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441
mewJakub Hrozek <jhrozek@redhat.com> - 0.14.0-5\N- Resolves: rhbz#1692470 - CVE-2019-3877 mod_auth_mellon: open redirect
                           in logout url when using URLs with backslashes
                           [rhel-7]Ie/Jakub Hrozek <jhrozek@redhat.com> - 0.14.0-4\@- Resolves: rhbz#1576719 - ECP flow not triggering, instead client access
                           secured resources without ECP authentication3~eJakub Hrozek <jhrozek@redhat.com> - 0.14.0-3\~d- Resolves: rhbz#1652980 - mod_auth_mellon Cert files name wrong when
                           hostname contains a numberg}K<jdennis@redhat.com> - 0.14.0-2[5A- Resolves: rhbz#1553885
- fix file permissions on doc files
l7%l4eJakub Hrozek <jhrozek@redhat.com> - 0.14.0-9^?@- Resolves: rhbz#1791264 - Backport SameSite=None cookie from upstream to
                           support latest browsers
e7Jakub Hrozek <jhrozek@redhat.com> - 0.14.0-8]- Resolves: rhbz#1731052 - CVE-2019-13038 mod_auth_mellon: an Open Redirect via
                           the login?ReturnTo= substring which could facilitate
                           information theft [rhel-7]'ekJakub Hrozek <jhrozek@redhat.com> - 0.14.0-7]Ik- Resolves: rhbz#1727789 - mod_auth_mellon fix for AJAX header name
                           X-Requested-WitheMJakub Hrozek <jhrozek@redhat.com> - 0.14.0-6\N- Apply the patch from the previous commit
- Resolves: rhbz#1692470 - CVE-2019-3877 mod_auth_mellon: open redirect
                           in logout url when using URLs with backslashes
                           [rhel-7]
cI	e/Jakub Hrozek <jhrozek@redhat.com> - 0.14.0-4\@- Resolves: rhbz#1576719 - ECP flow not triggering, instead client access
                           secured resources without ECP authentication3eJakub Hrozek <jhrozek@redhat.com> - 0.14.0-3\~d- Resolves: rhbz#1652980 - mod_auth_mellon Cert files name wrong when
                           hostname contains a numbergK<jdennis@redhat.com> - 0.14.0-2[5A- Resolves: rhbz#1553885
- fix file permissions on doc fileshK<jdennis@redhat.com> - 0.14.0-1[5@- Resolves: rhbz#1553885
- Rebase to current upstream release	c1John Dennis <jdennis@redhat.com> - 0.13.1-2Z@- Resolves: rhbz#1481330 Add diagnostic logging
- Resolves: rhbz#1295472 Add MellonSignatureMethod config option to set
  signature method used to sign SAML messages sent by Mellon.
  Defaults to original sha1.
3E3

e7Jakub Hrozek <jhrozek@redhat.com> - 0.14.0-8]- Resolves: rhbz#1731052 - CVE-2019-13038 mod_auth_mellon: an Open Redirect via
                           the login?ReturnTo= substring which could facilitate
                           information theft [rhel-7]'ekJakub Hrozek <jhrozek@redhat.com> - 0.14.0-7]Ik- Resolves: rhbz#1727789 - mod_auth_mellon fix for AJAX header name
                           X-Requested-WitheMJakub Hrozek <jhrozek@redhat.com> - 0.14.0-6\N- Apply the patch from the previous commit
- Resolves: rhbz#1692470 - CVE-2019-3877 mod_auth_mellon: open redirect
                           in logout url when using URLs with backslashes
                           [rhel-7]m
ewJakub Hrozek <jhrozek@redhat.com> - 0.14.0-5\N- Resolves: rhbz#1692470 - CVE-2019-3877 mod_auth_mellon: open redirect
                           in logout url when using URLs with backslashes
                           [rhel-7]
G>^@cJakub Hrozek <jhrozek@redhat.com> - 1.8.8-4\P@@- Resolves: rhbz#1626299 - CVE-2017-6059 mod_auth_openidc: Shows
                           user-supplied content on error pages [rhel-7][aWJohn Dennis <jdennis@redhat.com> - 1.8.8-3V@- fix unit test failure caused by apr_jwe_decrypt_content_aesgcm()
  failing to null terminate decrypted string
  Resolves: bug#1292561 New package: mod_auth_openidca)John Dennis <jdennis@redhat.com> - 1.8.8-2VnA- Add %check to run test
  Resolves: bug#1292561 New package: mod_auth_openidc|aJohn Dennis <jdennis@redhat.com> - 1.8.8-1Vn@- Initial import
  Resolves: bug#1292561 New package: mod_auth_openidc4eJakub Hrozek <jhrozek@redhat.com> - 0.14.0-9^?@- Resolves: rhbz#1791264 - Backport SameSite=None cookie from upstream to
                           support latest browsers
fff{cJakub Hrozek <jhrozek@redhat.com> - 1.8.8-7^ojA- Fix a regression in the previous patches
- Related: rhbz#1805748 - CVE-2019-20479 mod_auth_openidc: open redirect
                          issue exists in URLs with slash and backslash [rhel-7]c;Jakub Hrozek <jhrozek@redhat.com> - 1.8.8-6^oj@- Resolves: rhbz#1805748 - CVE-2019-20479 mod_auth_openidc: open redirect
                           issue exists in URLs with slash and backslash [rhel-7]
- Resolves: rhbz#1805067 - CVE-2019-14857 mod_auth_openidc: Open redirect
                           in logout url when using URLs with leading slashes
                           [rhel-7]c#Jakub Hrozek <jhrozek@redhat.com> - 1.8.8-5\P@A- Resolves: rhbz#1626297 - CVE-2017-6413 mod_auth_openidc: OIDC_CLAIM and
                           OIDCAuthNHeader not skipped in an "AuthType oauth20"
                           configuration [rhel-7]
))Tk?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyq]Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)cEJakub Hrozek <jhrozek@redhat.com> - 1.8.8-9_~@- Rebuild to pick up the proper build tag
- Related: rhbz#1823762 - Backport SameSite=None cookie from
                          mod_auth_openidc upstream to support
                          latest browsers [rhel-7.9.z]lcwJakub Hrozek <jhrozek@redhat.com> - 1.8.8-8_FN- Resolves: rhbz#1823762 - Backport SameSite=None cookie from
                           mod_auth_openidc upstream to support
                           latest browsers [rhel-7.9.z]
ejekILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
4k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
  P!}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.1ah- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases. qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues

er+V:eD
4d1bd70c6b0a083aa5199e8688e2f1a51866cd56dfb5c1d7604347e2bce43b18D
ed4172e7f07f89851711d81ae9ac691552500f1359efcfa1a0312b3c42b1e171D
d69a242a1a58b858cffa727cb8193e2ccaf358421e81076cf5c96b4a5082d5f9D
8bad0cae9095a9462eee405070201f5aa90c8754e0b955a3e7e3599af9f81ffbD

e35ecb4beea182f7288644cabd57114e698301a9bc0577e0b71c41956b316426D
bd9b457e03a3e875a7f50a246490891ba2bf62f71e73613950b38d17f84d340dD
931e68ffcae787d5ccc19e02105ea41bb97387921e3e0e7bfa8402118570759dD

ea6f1a1a7c98ce44e3489a64d9fcac1d1df66d5e27e509bf3c0413c0d2f01be2D	
d755a7a0945f9ae0c99eaa26a96db5d9fcca41d6a1a533a895cad61a85f4e6d6D
e91975b3209890c97303eaf69e0732753a849373370d3f3db3d54eaa5d7a540dD
9bc8c09cfaaabcb254797b1579fccbbf5a7ac3febd8172c07ad6764c33c3270eD
b505b67a44068dde29102d451d6c870990ee335392b3e5328c79d22c00912870D
9096f48c5db56f9f48a681b03c82afe3ed04a3f10af7b37ad132a68062fdc34b
#k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connectionT"k?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistency
//G&k%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications%kILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec$]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)
j_*q/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.)qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S(k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues'k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
&+&-kILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec,]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)P+}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.2a@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases
4/k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG.k%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
a-3qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart content2q/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.1qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S0k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
BB6kILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timeP5}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.4aZ@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesF4W7Luboš Uhliarik <luhliari@redhat.com>a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
48k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG7k%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
a-<qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart content;q/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.:qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S9k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
~~@m7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-88[+@- Resolves: #1527295 - httpd with worker/event mpm segfaults after multiple
  SIGUSR1P?}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.5b<]@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases:>qLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierS=q7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
22TBk?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyqA]Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)
ejeEkILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timecD]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)Ck9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
4Gk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGFk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
NIy%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos_- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesSHk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
4Kk9	Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGJk%	Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
a-Oqk	Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentNq/	Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.Mqm	Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SLk=	Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
f;fPS}%	CentOS Sources <bugs@centos.org> - 2.4.6-98.el7.centos.6c@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases)Rqc	Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:Qq	Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSPq7	Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
j_-Xqk
Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentWq/
Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.Vqm
Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SUk=
Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issuesTk9
Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
J;JF]OA
Johnny Hughes <johnny@centos.org>d-b- Manual CentOS Debranding"\qU
Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)[qc
Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:Zq
Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSYq7
Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
j_-bqkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentaq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.`qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S_k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues^k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
;"fqULuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)eqcLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:dqLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierScq7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
}Tik?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyqh]Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)gqLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-99.1dJc- Resolves: #2190143 - mod_rewrite regression with CVE-2023-25690
ejelkILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timeck]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)jk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
4nk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGmk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
  Pq}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.1ah- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases.pqmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sok=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
sk9
Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connectionTrk?
Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistency
//Gvk%
Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applicationsukI
Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timect]m
Joe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)
j_zq/
Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.yqm
Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sxk=
Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issueswk9
Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
&+&}kILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec|]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)P{}%
CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.2a@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases
4k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG~k%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
a-qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
BBkILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timeP}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.4aZ@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesFW7Luboš Uhliarik <luhliari@redhat.com>a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
4k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
a-qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.
qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S	k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
~~m7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-88[+@- Resolves: #1527295 - httpd with worker/event mpm segfaults after multiple
  SIGUSR1P}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.5b<]@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases:qLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierS
q7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
22Tk?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyq]Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)
ejekILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
4k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
Ny%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos_- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesSk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
4k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
a-qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
f;fP#}%CentOS Sources <bugs@centos.org> - 2.4.6-98.el7.centos.6c@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases)"qcLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:!qLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierS q7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session

er+V:eD
14915891af23de39be92b9e4e610d5fe1f11d691b6c0bd554ea4f71e130b80a8D
61b97c3a1622caf467be58d602a85f34f16db6320e94c9d471b9ef874ce61982D
66c291b64d8ff006ef287fd920978e0b901b0947dfa61d8ee3b0f3f76f242480D
0228887c20e6cb39e203d667f60bf1e06e9496f7302af59a477a3db454b70575D
81a303d0e2c1f786e5921377bd64c30c8d1daa75fda45c1e17c45ef28b02c568D
904bf015b9ebdad14b887224bff8f4c245ea3f185ebc64c0a9446b250f5ddcd2D
1cd1ae8c0b9506f0a8066d9b0a935712889175386de9909062d20b0523e2876bD
1cbb2208fd1a88235398a0429e2e4dfaef8c5ce0593aa8b550c370224ca23fe1D
f317e5b0fc8e8e40046f6893b5e1dc36e8b5cf17a92069152dccb27c1ff6c45dD
db914ded5eb6eb9d8b435563ac6f54fc75c81cd4118ec39a25d1562f420c41f8D
be8404b5ebae76ba968eb3364b0d41d94244b74d0af84bd6045d32cd88c42932D
deca008ed0c50034daab0bb70b65cd418b3ae2a3bb46f2fb5b5d2c80f9cbe0e5D
3b66f1712118ad0d41f8596409e86a1e86066cef3804f7bdd83ef8c519cbc003
j_-(qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart content'q/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.&qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S%k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues$k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
J;JF-OAJohnny Hughes <johnny@centos.org>d-b- Manual CentOS Debranding",qULuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)+qcLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:*qLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierS)q7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
j_-2qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart content1q/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.0qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S/k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues.k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
;"6qULuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)5qcLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:4qLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierS3q7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
Z}[Z=Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.2.6-5Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuildb<_iPeter Vrabec <pvrabec@redhat.com> 2.2.6-4P@- "extras" subpackage is not provided on RHEL7;uIAthmane Madjoudj <athmane@fedoraproject.org> 2.2.6-3P~- Remove the patch since we're requiring mod_security >= 2.7.0
- Require mod_security >= 2.7.0:uAthmane Madjoudj <athmane@fedoraproject.org> 2.2.6-2Pi- Add a patch to fix incompatible rules.
- Update to new git release9uAthmane Madjoudj <athmane@fedoraproject.org> 2.2.6-1PTm- Update to 2.2.6
- Update spec file since upstream moved to Github.i8uaAthmane Madjoudj <athmane@fedoraproject.org> 2.2.5-5PQ- Enable extra rules sub-package for EPEL.7qLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-99.1dJc- Resolves: #2190143 - mod_rewrite regression with CVE-2023-25690
KKTCk?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyqB]Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)}AcTomas Korbar <tkorbar@redhat.com> - 2.2.9-3c- Fix application of the response status patch
- Related: rhbz#2124200|@cTomas Korbar <tkorbar@redhat.com> - 2.2.9-2c- Move response status rule to earlier phase
- Resolves: rhbz#2124200?i;Daniel Kopecek <dkopecek@redhat.com> - 2.2.9-1WW@- Rebased to version 2.2.9
- Fixed bogus date in the changelog
  Resolves: rhbz#1150614L>]?Daniel Mach <dmach@redhat.com> - 2.2.6-6Rk- Mass rebuild 2013-12-27
ejeFkILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timecE]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)Dk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
4Hk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGGk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
  PK}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.1ah- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases.JqmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SIk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
Mk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connectionTLk?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistency
//GPk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applicationsOkILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timecN]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)
j_Tq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.SqmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SRk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issuesQk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
&+&WkILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timecV]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)PU}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.2a@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases
4Yk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGXk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
a-]qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart content\q/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.[qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SZk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
BB`kILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timeP_}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.4aZ@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesF^W7Luboš Uhliarik <luhliari@redhat.com>a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
4bk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGak%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
a-fqkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contenteq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.dqmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sck=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
~~jm7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-88[+@- Resolves: #1527295 - httpd with worker/event mpm segfaults after multiple
  SIGUSR1Pi}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.5b<]@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases:hqLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSgq7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
22Tlk?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyqk]Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)
ejeokILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timecn]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)mk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
4qk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGpk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
Nsy%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos_- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesSrk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
4uk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGtk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
a-yqkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentxq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.wqmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Svk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
f;fP}}%CentOS Sources <bugs@centos.org> - 2.4.6-98.el7.centos.6c@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases)|qcLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:{qLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSzq7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
j_-qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues~k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
J;JFOAJohnny Hughes <johnny@centos.org>d-b- Manual CentOS Debranding"qULuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)qcLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:qLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSq7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
j_-qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentq/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.
qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S	k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issuesk9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
;"qULuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)qcLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:qLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierS
q7Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
}Tk?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyq]Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)qLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-99.1dJc- Resolves: #2190143 - mod_rewrite regression with CVE-2023-25690
ejekILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connection
4k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGk%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
  P}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.1ah- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases.qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"Sk=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connectionTk?Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistency
//G k%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applicationskILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)
j_$q/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.#qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S"k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues!k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
&+&'kILubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec&]mJoe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)P%}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.2a@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases

er+V:eD+
1ec9ab3e99e2c5ab2c09573b75bace2a32b399ef7f96411b8be713b0793225deD*
7b45707f7663e49ac7b9284020212ac82fa961b018eae09ce504f69ced527ca1D)
fd4d10950f499e8ff12b7354df494a29bc6c5c88db808bb7245d05a900fc6dbfD(
42bfea454da2eacfb32d84a41908a2e6d89c8e46d04ea6a5ccefa5e251b3f3f9D'
eb48815ca014d65a115c0ac9dba6f0c28dc765fbc161fc9ac11d3573786c6b4aD&
72872ee299214c68c0fb449a111ab5178f764ab24db86850448332c6b4fb7cfcD%
5cc00750206f4e78afabfb9b056e174bae1ac30245373825f150d87b55a7c6abD$
25140183ca7e3bbe7db7168653af8054b00324b50e2d6f28041960f5bf914598D#
50da2508f98f265f7ea4063d0f2a29fa9248b1aab9b37f54f9278b1addfc22beD"
c44b275bbc2e3ffe972b69236172d24d3e22046b3060cd4282021355c2777c8dD!
25391ffb1394e063287420508e3e0ba93134a21e2a4cae273434eda6c0613fb1D 
e1558062e338ec19488115a645f60559e370f1ddbf06a4b6e522b9803ac21304D
dd0e9de5630bcc248395482170c7a3b3d61876f1b93a950464ca6a1125b6dd53
4)k9Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG(k%Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
a--qkLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart content,q/Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.+qmLuboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S*k=Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
BB0kI Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timeP/}%CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.4aZ@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesF.W7Luboš Uhliarik <luhliari@redhat.com>a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
42k9 Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG1k% Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
a-6qk Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart content5q/ Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.4qm Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"S3k= Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
~~:m7!Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-88[+@- Resolves: #1527295 - httpd with worker/event mpm segfaults after multiple
  SIGUSR1P9}% CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos.5b<]@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases:8q Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierS7q7 Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
22T<k?!Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-90\@- Resolves: #1566317 - CVE-2018-1312 httpd: Weak Digest auth nonce generation
  in mod_auth_digest
- Resolves: #1696141 - CVE-2019-0217 httpd: mod_auth_digest: access control
  bypass due to race condition
- Resolves: #1696096 - CVE-2019-0220 httpd: URL normalization inconsistencyq;]!Joe Orton <jorton@redhat.com> - 2.4.6-89\- fix per-request leak of bucket brigade structure (#1583218)
eje?kI!Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-93]z@- Resolves: #1677496 - CVE-2018-17199 httpd: mod_session_cookie does not respect
  expiry timec>]m!Joe Orton <jorton@redhat.com> - 2.4.6-92]^- htpasswd: add SHA-2 crypt() support (#1486889)=k9!Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-91]A- Resolves: #1630886 - scriptlet can fail if hostname is not installed
- Resolves: #1565465 - CVE-2017-15710 httpd: Out of bound write in
  mod_authnz_ldap when using too small Accept-Language values
- Resolves: #1568298 - CVE-2018-1301 httpd: Out of bounds access after
  failure in reading the HTTP request
- Resolves: #1673457 - Apache child process crashes because ScriptAliasMatch
  directive
- Resolves: #1633152 - mod_session missing apr-util-openssl
- Resolves: #1649470 - httpd response contains garbage in Content-Type header
- Resolves: #1724034 - Unexpected OCSP in proxy SSL connectionbR/WRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{.6.=.C.F.H.K.M.P.T.W.Y.].`.b.f/j/l/o/q/s/u/y/}//	/
///
//// /$/'/)/-/0/2/6/:/</?/A/C/ E/!I/"M/#R/$W/%\/&`/'h/(p/)x/*/+/,/-/.//'/1//26/3>/4F/5N/6U/7]/8e/9m/:u/;|/</=/>	/?/@/A/B/C!/D%/E+/G//H6/I;/J?/KD/LH/MM/NQ/OV/P]/Qb/Rh/Sm/Tq/Uv/V{
4Ak9!Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueG@k%!Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
NCy%!CentOS Sources <bugs@centos.org> - 2.4.6-97.el7.centos_- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliasesSBk=!Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
4Ek9"Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  valueGDk%"Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-94^|@- Resolves: #1565491 - CVE-2017-15715 httpd: <FilesMatch> bypass with a trailing
  newline in the file name
- Resolves: #1747283 - CVE-2019-10098 httpd: mod_rewrite potential open redirect
- Resolves: #1724879 - httpd terminates all SSL connections using an abortive
  shutdown
- Resolves: #1715981 - Backport of SessionExpiryUpdateInterval directive
- Resolves: #1565457 - CVE-2018-1303 httpd: Out of bounds read in
  mod_cache_socache can allow a remote attacker to cause a denial of service
- Resolves: #1566531 - CVE-2018-1283 httpd: Improper handling of headers in 
  mod_session can allow a remote user to modify session data for CGI applications
a-Iqk"Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentHq/"Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.Gqm"Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SFk="Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issues
f;fPM}%"CentOS Sources <bugs@centos.org> - 2.4.6-98.el7.centos.6c@- Remove index.html, add centos-noindex.tar.gz
- change vstring
- change symlink for poweredby.png
- update welcome.conf with proper aliases)Lqc"Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:Kq"Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSJq7"Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
j_-Rqk#Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart contentQq/#Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.Pqm#Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SOk=#Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issuesNk9#Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
J;JFWOA#Johnny Hughes <johnny@centos.org>d-b- Manual CentOS Debranding"VqU#Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)Uqc#Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:Tq#Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierSSq7#Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
j_-\qk$Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.3a- Resolves: #2035058 - CVE-2021-44790 httpd: mod_lua: possible buffer overflow
  when parsing multipart content[q/$Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.2av@- Resolves: #2015694 - proxy rewrite to unix socket fails with CVE-2021-40438 fix.Zqm$Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.1a^@- Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted
  request uri-path containing "unix:"SYk=$Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-97_}- Resolves: #1852350 - httpd/mod_proxy_http/mod_ssl aborted when sending
  a client cert to backend server
- Resolves: #1785100 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
- Resolves: #1862499 - Intermittent Segfault in Apache httpd due to pool
  concurrency issuesXk9$Lubos Uhliarik <luhliari@redhat.com> - 2.4.6-95^@- Resolves: #1823262 - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized
  value
;"`qU$Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.7d@- Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
  mod_rewrite and mod_proxy)_qc$Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.6c@- Resolves: #2101997 - HEAD request with a 404 and custom ErrorPage causes
  corrupt and mixed-up responses:^q$Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.5b9@- Resolves: #2065243 - CVE-2022-22720 httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlierS]q7$Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-97.4a- Resolves: #2031072 - CVE-2021-34798 httpd: NULL pointer dereference via
  malformed requests
- Resolves: #2031074 - CVE-2021-39275 httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
- Resolves: #1969226 - CVE-2021-26691 httpd: Heap overflow in mod_session
#}
	#thsy%Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103jgse%Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306vfs}%Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{es%Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799dg%Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-21^`- Add PING_TIMEOUT_DELAY to mutter MetaPreferences
  Resolves: #1809164cs
%Florian Müllner <fmuellner@redhat.com> - 3.28.3-20]N@- Free close dialog before unmanaging parent
  Related: #1753799obg{%Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-19])- Fix invalid read in idle monitor
  Resolves: #1752378aq$Luboš Uhliarik <luhliari@redhat.com> - 2.4.6-99.1dJc- Resolves: #2190143 - mod_rewrite regression with CVE-2023-25690
&s'&vps}&Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{os&Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799ng&Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-21^`- Add PING_TIMEOUT_DELAY to mutter MetaPreferences
  Resolves: #1809164ms
&Florian Müllner <fmuellner@redhat.com> - 3.28.3-20]N@- Free close dialog before unmanaging parent
  Related: #1753799olg{&Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-19])- Fix invalid read in idle monitor
  Resolves: #1752378]kc[%Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000tjg%Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029ig+%Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242
-1-{xs'Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799wg'Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-21^`- Add PING_TIMEOUT_DELAY to mutter MetaPreferences
  Resolves: #1809164vs
'Florian Müllner <fmuellner@redhat.com> - 3.28.3-20]N@- Free close dialog before unmanaging parent
  Related: #1753799]uc[&Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000ttg&Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029sg+&Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242trsy&Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103jqse&Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306
6:6s
(Florian Müllner <fmuellner@redhat.com> - 3.28.3-20]N@- Free close dialog before unmanaging parent
  Related: #1753799}g'Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-30_#- Try to fix leaks even more and a log spew fix
  Resolves: #1897063]~c['Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000t}g'Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029|g+'Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242t{sy'Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103jzse'Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306vys}'Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869
6{6]c[(Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000tg(Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029g+(Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242tsy(Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103jse(Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306vs}(Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{s(Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799g(Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-21^`- Add PING_TIMEOUT_DELAY to mutter MetaPreferences
  Resolves: #1809164
{g+)Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242tsy)Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103j
se)Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306vs})Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{s)Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799
g)Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-21^`- Add PING_TIMEOUT_DELAY to mutter MetaPreferences
  Resolves: #1809164}	g(Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-30_#- Try to fix leaks even more and a log spew fix
  Resolves: #1897063
8'$ 8jse*Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306vs}*Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{s*Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799g*Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-21^`- Add PING_TIMEOUT_DELAY to mutter MetaPreferences
  Resolves: #1809164~g)Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-31bf@- Fix race condition causing stuck pointer grabs
  Resolves: #2054507}g)Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-30_#- Try to fix leaks even more and a log spew fix
  Resolves: #1897063]c[)Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000tg)Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029
&"&vs}+Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{s+Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799~g*Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-31bf@- Fix race condition causing stuck pointer grabs
  Resolves: #2054507}g*Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-30_#- Try to fix leaks even more and a log spew fix
  Resolves: #1897063]c[*Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000tg*Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029g+*Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242tsy*Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103
&3&'e)+Jonas Ådahl <jadahl@redhat.com> - 3.28.3-32b(- Fix _NET_WM_FRAME_DRAWN timestamps when overflow occurs
  Resolves: #2128996~&g+Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-31bf@- Fix race condition causing stuck pointer grabs
  Resolves: #2054507}%g+Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-30_#- Try to fix leaks even more and a log spew fix
  Resolves: #1897063]$c[+Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000t#g+Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029"g++Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242t!sy+Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103j se+Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306

er+V:eD8
9cfc662e7205b955336839340e91d244d4c1151e65f24d263b83a7284397aadcD7
ef2da07e17ad85947c0e573c1504b7566d8f242eb7bd44c2113d1acbb0e78a60D6
3336d0c5df4e7d13b0a72ba226318a764a5ec8aa70ecdccfb63e3e01fe7dbf42D5
81842832fb5e2ebf0b8c4d8f9d6e5fce417deee396059e72dd09a8180b6c94afD4
0c05547ab6db1a5fe777068a16ceaf758e35d33abedd3643f7dc8bee4b68af5fD3
a44f98ca0940978bcb90de24620d95a537a8c46a0e15d0c211db20d0afe09131D2
4b14173ba0287bf249a3f49d9d5968a1bb673fe58f4a0ee8e066a9aa389741bdD1
be4849e6f5efd2df57c2054a73f7edaf2b47ce5ce34a2819269e10158ee4d460D0
2b4e66ff61ba4a7722ed44b9ca9487b146ddcbe7bc27c08a8b07be8049b546e7D/
ca6edad606ed1ae0aad8a9ae177f501264d15718f85d304957942d0ed5768647D.
d4f08989f469c8c654a2986c6fe6f0f1f7bb38bec3e1445f93c1df505f92d04aD-
7e5b27fb6123ab5f0cdd5f923b6c4f144c4cff9c981c132969b3026427a32a17D,
08949cdd78826f2931cedc5db7b5ecee0f22e07f614ab03c88690cc3ad353c4c
:!:}/g,Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-30_#- Try to fix leaks even more and a log spew fix
  Resolves: #1897063].c[,Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000t-g,Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029,g+,Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242t+sy,Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103j*se,Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306v)s},Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{(s,Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799
~xv6s}-Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{5s-Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #17537994g-Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-21^`- Add PING_TIMEOUT_DELAY to mutter MetaPreferences
  Resolves: #18091643s
-Florian Müllner <fmuellner@redhat.com> - 3.28.3-20]N@- Free close dialog before unmanaging parent
  Related: #1753799o2g{-Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-19])- Fix invalid read in idle monitor
  Resolves: #17523781e),Jonas Ådahl <jadahl@redhat.com> - 3.28.3-32b(- Fix _NET_WM_FRAME_DRAWN timestamps when overflow occurs
  Resolves: #2128996~0g,Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-31bf@- Fix race condition causing stuck pointer grabs
  Resolves: #2054507
9A9>g.Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-21^`- Add PING_TIMEOUT_DELAY to mutter MetaPreferences
  Resolves: #1809164=s
.Florian Müllner <fmuellner@redhat.com> - 3.28.3-20]N@- Free close dialog before unmanaging parent
  Related: #1753799o<g{.Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-19])- Fix invalid read in idle monitor
  Resolves: #1752378];c[-Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000t:g-Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #18110299g+-Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242t8sy-Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103j7se-Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306
8!8Fs
/Florian Müllner <fmuellner@redhat.com> - 3.28.3-20]N@- Free close dialog before unmanaging parent
  Related: #1753799]Ec[.Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000tDg.Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029Cg+.Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242tBsy.Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103jAse.Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306v@s}.Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{?s.Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799
6{6]Nc[/Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000tMg/Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029Lg+/Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242tKsy/Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103jJse/Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306vIs}/Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{Hs/Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799Gg/Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-21^`- Add PING_TIMEOUT_DELAY to mutter MetaPreferences
  Resolves: #1809164
w~tUsy0Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103jTse0Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306vSs}0Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{Rs0Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799Qg0Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-21^`- Add PING_TIMEOUT_DELAY to mutter MetaPreferences
  Resolves: #1809164Ps
0Florian Müllner <fmuellner@redhat.com> - 3.28.3-20]N@- Free close dialog before unmanaging parent
  Related: #1753799}Og/Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-30_#- Try to fix leaks even more and a log spew fix
  Resolves: #1897063
-s-j]se1Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306v\s}1Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{[s1Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799Zg1Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-21^`- Add PING_TIMEOUT_DELAY to mutter MetaPreferences
  Resolves: #1809164}Yg0Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-30_#- Try to fix leaks even more and a log spew fix
  Resolves: #1897063]Xc[0Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000tWg0Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029Vg+0Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242
"{es2Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799dg2Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-21^`- Add PING_TIMEOUT_DELAY to mutter MetaPreferences
  Resolves: #1809164~cg1Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-31bf@- Fix race condition causing stuck pointer grabs
  Resolves: #2054507}bg1Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-30_#- Try to fix leaks even more and a log spew fix
  Resolves: #1897063]ac[1Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000t`g1Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029_g+1Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242t^sy1Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103
7:7~mg2Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-31bf@- Fix race condition causing stuck pointer grabs
  Resolves: #2054507}lg2Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-30_#- Try to fix leaks even more and a log spew fix
  Resolves: #1897063]kc[2Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000tjg2Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029ig+2Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242thsy2Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103jgse2Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306vfs}2Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869
:!:}ug3Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-30_#- Try to fix leaks even more and a log spew fix
  Resolves: #1897063]tc[3Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000tsg3Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029rg+3Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242tqsy3Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103jpse3Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306vos}3Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{ns3Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799
~t|g+4Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-26^@- Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages
  Resolves: #1846242t{sy4Florian Müllner <fmuellner@redhat.com> - 3.28.3-25^- Notify workspace layout changes
  Resolves: #1848103jzse4Florian Müllner <fmuellner@redhat.com> - 3.28.3-24^- Fix extended OSK keys
  Resolves: #1625306vys}4Florian Müllner <fmuellner@redhat.com> - 3.28.3-23^@- Improve performance under IO load
  Resolves: #1824869{xs4Florian Müllner <fmuellner@redhat.com> - 3.28.3-22^b;@- Include one more close-dialog backport
  Related: #1753799we)3Jonas Ådahl <jadahl@redhat.com> - 3.28.3-32b(- Fix _NET_WM_FRAME_DRAWN timestamps when overflow occurs
  Resolves: #2128996~vg3Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-31bf@- Fix race condition causing stuck pointer grabs
  Resolves: #2054507
-'$-h[y5Jeff Moyer <jmoyer@redhat.com> - 60.3-4[^- Apply all patches (Jeff Moyer)
- Related: bz#1456320e)4Jonas Ådahl <jadahl@redhat.com> - 3.28.3-32b(- Fix _NET_WM_FRAME_DRAWN timestamps when overflow occurs
  Resolves: #2128996~g4Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-31bf@- Fix race condition causing stuck pointer grabs
  Resolves: #2054507}g4Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-30_#- Try to fix leaks even more and a log spew fix
  Resolves: #1897063]~c[4Ray Strode <rstrode@redhat.com> - 3.28.3-28_@- Try to fix leaks
  Resolves: #1717000t}g4Jonas Ådahl <jadahl@redhat.com>) - 3.28.3-27^A- Turn stacking warning into debug log
  Resolves: #1811029
	[95Jeff Moyer <jmoyer@redhat.com> - 64.1-2\e- Fix initramfs creating by forcing installation of libnvdimm.ko
- Related: bz#1634348?[%5Jeff Moyer <jmoyer@redhat.com> - 64.1-1\@- Rebase to v64.1 (Jeff Moyer)
  - add security commands
  - fix broken udev rule for dirty shutdown count
- Resolves: bz#1634348 bz#1635441)W}5Jeff Moyer <jmoyer@redhat.com> - 62-1[~- Rebase to v62 (Jeff Moyer)
  - a new monitor command / daemon
  - an ndctl udev rule for recording the unsafe shutdown count
  - smart error injection
  - create-namespace fix for fragmented namespaces
- Resolves: bz#1610649 bz#1611833 bz#1456320
?]?	_95Jeff Moyer <jmoyer@redhat.com> - 65.4.el7]QT- Add spaces to the add_driver directive in the dracut module
- Resolves: rhbz#17403834_5Jeff Moyer <jmoyer@redhat.com> - 65.3.el7]Ik- modify nvdimm-security.conf touse '&&' instead of ';'
  Without this change, the module doesn't load
- Resolves: rhbz#1725405P_C5Jeff Moyer <jmoyer@redhat.com> - 65.2.el7]>- Remove 'daxctl migrate-device-model' command.  We won't
  support hot-plugging device dax into the memory hierarchy
  on RHEL 7.
- Resolves: rhbz#1734153__5Jeff Moyer <jmoyer@redhat.com> - 65.1.el7]9- Rebase to v65
  - clear-errors: new command to clear errors on a namespace
  - monitor: remove the requirement of a default config
  - sanitize-dimm: allow a zero-key for secure-erase
  - sanitize-dimm: preserve keys after an overwrite
  - load-keys: fix for non-TPM keys
- Fix test harness to run against the rhel7 test kernel modules
- Related: rhbz#1722481
~_?[%6Jeff Moyer <jmoyer@redhat.com> - 64.1-1\@- Rebase to v64.1 (Jeff Moyer)
  - add security commands
  - fix broken udev rule for dirty shutdown count
- Resolves: bz#1634348 bz#1635441)
W}6Jeff Moyer <jmoyer@redhat.com> - 62-1[~- Rebase to v62 (Jeff Moyer)
  - a new monitor command / daemon
  - an ndctl udev rule for recording the unsafe shutdown count
  - smart error injection
  - create-namespace fix for fragmented namespaces
- Resolves: bz#1610649 bz#1611833 bz#1456320h[y6Jeff Moyer <jmoyer@redhat.com> - 60.3-4[^- Apply all patches (Jeff Moyer)
- Related: bz#1456320_#5Jeff Moyer <jmoyer@redhat.com> - 65.6.el7_ܙ- add space to install_items in dracut config file
- Resolves: rhbz#1909233~
_5Jeff Moyer <jmoyer@redhat.com> - 65.5.el7]w@- Once again attempt to fix nvdimm-security.conf
- Resolves: rhbz#1750199
ArA4_6Jeff Moyer <jmoyer@redhat.com> - 65.3.el7]Ik- modify nvdimm-security.conf touse '&&' instead of ';'
  Without this change, the module doesn't load
- Resolves: rhbz#1725405P_C6Jeff Moyer <jmoyer@redhat.com> - 65.2.el7]>- Remove 'daxctl migrate-device-model' command.  We won't
  support hot-plugging device dax into the memory hierarchy
  on RHEL 7.
- Resolves: rhbz#1734153__6Jeff Moyer <jmoyer@redhat.com> - 65.1.el7]9- Rebase to v65
  - clear-errors: new command to clear errors on a namespace
  - monitor: remove the requirement of a default config
  - sanitize-dimm: allow a zero-key for secure-erase
  - sanitize-dimm: preserve keys after an overwrite
  - load-keys: fix for non-TPM keys
- Fix test harness to run against the rhel7 test kernel modules
- Related: rhbz#1722481	[96Jeff Moyer <jmoyer@redhat.com> - 64.1-2\e- Fix initramfs creating by forcing installation of libnvdimm.ko
- Related: bz#1634348
pi)W}7Jeff Moyer <jmoyer@redhat.com> - 62-1[~- Rebase to v62 (Jeff Moyer)
  - a new monitor command / daemon
  - an ndctl udev rule for recording the unsafe shutdown count
  - smart error injection
  - create-namespace fix for fragmented namespaces
- Resolves: bz#1610649 bz#1611833 bz#1456320h[y7Jeff Moyer <jmoyer@redhat.com> - 60.3-4[^- Apply all patches (Jeff Moyer)
- Related: bz#1456320_#6Jeff Moyer <jmoyer@redhat.com> - 65.6.el7_ܙ- add space to install_items in dracut config file
- Resolves: rhbz#1909233~_6Jeff Moyer <jmoyer@redhat.com> - 65.5.el7]w@- Once again attempt to fix nvdimm-security.conf
- Resolves: rhbz#1750199_96Jeff Moyer <jmoyer@redhat.com> - 65.4.el7]QT- Add spaces to the add_driver directive in the dracut module
- Resolves: rhbz#1740383
6<6P_C7Jeff Moyer <jmoyer@redhat.com> - 65.2.el7]>- Remove 'daxctl migrate-device-model' command.  We won't
  support hot-plugging device dax into the memory hierarchy
  on RHEL 7.
- Resolves: rhbz#1734153__7Jeff Moyer <jmoyer@redhat.com> - 65.1.el7]9- Rebase to v65
  - clear-errors: new command to clear errors on a namespace
  - monitor: remove the requirement of a default config
  - sanitize-dimm: allow a zero-key for secure-erase
  - sanitize-dimm: preserve keys after an overwrite
  - load-keys: fix for non-TPM keys
- Fix test harness to run against the rhel7 test kernel modules
- Related: rhbz#1722481	[97Jeff Moyer <jmoyer@redhat.com> - 64.1-2\e- Fix initramfs creating by forcing installation of libnvdimm.ko
- Related: bz#1634348?[%7Jeff Moyer <jmoyer@redhat.com> - 64.1-1\@- Rebase to v64.1 (Jeff Moyer)
  - add security commands
  - fix broken udev rule for dirty shutdown count
- Resolves: bz#1634348 bz#1635441
G5D)!W}8Jeff Moyer <jmoyer@redhat.com> - 62-1[~- Rebase to v62 (Jeff Moyer)
  - a new monitor command / daemon
  - an ndctl udev rule for recording the unsafe shutdown count
  - smart error injection
  - create-namespace fix for fragmented namespaces
- Resolves: bz#1610649 bz#1611833 bz#1456320h [y8Jeff Moyer <jmoyer@redhat.com> - 60.3-4[^- Apply all patches (Jeff Moyer)
- Related: bz#1456320_#7Jeff Moyer <jmoyer@redhat.com> - 65.6.el7_ܙ- add space to install_items in dracut config file
- Resolves: rhbz#1909233~_7Jeff Moyer <jmoyer@redhat.com> - 65.5.el7]w@- Once again attempt to fix nvdimm-security.conf
- Resolves: rhbz#1750199_97Jeff Moyer <jmoyer@redhat.com> - 65.4.el7]QT- Add spaces to the add_driver directive in the dracut module
- Resolves: rhbz#17403834_7Jeff Moyer <jmoyer@redhat.com> - 65.3.el7]Ik- modify nvdimm-security.conf touse '&&' instead of ';'
  Without this change, the module doesn't load
- Resolves: rhbz#1725405
6<6P%_C8Jeff Moyer <jmoyer@redhat.com> - 65.2.el7]>- Remove 'daxctl migrate-device-model' command.  We won't
  support hot-plugging device dax into the memory hierarchy
  on RHEL 7.
- Resolves: rhbz#1734153$__8Jeff Moyer <jmoyer@redhat.com> - 65.1.el7]9- Rebase to v65
  - clear-errors: new command to clear errors on a namespace
  - monitor: remove the requirement of a default config
  - sanitize-dimm: allow a zero-key for secure-erase
  - sanitize-dimm: preserve keys after an overwrite
  - load-keys: fix for non-TPM keys
- Fix test harness to run against the rhel7 test kernel modules
- Related: rhbz#1722481	#[98Jeff Moyer <jmoyer@redhat.com> - 64.1-2\e- Fix initramfs creating by forcing installation of libnvdimm.ko
- Related: bz#1634348?"[%8Jeff Moyer <jmoyer@redhat.com> - 64.1-1\@- Rebase to v64.1 (Jeff Moyer)
  - add security commands
  - fix broken udev rule for dirty shutdown count
- Resolves: bz#1634348 bz#1635441
G5D)+W}9Jeff Moyer <jmoyer@redhat.com> - 62-1[~- Rebase to v62 (Jeff Moyer)
  - a new monitor command / daemon
  - an ndctl udev rule for recording the unsafe shutdown count
  - smart error injection
  - create-namespace fix for fragmented namespaces
- Resolves: bz#1610649 bz#1611833 bz#1456320h*[y9Jeff Moyer <jmoyer@redhat.com> - 60.3-4[^- Apply all patches (Jeff Moyer)
- Related: bz#1456320)_#8Jeff Moyer <jmoyer@redhat.com> - 65.6.el7_ܙ- add space to install_items in dracut config file
- Resolves: rhbz#1909233~(_8Jeff Moyer <jmoyer@redhat.com> - 65.5.el7]w@- Once again attempt to fix nvdimm-security.conf
- Resolves: rhbz#1750199'_98Jeff Moyer <jmoyer@redhat.com> - 65.4.el7]QT- Add spaces to the add_driver directive in the dracut module
- Resolves: rhbz#17403834&_8Jeff Moyer <jmoyer@redhat.com> - 65.3.el7]Ik- modify nvdimm-security.conf touse '&&' instead of ';'
  Without this change, the module doesn't load
- Resolves: rhbz#1725405

er+V:eDE
e1da241785b81fa88a78902772f84fe8352a55fdf1c3e24e75f1489f0ed6c85eDD
9384178dce07e0ac299086cce68e4bb80df8f3f7a7fbb3157138f9c5959fefa1DC
51baa210ba3ca7c7a874db3fb24682d5b524662f17895952c53f472c0c1d4c45DB
58bf74631393f9fcc43410a3e2bed3cad154da2aa6ea87017696651917d10727DA
aa775be36b0d57745dd1f04714358ec65cc663466eb081aaac7ad87e1fa83ddbD@
203db3d0d6a1ba449e52187f6910583ce0b23cd0c8ee52676a996d6659236bd9D?
9337c05672cf9bfec36d4f07ea3e1ff83103684578d98cb0b7c93d90c03620dcD>
940d3c647a6731e9ac3db41e0ac29dd98c5646b2f3d6559663e1ef5e309d5a77D=
27aff6d12be971449c18fbddaf62e746dbde00a72186da96eeb19d8af6a3783cD<
c355bbad46f478fe445b10f024dcf94c2baf4e0c856db5be8d2cb654bc37f559D;
8634b9087fce679a0f75d56b47ee7f5bab818bafc65af5c3bbf22d74b7807c3cD:
46bca967117d9441489461b3e6c17e9d3e387f3c3bfba523e30b819bb00825efD9
ff451f91104128c99b259625e000b9cbae52cee36db749f5b2e5291742d7ecc2
6<6P/_C9Jeff Moyer <jmoyer@redhat.com> - 65.2.el7]>- Remove 'daxctl migrate-device-model' command.  We won't
  support hot-plugging device dax into the memory hierarchy
  on RHEL 7.
- Resolves: rhbz#1734153.__9Jeff Moyer <jmoyer@redhat.com> - 65.1.el7]9- Rebase to v65
  - clear-errors: new command to clear errors on a namespace
  - monitor: remove the requirement of a default config
  - sanitize-dimm: allow a zero-key for secure-erase
  - sanitize-dimm: preserve keys after an overwrite
  - load-keys: fix for non-TPM keys
- Fix test harness to run against the rhel7 test kernel modules
- Related: rhbz#1722481	-[99Jeff Moyer <jmoyer@redhat.com> - 64.1-2\e- Fix initramfs creating by forcing installation of libnvdimm.ko
- Related: bz#1634348?,[%9Jeff Moyer <jmoyer@redhat.com> - 64.1-1\@- Rebase to v64.1 (Jeff Moyer)
  - add security commands
  - fix broken udev rule for dirty shutdown count
- Resolves: bz#1634348 bz#1635441
`G5:`d6eg:Josef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)n5e{:Josef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)r4e:Josef Ridky <jridky@redhat.com> - 1:5.7.2-41\@- secure magic variable to prevent daemon crash (#1635201)3_#9Jeff Moyer <jmoyer@redhat.com> - 65.6.el7_ܙ- add space to install_items in dracut config file
- Resolves: rhbz#1909233~2_9Jeff Moyer <jmoyer@redhat.com> - 65.5.el7]w@- Once again attempt to fix nvdimm-security.conf
- Resolves: rhbz#17501991_99Jeff Moyer <jmoyer@redhat.com> - 65.4.el7]QT- Add spaces to the add_driver directive in the dracut module
- Resolves: rhbz#174038340_9Jeff Moyer <jmoyer@redhat.com> - 65.3.el7]Ik- modify nvdimm-security.conf touse '&&' instead of ';'
  Without this change, the module doesn't load
- Resolves: rhbz#1725405
)y
)u;e:Josef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)d:eg:Josef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k9eu:Josef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)8e!:Josef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){7e:Josef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
*d?eg;Josef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)n>e{;Josef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)X=iK:Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)<e#:Josef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uDe;Josef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dCeg;Josef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kBeu;Josef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)Ae!;Josef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){@e;Josef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1dHeg<Josef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)gGii;Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XFiK;Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)Ee#;Josef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uMe<Josef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dLeg<Josef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kKeu<Josef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)Je!<Josef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){Ie<Josef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1kQiq<Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)gPii<Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XOiK<Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)Ne#<Josef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uVe=Josef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dUeg=Josef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kTeu=Josef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)Se!=Josef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){Re=Josef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
d1Ldn]e{>Josef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)r\e>Josef Ridky <jridky@redhat.com> - 1:5.7.2-41\@- secure magic variable to prevent daemon crash (#1635201)r[i=Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.4e5@- fix a crash triggered by a wrong passphrase (RHEL-2882)kZiq=Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)gYii=Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XXiK=Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)We#=Josef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
::dbeg>Josef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kaeu>Josef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)`e!>Josef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){_e>Josef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)d^eg>Josef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)
#;dheg?Josef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)nge{?Josef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)rfe?Josef Ridky <jridky@redhat.com> - 1:5.7.2-41\@- secure magic variable to prevent daemon crash (#1635201)XeiK>Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)de#>Josef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)uce>Josef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)
)y
)ume?Josef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dleg?Josef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kkeu?Josef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)je!?Josef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){ie?Josef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
*dqeg@Josef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)npe{@Josef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)XoiK?Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)ne#?Josef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uve@Josef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dueg@Josef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kteu@Josef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)se!@Josef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){re@Josef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
W1Wd{egAJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)nze{AJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)gyii@Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XxiK@Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)we#@Josef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)ueAJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)degAJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k~euAJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)}e!AJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){|eAJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1degBJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)giiAJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XiKAJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)e#AJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)u	eBJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)degBJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)keuBJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)e!BJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){eBJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
Z1ZdegCJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)k
iqBJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)giiBJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XiKBJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)
e#BJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)ueCJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)degCJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)keuCJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)e!CJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){eCJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1kiqCJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)giiCJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XiKCJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)e#CJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)ueDJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)degDJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)keuDJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)e!DJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){eDJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
L1Lr!iDJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.4e5@- fix a crash triggered by a wrong passphrase (RHEL-2882)k iqDJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)giiDJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XiKDJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)e#DJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)u&eEJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)d%egEJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k$euEJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)#e!EJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){"eEJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
d1Ldn-e{FJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)r,eFJosef Ridky <jridky@redhat.com> - 1:5.7.2-41\@- secure magic variable to prevent daemon crash (#1635201)r+iEJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.4e5@- fix a crash triggered by a wrong passphrase (RHEL-2882)k*iqEJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)g)iiEJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)X(iKEJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)'e#EJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)

er+V:eDR
b9e5d765d9cdb4e753cc90c405374ae4f1e90a89b8969164455783fc60720afdDQ
d85313c82ec7673519a211411e459e2105de52fc4111ca7c8f5993153e516415DP
f3cd33690b0532fcbb6ef97043d3026fa11e0d5e3583d070659675619ccd31b3DO
cb56c1afbb8da7034985bbc168d9be562e1692239a7ac99ac69557a2743af4cdDN
8bad4d40202c32d3b92c589f87621067f44ac2cd0793dc3c8ca85d82dc069603DM
729bff77f6c7fc23bab8a062cad450e4fec1ed72327936a033ec519b4a1f1a5dDL
003d6e4f36c75c96397d74a2057705deb39e076f3fc1a18799709b07c8140187DK
217a929503c5b9fc47654c4bd44a691380f40b921379b5acb0c12f913296b4ebDJ
002d4f7023944abaa5047112477822bce1cf921f395bbc76065f1bc6ecfa3c22DI
e6b656e21f27f47b357f21b2071ae59b0a85a6c23d1e221ddaa30e32116bf9e2DH
12a68692369968ab2848f9b52e492d4de687d092607a4bb029d6032c6b8512d8DG
b987f0cc8431b286cd14af878fe7d373d1fef790672495746f45a37477544b88DF
743f6a2f0afed6f677ea24028a9be02fb82801ed898d3523695bc6b923a302d3
::d2egFJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k1euFJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)0e!FJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){/eFJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)d.egFJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)
#;d8egGJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)n7e{GJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)r6eGJosef Ridky <jridky@redhat.com> - 1:5.7.2-41\@- secure magic variable to prevent daemon crash (#1635201)X5iKFJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)4e#FJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)u3eFJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)
)y
)u=eGJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)d<egGJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k;euGJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693):e!GJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){9eGJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
*dAegHJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)n@e{HJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)X?iKGJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)>e#GJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uFeHJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dEegHJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kDeuHJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)Ce!HJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){BeHJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
W1WdKegIJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)nJe{IJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)gIiiHJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XHiKHJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)Ge#HJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uPeIJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dOegIJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kNeuIJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)Me!IJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){LeIJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1dTegJJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)gSiiIJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XRiKIJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)Qe#IJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uYeJJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dXegJJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kWeuJJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)Ve!JJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){UeJJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
Z1Zd^egKJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)k]iqJJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)g\iiJJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)X[iKJJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)Ze#JJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uceKJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dbegKJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kaeuKJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)`e!KJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){_eKJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1kgiqKJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)gfiiKJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XeiKKJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)de#KJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uleLJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dkegLJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kjeuLJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)ie!LJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){heLJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
L1LrqiLJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.4e5@- fix a crash triggered by a wrong passphrase (RHEL-2882)kpiqLJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)goiiLJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XniKLJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)me#LJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uveMJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)duegMJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kteuMJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)se!MJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){reMJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
d1Ldn}e{NJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)r|eNJosef Ridky <jridky@redhat.com> - 1:5.7.2-41\@- secure magic variable to prevent daemon crash (#1635201)r{iMJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.4e5@- fix a crash triggered by a wrong passphrase (RHEL-2882)kziqMJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)gyiiMJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XxiKMJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)we#MJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
::degNJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)keuNJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)e!NJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){eNJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)d~egNJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)
I#IdegOJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)ne{OJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)XiKNJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)e#NJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)ueNJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)
)y
)ueOJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)degOJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k
euOJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)	e!OJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){eOJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1degPJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)giiOJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XiKOJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)
e#OJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uePJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)degPJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)keuPJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)e!PJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){ePJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1kiqPJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)giiPJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XiKPJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)e#PJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)ueQJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)degQJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)keuQJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)e!QJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){eQJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
d1Ldn%e{RJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)r$eRJosef Ridky <jridky@redhat.com> - 1:5.7.2-41\@- secure magic variable to prevent daemon crash (#1635201)r#iQJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.4e5@- fix a crash triggered by a wrong passphrase (RHEL-2882)k"iqQJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)g!iiQJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)X iKQJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)e#QJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
::d*egRJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k)euRJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)(e!RJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){'eRJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)d&egRJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)
#;d0egSJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)n/e{SJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)r.eSJosef Ridky <jridky@redhat.com> - 1:5.7.2-41\@- secure magic variable to prevent daemon crash (#1635201)X-iKRJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496),e#RJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)u+eRJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)

er+V:eD_
ea9c2c4f4cd124e0cdbfbb60888f7eea8cf1e397c7c5596b9b262f491182efdaD^
3ed462219356a67f4b4e61ac7fe20b5177652f7b0016197ed02c546f91020c7fD]
6e3ec45785f4e53b2ba5cb144820351bce901ac38bbe5bfece3b71293c84197aD\
141f11e739940e647d36915972ce6be77e89f7033f570f3ce6cad86a511b9f3fD[
ce1575869a76eeb5a281f8df3980870380850f3aff9297f84f741f893b7244fdDZ
5800fe1251af68096a15f87c737c6bb60eea189076391a14cee6c95f32fdb304DY
f9934db5cc1113b572f8e7b163ba8385a71464f8594e0a39efcdf885afab2e39DX
eaffff0c99bd293104ff77f035145a5872da50599d8f1b26609f145f305e2df4DW
648278bb5ec15af8835f0ac633c1ae82e1135e7a6bdc7ff8c3723b9319b41e7dDV
b6d30937baeaab87a757d348cb7d1c880d0d7835e383cdd00aa3006f7b1a6cecDU
92cbd8f4ae37e782c4571e81f3d13e76955fa6b037771d881242a1ec17cc5490DT
ab0dfa386979e8d8bdf410b61199e02f3996a0cafa084450435d18e99a7d33d2DS
bf6158e17a81b9067714e7011f8111f3764aec96494c531e4518423d302b355b
)y
)u5eSJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)d4egSJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k3euSJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)2e!SJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){1eSJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
*d9egTJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)n8e{TJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)X7iKSJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)6e#SJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)u>eTJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)d=egTJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k<euTJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693);e!TJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){:eTJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
W1WdCegUJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)nBe{UJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)gAiiTJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)X@iKTJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)?e#TJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uHeUJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dGegUJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kFeuUJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)Ee!UJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){DeUJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1dLegVJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)gKiiUJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XJiKUJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)Ie#UJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uQeVJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dPegVJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kOeuVJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)Ne!VJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){MeVJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
Z1ZdVegWJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)kUiqVJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)gTiiVJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XSiKVJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)Re#VJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)bR/RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{/X/Y	/Z/[/\/]/^!/_&/`-/b2/c8/d=/eA/fF/gK/hP/iT/jY/k^/lc/mg/nl/oq/pv/q}/r/s/t/u/v/w/x/y%/z*/{0/}5/~9/>/C/H/L/Q/V/[/_/d/i/n/u/z////
////"/'/,/0/5/9/>/E/J/O/T/X/]/a/f/m/r/w/|///	////%/./5/</B/G/L/T/[/b/i/p/w/~//

)y
)u[eWJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dZegWJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kYeuWJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)Xe!WJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){WeWJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1k_iqWJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)g^iiWJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)X]iKWJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)\e#WJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)udeXJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dcegXJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kbeuXJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)ae!XJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){`eXJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
L1LriiXJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.4e5@- fix a crash triggered by a wrong passphrase (RHEL-2882)khiqXJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)ggiiXJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XfiKXJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)ee#XJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uneYJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dmegYJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kleuYJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)ke!YJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){jeYJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
d1Ldnue{ZJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)rteZJosef Ridky <jridky@redhat.com> - 1:5.7.2-41\@- secure magic variable to prevent daemon crash (#1635201)rsiYJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.4e5@- fix a crash triggered by a wrong passphrase (RHEL-2882)kriqYJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)gqiiYJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XpiKYJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)oe#YJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
::dzegZJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kyeuZJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)xe!ZJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){weZJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)dvegZJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)
I#Ideg[Josef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)n~e{[Josef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)X}iKZJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)|e#ZJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)u{eZJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)
)y
)ue[Josef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)deg[Josef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)keu[Josef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)e![Josef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){e[Josef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1deg\Josef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)gii[Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XiK[Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)e#[Josef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)u
e\Josef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)deg\Josef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)keu\Josef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)
e!\Josef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){	e\Josef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1kiq\Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)gii\Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XiK\Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)e#\Josef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)ue]Josef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)deg]Josef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)keu]Josef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)e!]Josef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){e]Josef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
d1Ldne{^Josef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)re^Josef Ridky <jridky@redhat.com> - 1:5.7.2-41\@- secure magic variable to prevent daemon crash (#1635201)ri]Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.4e5@- fix a crash triggered by a wrong passphrase (RHEL-2882)kiq]Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)gii]Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XiK]Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)e#]Josef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
::d"eg^Josef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k!eu^Josef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693) e!^Josef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){e^Josef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)deg^Josef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)
I#Id'eg_Josef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)n&e{_Josef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)X%iK^Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)$e#^Josef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)u#e^Josef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)
)y
)u,e_Josef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)d+eg_Josef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k*eu_Josef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693))e!_Josef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){(e_Josef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1d0eg`Josef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)g/ii_Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)X.iK_Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)-e#_Josef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)

er+V:eDl
764049c60a710f88bfffed5ba17cd51ea7bb2822f89390f24d0db26a94bb9220Dk
a8f566d686a31517c6e1f0981aa8a7650ec4c8d5cea01c3500ae51e847966eeeDj
11d3ad095a9838e98b8360b005aa07fa292cf9a71c4265bdf7c5adda14d463b3Di
bb6c4bb2a43504110b58abd968a896a9cb28e447e17abd926b4366f43bb50835Dh
8737c27147724574d3a8eca1a97c42dbd392c654e638efa67e05c34316dbefa8Dg
9d052bd282880b22a3fdd0e733ea2b915e29942748f9ccc7ea825a12f74d2f1bDf
ecac7aae69f045e6bb94ecf2521d78d9f8f856a67352b6d877799477a31afa6bDe
da833fcbf72323a7a85e0da6ba8c9336419447f7d6dab0d5107ab974425ae951Dd
c2a79994207490930e3a02bf699b03b7c209983a3342dc5e7c7ba2451f5355c7Dc
fba2b7f38bb5d3e71e06753d36856e49f231e20be3c06505b414184bd656d595Db
bd8ba984e8b76d404b8422b2aeaf6d8ebee207f7fe92acda66e7ef0e2f94f312Da
eb2b61c0a574c0e3c540083c4f4f8009c0832616ae48554fa6f402b145b77bb0D`
47decaf77cfab5ae9ac6ca376aea7b186c9ab835d41abe31c6bcd91c3dee313f
)y
)u5e`Josef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)d4eg`Josef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k3eu`Josef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)2e!`Josef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){1e`Josef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1k9iq`Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)g8ii`Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)X7iK`Josef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)6e#`Josef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)u>eaJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)d=egaJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k<euaJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693);e!aJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){:eaJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
d1LdnEe{bJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)rDebJosef Ridky <jridky@redhat.com> - 1:5.7.2-41\@- secure magic variable to prevent daemon crash (#1635201)rCiaJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.4e5@- fix a crash triggered by a wrong passphrase (RHEL-2882)kBiqaJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)gAiiaJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)X@iKaJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)?e#aJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
::dJegbJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kIeubJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)He!bJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){GebJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)dFegbJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)
I#IdOegcJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)nNe{cJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)XMiKbJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)Le#bJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)uKebJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)
)y
)uTecJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)dSegcJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kReucJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)Qe!cJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){PecJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1dXegdJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)gWiicJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XViKcJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)Ue#cJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)u]edJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)d\egdJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)k[eudJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)Ze!dJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){YedJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1kaiqdJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)g`iidJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)X_iKdJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)^e#dJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)ufeeJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)deegeJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kdeueJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)ce!eJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){beeJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
d1Ldnme{fJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)rlefJosef Ridky <jridky@redhat.com> - 1:5.7.2-41\@- secure magic variable to prevent daemon crash (#1635201)rkieJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.4e5@- fix a crash triggered by a wrong passphrase (RHEL-2882)kjiqeJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)giiieJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XhiKeJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)ge#eJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
::dregfJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kqeufJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)pe!fJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){oefJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)dnegfJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)
I#IdweggJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)nve{gJosef Ridky <jridky@redhat.com> - 1:5.7.2-42\g- fix trapd crash when forward snmp v3 traps (#1680547)XuiKfJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)te#fJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)usefJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)
)y
)u|egJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)d{eggJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)kzeugJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)ye!gJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){xegJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1deghJosef Ridky <jridky@redhat.com> - 1:5.7.2-43\9- fix available memory calculation (#1250060)giigJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)X~iKgJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)}e#gJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)uehJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)deghJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)keuhJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)e!hJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){ehJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
1k	iqhJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)giihJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XiKhJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)e#hJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
)y
)ueiJosef Ridky <jridky@redhat.com> - 1:5.7.2-48^h- fix crash due of double-free of security context (#1809076)d
egiJosef Ridky <jridky@redhat.com> - 1:5.7.2-47]7@- revert calculation of free space (#1779609)keuiJosef Ridky <jridky@redhat.com> - 1:5.7.2-46]- fix sha224 and sha384 declaration check (#1774693)e!iJosef Ridky <jridky@redhat.com> - 1:5.7.2-45]- fix memory leak introduced by fix of snmp v3 traps forwarding (#1751195){
eiJosef Ridky <jridky@redhat.com> - 1:5.7.2-44]S- add support for glusterfs (#1316386)
- change services to start after network-online.target (#1388118)
- fix interface fadeout configuration (#1547355)
- fix scanf pattern for ICMP stats (#1693547)
- change buffer size in pass_common.c file (#1695363 and #1731357)
- remove initial whitespace reading from scanf pattern of /sys/dev/block/../stat file (#1700494)
- fix for CVE-2018-18066 (#1638911)
- add Counter64 support for UCD-SNMP-MIB (#1703752)
>1L>JY?jDaniel Mach <dmach@redhat.com> - 2.6-4Rk- Mass rebuild 2013-12-27joijNikos Mavrogiannopoulos <nmav@redhat.com> - 2.6-3R- Added patch nettle-tmpalloc.patch (#1033570)N]CjTomáš Mráz <tmraz@redhat.com> - 2.6-2QE- nettle includes use gmp.hriiJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.4e5@- fix a crash triggered by a wrong passphrase (RHEL-2882)kiqiJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.3d@- fix sendmsg error code for new kernel (#2229858)giiiJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.2b%- fix send response: Too long error (#2008696)XiKiJosef Ridky <jridky@redhat.com> - 1:5.7.2-49.1_@- fix CVE-2020-15862 (#1875496)e#iJosef Ridky <jridky@redhat.com> - 1:5.7.2-49^@- add missing part of memory leak patch (#1794168)
- fix if_inet6 messages floood (#1765449)
- revert bz#1486733 (#1771050)
- fix issue for process status when process name contains whitespace (#1782180)
L^Lw[jDaiki Ueno <dueno@redhat.com> - 2.7.1-9`m- Port fixes for potential miscalculation in ecdsa_verify (#1943156)EsjNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-8Wt@- Use a cache-silent version of mpz_powm to prevent cache-timing
  attacks against RSA and DSA in shared VMs. (#1364897,CVE-2016-6489)~sjNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-5V- Fixed SHA-3 implementation to conform to final standard (#1252936)
- Fixed CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 which caused issues
  in secp256r1 and secp384r1 calculations (#1314374)`sQjNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-4S׌- Correct path of links (#1117782)bsUjNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-3S;@- Added fipshmac checksum (#1117782)L]?jDaniel Mach <dmach@redhat.com> - 2.7.1-2RU- Mass rebuild 2014-01-24Na?jTomáš Mráz <tmraz@redhat.com> - 2.7.1-1Rx@- Updated to nettle 2.7.1
@P~%skNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-5V- Fixed SHA-3 implementation to conform to final standard (#1252936)
- Fixed CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 which caused issues
  in secp256r1 and secp384r1 calculations (#1314374)`$sQkNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-4S׌- Correct path of links (#1117782)b#sUkNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-3S;@- Added fipshmac checksum (#1117782)L"]?kDaniel Mach <dmach@redhat.com> - 2.7.1-2RU- Mass rebuild 2014-01-24N!a?kTomáš Mráz <tmraz@redhat.com> - 2.7.1-1Rx@- Updated to nettle 2.7.1J Y?kDaniel Mach <dmach@redhat.com> - 2.6-4Rk- Mass rebuild 2013-12-27joikNikos Mavrogiannopoulos <nmav@redhat.com> - 2.6-3R- Added patch nettle-tmpalloc.patch (#1033570)N]CkTomáš Mráz <tmraz@redhat.com> - 2.6-2QE- nettle includes use gmp.h
	A6i[A`.sQlNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-4S׌- Correct path of links (#1117782)b-sUlNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-3S;@- Added fipshmac checksum (#1117782)L,]?lDaniel Mach <dmach@redhat.com> - 2.7.1-2RU- Mass rebuild 2014-01-24N+a?lTomáš Mráz <tmraz@redhat.com> - 2.7.1-1Rx@- Updated to nettle 2.7.1J*Y?lDaniel Mach <dmach@redhat.com> - 2.6-4Rk- Mass rebuild 2013-12-27j)oilNikos Mavrogiannopoulos <nmav@redhat.com> - 2.6-3R- Added patch nettle-tmpalloc.patch (#1033570)N(]ClTomáš Mráz <tmraz@redhat.com> - 2.6-2QE- nettle includes use gmp.hw'[kDaiki Ueno <dueno@redhat.com> - 2.7.1-9`m- Port fixes for potential miscalculation in ecdsa_verify (#1943156)E&skNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-8Wt@- Use a cache-silent version of mpz_powm to prevent cache-timing
  attacks against RSA and DSA in shared VMs. (#1364897,CVE-2016-6489)
X3fXN5a?mTomáš Mráz <tmraz@redhat.com> - 2.7.1-1Rx@- Updated to nettle 2.7.1J4Y?mDaniel Mach <dmach@redhat.com> - 2.6-4Rk- Mass rebuild 2013-12-27j3oimNikos Mavrogiannopoulos <nmav@redhat.com> - 2.6-3R- Added patch nettle-tmpalloc.patch (#1033570)N2]CmTomáš Mráz <tmraz@redhat.com> - 2.6-2QE- nettle includes use gmp.hw1[lDaiki Ueno <dueno@redhat.com> - 2.7.1-9`m- Port fixes for potential miscalculation in ecdsa_verify (#1943156)E0slNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-8Wt@- Use a cache-silent version of mpz_powm to prevent cache-timing
  attacks against RSA and DSA in shared VMs. (#1364897,CVE-2016-6489)~/slNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-5V- Fixed SHA-3 implementation to conform to final standard (#1252936)
- Fixed CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 which caused issues
  in secp256r1 and secp384r1 calculations (#1314374)

er+V:eDy
c73295f51e8bcd58ab89943d676e27d4d7473a645904454667ae786d5b948bebDx
065c61acd07e5d7bf4396d3bb011f0b6440c73eae51c4902ebc118cfce7b8fd4Dw
7474f32c17d8003c3366608f1620d6945efdcff859c4f6900ae7da9ce3f9585bDv
b970000edfe83918a60d36a58443e70febbc8053c3ced7c67732f55f07d0a976Du
8d43d74f369183dc4073b21eb34b054828ea394433bb870f7b75b636e1135b24Dt
a1c734e7a148f0540c34ece6fc172664f88cf275abd4199a642731dc9f9bf5abDs
aa8fbebb1b09f5d4b003e51cc7e4003474c19e82d8bc3d986af0b378eb4ee9b5Dr
f725b54a5b7f5170fe4100a72816877759353b4ed7786387970c66d43de05d9dDq
27d1ba676d3d4007102e714f71f0f4e97d46890c6eed54e5f10720ff65e7cea8Dp
05fbad1e72d3fc82cab1e83391bf6c22c224dd3554ceed92227b792e08bf75b4Do
fd5d1ca9a11a3575a3c34f7dbcd30cc924d2b41a0a004c3a793506098be60bcaDn
4f58b903b21acdc1828cdfde9dd84d381db27ebca47cc84a8a8225dd657221ebDm
16a78c16f102931cd4ab634fc4177b99535edda6436721529c1f30e8ec464b9a
 J z<enSteve Dickson <steved@redhat.com> 1.3.0-0.60[z@- Updated: nfsd: Allow the caller to turn off NFSv4.0 (bz 1596138)w;[mDaiki Ueno <dueno@redhat.com> - 2.7.1-9`m- Port fixes for potential miscalculation in ecdsa_verify (#1943156)E:smNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-8Wt@- Use a cache-silent version of mpz_powm to prevent cache-timing
  attacks against RSA and DSA in shared VMs. (#1364897,CVE-2016-6489)~9smNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-5V- Fixed SHA-3 implementation to conform to final standard (#1252936)
- Fixed CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 which caused issues
  in secp256r1 and secp384r1 calculations (#1314374)`8sQmNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-4S׌- Correct path of links (#1117782)b7sUmNikos Mavrogiannopoulos <nmav@redhat.com> - 2.7.1-3S;@- Added fipshmac checksum (#1117782)L6]?mDaniel Mach <dmach@redhat.com> - 2.7.1-2RU- Mass rebuild 2014-01-24
4w64BenSteve Dickson <steved@redhat.com> 1.3.0-0.66]H@- nfs-utils_env.sh: Removed the hard coded number of nfsds (bz 1736801){AenSteve Dickson <steved@redhat.com> 1.3.0-0.65\A- Fixed typo of mountd-memleak.patch not being applied (bz 1711210)r@enSteve Dickson <steved@redhat.com> 1.3.0-0.64\@- rpc.mountd: Fix e_hostname and e_uuid leaks (bz 1711210)>?enSteve Dickson <steved@redhat.com> 1.3.0-0.63\- nfs.conf: Fixed manage-gids option typo (bz 1677403)
- sm-notify: Added -f flag to nfs.conf parsing (bz 1688932)
- Add nfs.conf equivalent for the statd --no-notify cmdline option (bz 1688918)
- nfs-server: Use reload not restart to start gssproxy (bz 1644169)>e#nSteve Dickson <steved@redhat.com> 1.3.0-0.62\ac- statd: fix use-after-free in monitor list if insertion fails (bz 1624542)=e%nSteve Dickson <steved@redhat.com> 1.3.0-0.61[t- nfs.conf: fail to disable major NFS version 4 using "vers4=n" (bz 1625032)
B$SBGe#oSteve Dickson <steved@redhat.com> 1.3.0-0.62\ac- statd: fix use-after-free in monitor list if insertion fails (bz 1624542)Fe%oSteve Dickson <steved@redhat.com> 1.3.0-0.61[t- nfs.conf: fail to disable major NFS version 4 using "vers4=n" (bz 1625032)hEiknSteve Dickson <steved@redhat.com> 1.3.0-0.68.1^y- exportfs: fix unexporting of '/' (bz 1958975)aDeanSteve Dickson <steved@redhat.com> 1.3.0-0.68^(@- gssd: closed resource leak. (bz 1167629)WCeKnSteve Dickson <steved@redhat.com> 1.3.0-0.67^- rpc.gssd: removed a number memory leaks (bz 1807110)
- mount: Report correct error in the fall_back cases (bz 1752329)
- gssd: daemonize earlier (bz 1645083)
iGEiWLeKoSteve Dickson <steved@redhat.com> 1.3.0-0.67^- rpc.gssd: removed a number memory leaks (bz 1807110)
- mount: Report correct error in the fall_back cases (bz 1752329)
- gssd: daemonize earlier (bz 1645083)KeoSteve Dickson <steved@redhat.com> 1.3.0-0.66]H@- nfs-utils_env.sh: Removed the hard coded number of nfsds (bz 1736801){JeoSteve Dickson <steved@redhat.com> 1.3.0-0.65\A- Fixed typo of mountd-memleak.patch not being applied (bz 1711210)rIeoSteve Dickson <steved@redhat.com> 1.3.0-0.64\@- rpc.mountd: Fix e_hostname and e_uuid leaks (bz 1711210)>HeoSteve Dickson <steved@redhat.com> 1.3.0-0.63\- nfs.conf: Fixed manage-gids option typo (bz 1677403)
- sm-notify: Added -f flag to nfs.conf parsing (bz 1688932)
- Add nfs.conf equivalent for the statd --no-notify cmdline option (bz 1688918)
- nfs-server: Use reload not restart to start gssproxy (bz 1644169)
T/i`ThTikpFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)SiOpCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)uRipFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)Qi/pFlorian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)cPiapFlorian Weimer <fweimer@redhat.com> - 2.17-313^0"@- Remove problematic Obsoletes: (#1795573)[OiQoSteve Dickson <steved@redhat.com> 1.3.0-0.68.2aj@- gssd: mutex updates (bz 1990981)hNikoSteve Dickson <steved@redhat.com> 1.3.0-0.68.1^y- exportfs: fix unexporting of '/' (bz 1958975)aMeaoSteve Dickson <steved@redhat.com> 1.3.0-0.68^(@- gssd: closed resource leak. (bz 1167629)
HQHu[iqFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)Zi/qFlorian Weimer <fweimer@redhat.com> - 2.17-314^1s- Disable libio vtable validation for interposed pre-2.1 stdio handles (#1775816)xYi	pCarlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/XiwpCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xWi	pCarlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)VipCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zUi
pCarlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)
E`vuExbi	qCarlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/aiwqCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)x`i	qCarlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)_iqCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)z^i
qCarlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)h]ikqFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)\iOqCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)
}xii	rCarlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)hirCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)zgi
rCarlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hfikrFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)eiOrCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)udirFlorian Weimer <fweimer@redhat.com> - 2.17-315^1s- argp: Do not override GCC keywords with macros (#1763325)fcs]qSiddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)
MLf7Mzpi
sCarlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hoiksFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)niOsCarlos O'Donell <carlos@redhat.com> - 2.17-316^2@- Adjust security hardening changes for 64-bit POWER BE due to
  toolchain limitations (#1793853)
ms#rSiddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fls]rSiddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xki	rCarlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/jiwrCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)
{Ke5wisFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
vs#sSiddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fus]sSiddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xti	sCarlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/siwsCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xri	sCarlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)qisCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)
4T[4i~WtDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)5}itFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
|s#tSiddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)f{s]tSiddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xzi	tCarlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/yiwtCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xxi	tCarlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)
-g-zi
uCarlos O'Donell <carlos@redhat.com> - 2.17-318_T- CVE-2019-25013: Fix EUC-KR conversion module defect (#1912543)hikuFlorian Weimer <fweimer@redhat.com> - 2.17-317^- Do not clobber errno in nss_compat (#1834816)rm{tFlorian Weimer <fweimer@redhat.com> - 2.17-326.3f3@- nscd: Fix timeout type in netgroup cache (RHEL-34263)Um?tFlorian Weimer <fweimer@redhat.com> - 2.17-326.2f0@- nscd: Do not use sendfile for the netgroup cache
- nscd: Use-after-free in netgroup cache
- CVE-2021-27645: nscd: double-free in netgroup cache
- CVE-2024-33599: nscd: buffer overflow in netgroup cache (RHEL-34263)
- CVE-2024-33600: nscd: null pointer dereferences in netgroup cache
- CVE-2024-33601: nscd: crash on out-of-memory condition
- CVE-2024-33602: nscd: memory corruption with NSS netgroup modulesm=tFlorian Weimer <fweimer@redhat.com> - 2.17-326.1fh@- CVE-2024-2961: Out of bounds write in iconv conversion to ISO-2022-CN-EXT (RHEL-31803)
{Ke5
iuFlorian Weimer <fweimer@redhat.com> - 2.17-325aG- Support /etc/sysconfig/strcasecmp-nonascii for enabling non-ASCII case
  conversion in strcasecmp, strncasecmp (#1993930)
	s#uSiddhesh Poyarekar <siddhesh@redhat.com> - 2.17-324`]- Move __isnanl_pseudo into its own file and link only into libc (#1927536)fs]uSiddhesh Poyarekar <siddhesh@redhat.com> - 2.17-323`3@- Fix isnanl check in printf. (#1925204)xi	uCarlos O'Donell <carlos@redhat.com> - 2.17-322_A- Enable file-based IFUNC selection on NVMe devices (#1883162)/iwuCarlos O'Donell <carlos@redhat.com> - 2.17-321_@- CVE-2020-10029: Prevent stack corruption from crafted input in cosl, sinl,
  sincosl, and tanl function. (#1812119)xi	uCarlos O'Donell <carlos@redhat.com> - 2.17-320_T- CVE-2020-29573: Harden printf family of functions (#1869380)iuCarlos O'Donell <carlos@redhat.com> - 2.17-319_T- Revert fix for #1772307 to improve Intel Xeon performance (#1889977)
	=y-=H]7vDaiki Ueno <dueno@redhat.com> - 4.21.0-1\+@- Rebase to NSPR 4.21H]7vDaiki Ueno <dueno@redhat.com> - 4.19.0-1Z1@- Rebase to NSPR 4.19TkAvDaiki Ueno <dueno@redhat.com> - 4.19.0-0.1.betaZ@- Rebase to NSPR 4.19 BETAH]7vDaiki Ueno <dueno@redhat.com> - 4.17.0-1Yp@- Rebase to NSPR 4.17H]7vDaiki Ueno <dueno@redhat.com> - 4.16.0-1Yn@- Rebase to NSPR 4.16La;vDaiki Ueno <dueno@redhat.com> - 4.13.1-1.0X@- Rebase to NSPR 4.13.1$
k_vElio Maldonado <emaldona@redhat.com> - 4.11.0-1V- Rebase to NSPR 4.11
- Resolves: Bug 1297941 - Rebase RHEL 7.3 to NSS 3.21 in preparation for Firefox 45Pk7vElio Maldonado <emaldona@redhat.com> - 4.10.8-2V - Resolves: Bug 1269363 - CVE-2015-7183
- nspr: heap-buffer overflow in PL_ARENA_ALLOCATE can lead to crash (under ASAN), potential memory corruptioniWuDJ Delorie <dj@redhat.com> - 2.17-326b4t@- resolv: Handle DNS transaction ID collisions (#2065058)
	T^DTH]7wDaiki Ueno <dueno@redhat.com> - 4.19.0-1Z1@- Rebase to NSPR 4.19TkAwDaiki Ueno <dueno@redhat.com> - 4.19.0-0.1.betaZ@- Rebase to NSPR 4.19 BETAH]7wDaiki Ueno <dueno@redhat.com> - 4.17.0-1Yp@- Rebase to NSPR 4.17H]7wDaiki Ueno <dueno@redhat.com> - 4.16.0-1Yn@- Rebase to NSPR 4.16La;wDaiki Ueno <dueno@redhat.com> - 4.13.1-1.0X@- Rebase to NSPR 4.13.1$k_wElio Maldonado <emaldona@redhat.com> - 4.11.0-1V- Rebase to NSPR 4.11
- Resolves: Bug 1297941 - Rebase RHEL 7.3 to NSS 3.21 in preparation for Firefox 45Pk7wElio Maldonado <emaldona@redhat.com> - 4.10.8-2V - Resolves: Bug 1269363 - CVE-2015-7183
- nspr: heap-buffer overflow in PL_ARENA_ALLOCATE can lead to crash (under ASAN), potential memory corruptionR]KvDaiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagH]7vDaiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25
Lhz">LJ(a7xBob Relyea <rrelyea@redhat.com> - 4.31.0-1`9@- Rebase to NSPR 4.31J'a7xBob Relyea <rrelyea@redhat.com> - 4.30.0-1`@- Rebase to NSPR 4.30R&]KxDaiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagH%]7xDaiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25H$]7xDaiki Ueno <dueno@redhat.com> - 4.21.0-1\+@- Rebase to NSPR 4.21H#]7xDaiki Ueno <dueno@redhat.com> - 4.19.0-1Z1@- Rebase to NSPR 4.19T"kAxDaiki Ueno <dueno@redhat.com> - 4.19.0-0.1.betaZ@- Rebase to NSPR 4.19 BETAH!]7xDaiki Ueno <dueno@redhat.com> - 4.17.0-1Yp@- Rebase to NSPR 4.17H ]7xDaiki Ueno <dueno@redhat.com> - 4.16.0-1Yn@- Rebase to NSPR 4.16R]KwDaiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagH]7wDaiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25H]7wDaiki Ueno <dueno@redhat.com> - 4.21.0-1\+@- Rebase to NSPR 4.21
4Wgy+4H4]7zDaiki Ueno <dueno@redhat.com> - 4.21.0-1\+@- Rebase to NSPR 4.21Y3aUyBob Relyea <rrelyea@redhat.com> - 4.32.0-1a#- Rebase to NSPR 4.32 for firefox 91J2a7yBob Relyea <rrelyea@redhat.com> - 4.31.0-1`9@- Rebase to NSPR 4.31J1a7yBob Relyea <rrelyea@redhat.com> - 4.30.0-1`@- Rebase to NSPR 4.30R0]KyDaiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagH/]7yDaiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25H.]7yDaiki Ueno <dueno@redhat.com> - 4.21.0-1\+@- Rebase to NSPR 4.21H-]7yDaiki Ueno <dueno@redhat.com> - 4.19.0-1Z1@- Rebase to NSPR 4.19T,kAyDaiki Ueno <dueno@redhat.com> - 4.19.0-0.1.betaZ@- Rebase to NSPR 4.19 BETAH+]7yDaiki Ueno <dueno@redhat.com> - 4.17.0-1Yp@- Rebase to NSPR 4.17H*]7yDaiki Ueno <dueno@redhat.com> - 4.16.0-1Yn@- Rebase to NSPR 4.16Y)aUxBob Relyea <rrelyea@redhat.com> - 4.32.0-1a#- Rebase to NSPR 4.32 for firefox 91

er+V:eD
5789e9eefcb8257802229f6c4a0c33ffeebca3524e72f87f7094d6126e171b3fD
09c89c08debacc489fe15a2e0025630de1bd775a0f8b0e4ef911abb61cc7f0d1D
c0b12c0fdbe123567a7fdef5ac2588a2251ae9765f4962c97c73d4a897684662D
15a8be046768a2968cfabc11099c94d9e4758a47f1ad0a4684b5381191fef135D
32f2360a1cd39e18ee281e0776cfb076b98630d9d2f537026ade2e9f9781d773D
e5da7feab326c7d54715dd536bcd5dfd2fb186f7fb2c524d033599095a696f93D
d21ecbddef5ee619c1909b27a81f4793db8cbaca93baa944afe265fce0c076c8D
990637f443055506d031e7c48d1973aa08e372a46ffffec43207a9c00ff8e8c4D~
9869383533db8674f9c9ae37eddb0b159acdfe01aa0d5ad7dfc0fbd06b550883D}
2d2d708e0066e80880184f19ceae8aceb4c6fdafaa3674831f96b0d35d4f1fd9D|
587553122ef589c1cf5063202b40fd092f24f3f9b50a3d38f3deb36d00ed7d2cD{
f2365b1ca47b98315778026ca1ce13fb99b6db32a6919f3686b8ecf3a457b96eDz
3034b99da622294d9d3140fc599314e5bd6267cc30dcbb8d88f15027d96d7fe0
G^e:GH?]7{Daiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25H>]7{Daiki Ueno <dueno@redhat.com> - 4.21.0-1\+@- Rebase to NSPR 4.21W=eMzBob Relyea <rrelyea@redhat.com> - 4.34.0-3.1bc@- Actually apply the patch in -3|<azBob Relyea <rrelyea@redhat.com> - 4.34.0-3b@- return the AI_PASSIVE result so servers can connect to all
  clientsI;a5zBob Relyea <rrelyea@redhat.com> - 4.34.0-2b@- Fix coverity issueZ:aWzBob Relyea <rrelyea@redhat.com> - 4.34.0-1b@- Rebase to NSPR 4.34 for firefox 102Y9aUzBob Relyea <rrelyea@redhat.com> - 4.32.0-1a#- Rebase to NSPR 4.32 for firefox 91J8a7zBob Relyea <rrelyea@redhat.com> - 4.31.0-1`9@- Rebase to NSPR 4.31J7a7zBob Relyea <rrelyea@redhat.com> - 4.30.0-1`@- Rebase to NSPR 4.30R6]KzDaiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagH5]7zDaiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25
;\S+;JJa7|Bob Relyea <rrelyea@redhat.com> - 4.30.0-1`@- Rebase to NSPR 4.30RI]K|Daiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagHH]7|Daiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25WGeM{Bob Relyea <rrelyea@redhat.com> - 4.34.0-3.1bc@- Actually apply the patch in -3|Fa{Bob Relyea <rrelyea@redhat.com> - 4.34.0-3b@- return the AI_PASSIVE result so servers can connect to all
  clientsIEa5{Bob Relyea <rrelyea@redhat.com> - 4.34.0-2b@- Fix coverity issueZDaW{Bob Relyea <rrelyea@redhat.com> - 4.34.0-1b@- Rebase to NSPR 4.34 for firefox 102YCaU{Bob Relyea <rrelyea@redhat.com> - 4.32.0-1a#- Rebase to NSPR 4.32 for firefox 91JBa7{Bob Relyea <rrelyea@redhat.com> - 4.31.0-1`9@- Rebase to NSPR 4.31JAa7{Bob Relyea <rrelyea@redhat.com> - 4.30.0-1`@- Rebase to NSPR 4.30R@]K{Daiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tag

EU*5EJTa7}Bob Relyea <rrelyea@redhat.com> - 4.30.0-1`@- Rebase to NSPR 4.30RS]K}Daiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagHR]7}Daiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25Q	!|Frantisek Krenzelok <krenzelok.frantisek@gmail.com> - 4.35.0-1d - Rebase to NSPR 4.35 for firefox 115
- Move from deprecate %patchN formatWPeM|Bob Relyea <rrelyea@redhat.com> - 4.34.0-3.1bc@- Actually apply the patch in -3|Oa|Bob Relyea <rrelyea@redhat.com> - 4.34.0-3b@- return the AI_PASSIVE result so servers can connect to all
  clientsINa5|Bob Relyea <rrelyea@redhat.com> - 4.34.0-2b@- Fix coverity issueZMaW|Bob Relyea <rrelyea@redhat.com> - 4.34.0-1b@- Rebase to NSPR 4.34 for firefox 102YLaU|Bob Relyea <rrelyea@redhat.com> - 4.32.0-1a#- Rebase to NSPR 4.32 for firefox 91JKa7|Bob Relyea <rrelyea@redhat.com> - 4.31.0-1`9@- Rebase to NSPR 4.31
`U*5`P\k7~Elio Maldonado <emaldona@redhat.com> - 4.10.8-2V - Resolves: Bug 1269363 - CVE-2015-7183
- nspr: heap-buffer overflow in PL_ARENA_ALLOCATE can lead to crash (under ASAN), potential memory corruption[	!}Frantisek Krenzelok <krenzelok.frantisek@gmail.com> - 4.35.0-1d - Rebase to NSPR 4.35 for firefox 115
- Move from deprecate %patchN formatWZeM}Bob Relyea <rrelyea@redhat.com> - 4.34.0-3.1bc@- Actually apply the patch in -3|Ya}Bob Relyea <rrelyea@redhat.com> - 4.34.0-3b@- return the AI_PASSIVE result so servers can connect to all
  clientsIXa5}Bob Relyea <rrelyea@redhat.com> - 4.34.0-2b@- Fix coverity issueZWaW}Bob Relyea <rrelyea@redhat.com> - 4.34.0-1b@- Rebase to NSPR 4.34 for firefox 102YVaU}Bob Relyea <rrelyea@redhat.com> - 4.32.0-1a#- Rebase to NSPR 4.32 for firefox 91JUa7}Bob Relyea <rrelyea@redhat.com> - 4.31.0-1`9@- Rebase to NSPR 4.31
	Wo3Re]K~Daiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagHd]7~Daiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25Hc]7~Daiki Ueno <dueno@redhat.com> - 4.21.0-1\+@- Rebase to NSPR 4.21Hb]7~Daiki Ueno <dueno@redhat.com> - 4.19.0-1Z1@- Rebase to NSPR 4.19TakA~Daiki Ueno <dueno@redhat.com> - 4.19.0-0.1.betaZ@- Rebase to NSPR 4.19 BETAH`]7~Daiki Ueno <dueno@redhat.com> - 4.17.0-1Yp@- Rebase to NSPR 4.17H_]7~Daiki Ueno <dueno@redhat.com> - 4.16.0-1Yn@- Rebase to NSPR 4.16L^a;~Daiki Ueno <dueno@redhat.com> - 4.13.1-1.0X@- Rebase to NSPR 4.13.1$]k_~Elio Maldonado <emaldona@redhat.com> - 4.11.0-1V- Rebase to NSPR 4.11
- Resolves: Bug 1297941 - Rebase RHEL 7.3 to NSS 3.21 in preparation for Firefox 45
	^+2B^Hn]7Daiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25Hm]7Daiki Ueno <dueno@redhat.com> - 4.21.0-1\+@- Rebase to NSPR 4.21Hl]7Daiki Ueno <dueno@redhat.com> - 4.19.0-1Z1@- Rebase to NSPR 4.19TkkADaiki Ueno <dueno@redhat.com> - 4.19.0-0.1.betaZ@- Rebase to NSPR 4.19 BETAHj]7Daiki Ueno <dueno@redhat.com> - 4.17.0-1Yp@- Rebase to NSPR 4.17Hi]7Daiki Ueno <dueno@redhat.com> - 4.16.0-1Yn@- Rebase to NSPR 4.16Lha;Daiki Ueno <dueno@redhat.com> - 4.13.1-1.0X@- Rebase to NSPR 4.13.1$gk_Elio Maldonado <emaldona@redhat.com> - 4.11.0-1V- Rebase to NSPR 4.11
- Resolves: Bug 1297941 - Rebase RHEL 7.3 to NSS 3.21 in preparation for Firefox 45Pfk7Elio Maldonado <emaldona@redhat.com> - 4.10.8-2V - Resolves: Bug 1269363 - CVE-2015-7183
- nspr: heap-buffer overflow in PL_ARENA_ALLOCATE can lead to crash (under ASAN), potential memory corruption
;^n"2;Hz]7Daiki Ueno <dueno@redhat.com> - 4.16.0-1Yn@- Rebase to NSPR 4.16YyaUBob Relyea <rrelyea@redhat.com> - 4.32.0-1a#- Rebase to NSPR 4.32 for firefox 91Jxa7Bob Relyea <rrelyea@redhat.com> - 4.31.0-1`9@- Rebase to NSPR 4.31Jwa7Bob Relyea <rrelyea@redhat.com> - 4.30.0-1`@- Rebase to NSPR 4.30Rv]KDaiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagHu]7Daiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25Ht]7Daiki Ueno <dueno@redhat.com> - 4.21.0-1\+@- Rebase to NSPR 4.21Hs]7Daiki Ueno <dueno@redhat.com> - 4.19.0-1Z1@- Rebase to NSPR 4.19TrkADaiki Ueno <dueno@redhat.com> - 4.19.0-0.1.betaZ@- Rebase to NSPR 4.19 BETAHq]7Daiki Ueno <dueno@redhat.com> - 4.17.0-1Yp@- Rebase to NSPR 4.17Hp]7Daiki Ueno <dueno@redhat.com> - 4.16.0-1Yn@- Rebase to NSPR 4.16Ro]KDaiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tag
;\x");R]KDaiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagH]7Daiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25H]7Daiki Ueno <dueno@redhat.com> - 4.21.0-1\+@- Rebase to NSPR 4.21YaUBob Relyea <rrelyea@redhat.com> - 4.32.0-1a#- Rebase to NSPR 4.32 for firefox 91Ja7Bob Relyea <rrelyea@redhat.com> - 4.31.0-1`9@- Rebase to NSPR 4.31Ja7Bob Relyea <rrelyea@redhat.com> - 4.30.0-1`@- Rebase to NSPR 4.30R]KDaiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagH]7Daiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25H~]7Daiki Ueno <dueno@redhat.com> - 4.21.0-1\+@- Rebase to NSPR 4.21H}]7Daiki Ueno <dueno@redhat.com> - 4.19.0-1Z1@- Rebase to NSPR 4.19T|kADaiki Ueno <dueno@redhat.com> - 4.19.0-0.1.betaZ@- Rebase to NSPR 4.19 BETAH{]7Daiki Ueno <dueno@redhat.com> - 4.17.0-1Yp@- Rebase to NSPR 4.17
Ed\5EJa7Bob Relyea <rrelyea@redhat.com> - 4.30.0-1`@- Rebase to NSPR 4.30R]KDaiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagH]7Daiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25H]7Daiki Ueno <dueno@redhat.com> - 4.21.0-1\+@- Rebase to NSPR 4.21W
eMBob Relyea <rrelyea@redhat.com> - 4.34.0-3.1bc@- Actually apply the patch in -3|aBob Relyea <rrelyea@redhat.com> - 4.34.0-3b@- return the AI_PASSIVE result so servers can connect to all
  clientsIa5Bob Relyea <rrelyea@redhat.com> - 4.34.0-2b@- Fix coverity issueZ
aWBob Relyea <rrelyea@redhat.com> - 4.34.0-1b@- Rebase to NSPR 4.34 for firefox 102Y	aUBob Relyea <rrelyea@redhat.com> - 4.32.0-1a#- Rebase to NSPR 4.32 for firefox 91Ja7Bob Relyea <rrelyea@redhat.com> - 4.31.0-1`9@- Rebase to NSPR 4.31Ja7Bob Relyea <rrelyea@redhat.com> - 4.30.0-1`@- Rebase to NSPR 4.30
4U*-4YaUBob Relyea <rrelyea@redhat.com> - 4.32.0-1a#- Rebase to NSPR 4.32 for firefox 91Ja7Bob Relyea <rrelyea@redhat.com> - 4.31.0-1`9@- Rebase to NSPR 4.31Ja7Bob Relyea <rrelyea@redhat.com> - 4.30.0-1`@- Rebase to NSPR 4.30R]KDaiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagH]7Daiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25WeMBob Relyea <rrelyea@redhat.com> - 4.34.0-3.1bc@- Actually apply the patch in -3|aBob Relyea <rrelyea@redhat.com> - 4.34.0-3b@- return the AI_PASSIVE result so servers can connect to all
  clientsIa5Bob Relyea <rrelyea@redhat.com> - 4.34.0-2b@- Fix coverity issueZaWBob Relyea <rrelyea@redhat.com> - 4.34.0-1b@- Rebase to NSPR 4.34 for firefox 102YaUBob Relyea <rrelyea@redhat.com> - 4.32.0-1a#- Rebase to NSPR 4.32 for firefox 91Ja7Bob Relyea <rrelyea@redhat.com> - 4.31.0-1`9@- Rebase to NSPR 4.31

EUz>EY&aUBob Relyea <rrelyea@redhat.com> - 4.32.0-1a#- Rebase to NSPR 4.32 for firefox 91J%a7Bob Relyea <rrelyea@redhat.com> - 4.31.0-1`9@- Rebase to NSPR 4.31J$a7Bob Relyea <rrelyea@redhat.com> - 4.30.0-1`@- Rebase to NSPR 4.30R#]KDaiki Ueno <dueno@redhat.com> - 4.25.0-2_@- Rebuild to fix wrong dist tagH"]7Daiki Ueno <dueno@redhat.com> - 4.25.0-1^- Rebase to NSPR 4.25!	!Frantisek Krenzelok <krenzelok.frantisek@gmail.com> - 4.35.0-1d - Rebase to NSPR 4.35 for firefox 115
- Move from deprecate %patchN formatW eMBob Relyea <rrelyea@redhat.com> - 4.34.0-3.1bc@- Actually apply the patch in -3|aBob Relyea <rrelyea@redhat.com> - 4.34.0-3b@- return the AI_PASSIVE result so servers can connect to all
  clientsIa5Bob Relyea <rrelyea@redhat.com> - 4.34.0-2b@- Fix coverity issueZaWBob Relyea <rrelyea@redhat.com> - 4.34.0-1b@- Rebase to NSPR 4.34 for firefox 102
UzI8-aBob Relyea <rrelyea@redhat.com> - 3.44.0-5]S- Fix pkix name constraints processing to only process the common name if the
  certusage you are checking is IPSEC or SSL Server.,aEBob Relyea <rrelyea@redhat.com> - 3.44.0-4\- Fix certutil man page
- Fix extracting a public key from a private key for dh, ec, and dsa+	!Frantisek Krenzelok <krenzelok.frantisek@gmail.com> - 4.35.0-1d - Rebase to NSPR 4.35 for firefox 115
- Move from deprecate %patchN formatW*eMBob Relyea <rrelyea@redhat.com> - 4.34.0-3.1bc@- Actually apply the patch in -3|)aBob Relyea <rrelyea@redhat.com> - 4.34.0-3b@- return the AI_PASSIVE result so servers can connect to all
  clientsI(a5Bob Relyea <rrelyea@redhat.com> - 4.34.0-2b@- Fix coverity issueZ'aWBob Relyea <rrelyea@redhat.com> - 4.34.0-1b@- Rebase to NSPR 4.34 for firefox 102
803]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesO2]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by defaultI1]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.10aWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'/aoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)x.aBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)
Px8aBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)87aBob Relyea <rrelyea@redhat.com> - 3.44.0-5]S- Fix pkix name constraints processing to only process the common name if the
  certusage you are checking is IPSEC or SSL Server.6aEBob Relyea <rrelyea@redhat.com> - 3.44.0-4\- Fix certutil man page
- Fix extracting a public key from a private key for dh, ec, and dsa25eJohnny Hughes <johnny@centos.org> - 3.53.1-3_@- much thanks to both Tuomo Soini (foobar.fi) and Pat Riehecky (scientificlinux.org)
  for finding the fix to these issuest4YTuomo Soini <tis@foobar.fi> - 3.53.1-3_w@- Fix tests by updating PayPalEE.cert to valid one
- Fix tests to expect small primes failing rhbz#1884793
- Fix Cannot compile code with nss headers and -Werror=strict-prototypes
  rhbz#1885321

er+V:eD
4ea1017b5a921ab782e09ead7f9368a70cc11716ebe116ff1cbc4c7bc8cddf99D
3645870dc323bf6f63b5757d520178a52a8a714d71e280c47014f095f2c2fe69D
2077a5a2df3692687ac9b3f892005ec2eabe97368eec05197fbf1f961f013442D
b53a6924f3594abaaeaa39917b0114b7f6f7dcf8df0ffe03ab3a8957ae3405c4D
aaa6f5e10bb4f066d056589fbd2c2409c9e33e21cf5e6a20cf1c81c4de17ff57D
c9abea6a673cf74708122a7d0f1620be7008d59c4f0a60af39850105cb52adadD

4631ab28c6b9c4fb1461b0f98b9c1de4c06d08fc1e07b0e42d44f966c8d31507D
62dcb9c05fcad8a7e7f0588dcf5a7500f9fb5e4b2cf0250f64430bd3a95b42f8D
bc3fa21f1527e3d417bd20356fdc535325869f41a856887ba3fa0883c308713eD

502759520df3c6fcc6838d5f2158c4dab3f4aada9ff9455473132a5be1808ca0D	
1eb686e8a290603d5223ec70ee6fb522d7289f9e573548836dfd8858a99a978bD
1b137d71d271e1a3ea8da17a90f65d981a49674c7781a7491eb07f02fd41cee6D
da19e809bc2749d2727d0bb85172cda681f9f2751137a52646ab7ebe32ebdf66
fTg_ft>YTuomo Soini <tis@foobar.fi> - 3.53.1-3_w@- Fix tests by updating PayPalEE.cert to valid one
- Fix tests to expect small primes failing rhbz#1884793
- Fix Cannot compile code with nss headers and -Werror=strict-prototypes
  rhbz#18853210=]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesO<]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by defaultI;]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1:aWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'9aoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)
,I!4,0E]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesOD]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by defaultIC]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1BaWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'AaoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)x@aBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)2?eJohnny Hughes <johnny@centos.org> - 3.53.1-3_@- much thanks to both Tuomo Soini (foobar.fi) and Pat Riehecky (scientificlinux.org)
  for finding the fix to these issues
Bg
BLaWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'KaoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)xJaBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)Ia)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protolHa{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`GacBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.FaIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.
`>Sa)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protolRa{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`QacBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.PaIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.0O]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesON]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by defaultIM]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1
iKNUiI[a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67NZa?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIYa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66Xa)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protolWa{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`VacBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.UaIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.0T]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cycles
"t"ba)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protolaa{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.``acBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack._aIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.0^]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cycles"]aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a=- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.\a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processing
taHtlja{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`iacBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.haIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn."gaeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a=- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.fa/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIea5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Nda?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIca5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66
rw*XrraIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.Iqa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"paeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.oa/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIna5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Nma?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIla5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66ka)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-proto
	7,V+7I{a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"zaeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.ya/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIxa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Nwa?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIva5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66ua)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protolta{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`sacBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.
	ca2cma}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZaWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingI~a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67N}a?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsI|a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66
	^3?Z
aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"
aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.	a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Na?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66QaEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.
	[:haWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Na?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsQaEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.ma}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression below
	m:Om^a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Na?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsHa3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767QaEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.ma}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression below
	P1]PZ(aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^'a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDI&a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"%aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.$a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingH#a3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767Q"aEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.m!a}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZ aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite
	3:3^1a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDI0a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"/aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work..a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processing-a/Bob Relyea <rrelyea@redhat.com> - 3.90.0-2d- fix EMS bug
- disbale ECH
- fix gtests in spec file
- restore missing test caseI,a5Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d@- Rebase to NSS 3.90H+a3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767Q*aEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.m)a}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression below
c1C c89aBob Relyea <rrelyea@redhat.com> - 3.44.0-5]S- Fix pkix name constraints processing to only process the common name if the
  certusage you are checking is IPSEC or SSL Server.8aEBob Relyea <rrelyea@redhat.com> - 3.44.0-4\- Fix certutil man page
- Fix extracting a public key from a private key for dh, ec, and dsa7a/Bob Relyea <rrelyea@redhat.com> - 3.90.0-2d- fix EMS bug
- disbale ECH
- fix gtests in spec file
- restore missing test caseI6a5Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d@- Rebase to NSS 3.90H5a3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767Q4aEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.m3a}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZ2aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite

er+V:eD 
02f9db11a20bee6dfde81279441c6b86bc5047ad9fc1b6243b5b1ed6d3a1608aD
78923c044dee6993ff55684229e266296bd04b772f4c47761a0e197bf8ddada6D
4b35cc37198ac1275db864e9be35ef4048337b891115e699165a85a519fdd7a2D
5ca34c751582faa8c936ab6598cc2492a6b1853a7b3f019060e590b86e7b9ee3D
abf2f157e578b874738281a5fe3e278b9d6fe5f4a908e78a8a0786e24009222dD
c8da0723eb57ace188d0bd03e37e8827a42913c10542cfa8bd6bd8817a724916D
d1faf007d61466191ae5ad07935839a8673f5e51b6c24bd3465e5503da56f20bD
956c25bea6f5a263d7233838769732e4650583ff222b531bdab7067f4a6a0b6fD
d4c9bba0cf86d681a086b4238c954468eb5e278505324118d68938f5918c7a89D
36cbb6317ac31a74661962dff6944ef7630e01a16c0c3426f1e58b4a6dbd259eD
3171334483be56275cf95caaad81576b0625965bf82c2a8cb91be41784e991d1D
534afd073131ca7dea6b8cf23565728f280489bcc5783d53e1fc4f3e92bef942D
ef051c1a4e1bb137134383ae56882cf3cd061c02e00abb7c467c618029133545
80?]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesO>]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by defaultI=]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1<aWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.';aoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)x:aBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)
PxDaBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)8CaBob Relyea <rrelyea@redhat.com> - 3.44.0-5]S- Fix pkix name constraints processing to only process the common name if the
  certusage you are checking is IPSEC or SSL Server.BaEBob Relyea <rrelyea@redhat.com> - 3.44.0-4\- Fix certutil man page
- Fix extracting a public key from a private key for dh, ec, and dsa2AeJohnny Hughes <johnny@centos.org> - 3.53.1-3_@- much thanks to both Tuomo Soini (foobar.fi) and Pat Riehecky (scientificlinux.org)
  for finding the fix to these issuest@YTuomo Soini <tis@foobar.fi> - 3.53.1-3_w@- Fix tests by updating PayPalEE.cert to valid one
- Fix tests to expect small primes failing rhbz#1884793
- Fix Cannot compile code with nss headers and -Werror=strict-prototypes
  rhbz#1885321
fTg_ftJYTuomo Soini <tis@foobar.fi> - 3.53.1-3_w@- Fix tests by updating PayPalEE.cert to valid one
- Fix tests to expect small primes failing rhbz#1884793
- Fix Cannot compile code with nss headers and -Werror=strict-prototypes
  rhbz#18853210I]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesOH]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by defaultIG]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1FaWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'EaoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)
,I!4,0Q]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesOP]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by defaultIO]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1NaWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'MaoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)xLaBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)2KeJohnny Hughes <johnny@centos.org> - 3.53.1-3_@- much thanks to both Tuomo Soini (foobar.fi) and Pat Riehecky (scientificlinux.org)
  for finding the fix to these issues
Bg
BXaWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'WaoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)xVaBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)Ua)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protolTa{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`SacBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.RaIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.
`>_a)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protol^a{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`]acBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.\aIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.0[]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesOZ]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by defaultIY]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1
iKNUiIga5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Nfa?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIea5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66da)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protolca{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`bacBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.aaIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.0`]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cycles
"t"na)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protolma{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`lacBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.kaIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.0j]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cycles"iaeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a=- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.ha/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processing
taHtlva{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`uacBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.taIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn."saeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a=- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.ra/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIqa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Npa?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIoa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66
rw*Xr~aIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.I}a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"|aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.{a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIza5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Nya?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIxa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66wa)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protobR0)RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{//(/‚4/Ă?/łJ/ƂT/ǂ\/Ȃe/ɂn/ʂz/˂/̂/͂/΂&/ς-/Ђ3/т8/ӂ>/ԂE/ՂL/ւS/ׂ[/؂b/قj/ڂr/ۂ{/܂/݂
/ނ/߂/(/Ⴔ1/₴9/䂴?/傴D/悴J/炴Q/肴X/邴_/ꂴg/내n/살v/킴~////"/+/4/=/F/N/V/\/b/i/o/v/}00000%0.070@0	I0
R0[0e0
l0s0y0000000%0,040;0C0I0O0V0\0 a0!g0"n0#u0$|0%0&0'0(
	7,V+7Ia5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Na?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66a)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protola{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`acBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.
	ca2cma}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZaWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDI
a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingI
a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67N	a?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66
	^3?ZaWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Na?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66QaEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.
	[:h"aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^!a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDI a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Na?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsQaEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.ma}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression below
	m:Om^+a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDI*a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527")aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.(a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingI'a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67N&a?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsH%a3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767Q$aEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.m#a}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression below
	P1]PZ4aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^3a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDI2a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"1aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.0a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingH/a3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767Q.aEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.m-a}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZ,aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite
	3:3^=a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDI<a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527";aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.:a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processing9a/Bob Relyea <rrelyea@redhat.com> - 3.90.0-2d- fix EMS bug
- disbale ECH
- fix gtests in spec file
- restore missing test caseI8a5Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d@- Rebase to NSS 3.90H7a3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767Q6aEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.m5a}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression below

er+V:eD-
74b63c28e824b50dfd7c42b254636029cedf22dfe885fc3017c73533680e434eD,
0328daa881db258b5d0dcafa3d0c1f8bb4e2dd5034a74b2938d69c73b0a7dcbdD+
feb6b437532dab8f5310701ed22fb3134f9e87f87fd7786802bcadba0cdeb3d6D*
821ad7280fd9322e235862f73d1cb6c433fe48e14911cbc39141b2df2732bc01D)
034c9033d1e0262176555d3b7dc0f189885361d53ccb042ac04e98012e34b040D(
fee0270ebb6d96079cd62a8292ee140622ec167fe229396b49b1691c2d2d6e74D'
64a40a4e60c03c1f3ad8929d3659cd713e7b869eb726d9f8cabf080ed73dfa6bD&
13fc5f5dbb279c4648c8bffcbb00b2e14727ae6ef9cbae25e6728251a8b2644eD%
1d64801f6bea041340ff67b2461569f13a202632b966b9ca8426a8027c14353bD$
0d33e36e3c9f478cdd404e7a15bdde7f8470d1267ae29e4c3127e06d2646a3b8D#
6f6a33848cbd89fc9434117312104d1e8bcbc065f6821b6b24ebf04def7bf36dD"
3cc12df2dbbe22e4c3186fdf10fdc4f4f176bdac5296996b92aafd1019a8fab1D!
e9f64d411062686481236a557581f3593d4706cf5f1fd5f942dc86a107e85be4
	1CkgF[wKamil Dudka <kdudka@redhat.com> 1.0.3-1X- update to latest upstream bugfix release (#1427917)qE[	Kamil Dudka <kdudka@redhat.com> 1.0.2-2X@- explicitly conflict with all nss builds with bundled nss-pemHD[9Kamil Dudka <kdudka@redhat.com> 1.0.2-1XA- imported into RHEL-7Ca/Bob Relyea <rrelyea@redhat.com> - 3.90.0-2d- fix EMS bug
- disbale ECH
- fix gtests in spec file
- restore missing test caseIBa5Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d@- Rebase to NSS 3.90HAa3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767Q@aEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.m?a}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZ>aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite
ky.GkHN[9Kamil Dudka <kdudka@redhat.com> 1.0.2-1XA- imported into RHEL-7Mk-Kamil Dudka <kdudka@redhat.com> 1.0.3-7.el7_9.1d6@- support a scenario where 2 distinct encrypted private keys are used (#2121064){L[Kamil Dudka <kdudka@redhat.com> 1.0.3-7\v{- reintroduce implementation of the WaitForSlotEvent callback (#1615980)dK[qKamil Dudka <kdudka@redhat.com> 1.0.3-6\<y- fix performance regression in libcurl (#1659108)kJ[Kamil Dudka <kdudka@redhat.com> 1.0.3-5[j@- update object ID while reusing a certificate (#1610998)^I[eKamil Dudka <kdudka@redhat.com> 1.0.3-4Y- fix missing prototypes detected by CovscanvH[Kamil Dudka <kdudka@redhat.com> 1.0.3-3X:@- remove implementation of the WaitForSlotEvent callback (#1445384)G[+Kamil Dudka <kdudka@redhat.com> 1.0.3-2XO@- require at least the version of nss that nss-pem was built against (#1428965)
g Ng{V[Kamil Dudka <kdudka@redhat.com> 1.0.3-7\v{- reintroduce implementation of the WaitForSlotEvent callback (#1615980)dU[qKamil Dudka <kdudka@redhat.com> 1.0.3-6\<y- fix performance regression in libcurl (#1659108)kT[Kamil Dudka <kdudka@redhat.com> 1.0.3-5[j@- update object ID while reusing a certificate (#1610998)^S[eKamil Dudka <kdudka@redhat.com> 1.0.3-4Y- fix missing prototypes detected by CovscanvR[Kamil Dudka <kdudka@redhat.com> 1.0.3-3X:@- remove implementation of the WaitForSlotEvent callback (#1445384)Q[+Kamil Dudka <kdudka@redhat.com> 1.0.3-2XO@- require at least the version of nss that nss-pem was built against (#1428965)gP[wKamil Dudka <kdudka@redhat.com> 1.0.3-1X- update to latest upstream bugfix release (#1427917)qO[	Kamil Dudka <kdudka@redhat.com> 1.0.2-2X@- explicitly conflict with all nss builds with bundled nss-pem
TpT\aWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'[aoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)xZaBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)8YaBob Relyea <rrelyea@redhat.com> - 3.44.0-5]S- Fix pkix name constraints processing to only process the common name if the
  certusage you are checking is IPSEC or SSL Server.XaEBob Relyea <rrelyea@redhat.com> - 3.44.0-4\- Fix certutil man page
- Fix extracting a public key from a private key for dh, ec, and dsaWk-Kamil Dudka <kdudka@redhat.com> 1.0.3-7.el7_9.1d6@- support a scenario where 2 distinct encrypted private keys are used (#2121064)
d`dbaEBob Relyea <rrelyea@redhat.com> - 3.44.0-4\- Fix certutil man page
- Fix extracting a public key from a private key for dh, ec, and dsa2aeJohnny Hughes <johnny@centos.org> - 3.53.1-3_@- much thanks to both Tuomo Soini (foobar.fi) and Pat Riehecky (scientificlinux.org)
  for finding the fix to these issuest`YTuomo Soini <tis@foobar.fi> - 3.53.1-3_w@- Fix tests by updating PayPalEE.cert to valid one
- Fix tests to expect small primes failing rhbz#1884793
- Fix Cannot compile code with nss headers and -Werror=strict-prototypes
  rhbz#18853210_]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesO^]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by defaultI]]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1
&C{.&0i]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesOh]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by defaultIg]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1faWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'eaoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)xdaBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)8caBob Relyea <rrelyea@redhat.com> - 3.44.0-5]S- Fix pkix name constraints processing to only process the common name if the
  certusage you are checking is IPSEC or SSL Server.
;P(;Io]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1naWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'maoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)xlaBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)2keJohnny Hughes <johnny@centos.org> - 3.53.1-3_@- much thanks to both Tuomo Soini (foobar.fi) and Pat Riehecky (scientificlinux.org)
  for finding the fix to these issuestjYTuomo Soini <tis@foobar.fi> - 3.53.1-3_w@- Fix tests by updating PayPalEE.cert to valid one
- Fix tests to expect small primes failing rhbz#1884793
- Fix Cannot compile code with nss headers and -Werror=strict-prototypes
  rhbz#1885321
_xvaBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)ua)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protolta{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`sacBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.raIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.0q]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesOp]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by default
bTg_b`}acBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.|aIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.0{]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesOz]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by defaultIy]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1xaWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'waoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)
\RU\a)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protola{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`acBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.aIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.0]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesa)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protol~a{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.
/a,/`acBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.aIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.0
]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cycles"	aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a=- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Na?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66
OhOaIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn."aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a=- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Na?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66a)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protol
a{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.
	7,V+7Ia5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Na?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66a)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protola{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`acBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.
g
k%a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingI$a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67N#a?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsI"a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66!a)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protol a{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`acBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.aIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.
	>Ym >^.a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDI-a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527",aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.+a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingI*a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67N)a?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsI(a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66I'a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"&aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.
	p1=dpI7a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"6aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.5a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingI4a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67N3a?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsI2a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66Q1aEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.m0a}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZ/aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite
	[@z(O[I@a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"?aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.>a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingI=a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67N<a?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsQ;aEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.m:a}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZ9aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^8a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module ID

er+V:eD:
790b5c852e13d4b60fb3844c4e81a28b8500aad7ad521d07ead00631d519881fD9
63b78d16ff05658c1581a33fcbba6aef6d587165c3310243fa9aef6ae820ac57D8
2c9e65472d82364af217344ab0110865c917422d27b922d937affb01473027fbD7
e34c0ad20744217c96add514c92d0cbc2a8b8784c76ab519306475684082bc7bD6
801c2058a333ace01ba2317b6297c530b615d43b97c7c076ab0842fec5a12dfbD5
72669bb54a42016961de3ef8bfcc2ec60aef58f9897e239a330679bdcf828e86D4
55e1830d8be44d9b010552a3d903913d14a27e26eafcd4cfb45fd3106ce59c32D3
47b2d4db641e0cb05ac7567ff73f91567cff400dec134469086e86b41ebe1072D2
72e40ba785c31c8259b00c65df653253a9d5ea138de40dbb02d655d32830c0c4D1
b8aa34987f1faadf2c76fb58239d11cf1222dba253fc175f21607f57bb0e908cD0
1140e209585f7f6f824c94f984cfe8ac43ee1498adcb74c031ce6e8e712d43b1D/
458d8d0ed05bdaad8b13b09c5d860beda84b34bf0ab4c5673194584865a68103D.
acd182fdbf43efaafafe21332a32ca669b688ad9760f5af2cbe33be296901606
	\@z.\"IaeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.Ha/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIGa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67NFa?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsHEa3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767QDaEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.mCa}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZBaWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^Aa_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module ID
	aQ-UaIRa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"QaeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.Pa/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingHOa3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767QNaEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.mMa}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZLaWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^Ka_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDIJa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527
	"@z.U""[aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.Za/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingYa/Bob Relyea <rrelyea@redhat.com> - 3.90.0-2d- fix EMS bug
- disbale ECH
- fix gtests in spec file
- restore missing test caseIXa5Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d@- Rebase to NSS 3.90HWa3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767QVaEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.mUa}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZTaWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^Sa_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module ID

>Q->pe]Daiki Ueno <dueno@redhat.com> - 3.44.0-6]@- Fix fipstest to use the standard mechanism for TLS 1.2 PRFRdaGBob Relyea <rrelyea@redhat.com> - 3.44.0-5\- Add pub from priv mechanismca/Bob Relyea <rrelyea@redhat.com> - 3.90.0-2d- fix EMS bug
- disbale ECH
- fix gtests in spec file
- restore missing test caseIba5Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d@- Rebase to NSS 3.90Haa3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767Q`aEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.m_a}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZ^aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^]a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDI\a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527
R_CRel]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changek]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linkedjaOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.bi]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)Ih]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1ngaBob Relyea <rrelyea@redhat.com> - 3.44.0-8]- Fix segfault on empty or malformed ecdh keys (#1777712)xfaBob Relyea <rrelyea@redhat.com> - 3.44.0-7]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)
&8bs]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)Ir]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1nqaBob Relyea <rrelyea@redhat.com> - 3.44.0-8]- Fix segfault on empty or malformed ecdh keys (#1777712)xpaBob Relyea <rrelyea@redhat.com> - 3.44.0-7]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)po]Daiki Ueno <dueno@redhat.com> - 3.44.0-6]@- Fix fipstest to use the standard mechanism for TLS 1.2 PRFRnaGBob Relyea <rrelyea@redhat.com> - 3.44.0-5\- Add pub from priv mechanismma7Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn of ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.
0\0by]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)Ix]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1wa7Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn of ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.ev]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changeu]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linkedtaOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.
/\/bagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptI~a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66}a9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.e|]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous change{]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linkedzaOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.
!.!e]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous change]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linkedaOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.b]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)I]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1Ma;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67
<e]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changeMa;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingI
a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67b	agBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66a9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.
<Ma;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67bagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66
a9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.
_2p_a9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.e]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changeUaMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pberaBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedEa-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbm
`M.`raBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedEa-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbmMa;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67bagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66
TA"Tr%aBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedE$a-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
#a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbmM"a;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingI!a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67b agBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptUaMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pbe
Y
9M,a;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingI+a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67b*agBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptg)aqBob Relyea <rrelyea@redhat.com> - 3.90.0-6dh- Fix double free issue when using dsa check filesK(a9Bob Relyea <rrelyea@redhat.com> - 3.90.0-5dh- Fix pbkdf indicatorsJ'a7Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d- Rebase to NSS 3.90.U&aMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pbe
{2<{R4aGBob Relyea <rrelyea@redhat.com> - 3.44.0-5\- Add pub from priv mechanismg3aqBob Relyea <rrelyea@redhat.com> - 3.90.0-6dh- Fix double free issue when using dsa check filesK2a9Bob Relyea <rrelyea@redhat.com> - 3.90.0-5dh- Fix pbkdf indicatorsJ1a7Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d- Rebase to NSS 3.90.U0aMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pber/aBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedE.a-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
-a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbm
GQG;]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linked:aOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.b9]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)I8]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1n7aBob Relyea <rrelyea@redhat.com> - 3.44.0-8]- Fix segfault on empty or malformed ecdh keys (#1777712)x6aBob Relyea <rrelyea@redhat.com> - 3.44.0-7]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)p5]Daiki Ueno <dueno@redhat.com> - 3.44.0-6]@- Fix fipstest to use the standard mechanism for TLS 1.2 PRF
1AbC]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)IB]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1nAaBob Relyea <rrelyea@redhat.com> - 3.44.0-8]- Fix segfault on empty or malformed ecdh keys (#1777712)x@aBob Relyea <rrelyea@redhat.com> - 3.44.0-7]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)p?]Daiki Ueno <dueno@redhat.com> - 3.44.0-6]@- Fix fipstest to use the standard mechanism for TLS 1.2 PRFR>aGBob Relyea <rrelyea@redhat.com> - 3.44.0-5\- Add pub from priv mechanism=a7Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn of ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.e<]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous change

er+V:eDG
d7d05bd3b99401da823317bb7e6c1a90595816c4f9e5eb8c21d12f8f3f5ebf66DF
be995dc375c67dc51acf2c699baca627283b58d86d70153bb13df3b2549662d4DE
23872416b1e3fe4aeba522975174df37b9536f0c3c2394d432e0af7788af80dfDD
e86b714d0c1f2ae4a38a0244f16cb28ce588dd6802d4a4341ea79e52e3cd5799DC
8d8b3cb385da57417205c3d9356d8976758920c3bc55610e49f55d64121a248eDB
8aa95e78921113508fef7b52fbf20b5c2731cc1b9798d653a482bf00087462c1DA
1098fb31b298327e754a43c15283034ffb6c1138ed0b9ba0e5547441891481dcD@
313127128dfeab1a78ae930c9890aa99789694b8356bad44d6b56c72932a543cD?
8519d3cb6d82e68f50832778a44e1f676b5fbb85f891a07751e7f2c0767112bcD>
f12b43b7660d30cf43f854e59aded17e8167850a81e00bc36ff1f71c6366769eD=
386bf9ac5cf0faeb2ff2784055e2032e081a36e7187d99c1111cf03fac18d874D<
8547960e747f135c2514a024771cf2225c649ca891512c2dd1069a06138796a8D;
bc8180bbf3602244c3a34b6a576fcd6db7b1b882332f6a22471bbdb479835f92
0\0bI]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)IH]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1Ga7Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn of ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.eF]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changeE]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linkedDaOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.
/\/bOagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptINa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66Ma9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.eL]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changeK]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linkedJaOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.
!.!eV]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changeU]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linkedTaOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.bS]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)IR]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1MQa;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIPa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67
<e\]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changeM[a;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIZa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67bYagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptIXa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66Wa9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.
<Maa;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingI`a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67b_agBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptI^a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66]a9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.
_2p_ga9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.ef]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changeUeaMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pberdaBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedEca-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
ba5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbm
`M.`rnaBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedEma-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
la5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbmMka;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIja5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67biagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptIha5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66
TA"TruaBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedEta-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
sa5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbmMra;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIqa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67bpagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptUoaMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pbe
Y
9M|a;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingI{a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67bzagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptgyaqBob Relyea <rrelyea@redhat.com> - 3.90.0-6dh- Fix double free issue when using dsa check filesKxa9Bob Relyea <rrelyea@redhat.com> - 3.90.0-5dh- Fix pbkdf indicatorsJwa7Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d- Rebase to NSS 3.90.UvaMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pbe
{2<{RaGBob Relyea <rrelyea@redhat.com> - 3.44.0-5\- Add pub from priv mechanismgaqBob Relyea <rrelyea@redhat.com> - 3.90.0-6dh- Fix double free issue when using dsa check filesKa9Bob Relyea <rrelyea@redhat.com> - 3.90.0-5dh- Fix pbkdf indicatorsJa7Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d- Rebase to NSS 3.90.UaMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pberaBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedE~a-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
}a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbm
GQG]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linked
aOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.b	]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)I]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1naBob Relyea <rrelyea@redhat.com> - 3.44.0-8]- Fix segfault on empty or malformed ecdh keys (#1777712)xaBob Relyea <rrelyea@redhat.com> - 3.44.0-7]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)p]Daiki Ueno <dueno@redhat.com> - 3.44.0-6]@- Fix fipstest to use the standard mechanism for TLS 1.2 PRF
1Ab]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)I]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1naBob Relyea <rrelyea@redhat.com> - 3.44.0-8]- Fix segfault on empty or malformed ecdh keys (#1777712)xaBob Relyea <rrelyea@redhat.com> - 3.44.0-7]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)p]Daiki Ueno <dueno@redhat.com> - 3.44.0-6]@- Fix fipstest to use the standard mechanism for TLS 1.2 PRFRaGBob Relyea <rrelyea@redhat.com> - 3.44.0-5\- Add pub from priv mechanism
a7Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn of ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.e]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous change
0\0b]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)I]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1a7Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn of ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.e]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous change]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linkedaOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.
/\/bagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66a9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.e]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous change]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linkedaOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.
!.!e&]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous change%]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linked$aOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.b#]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)I"]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1M!a;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingI a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67
<e,]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changeM+a;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingI*a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67b)agBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptI(a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66'a9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.
<M1a;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingI0a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67b/agBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptI.a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66-a9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.
_2p_7a9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.e6]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changeU5aMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pber4aBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedE3a-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
2a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbm
`M.`r>aBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedE=a-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
<a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbmM;a;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingI:a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67b9agBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptI8a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66
TA"TrEaBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedEDa-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
Ca5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbmMBa;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIAa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67b@agBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptU?aMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pbe

er+V:eDT
98f975d1354a7cc4711afccd61e1974d67622fdcd82305c34e00b404ab02ea8aDS
91e11d6d33aef2e3286d36cad20e968159d1995461d24cfd238bc15aa535639cDR
48329854b7d3d8bc442c5246bb0589aaffd665388bbecfc7c00032cfffabb222DQ
fee8dc3a19870d83d686d8f123acfabb5dcca85f4ee2450ffe3dbd5f3b132a54DP
f5e6524f1f2a9dcc72ebf9399a52dc24da1e60c30002c88d69c630e49623aac1DO
606cd78f5ca90a81ab3e934fbd5a9355ef4e5232694e0583575fe2c6144e00daDN
3b52c38e47ee82671fa761bae2755fd870054dc377cb23f09b0dda2a5da96a65DM
3d9a71ffb2359ea5a0dc6d4ed6231ba9e22038c3542aa2e129564b7029b25277DL
533e33c4dc57038b0d5c6ee8639e010a745908371d1295b11c0afcfbabbf8231DK
9cda3404dd4c70ddebe5fc092534a2952e3c6f66ae3e9452bbdfded07730a7e5DJ
d81caf81254734559eabc40be6eb6cddaeb393b4e93b64804cb596861d688776DI
4499296b0da4f8a6353fc0b32880c2dd463d4a440d98446b29fd4d12a5a2ed28DH
b7e366f21ddcc468fdf5911183613253aa34811a255f3ce61359b728e281b233
Y
9MLa;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIKa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67bJagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptgIaqBob Relyea <rrelyea@redhat.com> - 3.90.0-6dh- Fix double free issue when using dsa check filesKHa9Bob Relyea <rrelyea@redhat.com> - 3.90.0-5dh- Fix pbkdf indicatorsJGa7Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d- Rebase to NSS 3.90.UFaMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pbe
{2<{RTaGBob Relyea <rrelyea@redhat.com> - 3.44.0-5\- Add pub from priv mechanismgSaqBob Relyea <rrelyea@redhat.com> - 3.90.0-6dh- Fix double free issue when using dsa check filesKRa9Bob Relyea <rrelyea@redhat.com> - 3.90.0-5dh- Fix pbkdf indicatorsJQa7Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d- Rebase to NSS 3.90.UPaMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pberOaBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedENa-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
Ma5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbm
GQG[]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linkedZaOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.bY]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)IX]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1nWaBob Relyea <rrelyea@redhat.com> - 3.44.0-8]- Fix segfault on empty or malformed ecdh keys (#1777712)xVaBob Relyea <rrelyea@redhat.com> - 3.44.0-7]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)pU]Daiki Ueno <dueno@redhat.com> - 3.44.0-6]@- Fix fipstest to use the standard mechanism for TLS 1.2 PRF
1Abc]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)Ib]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1naaBob Relyea <rrelyea@redhat.com> - 3.44.0-8]- Fix segfault on empty or malformed ecdh keys (#1777712)x`aBob Relyea <rrelyea@redhat.com> - 3.44.0-7]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)p_]Daiki Ueno <dueno@redhat.com> - 3.44.0-6]@- Fix fipstest to use the standard mechanism for TLS 1.2 PRFR^aGBob Relyea <rrelyea@redhat.com> - 3.44.0-5\- Add pub from priv mechanism]a7Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn of ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.e\]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous change
0\0bi]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)Ih]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1ga7Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn of ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.ef]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changee]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linkeddaOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.
/\/boagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptIna5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66ma9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.el]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changek]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linkedjaOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.
!.!ev]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changeu]+Daiki Ueno <dueno@redhat.com> - 3.53.1-4_P- Fix glibc regression in the rebase; run RNG self-tests only if NSPR is linkedtaOBob Relyea <rrelyea@redhat.com> - 3.53.1-3_G@- include patches for CVE-2020-6829, CVE-2020-12400,
  and CVE-2020-12401 from upstream (ECC constant time issues).
- include patches for CVE-2020-12403 from upstream
  (CHACHA issues).
- include self-tests for kdfs and cmac.bs]kDaiki Ueno <dueno@redhat.com> - 3.53.1-2_*A- Install cmac.h required by blapi.h (#1764513)Ir]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1Mqa;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIpa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67
<e|]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changeM{a;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIza5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67byagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptIxa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66wa9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.
<Ma;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67bagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptI~a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66}a9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.
_2p_a9Bob Relyea <rrelyea@redhat.com> - 3.53.1-6_[f- turn off ALTIVEC instruction for powerpc because they require
  power8 and we need to support power7 on RHEL7 still.
- Fix typo in measure.
- Make sure only 2048 and greater primes are used in FIPS mode
  for dh.e]qDaiki Ueno <dueno@redhat.com> - 3.53.1-5_P- Fix the patch application in the previous changeUaMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pberaBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedEa-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbm
`M.`raBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedE
a-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbmMa;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingI
a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67b	agBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66
TA"TraBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedEa-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbmMa;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67bagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptUaMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pbe
Y
9Ma;Bob Relyea <rrelyea@redhat.com> - 3.67.0-3a8- Include softoken specific patches required by the NSS 3.67
  release including:
-  sdb timeout fixes.
-  coverity patch.
-  fixing private key macingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`9@- Rebase to NSS 3.67bagBob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- fix crash in freebl when called by libcryptgaqBob Relyea <rrelyea@redhat.com> - 3.90.0-6dh- Fix double free issue when using dsa check filesKa9Bob Relyea <rrelyea@redhat.com> - 3.90.0-5dh- Fix pbkdf indicatorsJa7Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d- Rebase to NSS 3.90.UaMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pbe
:2<:$aEBob Relyea <rrelyea@redhat.com> - 3.44.0-4\- Fix certutil man page
- Fix extracting a public key from a private key for dh, ec, and dsag#aqBob Relyea <rrelyea@redhat.com> - 3.90.0-6dh- Fix double free issue when using dsa check filesK"a9Bob Relyea <rrelyea@redhat.com> - 3.90.0-5dh- Fix pbkdf indicatorsJ!a7Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d- Rebase to NSS 3.90.U aMBob Relyea <rrelyea@redhat.com> - 3.79.0-4bl- increase the cache for the pberaBob Relyea <rrelyea@redhat.com> - 3.79.0-3bx@- fix test regression: freebl crash when nss-util not loadedEa-Bob Relyea <rrelyea@redhat.com> - 3.79.0-2b2@- include dbtool
a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b- Rebase to NSS 3.79.
- add reader/writer lock on encrypted attribute access
- skip attribute verification on attributes with default values
- don't export trust objects if they are default trust objects from dbm
&C{.&0+]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesO*]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by defaultI)]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1(aWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.''aoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)x&aBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)8%aBob Relyea <rrelyea@redhat.com> - 3.44.0-5]S- Fix pkix name constraints processing to only process the common name if the
  certusage you are checking is IPSEC or SSL Server.
;P(;I1]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.10aWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'/aoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)x.aBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)2-eJohnny Hughes <johnny@centos.org> - 3.53.1-3_@- much thanks to both Tuomo Soini (foobar.fi) and Pat Riehecky (scientificlinux.org)
  for finding the fix to these issuest,YTuomo Soini <tis@foobar.fi> - 3.53.1-3_w@- Fix tests by updating PayPalEE.cert to valid one
- Fix tests to expect small primes failing rhbz#1884793
- Fix Cannot compile code with nss headers and -Werror=strict-prototypes
  rhbz#1885321
M_M08]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cycles7a)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protol6a{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`5acBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.4aIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.03]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesO2]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by default
g
k@a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingI?a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67N>a?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsI=a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66<a)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protol;a{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`:acBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.9aIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.
wY\cwIHa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67NGa?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIFa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66Ea)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protolDa{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`CacBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.BaIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn."AaeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a=- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.

er+V:eDa
0cc793e2d0f59813a9e09567f1c3af4510272946883ebb48cc9cce9189664c7eD`
627873cfe317368f11a034089c743611ad85c7f5985f6c68ca714c1b0329eec3D_
794a3fb2e476acfb436f4d7da625bc3f96841861ad270f795c67ff6046875f47D^
1849014c019076934853ec6d7ad795b91829e59d3946c36ff4c13951f53c6a67D]
d2ee3c87b0f7cd858c02969d5c617afe7f2d92c540498c4ce94ecaf46e9f8f0dD\
e649737e5bf6a5d2b0bb6c20cbdfd046ba295e9f79765fec2800f61f3d408ac0D[
0db1ad475d57dd2dcf3165a763d246f2f2b899c3bc4bad744291c568d041127cDZ
7ed2c97dedcd344ca3d389d366a728d3d18c9b22b1f567b0d03394574fd4ba2cDY
c7fd61c26b7aa8ef79e64d61f67cf2643bdfb67b8af8ac5993f3fe4e727d44e6DX
ebc3f9be0c742cb29c3852f630ce1ed5605f07849ea71b3f6dcad16424055700DW
a687f0ccd9e74160f22533e305c5bb77d33023ba63729183e338ad27461a5494DV
fc8271b385663f8ee5b7718d56371ca3af96ca4df7b25c4f38ff59ce2e327270DU
56f07c39bdea546bc3f3eb930711eb7562fbf0cd8fbcbd9f5e3f7fae8dbf2013
at3a"PaeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.Oa/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingINa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67NMa?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsILa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66IKa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"JaeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.Ia/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processing
	[Q-["YaeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.Xa/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIWa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67NVa?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsQUaEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.mTa}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZSaWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^Ra_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDIQa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527
	aQ-UaIba5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"aaeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.`a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingH_a3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767Q^aEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.m]a}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZ\aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^[a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDIZa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527
@z.UjaEBob Relyea <rrelyea@redhat.com> - 3.44.0-4\- Fix certutil man page
- Fix extracting a public key from a private key for dh, ec, and dsaia/Bob Relyea <rrelyea@redhat.com> - 3.90.0-2d- fix EMS bug
- disbale ECH
- fix gtests in spec file
- restore missing test caseIha5Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d@- Rebase to NSS 3.90Hga3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767QfaEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.mea}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZdaWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^ca_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module ID
&C{.&0q]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesOp]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by defaultIo]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1naWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'maoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)xlaBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)8kaBob Relyea <rrelyea@redhat.com> - 3.44.0-5]S- Fix pkix name constraints processing to only process the common name if the
  certusage you are checking is IPSEC or SSL Server.
;P(;Iw]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_*@- Rebase to NSS 3.53.1vaWBob Relyea <rrelyea@redhat.com> - 3.44.0-8]B- Increase timeout on ssl_gtest so that slow platforms can complete when
   running on a busy system.'uaoBob Relyea <rrelyea@redhat.com> - 3.44.0-7]@- back out out-of-bounds patch (patch for nss-softokn).
- Fix segfault on empty or malformed ecdh keys (#1777712)xtaBob Relyea <rrelyea@redhat.com> - 3.44.0-6]- Fix out-of-bounds write in NSC_EncryptUpdate (#1775911,#1775910)2seJohnny Hughes <johnny@centos.org> - 3.53.1-3_@- much thanks to both Tuomo Soini (foobar.fi) and Pat Riehecky (scientificlinux.org)
  for finding the fix to these issuestrYTuomo Soini <tis@foobar.fi> - 3.53.1-3_w@- Fix tests by updating PayPalEE.cert to valid one
- Fix tests to expect small primes failing rhbz#1884793
- Fix Cannot compile code with nss headers and -Werror=strict-prototypes
  rhbz#1885321
M_M0~]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cycles}a)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protol|a{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`{acBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.zaIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.0y]Daiki Ueno <dueno@redhat.com> - 3.53.1-3_%Y@- Disable dh timing test because it's unreliable on s390 (from Bob Relyea)
- Explicitly enable upgradedb/sharedb test cyclesOx]EDaiki Ueno <dueno@redhat.com> - 3.53.1-2_"@- Disable TLS 1.3 by default
g
ka/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Na?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66a)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protola{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`acBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.aIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn.
wY\cwIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67N
a?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66a)Bob Relyea <rrelyea@redhat.com> - 3.53.1-7`?z@- Fix HSM load failure because of CKO_Profile
- Allow builds with strict-protol
a{Bob Relyea <rrelyea@redhat.com> - 3.53.1-6`3- Update to CVE 2020-256423 TLS flood DOS attack patch.`	acBob Relyea <rrelyea@redhat.com> - 3.53.1-5`.V- Fix CVE 2020-256423 TLS flood DOS Attack.aIBob Relyea <rrelyea@redhat.com> - 3.53.1-4`@- Fix deadlock issue
- Fix 3 FTBS issues, 2 expired certs, one semantic change in nss-softokn."aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a=- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.
at3a"aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Na?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsIa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66Ia5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processing
	[Q-["aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`- Rebase to NSS 3.67Na?Bob Relyea <rrelyea@redhat.com> - 3.66.0-2`Ȗ@- restore pkcs12 defaultsQaEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.ma}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZaWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDIa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527
	aQ-UaI(a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527"'aeBob Relyea <rrelyea@redhat.com> - 3.67.0-3a@- revert sql default language in man pages
- fix SEC_PKCS12EnableCipher so python-nss tests will still work.&a/Bob Relyea <rrelyea@redhat.com> - 3.67.0-2`@- fix sdb timeout issue
- fix incorrect ssl alerts in Signature scheme processingH%a3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767Q$aEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.m#a}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZ"aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^!a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module IDI a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-4a@@- fix CVE-2021-43527

Y@z.UYG2]5Daiki Ueno <dueno@redhat.com> - 3.36.0-1Z1@- Rebase to NSS 3.36S1k?Daiki Ueno <dueno@redhat.com> - 3.36.0-0.1.betaZ@- Rebase to NSS 3.36 BETAV0]SDaiki Ueno <dueno@redhat.com> - 3.34.0-2Z]@- Recognize "ECC" flag in slotFlags/a/Bob Relyea <rrelyea@redhat.com> - 3.90.0-2d- fix EMS bug
- disbale ECH
- fix gtests in spec file
- restore missing test caseI.a5Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d@- Rebase to NSS 3.90H-a3Bob Relyea <rrelyea@redhat.com> - 3.79.0-5dx- fix CVE-2023-0767Q,aEBob Relyea <rrelyea@redhat.com> - 3.79.0-4b?- fix regression for pkcs12.m+a}Bob Relyea <rrelyea@redhat.com> - 3.79.0-3by@- fix crash in curl. better fix for the regression belowZ*aWBob Relyea <rrelyea@redhat.com> - 3.79.0-2b- fix regressions found in test suite^)a_Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79
- Set FIPS Module ID

Ty.PTG<]5Daiki Ueno <dueno@redhat.com> - 3.36.0-1Z1@- Rebase to NSS 3.36S;k?Daiki Ueno <dueno@redhat.com> - 3.36.0-0.1.betaZ@- Rebase to NSS 3.36 BETAV:]SDaiki Ueno <dueno@redhat.com> - 3.34.0-2Z]@- Recognize "ECC" flag in slotFlagsI9]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1n8aBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)7a%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKEI6a5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsG5]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44G4]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.433a%Bob Relyea <rrelyea@redhat.com> - 3.36.0-2[k@- Update the cert verify code to allow a new ipsec usage and follow RFC 4945

3y.P~3GF]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43Ea%Bob Relyea <rrelyea@redhat.com> - 3.36.0-2[k@- Update the cert verify code to allow a new ipsec usage and follow RFC 4945GD]5Daiki Ueno <dueno@redhat.com> - 3.36.0-1Z1@- Rebase to NSS 3.36IC]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1nBaBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)Aa%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKEI@a5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsG?]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44G>]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43=a%Bob Relyea <rrelyea@redhat.com> - 3.36.0-2[k@- Update the cert verify code to allow a new ipsec usage and follow RFC 4945

er+V:eDn
ac3b19c2af6397ecfc8da1ca8a214b082e2537deb956d6f9ef387d52189be60aDm
19978c4af00a791c32ebd350c7567fcaa35f1777bf2095ed486565c265b574f7Dl
0c048c74887e157b97b761a85580b46558525fc2a03b50627c102edbdffe5e76Dk
b1ef52251919f4f18e97753ef2b6c690ce946d73749b031333749d21518f5096Dj
117dfa1e07c65b202f4bbd0243e69bb5e24c7be31b9f971550d6ed083315bdc9Di
9e0df1a28efc20a09397d8fda7acd78003130bd6e24eaa47905a3a1c11b8fd1bDh
2872eebb01865b8ead0f4f8bb9b8cda849c0b3a564ce459640c72efad9cb6f83Dg
f6b2698566260a93a03d412c81d071599637c1e75b05da8cabdcc3de0e4591eaDf
579a8660d11a9685cd885b48ee54281757a07a1f578e4d25da3e9a0fe38a378dDe
b58fd5d0fbbbaf80d3e0405749952cb4e46fea09ad96f495282995d6dc2f0a15Dd
ee6eb3ef29eea0165c0b0ffc82aba7958b58d0abbb0174433821699be8a41789Dc
b6e274e05ac34f9451986e5f375b66cef94037ebc8c2b402675b73d23033f6d4Db
8d96cac84dd7d2d8bf80953662039db4ad42350b6281599a0f5b97a679b9c4b2
 ho"=k GQ]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44GP]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43Oa%Bob Relyea <rrelyea@redhat.com> - 3.36.0-2[k@- Update the cert verify code to allow a new ipsec usage and follow RFC 4945GN]5Daiki Ueno <dueno@redhat.com> - 3.36.0-1Z1@- Rebase to NSS 3.36IMa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`9@- Rebase to NSS 3.66ILa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66IK]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1nJaBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)Ia%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKEIHa5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsGG]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44

i,m LiI[a5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsGZ]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44GY]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43Xa%Bob Relyea <rrelyea@redhat.com> - 3.36.0-2[k@- Update the cert verify code to allow a new ipsec usage and follow RFC 4945IWa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`9@- Rebase to NSS 3.66IVa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66IU]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1nTaBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)Sa%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKEIRa5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanisms

iym LiIea5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsGd]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44Gc]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43ba%Bob Relyea <rrelyea@redhat.com> - 3.36.0-2[k@- Update the cert verify code to allow a new ipsec usage and follow RFC 4945Iaa5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79I`a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`9@- Rebase to NSS 3.66I_a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66I^]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1n]aBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)\a%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKEbR0RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{0*&0+,0,10-70.>0/E01L02T03[04c05i06o07v08|090:0;0<0=0>$0?+0@10A80B@0CH0EP0FY0Gb0Hj0Iq0Jw0K~0L0M0N0O0P(0Q20R<0SF0UQ0V[0We0Yo0Zy0[0\
0]0^"0_,0`60aA0bL0dT0e[0fa0gh0ho0iu0jz0k}0l0m0n0o	0p0q0r0s0t0u0v0w!0x$0y'0z*0{-0|00}30~6090<0@0C0F0I0L0O0R0U0X0[0^0a0d0g0j0m

iym =ioa%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKEIna5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsGm]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44Gl]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43Ika5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79Ija5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`9@- Rebase to NSS 3.66Iia5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66Ih]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1ngaBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)fa%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKE

AZTya%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKEIxa5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsGw]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44Gv]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43lua{Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d- Rebase to NSS 3.90
- Replace deprecate %patchN syntaxIta5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79Isa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`9@- Rebase to NSS 3.66Ira5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66Iq]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1npaBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)

gAZ9ga%Bob Relyea <rrelyea@redhat.com> - 3.36.0-2[k@- Update the cert verify code to allow a new ipsec usage and follow RFC 4945G]5Daiki Ueno <dueno@redhat.com> - 3.36.0-1Z1@- Rebase to NSS 3.36Sk?Daiki Ueno <dueno@redhat.com> - 3.36.0-0.1.betaZ@- Rebase to NSS 3.36 BETAV]SDaiki Ueno <dueno@redhat.com> - 3.34.0-2Z]@- Recognize "ECC" flag in slotFlagsla{Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d- Rebase to NSS 3.90
- Replace deprecate %patchN syntaxI~a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79I}a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`9@- Rebase to NSS 3.66I|a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66I{]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1nzaBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)

Tj$}&T
a%Bob Relyea <rrelyea@redhat.com> - 3.36.0-2[k@- Update the cert verify code to allow a new ipsec usage and follow RFC 4945G]5Daiki Ueno <dueno@redhat.com> - 3.36.0-1Z1@- Rebase to NSS 3.36Sk?Daiki Ueno <dueno@redhat.com> - 3.36.0-0.1.betaZ@- Rebase to NSS 3.36 BETAV
]SDaiki Ueno <dueno@redhat.com> - 3.34.0-2Z]@- Recognize "ECC" flag in slotFlagsI	]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1naBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)a%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKEIa5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsG]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44G]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43
"j$o"Ia5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsG]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44G]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43a%Bob Relyea <rrelyea@redhat.com> - 3.36.0-2[k@- Update the cert verify code to allow a new ipsec usage and follow RFC 4945G]5Daiki Ueno <dueno@redhat.com> - 3.36.0-1Z1@- Rebase to NSS 3.36I]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1naBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)a%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKEIa5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsG]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44G]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43

kym NkI"a5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsG!]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44G ]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43a%Bob Relyea <rrelyea@redhat.com> - 3.36.0-2[k@- Update the cert verify code to allow a new ipsec usage and follow RFC 4945G]5Daiki Ueno <dueno@redhat.com> - 3.36.0-1Z1@- Rebase to NSS 3.36Ia5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`9@- Rebase to NSS 3.66Ia5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66I]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1naBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)a%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKE

/ym N/,a%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKEI+a5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsG*]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44G)]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43(a%Bob Relyea <rrelyea@redhat.com> - 3.36.0-2[k@- Update the cert verify code to allow a new ipsec usage and follow RFC 4945I'a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`9@- Rebase to NSS 3.66I&a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66I%]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1n$aBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)#a%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKE

iAZ=i6a%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKEI5a5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsG4]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44G3]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.432a%Bob Relyea <rrelyea@redhat.com> - 3.36.0-2[k@- Update the cert verify code to allow a new ipsec usage and follow RFC 4945I1a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79I0a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`9@- Rebase to NSS 3.66I/a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66I.]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1n-aBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)
1AZw~1IA]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1n@aBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)?a%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKEI>a5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsG=]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44G<]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43I;a5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79I:a5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`9@- Rebase to NSS 3.66I9a5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66I8]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1n7aBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)
3f^?3ILa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66IK]9Daiki Ueno <dueno@redhat.com> - 3.53.1-1_@- Rebase to NSS 3.53.1nJaBob Relyea <rrelyea@redhat.com> - 3.44.0-4]@- Fix segfault on empty or malformed ecdh keys (#1777712)Ia%Bob Relyea <rrelyea@redhat.com> - 3.44.0-3\- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKEIHa5Bob Relyea <rrelyea@redhat.com> - 3.44.0-2\9- Add ike mechanismsGG]5Daiki Ueno <dueno@redhat.com> - 3.44.0-1\@- Rebase to NSS 3.44GF]5Daiki Ueno <dueno@redhat.com> - 3.43.0-1\|- Rebase to NSS 3.43lEa{Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d- Rebase to NSS 3.90
- Replace deprecate %patchN syntaxIDa5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79ICa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`9@- Rebase to NSS 3.66IBa5Bob Relyea <rrelyea@redhat.com> - 3.66.0-1`@- Rebase to NSS 3.66

er+V:eD{
013236ef5fa8a51d31d6d13a69fb89b023f7bf87400cfbe7442751e25e4a0c0dDz
ee831a9a421c3f86e21ee19ee0a9cf5254cfb534d32e86d6e52c61dba58a55f3Dy
de9e4e230ed945c27a0bd1d2400e9562d9cfd0a8d54ca6d1bc09dda52211b3f1Dx
ebcf9402d4327c9a14ef951bf3262aefce60b172528292bf1c628e54a7055235Dw
6d1470830d621e224bc916d1ef07109d5e9c254b87795bc6bce9f712f138681eDv
5ea1964ea7cdad4c1675afa57a96c5cca4a574eb022294b1d38ddcc08e6c6b3dDu
55be553fdb6b711c94e1f41369abf744fab2d8d3938dc7af09ee75d2249c22d5Dt
39b51aaf98eda72373e0ad8ad89a206476833813b0262e2e149bab9f2fa4e4b2Ds
e256274cc5f1a6f7f97af45288258ffc553c2f425401d35928622845d32c4465Dr
db0b608c42aca3d5a6652b87d0c3bce10a8ae188cd758704c3f1f4b70ea42cbdDq
27554b9b56bcf99ec38c5aac4a10faefaeb0b46d53264ec179036107f7c5461fDp
34a441b65b1e00f9aabba569dcd45ab40478d9681269cef9566513b8b0754934Do
067642d9046b8566ef1ed0cf884f58e8a6d4e400e732070462b2051471465a19
<fu<BTsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056nSsmRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
Rs)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992Qs/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056VPs=Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.2S- Resolves: rhbz#1125544lOa{Bob Relyea <rrelyea@redhat.com> - 3.90.0-1d- Rebase to NSS 3.90
- Replace deprecate %patchN syntaxINa5Bob Relyea <rrelyea@redhat.com> - 3.79.0-1b@- Rebase to NSS 3.79IMa5Bob Relyea <rrelyea@redhat.com> - 3.67.0-1`9@- Rebase to NSS 3.66
We@
[s)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992Zs/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056Yu;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500XuRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{WsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983oVsoRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$UsWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.
,auRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{`sRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983o_soRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$^sWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.B]sRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056n\smRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
d}VBhsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056ngsmRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
fs)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992es/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056Vds=Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.2S- Resolves: rhbz#1125544cuRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.12a@- Limit recursion in ri-records (CVE-2021-3622)
  resolves: rhbz#1976193bu;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500
We@
os)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992ns/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056mu;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500luRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{ksRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983ojsoRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$isWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.
,uuRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{tsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983ossoRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$rsWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.BqsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056npsmRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
drqzqOMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-1\b@- Updated RHEL version
- Resolves: bz#1667549
  ([RHEL 7.7, ESXi] Rebase open-vm-tools to 10.3.0)|yq	Miroslav Rezanina <mrezanin@redhat.com> - 10-2.5-3[{- ovt-Workaround-for-false-negative-result-when-detecting.patch [bz#1601559]
- Resolves: bz#1601559
  ([ESXi][RHEL7.6] Include new open-vm-tools patches for cloud-init to work with python-2)axuQRavindra Kumar <ravindrakumar@vmware.com> - 10.2.5-2Z- Use tirpc for Fedora 28 onwards.wuRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.12a@- Limit recursion in ri-records (CVE-2021-3622)
  resolves: rhbz#1976193vu;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500
[[x}sMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*|scMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)t{qyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
Iy9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)iy[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2~quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
TTqOMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-1\b@- Updated RHEL version
- Resolves: bz#1667549
  ([RHEL 7.7, ESXi] Rebase open-vm-tools to 10.3.0)|q	Miroslav Rezanina <mrezanin@redhat.com> - 10-2.5-3[{- ovt-Workaround-for-false-negative-result-when-detecting.patch [bz#1601559]
- Resolves: bz#1601559
  ([ESXi][RHEL7.6] Include new open-vm-tools patches for cloud-init to work with python-2)Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
[[xsMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*scMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)tqyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
I	y9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)iy[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
qOMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-1\b@- Updated RHEL version
- Resolves: bz#1667549
  ([RHEL 7.7, ESXi] Rebase open-vm-tools to 10.3.0)2myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
[[xsMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*scMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)t
qyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
Iy9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)iy[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
[[xsMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*scMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)tqyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
Iy9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)iy[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
x2!quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)x sMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)m!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])
nun$Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])#y9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)i"y[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)
'm!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])&Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2%myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")
}44}2*quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9){)mJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.6d}- ovt-Remove-some-dead-code.patch [bz#2215562]
- Resolves: bz#2215562
  ([CISA Major Incident] CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [rhel-7])G(
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.5dm@- ovt-Track-Linux-filesystem-id-FSID-for-quiesced-frozen-f.patch [bz#1880404 bz#1994590]
- Resolves: bz#1880404
  ([ESXi] [RHEL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml')
- Resolves: bz#1994590
  ([ESXi][RHEL7.9][open-vm-tools] Snapshot of the RHEL7 guest on the VMWare ESXi hypervisor failed vm hangs)
nun-Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z]),y9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)i+y[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)
0m!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])/Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2.myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")
;44;t3gMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.7d@- ovt-VGAuth-Allow-only-X509-certs-to-verify-the-SAML-toke.patch [RHEL-2413]
- Resolves: RHEL-2413
  (CVE-2023-20900 open-vm-tools: SAML token signature bypass [rhel-7.9.z]){2mJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.6d}- ovt-Remove-some-dead-code.patch [bz#2215562]
- Resolves: bz#2215562
  ([CISA Major Incident] CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [rhel-7])G1
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.5dm@- ovt-Track-Linux-filesystem-id-FSID-for-quiesced-frozen-f.patch [bz#1880404 bz#1994590]
- Resolves: bz#1880404
  ([ESXi] [RHEL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml')
- Resolves: bz#1994590
  ([ESXi][RHEL7.9][open-vm-tools] Snapshot of the RHEL7 guest on the VMWare ESXi hypervisor failed vm hangs)
26myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")5Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])4y9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)
  G9
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.5dm@- ovt-Track-Linux-filesystem-id-FSID-for-quiesced-frozen-f.patch [bz#1880404 bz#1994590]
- Resolves: bz#1880404
  ([ESXi] [RHEL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml')
- Resolves: bz#1994590
  ([ESXi][RHEL7.9][open-vm-tools] Snapshot of the RHEL7 guest on the VMWare ESXi hypervisor failed vm hangs)8m!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])7Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])
e<m_Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.8ej- ovt-Provide-alternate-method-to-allow-expected-pre-froze.patch [bz#2226921]
- Resolves: bz#2226921
  ([RHEL7.9][ESXi]Latest version of open-vm-tools breaks VM backups)t;gMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.7d@- ovt-VGAuth-Allow-only-X509-certs-to-verify-the-SAML-toke.patch [RHEL-2413]
- Resolves: RHEL-2413
  (CVE-2023-20900 open-vm-tools: SAML token signature bypass [rhel-7.9.z]){:mJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.6d}- ovt-Remove-some-dead-code.patch [bz#2215562]
- Resolves: bz#2215562
  ([CISA Major Incident] CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [rhel-7])
.8.@qOMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-1\b@- Updated RHEL version
- Resolves: bz#1667549
  ([RHEL 7.7, ESXi] Rebase open-vm-tools to 10.3.0)|?q	Miroslav Rezanina <mrezanin@redhat.com> - 10-2.5-3[{- ovt-Workaround-for-false-negative-result-when-detecting.patch [bz#1601559]
- Resolves: bz#1601559
  ([ESXi][RHEL7.6] Include new open-vm-tools patches for cloud-init to work with python-2)a>uQRavindra Kumar <ravindrakumar@vmware.com> - 10.2.5-2Z- Use tirpc for Fedora 28 onwards.C=Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.9eC@- ovt-Don-t-accept-tokens-with-unrelated-certs.patch [RHEL-14642]
- ovt-File-descriptor-vulnerability-in-the-open-vm-tools-v.patch [RHEL-14676]
- Resolves: RHEL-14642
  (CVE-2023-34058 open-vm-tools: SAML token signature bypass [rhel-7.9.z])
- Resolves: RHEL-14676
  (CVE-2023-34059 open-vm-tools: file descriptor hijack vulnerability in the vmware-user-suid-wrapper [rhel-7.9.z])
[[xCsMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*BscMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)tAqyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
IFy9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)iEy[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2DquMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
TTIqOMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-1\b@- Updated RHEL version
- Resolves: bz#1667549
  ([RHEL 7.7, ESXi] Rebase open-vm-tools to 10.3.0)|Hq	Miroslav Rezanina <mrezanin@redhat.com> - 10-2.5-3[{- ovt-Workaround-for-false-negative-result-when-detecting.patch [bz#1601559]
- Resolves: bz#1601559
  ([ESXi][RHEL7.6] Include new open-vm-tools patches for cloud-init to work with python-2)GMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])

er+V:eD
53d8438b425a4358f4349cb5b43de3ceb51d10df527995c1c37a7d1598e8e8eeD
0f703e8cc67838485cc773d2d5fbbc55f6844c4144d32644f69e6d0005d860f6D
f72c4452b5c2bc0bf8146118cc495dcd56c62624ab38dedb3ae6ba2a0abd7a9cD
95cd2150c007f035eadda039e10d251a6fba3aab09685ce25fd54a2cf296e7b5D
a7bda59425c5271981f20e38206eeec1c614dac49d55e56b9e6f1d73803d442aD
295238e79bcc60f7da37eb6e533e39f157bbafa94bbd0724124a24661cfe67f7D
1c7643a1efa2eb22c7167b8cee83405baa0f986f5f651d3226b0e0e5a443279dD
6a423d2e3e4b4b0cd81b2df3ad65109a6c7e435cf5f4d7b65f79f895ac7dd281D
9d07ac1bce7ef2c7b3f3df53bb8c04ddc9c17ab0cc6bc18d729ee1c7f97f800aD
ee53408fcafec1e4615b6bf7b7991d0eacea72066fe43c1f01e49800d46bebceD~
4c0f98326dda59f363bb5eed1feaf1425f58894bb5fc4394be480c3fd35ff517D}
029155dd11073cb7e583700a754feaab925bd20b392240a64723cb67d3a4db5bD|
bede1b23de7ac03e2016ec4a2b4e29cd230b29837f427b14a2d8d9c06f385151
[[xLsMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*KscMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)tJqyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
IOy9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)iNy[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2MquMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
RqOMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-1\b@- Updated RHEL version
- Resolves: bz#1667549
  ([RHEL 7.7, ESXi] Rebase open-vm-tools to 10.3.0)2QmyJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")PMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
[[xUsMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*TscMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)tSqyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
IXy9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)iWy[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2VquMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2ZmyJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")YMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
[[x^sMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*]scMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)t\qyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
Iay9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)i`y[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2_quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
dMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2cmyJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")bMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
x2gquMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)xfsMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)em!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])
nunjMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])iy9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)ihy[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)
mm!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])lMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2kmyJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")
}44}2pquMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9){omJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.6d}- ovt-Remove-some-dead-code.patch [bz#2215562]
- Resolves: bz#2215562
  ([CISA Major Incident] CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [rhel-7])Gn
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.5dm@- ovt-Track-Linux-filesystem-id-FSID-for-quiesced-frozen-f.patch [bz#1880404 bz#1994590]
- Resolves: bz#1880404
  ([ESXi] [RHEL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml')
- Resolves: bz#1994590
  ([ESXi][RHEL7.9][open-vm-tools] Snapshot of the RHEL7 guest on the VMWare ESXi hypervisor failed vm hangs)
nunsMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])ry9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)iqy[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)
vm!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])uMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2tmyJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")
;44;tygMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.7d@- ovt-VGAuth-Allow-only-X509-certs-to-verify-the-SAML-toke.patch [RHEL-2413]
- Resolves: RHEL-2413
  (CVE-2023-20900 open-vm-tools: SAML token signature bypass [rhel-7.9.z]){xmJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.6d}- ovt-Remove-some-dead-code.patch [bz#2215562]
- Resolves: bz#2215562
  ([CISA Major Incident] CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [rhel-7])Gw
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.5dm@- ovt-Track-Linux-filesystem-id-FSID-for-quiesced-frozen-f.patch [bz#1880404 bz#1994590]
- Resolves: bz#1880404
  ([ESXi] [RHEL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml')
- Resolves: bz#1994590
  ([ESXi][RHEL7.9][open-vm-tools] Snapshot of the RHEL7 guest on the VMWare ESXi hypervisor failed vm hangs)
2|myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2"){Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])zy9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)
  G
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.5dm@- ovt-Track-Linux-filesystem-id-FSID-for-quiesced-frozen-f.patch [bz#1880404 bz#1994590]
- Resolves: bz#1880404
  ([ESXi] [RHEL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml')
- Resolves: bz#1994590
  ([ESXi][RHEL7.9][open-vm-tools] Snapshot of the RHEL7 guest on the VMWare ESXi hypervisor failed vm hangs)~m!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])}Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])
em_Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.8ej- ovt-Provide-alternate-method-to-allow-expected-pre-froze.patch [bz#2226921]
- Resolves: bz#2226921
  ([RHEL7.9][ESXi]Latest version of open-vm-tools breaks VM backups)tgMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.7d@- ovt-VGAuth-Allow-only-X509-certs-to-verify-the-SAML-toke.patch [RHEL-2413]
- Resolves: RHEL-2413
  (CVE-2023-20900 open-vm-tools: SAML token signature bypass [rhel-7.9.z]){mJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.6d}- ovt-Remove-some-dead-code.patch [bz#2215562]
- Resolves: bz#2215562
  ([CISA Major Incident] CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [rhel-7])
.8.qOMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-1\b@- Updated RHEL version
- Resolves: bz#1667549
  ([RHEL 7.7, ESXi] Rebase open-vm-tools to 10.3.0)|q	Miroslav Rezanina <mrezanin@redhat.com> - 10-2.5-3[{- ovt-Workaround-for-false-negative-result-when-detecting.patch [bz#1601559]
- Resolves: bz#1601559
  ([ESXi][RHEL7.6] Include new open-vm-tools patches for cloud-init to work with python-2)auQRavindra Kumar <ravindrakumar@vmware.com> - 10.2.5-2Z- Use tirpc for Fedora 28 onwards.CMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.9eC@- ovt-Don-t-accept-tokens-with-unrelated-certs.patch [RHEL-14642]
- ovt-File-descriptor-vulnerability-in-the-open-vm-tools-v.patch [RHEL-14676]
- Resolves: RHEL-14642
  (CVE-2023-34058 open-vm-tools: SAML token signature bypass [rhel-7.9.z])
- Resolves: RHEL-14676
  (CVE-2023-34059 open-vm-tools: file descriptor hijack vulnerability in the vmware-user-suid-wrapper [rhel-7.9.z])
[[x	sMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*scMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)tqyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
Iy9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)iy[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2
quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
TTqOMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-1\b@- Updated RHEL version
- Resolves: bz#1667549
  ([RHEL 7.7, ESXi] Rebase open-vm-tools to 10.3.0)|q	Miroslav Rezanina <mrezanin@redhat.com> - 10-2.5-3[{- ovt-Workaround-for-false-negative-result-when-detecting.patch [bz#1601559]
- Resolves: bz#1601559
  ([ESXi][RHEL7.6] Include new open-vm-tools patches for cloud-init to work with python-2)
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
[[xsMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*scMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)tqyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
Iy9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)iy[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
qOMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-1\b@- Updated RHEL version
- Resolves: bz#1667549
  ([RHEL 7.7, ESXi] Rebase open-vm-tools to 10.3.0)2myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
[[xsMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*scMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)tqyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
Iy9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)iy[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
!Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2 myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
[[x$sMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*#scMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)t"qyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
I'y9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)i&y[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2%quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
*Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2)myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")(Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
x2-quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)x,sMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)+m!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])
nun0Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])/y9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)i.y[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)
3m!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])2Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])21myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")
}44}26quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9){5mJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.6d}- ovt-Remove-some-dead-code.patch [bz#2215562]
- Resolves: bz#2215562
  ([CISA Major Incident] CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [rhel-7])G4
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.5dm@- ovt-Track-Linux-filesystem-id-FSID-for-quiesced-frozen-f.patch [bz#1880404 bz#1994590]
- Resolves: bz#1880404
  ([ESXi] [RHEL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml')
- Resolves: bz#1994590
  ([ESXi][RHEL7.9][open-vm-tools] Snapshot of the RHEL7 guest on the VMWare ESXi hypervisor failed vm hangs)
nun9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])8y9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)i7y[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)
<m!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z]);Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2:myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")
;44;t?gMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.7d@- ovt-VGAuth-Allow-only-X509-certs-to-verify-the-SAML-toke.patch [RHEL-2413]
- Resolves: RHEL-2413
  (CVE-2023-20900 open-vm-tools: SAML token signature bypass [rhel-7.9.z]){>mJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.6d}- ovt-Remove-some-dead-code.patch [bz#2215562]
- Resolves: bz#2215562
  ([CISA Major Incident] CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [rhel-7])G=
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.5dm@- ovt-Track-Linux-filesystem-id-FSID-for-quiesced-frozen-f.patch [bz#1880404 bz#1994590]
- Resolves: bz#1880404
  ([ESXi] [RHEL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml')
- Resolves: bz#1994590
  ([ESXi][RHEL7.9][open-vm-tools] Snapshot of the RHEL7 guest on the VMWare ESXi hypervisor failed vm hangs)
2BmyJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")AMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])@y9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)
  GE
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.5dm@- ovt-Track-Linux-filesystem-id-FSID-for-quiesced-frozen-f.patch [bz#1880404 bz#1994590]
- Resolves: bz#1880404
  ([ESXi] [RHEL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml')
- Resolves: bz#1994590
  ([ESXi][RHEL7.9][open-vm-tools] Snapshot of the RHEL7 guest on the VMWare ESXi hypervisor failed vm hangs)Dm!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])CMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])
eHm_Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.8ej- ovt-Provide-alternate-method-to-allow-expected-pre-froze.patch [bz#2226921]
- Resolves: bz#2226921
  ([RHEL7.9][ESXi]Latest version of open-vm-tools breaks VM backups)tGgMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.7d@- ovt-VGAuth-Allow-only-X509-certs-to-verify-the-SAML-toke.patch [RHEL-2413]
- Resolves: RHEL-2413
  (CVE-2023-20900 open-vm-tools: SAML token signature bypass [rhel-7.9.z]){FmJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.6d}- ovt-Remove-some-dead-code.patch [bz#2215562]
- Resolves: bz#2215562
  ([CISA Major Incident] CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [rhel-7])
.8.LqO	Miroslav Rezanina <mrezanin@redhat.com> - 10.3.0-1\b@- Updated RHEL version
- Resolves: bz#1667549
  ([RHEL 7.7, ESXi] Rebase open-vm-tools to 10.3.0)|Kq		Miroslav Rezanina <mrezanin@redhat.com> - 10-2.5-3[{- ovt-Workaround-for-false-negative-result-when-detecting.patch [bz#1601559]
- Resolves: bz#1601559
  ([ESXi][RHEL7.6] Include new open-vm-tools patches for cloud-init to work with python-2)aJuQ	Ravindra Kumar <ravindrakumar@vmware.com> - 10.2.5-2Z- Use tirpc for Fedora 28 onwards.CIMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.9eC@- ovt-Don-t-accept-tokens-with-unrelated-certs.patch [RHEL-14642]
- ovt-File-descriptor-vulnerability-in-the-open-vm-tools-v.patch [RHEL-14676]
- Resolves: RHEL-14642
  (CVE-2023-34058 open-vm-tools: SAML token signature bypass [rhel-7.9.z])
- Resolves: RHEL-14676
  (CVE-2023-34059 open-vm-tools: file descriptor hijack vulnerability in the vmware-user-suid-wrapper [rhel-7.9.z])

er+V:eD
3ae0d9e3b7846210244c8d17e6fbf04621eea150bfe308a6b23c21561cc38acdD
cd951b49a8dc85630b344b12bc84af00fff22d713c5869528aabb40dc78fa0c0D
7c4bcb2fae18cd595ec3e02100dba37726442206905efcc349d085f60cef45e3D
66aed3864f29912482e74e2a3bb2ea45d7402aa197018dc629d10fcebcd960abD
42e853b9aba262824af1f06fbf3521c29f339081059d0bab496fb26bc0f3ab17D
de3aeef4443f60aa6795ee64bd6c2d7bf33a2b82ff3b9119c255830faa49f4c4D
c567a821a6580c7066f9d12f98b47ff92838fdd821cc89005118e82149703252D
6ccf9907f4606b6cd68c6c6cb2c66c9cdf87b17f1ef8f2839dbf76b985bdf369D

3791b9ec0f2a83fb568d433ee44df76fab4784e85ba1e6da6172d66b8161511eD
6e083d21d81ff7ba6c8b92912ea5657be3fb00255a52e7d3ad7fbf5f49b55960D
d96f6359c8daf94bb109d46c6f4da10422a428e3101b641458380f3246030c16D

ffbadd5995846ef0be55a84dee1a668513bc703e46ee467cb84a4e847415cbe4D	
e1558a4ef78a248b5c220ba56ed44d6ebb4fc90cf62cd3efcf72e602bc088eb0
[[xOs	Miroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*Nsc	Miroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)tMqy	Miroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
IRy9	Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)iQy[	Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2Pqu	Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
TTUqO
Miroslav Rezanina <mrezanin@redhat.com> - 10.3.0-1\b@- Updated RHEL version
- Resolves: bz#1667549
  ([RHEL 7.7, ESXi] Rebase open-vm-tools to 10.3.0)|Tq	
Miroslav Rezanina <mrezanin@redhat.com> - 10-2.5-3[{- ovt-Workaround-for-false-negative-result-when-detecting.patch [bz#1601559]
- Resolves: bz#1601559
  ([ESXi][RHEL7.6] Include new open-vm-tools patches for cloud-init to work with python-2)S	Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
[[xXs
Miroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*Wsc
Miroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)tVqy
Miroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
I[y9
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)iZy[
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2Yqu
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
^qOMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-1\b@- Updated RHEL version
- Resolves: bz#1667549
  ([RHEL 7.7, ESXi] Rebase open-vm-tools to 10.3.0)2]my
Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")\
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
[[xasMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*`scMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)t_qyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
Idy9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)icy[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2bquMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
gMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2fmyJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")eMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
[[xjsMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)*iscMiroslav Rezanina <mrezanin@redhat.com> - 10.3.10-1]^- Rebase to 10.3.10 [bz#1725187]
- Resolves: bz#1725187
  ([ESXi][RHEL7.8 ]Rebase open-vm-tools to 10.3.10)thqyMiroslav Rezanina <mrezanin@redhat.com> - 10.3.0-2\- ovt-Enable-cloud-init-by-default-to-change-the-systemd-u.patch [bz#1662278]
- ovt-Fix-RELRO-flag.patch [bz#1678576]
- Resolves: bz#1662278
  ([ESXi][RHEL7.7]Enable cloud-init by default to change the systemd unit file vmtoolsd.service)
- Resolves: bz#1678576
  ([ESXi][RHEL7.6] Several files lost Full RELRO)
Imy9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)ily[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)2kquMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)
pMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2omyJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")nMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])
x2squ
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9)xrs
Miroslav Rezanina <mrezanin@redhat.com> - 10.3.10-2]- ovt-Fix-memory-leaks-in-vix-tools-plugin.patch [bz#1760625]
- ovt-End-VGAuth-impersonation-in-the-case-of-error.patch [bz#1760625]
- ovt-Fix-leaks-in-ListAliases-and-ListMappedAliases-9bc72.patch [bz#1760625]
- Resolves: bz#1760625
  ([ESXi][RHEL7.8]Need to backport some severe memory leak fixes from upstream)qm!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])bR0RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{0s0v0y0|0000	00000000!0$0'0*0-000306090<0?0B0E0H0L0O0R0U0X0[0^0a0d0g0j0m0p0s0v0y0‚|0Â0Ă0ł0Ƃ0ǂ0Ȃ0ɂ0ʂ0˂0̂#0͂(0΂.0ς30Ђ90тA0҂F0ӂL0ՂQ0ւW0ׂ_0؂d0قj0ڂo0ۂu0܂}0݂0ނ	0߂00Ⴟ0₿0タ"0䂿'0傿,0悿10炿70肿;0邿A0ꂿF0낿K0삿P0V0[0a0e0k0o0u0z000

nunv
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])uy9
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)ity[
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)
ym!
Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])x
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2wmy
Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")
}44}2|quMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-1^p- Rebase to 11.0.5 [bz#1806675]
- Resolves: bz#1806675
 ([ESXi][RHEL7.9]Rebase open-vm-tools to 11.0.5 for RHEL 7.9){{m
Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.6d}- ovt-Remove-some-dead-code.patch [bz#2215562]
- Resolves: bz#2215562
  ([CISA Major Incident] CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [rhel-7])Gz

Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.5dm@- ovt-Track-Linux-filesystem-id-FSID-for-quiesced-frozen-f.patch [bz#1880404 bz#1994590]
- Resolves: bz#1880404
  ([ESXi] [RHEL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml')
- Resolves: bz#1994590
  ([ESXi][RHEL7.9][open-vm-tools] Snapshot of the RHEL7 guest on the VMWare ESXi hypervisor failed vm hangs)
nunMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])~y9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)i}y[Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-2.el7^- ovt-Fix-ldconfig-call.patch [bz#1815549]
- ovt-add-appinfo-plugin.patch [bz#1809753]
- Resolves: bz#1809753
  ([ESXi][RHEL7.9]open-vm-tools add appinfo plugin patch)
- Resolves: bz#1815549
  ([ESXi][RHEL7.9]open-vm-tools reports line 1: ?ldconfig: command not found during system installation)
m!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])2myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")
;44;tgMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.7d@- ovt-VGAuth-Allow-only-X509-certs-to-verify-the-SAML-toke.patch [RHEL-2413]
- Resolves: RHEL-2413
  (CVE-2023-20900 open-vm-tools: SAML token signature bypass [rhel-7.9.z]){mJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.6d}- ovt-Remove-some-dead-code.patch [bz#2215562]
- Resolves: bz#2215562
  ([CISA Major Incident] CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [rhel-7])G
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.5dm@- ovt-Track-Linux-filesystem-id-FSID-for-quiesced-frozen-f.patch [bz#1880404 bz#1994590]
- Resolves: bz#1880404
  ([ESXi] [RHEL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml')
- Resolves: bz#1994590
  ([ESXi][RHEL7.9][open-vm-tools] Snapshot of the RHEL7 guest on the VMWare ESXi hypervisor failed vm hangs)
2myJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.2`+- ovt-Rectify-a-log-spew-in-vmsvc-logging-vmware-vmsvc-roo.patch [bz#1911853]
- Resolves: bz#1911853
  ([ESXi][RHEL7.9][ warning] [guestinfo] GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for "/", fsName: "/dev/sda2")Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.1_t@- ovt-Updated-PAM-configuration-file-to-follow-configured-.patch [bz#1840309]
- Resolves: bz#1840309
  ([ESXi][RHEL7]vmtoolsd authentication issues with ActiveDirectory (AD) [rhel-7.9.z])y9Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7^k@- ovt-Fix-a-trivial-memory-leak-in-namespacetool.c.patch [bz#1818109]
- ovt-Update-copyright-to-reflect-previous-change.patch [bz#1818109]
- Resolves: bz#1818109
  ([ESXi][RHEL7.9]open-vm-tools coverity scan issue)
  G
Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.5dm@- ovt-Track-Linux-filesystem-id-FSID-for-quiesced-frozen-f.patch [bz#1880404 bz#1994590]
- Resolves: bz#1880404
  ([ESXi] [RHEL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file 'quiesce_manifest.xml')
- Resolves: bz#1994590
  ([ESXi][RHEL7.9][open-vm-tools] Snapshot of the RHEL7 guest on the VMWare ESXi hypervisor failed vm hangs)
m!Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.4c@- ovt-Properly-check-authorization-on-incoming-guestOps-re.patch [bz#2119310]
- Resolves: bz#2119310
  (CVE-2022-31676 open-vm-tools: local root privilege escalation in the virtual machine [rhel-7.9.z])	Miroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.3`lM@- ovt-Fix-memory-leaks-in-guestInfo-diskInfo.c.patch [bz#1937420]
- Resolves: bz#1937420
  ([ESXi][RHEL7.9] Memory leak in vmtoolsd when disable-query-diskinfo is set to false [rhel-7.9.z])
em_Jon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.8ej- ovt-Provide-alternate-method-to-allow-expected-pre-froze.patch [bz#2226921]
- Resolves: bz#2226921
  ([RHEL7.9][ESXi]Latest version of open-vm-tools breaks VM backups)t
gMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.7d@- ovt-VGAuth-Allow-only-X509-certs-to-verify-the-SAML-toke.patch [RHEL-2413]
- Resolves: RHEL-2413
  (CVE-2023-20900 open-vm-tools: SAML token signature bypass [rhel-7.9.z]){mJon Maloy <jmaloy@redhat.com> - 11.0.5-3.el7_9.6d}- ovt-Remove-some-dead-code.patch [bz#2215562]
- Resolves: bz#2215562
  ([CISA Major Incident] CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [rhel-7])
8e;Sinny Kumari <skumari@redhat.com> - 3.10.0-2[~- Resolves: #1613743 - ICA Token specific des3 cbc encrypt failed - token not availableCMiroslav Rezanina <mrezanin@redhat.com> - 11.0.5-3.el7_9.9eC@- ovt-Don-t-accept-tokens-with-unrelated-certs.patch [RHEL-14642]
- ovt-File-descriptor-vulnerability-in-the-open-vm-tools-v.patch [RHEL-14676]
- Resolves: RHEL-14642
  (CVE-2023-34058 open-vm-tools: SAML token signature bypass [rhel-7.9.z])
- Resolves: RHEL-14676
  (CVE-2023-34059 open-vm-tools: file descriptor hijack vulnerability in the vmware-user-suid-wrapper [rhel-7.9.z])
;`&;tWThan Ngo <than@redhat.com> - 3.11.0-5]@- Resolves: #1756956, ICA HW token missing after the package updateoW	Than Ngo <than@redhat.com> - 3.11.0-4]@- Resolves: #1755463, EP11: Support tolerated new crypto cards,WThan Ngo <than@redhat.com> - 3.11.0-3\B@- Resolves: #1688891 - C_EncryptInit fails with CKR_KEY_TYPE_INCONSISTENT. on ep11 token when using imported RSA public keyW3Than Ngo <than@redhat.com> - 3.11.0-2\n- Resolves: #1678788 - EP11 token fails when using Strict-Session mode or VHSM-ModeWaThan Ngo <than@redhat.com> - 3.11.0-1\k- Resolves: #1063763 - opencryptoki tools should inform the user that he is not in pkcs11 group 
- Resolves: #1641027 - enhanced IBM z14 functions
- Resolves: #1641026 - support m_*Single functions from ep11 lib
- Resolves: #1641025 - rebase to 3.11.0
- Resolves: #1519386 - use CPACF hashes in ep11 token
- Resolves: #1373833 - lock file directory is %ghost now
=Mq=WaThan Ngo <than@redhat.com> - 3.11.0-1\k- Resolves: #1063763 - opencryptoki tools should inform the user that he is not in pkcs11 group 
- Resolves: #1641027 - enhanced IBM z14 functions
- Resolves: #1641026 - support m_*Single functions from ep11 lib
- Resolves: #1641025 - rebase to 3.11.0
- Resolves: #1519386 - use CPACF hashes in ep11 token
- Resolves: #1373833 - lock file directory is %ghost nowe;Sinny Kumari <skumari@redhat.com> - 3.10.0-2[~- Resolves: #1613743 - ICA Token specific des3 cbc encrypt failed - token not availablehW}Than Ngo <than@redhat.com> - 3.12.1-3_q@- Resolves: #1883185, opencryptoki - do_DeriveDHKey FAILlWThan Ngo <than@redhat.com> - 3.12.1-2]q- Resolves: #1782444, EP11: Fix EC-uncompress buffer lengthUWWThan Ngo <than@redhat.com> - 3.12.1-1]߶- Related: #1770883, rebase to 3.12.1VWYThan Ngo <than@redhat.com> - 3.12.0-1]ʞ- Resolves: #1770883, rebase to 3.12.0
LwS(Lh#W}Than Ngo <than@redhat.com> - 3.12.1-3_q@- Resolves: #1883185, opencryptoki - do_DeriveDHKey FAILl"WThan Ngo <than@redhat.com> - 3.12.1-2]q- Resolves: #1782444, EP11: Fix EC-uncompress buffer lengthU!WWThan Ngo <than@redhat.com> - 3.12.1-1]߶- Related: #1770883, rebase to 3.12.1V WYThan Ngo <than@redhat.com> - 3.12.0-1]ʞ- Resolves: #1770883, rebase to 3.12.0tWThan Ngo <than@redhat.com> - 3.11.0-5]@- Resolves: #1756956, ICA HW token missing after the package updateoW	Than Ngo <than@redhat.com> - 3.11.0-4]@- Resolves: #1755463, EP11: Support tolerated new crypto cards,WThan Ngo <than@redhat.com> - 3.11.0-3\B@- Resolves: #1688891 - C_EncryptInit fails with CKR_KEY_TYPE_INCONSISTENT. on ep11 token when using imported RSA public keyW3Than Ngo <than@redhat.com> - 3.11.0-2\n- Resolves: #1678788 - EP11 token fails when using Strict-Session mode or VHSM-Mode
lCo(W	Than Ngo <than@redhat.com> - 3.11.0-4]@- Resolves: #1755463, EP11: Support tolerated new crypto cards,'WThan Ngo <than@redhat.com> - 3.11.0-3\B@- Resolves: #1688891 - C_EncryptInit fails with CKR_KEY_TYPE_INCONSISTENT. on ep11 token when using imported RSA public key&W3Than Ngo <than@redhat.com> - 3.11.0-2\n- Resolves: #1678788 - EP11 token fails when using Strict-Session mode or VHSM-Mode%WaThan Ngo <than@redhat.com> - 3.11.0-1\k- Resolves: #1063763 - opencryptoki tools should inform the user that he is not in pkcs11 group 
- Resolves: #1641027 - enhanced IBM z14 functions
- Resolves: #1641026 - support m_*Single functions from ep11 lib
- Resolves: #1641025 - rebase to 3.11.0
- Resolves: #1519386 - use CPACF hashes in ep11 token
- Resolves: #1373833 - lock file directory is %ghost now$e;Sinny Kumari <skumari@redhat.com> - 3.10.0-2[~- Resolves: #1613743 - ICA Token specific des3 cbc encrypt failed - token not available
e.ee.e;Sinny Kumari <skumari@redhat.com> - 3.10.0-2[~- Resolves: #1613743 - ICA Token specific des3 cbc encrypt failed - token not availableh-W}Than Ngo <than@redhat.com> - 3.12.1-3_q@- Resolves: #1883185, opencryptoki - do_DeriveDHKey FAILl,WThan Ngo <than@redhat.com> - 3.12.1-2]q- Resolves: #1782444, EP11: Fix EC-uncompress buffer lengthU+WWThan Ngo <than@redhat.com> - 3.12.1-1]߶- Related: #1770883, rebase to 3.12.1V*WYThan Ngo <than@redhat.com> - 3.12.0-1]ʞ- Resolves: #1770883, rebase to 3.12.0t)WThan Ngo <than@redhat.com> - 3.11.0-5]@- Resolves: #1756956, ICA HW token missing after the package update
;`&;t3WThan Ngo <than@redhat.com> - 3.11.0-5]@- Resolves: #1756956, ICA HW token missing after the package updateo2W	Than Ngo <than@redhat.com> - 3.11.0-4]@- Resolves: #1755463, EP11: Support tolerated new crypto cards,1WThan Ngo <than@redhat.com> - 3.11.0-3\B@- Resolves: #1688891 - C_EncryptInit fails with CKR_KEY_TYPE_INCONSISTENT. on ep11 token when using imported RSA public key0W3Than Ngo <than@redhat.com> - 3.11.0-2\n- Resolves: #1678788 - EP11 token fails when using Strict-Session mode or VHSM-Mode/WaThan Ngo <than@redhat.com> - 3.11.0-1\k- Resolves: #1063763 - opencryptoki tools should inform the user that he is not in pkcs11 group 
- Resolves: #1641027 - enhanced IBM z14 functions
- Resolves: #1641026 - support m_*Single functions from ep11 lib
- Resolves: #1641025 - rebase to 3.11.0
- Resolves: #1519386 - use CPACF hashes in ep11 token
- Resolves: #1373833 - lock file directory is %ghost now
=Mq=9WaThan Ngo <than@redhat.com> - 3.11.0-1\k- Resolves: #1063763 - opencryptoki tools should inform the user that he is not in pkcs11 group 
- Resolves: #1641027 - enhanced IBM z14 functions
- Resolves: #1641026 - support m_*Single functions from ep11 lib
- Resolves: #1641025 - rebase to 3.11.0
- Resolves: #1519386 - use CPACF hashes in ep11 token
- Resolves: #1373833 - lock file directory is %ghost now8e;Sinny Kumari <skumari@redhat.com> - 3.10.0-2[~- Resolves: #1613743 - ICA Token specific des3 cbc encrypt failed - token not availableh7W}Than Ngo <than@redhat.com> - 3.12.1-3_q@- Resolves: #1883185, opencryptoki - do_DeriveDHKey FAILl6WThan Ngo <than@redhat.com> - 3.12.1-2]q- Resolves: #1782444, EP11: Fix EC-uncompress buffer lengthU5WWThan Ngo <than@redhat.com> - 3.12.1-1]߶- Related: #1770883, rebase to 3.12.1V4WYThan Ngo <than@redhat.com> - 3.12.0-1]ʞ- Resolves: #1770883, rebase to 3.12.0
LwS(LhAW}Than Ngo <than@redhat.com> - 3.12.1-3_q@- Resolves: #1883185, opencryptoki - do_DeriveDHKey FAILl@WThan Ngo <than@redhat.com> - 3.12.1-2]q- Resolves: #1782444, EP11: Fix EC-uncompress buffer lengthU?WWThan Ngo <than@redhat.com> - 3.12.1-1]߶- Related: #1770883, rebase to 3.12.1V>WYThan Ngo <than@redhat.com> - 3.12.0-1]ʞ- Resolves: #1770883, rebase to 3.12.0t=WThan Ngo <than@redhat.com> - 3.11.0-5]@- Resolves: #1756956, ICA HW token missing after the package updateo<W	Than Ngo <than@redhat.com> - 3.11.0-4]@- Resolves: #1755463, EP11: Support tolerated new crypto cards,;WThan Ngo <than@redhat.com> - 3.11.0-3\B@- Resolves: #1688891 - C_EncryptInit fails with CKR_KEY_TYPE_INCONSISTENT. on ep11 token when using imported RSA public key:W3Than Ngo <than@redhat.com> - 3.11.0-2\n- Resolves: #1678788 - EP11 token fails when using Strict-Session mode or VHSM-Mode
lCoFW	Than Ngo <than@redhat.com> - 3.11.0-4]@- Resolves: #1755463, EP11: Support tolerated new crypto cards,EWThan Ngo <than@redhat.com> - 3.11.0-3\B@- Resolves: #1688891 - C_EncryptInit fails with CKR_KEY_TYPE_INCONSISTENT. on ep11 token when using imported RSA public keyDW3Than Ngo <than@redhat.com> - 3.11.0-2\n- Resolves: #1678788 - EP11 token fails when using Strict-Session mode or VHSM-ModeCWaThan Ngo <than@redhat.com> - 3.11.0-1\k- Resolves: #1063763 - opencryptoki tools should inform the user that he is not in pkcs11 group 
- Resolves: #1641027 - enhanced IBM z14 functions
- Resolves: #1641026 - support m_*Single functions from ep11 lib
- Resolves: #1641025 - rebase to 3.11.0
- Resolves: #1519386 - use CPACF hashes in ep11 token
- Resolves: #1373833 - lock file directory is %ghost nowBe;Sinny Kumari <skumari@redhat.com> - 3.10.0-2[~- Resolves: #1613743 - ICA Token specific des3 cbc encrypt failed - token not available
e.eeLe;Sinny Kumari <skumari@redhat.com> - 3.10.0-2[~- Resolves: #1613743 - ICA Token specific des3 cbc encrypt failed - token not availablehKW}Than Ngo <than@redhat.com> - 3.12.1-3_q@- Resolves: #1883185, opencryptoki - do_DeriveDHKey FAILlJWThan Ngo <than@redhat.com> - 3.12.1-2]q- Resolves: #1782444, EP11: Fix EC-uncompress buffer lengthUIWWThan Ngo <than@redhat.com> - 3.12.1-1]߶- Related: #1770883, rebase to 3.12.1VHWYThan Ngo <than@redhat.com> - 3.12.0-1]ʞ- Resolves: #1770883, rebase to 3.12.0tGWThan Ngo <than@redhat.com> - 3.11.0-5]@- Resolves: #1756956, ICA HW token missing after the package update

er+V:eD"
35add167f7cb884e0fa8709237307f4caa3297832e3165d1530bcf474ed45e74D!
a41884a9bea64c478434afa440f59ad7fb2b3251861261bfa51c4a6142be01f3D 
7dc75ff8c8c8c6b5a6b9fc8c0b75b9ddaaaff8045fabbd17663a334c27c8b9cbD
4d12827b417a44adfb6029689a3750767d051d27bb01400addcf87233d9c73aaD
912bd6993c1df63e3c9381201d80fe8178c75ff27aeb3b45999e28983222ff86D
f42f1e28a26e049582540bf27d99e95a1b241c2fc2e9faf3b2165ac8dbdd35e8D
2ad84664179e15d935155fba6042722c65d3395b14c39b9f1b0c8766d4fb802bD
3f3deff3566c606e953d135ea14e38e49de5f579a679c901193204c07cb123f1D
36621778bbfe07d63cf5e8b83b198171e5f1bcc467910e9ea517faecfc1e27faD
85d24ca3ceecf07ce09d89a8ea7abcb5f605c7de3bd556f87b0654c517fd5759D
839520c8f5c973a577f0bb417d4afcf5cee1ae5ae2f72e64134b38bae1468c0cD
ee16939ba598d58caca0f792ce6324cd0251c779d1d37874af442d8cba4c2f23D
2aabb9b7280de41a29a8a6d2e099490ab2248876bb0e907b1ac88eee12a34093
;`&;tQWThan Ngo <than@redhat.com> - 3.11.0-5]@- Resolves: #1756956, ICA HW token missing after the package updateoPW	Than Ngo <than@redhat.com> - 3.11.0-4]@- Resolves: #1755463, EP11: Support tolerated new crypto cards,OWThan Ngo <than@redhat.com> - 3.11.0-3\B@- Resolves: #1688891 - C_EncryptInit fails with CKR_KEY_TYPE_INCONSISTENT. on ep11 token when using imported RSA public keyNW3Than Ngo <than@redhat.com> - 3.11.0-2\n- Resolves: #1678788 - EP11 token fails when using Strict-Session mode or VHSM-ModeMWaThan Ngo <than@redhat.com> - 3.11.0-1\k- Resolves: #1063763 - opencryptoki tools should inform the user that he is not in pkcs11 group 
- Resolves: #1641027 - enhanced IBM z14 functions
- Resolves: #1641026 - support m_*Single functions from ep11 lib
- Resolves: #1641025 - rebase to 3.11.0
- Resolves: #1519386 - use CPACF hashes in ep11 token
- Resolves: #1373833 - lock file directory is %ghost now
=Mq=WWaThan Ngo <than@redhat.com> - 3.11.0-1\k- Resolves: #1063763 - opencryptoki tools should inform the user that he is not in pkcs11 group 
- Resolves: #1641027 - enhanced IBM z14 functions
- Resolves: #1641026 - support m_*Single functions from ep11 lib
- Resolves: #1641025 - rebase to 3.11.0
- Resolves: #1519386 - use CPACF hashes in ep11 token
- Resolves: #1373833 - lock file directory is %ghost nowVe;Sinny Kumari <skumari@redhat.com> - 3.10.0-2[~- Resolves: #1613743 - ICA Token specific des3 cbc encrypt failed - token not availablehUW}Than Ngo <than@redhat.com> - 3.12.1-3_q@- Resolves: #1883185, opencryptoki - do_DeriveDHKey FAILlTWThan Ngo <than@redhat.com> - 3.12.1-2]q- Resolves: #1782444, EP11: Fix EC-uncompress buffer lengthUSWWThan Ngo <than@redhat.com> - 3.12.1-1]߶- Related: #1770883, rebase to 3.12.1VRWYThan Ngo <than@redhat.com> - 3.12.0-1]ʞ- Resolves: #1770883, rebase to 3.12.0
LwS(Lh_W}Than Ngo <than@redhat.com> - 3.12.1-3_q@- Resolves: #1883185, opencryptoki - do_DeriveDHKey FAILl^WThan Ngo <than@redhat.com> - 3.12.1-2]q- Resolves: #1782444, EP11: Fix EC-uncompress buffer lengthU]WWThan Ngo <than@redhat.com> - 3.12.1-1]߶- Related: #1770883, rebase to 3.12.1V\WYThan Ngo <than@redhat.com> - 3.12.0-1]ʞ- Resolves: #1770883, rebase to 3.12.0t[WThan Ngo <than@redhat.com> - 3.11.0-5]@- Resolves: #1756956, ICA HW token missing after the package updateoZW	Than Ngo <than@redhat.com> - 3.11.0-4]@- Resolves: #1755463, EP11: Support tolerated new crypto cards,YWThan Ngo <than@redhat.com> - 3.11.0-3\B@- Resolves: #1688891 - C_EncryptInit fails with CKR_KEY_TYPE_INCONSISTENT. on ep11 token when using imported RSA public keyXW3Than Ngo <than@redhat.com> - 3.11.0-2\n- Resolves: #1678788 - EP11 token fails when using Strict-Session mode or VHSM-Mode
lCodW	Than Ngo <than@redhat.com> - 3.11.0-4]@- Resolves: #1755463, EP11: Support tolerated new crypto cards,cWThan Ngo <than@redhat.com> - 3.11.0-3\B@- Resolves: #1688891 - C_EncryptInit fails with CKR_KEY_TYPE_INCONSISTENT. on ep11 token when using imported RSA public keybW3Than Ngo <than@redhat.com> - 3.11.0-2\n- Resolves: #1678788 - EP11 token fails when using Strict-Session mode or VHSM-ModeaWaThan Ngo <than@redhat.com> - 3.11.0-1\k- Resolves: #1063763 - opencryptoki tools should inform the user that he is not in pkcs11 group 
- Resolves: #1641027 - enhanced IBM z14 functions
- Resolves: #1641026 - support m_*Single functions from ep11 lib
- Resolves: #1641025 - rebase to 3.11.0
- Resolves: #1519386 - use CPACF hashes in ep11 token
- Resolves: #1373833 - lock file directory is %ghost now`e;Sinny Kumari <skumari@redhat.com> - 3.10.0-2[~- Resolves: #1613743 - ICA Token specific des3 cbc encrypt failed - token not available
e.eeje;Sinny Kumari <skumari@redhat.com> - 3.10.0-2[~- Resolves: #1613743 - ICA Token specific des3 cbc encrypt failed - token not availablehiW}Than Ngo <than@redhat.com> - 3.12.1-3_q@- Resolves: #1883185, opencryptoki - do_DeriveDHKey FAILlhWThan Ngo <than@redhat.com> - 3.12.1-2]q- Resolves: #1782444, EP11: Fix EC-uncompress buffer lengthUgWWThan Ngo <than@redhat.com> - 3.12.1-1]߶- Related: #1770883, rebase to 3.12.1VfWYThan Ngo <than@redhat.com> - 3.12.0-1]ʞ- Resolves: #1770883, rebase to 3.12.0teWThan Ngo <than@redhat.com> - 3.11.0-5]@- Resolves: #1756956, ICA HW token missing after the package update
;`&;toWThan Ngo <than@redhat.com> - 3.11.0-5]@- Resolves: #1756956, ICA HW token missing after the package updateonW	Than Ngo <than@redhat.com> - 3.11.0-4]@- Resolves: #1755463, EP11: Support tolerated new crypto cards,mWThan Ngo <than@redhat.com> - 3.11.0-3\B@- Resolves: #1688891 - C_EncryptInit fails with CKR_KEY_TYPE_INCONSISTENT. on ep11 token when using imported RSA public keylW3Than Ngo <than@redhat.com> - 3.11.0-2\n- Resolves: #1678788 - EP11 token fails when using Strict-Session mode or VHSM-ModekWaThan Ngo <than@redhat.com> - 3.11.0-1\k- Resolves: #1063763 - opencryptoki tools should inform the user that he is not in pkcs11 group 
- Resolves: #1641027 - enhanced IBM z14 functions
- Resolves: #1641026 - support m_*Single functions from ep11 lib
- Resolves: #1641025 - rebase to 3.11.0
- Resolves: #1519386 - use CPACF hashes in ep11 token
- Resolves: #1373833 - lock file directory is %ghost now
=Mq=uWaThan Ngo <than@redhat.com> - 3.11.0-1\k- Resolves: #1063763 - opencryptoki tools should inform the user that he is not in pkcs11 group 
- Resolves: #1641027 - enhanced IBM z14 functions
- Resolves: #1641026 - support m_*Single functions from ep11 lib
- Resolves: #1641025 - rebase to 3.11.0
- Resolves: #1519386 - use CPACF hashes in ep11 token
- Resolves: #1373833 - lock file directory is %ghost nowte;Sinny Kumari <skumari@redhat.com> - 3.10.0-2[~- Resolves: #1613743 - ICA Token specific des3 cbc encrypt failed - token not availablehsW}Than Ngo <than@redhat.com> - 3.12.1-3_q@- Resolves: #1883185, opencryptoki - do_DeriveDHKey FAILlrWThan Ngo <than@redhat.com> - 3.12.1-2]q- Resolves: #1782444, EP11: Fix EC-uncompress buffer lengthUqWWThan Ngo <than@redhat.com> - 3.12.1-1]߶- Related: #1770883, rebase to 3.12.1VpWYThan Ngo <than@redhat.com> - 3.12.0-1]ʞ- Resolves: #1770883, rebase to 3.12.0
LwS(Lh}W}Than Ngo <than@redhat.com> - 3.12.1-3_q@- Resolves: #1883185, opencryptoki - do_DeriveDHKey FAILl|WThan Ngo <than@redhat.com> - 3.12.1-2]q- Resolves: #1782444, EP11: Fix EC-uncompress buffer lengthU{WWThan Ngo <than@redhat.com> - 3.12.1-1]߶- Related: #1770883, rebase to 3.12.1VzWYThan Ngo <than@redhat.com> - 3.12.0-1]ʞ- Resolves: #1770883, rebase to 3.12.0tyWThan Ngo <than@redhat.com> - 3.11.0-5]@- Resolves: #1756956, ICA HW token missing after the package updateoxW	Than Ngo <than@redhat.com> - 3.11.0-4]@- Resolves: #1755463, EP11: Support tolerated new crypto cards,wWThan Ngo <than@redhat.com> - 3.11.0-3\B@- Resolves: #1688891 - C_EncryptInit fails with CKR_KEY_TYPE_INCONSISTENT. on ep11 token when using imported RSA public keyvW3Than Ngo <than@redhat.com> - 3.11.0-2\n- Resolves: #1678788 - EP11 token fails when using Strict-Session mode or VHSM-Mode
lCoW	Than Ngo <than@redhat.com> - 3.11.0-4]@- Resolves: #1755463, EP11: Support tolerated new crypto cards,WThan Ngo <than@redhat.com> - 3.11.0-3\B@- Resolves: #1688891 - C_EncryptInit fails with CKR_KEY_TYPE_INCONSISTENT. on ep11 token when using imported RSA public keyW3Than Ngo <than@redhat.com> - 3.11.0-2\n- Resolves: #1678788 - EP11 token fails when using Strict-Session mode or VHSM-ModeWaThan Ngo <than@redhat.com> - 3.11.0-1\k- Resolves: #1063763 - opencryptoki tools should inform the user that he is not in pkcs11 group 
- Resolves: #1641027 - enhanced IBM z14 functions
- Resolves: #1641026 - support m_*Single functions from ep11 lib
- Resolves: #1641025 - rebase to 3.11.0
- Resolves: #1519386 - use CPACF hashes in ep11 token
- Resolves: #1373833 - lock file directory is %ghost now~e;Sinny Kumari <skumari@redhat.com> - 3.10.0-2[~- Resolves: #1613743 - ICA Token specific des3 cbc encrypt failed - token not available
e.ee	c%Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)c-Matus Honek <mhonek@redhat.com> - 2.4.44-13Zq- MozNSS Compat. Layer: fix recursive directory deletion (#1516409)
- MozNSS Compat. Layer: fix PIN disclaimer not always shown (#1516409)
- MozNSS Compat. Layer: fix incorrect parsing of CACertDir (#1533955)hW}Than Ngo <than@redhat.com> - 3.12.1-3_q@- Resolves: #1883185, opencryptoki - do_DeriveDHKey FAILlWThan Ngo <than@redhat.com> - 3.12.1-2]q- Resolves: #1782444, EP11: Fix EC-uncompress buffer lengthUWWThan Ngo <than@redhat.com> - 3.12.1-1]߶- Related: #1770883, rebase to 3.12.1VWYThan Ngo <than@redhat.com> - 3.12.0-1]ʞ- Resolves: #1770883, rebase to 3.12.0tWThan Ngo <than@redhat.com> - 3.11.0-5]@- Resolves: #1756956, ICA HW token missing after the package update
i=c!Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)
c+Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(coMatus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'cmMatus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)
cCMatus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)
+c%Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)c-Matus Honek <mhonek@redhat.com> - 2.4.44-13Zq- MozNSS Compat. Layer: fix recursive directory deletion (#1516409)
- MozNSS Compat. Layer: fix PIN disclaimer not always shown (#1516409)
- MozNSS Compat. Layer: fix incorrect parsing of CACertDir (#1533955)"mYSimon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(coMatus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}cMatus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)
i=c!Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)c+Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(coMatus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'cmMatus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)cCMatus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)
+cCMatus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)c%Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)"mYSimon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(coMatus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}cMatus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)
'}"cMatus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)!c!Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922) c+Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(coMatus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'cmMatus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)
S*'cCMatus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)&c%Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)~%mSimon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)"$mYSimon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(#coMatus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)
'},cMatus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)+c!Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)*c+Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)()coMatus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'(cmMatus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)
gS*g'1cm Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)0cC Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)~/mSimon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)".mYSimon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(-coMatus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)
mSBm"7mY Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(6co Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}5c Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)4c! Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)3c+ Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(2co Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)
~x';cm!Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451):cC!Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)9m Simon Pichugin <spichugi@redhat.com> - 2.4.44-25a@- Fix CVE-2020-25709 openldap: assertion failure in Certificate List syntax validation (#2040539)
- Fix CVE-2020-25710 openldap: assertion failure in CSN normalization with invalid input (#2040538)~8m Simon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)
mSBm"AmY!Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(@co!Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}?c!Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)>c!!Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)=c+!Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(<co!Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)
M~xlMFcC"Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)Ec%"Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)Dc-"Matus Honek <mhonek@redhat.com> - 2.4.44-13Zq- MozNSS Compat. Layer: fix recursive directory deletion (#1516409)
- MozNSS Compat. Layer: fix PIN disclaimer not always shown (#1516409)
- MozNSS Compat. Layer: fix incorrect parsing of CACertDir (#1533955)Cm!Simon Pichugin <spichugi@redhat.com> - 2.4.44-25a@- Fix CVE-2020-25709 openldap: assertion failure in Certificate List syntax validation (#2040539)
- Fix CVE-2020-25710 openldap: assertion failure in CSN normalization with invalid input (#2040538)~Bm!Simon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)
'}Kc"Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)Jc!"Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)Ic+"Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(Hco"Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'Gcm"Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)
aS$a'Pcm#Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)OcC#Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)Nc%#Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)"MmY"Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(Lco"Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)

er+V:eD/
2a6f1dc296b8103e565b9c2b18d2f04ed098a133f239f299f974b5430b5cda97D.
5ab1da2e283d1df09cccde7a8681441b9f5b20a027b34d367ff19dda331235d5D-
ecbcdfc04b53ea64ad8edb3e42271b75385cb3a6087173d58c0d0e9ac5074c56D,
8f4f01e9c17c3579c8a8e8757582b5911c301c9f5219d0fa56b868db7964640fD+
51bd5d48aea076879005b6bb6ecd6f14aa7212f61f98a0ad49b0b9379badb17aD*
39ac6caf2f744acfdea88f8f05d08f1cc0f3ead1b5cc458a36db4d7d5553972fD)
5f4ca284587783143968fcdf3917477a4d6a68b7e9106aa1c96b92591e63a261D(
9711433d3deaee69fd66f5b86d352d4250222cc0624b6a64b1cab5215d69348bD'
ae3c48f21e37c807df89c63a1fa1216f44279908239b46e4dc5f7fc63160d0ddD&
88e20a1e34cd524371d77d54b3e1c9679b5fc0a76238556241eba29703e64e10D%
0b29c214b8a3ff37cfcb010079194019a3d4b2e97d32adcd0571daa7b2572234D$
bc3ad50d23ee3913b90b02ecb46fe4404d8bee5abbbce1bcd8310b15ba6abf16D#
cc0d2cbf6bd6a4619b82b4666f297b6d0d894f6e665d587919aeb24e013118a5
mSBm"VmY#Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(Uco#Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}Tc#Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)Sc!#Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)Rc+#Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(Qco#Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)
~[c+$Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(Zco$Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'Ycm$Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)XcC$Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)~Wm#Simon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)
zL#am$Simon Pichugin <spichugi@redhat.com> - 2.4.44-25a@- Fix CVE-2020-25709 openldap: assertion failure in Certificate List syntax validation (#2040539)
- Fix CVE-2020-25710 openldap: assertion failure in CSN normalization with invalid input (#2040538)~`m$Simon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)"_mY$Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(^co$Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}]c$Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)\c!$Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)
l'ecm%Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)dcC%Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)cc%%Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)bc-%Matus Honek <mhonek@redhat.com> - 2.4.44-13Zq- MozNSS Compat. Layer: fix recursive directory deletion (#1516409)
- MozNSS Compat. Layer: fix PIN disclaimer not always shown (#1516409)
- MozNSS Compat. Layer: fix incorrect parsing of CACertDir (#1533955)
mSBm"kmY%Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(jco%Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}ic%Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)hc!%Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)gc+%Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(fco%Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)
l'ocm&Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)ncC&Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)mc%&Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)lc-&Matus Honek <mhonek@redhat.com> - 2.4.44-13Zq- MozNSS Compat. Layer: fix recursive directory deletion (#1516409)
- MozNSS Compat. Layer: fix PIN disclaimer not always shown (#1516409)
- MozNSS Compat. Layer: fix incorrect parsing of CACertDir (#1533955)
mSBm"umY&Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(tco&Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}sc&Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)rc!&Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)qc+&Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(pco&Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)
}x}zc+'Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(yco'Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'xcm'Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)wcC'Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)vc%'Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)
zL#c%(Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)~m'Simon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)"~mY'Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(}co'Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}|c'Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184){c!'Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)
i=c!(Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)c+(Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(co(Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'cm(Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)cC(Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)
+
cC)Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)~	m(Simon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)"mY(Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(co(Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}c(Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)
'}c)Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)c!)Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)
c+)Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(co)Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'cm)Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)
S*$cC*Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)m)Simon Pichugin <spichugi@redhat.com> - 2.4.44-25a@- Fix CVE-2020-25709 openldap: assertion failure in Certificate List syntax validation (#2040539)
- Fix CVE-2020-25710 openldap: assertion failure in CSN normalization with invalid input (#2040538)~m)Simon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)"mY)Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(co)Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)
'}c*Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)c!*Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)c+*Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(co*Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'cm*Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)
S*$c-+Matus Honek <mhonek@redhat.com> - 2.4.44-13Zq- MozNSS Compat. Layer: fix recursive directory deletion (#1516409)
- MozNSS Compat. Layer: fix PIN disclaimer not always shown (#1516409)
- MozNSS Compat. Layer: fix incorrect parsing of CACertDir (#1533955)m*Simon Pichugin <spichugi@redhat.com> - 2.4.44-25a@- Fix CVE-2020-25709 openldap: assertion failure in Certificate List syntax validation (#2040539)
- Fix CVE-2020-25710 openldap: assertion failure in CSN normalization with invalid input (#2040538)~m*Simon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)"mY*Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(co*Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)
}x}#c++Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)("co+Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'!cm+Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451) cC+Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)c%+Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)
zL)cC,Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)(c%,Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)"'mY+Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(&co+Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}%c+Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)$c!+Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)
'}.c,Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)-c!,Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922),c+,Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(+co,Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'*cm,Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)
gS*g'3cm-Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)2cC-Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)~1m,Simon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)"0mY,Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(/co,Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)
mSBm"9mY-Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(8co-Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}7c-Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)6c!-Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)5c+-Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(4co-Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)
M~xlM>cC.Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)=c%.Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)<c-.Matus Honek <mhonek@redhat.com> - 2.4.44-13Zq- MozNSS Compat. Layer: fix recursive directory deletion (#1516409)
- MozNSS Compat. Layer: fix PIN disclaimer not always shown (#1516409)
- MozNSS Compat. Layer: fix incorrect parsing of CACertDir (#1533955);m-Simon Pichugin <spichugi@redhat.com> - 2.4.44-25a@- Fix CVE-2020-25709 openldap: assertion failure in Certificate List syntax validation (#2040539)
- Fix CVE-2020-25710 openldap: assertion failure in CSN normalization with invalid input (#2040538)~:m-Simon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)
'}Cc.Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)Bc!.Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)Ac+.Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(@co.Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'?cm.Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)
aS$a'Hcm/Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)GcC/Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)Fc%/Matus Honek <mhonek@redhat.com> - 2.4.44-14Z@- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)"EmY.Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(Dco.Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)
mSBm"NmY/Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(Mco/Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}Lc/Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)Kc!/Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)Jc+/Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(Ico/Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)
~Sc+0Matus Honek <mhonek@redhat.com> - 2.4.44-19[r@- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)(Rco0Matus Honek <mhonek@redhat.com> - 2.4.44-18[+A- MozNSS Compat. Layer: Make log messages more clear (#1543955)
- Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)'Qcm0Matus Honek <mhonek@redhat.com> - 2.4.44-17[+@- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549)
- Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382)
- MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)PcC0Matus Honek <mhonek@redhat.com> - 2.4.44-16Zľ@- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)~Om/Simon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)

er+V:eD<
9006cdd20e1088f1fdd49320df4c8447cf22d2feb90151205e9288920768b599D;
02ddd2f4ddbeafacbe9cdecd7071ce4d21239067950fce14f915e65b88e056b0D:
2eb468f0d5d765cc3f6897270a1abde77e76fa366c6ca1473a03ee15bc47748dD9
5bae0cc126abb5ec4f6861872ef8dca8ae25c3d7c3bc9d186d3450e8e5f8cb46D8
a979c38358d8c02e4590026e728a88db7c7b8f5f4eb9e080f77812bbe26a018bD7
a4d1e02c406da42d667a511a3172beae376e11ced63bb428e16894a66b914592D6
a35e2c0d9f1e86c4ba70006c038141ae46bea796e4e9375fff2d525742bf85d7D5
24b0fb3cf77c1414e8d4be523ab73cb876049596622b95f63dc9c7aa989b8066D4
ce586e3bad67654fe73ef5a5f9ade5281e7611c7839e8ee28c76f1f48753cbfaD3
498b3c4385806f5535a6ebd9a444db2e30938bba2f9b1f553b35189edc73b0e4D2
1e8f0a4b4a44bd6aebb338ec755620508f9ad59babc55b9832396a5439cbf583D1
bb889461e56e1855ace7437bb01465dd50bda036d71e6dc023139aefdb0ee98eD0
8c1a2436bb9993077d1787d888e9de96eb7d1ce37e361e8ed8f64c131ab0b58e
zL#Ym0Simon Pichugin <spichugi@redhat.com> - 2.4.44-25a@- Fix CVE-2020-25709 openldap: assertion failure in Certificate List syntax validation (#2040539)
- Fix CVE-2020-25710 openldap: assertion failure in CSN normalization with invalid input (#2040538)~Xm0Simon Pichugin <spichugi@redhat.com> - 2.4.44-24a
@- CLDAP ldap_result hangs if nobody listens on the port (#1989919)"WmY0Simon Pichugin <spichugi@redhat.com> - 2.4.44-23_@- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)(Vco0Matus Honek <mhonek@redhat.com> - 2.4.44-22^ۅ@- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)}Uc0Matus Honek <mhonek@redhat.com> - 2.4.44-21\@- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)Tc!0Matus Honek <mhonek@redhat.com> - 2.4.44-20[{- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)
u]ys1Jakub Jelen <jjelen@redhat.com> - 0.16.0-8.20170227gitZL- Copy labels from certificate (#1448555)
- Avoid infinite loop in CAC driver when reading non-CAC cards (#1473335)
- Properly parse Simple TLV structures in CAC driver (#1473418)\yC1Jakub Jelen <jjelen@redhat.com> - 0.16.0-7.20170227gitZ@- Fix issues reported by Coverity
- Use upstream accepted fix for CAC Alt tokens (#1473418)[y11Jakub Jelen <jjelen@redhat.com> - 0.16.0-6.20170227gitYZ@- Use label from certificate DN if there is none (#1448555)
- Use Cardholder name in the token label (#1449740)
- Avoid infinite loop when reading CAC cards (#1473335)
- Workaround for CAC Alt tokens (#1473418)cZyQ1Jakub Jelen <jjelen@redhat.com> - 0.16.0-5.20170227gitY- Add missing pkcs11-switch script
v`a
1Jakub Jelen <jjelen@redhat.com> - 0.19.0-1\\- Rebase to new upstream release (#1656791)
  - Add Support for HID Crescendo 144K (#1612372)
  - Add Support for CAC Alt tokens (#1645581)
  - Fix usage detection from certificates (#1672898)
  - Fix security issues:
    - CVE-2018-16391
    - CVE-2018-16392
    - CVE-2018-16393
    - CVE-2018-16418
    - CVE-2018-16419
    - CVE-2018-16420
    - CVE-2018-16421
    - CVE-2018-16422
    - CVE-2018-16423
    - CVE-2018-16426
    - CVE-2018-16427_{1Jakub Jelen <jjelen@redhat.com> - 0.16.0-10.20170227git[;e@- Improve support for ECC-enabled CardOS 5.3 card (#1562277)p^yi1Jakub Jelen <jjelen@redhat.com> - 0.16.0-9.20170227git[(@- make ECPoint behavior standards compliant by default (#1562572)
- allow mechanism to be specified in hexadecimal (#1562572)
- Disable pinpad by default (#1547117, #1547744)
}@'fyC2Jakub Jelen <jjelen@redhat.com> - 0.16.0-7.20170227gitZ@- Fix issues reported by Coverity
- Use upstream accepted fix for CAC Alt tokens (#1473418)ey12Jakub Jelen <jjelen@redhat.com> - 0.16.0-6.20170227gitYZ@- Use label from certificate DN if there is none (#1448555)
- Use Cardholder name in the token label (#1449740)
- Avoid infinite loop when reading CAC cards (#1473335)
- Workaround for CAC Alt tokens (#1473418)cdyQ2Jakub Jelen <jjelen@redhat.com> - 0.16.0-5.20170227gitY- Add missing pkcs11-switch scriptgcaq1Jakub Jelen <jjelen@redhat.com> - 0.19.0-4_u@- Support PIN change for HID Alt tokens (#1893856)gbaq1Jakub Jelen <jjelen@redhat.com> - 0.19.0-3\e- Make OpenSC multilib also on s390 and ppc archesaa1Jakub Jelen <jjelen@redhat.com> - 0.19.0-2\e- Make OpenSC multilib again by moving the conflicting files on ix86 arch
i{2Jakub Jelen <jjelen@redhat.com> - 0.16.0-10.20170227git[;e@- Improve support for ECC-enabled CardOS 5.3 card (#1562277)phyi2Jakub Jelen <jjelen@redhat.com> - 0.16.0-9.20170227git[(@- make ECPoint behavior standards compliant by default (#1562572)
- allow mechanism to be specified in hexadecimal (#1562572)
- Disable pinpad by default (#1547117, #1547744)ugys2Jakub Jelen <jjelen@redhat.com> - 0.16.0-8.20170227gitZL- Copy labels from certificate (#1448555)
- Avoid infinite loop in CAC driver when reading non-CAC cards (#1473335)
- Properly parse Simple TLV structures in CAC driver (#1473418)
--{na3Jan Černý <jcerny@redhat.com> - 1.2.17-4\@- Make is_local_fs static again to avoid API changes between releasesgmaq2Jakub Jelen <jjelen@redhat.com> - 0.19.0-4_u@- Support PIN change for HID Alt tokens (#1893856)glaq2Jakub Jelen <jjelen@redhat.com> - 0.19.0-3\e- Make OpenSC multilib also on s390 and ppc archeska2Jakub Jelen <jjelen@redhat.com> - 0.19.0-2\e- Make OpenSC multilib again by moving the conflicting files on ix86 archvja
2Jakub Jelen <jjelen@redhat.com> - 0.19.0-1\\- Rebase to new upstream release (#1656791)
  - Add Support for HID Crescendo 144K (#1612372)
  - Add Support for CAC Alt tokens (#1645581)
  - Fix usage detection from certificates (#1672898)
  - Fix security issues:
    - CVE-2018-16391
    - CVE-2018-16392
    - CVE-2018-16393
    - CVE-2018-16418
    - CVE-2018-16419
    - CVE-2018-16420
    - CVE-2018-16421
    - CVE-2018-16422
    - CVE-2018-16423
    - CVE-2018-16426
    - CVE-2018-16427
$^T$+tcu3Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)bsag3Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)TraK3Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|qa3Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)Gpa/3Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).omO3Vojtech Polasek <vpolasek@redhat.com> - 1.2.17-5]@- Fixed XSLT template making rule details in reports accessible for screenreader users (#1767826)
9)'9|{a4Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)Gza/4Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).ymO4Vojtech Polasek <vpolasek@redhat.com> - 1.2.17-5]@- Fixed XSLT template making rule details in reports accessible for screenreader users (#1767826){xa4Jan Černý <jcerny@redhat.com> - 1.2.17-4\@- Make is_local_fs static again to avoid API changes between releaseswc3Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nvc}3Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)aucc3Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)
B;c4Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nc}4Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)acc4Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+~cu4Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)b}ag4Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)T|aK4Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)
a4\aacc5Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+cu5Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)bag5Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)TaK5Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|a5Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)Ga/5Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).
;;{a6Jan Černý <jcerny@redhat.com> - 1.2.17-4\@- Make is_local_fs static again to avoid API changes between releases\cY5Jan Černý <jcerny@redhat.com> - 1.2.17-15c- Prevent memory errors (rhbz#2111041)l
qi5Marcus Burghardt <maburgha@redhat.com> - 1.2.17-14a- Fix memory leaks in probe-api (RHBZ#1861793)
- Prevent duplicate variables in Ansible Playbooks (RHBZ#1944683)
- Fix trailing whitespace in Ansible Playbooks
- Fix inconsistent result from security_patches_up_to_date (RHBZ#1858502)
- Fix multiple segfaults and broken test (RHBZ#1911999)
- Improve --stig-viewer output when there is no 1:1 connection between rules
- Lower memory limits and improve their checking (RHBZ#1932833)	c5Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nc}5Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)
$^T$+cu6Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)bag6Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)TaK6Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|a6Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)Ga/6Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).
mO6Vojtech Polasek <vpolasek@redhat.com> - 1.2.17-5]@- Fixed XSLT template making rule details in reports accessible for screenreader users (#1767826)
)Zbag7Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)TaK7Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|a7Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)Ga/7Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).c6Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nc}6Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)acc6Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)
vkvc7Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nc}7Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)acc7Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+cu7Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)
0!mO8Vojtech Polasek <vpolasek@redhat.com> - 1.2.17-5]@- Fixed XSLT template making rule details in reports accessible for screenreader users (#1767826){ a8Jan Černý <jcerny@redhat.com> - 1.2.17-4\@- Make is_local_fs static again to avoid API changes between releases\cY7Jan Černý <jcerny@redhat.com> - 1.2.17-15c- Prevent memory errors (rhbz#2111041)lqi7Marcus Burghardt <maburgha@redhat.com> - 1.2.17-14a- Fix memory leaks in probe-api (RHBZ#1861793)
- Prevent duplicate variables in Ansible Playbooks (RHBZ#1944683)
- Fix trailing whitespace in Ansible Playbooks
- Fix inconsistent result from security_patches_up_to_date (RHBZ#1858502)
- Fix multiple segfaults and broken test (RHBZ#1911999)
- Improve --stig-viewer output when there is no 1:1 connection between rules
- Lower memory limits and improve their checking (RHBZ#1932833)
a4\aa'cc8Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+&cu8Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)b%ag8Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)T$aK8Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|#a8Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)G"a/8Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).
FFT.aK9Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|-a9Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)G,a/9Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).+mO9Vojtech Polasek <vpolasek@redhat.com> - 1.2.17-5]@- Fixed XSLT template making rule details in reports accessible for screenreader users (#1767826){*a9Jan Černý <jcerny@redhat.com> - 1.2.17-4\@- Make is_local_fs static again to avoid API changes between releases)c8Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)n(c}8Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)
DjDG4a/:Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).3c9Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)n2c}9Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)a1cc9Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+0cu9Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)b/ag9Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)
8(-8;c:Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)n:c}:Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)a9cc:Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+8cu:Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)b7ag:Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)T6aK:Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|5a:Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)
0?mO;Vojtech Polasek <vpolasek@redhat.com> - 1.2.17-5]@- Fixed XSLT template making rule details in reports accessible for screenreader users (#1767826){>a;Jan Černý <jcerny@redhat.com> - 1.2.17-4\@- Make is_local_fs static again to avoid API changes between releases\=cY:Jan Černý <jcerny@redhat.com> - 1.2.17-15c- Prevent memory errors (rhbz#2111041)l<qi:Marcus Burghardt <maburgha@redhat.com> - 1.2.17-14a- Fix memory leaks in probe-api (RHBZ#1861793)
- Prevent duplicate variables in Ansible Playbooks (RHBZ#1944683)
- Fix trailing whitespace in Ansible Playbooks
- Fix inconsistent result from security_patches_up_to_date (RHBZ#1858502)
- Fix multiple segfaults and broken test (RHBZ#1911999)
- Improve --stig-viewer output when there is no 1:1 connection between rules
- Lower memory limits and improve their checking (RHBZ#1932833)
a4\aaEcc;Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+Dcu;Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)bCag;Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)TBaK;Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|Aa;Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)G@a/;Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).
FFTLaK<Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|Ka<Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)GJa/<Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).ImO<Vojtech Polasek <vpolasek@redhat.com> - 1.2.17-5]@- Fixed XSLT template making rule details in reports accessible for screenreader users (#1767826){Ha<Jan Černý <jcerny@redhat.com> - 1.2.17-4\@- Make is_local_fs static again to avoid API changes between releasesGc;Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nFc};Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)
DjDGRa/=Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).Qc<Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nPc}<Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)aOcc<Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+Ncu<Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)bMag<Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)

er+V:eDI
e65e62f1a74d176259823a76ae7741ded81383eefe67562563e90a903f05c86cDH
79de22a187c8d6582548815722742e3d7cc19659ecf90597109866199ec5deeeDG
e7e24cc31f3c532de3376ea95f7fa6356ead993a563d11fdc5f66f22f5c565ffDF
80f55b0df82d9eb00f5b602013b5219abee2198b4d76be5dbf7622302dc2c749DE
56f9a2f564549616cc842c446f06bff9820333e8cf00b5f21132bfd6597f6be2DD
20de254161b05ef02d837d21731032c8f4207723f0eccf9665c6f04f2b1e2866DC
97f2d1ab20836c94cc0c8fb0f450e8d93261f964058478270e2b309a246e35c0DB
cd61cf9c12e868cd95161567895609d82e39f45f923f851caab9d599ebecf0a6DA
69a52650aaaa5549296f7aed59178ab2f5ca948416e7e89b182107dc728f0387D@
9f4044376829fa18da40d132a93644d44691a5cb6c1af69c266fa8e7c7187cddD?
49bbdc6d250ec47750ab688a1618baefc947110bdd51d0ede255d5b1610a74fdD>
597a98034f38019a6ec047dd5674188fbb428a55fadfca294b210b303125fa02D=
029192b133954b86d152440adc98cc50c2ad3ded6b1f727f31615807b2d6ac98
8(-8Yc=Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nXc}=Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)aWcc=Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+Vcu=Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)bUag=Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)TTaK=Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|Sa=Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)
0]mO>Vojtech Polasek <vpolasek@redhat.com> - 1.2.17-5]@- Fixed XSLT template making rule details in reports accessible for screenreader users (#1767826){\a>Jan Černý <jcerny@redhat.com> - 1.2.17-4\@- Make is_local_fs static again to avoid API changes between releases\[cY=Jan Černý <jcerny@redhat.com> - 1.2.17-15c- Prevent memory errors (rhbz#2111041)lZqi=Marcus Burghardt <maburgha@redhat.com> - 1.2.17-14a- Fix memory leaks in probe-api (RHBZ#1861793)
- Prevent duplicate variables in Ansible Playbooks (RHBZ#1944683)
- Fix trailing whitespace in Ansible Playbooks
- Fix inconsistent result from security_patches_up_to_date (RHBZ#1858502)
- Fix multiple segfaults and broken test (RHBZ#1911999)
- Improve --stig-viewer output when there is no 1:1 connection between rules
- Lower memory limits and improve their checking (RHBZ#1932833)
a4\aaccc>Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+bcu>Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)baag>Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)T`aK>Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|_a>Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)G^a/>Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).
FFTjaK?Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|ia?Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)Gha/?Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).gmO?Vojtech Polasek <vpolasek@redhat.com> - 1.2.17-5]@- Fixed XSLT template making rule details in reports accessible for screenreader users (#1767826){fa?Jan Černý <jcerny@redhat.com> - 1.2.17-4\@- Make is_local_fs static again to avoid API changes between releasesec>Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)ndc}>Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)
DjDGpa/@Matěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).oc?Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nnc}?Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)amcc?Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+lcu?Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)bkag?Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)
8(-8wc@Jan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nvc}@Jan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)aucc@Jan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+tcu@Jan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)bsag@Jan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)TraK@Jan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|qa@Jan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)
0{mOAVojtech Polasek <vpolasek@redhat.com> - 1.2.17-5]@- Fixed XSLT template making rule details in reports accessible for screenreader users (#1767826){zaAJan Černý <jcerny@redhat.com> - 1.2.17-4\@- Make is_local_fs static again to avoid API changes between releases\ycY@Jan Černý <jcerny@redhat.com> - 1.2.17-15c- Prevent memory errors (rhbz#2111041)lxqi@Marcus Burghardt <maburgha@redhat.com> - 1.2.17-14a- Fix memory leaks in probe-api (RHBZ#1861793)
- Prevent duplicate variables in Ansible Playbooks (RHBZ#1944683)
- Fix trailing whitespace in Ansible Playbooks
- Fix inconsistent result from security_patches_up_to_date (RHBZ#1858502)
- Fix multiple segfaults and broken test (RHBZ#1911999)
- Improve --stig-viewer output when there is no 1:1 connection between rules
- Lower memory limits and improve their checking (RHBZ#1932833)bR1aRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{0000#0)0.13191>1C1H1N1S1Y1	]1
`1f1i1
n1t1{1111111!1'1.141;1?1E1L1R1 Y1!]1"c1#j1$p1%w1&{1(1)1*1+1,1-1.1/#10)11/12313714=15C16G17L18T1:\1;c1<j1=r1>z1?1@1A1B1C1D1E%1F)1G.1H21I91J=1KB1LF1MM1NQ1OV1QZ1Ra1Se1Tj1Un1Vu1Wy1X~1Y1Z	1[
1\1]1^1_!1`&
a4\aaccAJan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+cuAJan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)bagAJan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)T~aKAJan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|}aAJan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)G|a/AMatěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).
?gbagBJan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)TaKBJan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|aBJan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)Ga/BMatěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).cAJan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nc}AJan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)
vkvcBJan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)n
c}BJan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)a	ccBJan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+cuBJan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)
0mOCVojtech Polasek <vpolasek@redhat.com> - 1.2.17-5]@- Fixed XSLT template making rule details in reports accessible for screenreader users (#1767826){aCJan Černý <jcerny@redhat.com> - 1.2.17-4\@- Make is_local_fs static again to avoid API changes between releases\
cYBJan Černý <jcerny@redhat.com> - 1.2.17-15c- Prevent memory errors (rhbz#2111041)lqiBMarcus Burghardt <maburgha@redhat.com> - 1.2.17-14a- Fix memory leaks in probe-api (RHBZ#1861793)
- Prevent duplicate variables in Ansible Playbooks (RHBZ#1944683)
- Fix trailing whitespace in Ansible Playbooks
- Fix inconsistent result from security_patches_up_to_date (RHBZ#1858502)
- Fix multiple segfaults and broken test (RHBZ#1911999)
- Improve --stig-viewer output when there is no 1:1 connection between rules
- Lower memory limits and improve their checking (RHBZ#1932833)
a4\aaccCJan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+cuCJan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)bagCJan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)TaKCJan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|aCJan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)Ga/CMatěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).
?gbagDJan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)TaKDJan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|aDJan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)Ga/DMatěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).cCJan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nc}CJan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)
vkvcDJan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nc}DJan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)accDJan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+cuDJan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)
0#mOEVojtech Polasek <vpolasek@redhat.com> - 1.2.17-5]@- Fixed XSLT template making rule details in reports accessible for screenreader users (#1767826){"aEJan Černý <jcerny@redhat.com> - 1.2.17-4\@- Make is_local_fs static again to avoid API changes between releases\!cYDJan Černý <jcerny@redhat.com> - 1.2.17-15c- Prevent memory errors (rhbz#2111041)l qiDMarcus Burghardt <maburgha@redhat.com> - 1.2.17-14a- Fix memory leaks in probe-api (RHBZ#1861793)
- Prevent duplicate variables in Ansible Playbooks (RHBZ#1944683)
- Fix trailing whitespace in Ansible Playbooks
- Fix inconsistent result from security_patches_up_to_date (RHBZ#1858502)
- Fix multiple segfaults and broken test (RHBZ#1911999)
- Improve --stig-viewer output when there is no 1:1 connection between rules
- Lower memory limits and improve their checking (RHBZ#1932833)
a4\aa)ccEJan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+(cuEJan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)b'agEJan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)T&aKEJan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|%aEJan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)G$a/EMatěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).
?gb/agFJan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)T.aKFJan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|-aFJan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)G,a/FMatěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).+cEJan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)n*c}EJan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)
vkv3cFJan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)n2c}FJan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)a1ccFJan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+0cuFJan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)
07mOGVojtech Polasek <vpolasek@redhat.com> - 1.2.17-5]@- Fixed XSLT template making rule details in reports accessible for screenreader users (#1767826){6aGJan Černý <jcerny@redhat.com> - 1.2.17-4\@- Make is_local_fs static again to avoid API changes between releases\5cYFJan Černý <jcerny@redhat.com> - 1.2.17-15c- Prevent memory errors (rhbz#2111041)l4qiFMarcus Burghardt <maburgha@redhat.com> - 1.2.17-14a- Fix memory leaks in probe-api (RHBZ#1861793)
- Prevent duplicate variables in Ansible Playbooks (RHBZ#1944683)
- Fix trailing whitespace in Ansible Playbooks
- Fix inconsistent result from security_patches_up_to_date (RHBZ#1858502)
- Fix multiple segfaults and broken test (RHBZ#1911999)
- Improve --stig-viewer output when there is no 1:1 connection between rules
- Lower memory limits and improve their checking (RHBZ#1932833)
a4\aa=ccGJan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+<cuGJan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)b;agGJan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)T:aKGJan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|9aGJan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)G8a/GMatěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).
?gbCagHJan Černý <jcerny@redhat.com> - 1.2.17-9^r- Add new DISA STIG Viewer URI (RHBZ#1783200)TBaKHJan Černý <jcerny@redhat.com> - 1.2.17-8]߶- Add RHEL 8 CPE (RHBZ#1777860)|AaHJan Černý <jcerny@redhat.com> - 1.2.17-7]@- Use and return canonical paths in rpmverifyfile probe (RHBZ#1766489)G@a/HMatěj Týč <matyc@redhat.com> - 1.2.17-6]µ- Enabled the virtual '(all)' profile support for the scanner (RHBZ#1769272).
- Enabled the '(all)' profile support for oscap-ssh (RHBZ#1769272).?cGJan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)n>c}GJan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)
vkvGcHJan Černý <jcerny@redhat.com> - 1.2.17-13_h- Enable gzip compression when downloading remote content (RHBZ#1870147)nFc}HJan Černý <jcerny@redhat.com> - 1.2.17-12_-B@- Fix memory leaks in rpmverifyfile probe (RHBZ#1861300)aEccHJan Černý <jcerny@redhat.com> - 1.2.17-11^- Fix URL for Red Hat Errata (RHBZ#1828779)+DcuHJan Černý <jcerny@redhat.com> - 1.2.17-10^s^- Fix segfault in systemdunitdependency probe (RHBZ#1478285)
- Build and ship HTML manual (RHBZ#1465661)
- Fix oscap-ssh with --sudo (RHBZ#1803114)
- Change category of verbose message (RHBZ#1640522)
- Fix segfault in CVRF module (RHBZ#1642283)
##LgIDoug Ledford <dledford@redhat.com> - 3.3.19-1Uq@- Update to latest upstream release
- Build on s390
- Related: bz1186159lKguIDoug Ledford <dledford@redhat.com> - 3.3.18-2TA- Fix an issue found by rpmdiff
- Related: bz1061587Jg=IDoug Ledford <dledford@redhat.com> - 3.3.18-1T6x- Update to latest upstream release
- Resolves: bz1061587, bz1042745, bz884555, bz948475\IcYHJan Černý <jcerny@redhat.com> - 1.2.17-15c- Prevent memory errors (rhbz#2111041)lHqiHMarcus Burghardt <maburgha@redhat.com> - 1.2.17-14a- Fix memory leaks in probe-api (RHBZ#1861793)
- Prevent duplicate variables in Ansible Playbooks (RHBZ#1944683)
- Fix trailing whitespace in Ansible Playbooks
- Fix inconsistent result from security_patches_up_to_date (RHBZ#1858502)
- Fix multiple segfaults and broken test (RHBZ#1911999)
- Improve --stig-viewer output when there is no 1:1 connection between rules
- Lower memory limits and improve their checking (RHBZ#1932833)
AnVATg=JDoug Ledford <dledford@redhat.com> - 3.3.18-1T6x- Update to latest upstream release
- Resolves: bz1061587, bz1042745, bz884555, bz948475{S_IHonggang Li <honli@redhat.com> - 3.3.21-4_j- Allow MCMR requests with default subnet prefix
- Resolves: bz1898273cR_kIHonggang Li <honli@redhat.com> - 3.3.21-3^- Fix subnet_prefix issue
- Resolves: bz1828452]Q__IHonggang Li <honli@redhat.com> - 3.3.21-2\d- Fix a few defects
- Resolves: bz1668201P_#IHonggang Li <honli@redhat.com> - 3.3.21-1\E@- Rebase to latest upstream release 3.3.21
- Resolves: bz1535978, bz1653660]O__IHonggang Li <honli@redhat.com> - 3.3.20-3[(@- Fix BuildRequires
- Resolves: bz1567528fN_qIHonggang Li <honli@redhat.com> - 3.3.20-2Y@- Fix up preuninstall script
- Resolves: bz1508334
M_=IHonggang Li <honli@redhat.com> - 3.3.20-1Y@- Cleanup the spec file
- Rebase to latest upstream release 3.3.20
- Resolves: bz1456524

er+V:eDV
e95f299b4e1d9a775808bed9298856196169c363ce0d077bfc1bda79e4c4d4f4DU
80ae1fdd564cfbaee7f977fca0a23cb7bb35f9a6955a26b716894f379759d7d0DT
15d88fa90e0a746ab04810e8c5001282b587b8a21da83e08f7a05195f6fdd775DS
6a5c15723351049958d68d7476e529ec68de1d64478a1e66f36bbf5a50e2f0d9DR
a7333d8c99f660e6187ca76984c04c77a50d5b4767823ec52cc7f53fbdeb43bcDQ
4371a5846dcf1faffbb4329cff76c64cdf7cf7f9103bbdde6357e230e6f9ba83DP
d2d641c7cc9c03e9ca6482ca35b0c36b1e23ba7b853e1bdc6bec25eb9af46a6eDO
3ab4d0b3d34008809f0d657e9f4732dbc33963cf480b77f6b3afa455be2b0eb3DN
537d165748ea34474b3c9f20b83e298df8f9c60a97f43737c751dec828963330DM
f3a76eebff774f1e84066ca2ae1e4c12833ebcff375ee7d2d50547214c4f9d1bDL
53dcd4410dcf2e10fbcb28e2ca530d42ca4402dc531e3e719f798111531560f9DK
328f46b687b75e421aa0632db00bd3a424a9bb575aee94e2ddd24cd9fa19ab14DJ
afc40dc3937d9d41e9145c8c39744dfafffd80bb988b7e391d6d9deddaa9e317
`
x(`c\_kJHonggang Li <honli@redhat.com> - 3.3.21-3^- Fix subnet_prefix issue
- Resolves: bz1828452][__JHonggang Li <honli@redhat.com> - 3.3.21-2\d- Fix a few defects
- Resolves: bz1668201Z_#JHonggang Li <honli@redhat.com> - 3.3.21-1\E@- Rebase to latest upstream release 3.3.21
- Resolves: bz1535978, bz1653660]Y__JHonggang Li <honli@redhat.com> - 3.3.20-3[(@- Fix BuildRequires
- Resolves: bz1567528fX_qJHonggang Li <honli@redhat.com> - 3.3.20-2Y@- Fix up preuninstall script
- Resolves: bz1508334
W_=JHonggang Li <honli@redhat.com> - 3.3.20-1Y@- Cleanup the spec file
- Rebase to latest upstream release 3.3.20
- Resolves: bz1456524VgJDoug Ledford <dledford@redhat.com> - 3.3.19-1Uq@- Update to latest upstream release
- Build on s390
- Related: bz1186159lUguJDoug Ledford <dledford@redhat.com> - 3.3.18-2TA- Fix an issue found by rpmdiff
- Related: bz1061587
{c]c__KHonggang Li <honli@redhat.com> - 3.3.20-3[(@- Fix BuildRequires
- Resolves: bz1567528fb_qKHonggang Li <honli@redhat.com> - 3.3.20-2Y@- Fix up preuninstall script
- Resolves: bz1508334
a_=KHonggang Li <honli@redhat.com> - 3.3.20-1Y@- Cleanup the spec file
- Rebase to latest upstream release 3.3.20
- Resolves: bz1456524`gKDoug Ledford <dledford@redhat.com> - 3.3.19-1Uq@- Update to latest upstream release
- Build on s390
- Related: bz1186159l_guKDoug Ledford <dledford@redhat.com> - 3.3.18-2TA- Fix an issue found by rpmdiff
- Related: bz1061587^g=KDoug Ledford <dledford@redhat.com> - 3.3.18-1T6x- Update to latest upstream release
- Resolves: bz1061587, bz1042745, bz884555, bz948475{]_JHonggang Li <honli@redhat.com> - 3.3.21-4_j- Allow MCMR requests with default subnet prefix
- Resolves: bz1898273
{4.jgLDoug Ledford <dledford@redhat.com> - 3.3.19-1Uq@- Update to latest upstream release
- Build on s390
- Related: bz1186159liguLDoug Ledford <dledford@redhat.com> - 3.3.18-2TA- Fix an issue found by rpmdiff
- Related: bz1061587hg=LDoug Ledford <dledford@redhat.com> - 3.3.18-1T6x- Update to latest upstream release
- Resolves: bz1061587, bz1042745, bz884555, bz948475{g_KHonggang Li <honli@redhat.com> - 3.3.21-4_j- Allow MCMR requests with default subnet prefix
- Resolves: bz1898273cf_kKHonggang Li <honli@redhat.com> - 3.3.21-3^- Fix subnet_prefix issue
- Resolves: bz1828452]e__KHonggang Li <honli@redhat.com> - 3.3.21-2\d- Fix a few defects
- Resolves: bz1668201d_#KHonggang Li <honli@redhat.com> - 3.3.21-1\E@- Rebase to latest upstream release 3.3.21
- Resolves: bz1535978, bz1653660
AnVArg=MDoug Ledford <dledford@redhat.com> - 3.3.18-1T6x- Update to latest upstream release
- Resolves: bz1061587, bz1042745, bz884555, bz948475{q_LHonggang Li <honli@redhat.com> - 3.3.21-4_j- Allow MCMR requests with default subnet prefix
- Resolves: bz1898273cp_kLHonggang Li <honli@redhat.com> - 3.3.21-3^- Fix subnet_prefix issue
- Resolves: bz1828452]o__LHonggang Li <honli@redhat.com> - 3.3.21-2\d- Fix a few defects
- Resolves: bz1668201n_#LHonggang Li <honli@redhat.com> - 3.3.21-1\E@- Rebase to latest upstream release 3.3.21
- Resolves: bz1535978, bz1653660]m__LHonggang Li <honli@redhat.com> - 3.3.20-3[(@- Fix BuildRequires
- Resolves: bz1567528fl_qLHonggang Li <honli@redhat.com> - 3.3.20-2Y@- Fix up preuninstall script
- Resolves: bz1508334
k_=LHonggang Li <honli@redhat.com> - 3.3.20-1Y@- Cleanup the spec file
- Rebase to latest upstream release 3.3.20
- Resolves: bz1456524
`
x(`cz_kMHonggang Li <honli@redhat.com> - 3.3.21-3^- Fix subnet_prefix issue
- Resolves: bz1828452]y__MHonggang Li <honli@redhat.com> - 3.3.21-2\d- Fix a few defects
- Resolves: bz1668201x_#MHonggang Li <honli@redhat.com> - 3.3.21-1\E@- Rebase to latest upstream release 3.3.21
- Resolves: bz1535978, bz1653660]w__MHonggang Li <honli@redhat.com> - 3.3.20-3[(@- Fix BuildRequires
- Resolves: bz1567528fv_qMHonggang Li <honli@redhat.com> - 3.3.20-2Y@- Fix up preuninstall script
- Resolves: bz1508334
u_=MHonggang Li <honli@redhat.com> - 3.3.20-1Y@- Cleanup the spec file
- Rebase to latest upstream release 3.3.20
- Resolves: bz1456524tgMDoug Ledford <dledford@redhat.com> - 3.3.19-1Uq@- Update to latest upstream release
- Build on s390
- Related: bz1186159lsguMDoug Ledford <dledford@redhat.com> - 3.3.18-2TA- Fix an issue found by rpmdiff
- Related: bz1061587
{c]__NHonggang Li <honli@redhat.com> - 3.3.20-3[(@- Fix BuildRequires
- Resolves: bz1567528f_qNHonggang Li <honli@redhat.com> - 3.3.20-2Y@- Fix up preuninstall script
- Resolves: bz1508334
_=NHonggang Li <honli@redhat.com> - 3.3.20-1Y@- Cleanup the spec file
- Rebase to latest upstream release 3.3.20
- Resolves: bz1456524~gNDoug Ledford <dledford@redhat.com> - 3.3.19-1Uq@- Update to latest upstream release
- Build on s390
- Related: bz1186159l}guNDoug Ledford <dledford@redhat.com> - 3.3.18-2TA- Fix an issue found by rpmdiff
- Related: bz1061587|g=NDoug Ledford <dledford@redhat.com> - 3.3.18-1T6x- Update to latest upstream release
- Resolves: bz1061587, bz1042745, bz884555, bz948475{{_MHonggang Li <honli@redhat.com> - 3.3.21-4_j- Allow MCMR requests with default subnet prefix
- Resolves: bz1898273
{4.gODoug Ledford <dledford@redhat.com> - 3.3.19-1Uq@- Update to latest upstream release
- Build on s390
- Related: bz1186159lguODoug Ledford <dledford@redhat.com> - 3.3.18-2TA- Fix an issue found by rpmdiff
- Related: bz1061587g=ODoug Ledford <dledford@redhat.com> - 3.3.18-1T6x- Update to latest upstream release
- Resolves: bz1061587, bz1042745, bz884555, bz948475{_NHonggang Li <honli@redhat.com> - 3.3.21-4_j- Allow MCMR requests with default subnet prefix
- Resolves: bz1898273c_kNHonggang Li <honli@redhat.com> - 3.3.21-3^- Fix subnet_prefix issue
- Resolves: bz1828452]__NHonggang Li <honli@redhat.com> - 3.3.21-2\d- Fix a few defects
- Resolves: bz1668201_#NHonggang Li <honli@redhat.com> - 3.3.21-1\E@- Rebase to latest upstream release 3.3.21
- Resolves: bz1535978, bz1653660
JnVJwPJakub Jelen <jjelen@redhat.com> - 7.4p1-13 + 0.10.3-1Y- Revert default of GSSAPIStrictAcceptorCheck=no back to yes (#1488982){_OHonggang Li <honli@redhat.com> - 3.3.21-4_j- Allow MCMR requests with default subnet prefix
- Resolves: bz1898273c_kOHonggang Li <honli@redhat.com> - 3.3.21-3^- Fix subnet_prefix issue
- Resolves: bz1828452]
__OHonggang Li <honli@redhat.com> - 3.3.21-2\d- Fix a few defects
- Resolves: bz1668201_#OHonggang Li <honli@redhat.com> - 3.3.21-1\E@- Rebase to latest upstream release 3.3.21
- Resolves: bz1535978, bz1653660]__OHonggang Li <honli@redhat.com> - 3.3.20-3[(@- Fix BuildRequires
- Resolves: bz1567528f
_qOHonggang Li <honli@redhat.com> - 3.3.20-2Y@- Fix up preuninstall script
- Resolves: bz1508334
	_=OHonggang Li <honli@redhat.com> - 3.3.20-1Y@- Cleanup the spec file
- Rebase to latest upstream release 3.3.20
- Resolves: bz1456524
*wGPJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cwSPJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)wPJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)a9PNikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5
NDa9QNikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.57PDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)wPJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|wPJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)wPJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)-wePJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)
::-weQJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)wGQJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cwSQJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)wQJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
/vi!/a%9RNikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5$wRJakub Jelen <jjelen@redhat.com> - 7.4p1-13 + 0.10.3-1Y- Revert default of GSSAPIStrictAcceptorCheck=no back to yes (#1488982)#7QDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-23 + 0.10.3-2d!- Avoid remote code execution in ssh-agent PKCS#11 support
  Resolves: CVE-2023-38408"7QDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)!wQJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)| wQJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)wQJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-)weRJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)(wGRJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)c'wSRJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)&wRJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
`vi`a.9SNikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5-7RDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884),wRJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|+wRJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)*wRJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-2weSJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)1wGSJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)c0wSSJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)/wSJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
/vi!/a99TNikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.58wTJakub Jelen <jjelen@redhat.com> - 7.4p1-13 + 0.10.3-1Y- Revert default of GSSAPIStrictAcceptorCheck=no back to yes (#1488982)77SDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-23 + 0.10.3-2d!- Avoid remote code execution in ssh-agent PKCS#11 support
  Resolves: CVE-2023-3840867SDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)5wSJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|4wSJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)3wSJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-=weTJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)<wGTJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)c;wSTJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226):wTJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
`vi`aB9UNikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5A7TDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)@wTJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|?wTJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)>wTJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-FweUJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)EwGUJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cDwSUJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)CwUJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
/vi!/aM9VNikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5LwVJakub Jelen <jjelen@redhat.com> - 7.4p1-13 + 0.10.3-1Y- Revert default of GSSAPIStrictAcceptorCheck=no back to yes (#1488982)K7UDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-23 + 0.10.3-2d!- Avoid remote code execution in ssh-agent PKCS#11 support
  Resolves: CVE-2023-38408J7UDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)IwUJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|HwUJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)GwUJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-QweVJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)PwGVJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cOwSVJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)NwVJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
`vi`aV9WNikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5U7VDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)TwVJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|SwVJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)RwVJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)

er+V:eDc
04f581972286e776f852cf380fd0a4c05af1556c3d62f8ad579d87985ee0467cDb
23e60a3de6f5ccfa5704efa5c39a19b795f04e65312ef6af6e4264233e4fa953Da
a9775c264bc9077729880ff223db6978a0ee4aae22b8fbdf9d5c6d935f6518a3D`
969eab9ba9b8ec436addf7c0e053780ff8e9fcafc51ae2195eee7d809f21dc64D_
e73f1115eaf8a0021df6047f5efc221b536a0cd13fdd292d1f38a1f658589414D^
bc124f709e0c7debfdda22b0a98dbce5ebc798a8c16477f0129128e573b3a65cD]
4f162133b3536d798fabbd26d093d1126b87e049d6687beb758da8930753e4f8D\
01b2d6f4dd3c509eda7a3396036cc2ba36461c6d867b18c64e8358fba4982e34D[
975ab2772de42fecf4ee5854a33ecf17992227d28f7a91eec834e9caac12e7feDZ
339f233813e1f39b24e1e909a69e3050071f267633c137494ad16972ff55f201DY
2df5c1c5020f78e8c1d592e7c531833f864133f64fb76513eda7fa4b1d3f8a79DX
11d891b8f8df76c76199d0d95bc23fe7ef53c80851883e2f7981576c44654966DW
5d6009ff10b81ed847436f4edd71eb726209b7ed8b9c98078577cd9ace844de0
::-ZweWJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)YwGWJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cXwSWJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)WwWJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
/vi!/aa9XNikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5`wXJakub Jelen <jjelen@redhat.com> - 7.4p1-13 + 0.10.3-1Y- Revert default of GSSAPIStrictAcceptorCheck=no back to yes (#1488982)_7WDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-23 + 0.10.3-2d!- Avoid remote code execution in ssh-agent PKCS#11 support
  Resolves: CVE-2023-38408^7WDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)]wWJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|\wWJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)[wWJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-eweXJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)dwGXJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)ccwSXJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)bwXJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
`vi`aj9YNikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5i7XDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)hwXJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|gwXJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)fwXJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-nweYJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)mwGYJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)clwSYJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)kwYJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
/vi!/au9ZNikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5twZJakub Jelen <jjelen@redhat.com> - 7.4p1-13 + 0.10.3-1Y- Revert default of GSSAPIStrictAcceptorCheck=no back to yes (#1488982)s7YDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-23 + 0.10.3-2d!- Avoid remote code execution in ssh-agent PKCS#11 support
  Resolves: CVE-2023-38408r7YDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)qwYJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|pwYJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)owYJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-yweZJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)xwGZJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cwwSZJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)vwZJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
`vi`a~9[Nikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5}7ZDmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)|wZJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|{wZJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)zwZJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-we[Jakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)wG[Jakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cwS[Jakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)w[Jakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
/vi!/a	9\Nikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5w\Jakub Jelen <jjelen@redhat.com> - 7.4p1-13 + 0.10.3-1Y- Revert default of GSSAPIStrictAcceptorCheck=no back to yes (#1488982)7[Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-23 + 0.10.3-2d!- Avoid remote code execution in ssh-agent PKCS#11 support
  Resolves: CVE-2023-384087[Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)w[Jakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|w[Jakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)w[Jakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-
we\Jakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)wG\Jakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cwS\Jakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)
w\Jakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
`vi`a9]Nikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.57\Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)w\Jakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|w\Jakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)w\Jakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-we]Jakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)wG]Jakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cwS]Jakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)w]Jakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
/vi!/a9^Nikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5w^Jakub Jelen <jjelen@redhat.com> - 7.4p1-13 + 0.10.3-1Y- Revert default of GSSAPIStrictAcceptorCheck=no back to yes (#1488982)7]Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-23 + 0.10.3-2d!- Avoid remote code execution in ssh-agent PKCS#11 support
  Resolves: CVE-2023-384087]Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)w]Jakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|w]Jakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)w]Jakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-!we^Jakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735) wG^Jakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cwS^Jakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)w^Jakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
`vi`a&9_Nikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5%7^Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)$w^Jakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|#w^Jakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)"w^Jakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-*we_Jakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735))wG_Jakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)c(wS_Jakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)'w_Jakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
vi!f0ao`Tomáš Mráz <tmraz@redhat.com> 1.0.2k-11Z'- fix deadlock in RNG in the FIPS mode in mariadb/7_Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-23 + 0.10.3-2d!- Avoid remote code execution in ssh-agent PKCS#11 support
  Resolves: CVE-2023-38408.7_Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)-w_Jakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|,w_Jakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)+w_Jakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
\9(\G4a/`Tomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)f3ao`Tomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)"2ae`Tomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structureB1a%`Tomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulus
7K99c#`Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchz8c`Sahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference7a?`Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g6ao`Tomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)D5a)`Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction
\9(\G=a/aTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)f<aoaTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)";aeaTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structureB:a%aTomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulus
7K9Bc#aSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzAcaSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference@a?aTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g?aoaTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)D>a)aTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction
gGaobTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)DFa)bTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGEa/bTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)fDaobTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)vCcaSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126
&lgl& Mc_bSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993LcWbSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vKcbSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126Jc#bSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzIcbSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referenceHa?bTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)
m4kmzRccSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referenceQa?cTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gPaocTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)DOa)cTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGNa/cTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)
y~81WwmcDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160 Vc_cSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993UcWcSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vTccSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126Sc#cSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patch

er+V:eDp
820567529a85b68ae8094f0be50f5116b0622ed1c526afa0e239f84b9bcb0860Do
15eee91d297a4a3b7715b991e5411fa38326f5c44b7a58895868067a828537daDn
a5f13a41cc54cc7e9bcaf76ee19fec24dd4c8b4f637c43a411f8fe4af310a88cDm
1771d7f870046fcd2d0c96d054f425f3032a0f4271dfb54c5e5bb22cd2f87d11Dl
5989f8701c6fe912d154675a3f7ad276f5dccc5afc8ccce28405408ee673c16cDk
08396cb866f024b0054c16918fe544406f737f7ddefcecbda04ad29ab9a27a15Dj
94cc4c729c9fc12e3385fb74c8004acc5ebf27eed73cae3facf775403d14109eDi
37388f00a7d1fc6d93e26f1ef6a2ace5b99ec8b0ff895e5d156253d00fa59db3Dh
3f51b4953396f40f83ef6281561e6aa2bd69daf5e98921e1562160c40eb64061Dg
bf4623f90ace835b85614e7e022ffcb2427a5b8235c7dedd511d580ac0c878aaDf
96b2891b2db1ae3878909b85454b12d4f3bf98634a199e8944cd81886d37e424De
eb5ebcc220cbcdd1df7a8fd9b4c1dcc27b611af10741997070d522208153e79bDd
74be24de7bd01781535f8ae78fba77bf331f0afd97e69de054496dfa406689b1
7K9\c#dSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchz[cdSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referenceZa?dTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gYaodTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)DXa)dTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction
cd	c!awMdDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-26d- Fixes CVE-2023-0286 X.400 address type confusion in X.509 GeneralName
- Resolves: rhbz#21767901`wmdDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160 _c_dSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993^cWdSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054v]cdSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126
(feaoeTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)"daeeTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structureBca%eTomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulusfbaoeTomáš Mráz <tmraz@redhat.com> 1.0.2k-11Z'- fix deadlock in RNG in the FIPS mode in mariadb
m4kmzjceSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referenceia?eTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)ghaoeTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Dga)eTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGfa/eTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)
7yH7foaofTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)"naefTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structureBma%fTomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulusflaofTomáš Mráz <tmraz@redhat.com> 1.0.2k-11Z'- fix deadlock in RNG in the FIPS mode in mariadbkc#eSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patch
m4kmztcfSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referencesa?fTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)graofTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Dqa)fTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGpa/fTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)
yfxaogTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)"waegTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structureBva%gTomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulusuc#fSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patch
m4kmz}cgSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference|a?gTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g{aogTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Dza)gTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGya/gTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)
y~"aehTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structureBa%hTomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulusvcgSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126~c#gSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patch
a?hTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gaohTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Da)hTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGa/hTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)faohTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)
Ga/iTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)f
aoiTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)v	chSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126c#hSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzchSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference
7K9c#iSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzciSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referencea?iTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g
aoiTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Da)iTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction
dUGa/jTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)faojTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004) c_iSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993cWiSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vciSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126
7K9c#jSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzcjSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referencea?jTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gaojTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Da)jTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction
*d*Da)kTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGa/kTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597) c_jSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993cWjSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vcjSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126
{v$ckSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126#c#kSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchz"ckSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference!a?kTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g aokTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)
o_8oD)a)lTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionG(a/lTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)1'wmkDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160 &c_kSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993%cWkSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054
{v.clSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126-c#lSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchz,clSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference+a?lTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g*aolTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)
O_;Og3aomTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)D2a)mTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction11wmlDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160 0c_lSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993/cWlSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054
&lgl& 9c_mSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#20399938cWmSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054v7cmSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#19321266c#mSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchz5cmSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference4a?mTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)
[J[>a?nTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g=aonTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)D<a)nTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction!;wMmDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-26d- Fixes CVE-2023-0286 X.400 address type confusion in X.509 GeneralName
- Resolves: rhbz#21767901:wmmDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160
_ Cc_nSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993BcWnSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vAcnSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126@c#nSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchz?cnSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference
sJ:sBGa%oTomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulusfFaooTomáš Mráz <tmraz@redhat.com> 1.0.2k-11Z'- fix deadlock in RNG in the FIPS mode in mariadb!EwMnDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-26d- Fixes CVE-2023-0286 X.400 address type confusion in X.509 GeneralName
- Resolves: rhbz#21767901DwmnDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160
ZY#ZDKa)oTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGJa/oTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)fIaooTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)"HaeoTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structure
J{JBQa%pTomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulusfPaopTomáš Mráz <tmraz@redhat.com> 1.0.2k-11Z'- fix deadlock in RNG in the FIPS mode in mariadbOc#oSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzNcoSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referenceMa?oTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gLaooTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)
ZY#ZDUa)pTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGTa/pTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)fSaopTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)"RaepTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structure
{BZa%qTomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulusYc#pSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzXcpSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referenceWa?pTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gVaopTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)

er+V:eD}
de13d1a20b6a077c828b91d64b7be5abb1b5809f45b27d389afd2811ffa6f9c1D|
593df90370183706f3bc69451b1aa4c6cd88b0a4d1d3964bc1b8e621b3d67d97D{
fc6cceaef55bd37f4fcdef13e567e0f496246d1ef59bd1803f1d77af60ef774aDz
60601627ced255e03b49d78f605f8c7726747b2eb27ab5531b5296d0afd1b2ceDy
d7327ee1af7919fb77069b475af28300ad4c73d10e840a156a1105e5099f1885Dx
658486f1d946fc518624c59a2badf6990f524bb7d5d660d1e34420cc78dcfe62Dw
49a7e87cdd6368571e9c30b74a1800f53df55d4cd91fc41ab8073e666edbda38Dv
c01bfc1d06b6e8d39a0bb038993a565a42a4f152542fec05d266098c4206140fDu
7a1256ee4fd271d588649f70d8aa4492d3967b0afd9d82a145275924442baae0Dt
9f4028fe73544b73e189e0028f1dae14bb0a141130988e21021ac4cef2074065Ds
c403db828d16aa325941eddc93e7be599767dc0bb4ec3be436c20c8a9ad14744Dr
b3004d122d0a738cbff817b9531b9787dcd2e46f3ed06c59e99fd50749720806Dq
4d49a5d533e4c753cbeaf06a490dca1f72f5462a8fa7f3c634484c68241ddc7c
ZY#ZD^a)qTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionG]a/qTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)f\aoqTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)"[aeqTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structure
{vccqSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126bc#qSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzacqSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference`a?qTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g_aoqTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)
\9(\Gga/rTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)ffaorTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)"eaerTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structureBda%rTomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulus
7K9lc#rSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzkcrSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referenceja?rTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)giaorTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Dha)rTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction
gqaosTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Dpa)sTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGoa/sTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)fnaosTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)vmcrSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126
&lgl& wc_sSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993vcWsSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vucsSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126tc#sSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzscsSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referencera?sTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)
|a?tTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g{aotTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Dza)tTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGya/tTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)fxaotTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)bR1RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{1b01c41d91e=1fB1gG1hM1iR1jW1l\1ma1ne1oj1po1qt1rx1s}1t1u1v1w1x1y1z1{$1|)1}.1~3191>1C1G1K1Q1U1Z1^1c1g1l1q1w1|11111111$1)1-12161;1@1E1J1P1U1Z1_1d1i1n1r1w1{111
11111#1(1-13181=1B1G1K1N1Q1T1W1[1^1‚a1Âe1Ăh1łk1Ƃo1ǂr1Ȃu
_ c_tSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993cWtSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vctSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126~c#tSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchz}ctSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference
m4kmzcuSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referencea?uTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gaouTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Da)uTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGa/uTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)
y~81wmuDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160 
c_uSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993	cWuSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vcuSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126c#uSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patch
m4kmzcvSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referencea?vTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gaovTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)D
a)vTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGa/vTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)
y~81wmvDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160 c_vSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993cWvSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vcvSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126c#vSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patch
7K9c#wSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzcwSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referencea?wTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gaowTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Da)wTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction
cd	c!wMwDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-26d- Fixes CVE-2023-0286 X.400 address type confusion in X.509 GeneralName
- Resolves: rhbz#21767901wmwDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160 c_wSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993cWwSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vcwSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126
7K9$c#xSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchz#cxSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference"a?xTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g!aoxTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)D a)xTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction
cd	c!)wMxDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-26d- Fixes CVE-2023-0286 X.400 address type confusion in X.509 GeneralName
- Resolves: rhbz#21767901(wmxDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160 'c_xSahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993&cWxSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054v%cxSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126
(f-aoyTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)",aeyTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structureB+a%yTomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulusf*aoyTomáš Mráz <tmraz@redhat.com> 1.0.2k-11Z'- fix deadlock in RNG in the FIPS mode in mariadb
m4kmz2cySahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference1a?yTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g0aoyTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)D/a)yTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionG.a/yTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)
yf6aozTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)"5aezTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structureB4a%zTomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulus3c#ySahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patch
m4kmz;czSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference:a?zTomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g9aozTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)D8a)zTomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionG7a/zTomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)
y~HD@a){Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionG?a/{Tomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)f>ao{Tomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)v=czSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126<c#zSahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patch
{vEc{Sahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126Dc#{Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzCc{Sahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referenceBa?{Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gAao{Tomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)
9_%9gJao|Tomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)DIa)|Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGHa/|Tomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597) Gc_{Sahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993FcW{Sahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054
&lgl& Pc_|Sahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993OcW|Sahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vNc|Sahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126Mc#|Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzLc|Sahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referenceKa?|Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)
JzUc}Sahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referenceTa?}Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gSao}Tomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)DRa)}Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction1Qwm|Dmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160
y~81Zwm}Dmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160 Yc_}Sahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993XcW}Sahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vWc}Sahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126Vc#}Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patch
Z)f_ao~Tomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)"^ae~Tomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structureB]a%~Tomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulusf\ao~Tomáš Mráz <tmraz@redhat.com> 1.0.2k-11Z'- fix deadlock in RNG in the FIPS mode in mariadb![wM}Dmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-26d- Fixes CVE-2023-0286 X.400 address type confusion in X.509 GeneralName
- Resolves: rhbz#2176790

er+V:eD

9160f97ee226a06b3da3e93f37a538bc89b639fbbfac6c152018d42532d6799bD	
712ab01fa46be5aaee9891582b7f8a686291b410d047f9e6094789f904b00faaD
888ebbd06b84707dedf11dfd38f8932aad6140dc08932e3e14ac9591d14843c5D
cc98e7151dca218503a6d908ee58257a7e7958347117c435c93746255a841c89D
62ee7eed9057a933f386601510a2ee1dbe6cee295c00a4e75c1d5ca32a0e17cdD
1adcef07e0e83f4fc27809eacf51bdd1d75267095f0cf92832e1d636e04e477cD
d2bc75a69afc2e940e2a933c55941d7c4f269ade992c161c681b9cd72ff158a4D
0460e382ab0b0ff062ef27fbd07fe4a599aeb4704c295ef0ba4f0c14632a257aD
eff160acd2825b382858cba77f4f60a433755fd1621b6510f0a8a57dae54a512D
2130f82985059fdc1825e34c818c10ce54691d99d56fb5b663cd8452c750913eD
d8d9646b9eb2ea7556c1afe53b0eacb8fcacd861d66fc82fd1bcecaf2c47e41aD
569c75b83fb8869babbff7da458924e4ef2a3cceabd9c1e5b1274d1d95ca521cD~
eee4cb71588d025d63ac9b8c966fe2a49c4d9ab89f23553fcb7e360eb7ef2343
m4kmzdc~Sahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referenceca?~Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gbao~Tomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Daa)~Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionG`a/~Tomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)
7yH7fiaoTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)"haeTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structureBga%Tomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulusffaoTomáš Mráz <tmraz@redhat.com> 1.0.2k-11Z'- fix deadlock in RNG in the FIPS mode in mariadbec#~Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patch
m4kmzncSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referencema?Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)glaoTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Dka)Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGja/Tomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)
yfraoTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)"qaeTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structureBpa%Tomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulusoc#Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patch
m4kmzwcSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referenceva?Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)guaoTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Dta)Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGsa/Tomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)
y~"{aeTomáš Mráz <tmraz@redhat.com> 1.0.2k-13['- add S390x assembler updates
- make CA name list comparison function case sensitive (#1548401)
- fix CVE-2017-3735 - possible one byte overread with X.509 IPAdressFamily
- fix CVE-2018-0732 - large prime DH DoS of TLS client
- fix CVE-2018-0737 - RSA key generation cache timing vulnerability
- fix CVE-2018-0739 - stack overflow parsing recursive ASN.1 structureBza%Tomáš Mráz <tmraz@redhat.com> 1.0.2k-12Z1@- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulusvycSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126xc#Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patch
a?Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gaoTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)D~a)Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionG}a/Tomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)f|aoTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)
Ga/Tomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)faoTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004)vcSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126c#Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzcSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference
7K9
c#Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchz	cSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referencea?Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gaoTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Da)Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction
dUGa/Tomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)faoTomáš Mráz <tmraz@redhat.com> 1.0.2k-14[(@- ppc64le is not multilib architecture (#1585004) 
c_Sahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993cWSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vcSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126
7K9c#Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzcSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referencea?Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gaoTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)Da)Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction
*d*Da)Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionGa/Tomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597) c_Sahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993cWSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054vcSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126
{vcSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126c#Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchzcSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-referencea?Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)gaoTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)
o_8oD#a)Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extractionG"a/Tomáš Mráz <tmraz@redhat.com> 1.0.2k-16[r@- fix CVE-2018-0495 - ROHNP - Key Extraction Side Channel on DSA, ECDSA
- fix incorrect error message on FIPS DSA parameter generation (#1603597)1!wmDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160  c_Sahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993cWSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054
{v(cSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126'c#Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchz&cSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference%a?Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g$aoTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)
O_;Og-aoTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)D,a)Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction1+wmDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160 *c_Sahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993)cWSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054
&lgl& 3c_Sahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#20399932cWSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054v1cSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#19321260c#Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchz/cSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference.a?Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)
[J[8a?Tomáš Mráz <tmraz@redhat.com> 1.0.2k-19\@- close the RSA decryption 9 lives of Bleichenbacher cat
  timing side channel (#1649568)g7aoTomáš Mráz <tmraz@redhat.com> 1.0.2k-18\C@- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)D6a)Tomáš Mráz <tmraz@redhat.com> 1.0.2k-17\Z@- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
  timing side-channel key extraction!5wMDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-26d- Fixes CVE-2023-0286 X.400 address type confusion in X.509 GeneralName
- Resolves: rhbz#217679014wmDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160
_ =c_Sahana Prasad <sahana@redhat.com> 1.0.2k-24a@- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993<cWSahana Prasad <sahana@redhat.com> 1.0.2k-23a@- fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- Resolves: rhbz#1996054v;cSahana Prasad <sahana@redhat.com> 1.0.2k-22a/k@- fix CVE-2021-23841 openssl: NULL pointer dereference
  in X509_issuer_and_serial_hash()
- fix CVE-2021-23840 openssl: integer overflow in CipherUpdate
- Resolves: rhbz#1932132, rhbz#1932126:c#Sahana Prasad <sahana@redhat.com> 1.0.2k-21_$- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patchz9cSahana Prasad <sahana@redhat.com> 1.0.2k-20_$- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference
JBbBgAJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[AgQJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603^@gYJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129!?wMDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-26d- Fixes CVE-2023-0286 X.400 address type confusion in X.509 GeneralName
- Resolves: rhbz#21767901>wmDmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.0.2k-25b;- Fixes CVE-2022-2078 Infinite loop in BN_mod_sqrt() reachable when parsing certificates
- Related: rhbz#2067160
^0	W^tGiJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-FisJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762EiOJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560DiJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560KCi/Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441
WmWKeUKen Gaillot <kgaillot@redhat.com> - 1.1.20-4\@- Update security patches
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907hJemKen Gaillot <kgaillot@redhat.com> - 1.1.20-3\- Support more than 64KB of fence agent output
- Avoid unnecessary recovery of group member
- Improve IPC clients' authentication of servers (CVE-2018-16877)
- Improve pacemakerd authentication of running subdaemons (CVE-2018-16878)
- Fix use-after-free with potential information disclosure (CVE-2019-3885)
- Resolves: rhbz#1549366
- Resolves: rhbz#1609453
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907IiJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159Hi5Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401
z:Ne-Ken Gaillot <kgaillot@redhat.com> - 1.1.21-2]e@- Add latest upstream bug fixes to rebase roll-up patch
- Resolves: rhbz#1731189;MeKen Gaillot <kgaillot@redhat.com> - 1.1.21-1]@1@- Recover from quiesced DC disk
- Avoid timeouts and excessive stonithd CPU usage at start-up in large clusters
- Default serialized order constraints to symmetrical=false
- Avoid fence loops due to incorrect Pacemaker Remote ordering
- Default concurrent-fencing to true
- Harden GnuTLS priorities
- Rebase on upstream 1.1.21 final version
- Resolves: rhbz#1596125
- Resolves: rhbz#1625671
- Resolves: rhbz#1672225
- Resolves: rhbz#1704870
- Resolves: rhbz#1710422
- Resolves: rhbz#1727280
- Resolves: rhbz#1731189LeKen Gaillot <kgaillot@redhat.com> - 1.1.20-5\- Correct memory issue in fence agent output fix
- Resolves: rhbz#1549366
ZbQeaKen Gaillot <kgaillot@redhat.com> - 1.1.22-1^@- Show correct disabled resource count in status display
- Run-time option for Pacemaker Remote bind address
- Avoid restart loop when migration is left dangling
- Improve help for clean-up option
- Do not overweight group colocation scores
- Rebase on upstream 1.1.22+63d2d79
- Resolves: rhbz#1458953
- Resolves: rhbz#1743373
- Resolves: rhbz#1757951
- Resolves: rhbz#1758969
- Resolves: rhbz#1760669
- Resolves: rhbz#1792492rPeKen Gaillot <kgaillot@redhat.com> - 1.1.21-4^ P@- Implement shutdown-lock feature
- Resolves: rhbz#1781820!Oe_Ken Gaillot <kgaillot@redhat.com> - 1.1.21-3]@- Avoid invalid transition when guest node's host is unclean but can't be fenced
- Resolves: rhbz#1755659
}hTemKen Gaillot <kgaillot@redhat.com> - 1.1.20-3\- Support more than 64KB of fence agent output
- Avoid unnecessary recovery of group member
- Improve IPC clients' authentication of servers (CVE-2018-16877)
- Improve pacemakerd authentication of running subdaemons (CVE-2018-16878)
- Fix use-after-free with potential information disclosure (CVE-2019-3885)
- Resolves: rhbz#1549366
- Resolves: rhbz#1609453
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907xSi	Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1.1_- Prevent ACL bypass (CVE-2020-25654)
- Resolves: rhbz#1892140Re!Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1^V@- Improve help for clean-up option
- Avoid pending DC fencing getting "stuck" in status display
- Rebase on upstream 1.1.23-rc1
- Resolves: rhbz#1758969
- Resolves: rhbz#1787749
- Resolves: rhbz#1792492
_;WeKen Gaillot <kgaillot@redhat.com> - 1.1.21-1]@1@- Recover from quiesced DC disk
- Avoid timeouts and excessive stonithd CPU usage at start-up in large clusters
- Default serialized order constraints to symmetrical=false
- Avoid fence loops due to incorrect Pacemaker Remote ordering
- Default concurrent-fencing to true
- Harden GnuTLS priorities
- Rebase on upstream 1.1.21 final version
- Resolves: rhbz#1596125
- Resolves: rhbz#1625671
- Resolves: rhbz#1672225
- Resolves: rhbz#1704870
- Resolves: rhbz#1710422
- Resolves: rhbz#1727280
- Resolves: rhbz#1731189VeKen Gaillot <kgaillot@redhat.com> - 1.1.20-5\- Correct memory issue in fence agent output fix
- Resolves: rhbz#1549366UeUKen Gaillot <kgaillot@redhat.com> - 1.1.20-4\@- Update security patches
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907
psWpb[eaKen Gaillot <kgaillot@redhat.com> - 1.1.22-1^@- Show correct disabled resource count in status display
- Run-time option for Pacemaker Remote bind address
- Avoid restart loop when migration is left dangling
- Improve help for clean-up option
- Do not overweight group colocation scores
- Rebase on upstream 1.1.22+63d2d79
- Resolves: rhbz#1458953
- Resolves: rhbz#1743373
- Resolves: rhbz#1757951
- Resolves: rhbz#1758969
- Resolves: rhbz#1760669
- Resolves: rhbz#1792492rZeKen Gaillot <kgaillot@redhat.com> - 1.1.21-4^ P@- Implement shutdown-lock feature
- Resolves: rhbz#1781820!Ye_Ken Gaillot <kgaillot@redhat.com> - 1.1.21-3]@- Avoid invalid transition when guest node's host is unclean but can't be fenced
- Resolves: rhbz#1755659Xe-Ken Gaillot <kgaillot@redhat.com> - 1.1.21-2]e@- Add latest upstream bug fixes to rebase roll-up patch
- Resolves: rhbz#1731189
}h^emKen Gaillot <kgaillot@redhat.com> - 1.1.20-3\- Support more than 64KB of fence agent output
- Avoid unnecessary recovery of group member
- Improve IPC clients' authentication of servers (CVE-2018-16877)
- Improve pacemakerd authentication of running subdaemons (CVE-2018-16878)
- Fix use-after-free with potential information disclosure (CVE-2019-3885)
- Resolves: rhbz#1549366
- Resolves: rhbz#1609453
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907x]i	Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1.1_- Prevent ACL bypass (CVE-2020-25654)
- Resolves: rhbz#1892140\e!Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1^V@- Improve help for clean-up option
- Avoid pending DC fencing getting "stuck" in status display
- Rebase on upstream 1.1.23-rc1
- Resolves: rhbz#1758969
- Resolves: rhbz#1787749
- Resolves: rhbz#1792492

er+V:eD
548503fcc3f2803339a5af3de411713359e79ca6ca3db7aa4c0e221102c86c86D
5a1a14cf6500d688cfc898ef4ad3cdca51ca829da10e098f412a9a7c63ce86a6D
75e71ed053fe00917b68d0c20c63e517d0ac97df8a4844808522ccadcc94f568D
b44b031eb36308c5d95e0003f3cb129a5fec117dca9e4bca0e8448da97c03db7D
b465213867e16065d782ed8791eb493ef1e3a0260294e730ea9d4c86e4e7510fD
ce2818bc990e044731480c4212c5c16d899dd8492d225c3948f138e58c8031c5D
d56af4f540372397f7f6ab93063de3ab226d756872e62f763f65d636a00b901cD
8dedf2da6f27ca502253716ed29c2de2e1c11c34463b46e12d9e88053e48796cD
232dc47c310816030f4221dedbaacb35004dc24f0a8fd53b574e4aaf87fa67d7D
0a050612befea77a0541c8b1e8c5655262271ebc40a5897b3fcb7bc85c56fc53D

8d89498cb8dcf0209edf2265d251f9c645f540e964d455d6554b04f5f5f6edd8D
54ab243faa67657b5614c4deb2cdc3ed777723a654a2faa316fcbea81f89ea3aD
7878e948667fc382edca199743ec7e4e3bd9f82c2a0b2e50af7f93121264ee6e
_;aeKen Gaillot <kgaillot@redhat.com> - 1.1.21-1]@1@- Recover from quiesced DC disk
- Avoid timeouts and excessive stonithd CPU usage at start-up in large clusters
- Default serialized order constraints to symmetrical=false
- Avoid fence loops due to incorrect Pacemaker Remote ordering
- Default concurrent-fencing to true
- Harden GnuTLS priorities
- Rebase on upstream 1.1.21 final version
- Resolves: rhbz#1596125
- Resolves: rhbz#1625671
- Resolves: rhbz#1672225
- Resolves: rhbz#1704870
- Resolves: rhbz#1710422
- Resolves: rhbz#1727280
- Resolves: rhbz#1731189`eKen Gaillot <kgaillot@redhat.com> - 1.1.20-5\- Correct memory issue in fence agent output fix
- Resolves: rhbz#1549366_eUKen Gaillot <kgaillot@redhat.com> - 1.1.20-4\@- Update security patches
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907
psWpbeeaKen Gaillot <kgaillot@redhat.com> - 1.1.22-1^@- Show correct disabled resource count in status display
- Run-time option for Pacemaker Remote bind address
- Avoid restart loop when migration is left dangling
- Improve help for clean-up option
- Do not overweight group colocation scores
- Rebase on upstream 1.1.22+63d2d79
- Resolves: rhbz#1458953
- Resolves: rhbz#1743373
- Resolves: rhbz#1757951
- Resolves: rhbz#1758969
- Resolves: rhbz#1760669
- Resolves: rhbz#1792492rdeKen Gaillot <kgaillot@redhat.com> - 1.1.21-4^ P@- Implement shutdown-lock feature
- Resolves: rhbz#1781820!ce_Ken Gaillot <kgaillot@redhat.com> - 1.1.21-3]@- Avoid invalid transition when guest node's host is unclean but can't be fenced
- Resolves: rhbz#1755659be-Ken Gaillot <kgaillot@redhat.com> - 1.1.21-2]e@- Add latest upstream bug fixes to rebase roll-up patch
- Resolves: rhbz#1731189
}hhemKen Gaillot <kgaillot@redhat.com> - 1.1.20-3\- Support more than 64KB of fence agent output
- Avoid unnecessary recovery of group member
- Improve IPC clients' authentication of servers (CVE-2018-16877)
- Improve pacemakerd authentication of running subdaemons (CVE-2018-16878)
- Fix use-after-free with potential information disclosure (CVE-2019-3885)
- Resolves: rhbz#1549366
- Resolves: rhbz#1609453
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907xgi	Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1.1_- Prevent ACL bypass (CVE-2020-25654)
- Resolves: rhbz#1892140fe!Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1^V@- Improve help for clean-up option
- Avoid pending DC fencing getting "stuck" in status display
- Rebase on upstream 1.1.23-rc1
- Resolves: rhbz#1758969
- Resolves: rhbz#1787749
- Resolves: rhbz#1792492
_;keKen Gaillot <kgaillot@redhat.com> - 1.1.21-1]@1@- Recover from quiesced DC disk
- Avoid timeouts and excessive stonithd CPU usage at start-up in large clusters
- Default serialized order constraints to symmetrical=false
- Avoid fence loops due to incorrect Pacemaker Remote ordering
- Default concurrent-fencing to true
- Harden GnuTLS priorities
- Rebase on upstream 1.1.21 final version
- Resolves: rhbz#1596125
- Resolves: rhbz#1625671
- Resolves: rhbz#1672225
- Resolves: rhbz#1704870
- Resolves: rhbz#1710422
- Resolves: rhbz#1727280
- Resolves: rhbz#1731189jeKen Gaillot <kgaillot@redhat.com> - 1.1.20-5\- Correct memory issue in fence agent output fix
- Resolves: rhbz#1549366ieUKen Gaillot <kgaillot@redhat.com> - 1.1.20-4\@- Update security patches
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907
psWpboeaKen Gaillot <kgaillot@redhat.com> - 1.1.22-1^@- Show correct disabled resource count in status display
- Run-time option for Pacemaker Remote bind address
- Avoid restart loop when migration is left dangling
- Improve help for clean-up option
- Do not overweight group colocation scores
- Rebase on upstream 1.1.22+63d2d79
- Resolves: rhbz#1458953
- Resolves: rhbz#1743373
- Resolves: rhbz#1757951
- Resolves: rhbz#1758969
- Resolves: rhbz#1760669
- Resolves: rhbz#1792492rneKen Gaillot <kgaillot@redhat.com> - 1.1.21-4^ P@- Implement shutdown-lock feature
- Resolves: rhbz#1781820!me_Ken Gaillot <kgaillot@redhat.com> - 1.1.21-3]@- Avoid invalid transition when guest node's host is unclean but can't be fenced
- Resolves: rhbz#1755659le-Ken Gaillot <kgaillot@redhat.com> - 1.1.21-2]e@- Add latest upstream bug fixes to rebase roll-up patch
- Resolves: rhbz#1731189
}hremKen Gaillot <kgaillot@redhat.com> - 1.1.20-3\- Support more than 64KB of fence agent output
- Avoid unnecessary recovery of group member
- Improve IPC clients' authentication of servers (CVE-2018-16877)
- Improve pacemakerd authentication of running subdaemons (CVE-2018-16878)
- Fix use-after-free with potential information disclosure (CVE-2019-3885)
- Resolves: rhbz#1549366
- Resolves: rhbz#1609453
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907xqi	Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1.1_- Prevent ACL bypass (CVE-2020-25654)
- Resolves: rhbz#1892140pe!Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1^V@- Improve help for clean-up option
- Avoid pending DC fencing getting "stuck" in status display
- Rebase on upstream 1.1.23-rc1
- Resolves: rhbz#1758969
- Resolves: rhbz#1787749
- Resolves: rhbz#1792492
_;ueKen Gaillot <kgaillot@redhat.com> - 1.1.21-1]@1@- Recover from quiesced DC disk
- Avoid timeouts and excessive stonithd CPU usage at start-up in large clusters
- Default serialized order constraints to symmetrical=false
- Avoid fence loops due to incorrect Pacemaker Remote ordering
- Default concurrent-fencing to true
- Harden GnuTLS priorities
- Rebase on upstream 1.1.21 final version
- Resolves: rhbz#1596125
- Resolves: rhbz#1625671
- Resolves: rhbz#1672225
- Resolves: rhbz#1704870
- Resolves: rhbz#1710422
- Resolves: rhbz#1727280
- Resolves: rhbz#1731189teKen Gaillot <kgaillot@redhat.com> - 1.1.20-5\- Correct memory issue in fence agent output fix
- Resolves: rhbz#1549366seUKen Gaillot <kgaillot@redhat.com> - 1.1.20-4\@- Update security patches
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907
psWpbyeaKen Gaillot <kgaillot@redhat.com> - 1.1.22-1^@- Show correct disabled resource count in status display
- Run-time option for Pacemaker Remote bind address
- Avoid restart loop when migration is left dangling
- Improve help for clean-up option
- Do not overweight group colocation scores
- Rebase on upstream 1.1.22+63d2d79
- Resolves: rhbz#1458953
- Resolves: rhbz#1743373
- Resolves: rhbz#1757951
- Resolves: rhbz#1758969
- Resolves: rhbz#1760669
- Resolves: rhbz#1792492rxeKen Gaillot <kgaillot@redhat.com> - 1.1.21-4^ P@- Implement shutdown-lock feature
- Resolves: rhbz#1781820!we_Ken Gaillot <kgaillot@redhat.com> - 1.1.21-3]@- Avoid invalid transition when guest node's host is unclean but can't be fenced
- Resolves: rhbz#1755659ve-Ken Gaillot <kgaillot@redhat.com> - 1.1.21-2]e@- Add latest upstream bug fixes to rebase roll-up patch
- Resolves: rhbz#1731189
}h|emKen Gaillot <kgaillot@redhat.com> - 1.1.20-3\- Support more than 64KB of fence agent output
- Avoid unnecessary recovery of group member
- Improve IPC clients' authentication of servers (CVE-2018-16877)
- Improve pacemakerd authentication of running subdaemons (CVE-2018-16878)
- Fix use-after-free with potential information disclosure (CVE-2019-3885)
- Resolves: rhbz#1549366
- Resolves: rhbz#1609453
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907x{i	Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1.1_- Prevent ACL bypass (CVE-2020-25654)
- Resolves: rhbz#1892140ze!Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1^V@- Improve help for clean-up option
- Avoid pending DC fencing getting "stuck" in status display
- Rebase on upstream 1.1.23-rc1
- Resolves: rhbz#1758969
- Resolves: rhbz#1787749
- Resolves: rhbz#1792492
_;eKen Gaillot <kgaillot@redhat.com> - 1.1.21-1]@1@- Recover from quiesced DC disk
- Avoid timeouts and excessive stonithd CPU usage at start-up in large clusters
- Default serialized order constraints to symmetrical=false
- Avoid fence loops due to incorrect Pacemaker Remote ordering
- Default concurrent-fencing to true
- Harden GnuTLS priorities
- Rebase on upstream 1.1.21 final version
- Resolves: rhbz#1596125
- Resolves: rhbz#1625671
- Resolves: rhbz#1672225
- Resolves: rhbz#1704870
- Resolves: rhbz#1710422
- Resolves: rhbz#1727280
- Resolves: rhbz#1731189~eKen Gaillot <kgaillot@redhat.com> - 1.1.20-5\- Correct memory issue in fence agent output fix
- Resolves: rhbz#1549366}eUKen Gaillot <kgaillot@redhat.com> - 1.1.20-4\@- Update security patches
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907
psWpbeaKen Gaillot <kgaillot@redhat.com> - 1.1.22-1^@- Show correct disabled resource count in status display
- Run-time option for Pacemaker Remote bind address
- Avoid restart loop when migration is left dangling
- Improve help for clean-up option
- Do not overweight group colocation scores
- Rebase on upstream 1.1.22+63d2d79
- Resolves: rhbz#1458953
- Resolves: rhbz#1743373
- Resolves: rhbz#1757951
- Resolves: rhbz#1758969
- Resolves: rhbz#1760669
- Resolves: rhbz#1792492reKen Gaillot <kgaillot@redhat.com> - 1.1.21-4^ P@- Implement shutdown-lock feature
- Resolves: rhbz#1781820!e_Ken Gaillot <kgaillot@redhat.com> - 1.1.21-3]@- Avoid invalid transition when guest node's host is unclean but can't be fenced
- Resolves: rhbz#1755659e-Ken Gaillot <kgaillot@redhat.com> - 1.1.21-2]e@- Add latest upstream bug fixes to rebase roll-up patch
- Resolves: rhbz#1731189
}hemKen Gaillot <kgaillot@redhat.com> - 1.1.20-3\- Support more than 64KB of fence agent output
- Avoid unnecessary recovery of group member
- Improve IPC clients' authentication of servers (CVE-2018-16877)
- Improve pacemakerd authentication of running subdaemons (CVE-2018-16878)
- Fix use-after-free with potential information disclosure (CVE-2019-3885)
- Resolves: rhbz#1549366
- Resolves: rhbz#1609453
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907xi	Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1.1_- Prevent ACL bypass (CVE-2020-25654)
- Resolves: rhbz#1892140e!Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1^V@- Improve help for clean-up option
- Avoid pending DC fencing getting "stuck" in status display
- Rebase on upstream 1.1.23-rc1
- Resolves: rhbz#1758969
- Resolves: rhbz#1787749
- Resolves: rhbz#1792492
_;	eKen Gaillot <kgaillot@redhat.com> - 1.1.21-1]@1@- Recover from quiesced DC disk
- Avoid timeouts and excessive stonithd CPU usage at start-up in large clusters
- Default serialized order constraints to symmetrical=false
- Avoid fence loops due to incorrect Pacemaker Remote ordering
- Default concurrent-fencing to true
- Harden GnuTLS priorities
- Rebase on upstream 1.1.21 final version
- Resolves: rhbz#1596125
- Resolves: rhbz#1625671
- Resolves: rhbz#1672225
- Resolves: rhbz#1704870
- Resolves: rhbz#1710422
- Resolves: rhbz#1727280
- Resolves: rhbz#1731189eKen Gaillot <kgaillot@redhat.com> - 1.1.20-5\- Correct memory issue in fence agent output fix
- Resolves: rhbz#1549366eUKen Gaillot <kgaillot@redhat.com> - 1.1.20-4\@- Update security patches
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907
psWpb
eaKen Gaillot <kgaillot@redhat.com> - 1.1.22-1^@- Show correct disabled resource count in status display
- Run-time option for Pacemaker Remote bind address
- Avoid restart loop when migration is left dangling
- Improve help for clean-up option
- Do not overweight group colocation scores
- Rebase on upstream 1.1.22+63d2d79
- Resolves: rhbz#1458953
- Resolves: rhbz#1743373
- Resolves: rhbz#1757951
- Resolves: rhbz#1758969
- Resolves: rhbz#1760669
- Resolves: rhbz#1792492reKen Gaillot <kgaillot@redhat.com> - 1.1.21-4^ P@- Implement shutdown-lock feature
- Resolves: rhbz#1781820!e_Ken Gaillot <kgaillot@redhat.com> - 1.1.21-3]@- Avoid invalid transition when guest node's host is unclean but can't be fenced
- Resolves: rhbz#1755659
e-Ken Gaillot <kgaillot@redhat.com> - 1.1.21-2]e@- Add latest upstream bug fixes to rebase roll-up patch
- Resolves: rhbz#1731189
}hemKen Gaillot <kgaillot@redhat.com> - 1.1.20-3\- Support more than 64KB of fence agent output
- Avoid unnecessary recovery of group member
- Improve IPC clients' authentication of servers (CVE-2018-16877)
- Improve pacemakerd authentication of running subdaemons (CVE-2018-16878)
- Fix use-after-free with potential information disclosure (CVE-2019-3885)
- Resolves: rhbz#1549366
- Resolves: rhbz#1609453
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907xi	Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1.1_- Prevent ACL bypass (CVE-2020-25654)
- Resolves: rhbz#1892140e!Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1^V@- Improve help for clean-up option
- Avoid pending DC fencing getting "stuck" in status display
- Rebase on upstream 1.1.23-rc1
- Resolves: rhbz#1758969
- Resolves: rhbz#1787749
- Resolves: rhbz#1792492
_;eKen Gaillot <kgaillot@redhat.com> - 1.1.21-1]@1@- Recover from quiesced DC disk
- Avoid timeouts and excessive stonithd CPU usage at start-up in large clusters
- Default serialized order constraints to symmetrical=false
- Avoid fence loops due to incorrect Pacemaker Remote ordering
- Default concurrent-fencing to true
- Harden GnuTLS priorities
- Rebase on upstream 1.1.21 final version
- Resolves: rhbz#1596125
- Resolves: rhbz#1625671
- Resolves: rhbz#1672225
- Resolves: rhbz#1704870
- Resolves: rhbz#1710422
- Resolves: rhbz#1727280
- Resolves: rhbz#1731189eKen Gaillot <kgaillot@redhat.com> - 1.1.20-5\- Correct memory issue in fence agent output fix
- Resolves: rhbz#1549366eUKen Gaillot <kgaillot@redhat.com> - 1.1.20-4\@- Update security patches
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907
psWpbeaKen Gaillot <kgaillot@redhat.com> - 1.1.22-1^@- Show correct disabled resource count in status display
- Run-time option for Pacemaker Remote bind address
- Avoid restart loop when migration is left dangling
- Improve help for clean-up option
- Do not overweight group colocation scores
- Rebase on upstream 1.1.22+63d2d79
- Resolves: rhbz#1458953
- Resolves: rhbz#1743373
- Resolves: rhbz#1757951
- Resolves: rhbz#1758969
- Resolves: rhbz#1760669
- Resolves: rhbz#1792492reKen Gaillot <kgaillot@redhat.com> - 1.1.21-4^ P@- Implement shutdown-lock feature
- Resolves: rhbz#1781820!e_Ken Gaillot <kgaillot@redhat.com> - 1.1.21-3]@- Avoid invalid transition when guest node's host is unclean but can't be fenced
- Resolves: rhbz#1755659e-Ken Gaillot <kgaillot@redhat.com> - 1.1.21-2]e@- Add latest upstream bug fixes to rebase roll-up patch
- Resolves: rhbz#1731189
}hemKen Gaillot <kgaillot@redhat.com> - 1.1.20-3\- Support more than 64KB of fence agent output
- Avoid unnecessary recovery of group member
- Improve IPC clients' authentication of servers (CVE-2018-16877)
- Improve pacemakerd authentication of running subdaemons (CVE-2018-16878)
- Fix use-after-free with potential information disclosure (CVE-2019-3885)
- Resolves: rhbz#1549366
- Resolves: rhbz#1609453
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907xi	Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1.1_- Prevent ACL bypass (CVE-2020-25654)
- Resolves: rhbz#1892140e!Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1^V@- Improve help for clean-up option
- Avoid pending DC fencing getting "stuck" in status display
- Rebase on upstream 1.1.23-rc1
- Resolves: rhbz#1758969
- Resolves: rhbz#1787749
- Resolves: rhbz#1792492
_;eKen Gaillot <kgaillot@redhat.com> - 1.1.21-1]@1@- Recover from quiesced DC disk
- Avoid timeouts and excessive stonithd CPU usage at start-up in large clusters
- Default serialized order constraints to symmetrical=false
- Avoid fence loops due to incorrect Pacemaker Remote ordering
- Default concurrent-fencing to true
- Harden GnuTLS priorities
- Rebase on upstream 1.1.21 final version
- Resolves: rhbz#1596125
- Resolves: rhbz#1625671
- Resolves: rhbz#1672225
- Resolves: rhbz#1704870
- Resolves: rhbz#1710422
- Resolves: rhbz#1727280
- Resolves: rhbz#1731189eKen Gaillot <kgaillot@redhat.com> - 1.1.20-5\- Correct memory issue in fence agent output fix
- Resolves: rhbz#1549366eUKen Gaillot <kgaillot@redhat.com> - 1.1.20-4\@- Update security patches
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907
psWpb!eaKen Gaillot <kgaillot@redhat.com> - 1.1.22-1^@- Show correct disabled resource count in status display
- Run-time option for Pacemaker Remote bind address
- Avoid restart loop when migration is left dangling
- Improve help for clean-up option
- Do not overweight group colocation scores
- Rebase on upstream 1.1.22+63d2d79
- Resolves: rhbz#1458953
- Resolves: rhbz#1743373
- Resolves: rhbz#1757951
- Resolves: rhbz#1758969
- Resolves: rhbz#1760669
- Resolves: rhbz#1792492r eKen Gaillot <kgaillot@redhat.com> - 1.1.21-4^ P@- Implement shutdown-lock feature
- Resolves: rhbz#1781820!e_Ken Gaillot <kgaillot@redhat.com> - 1.1.21-3]@- Avoid invalid transition when guest node's host is unclean but can't be fenced
- Resolves: rhbz#1755659e-Ken Gaillot <kgaillot@redhat.com> - 1.1.21-2]e@- Add latest upstream bug fixes to rebase roll-up patch
- Resolves: rhbz#1731189
}h$emKen Gaillot <kgaillot@redhat.com> - 1.1.20-3\- Support more than 64KB of fence agent output
- Avoid unnecessary recovery of group member
- Improve IPC clients' authentication of servers (CVE-2018-16877)
- Improve pacemakerd authentication of running subdaemons (CVE-2018-16878)
- Fix use-after-free with potential information disclosure (CVE-2019-3885)
- Resolves: rhbz#1549366
- Resolves: rhbz#1609453
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907x#i	Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1.1_- Prevent ACL bypass (CVE-2020-25654)
- Resolves: rhbz#1892140"e!Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1^V@- Improve help for clean-up option
- Avoid pending DC fencing getting "stuck" in status display
- Rebase on upstream 1.1.23-rc1
- Resolves: rhbz#1758969
- Resolves: rhbz#1787749
- Resolves: rhbz#1792492
_;'eKen Gaillot <kgaillot@redhat.com> - 1.1.21-1]@1@- Recover from quiesced DC disk
- Avoid timeouts and excessive stonithd CPU usage at start-up in large clusters
- Default serialized order constraints to symmetrical=false
- Avoid fence loops due to incorrect Pacemaker Remote ordering
- Default concurrent-fencing to true
- Harden GnuTLS priorities
- Rebase on upstream 1.1.21 final version
- Resolves: rhbz#1596125
- Resolves: rhbz#1625671
- Resolves: rhbz#1672225
- Resolves: rhbz#1704870
- Resolves: rhbz#1710422
- Resolves: rhbz#1727280
- Resolves: rhbz#1731189&eKen Gaillot <kgaillot@redhat.com> - 1.1.20-5\- Correct memory issue in fence agent output fix
- Resolves: rhbz#1549366%eUKen Gaillot <kgaillot@redhat.com> - 1.1.20-4\@- Update security patches
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907
psWpb+eaKen Gaillot <kgaillot@redhat.com> - 1.1.22-1^@- Show correct disabled resource count in status display
- Run-time option for Pacemaker Remote bind address
- Avoid restart loop when migration is left dangling
- Improve help for clean-up option
- Do not overweight group colocation scores
- Rebase on upstream 1.1.22+63d2d79
- Resolves: rhbz#1458953
- Resolves: rhbz#1743373
- Resolves: rhbz#1757951
- Resolves: rhbz#1758969
- Resolves: rhbz#1760669
- Resolves: rhbz#1792492r*eKen Gaillot <kgaillot@redhat.com> - 1.1.21-4^ P@- Implement shutdown-lock feature
- Resolves: rhbz#1781820!)e_Ken Gaillot <kgaillot@redhat.com> - 1.1.21-3]@- Avoid invalid transition when guest node's host is unclean but can't be fenced
- Resolves: rhbz#1755659(e-Ken Gaillot <kgaillot@redhat.com> - 1.1.21-2]e@- Add latest upstream bug fixes to rebase roll-up patch
- Resolves: rhbz#1731189
}h.emKen Gaillot <kgaillot@redhat.com> - 1.1.20-3\- Support more than 64KB of fence agent output
- Avoid unnecessary recovery of group member
- Improve IPC clients' authentication of servers (CVE-2018-16877)
- Improve pacemakerd authentication of running subdaemons (CVE-2018-16878)
- Fix use-after-free with potential information disclosure (CVE-2019-3885)
- Resolves: rhbz#1549366
- Resolves: rhbz#1609453
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907x-i	Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1.1_- Prevent ACL bypass (CVE-2020-25654)
- Resolves: rhbz#1892140,e!Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1^V@- Improve help for clean-up option
- Avoid pending DC fencing getting "stuck" in status display
- Rebase on upstream 1.1.23-rc1
- Resolves: rhbz#1758969
- Resolves: rhbz#1787749
- Resolves: rhbz#1792492
_;1eKen Gaillot <kgaillot@redhat.com> - 1.1.21-1]@1@- Recover from quiesced DC disk
- Avoid timeouts and excessive stonithd CPU usage at start-up in large clusters
- Default serialized order constraints to symmetrical=false
- Avoid fence loops due to incorrect Pacemaker Remote ordering
- Default concurrent-fencing to true
- Harden GnuTLS priorities
- Rebase on upstream 1.1.21 final version
- Resolves: rhbz#1596125
- Resolves: rhbz#1625671
- Resolves: rhbz#1672225
- Resolves: rhbz#1704870
- Resolves: rhbz#1710422
- Resolves: rhbz#1727280
- Resolves: rhbz#17311890eKen Gaillot <kgaillot@redhat.com> - 1.1.20-5\- Correct memory issue in fence agent output fix
- Resolves: rhbz#1549366/eUKen Gaillot <kgaillot@redhat.com> - 1.1.20-4\@- Update security patches
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907
psWpb5eaKen Gaillot <kgaillot@redhat.com> - 1.1.22-1^@- Show correct disabled resource count in status display
- Run-time option for Pacemaker Remote bind address
- Avoid restart loop when migration is left dangling
- Improve help for clean-up option
- Do not overweight group colocation scores
- Rebase on upstream 1.1.22+63d2d79
- Resolves: rhbz#1458953
- Resolves: rhbz#1743373
- Resolves: rhbz#1757951
- Resolves: rhbz#1758969
- Resolves: rhbz#1760669
- Resolves: rhbz#1792492r4eKen Gaillot <kgaillot@redhat.com> - 1.1.21-4^ P@- Implement shutdown-lock feature
- Resolves: rhbz#1781820!3e_Ken Gaillot <kgaillot@redhat.com> - 1.1.21-3]@- Avoid invalid transition when guest node's host is unclean but can't be fenced
- Resolves: rhbz#17556592e-Ken Gaillot <kgaillot@redhat.com> - 1.1.21-2]e@- Add latest upstream bug fixes to rebase roll-up patch
- Resolves: rhbz#1731189
}h8emKen Gaillot <kgaillot@redhat.com> - 1.1.20-3\- Support more than 64KB of fence agent output
- Avoid unnecessary recovery of group member
- Improve IPC clients' authentication of servers (CVE-2018-16877)
- Improve pacemakerd authentication of running subdaemons (CVE-2018-16878)
- Fix use-after-free with potential information disclosure (CVE-2019-3885)
- Resolves: rhbz#1549366
- Resolves: rhbz#1609453
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907x7i	Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1.1_- Prevent ACL bypass (CVE-2020-25654)
- Resolves: rhbz#18921406e!Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1^V@- Improve help for clean-up option
- Avoid pending DC fencing getting "stuck" in status display
- Rebase on upstream 1.1.23-rc1
- Resolves: rhbz#1758969
- Resolves: rhbz#1787749
- Resolves: rhbz#1792492
_;;eKen Gaillot <kgaillot@redhat.com> - 1.1.21-1]@1@- Recover from quiesced DC disk
- Avoid timeouts and excessive stonithd CPU usage at start-up in large clusters
- Default serialized order constraints to symmetrical=false
- Avoid fence loops due to incorrect Pacemaker Remote ordering
- Default concurrent-fencing to true
- Harden GnuTLS priorities
- Rebase on upstream 1.1.21 final version
- Resolves: rhbz#1596125
- Resolves: rhbz#1625671
- Resolves: rhbz#1672225
- Resolves: rhbz#1704870
- Resolves: rhbz#1710422
- Resolves: rhbz#1727280
- Resolves: rhbz#1731189:eKen Gaillot <kgaillot@redhat.com> - 1.1.20-5\- Correct memory issue in fence agent output fix
- Resolves: rhbz#15493669eUKen Gaillot <kgaillot@redhat.com> - 1.1.20-4\@- Update security patches
- Resolves: rhbz#1694556
- Resolves: rhbz#1694559
- Resolves: rhbz#1694907
psWpb?eaKen Gaillot <kgaillot@redhat.com> - 1.1.22-1^@- Show correct disabled resource count in status display
- Run-time option for Pacemaker Remote bind address
- Avoid restart loop when migration is left dangling
- Improve help for clean-up option
- Do not overweight group colocation scores
- Rebase on upstream 1.1.22+63d2d79
- Resolves: rhbz#1458953
- Resolves: rhbz#1743373
- Resolves: rhbz#1757951
- Resolves: rhbz#1758969
- Resolves: rhbz#1760669
- Resolves: rhbz#1792492r>eKen Gaillot <kgaillot@redhat.com> - 1.1.21-4^ P@- Implement shutdown-lock feature
- Resolves: rhbz#1781820!=e_Ken Gaillot <kgaillot@redhat.com> - 1.1.21-3]@- Avoid invalid transition when guest node's host is unclean but can't be fenced
- Resolves: rhbz#1755659<e-Ken Gaillot <kgaillot@redhat.com> - 1.1.21-2]e@- Add latest upstream bug fixes to rebase roll-up patch
- Resolves: rhbz#1731189
}aC9Nikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5BwJakub Jelen <jjelen@redhat.com> - 7.4p1-13 + 0.10.3-1Y- Revert default of GSSAPIStrictAcceptorCheck=no back to yes (#1488982)xAi	Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1.1_- Prevent ACL bypass (CVE-2020-25654)
- Resolves: rhbz#1892140@e!Ken Gaillot <kgaillot@redhat.com> - 1.1.23-1^V@- Improve help for clean-up option
- Avoid pending DC fencing getting "stuck" in status display
- Rebase on upstream 1.1.23-rc1
- Resolves: rhbz#1758969
- Resolves: rhbz#1787749
- Resolves: rhbz#1792492
::-GweJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)FwGJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cEwSJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)DwJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
vi8aM9Nikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5LwJakub Jelen <jjelen@redhat.com> - 7.4p1-13 + 0.10.3-1Y- Revert default of GSSAPIStrictAcceptorCheck=no back to yes (#1488982)K7Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)JwJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|IwJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)HwJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-QweJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)PwGJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cOwSJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)NwJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
`vi`aV9Nikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5U7Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)TwJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|SwJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)RwJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
::-ZweJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)YwGJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cXwSJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)WwJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
vi!a`9Nikos Mavrogiannopoulos <nmav@redhat.com> - 7.4p1-14 + 0.10.3-2YZ@- Rebuilt for RHEL-7.5_7Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-23 + 0.10.3-2d!- Avoid remote code execution in ssh-agent PKCS#11 support
  Resolves: CVE-2023-38408^7Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)]wJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|\wJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)[wJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)

er+V:eD$
1d55e611e9d8085d8a329b27450b4fb96d5c488a59e0f8043df68d8765940b62D#
c72ec63e342428ba130a7b46db76c98e1bb002c13c208a1768a433c1cb1625f6D"
0e0d9ae9f3664f3a8aa2a994019ef5a1293a67c401f5fde714661afc37cd8438D!
1e9916f4ea1571cb999400331ff1a0186d71b4f21844b0f5ed33712e42b454deD 
92f5cebdb6aa43fe3966ec42e66aa71cfa74ff2c65896eb315d447b773ceeffaD
ffa522d1a8d77788b084a92a321a67dd3087522b4c665f5b59ff0576763efcd2D
b54db851c807040a3e77a35898fb88a95a15258a38f47ec41a9657101b87a477D
524cdd869b6f342223fb2289ff3e3ebaa8408bf57bbd257d0349efe0946b9dbdD
06218f80b35658bc0f58476f103dcd67638009385f21b603c1005339fbd5841eD
ce80d24890bb555cc41eecc7ee95f5ff2de2c648c51eb9f4c10e2d48275a1c45D
c382bcbdefe46cc6dfe4495a86577e964b1e6d8d445b5112c6f6224c1177b7ebD
dd909825185de2980f63f3adca1ec98161c8737e440d1fdcae489d50885111a0D
e204c387125736b5126202b4d99222db286a7d676c022fc50ccfe99a1a8ed302
::-dweJakub Jelen <jjelen@redhat.com> - 7.4p1-18 + 0.10.3-2\d- invalidate supplemental group cache used by temporarily_use_uid()
  when the target uid differs (#1583735)cwGJakub Jelen <jjelen@redhat.com> - 7.4p1-17 + 0.10.3-2\<y- Fix for CVE-2018-15473 (#1619079)
- Enable GCM mode for AES ciphers in FIPS mode (#1600869)cbwSJakub Jelen <jjelen@redhat.com> - 7.4p1-16 + 0.10.3-2Z	- Fix for CVE-2017-15906 (#1517226)awJakub Jelen <jjelen@redhat.com> - 7.4p1-15 + 0.10.3-2ZN- Do not hang if SSH AuthorizedKeysCommand output is too large (#1496467)
- Do not segfault pam_ssh_agent_auth if keyfile is missing (#1494268)
- Do not segfault in audit code during cleanup (#1488083)
- Add WinSCP 5.10+ compatibility (#1496808)
- Clatch between ClientAlive and rekeying timeouts (#1480510)
- Exclude dsa and ed25519 from default proposed keys in FIPS mode (#1456853)
- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1478035)
Jvi!J8kWTim Waugh <twaugh@redhat.com> 0.3.2-1MS@- 0.3.2.jFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.3.1-4MQ0@- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuildi7Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-23 + 0.10.3-2d!- Avoid remote code execution in ssh-agent PKCS#11 support
  Resolves: CVE-2023-38408h7Dmitry Belyavskiy <dbelyavs@redhat.com> - 7.4p1-22 + 0.10.3-2aU- avoid segfault in Kerberos cache cleanup (#1999263)
- fix CVE-2021-41617 (#2008884)gwJakub Jelen <jjelen@redhat.com> - 7.4p1-21 + 0.10.3-2]- Avoid double comma in the default cipher list in FIPS mode (#1722446)|fwJakub Jelen <jjelen@redhat.com> - 7.4p1-20 + 0.10.3-2\@- Revert the updating of cached passwd structure (#1712053)ewJakub Jelen <jjelen@redhat.com> - 7.4p1-19 + 0.10.3-2\}@- Update cached passwd structure after PAM authentication (#1674541)
Se/3SsUCThan Ngo <than@redhat.com> - 0.3.3-5_- Resolves: #1905282, filterdiff not removing the header from excluded files in a git patchLr]?Daniel Mach <dmach@redhat.com> - 0.3.3-4RU- Mass rebuild 2014-01-24Lq]?Daniel Mach <dmach@redhat.com> - 0.3.3-3Rk- Mass rebuild 2013-12-27lpWTim Waugh <twaugh@redhat.com> 0.3.3-2Qf- Fixed help output (bug #948973).
- Fixed changelog dates.8oWTim Waugh <twaugh@redhat.com> 0.3.3-1QZ@- 0.3.3.nFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.3.2-4Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildmFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.3.2-3P	H@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildlFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.3.2-2O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
+vcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSucENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ytcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5zc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)yc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sxcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`wc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|y~cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M}e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x|e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4{cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YS	cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|
c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)bR20RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{1ʂ|1˂1̂1͂1΂	1ς
1Ђ1т1҂1ӂ1Ԃ1Ղ!1ւ$1ׂ'1؂+1ق.1ڂ11ۂ51܂81݂;1ނ?1߂C1G1M1Q1V1Z1`1d1k1s1v1z1~111	1
111111$1'1+1/12161:1=1B2E2I2M2P2T2X2[2`2c2
g2k2n2
r2v2y2~222	2222222#2'2*2.22252 :2!=2"A2#E2$H2%L2&P2'S2(X2)[2*_2+c2-f2.j2/n
Gx$e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4#cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5"c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)!c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YS'cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y&cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M%e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|+c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s*cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`)c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)(cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?M/e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x.e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4-cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5,c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+2cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS1cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y0cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb56c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)5c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s4cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`3c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|y:cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M9e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x8e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)47cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`=c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)<cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS;cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
GxBe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4AcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5@c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)?c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s>cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSEcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yDcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MCe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|Ic%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sHcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`Gc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)FcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?MMe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xLe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4KcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5Jc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+PcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSOcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yNcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5Tc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Sc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sRcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`Qc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|yXcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MWe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xVe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4UcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`[c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)ZcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSYcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gx`e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4_cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5^c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)]c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s\cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSccENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ybcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Mae7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)

er+V:eD1
a679dce4cdf9324f44ec3dde672fc1978611c584f08c5d478d5091c78cbd8d27D0
47969fe770db3c0a761b6cada255644049a5915767baa562e1ad4010e338fa35D/
1563bc40289a666bdb5b6b948e788815b2b17e6ae8e32bd7645f8b2183f82d81D.
61a3387e568e2d46dba9932a1b959d8cdcdc17e7ba5ba6162d1085700bca40bfD-
afbb3b090c43e945d72c42562f98eaacc46b54087a8745127ab819b83c16c1d4D,
a9fe909da2403e47e2010f35a9f2d61ffe1808b042a987b503c7c7c86a4ca895D+
935c4a6b750a10f3954948c3fdc3d3d3fc914b613533a75f0b3f087222591c52D*
6d7a031416a306298ea9aa3f89fda52e0ed56ff1a48e7c9aa6e2d05c299a912bD)
cb8f53283b6ea93d8c0582b7445551d68528dd0bc9eb4f0843b5026088dc7d1bD(
c6d99f5b0af764bb805c8a25d287df1075775cac7560d92681c1956e45be1836D'
db61bcfb079f0f252d5ffb4b3f3f8e5ecb7d0963e782c43dc2c33b98250903afD&
e2c51db626a29271a596a4998c57628cb1a37278b0c06566729c4f36ebe12ebfD%
1c18af2ea0813b4f11b632925aa26a45a80769bbc1970188c2088f2a572d15f2
|`{|gc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sfcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`ec_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)dcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Mke7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xje
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4icNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5hc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+ncUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSmcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ylcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5rc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)qc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)spcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`oc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|yvcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Mue7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xte
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4scNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`yc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)xcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSwcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gx~e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4}cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5|c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373){c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)szcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?M	e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y
cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`
c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|#c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s"cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`!c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989) cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?M'e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x&e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4%cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5$c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+*cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS)cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y(cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5.c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)-c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s,cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`+c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|y2cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M1e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x0e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4/cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`5c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)4cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS3cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gx:e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)49cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)58c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)7c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s6cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YS=cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y<cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M;e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|Ac%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s@cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`?c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)>cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?MEe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xDe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4CcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5Bc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+HcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSGcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yFcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5Lc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Kc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sJcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`Ic_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|yPcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MOe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xNe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4McNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`Sc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)RcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSQcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
GxXe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4WcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5Vc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Uc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sTcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YS[cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yZcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MYe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|_c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s^cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`]c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)\cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Mce7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xbe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4acNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5`c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)

er+V:eD>
ef66a09a84348d5622f0a06d5b40c4c3a826cd62cc050713646da3398248d3bcD=
000c783ad67a44fbc26df8ad81ecd49cdb80c72bac2e0468445fe1454d75a522D<
3d240ca1688d3b6d6b6371756d97a6aeb744a9a8557a0e554507ed284c013250D;
fb054f7e2c4002421c1a192b728bcaf7b397d066ecfefa67cb8fef0e35bc581cD:
58e972759347ee479f41461c94e8a34221731d3f5e4a517f3472362a853548e8D9
517ba6cf72ceb45dad798a989a8d5555073598c3fdb08328ca70ce3270d794ecD8
555b9b32b3933d547da1546861b8ba783cebcece9d878cb604bcea85de993e1eD7
9c7aa04ec57ce07caa9cac6c9e1c323ac60dccf00396891f117caa96863e4bc8D6
0e50e504282d4892f5bb05084db338d47c7312f569aaa3fcbb60451b38e17abdD5
3d77cb8ffdf08db08553aa94df7707d9a0b2fdd0e4b233f18189356e16f26f6dD4
50637eb878b9d983dd9ef2ddcf46fd38bb751310409cbed318028c6ff3c514daD3
31030f948b4de98b9532d047d42d0551f372894911f715fa36be3ad12c33673bD2
830b3c9f628ae0632f8a286c53dd687d6d9700525aa381704ed8d5f152ff43d5
+fcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSecENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ydcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5jc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)ic%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)shcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`gc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|yncNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Mme7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xle
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4kcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`qc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)pcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSocENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxve
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4ucNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5tc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)sc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)srcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSycENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yxcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Mwe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|}c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s|cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`{c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)zcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5~c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x
e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4	cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS
cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+"cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS!cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5&c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)%c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s$cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`#c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|y*cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M)e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x(e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4'cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`-c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989),cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS+cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gx2e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)41cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)50c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)/c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s.cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YS5cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y4cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M3e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|9c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s8cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`7c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)6cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?M=e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x<e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4;cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5:c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+@cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS?cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y>cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5Dc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Cc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sBcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`Ac_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|yHcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MGe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xFe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4EcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`Kc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)JcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSIcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
GxPe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4OcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5Nc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Mc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sLcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yRcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MQe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|Wc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sVcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`Uc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)TcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?M[e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xZe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4YcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5Xc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+^cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS]cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y\cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5bc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)ac%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s`cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`_c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|yfcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Mee7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xde
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4ccNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)

er+V:eDK
593add2cc79905baeb70c882cdcad64327b85acb067b1c40ed26d9b81428f98fDJ
fdd43196e4073342f9366aaa990c71e1f5ed36c633b8c6bc935da0a5d6fd8dd6DI
e1c638e35cb4c885aeeee8317465b9424dc26e85b3d95b1a84601727366a7bafDH
1d1a5f1c9af127056984dbd611ad930070668a97c33632c67e5261d7e1cb2491DG
02bef4b4e654f8dd811b3eecdf5516bd91608806ac3f8f3f596117947edc6652DF
e6275a113df1d4b0f258355e75adebd1cc562e086cb9229721d17bdf2efe7547DE
5b2d852e11af1f062bd27d2ec053f7544ae75e75c9c69a0eba94e287ef60f044DD
25c2ea7e33ae0636ef4ab7f805e637c22a39efff5c74c6192209cc229e03cc3fDC
f26eeb8cccc9c113330f61096bc1da10e3aa2798e3da03526928f761d77785ecDB
3aca72fcb712db6bcacfb3033aa1cee51230819ab53e90a5d44e468d36de4777DA
625bcfa68a8612af0baa8859f0b08904bf96f2b85129d8b178500dc33ae0d9b1D@
e15ae7c19afb196a228163866e632f1a6dcc877a8490009959707d354bf833c5D?
3b6da3b418fa4789feaf744245bf1f8d61ffecf40017e594ba7ddac0372332c0
##`ic_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)hcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSgcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxne
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4mcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5lc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)kc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sjcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSqcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ypcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Moe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|uc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)stcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`sc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)rcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Mye7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xxe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4wcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5vc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+|cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS{cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yzcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s~cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`}c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5
c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)	c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M
e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issuebR2RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{21v22y23}2425262728292:2;2<2="2>&2?*2@-2A22B52C92D=2E@2FD2GH2HK2IP2JS2KW2L[2M^2Nb2Of2Qi2Rn2Sq2Tu2Uy2V|2W2X2Y2Z2[2\2^2_2`2a"2b%2c*2d-2e12f52g82h<2i@2jC2kH2lK2mO2nS2oV2pZ2q^2ra2sf2ti2vm2wq2xt2yx2z|2{2|2}2~222222"2%2)2-2024282;2@2C2G2K2N2R2V2Y2^2a
?F?Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|y"cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M!e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`%c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)$cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS#cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gx*e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4)cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5(c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)'c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s&cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YS-cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y,cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M+e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|1c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s0cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`/c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989).cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?M5e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x4e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)43cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)52c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+8cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS7cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y6cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5<c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373);c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s:cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`9c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|y@cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M?e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x>e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4=cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`Cc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)BcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSAcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
GxHe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4GcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5Fc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Ec%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sDcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSKcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yJcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MIe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|Oc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sNcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`Mc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)LcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?MSe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xRe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4QcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5Pc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+VcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSUcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yTcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5Zc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Yc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sXcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`Wc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|y^cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M]e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x\e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4[cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`ac_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)`cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS_cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxfe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4ecNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5dc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)cc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sbcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSicENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yhcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Mge7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)

er+V:eDX
fabce6473ab9dd2d36533444066b3b09b7055e6949844f6b7b52531e3d42f914DW
f6db1b3fb1c1f752662a489c152e531a9bb3841011827eb8aa03225e7521e058DV
f26c9b240bf171505aca04c2bee6244c21da11124c5c4e9424507df05251fc9dDU
c17c899c85f4bf07e0a3d27c864052d979465728527bfb0e23eee049af68e8daDT
07061aa8f12ae1f09d204f2dc47e1608d9dce33042da18739a076fb7fa37fc13DS
484cb9d2c6a1b098378ddaf70bdb38133dc17da620e66106b68fe5d774de37f0DR
83798801595394e9798351e90ce24993027044de3f66b95c7da60059c1e8b1e1DQ
f636e55dd0ac87d64782eab7493353a4a5210c1b1178a67593b356a1a82b9180DP
c03292752990aca90663df6d79d0ced6a2ec2471fe674a726f6cb19f9a3d1044DO
a24b7bc1700c9020bc5e2e066c84007538c58004033ee208ec22a6eaec755711DN
66fb08b8f23996f9e3c5ff82303886294a5596df60377f29eaf713d40038fe52DM
f63a8f468eb357e3dd612d59f718c35eb2605df94684b551b1a984c732862fbeDL
9fff25a7253ba8afcc5b3c163312a1f8eb3150a5d840c690f898fdad96a16863
|`{|mc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)slcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`kc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)jcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Mqe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xpe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4ocNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5nc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+tcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSscENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yrcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5xc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)wc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)svcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`uc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|y|cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M{e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xze
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4ycNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)~cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS}cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s
cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`	c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4
cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gx"e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4!cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5 c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YS%cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y$cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M#e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s(cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`'c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)&cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?M-e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x,e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4+cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5*c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+0cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS/cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y.cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb54c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)3c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s2cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`1c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|y8cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M7e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x6e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)45cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`;c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989):cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS9cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gx@e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4?cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5>c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)=c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s<cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSCcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yBcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MAe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|Gc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sFcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`Ec_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)DcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?MKe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xJe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4IcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5Hc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+NcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSMcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yLcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5Rc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Qc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sPcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`Oc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|yVcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MUe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xTe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4ScNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`Yc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)XcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSWcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gx^e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4]cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5\c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)[c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sZcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSacENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y`cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M_e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|ec%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sdcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`cc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)bcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Mie7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xhe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4gcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5fc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)

er+V:eDe
3a8eb48fa6a00af9e9dcaea80df8b2f0afdff3c5e06bdb7f02f38db59317e110Dd
80f69ad6b79f4c708720c43f742e85b81d91b383f247fed78bd4d579dc9c3358Dc
1ff119238acc93098135e4601d4178d8f681c72ad91be0993739d0774b0824fcDb
f01ff7e1c5e53cb4a291d2d25285e11895191ae658824d9c05669907941f4c34Da
4bc4f9b1528598d166b590b62bdc782e328cf226edcc858a3d5a60dfc73ace54D`
0265dca6e210e12ede6c0a683df0e1068291dfc35f0589544af045bc6f7bc898D_
80476ff98812cbbcef61bbadab92341dfb34cec67d6654aa104495f4469a5e98D^
4933dfa26c52c90e550bd7f8821e6e879a155babc9e60eba5472271aa463f60dD]
319595ccfe3f0ebb45ebf6df0161096bcff75941edf191e4b985817405996515D\
8f4946bea37ca0505511d6afe2aeaedbca2a9b61c752de65d10866dcea00fad4D[
7ec31554c4d3119952f3384c6c4e611722a6b4069ee4f6de885660f933e49194DZ
764b877678619df456d5a383316616afaadcb63072ba391f1e306803942b51c7DY
ef84b3d3c085de9b3168fe830f5afbe609ea6253e83c2174f7a07ed4efa94889
+lcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSkcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yjcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5pc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)oc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sncNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`mc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|ytcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Mse7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xre
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4qcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`wc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)vcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSucENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gx|e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4{cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5zc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)yc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sxcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y~cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M}e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+
cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS	cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|!c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?M%e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x$e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4#cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5"c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+(cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS'cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y&cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5,c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)+c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s*cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`)c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|y0cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M/e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x.e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4-cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`3c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)2cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS1cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gx8e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)47cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)56c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)5c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s4cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YS;cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y:cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M9e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|?c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s>cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`=c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)<cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?MCe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xBe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4AcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5@c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+FcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSEcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yDcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5Jc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Ic%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sHcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`Gc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|yNcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MMe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xLe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4KcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`Qc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)PcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSOcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
GxVe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4UcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5Tc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Sc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sRcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSYcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yXcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MWe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|]c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s\cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`[c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)ZcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Mae7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x`e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4_cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5^c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+dcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSccENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ybcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5hc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)gc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sfcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`ec_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|ylcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Mke7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xje
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4icNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)

er+V:eDr
e7dd086b27d2e2fb6eeac4d5032cfb52149916c6c88f31b59a12c5bc48c71672Dq
d5ca3273956d3492b8666156d82f9217e75f2dc732b30d638dfba9f17f7cebd1Dp
d8993e0975c0634b18618194daf0bdb6dc0edc17cb7ba015d6a03e74436a21b9Do
af1a3c42b3b93fdac07667c059dd206acf1333b397990288ff235aa9fb0d2febDn
8d0c9dc0f9481cf8541a333911be9aaa997c3a44c8cccd0692a6c28d7a5cc0afDm
492eb3d51d30fb1af43e49282e578161b5b19cce5b45e3fad31bb1affd621cffDl
f3feee0430c1446d861e17d9a043a72cc0690f3c3618ae27a60610bfc197c499Dk
26d3fc7fdf6a25b2590dc3f7c8cdb80f22bcb6b5d68c1dad9f14e3337c0ff45bDj
4d30dcad5eaa26754ca93719c17a0897f17b0ffe1c050c78afd90769cefa027dDi
72c749a3e397bf18c32e697dd5d3adea234b8aa2a9755e5fd2cd34140f3988eeDh
9f3c7997d99823801fcaa63e46125569a1f11fcfe6050871f1260ac19a424cabDg
b7b161ba7512043214d72f44fb3c9276bcc89dc678e4ff85292f3754b4a8eb45Df
7a77df777aa49e715d99b786d4ec6329b8453f637359c0c17c35c656462e7f18
##`oc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)ncUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSmcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxte
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4scNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5rc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)qc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)spcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSwcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yvcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Mue7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|{c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)szcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`yc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)xcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x~e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4}cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5|c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)bR2RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{2i2l2p2t2w2|2222
222222!2%2(2,2023282;2?2C2F2J2N2Q2V2Y2]2a2d2h2l2o2t2w2{22‚2Â2ł
2Ƃ
2ǂ2Ȃ2ɂ2ʂ2˂ 2̂$2͂(2΂+2ς02Ђ32т72҂;2ӂ>2ԂB2ՂF2ւI2ׂN2؂Q2قU2ڂY2ۂ\2܂`2݂d2ނg2߂l2o2s2w2z2~222
2
22222!2%2)2-2125292=2@2A2C2E2H2J2L
|G|y
cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M	e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`
c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+ cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5$c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)#c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s"cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`!c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|y(cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M'e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x&e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4%cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`+c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)*cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS)cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gx0e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4/cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5.c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)-c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s,cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YS3cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y2cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)M1e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|7c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s6cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`5c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)4cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?M;e7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)x:e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)49cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)58c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+>cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS=cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)y<cNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5Bc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Ac%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s@cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`?c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|yFcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MEe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xDe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4CcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`Ic_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)HcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSGcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
GxNe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4McNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5Lc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Kc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sJcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSQcENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yPcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MOe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|Uc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sTcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`Sc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)RcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?MYe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xXe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4WcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5Vc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+\cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS[cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yZcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5`c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)_c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s^cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`]c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|ydcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Mce7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xbe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4acNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`gc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)fcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSecENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxle
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4kcNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5jc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)ic%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)shcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSocENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yncNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Mme7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)

er+V:eD
0af8a6a9e3b24968bed3be9b8de12ef658fbbfc2164edfd7186a7cced585e5ecD~
ab2758dd1426e326fee61bd2598d1e3e1099478f8620ffce7bed64945dec78b0D}
5bee4fc25b489a427e91f9972dc2c6116c2159fb420fda53da7e793376b51ff1D|
d9c05b12d02951ae6c67f270d0144e1db212577c99d87cbff4e1fbf63e9576cdD{
dc05a54d0cc4b8594a65cf6d4163952f2a15da4e0eb7775e31af36653653ed82Dz
27200e5f598a44637d8820694fe7f924e715e6052b300a7ab49405cf2a482a7fDy
59c284ae5662792cf83c5c6b3c1f1a903d45dae94e28667259f016a7aec17a9fDx
eb29338fad95f41a0a8ae1941a0bf623792e7b35ba434c87283f68788f25817dDw
e2176587ba77f1d2a38ee9ec89781028cc33042f069dc103523ebee850d6b68fDv
36de51c65d7a208f69d6a68ad07d468a5ba7dc6b245097eac3e9db107d5d6ef4Du
63558d42575ae3f93c0f05594402264ff08a7344fbea29b0340f75e051de0cf2Dt
555f9e2c01c86b0dd1946344981074918e29ef0848b6ac14772ed9fef57c2115Ds
6ddc2c9687b0552d18c038d01ec287088d430f5ce898b65fb0fe065c00b8ef8f
|`{|sc%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)srcNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`qc_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)pcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Mwe7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xve
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4ucNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5tc	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+zcUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSycENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yxcNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5~c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)}c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s|cNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`{c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueScENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gx
e
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4	cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YS
cENathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)ycNathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|c%Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)scNathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`c_Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cUNathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?Me7Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xe
Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4cNathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
55#agIvan Devat <idevat@redhat.com> - 0.9.168-2]@- Do not generate custom DH key if it was not requested by setting its custom length
- Resolves: rhbz#1760434"aeIvan Devat <idevat@redhat.com> - 0.9.168-1]H@- Rebased to latest upstream sources (see CHANGELOG.md)
- Resolves: rhbz#1730747 rhbz#1725849 rhbz#1551663 rhbz#1595444 rhbz#1671174 rhbz#1712315 rhbz#1619253 rhbz#1710750 rhbz#1466088 rhbz#1558063 rhbz#1665898 rhbz#1500012 rhbz#1673829a!Ivan Devat <idevat@redhat.com> - 0.9.167-3]@- Fixed crashes in the `pcs cluster auth` command
- Resolves: rhbz#1676956saIvan Devat <idevat@redhat.com> - 0.9.167-2\8- Updated logo and favicon in web UI
- Resolves: rhbz#1700542
p\pgaoIvan Devat <idevat@redhat.com> - 0.9.169-2^- Keep autogenerated IDs of set constraints reasonably short
- Use fixed version of python module subprocess (package python2-subprocess32)
- Resolves: rhbz#1820813 rhbz#1824206 aaIvan Devat <idevat@redhat.com> - 0.9.169-1^@- Rebased to latest upstream sources (see CHANGELOG.md)
- Resolves: rhbz#1822078 rhbz#1759269 rhbz#14485692eOndrej Mular <omular@redhat.com> - 0.9.168-4]- Added command 'pcs resource relations'
- Added command 'pcs resource safe-disable'
- Resolves: rhbz#1770975 rhbz#1770973Ca'Ivan Devat <idevat@redhat.com> - 0.9.168-3]d@- More fixes for the case when PATH environment variable is not set
- Pcsd no longer sends Server HTTP header
- Empty constraint option are not allowed in pcs constraint order and pcs constraint colocation add commands
- Resolves: rhbz#1500012 rhbz#1765606 rhbz#1671174
<c<"!aeIvan Devat <idevat@redhat.com> - 0.9.168-1]H@- Rebased to latest upstream sources (see CHANGELOG.md)
- Resolves: rhbz#1730747 rhbz#1725849 rhbz#1551663 rhbz#1595444 rhbz#1671174 rhbz#1712315 rhbz#1619253 rhbz#1710750 rhbz#1466088 rhbz#1558063 rhbz#1665898 rhbz#1500012 rhbz#1673829 a!Ivan Devat <idevat@redhat.com> - 0.9.167-3]@- Fixed crashes in the `pcs cluster auth` command
- Resolves: rhbz#1676956qqsIvan Devat <idevat@redhat.com> - 0.9.169-3.el7_3.1_u@- Explicitly close libcurl connections to prevent stalled TCP connections in CLOSE-WAIT state
- Added support for loading DH keys from a file
- Resolves: rhbz#1870551 rhbz#1888479a[Ivan Devat <idevat@redhat.com> - 0.9.169-3^W@- Added option: pcs resource [safe-]disable --simulate` has a new option `--brief` to print only a list of affected resources
- Fixed race-condition when removing multiple resources from web UI
- Resolves: rhbz#1833115 rhbz#1843593
XY %aaIvan Devat <idevat@redhat.com> - 0.9.169-1^@- Rebased to latest upstream sources (see CHANGELOG.md)
- Resolves: rhbz#1822078 rhbz#1759269 rhbz#14485692$eOndrej Mular <omular@redhat.com> - 0.9.168-4]- Added command 'pcs resource relations'
- Added command 'pcs resource safe-disable'
- Resolves: rhbz#1770975 rhbz#1770973C#a'Ivan Devat <idevat@redhat.com> - 0.9.168-3]d@- More fixes for the case when PATH environment variable is not set
- Pcsd no longer sends Server HTTP header
- Empty constraint option are not allowed in pcs constraint order and pcs constraint colocation add commands
- Resolves: rhbz#1500012 rhbz#1765606 rhbz#1671174#"agIvan Devat <idevat@redhat.com> - 0.9.168-2]@- Do not generate custom DH key if it was not requested by setting its custom length
- Resolves: rhbz#1760434
cc)q9Ivan Devat <idevat@redhat.com> - 0.9.169-3.el7_3.2c>@- Update rubygem rack
- Upgrade jquery in web-ui
- Resolves: rhbz#2099578 rhbz#2093232q(qsIvan Devat <idevat@redhat.com> - 0.9.169-3.el7_3.1_u@- Explicitly close libcurl connections to prevent stalled TCP connections in CLOSE-WAIT state
- Added support for loading DH keys from a file
- Resolves: rhbz#1870551 rhbz#1888479'a[Ivan Devat <idevat@redhat.com> - 0.9.169-3^W@- Added option: pcs resource [safe-]disable --simulate` has a new option `--brief` to print only a list of affected resources
- Fixed race-condition when removing multiple resources from web UI
- Resolves: rhbz#1833115 rhbz#1843593g&aoIvan Devat <idevat@redhat.com> - 0.9.169-2^- Keep autogenerated IDs of set constraints reasonably short
- Use fixed version of python module subprocess (package python2-subprocess32)
- Resolves: rhbz#1820813 rhbz#1824206
55#-agIvan Devat <idevat@redhat.com> - 0.9.168-2]@- Do not generate custom DH key if it was not requested by setting its custom length
- Resolves: rhbz#1760434",aeIvan Devat <idevat@redhat.com> - 0.9.168-1]H@- Rebased to latest upstream sources (see CHANGELOG.md)
- Resolves: rhbz#1730747 rhbz#1725849 rhbz#1551663 rhbz#1595444 rhbz#1671174 rhbz#1712315 rhbz#1619253 rhbz#1710750 rhbz#1466088 rhbz#1558063 rhbz#1665898 rhbz#1500012 rhbz#1673829+a!Ivan Devat <idevat@redhat.com> - 0.9.167-3]@- Fixed crashes in the `pcs cluster auth` command
- Resolves: rhbz#1676956s*aIvan Devat <idevat@redhat.com> - 0.9.167-2\8- Updated logo and favicon in web UI
- Resolves: rhbz#1700542
p\pg1aoIvan Devat <idevat@redhat.com> - 0.9.169-2^- Keep autogenerated IDs of set constraints reasonably short
- Use fixed version of python module subprocess (package python2-subprocess32)
- Resolves: rhbz#1820813 rhbz#1824206 0aaIvan Devat <idevat@redhat.com> - 0.9.169-1^@- Rebased to latest upstream sources (see CHANGELOG.md)
- Resolves: rhbz#1822078 rhbz#1759269 rhbz#14485692/eOndrej Mular <omular@redhat.com> - 0.9.168-4]- Added command 'pcs resource relations'
- Added command 'pcs resource safe-disable'
- Resolves: rhbz#1770975 rhbz#1770973C.a'Ivan Devat <idevat@redhat.com> - 0.9.168-3]d@- More fixes for the case when PATH environment variable is not set
- Pcsd no longer sends Server HTTP header
- Empty constraint option are not allowed in pcs constraint order and pcs constraint colocation add commands
- Resolves: rhbz#1500012 rhbz#1765606 rhbz#1671174
<c<"5aeIvan Devat <idevat@redhat.com> - 0.9.168-1]H@- Rebased to latest upstream sources (see CHANGELOG.md)
- Resolves: rhbz#1730747 rhbz#1725849 rhbz#1551663 rhbz#1595444 rhbz#1671174 rhbz#1712315 rhbz#1619253 rhbz#1710750 rhbz#1466088 rhbz#1558063 rhbz#1665898 rhbz#1500012 rhbz#16738294a!Ivan Devat <idevat@redhat.com> - 0.9.167-3]@- Fixed crashes in the `pcs cluster auth` command
- Resolves: rhbz#1676956q3qsIvan Devat <idevat@redhat.com> - 0.9.169-3.el7_3.1_u@- Explicitly close libcurl connections to prevent stalled TCP connections in CLOSE-WAIT state
- Added support for loading DH keys from a file
- Resolves: rhbz#1870551 rhbz#18884792a[Ivan Devat <idevat@redhat.com> - 0.9.169-3^W@- Added option: pcs resource [safe-]disable --simulate` has a new option `--brief` to print only a list of affected resources
- Fixed race-condition when removing multiple resources from web UI
- Resolves: rhbz#1833115 rhbz#1843593
XY 9aaIvan Devat <idevat@redhat.com> - 0.9.169-1^@- Rebased to latest upstream sources (see CHANGELOG.md)
- Resolves: rhbz#1822078 rhbz#1759269 rhbz#144856928eOndrej Mular <omular@redhat.com> - 0.9.168-4]- Added command 'pcs resource relations'
- Added command 'pcs resource safe-disable'
- Resolves: rhbz#1770975 rhbz#1770973C7a'Ivan Devat <idevat@redhat.com> - 0.9.168-3]d@- More fixes for the case when PATH environment variable is not set
- Pcsd no longer sends Server HTTP header
- Empty constraint option are not allowed in pcs constraint order and pcs constraint colocation add commands
- Resolves: rhbz#1500012 rhbz#1765606 rhbz#1671174#6agIvan Devat <idevat@redhat.com> - 0.9.168-2]@- Do not generate custom DH key if it was not requested by setting its custom length
- Resolves: rhbz#1760434
cc=q9Ivan Devat <idevat@redhat.com> - 0.9.169-3.el7_3.2c>@- Update rubygem rack
- Upgrade jquery in web-ui
- Resolves: rhbz#2099578 rhbz#2093232q<qsIvan Devat <idevat@redhat.com> - 0.9.169-3.el7_3.1_u@- Explicitly close libcurl connections to prevent stalled TCP connections in CLOSE-WAIT state
- Added support for loading DH keys from a file
- Resolves: rhbz#1870551 rhbz#1888479;a[Ivan Devat <idevat@redhat.com> - 0.9.169-3^W@- Added option: pcs resource [safe-]disable --simulate` has a new option `--brief` to print only a list of affected resources
- Fixed race-condition when removing multiple resources from web UI
- Resolves: rhbz#1833115 rhbz#1843593g:aoIvan Devat <idevat@redhat.com> - 0.9.169-2^- Keep autogenerated IDs of set constraints reasonably short
- Use fixed version of python module subprocess (package python2-subprocess32)
- Resolves: rhbz#1820813 rhbz#1824206
{3{3@eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]<?wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}>
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]
KA}Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tCgRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iBQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]2
-EWRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]MDRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
<<KH}Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]G9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]LFRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tJgRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iIQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]2
-LWRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]MKRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
N9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]LMRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
1P1Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_f3JORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<MRRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}?Q{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
NLTRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}-SWRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]
W1Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_f3JVRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)U9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<<?X{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
dYERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
p,p7[kRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]OZRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
P]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol3
^\9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999_oAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] pow3
t^eAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command3erpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
yya7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han3X`-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
fbIAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oocAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
odYAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


qe]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
dfERado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
o,po|iuRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]7hkRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]OgRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Y}lwRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]BkRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"jARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]
  ?o{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.2.el7]ef@- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}4neRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^m9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}

er+V:eD
5dd9606b0cc78d1b1b9d016a6fa1467882e158f9ff00e4781a33715ab0889212D
290f6f5895e4d30a12a9560261497d6ad631dbba6dd34aa352f5df74c5b51a5fD

82af7be38d0c8eb49df265c4c0138bdc35cb7ac26a1b6e3a4d0f0a47d293dc93D	
cc99796988903240582ca2234451a6b7eaa5f9534e910f4f9838cbd024cc7b0aD
135902f9e5faac7a0682e6189f5cfddf652759007d300d8dd5ccb7d527fec1f4D
6de2aaa52ef36e3802e22e8f09a0ff085d85520f42e12fcdb9a095686b4d365cD
9124221e268619f8424d72980a7b256e0e00ba0639fcf0be1387712d145c7416D
2520a8d9459f82ba9401fb0a86ddb5154277672b55919b252535b199ef9fc3d4D
37dc67f68342f587481c58ec0ac8c6ada7eb0f9e8b5e356c1864db3cec910332D
1e2e0f37c2f3a9f903d1952f17782bcb4362107488cc541c0bb3de118635d8f4D
f9905c0c94b3cb7db5412f3ffcce1c6b2b13d3d3d679ba948bd55a6d413c8944D
733a34dc60cdc0d449bbed26105adcf2ede2d935f0d054e31690592628f2fd4dD
a48132ab5f5f42b2a741922bb5933c0f84e9994688313798505382288ac76453
XBrRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"qARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]|puRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]
}swRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]
4ueRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^t9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bwARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~vyRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
%n%"zARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]y7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]xRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens3
}|wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]B{Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}
4~eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^}9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~yRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
n+	MRadomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens3"dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han3$
fIAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
ooAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
oYAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
--R
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE3+^	7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
,,OAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]
'
1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.2.el7]`	l- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]T#Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]
AAsJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check 3/Js#Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDsJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}osmJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjscJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]s1Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5+Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]FsJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
sJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check 34^9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDsJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}osmJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjscJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]s1Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5+Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]FsJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]bR3yRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{3P3R3T3W3X3Y3[3	]3_3a3b3c3d3e3f3i3l3o3r3s3u3w3z3|3 ~3!3#3%3&3'3(3)3*
3,3-
3.3031323335363739 3:"3<$3=&3?'3@(3A)3B*3D+3E-3G.3H/3I03J13L23M43N63P73Q83R93S:3U;3V=3W>3X?3YA3ZB3[D3\F3]G3^H3_I3`J3aK3bL3cM3eO3fQ3gS3iU3jW3kX3lY3mZ3n\3o^3p_3q`3ra3sb3td3ug3vh3wi3xk
^ 9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]
ww^"7Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]!!?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.2.el7]_- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
O$Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]R#Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE3;
?'?[&1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [19017973>T%#Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b'?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4(cAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J)Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J*Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
+Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend3C
?'?[-1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [19017973FT,#Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b.?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4/cAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J0Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J1Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
2Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend3K
KK/4YAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|3sAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
`H`[61Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [19017973O35aAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b7?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
48cAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11J9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
;Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend3T
KK/=YAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|<sAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3>aAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
AA:?oAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
KK/AYAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|@sAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3BaAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
4A4DAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.26.1.el7]`~@- selinux: fix deadlock in security_set_bools() (Ondrej Mosnacek) [1939091]
- md: fix md io stats accounting broken (Ming Lei) [1927106]
- redhat: Fix realtime_check for -private (Juri Lelli):CoAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
//F	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]@E{Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.27.1.el7]`N@- video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (Mohammed Gamal) [1941841]
- Drivers: hv: vmbus: enable VMBus protocol version 5.0 (Mohammed Gamal) [1941841]
- redhat: Add git suffix to realtime_check merge_tree (Juri Lelli)
==>GwAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
H#Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..MIAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]
ttJ		Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]
==>Kw	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
L#	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..MM	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+O'	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}HN	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 3d
SzS"Q?	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]P}	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
,,S-	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.2.el7]`A- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]1R]	Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+U'
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}HT
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 3h
SzS"W?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]V}
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
1X]
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
Y
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
Z
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2\_
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]['
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\^}Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]]9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
"_?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
1`]Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
aAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
bAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2d_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]c'Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\g9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"f?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]e9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
hAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
iAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2k_Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]j'Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\n9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"m?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]l9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
22Io
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmpRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [183483{
nnr9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]iqQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]

er+V:eD
2ae808b4a690aa7b3a3a08ea73c102fff26dca7c8554dd72bc2269c985154726D
62f9c2b74b51bf8854ad9eb25a2929d8ce7ccc484972923e91b52d1a2e026a77D
6288171549b2c71602c97035ef0f1d087455361c00d42948b460d82d0c0c4387D
d6c3d91ad22937af9a211a458f12e6b3d4f7bdc4b0d3241d7559e29615a2e379D
6f2f5c5aaa6b9cf8f21471e48aa6a2516a79b06217aba938f508f1ec9e32759dD
1a13b258a98c48877d221312e7236468718d76e2db7278d2da0271a016036278D
38e563cf1d4db62856dbadb61d0f77927c69dd05e4c6cc79a131fa4eb2081514D
df82dbee56b4fa877e8f7aef9b9d8dbc81c598816135c2ccea24f43af66790f7D
20c77d771507c889e3dc80615a78f99df44de70df4d11450949897b0fb73e028D
c72af8695184bcf71c7eb184fbd1f20bd8db5be9ccb44f698e3109b9ac66cb88D
b41d7b6dcc5a7a79787391b203c6f01ca8cc2b821d1918b71d1f1e0fd2182b3cD
70e9899b03ea3d4adef955f81b9ef893b9391bf9f209434d85b8d5254d3b97e0D

2e128ce7e0b40d016f4c989a929934ab7599ef1aeb57ed1bb868a609e4680dc3
Yt9
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"s?
Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]
22Iu

Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmv
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [183483
iwQ
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_x=
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7ym
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!{A
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7zm
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mm|Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [183483
i}QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_~=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!ARado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]
pepp_Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]+Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}
!+Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}n[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig3Z3Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]3et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush 3if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r3eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
,n	[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig3Z3Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]p_Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]3et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush 3if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r3eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030603
}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
"Q"s1Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]%IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}
FsJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]jscJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]
+Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]
PAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol3^9Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999oAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] pow3teAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command3erpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
33n[Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig3X-Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}3et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush 3if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r3eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030603}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
QQ% IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\!7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT3
PP+"URado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S#%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
up%&IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}$Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\'7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT3
PP+(URado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S)%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM,Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%+IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}*Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D-Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
((S.%Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM1Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%0IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}/Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D2Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
%v%L4Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]3	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d
7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]6)Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]5-Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]bR4RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{3zo3|p3}r3t3u3v3w3x3y3{3|3}3~33333	33
333333333 3!3"3#3&3'3(3)3,3-3.31323437393=3?3@3‚D3ÂE3łF3ƂH3ǂK3͂N3ςO3ЂQ3тT3ׂV3قW3ڂY3ۂ\3]3^3`3b3c3e3f3h3j3k3m3n3p3s3u3v3x3|3~334	44444	444
4%4+434<4D4J4P4W
%v%L9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]8	Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d&=KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000];)Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]:-Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
xx?#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]l>WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T@'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 3
3^O$3lDWRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&CKRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
BRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]A9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
iiE#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
TF'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 3
G^GH#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]G9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(BKRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-238253ȁ+IURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}3 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV3E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 3CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [20902273] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
MMN#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lMWRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&LKRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
TO'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 3
G^GQ#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]P9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(BTRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-238253ҁ+RURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}3 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV3E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 3CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [20902273] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
V#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]LURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
TW'Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 3
G^GY#Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]X9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B\Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856][Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-238253܁+ZURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}3 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV3E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 3CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [20902273] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
L]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]
&&U^)Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
`Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-238253_Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}3 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV3E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 3CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [20902273] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
hhLbRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]BaRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
&&Uc)Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
ieQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]dRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@fRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7hmRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc3g1Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
wwLjRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]3ieRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
&&Uk)Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
imQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]lRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@nRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7pmRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc3o1Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
E)E_s=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]r3Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3qeRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]

er+V:eD&
c58619a42724ddd986279b0da66e4cf0f075d25cfbc11cc80a105c9c47f0cc1cD%
8e6103f5bc92eabbe008d9d10cd7ea86a1fd82eed882657037c36f9c0dd9ef59D$
03c52d5fc8024d804e827e048d07e835a984ac5f5d9391614c51b0905c9772a0D#
6c91bb92ae5a0ac8598c4281307b9ca0d51ba4690e5f6927ebd9bc857c360de6D"
c1de6a4cb5385396b3e8ffd02b9cdbcb0a79b12b5db809d846de74cd4322d1a3D!
a42f0d2d5c250a9f3a20b0d1766de040990c5ff04917d87601eb5ecaca50cc8bD 
4cd8e9cddd54af538fc6e1a395c1cb5338b2616fac4687ec3606a53441b3b88dD
a85e9e7ec0cfd813ac23ae166540cb1ddbf0a4789afa4784dbb9d8f3c07ce5feD
02cad16355e1d26c8bd3d5c772f181d7659d048dff3d0ae06e95050139572debD
d81e6ad3a689839ef620ae3e5c932a9d0f5ef9bcd3f88d2e10f029ceb30a4f23D
8be164f0d67b7adb4850c664fc43b933559317a3a400aea58cb4c0f28d317ff3D
995ede74f9ad67d498e9de6c2936cb1589f9d0f6316193c57d226d30e41b59eaD
06e4169680e37d4d65bf7fd8382c034d2d0434ae20eadb40888e7ab261de6aa2
iuQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]tRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@vRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7xmRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc3w1Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
)E|7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_{=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]z3Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3yeRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
WW~1Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]}Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
<e_=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]7mRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc3
_TH<wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]
Hd	7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
((<wRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]
Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]
HK}Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3
eRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tgRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]4
sJan Stancek <jstancek@redhat.com> [3.10.0-1152.el7]^- [nvmem] nvmem: properly handle returned value nvmem_reg_read (Vladis Drono4	s!Jan Stancek <jstancek@redhat.com> [3.10.0-1151.el7]^W@- [netdrv] qede: Fix multicast mac configuration (Michal Schmidt) [1740064]
- [scsi] sd_dif: avoid incorrect ref_tag errors on 4K devices larger than 2TB (Ewan Milne) [1833528]
- [hid] HID: hiddev: do clean4MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}up in failure of opening a device (Torez Smith) [1814257] {CVE-2019-19527}
- [hid] HID: hiddev: avoid opening a disconnected device (Torez Smith) [1814257] {CVE-2019-19527}
- [x86] x86: make mul_u64_u64_div_u64() "static inline" (Oleg Nesterov) [1845864]
- [mm] mm: page_isolation: fix potential warning from user (Rafael Aquini) [1845620]
- [s390] s390/mm: correct return value of pmd_pfn (Claudio Imbrenda) [1841106]
- [fs] fs/proc/vmcore.c:mmap_vmcore: skip non-ram pages reported by hypervisors (Lianbo Jiang) [1790799]
- [kernel] kernel/sysctl.c: ignore out-of-range taint bits introduced via kernel.tainted (Rafael Aquini) [1845356]
- [documentation] kernel: add panic_on_taint (Rafael Aquini) [1845356]
- [fs] ext4: Remove unwanted ext4_bread() from ext4_quota_write() (Lukas Czerner) [1845379]
- [scsi] scsi: sg: add sg_remove_request in sg_write ("Ewan D. Milne") [1840699] {CVE-2020-12770}
- [fs] fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (Donghai Qiao) [1832062] {CVE-2020-10732}4v) [1844409]
- [mailbox] PCC: fix dereference of ERR_PTR (Vladis Dronov) [1844409]
- [kernel] futex: Unlock hb->lock in futex_wait_requeue_pi() error path (Vladis Dronov) [1844409]
- [fs] aio: fix inconsistent ring state (Jeff Moyer) [1845326]
- [vfio] vfio/mdev: make create attribute static (Vladis Dronov) [1837549]
- [vfio] treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Synchronize device create/remove with parent removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid creating sysfs remove file on stale device removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Improve the create/remove sequence (Vladis Dronov) [1837549]
- [vfio] treewide: Add SPDX license identifier - Makefile/Kconfig (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid inline get and put parent helpers (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Fix aborting mdev child device removal if one fails (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Follow correct remove sequence (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid masking error code to EBUSY (Vladis Dronov) [1837549]
- [include] vfio/mdev: Drop redundant extern for exported symbols (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Removed unused kref (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid release parent reference during error path (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Add iommu related member in mdev_device (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: add static modifier to add_mdev_supported_type (Vladis Dronov) [1837549]
- [vfio] vfio: mdev: make a couple of functions and structure vfio_mdev_driver static (Vladis Dronov) [1837549]
- [char] tpm/tpm_tis: Free IRQ if probing fails (David Arcari) [1774698]
- [kernel] audit: fix a memleak caused by auditing load module (Richard Guy Briggs) [1843370]
- [kernel] audit: fix potential null dereference 'context->module.name' (Richard Guy Briggs) [1843370]
- [nvme] nvme: limit number of IO queues on Dell/Samsung config (David Milburn) [1837617]
AAsJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check 4
Js#Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDsJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}osmJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjscJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]s1Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []s7Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
k5k wKJitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%wUJitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibsww{Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)FsJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
)
)%wJitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[$gSPetr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)w#g	Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)v"wyJitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)s!gPetr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107) w+Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)egePetr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347)
@6L@s+gPetr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)*w+Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)e)gePetr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347) (wKJitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%'wUJitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibsw&w{Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)
I0I3 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.19.2-3P	H@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildG2_3 Petr Pisar <ppisar@redhat.com> - 2.19.2-2Ou@- Perl 5.16 rebuildO1u- Marcela Mašláňová <mmaslano@redhat.com> 2.19.2-1O`@- bump to 2.19.20 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.18.0-4O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild/wJitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[.gSPetr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)w-g	Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)v,wyJitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)
	jK*G<_3!Petr Pisar <ppisar@redhat.com> - 2.19.2-2Ou@- Perl 5.16 rebuildO;u-!Marcela Mašláňová <mmaslano@redhat.com> 2.19.2-1O`@- bump to 2.19.2:!Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.18.0-4O- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild9o Jitka Plesnikova <jplesnik@redhat.com> - 2.19.3-5a@- Always clear out libpq results before reassigning (rhbz #2020111)M8_? Daniel Mach <dmach@redhat.com> - 2.19.3-4RU- Mass rebuild 2014-01-24M7_? Daniel Mach <dmach@redhat.com> - 2.19.3-3Rk- Mass rebuild 2013-12-27y6_ Petr Pisar <ppisar@redhat.com> - 2.19.3-2P4- Specify all dependencies
- Move testme.tmp.pl to tests sub-packageA5_' Petr Pisar <ppisar@redhat.com> - 2.19.3-1P4- 2.19.3 bumpM4c; Daniel Mach <dmach@redhat.com> - 2.19.2-3.1P+@- Rebuild for perl 5.16
dQ*wDw{"Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)Co!Jitka Plesnikova <jplesnik@redhat.com> - 2.19.3-5a@- Always clear out libpq results before reassigning (rhbz #2020111)MB_?!Daniel Mach <dmach@redhat.com> - 2.19.3-4RU- Mass rebuild 2014-01-24MA_?!Daniel Mach <dmach@redhat.com> - 2.19.3-3Rk- Mass rebuild 2013-12-27y@_!Petr Pisar <ppisar@redhat.com> - 2.19.3-2P4- Specify all dependencies
- Move testme.tmp.pl to tests sub-packageA?_'!Petr Pisar <ppisar@redhat.com> - 2.19.3-1P4- 2.19.3 bumpM>c;!Daniel Mach <dmach@redhat.com> - 2.19.2-3.1P+@- Rebuild for perl 5.16=!Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.19.2-3P	H@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
AV2AvJwy"Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)sIg"Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)Hw+"Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)eGge"Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347) FwK"Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%EwU"Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibs
&t PwK#Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%OwU#Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibswNw{#Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)Mw"Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[LgS"Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)wKg	"Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)
)
)Ww#Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[VgS#Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)wUg	#Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)vTwy#Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)sSg#Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)Rw+#Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)eQge#Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347)
@6L@s]g$Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)\w+$Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)e[ge$Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347) ZwK$Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%YwU$Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibswXw{$Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)
??[bqG%Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081aw$Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[`gS$Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)w_g	$Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)v^wy$Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)
F9eiQ%Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.di)%Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5cq{%Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.
,iiu=%Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601huo%Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387gi)%Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Ofq/%Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059
A5lq{&Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.k{	%Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:jk%Vít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008
qR~qpi)&Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Ooq/&Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059niQ&Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.mi)&Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
Jhus&Masahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365t{	&Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:sk&Vít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008ru=&Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601quo&Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387

er+V:eD3
01fb0c20e028f3f34cb3fc42c0360980946fc9b2e0f4b1cfcbe93c2777912606D2
f83a9cc23d159877dba95b62d685edf3a6968d8d968732049c688fe7d49777d4D1
6f515d110cfd49f16feb45eb873662abd7d90f7d6a9521856506cb39bc3ec434D0
00f64801d8abc5d57fcf628994aeed0267baba42e5be15b3a5d445cd3a2f1226D/
f3cd69f130263e2bd4ccca5ef76054432d3c23432298df1d0aeed37eda7db3f4D.
0821b9fe0910e051ebf760e8df0198202117a973492dee2aca30504c0f8a5544D-
36101de00585de431de07579343b064018d049adcaa3bb90ae0c55e997d8e1a8D,
73ea554de089905aab93ded3a974f753899d2b8f0f3f3044d9f41d44a86324dbD+
6bc5d11d6925535123b8762c2ad80e64d81a9fc384b6def702e2585966637c24D*
d357914edfc5e38eb99a385b00d0fb43d1c581d9af1d12406c5dbae63542e08eD)
ddc9339c832234c2d2d9c946d96c23c6d1fe5ea3a34710694d2a8bd819d4b8f3D(
e90d3b7f1beb833473709255affdf6f47d5b2f24def150c5ba2db2d65edf7daeD'
d666c7aa2c9af7b68e1d9bb3646d95b078ea804f6833a701a44fd99fac4c9ae2
Y fYxi)'Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.5wq{'Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.[vqG'Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-15[(@- move instaweb to separate git-instaweb subpackage.
	Resolves: #1213059
- move gnome-keyring to a separate git-gnome-keyring subpackage.
	Resolves: #1284081
+_~+}u='Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601|uo'Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387{i)'Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Ozq/'Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059yiQ'Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.
A5q{(Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-16[:- Remove EL-5 settings and old Fedora conditionals.
  Taken from fedora commits 903d8f35ed8ae16bece8ae8033f3d3926cc97595 and
  2c6eff99d7b50b87e8a1fe2e4a0489dfd90659b8.
- Fix builds using '--without docs'
- Change git-instaweb default from lighttpd(not available in rhel7) to
  apache2.
- Add requires for git-{instaweb,gnome-keyring} to pull them, when
  installing git-all.{	'Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:~k'Vít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008
qR~qi)(Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-20[@- Fix CVE-2018-17456: arbitrary code execution via .gitmodules
  Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.1.x
  and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 1.9.1Oq/(Sebastian Kisela <skisela@redhat.com> - 1.8.3.1-19[- Fix httpd modules path to be independent from system architecture.
Upstream commit: 1976311aa285549599e5a451d7ad72b55a2b60e2
Resolves: #1213059iQ(Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-18[H@- Use the correct apache module directory in instaweb.
- Apply the docs fixes to instaweb as well.i)(Pavel Cahyna <pcahyna@redhat.com> - 1.8.3.1-17[D- Correctly return an error from fsck on encountering a .gitmodules symlink.
  This was broken in the debian 2.1.x backport and found by covscan.
  Fix the test to catch this.
- Correct a typo in changelog.
aJhaw
w{)Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)	s(Masahiro Matsuya <mmatsuya@redhat.com> - 1.8.3.1-25df@- Fixes CVE-2023-25652 and CVE-2023-29007
- Resolves: #2188354, #2188365{	(Ondřej Pohořelský <opohorel@redhat.com> - 1.8.3.1-24c@- Fixes CVE-2022-23521 and CVE-2022-41903
- Resolves: #2162067:k(Vít Ondruch <vondruch@redhat.com> - 1.8.3.1-23^˳@- Prevent crafted URL containing new lines, empty host or lacks a scheme
  to cause credential leak.
  Resolves: CVE-2020-11008u=(Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-22^@- Crafted URL containing new lines can cause credential leak  
- Resolves: CVE-2020-52601uo(Ondrej Pohorelsky <opohorel@redhat.com> - 1.8.3.1-21]- Fix CVE-2019-1387: remote code execution in recursive clones with nested
  submodules
  Resolves: CVE-2019-1387
AV2Avwy)Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)sg)Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)w+)Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)e
ge)Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347) wK)Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%wU)Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibs
&t wK*Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%wU*Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibsww{*Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)w)Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[gS)Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)wg	)Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)
)
)w*Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[gS*Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)wg	*Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)vwy*Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)sg*Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)w+*Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)ege*Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347)
@6L@s#g+Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)"w++Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)e!ge+Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347)  wK+Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%wU+Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibsww{+Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)
UU *wK,Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%)wU,Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibsw(w{,Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)'w+Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[&gS+Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)w%g	+Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)v$wy+Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)
)
)1w,Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[0gS,Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)w/g	,Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)v.wy,Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)s-g,Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107),w+,Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)e+ge,Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347)
@6L@s7g-Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)6w+-Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)e5ge-Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347) 4wK-Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%3wU-Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibsw2w{-Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)
y<c.Nathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262);w-Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[:gS-Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)w9g	-Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)v8wy-Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)
##`?c_.Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)>cU.Nathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS=cE.Nathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
GxDe
.Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4Cc.Nathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5Bc	.Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Ac%.Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s@c.Nathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
Y.YSGcE/Nathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yFc/Nathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MEe7.Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
|`{|Kc%/Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sJc/Nathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`Ic_/Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)HcU/Nathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issue
?F?MOe7/Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xNe
/Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4Mc/Nathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5Lc	/Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)
+RcU0Nathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueSQcE0Nathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)yPc0Nathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)
bb5Vc	0Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)Uc%0Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sTc0Nathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)`Sc_0Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)
|G|yZc1Nathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)MYe70Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)xXe
0Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4Wc0Nathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)
##`]c_1Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)\cU1Nathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS[cE1Nathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxbe
1Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4ac1Nathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5`c	1Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)_c%1Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)s^c1Nathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
z.	dzegge2Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347) fwK2Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%ewU2Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibswdw{2Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)Mce71Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
kzwnw{3Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)mw2Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[lgS2Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)wkg	2Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)vjwy2Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)sig2Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)hw+2Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)
AV2Avtwy3Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)ssg3Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)rw+3Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)eqge3Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347) pwK3Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%owU3Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibs
&t zwK4Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%ywU4Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibswxw{4Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)ww3Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[vgS3Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)wug	3Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)

er+V:eD@
821164fdb3e807716631102ab1778e4736d70fc13bfc34bebdebe03bcfc8510fD?
74668b90f41c424000d241ad2f9a624d6386a447a8d58add20fd173375e09b32D>
c041cb0f7c5becd34a9fa8c2693fe7723c0e561a13cee7ae61287bfc4ff2eb4dD=
4a2de0d15d4fadd42283d48bfb0d4abea9092c5e82e168374e117d6b6d7b27d4D<
0ba33a407f36442d9f5f526712fe0c940b67897540b9e10a14271928cffed297D;
3a16156819b55d3d9e234fe19ee8f016b2394f4d77627ba4be2bfe06f19a148fD:
5ce2a0af968d496cf93f82d5106b30e2f55b8df48349636d27dfb49c14f8905bD9
eb68b066fac31ef1d13db384711879546250d149147a9bfbe0a62bd5f62d0bcaD8
9d883529a429fd5676d5deb1bcbc66ddd6a9aebebfe215ea0436c33ff0387b2fD7
ed34b500e7e1951b8208f45e26b323c12c4fe5f89a8823445ddeeb1f28d5e93eD6
840f1eeb8f5f65eb3e144edba32348ee678812d22065a6e75c237879369172b3D5
816ca6511f010052482e88ab2a3bafd3be37b7f6544e98aa51c2e521eea8ab26D4
16c4eac47cfb42c7b2453290f21172024727ffd7444425d48a2170493b43db78
)
)w4Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[gS4Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)wg	4Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)v~wy4Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)s}g4Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)|w+4Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)e{ge4Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347)
@6L@sg5Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)w+5Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)ege5Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347) wK5Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%wU5Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibsww{5Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)
UU wK6Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%
wU6Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibsww{6Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)w5Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[
gS5Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)w	g	5Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)vwy5Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)
)
)w6Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[gS6Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)wg	6Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)vwy6Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)sg6Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)w+6Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)ege6Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347)
@6L@sg7Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)w+7Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)ege7Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347) wK7Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%wU7Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibsww{7Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)
,0,n#sm8Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
"s)8Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992!s/8Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056V s=8Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.2S- Resolves: rhbz#1125544w7Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[gS7Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)wg	7Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)vwy7Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)
y9y)u;8Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500(u8Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{'s8Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983o&so8Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$%sW8Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.B$s8Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056
kgo/so9Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$.sW9Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.B-s9Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056n,sm9Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
+s)9Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992*s/9Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056
\T%5wU:Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibsw4w{:Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)3u9Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.12a@- Limit recursion in ri-records (CVE-2021-3622)
  resolves: rhbz#19761932u;9Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#19505001u9Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{0s9Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983
p[qepw;g	:Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)v:wy:Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)s9g:Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)8w+:Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)e7ge:Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347) 6wK:Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)bR4RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{4b4e4i4l4p4u4x4}4 4!4"
4#4$4%4&#4'*4(14)74*<4+?4,D4-G4.K4/O40R41V42Z43]44b45g46n47t48z4:4;4<4=4>4?#4@)4A/4B54C;4EA4FH4GN4HT4I[4Jc4Ki4Lo4Mp4Nr4Ot4Pv4Qz4W|4X~4Y4^4`4a4b
4g4i4j4k4p4r4s4t4u4z4|4} 4~#4%4'4(4)4,4.404142444547494:4<4=4>4?4@4A4C4D
`J`eAge;Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347) @wK;Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%?wU;Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibsw>w{;Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)=w:Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[<gS:Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)
kzwHw{<Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)Gw;Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[FgS;Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)wEg	;Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)vDwy;Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)sCg;Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)Bw+;Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)
AV2AvNwy<Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)sMg<Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)Lw+<Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)eKge<Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347) JwK<Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%IwU<Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibs
&t TwK=Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-292X- Removed perl-Perl4-CoreLibs because it was added as separate package to
  RHEL (bug #1366724)%SwU=Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-291WQ- Backported and sub-packaged libraries historically supplied with Perl 4
  into perl-Perl4-CoreLibswRw{=Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-290W@- Removed deprecated files from provides (bug #1365991)Qw<Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[PgS<Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)wOg	<Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)
)
)[w=Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-299_- Fix CVE-2020-10543 (bug #1839272)
- Fix CVE-2020-10878 (bug #1839275)[ZgS=Petr Pisar <ppisar@redhat.com> - 4:5.16.3-298_ܙ- Fix CVE-2020-12723 (bug #1839278)wYg	=Petr Pisar <ppisar@redhat.com> - 4:5.16.3-297^S- Fix a file mode of a perl-example.stp example (bug #1806523)vXwy=Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-296^%@- Fix day of year parsing (like "%y%j") (bug #1751381)sWg=Petr Pisar <ppisar@redhat.com> - 4:5.16.3-295]8H@- Fix a spurious timeout in Net::FTP::close (bug #1626107)Vw+=Jitka Plesnikova <jplesnik@redhat.com> - 4:5.16.3-294\3?@- Fix CVE-2018-18311 Integer overflow leading to buffer overflow (bug #1653527)eUge=Petr Pisar <ppisar@redhat.com> - 4:5.16.3-293ZI@- Add SSL support to Net::SMTP (bug #1557574)
- Do not overload ".." in Math::BigInt (bug #1497734)
- Provide perl(:VERSION) and perl-interpreter RPM symbols (bug #1410347)
(Vbc_i>Peter Jones <pjones@redhat.com> - 0.109-9TA- Fix man page errors.
  Resolves: rhbz#948850kb_{>Peter Jones <pjones@redhat.com> - 0.109-9T@- Build as PIE+RELRO binaries.
  Resolves: rhbz#1092542oa_>Peter Jones <pjones@redhat.com> - 0.109-8SA- Include aarch64 in the rpm macro
  Related: rhbz#1100042[`_[>Peter Jones <pjones@redhat.com> - 0.109-7S@- Add aarch64.
  Resolves: rhbz#1100042__K>Peter Jones <pjones@redhat.com> - 0.109-6S*@- Make sure CFLAGS is inherited properly for -fstack-protector-strong.
  Resolves: rhbz#1070782L^]?>Daniel Mach <dmach@redhat.com> - 0.109-5Rk- Mass rebuild 2013-12-27v]_>Peter Jones <pjones@redhat.com> - 0.109-4Ro@- Tweak the signing rules just a bit more.
  Related: rhbz1017857q\_>Peter Jones <pjones@redhat.com> - 0.109-3Rj]@- Update to fix a bug coverity found.
  Related: rhbz1017857
+pT+}ic?Remi Collet <rcollet@redhat.com> 1:1.9.4-17Qy- improve post scriptlet to avoid updating pear.conf
  when not needed#hI?Ralf Corsépius <corsepiu@fedoraproject.org> - 1:1.9.4-16Q?- Remove %config from %{_sysconfdir}/rpm/macros.*
  (https://fedorahosted.org/fpc/ticket/259).~gk?Remi Collet <remi@fedoraproject.org> 1:1.9.4-15Q:@- update Archive_Tar to 1.3.11
- drop php 5.5 patch merged upstreamfk3?Remi Collet <remi@fedoraproject.org> 1:1.9.4-14P @- add explicit requires on all needed extensions (phpci)
- fix pecl launcher (need ini to be parsed for some
  extenstions going to be build as shared, mainly simplexml)
- add fix for new unpack format (php 5.5)ek>Robbie Harwood <rharwood@redhat.com> - 0.109-11c@- Backport newer, deprecated pesign-authorize
- Resolves: CVE-2022-3560de3>Peter Jones <pjones@redhat.com> - - 0.109-10W9@- Add support for /etc/pesign/users and /etc/pesign/groups
  Resolves: rhbz#1141263
~5~oc'?Remi Collet <rcollet@redhat.com> 1:1.9.4-23c,N@- update Archive_Tar to 1.4.14
  CVE-2020-36193 CVE-2020-28948 CVE-2020-28949|nc?Remi Collet <rcollet@redhat.com> 1:1.9.4-22^@- fix fatal error: gnu/stubs-64.h: No such file or directory #1720375Omc??Daniel Mach <dmach@redhat.com> - 1:1.9.4-21Rk- Mass rebuild 2013-12-27WlcO?Remi Collet <rcollet@redhat.com> 1:1.9.4-20QL- add man page for pear.conf fileikcs?Remi Collet <rcollet@redhat.com> 1:1.9.4-19QK- add man pages for pear, peardev and pecl commandsZjcU?Remi Collet <rcollet@redhat.com> 1:1.9.4-18Q- don't verify metadata file content
ype@Dogtag Team <pki-devel@redhat.com> 10.5.18-3^=@- Updated jss dependencies
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)
##reI@Dogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)=qe@Dogtag Team <pki-devel@redhat.com> 10.5.18-4^U@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE
  additional support and touch-up (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new
1"tea@Dogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)Jse1@Dogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??Cve#@Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tue@Dogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rzeIADogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)yg'@Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4Texge@Dogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4R}wg@Dogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)4Sug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and4Uug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

er+V:eDM
e1dd38dc66a44126b420260a1c8cbd7fc5a5e66fca9097fbacb6645b53215ec9DL
ea213c63260f95219614321b7530531b4a081af5c6ae3749a8ed600ba0507ddbDK
b97ca8437ca8ddd548433b4e5244b6b95c3c06fabebee6a67b64e0183ff83641DJ
401c21fed02d492f7c9f4ef47e8a82e8a7bfeb0a3e08789c00a7220db5e1fbd8DI
d3aeeaf9aaede46280cce061abf9bec44b4dbe1a3fa01fd5d3ec75cf1be3ff14DH
285022f2d97dce4f3ed1d27af515d776f7bf7d3331bcfaee0f0945955f738288DG
42bea60ba5a685f45ed8675f855c453f0cc42f054af12af28b5201bf1a660ffcDF
b09cfd3f84ca7ac6c285e49ce46e9ee51537af067b1965560dd41d5f82f50deeDE
0da377da9a9dc6f3210ae58f9365d1e379b41bfbc986639c5cb7df02de772356DD
45d71f9f39e70560b9d5baa82caf326bdbcb0b135c3f872940bebef466ce91c6DC
76cfa65febb7025f91800c11072204ec3748d9a68501cdf0cfde5a6c5404f0e4DB
36700e5bb7c0b78ab0e613260beefe4a8ca7dcad56b18461ccd56a4d671e6938DA
61ec99762a4cb0f13335876298ef0c38a6f690949282991213f5505233899d63
1"|eaADogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)J{e1ADogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??C~e#ADogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)t}eADogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrg'ADogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4\egeADogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4Z}gADogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)4[ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and4]ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g!ADogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################4_Jg/ADogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
1"eaBDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)Je1BDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??Ce#BDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)teBDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rr
g'BDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4ee	geBDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4c}gBDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)4dug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and4fug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g!BDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################4hJg/BDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
`"eaCDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)
qGBDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
??Ce#CDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)teCDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrg'CDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4negeCDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4l}gCDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)4mug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and4oug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g!CDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################4qJg/CDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``qGCDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
qOCDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
??Ce#DDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)teDDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrg'DDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4xegeDDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4v}gDDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)4wug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and4yug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g!DDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################4{Jg/DDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``qGDDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
 qODDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
X}#gEDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)C"e#EDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)#!qWDDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

%g'EDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4e$geEDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B44ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1'g!EDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################4J&g/EDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``(qGEDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
)qOEDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
gXg},gFDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)h+qaEDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################4#*qWEDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

.g'FDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4e-geFDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B44ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
10g!FDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################4J/g/FDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``1qGFDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
2qOFDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xh4qaFDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################4#3qWFDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%5q[FDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
J7g/GDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)6g'GDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
9qGGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)8g!GDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################4
:qOGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xh<qaGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################4#;qWGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%=q[GDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__>qIGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
""Y?qCGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
``@qGHDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
AqOHDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhCqaHDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################4#BqWHDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%Dq[HDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__EqIHDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"GqHDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################4YFqCHDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
reIq[HDogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)HqHDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################4
JqOIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhLqaIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################4#KqWIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%Mq[IDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__NqIIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"PqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################4YOqCIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
reRq[IDogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)QqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################4
_hTqaJDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################4SqIIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%Uq[JDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__VqIJDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"XqJDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################4YWqCJDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
reZq[JDogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)YqJDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################4
__[qIJDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
H\q!JDogtag Team <devel@lists.dogtagpki.org> 10.5.18-26d- ##########################################################################
- # RHEL 7.9 (Batch Update 22):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 22):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
H]q!JDogtag Team <devel@lists.dogtagpki.org> 10.5.18-27dO- ##########################################################################
- # RHEL 7.9 (Batch Update 23):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 23):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
y^eKDogtag Team <pki-devel@redhat.com> 10.5.18-3^=@- Updated jss dependencies
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)
##`eIKDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)=_eKDogtag Team <pki-devel@redhat.com> 10.5.18-4^U@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE
  additional support and touch-up (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new
1"beaKDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)Jae1KDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??Cde#KDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tceKDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rheILDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)gg'KDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4ƑefgeKDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4}egKDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1"jeaLDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)Jie1LDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??Cle#LDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tkeLDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrog'LDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4͑engeLDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4}mgLDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1qg!LDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################4ЅJpg/LDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
1"seaMDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)Jre1MDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??Cue#MDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tteMDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrxg'MDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4֑ewgeMDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4}vgMDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1zg!MDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################4مJyg/MDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
`"|eaNDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne){qGMDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)

er+V:eDZ
b38d022364150a6b271f7303931e221b21fa89648ecf7b19689e3aff7f73b9dbDY
f3aaf1422d162735cb3147c5876e2d569c5ab751c3e355d4f973d16250916a4cDX
c4776c0f7679c318248d6de58590eabf05cbf410c78eb952a8d259663745c806DW
e651cd64c12f15c06125f138481787d6ec5290b1c58e9c8b7898b52c10c8441aDV
c799c7a9b990e36dedf9785fd1b300a75ffe77c3f8e0e9074d4279a3d1d85cd7DU
757db012689225d59ae444ae9fe49b96ad20d6b478e9a2858bc9c4a3c2ce5b7cDT
9094f634e973446d22eec7485aece9a4f3294db660812abe442e6d174a51ee34DS
008b4a8cee71d4770d3f1c7d68b7c37fc61c86104417e049e1fd9eca1270711bDR
684af720a124815101b07a8a52109e6312fa2da52e6a2f276a425b50b688b7a4DQ
74b69c0cad0206438485f298e20a6d074c6e227e6785bba46afaca709e38ef8bDP
102ed9eedebeacd4ea5f6fc19a2a0cffb500ccb7516b4f616a67ee86654acde1DO
b57dcb1aa6d049c9f0206c226dae51fc7047a9bd3a94dd60673d7d58d3e0a2d2DN
769518511a9626c3f684d9b19a35320e0bf5eaad8dc6377c966be0005c590641
??C~e#NDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)t}eNDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrg'NDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4egeNDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4}gNDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g!NDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################4Jg/NDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``qGNDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
qONDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
??Ce#ODogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)teODogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rr
g'ODogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4e	geODogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4}gODogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g!ODogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################4Jg/ODogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``
qGODogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
qOODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
X}gPDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)Ce#PDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)#qWODogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

g'PDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B4egePDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B44ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g!PDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################4Jg/PDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)bR5WRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{4G4I4J4L4M4N4P4R4T4U4V4X4Z4[4\4]4^4`4b4‚d4Âh4Ȃj4ɂl4ʂo4ςq4тs4҂u4ӂx4؂z4ڂ|4܂~4݂44444
44
44444444555 5"5#5%5
'5(5*5+5,5-5.5/5152535557585:5!;5"<5#>5&@5'B5)C5*D5+F5.H5/I50J51K52L53N54P55R56V5;X5<Z5=]5B_5Da5Ec5Ff5Kh5Mj5Nl5Oo5Tq5Vr##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``qGPDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
qOPDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
gXg}gQDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)hqaPDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################4#qWPDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)4ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

g'QDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5egeQDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B45ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g!QDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5Jg/QDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``qGQDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
 qOQDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xh"qaQDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5#!qWQDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%#q[QDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)5
ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
J%g/RDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)$g'RDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5	##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
'qGRDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)&g!RDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5
(qORDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xh*qaRDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5#)qWRDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%+q[RDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__,qIRDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
""Y-qCRDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
``.qGSDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
/qOSDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xh1qaSDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5#0qWSDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%2q[SDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__3qISDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"5qSDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################5Y4qCSDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
re7q[SDogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)6qSDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################5
8qOTDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xh:qaTDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5 #9qWTDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%;q[TDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__<qITDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
">qTDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################5$Y=qCTDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
re@q[TDogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)?qTDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################5%
_hBqaUDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5(AqITDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%Cq[UDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__DqIUDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"FqUDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################5,YEqCUDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
reHq[UDogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)GqUDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################5-
__IqIUDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
HJq!UDogtag Team <devel@lists.dogtagpki.org> 10.5.18-26d- ##########################################################################
- # RHEL 7.9 (Batch Update 22):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 22):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
HKq!UDogtag Team <devel@lists.dogtagpki.org> 10.5.18-27dO- ##########################################################################
- # RHEL 7.9 (Batch Update 23):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 23):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
yLeVDogtag Team <pki-devel@redhat.com> 10.5.18-3^=@- Updated jss dependencies
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)
##NeIVDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)=MeVDogtag Team <pki-devel@redhat.com> 10.5.18-4^U@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE
  additional support and touch-up (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new
1"PeaVDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)JOe1VDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??CRe#VDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tQeVDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rVeIWDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)Ug'VDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B59eTgeVDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B57}SgVDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)58ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and5:ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1"XeaWDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)JWe1WDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??CZe#WDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tYeWDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rr]g'WDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5@e\geWDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5>}[gWDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)5?ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and5Aug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1_g!WDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5CJ^g/WDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
1"aeaXDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)J`e1XDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??Cce#XDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tbeXDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrfg'XDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5IeegeXDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5G}dgXDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)5Hug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and5Jug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1hg!XDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5LJgg/XDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
`"jeaYDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)iqGXDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
??Cle#YDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tkeYDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrog'YDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5RengeYDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5P}mgYDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)5Qug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and5Sug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1qg!YDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5UJpg/YDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``rqGYDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
sqOYDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
??Cue#ZDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tteZDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrxg'ZDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5\ewgeZDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5Z}vgZDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)5[ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and5]ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1zg!ZDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5_Jyg/ZDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``{qGZDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
|qOZDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
X}g[Dogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)C~e#[Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)#}qWZDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)

er+V:eDg
78bf4a4e4e5885b5d88e541e46d3237eddae49bc51b74c8c40c52741b0ce4534Df
be04d6f2b74a87abab03f3e5db7bd69c9c3aba89bf5aeaf5464dfb3e90027fe0De
240e9a52eaeceaf3760066a892aab0f7a74bac5492ba14ced65ddc253119eed6Dd
a3ad033749fd54a7fd723f8b31abd4dea531eae66ff59e0f48a1e7412fd09051Dc
0a5a7250aabe9649c502bfc98a71ff102a3a30a37575ea8c1c0ae22c267a6640Db
928ac4b150a768535d5d82dad1f8f4549ff8ef568798b62c65debe00f659767dDa
86754c49d208af8b291d53143af752244a68d88e0b4ccbd4efb6811386339d4cD`
83b8bc9adb407e5d032b0b7036ab81ae352bb583870b195e840ac2f094c2cde6D_
3a9368e803399e85ff27406fbdc5d6ffad6e000d636a8540ac83b236273b5d2aD^
5473bf46793bafa1cf84c7ae24ecb341d287d12494cbea04a1fd46c81fd5c2c8D]
83d61057ed2eda189f751ce319a8369da48465187416f37a4dbc5db0b9df35a8D\
f3d62a8cb0a97c76e6a8d6432f16d9b3f9040d5289f63d709f50a3776efaa8b4D[
48f161dd4b8ad99c1d1c53c15b3b1e64dea4116e9347fd9464c14ac1742ff5cd5eug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

g'[Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5gege[Dogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5d5hug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g![Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5jJg/[Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``qG[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
qO[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
gXg}g\Dogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)hqa[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5n#qW[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)5pug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and


g'\Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5re	ge\Dogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5o5sug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g!\Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5uJg/\Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``
qG\Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
qO\Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xhqa\Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5y#qW\Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%q[\Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)5|ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
Jg/]Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)g']Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5{##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
qG]Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)g!]Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5~
qO]Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xhqa]Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5#qW]Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%q[]Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__qI]Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
""YqC]Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
``qG^Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
qO^Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xhqa^Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5#qW^Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
% q[^Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__!qI^Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"#q^Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################5Y"qC^Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
re%q[^Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)$q^Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################5
&qO_Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xh(qa_Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5#'qW_Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%)q[_Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__*qI_Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
",q_Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################5Y+qC_Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
re.q[_Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)-q_Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################5
_h0qa`Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5/qI_Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%1q[`Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__2qI`Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"4q`Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################5Y3qC`Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
re6q[`Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)5q`Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################5
__7qI`Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)bR6RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{5Xu5Yx5^z5`{5a|5b5f5i5k5l5m5q
5t5v
5w5x5z5}5555555555 5!5#5%5&5(5)5*5,5.50515254565758595:5<5>5@5D5F5H5K5M5O5Q5T5V5X5Z5‚]5ǂ_5ɂ`5ʂa5˂c5̂f5тh5ӂi5Ԃj5Ղm5؂o5ۂq5݂r5ނs5߂v5x5z5{5|5~55555555	5
55
5556666
H8q!`Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-26d- ##########################################################################
- # RHEL 7.9 (Batch Update 22):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 22):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
H9q!`Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-27dO- ##########################################################################
- # RHEL 7.9 (Batch Update 23):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 23):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
y:eaDogtag Team <pki-devel@redhat.com> 10.5.18-3^=@- Updated jss dependencies
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)
##<eIaDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)=;eaDogtag Team <pki-devel@redhat.com> 10.5.18-4^U@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE
  additional support and touch-up (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new
1">eaaDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)J=e1aDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??C@e#aDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)t?eaDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rDeIbDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)Cg'aDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5eBgeaDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5}AgaDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)5ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and5ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1"FeabDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)JEe1bDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??CHe#bDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tGebDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrKg'bDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5eJgebDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5}IgbDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)5ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and5ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1Mg!bDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5JLg/bDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
1"OeacDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)JNe1cDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??CQe#cDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tPecDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrTg'cDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5eSgecDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5}RgcDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)5ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and5ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1Vg!cDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5JUg/cDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
`"XeadDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)WqGcDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
??CZe#dDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tYedDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rr]g'dDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5őe\gedDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5}[gdDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)5ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and5ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1_g!dDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5ȅJ^g/dDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
```qGdDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
aqOdDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
??Cce#eDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tbeeDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrfg'eDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5ϑeegeeDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5}dgeDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)5ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and5ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1hg!eDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5҅Jgg/eDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``iqGeDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
jqOeDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
X}mgfDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)Cle#fDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)#kqWeDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)5ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

og'fDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5ّengefDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B55ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1qg!fDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5܅Jpg/fDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``rqGfDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
sqOfDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
gXg}vggDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)huqafDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5#tqWfDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)5ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

xg'gDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5ewgegDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B55ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1zg!gDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5Jyg/gDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``{qGgDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
|qOgDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xh~qagDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5#}qWgDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%q[gDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)

er+V:eDt
d0f42f7832c466e0318f15b6905f47d9e8977a198c140303463e8baf861f9983Ds
2a98b158e15d67666730cc76ed42eba2c909cbdb8c3d93ede1374768389a48b3Dr
5fb4e74677604f4bdb11376b47ccc1642147df00b0cd8d54f349ffc0749a8bf7Dq
c73585577567169544907d481ba9e354f44184d1e11e8bddbfc58e96334f4a21Dp
c82b48182722e9c7204fcb4910d9aa25f350db17be47eea64e52281990462ea1Do
231c99ff7648c2fa512b52e36ee21cfb15033bb178cb5c38c37a3928feedec99Dn
1e40420731f3976bda8671ed42244cc12837a19a812572d663d3731cfde54fc3Dm
fa1ad496790644bccab3140b7f585dd72d55f3d0b242ec69cf7c2939b91b468bDl
f5ed6de364527262c7c94c0a93639ae14e4a1137b79f84385dfd331a2a78b7f4Dk
6fa692d6d3de0571869dd57603761a3835f55a4a06091767d81757431cfffe68Dj
d95a1b973a2d9ba1396f6af5f28e140022664ee433c6719ad7033c59b8007afcDi
bb4b4f96791149e67da2521bb1cfaefb082667ce11c33f3fb4daf083fc100c8dDh
014d6cdbaef0539c9b70adc727d4252d7aa3200cd7ca7a1afabf2ed85ad8feef5ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
Jg/hDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)g'hDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B5##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
qGhDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)g!hDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################5
qOhDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhqahDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5#qWhDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%q[hDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__qIhDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
""Y	qChDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
``
qGiDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
qOiDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xh
qaiDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################5#qWiDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%q[iDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__qIiDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"qiDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################6YqCiDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
req[iDogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)qiDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################6
qOjDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhqajDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6#qWjDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%q[jDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__qIjDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"qjDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################6	YqCjDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
req[jDogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)qjDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################6

_hqakDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6
qIjDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%q[kDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__ qIkDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
""qkDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################6Y!qCkDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
re$q[kDogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)#qkDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################6
__%qIkDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
H&q!kDogtag Team <devel@lists.dogtagpki.org> 10.5.18-26d- ##########################################################################
- # RHEL 7.9 (Batch Update 22):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 22):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
H'q!kDogtag Team <devel@lists.dogtagpki.org> 10.5.18-27dO- ##########################################################################
- # RHEL 7.9 (Batch Update 23):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 23):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
y(elDogtag Team <pki-devel@redhat.com> 10.5.18-3^=@- Updated jss dependencies
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)
##*eIlDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)=)elDogtag Team <pki-devel@redhat.com> 10.5.18-4^U@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE
  additional support and touch-up (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new
1",ealDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)J+e1lDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??C.e#lDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)t-elDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
r2eImDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)1g'lDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6e0gelDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6}/glDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1"4eamDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)J3e1mDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??C6e#mDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)t5emDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rr9g'mDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6%e8gemDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6#}7gmDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)6$ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and6&ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1;g!mDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################6(J:g/mDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
1"=eanDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)J<e1nDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??C?e#nDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)t>enDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrBg'nDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6.eAgenDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6,}@gnDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)6-ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and6/ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1Dg!nDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################61JCg/nDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
`"FeaoDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)EqGnDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
??CHe#oDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tGeoDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrKg'oDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B67eJgeoDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B65}IgoDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)66ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and68ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1Mg!oDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################6:JLg/oDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``NqGoDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
OqOoDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
??CQe#pDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tPepDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrTg'pDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6AeSgepDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6?}RgpDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)6@ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and6Bug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1Vg!pDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################6DJUg/pDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``WqGpDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
XqOpDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
X}[gqDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)CZe#qDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)#YqWpDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)6Iug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

]g'qDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6Ke\geqDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6H6Lug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1_g!qDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################6NJ^g/qDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
```qGqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
aqOqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
gXg}dgrDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)hcqaqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6R#bqWqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)6Tug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

fg'rDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6VeegerDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6S6Wug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1hg!rDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################6YJgg/rDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``iqGrDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)bR6RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{66666 6"6$6%6&6'6(6*6,6.626 46!66"96';6)=6*?6+B60D62F63H64K69M6;N6<O6=Q6>T6CV6EW6FX6G[6J]6M_6O`6Pa6Qd6Uf6Xh6Zi6\j6]l6_m6bo6dq6er6ft6hu6iv6jw6kx6ly6m{6o|6p}6q6t6v6w6y6z6{6~
66
66666666666 6"6$6'6)6+6-60626466696;6<6=6?6B6D6E6F
jqOrDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhlqarDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6^#kqWrDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%mq[rDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)6aug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
Jog/sDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)ng'sDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6`##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
qqGsDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)pg!sDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################6c
rqOsDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhtqasDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6g#sqWsDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%uq[sDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__vqIsDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
""YwqCsDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
``xqGtDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
yqOtDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xh{qatDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6n#zqWtDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%|q[tDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__}qItDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"qtDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################6rY~qCtDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
req[tDogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)qtDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################6s

er+V:eD
92e24421bd43dc1bc206b56f3d63452a3bffc509e64e9b541086b542c48c40deD
3cc29a69aafb39574532fe2809182aad0e720f88cccd15dc57272ac96c7b2417D
cce50d5874faecf4616bbc5ef77e0672efaef940a90870c5d652dbb07846408cD~
f47163cfd1c460c07d781e489622d1befb7dde8116948f80289c8bc685eef102D}
3442dd9e3cb39ce1bccd183f239742f4ae9a9499d4772d140b7b2a2c451d5507D|
d8752f8190b36bb9dd01e3568f7822c9a11fbce472408c4206c1a371ea109c53D{
3b6744ba25565e7f93733bc406e01364aff0968d6eb153c58e942635400ed11cDz
49e9c90df2985998052c0402a2bc848b5090e19a31cd9259e1fd77529e6a3505Dy
faacc67629472caf8377dc9a0bf33c24bb238dbcb391edf62435e70baf591d97Dx
f807177c77f5b66e10ff872d87a5651796c519c8d3b788ad034ec80c6c71e89fDw
c2282a789d3df8501b91543727d2c0b76e144991275bca82e8c75c83afbe05d7Dv
125ae22f4c9e8e637d89b849935d280420235c63f848bc2c66d739962c4cbf45Du
93ffdd88323d633406fd4f495ae9b81a2e9022740ce9b398b77bb2fad9f8c6ee
qOuDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhqauDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6x#qWuDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%q[uDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__qIuDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"quDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################6|YqCuDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
re
q[uDogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)	quDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################6}
_hqavDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6qIuDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%
q[vDogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__qIvDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"qvDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################6YqCvDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
req[vDogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)qvDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################6
__qIvDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
Hq!vDogtag Team <devel@lists.dogtagpki.org> 10.5.18-26d- ##########################################################################
- # RHEL 7.9 (Batch Update 22):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 22):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
Hq!vDogtag Team <devel@lists.dogtagpki.org> 10.5.18-27dO- ##########################################################################
- # RHEL 7.9 (Batch Update 23):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 23):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
yewDogtag Team <pki-devel@redhat.com> 10.5.18-3^=@- Updated jss dependencies
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)
##eIwDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)=ewDogtag Team <pki-devel@redhat.com> 10.5.18-4^U@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE
  additional support and touch-up (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new
1"eawDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)Je1wDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??Ce#wDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tewDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
r eIxDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)g'wDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6egewDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6}gwDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1""eaxDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)J!e1xDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??C$e#xDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)t#exDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rr'g'xDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6e&gexDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6}%gxDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1)g!xDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################6J(g/xDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
1"+eayDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)J*e1yDogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??C-e#yDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)t,eyDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rr0g'yDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6e/geyDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6}.gyDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
12g!yDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################6J1g/yDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
`"4eazDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)3qGyDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
??C6e#zDogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)t5ezDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rr9g'zDogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6e8gezDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6}7gzDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1;g!zDogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################6J:g/zDogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``<qGzDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
=qOzDogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
??C?e#{Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)t>e{Dogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrBg'{Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6eAge{Dogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6}@g{Dogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1Dg!{Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################6JCg/{Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``EqG{Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
FqO{Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
X}Ig|Dogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)CHe#|Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)#GqW{Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

Kg'|Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6eJge|Dogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B66ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1Mg!|Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################6JLg/|Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``NqG|Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
OqO|Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
gXg}Rg}Dogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)hQqa|Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6Ņ#PqW|Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

Tg'}Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6ɑeSge}Dogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B66ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1Vg!}Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################6̅JUg/}Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``WqG}Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
XqO}Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhZqa}Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6Ѕ#YqW}Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%[q[}Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)6ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
J]g/~Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)\g'~Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B6##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
_qG~Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)^g!~Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################6
`qO~Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xhbqa~Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6م#aqW~Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%cq[~Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__dqI~Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
""YeqC~Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
``fqGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
gqODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhiqaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6#hqWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%jq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__kqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"mqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################6YlqCDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
reoq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)nqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################6
pqODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhrqaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6#qqWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%sq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__tqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"vqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################6YuqCDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
rexq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)wqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################6
_hzqaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################6yqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%{q[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__|qIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"~qDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################6Y}qCDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
req[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)qDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################6
__qIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
Hq!Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-26d- ##########################################################################
- # RHEL 7.9 (Batch Update 22):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 22):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
Hq!Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-27dO- ##########################################################################
- # RHEL 7.9 (Batch Update 23):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 23):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)

er+V:eD
f6b64e5a20d4a11fbbe440a1ef9cc7566bba9bb10dcf6852b1d53148fdcf01b6D

3518ffcaeb18d70ca1e7a98dfb39cdb789944a2791b29a154aa0a970188b0b33D
68c5c1e442cb8c8c7a3e075f4f200477ce6b2f53023da840209a0d79dbb16cacD
eecc80d13fe486baa625924789eb5a656a1d00ebf4d3802de276c8d8c56dcb47D

ca59a355697c31c9ad51c2e64ca52833b18efc933c257e7d0dfe4f7509ec425bD	
d64ab36b01ec9723eaab8170d2287e1ce9a08cb7098b0c0912d596f03dfbcbbdD
ab37b1d65a0c8a304dddc11c7c15156bfbf447331a7afdff3f2f1c4a7632a7ffD
42cf93b353c32a2f1ee4496369b7f3181e00c033475ee1a6ada5dd1706c96a78D
9b49885bec503dbc2bbb82461da78b854568129c5ea70410fc3d5ba68dd1e97dD
76b9c89c43e25719214415b156394b6c8108b41639e8116895753032c1480241D
072e6332387b7078fb53410078598cb6a9480bef04a1e72bcfd996503ff19d12D
50d0381894cd1165df39084b17a13d53f360ad62fcfdcffb2c1b16a1684643acD
d5f36384f01382169e35a68adc8feedd5a3f1bb1e38a45244efcf65320e8c633
yeDogtag Team <pki-devel@redhat.com> 10.5.18-3^=@- Updated jss dependencies
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)
##eIDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)=eDogtag Team <pki-devel@redhat.com> 10.5.18-4^U@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE
  additional support and touch-up (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new
1"eaDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)Je1Dogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??C
e#Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)t	eDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the userbR7iRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{6K6M6‚N6ÂO6ĂR6ȂT6˂V6͂W6΂X6ςZ6т[6Ԃ]6ւ_6ׂ`6؂b6ڂc6ۂd6܂e6݂f6ނg6߂i6j6k6m6o6p6r6s6t6v6x6z6{6|6~66666666
777	7
77777 7"7$7'7!)7#*7$+7%-7&07+27-37.47/772975;77<78=79@7=B7@D7BE7CF7DH7FI7IK7KM7LN7MP7OQ7PR7QS7RT7SU7TW7VX7WY7X[7[]7\^7]`7_a7`b7ad7df7eh7gi7hj;D	!'.5<CJQX_fmt{Y#4!b7\JP!Ŵ	;FX%.
I	L	y-	<
h"
RR/9>BM
cR
9habwɁ
6BzmしhO%q8knׁDDj7ee`܁@i!J'+Ɂce=Jx '.5<CJQX_fmt{qjc\UNG@92+$|ung`YRKD=J&!IIT?HxH~HuGwG:F F!:EqET9DwD9D$CACYB>BB(=AÃA\,@@P@%A?6?U>탍>l=G='=*"<6<S~;؂;R>:l:$9c9vN918681
7,7lCbo#{S7 -f !HH!́"V9"^#([#8$
f$p$ف1%BE%Y&m&}V&䂁'LN'(G(|(ႈB)G)2*f*w"*݂`+Cl+,?,vi,݂G-JB-.2///0Xp01'*1y1q2]e2ĂN38n3]4DE4s6[I5
reIDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)
g'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7egeDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7}gDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1"eaDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)Je1Dogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??Ce#Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)teDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrg'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7
egeDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7}gDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################7Jg/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
1"eaDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)Je1Dogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??Ce#Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)teDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrg'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7egeDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7}gDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1 g!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################7Jg/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
`""eaDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)!qGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
??C$e#Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)t#eDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rr'g'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7e&geDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7}%gDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and7 ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1)g!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################7"J(g/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``*qGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
+qODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
??C-e#Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)t,eDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rr0g'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7)e/geDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7'}.gDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)7(ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and7*ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
12g!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################7,J1g/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``3qGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
4qODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
X}7gDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)C6e#Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)#5qWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)71ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

9g'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B73e8geDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7074ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1;g!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################76J:g/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``<qGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
=qODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
gXg}@gDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)h?qaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################7:#>qWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)7<ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

Bg'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7>eAgeDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7;7?ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1Dg!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################7AJCg/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``EqGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
FqODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhHqaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################7E#GqWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%Iq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)7Hug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
JKg/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)Jg'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7G##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
MqGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)Lg!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################7J
NqODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhPqaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################7N#OqWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%Qq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__RqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
""YSqCDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
``TqGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
UqODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhWqaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################7U#VqWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%Xq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__YqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"[qDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################7YYZqCDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
re]q[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)\qDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################7Z
^qODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xh`qaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################7^#_qWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%aq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__bqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"dqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################7bYcqCDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
refq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)eqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################7c
_hhqaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################7fgqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%iq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__jqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"lqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################7jYkqCDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
renq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)mqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################7k
__oqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
Hpq!Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-26d- ##########################################################################
- # RHEL 7.9 (Batch Update 22):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 22):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
Hqq!Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-27dO- ##########################################################################
- # RHEL 7.9 (Batch Update 23):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 23):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
yreDogtag Team <pki-devel@redhat.com> 10.5.18-3^=@- Updated jss dependencies
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- Bugzilla Bug #1809273 - CRL generation performs an unindexed search (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1549307 - No default TPS Auditor group (ascheel)
##teIDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne)=seDogtag Team <pki-devel@redhat.com> 10.5.18-4^U@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE
  additional support and touch-up (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710975 - TPS - Searching the certificate DB for a brand new
1"veaDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)Jue1Dogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??Cxe#Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)tweDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
r|eIDogtag Team <pki-devel@redhat.com> 10.5.18-5^@- Updated jss dependencies
- Bugzilla Bug #1710109 - add RSA PSS support - fix SHA512 (jmagne){g'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7wezgeDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7u}ygDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)7vug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and7xug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1"~eaDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)J}e1Dogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??Ce#Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)teDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrg'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7~egeDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7|}gDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)7}ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################7Jg/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)

er+V:eD
6b85f79e92ef0c82246378fae50f149f91d8ee31ac8f97a53f0333aef59c5632D
f74a68159214f1426d96de0733bdacb896eb4589d3e21a7f2e703f6256d709bcD
b55dbe4208bb3c90683449a91d2a51f9e672cea8adfe70dae659fe5f39549d2fD
2152a348fc6d94205b82143e948cc225b5abf2e72debfedc99a192d0540f8dd9D
f6a7307b2019d7d0e915192006d8ef7f56bbd11efafed60f9a5cb5f67f74db72D
e6e6ba69197bfc243b1960a9622d4e657bb927c0f6bd1e8cc8ee4f1cbc2162e3D
83c818ad04bf6b2bffa2f694713b5cf4daf9cb03a8d10c5c5bf31c984bf9fd5bD
2bb0b6d6fcc0774c8edfa188a222399464a6b216f7edf3776d72aba9dd432b37D
7fad090d109f3a2e81094996192b76c6a9c2f3dc5bdf9730d806f26705d9ec47D
b10e3c319490493ec81ce895694bf20ebddb48ec604b6a5d8d41cae60cbe4adaD
f09a628b0ae728f1bafc53c158926f284c0273e95363412bc951888d30e73e36D
c328c37ab19654e8c75410894318772e2ded988336a832db854b41d7fdb4f144D
218cc9a564ccf2b06cc13a609ffdc007f0f4e45e935a32631db3d78e1c63ccb6
1"eaDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)Je1Dogtag Team <pki-devel@redhat.com> 10.5.18-6^@- Patch for CMC Credential Error, RSA PSS typo, and new profile
  for directory-authentication-based Server-Side keygen
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1710109 - add RSA PSS support (jmagne)
- Bugzilla Bug #1794213 - Server-Side keygen Enrollment for EE (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
??C	e#Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)teDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrg'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7egeDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7}
gDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################7J
g/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
`"eaDogtag Team <pki-devel@redhat.com> 10.5.18-7^V@- Patch for CMCResponse tool
- Bugzilla Bug #1710109 - add RSA PSS support - fix CMCResponse tool (jmagne)qGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
??Ce#Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)teDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrg'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7egeDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7}gDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1g!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################7Jg/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``qGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
qODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
??Ce#Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)teDogtag Team <pki-devel@redhat.com> 10.5.18-8_@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug #1883639 - add profile caAuditSigningCert (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1710978 - TPS - Add logging to tdbAddCertificatesForCUID if
  - # Bugzilla Bug #1858860 - TPS - Update Error Codes returned to client
  - # Bugzilla Bug #1858861 - TPS - Server side key generation is not working
  - # Bugzilla Bug #1858867 - TPS does not check token cuid on the user
rrg'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7egeDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7}gDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1 g!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################7Jg/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``!qGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"qODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
X}%gDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)C$e#Dogtag Team <pki-devel@redhat.com> 10.5.18-9_@- Bugzilla Bug #1883639 - additional support on upgrade for audit
  cert profile and auditProfileUpgrade + auditProfileUpgrade part 2 (cfu)##qWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

'g'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7e&geDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B77ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
1)g!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################7J(g/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``*qGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
+qODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
gXg}.gDogtag Team <pki-devel@redhat.com> 10.5.18-10_$- Bugzilla Bug #1883639 - additional fix to upgrade script (edewata)h-qaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################7#,qWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and

0g'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7e/geDogtag Team <pki-devel@redhat.com> 10.5.18-11`%@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B77ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
12g!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################7J1g/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
``3qGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
4qODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
Xh6qaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################7#5qWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%7q[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)7ug 1883639 - Add KRA Transport and Storage Certificates
  profiles, audit for IPA (edewata)
- ##########################################################################
- # Backported CVEs (ascheel):
- ##########################################################################
- Bugzilla Bug 1724697 - CVE-2019-10180 pki-core: unsanitized token
  parameters in TPS resulting in stored XSS [certificate_system_9-default]
  (edewata, ascheel)
- Bugzilla Bug 1725128 - CVE-2019-10178 pki-core: stored Cross-site
  scripting (XSS) in the pki-tps web Activity tab
  [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1791100 - CVE-2020-1696 pki-core: Stored XSS in TPS profile
  creation [certificate_system_9-default] (edewata, ascheel)
- Bugzilla Bug 1724688 - CVE-2019-10146 pki-core: Reflected Cross-Site
  Scripting in 'path length' constraint field in CA's Agent page
  [rhel-7.9.z] (dmoluguw, ascheel)
- Bugzilla Bug 1789843 - CVE-2019-10221 pki-core: reflected cross site
  scripting in getcookies?url= endpoint in CA [rhel-7.9.z]
  (dmoluguw, ascheel)
- Bugzilla Bug 1724713 - CVE-2019-10179 pki-core: pki-core/pki-kra:
  Reflected XSS in recoveryID search field at KRA's DRM agent page in
  authorize recovery tab [rhel-7.9.z] (ascheel)
- Bugzilla Bug 1798011 - CVE-2020-1721 pki-core: KRA vulnerable to
  reflected XSS via the getPk12 page [rhel-7.9.z] (ascheel,jmagne)
- ##########################################################################
- Update to jquery v3.4.1 (ascheel)
- Update to jquery-i18n-properties v1.2.7 (ascheel)
- Update to backbone v1.4.0 (ascheel)
- Upgrade to underscore v1.9.2 (ascheel)
- Update to patternfly v3.59.3 (ascheel)
- Update to jQuery v3.5.1 (ascheel)
- Upgrade to bootstrap v3.4.1 (ascheel)
- Link in new Bootstrap CSS file (ascheel)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- # Bugzilla Bug #1733588 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
J9g/Dogtag Team <pki-devel@redhat.com> 10.5.18-13`e@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1949136 - PKI instance creation failed with new 389-ds-base
  build (jmagne)
- Bugzilla Bug 1949656 - CRMF requests with extensions other than SKID cannot
  be processed (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)8g'Dogtag Team <pki-devel@redhat.com> 10.5.18-12`6?- Change variable 'TPS' to 'tps'
- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla B7##############################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1911472 - Revoke via REST API not working when Agent
  certificate not issued by CA [rhel-7.9.z] (cfu)
- Bugzilla Bug 1914587 - RHEL IPA PKI - Failed to read product version
  String.java.io.FileNotFoundException (ckelley)
- Bugzilla Bug 1942687 - TPS not populating Token Policy, or switching
  PIN_RESET=YES to NO [rhel-7.9.z] (jmagne)
- Bugzilla Bug 1955633 - Recovery of Keys migrated to latest version of KRA
  fail to recover and result in Null Point Exception [rhel-7.9.z] (jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 6)
;qGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7):g!Dogtag Team <pki-devel@redhat.com> 10.5.18-14`- ############################################7
<qODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]bR8RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{7ln7mo7np7oq7pr7qt7rv7sx7t|7y~7z7{777	77777777777 7!7"7%7'7)7*7+7.707273747677797;7<7>7‚?7Â@7ĂA7łB7ƂC7ǂE7ɂF7ʂG7˂I7΂K7ςL7ЂN7҂O7ӂP7ԂR7ׂT7؂V7ڂW7ۂX7܂Z7߂\7]7^7`7e7j7o7u7|77
7777&7-747;7B7H7O7V7\7c7j7p7w7~777888&
Xh>qaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################7#=qWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%?q[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__@qIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
""YAqCDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
``BqGDogtag Team <devel@lists.dogtagpki.org> 10.5.18-15`@- ##########################################################################
- # RHEL 7.9:
- ##########################################################################
- Bugzilla Bug 1905374 - restrict EE profile list and enrollment submission
  per LDAP group without immediate issuance [rhel-7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
CqODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhEqaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################7ȅ#DqWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%Fq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__GqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"IqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################7̅YHqCDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
reKq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)JqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################7
LqODogtag Team <devel@lists.dogtagpki.org> 10.5.18-16a- ##########################################################################
- # RHEL 7.9 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1958277 - PKCS10Client EC Attribute Encoding [cfu]
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500:
  Non-2xx response from CA REST API: 500 [ftweedale, ckelley]
- ##########################################################################
- # RHCS 9.7 (Batch Update 8):
- ##########################################################################
- Bugzilla Bug 1959937 - TPS Allowing Token Transactions while
  the CA is Down [cfu]
- Bugzilla Bug 1979710 - TPS Not properly enforcing Token Profile
  Separation [cfu]
XhNqaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################7х#MqWDogtag Team <devel@lists.dogtagpki.org> 10.5.18-17aA@- ##########################################################################
- # RHEL 7.9 (Batch Update 9):
- ##########################################################################
- Bugzilla Bug 1958788 - ipa: ERROR: Request failed with status 500: Non-2xx
  response from CA REST API: 500 [ftweedal, ckelley]
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%Oq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__PqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"RqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################7ՅYQqCDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
reTq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)SqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################7
_hVqaDogtag Team <devel@lists.dogtagpki.org> 10.5.18-18as@- #######################################7مUqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)###################################
- # RHEL 7.9 (Batch Update 10):
- ##########################################################################
- Bugzillla Bug 1978345 - End Entity's List Certificates Page Back/Forward
  Buttons are Broken (ckelley, jonahon.d.parrish@mail.mil, mharmsen)
- Bugzilla Bug 2008707 - pkispawn bails out too easily for things that could
  have been worked around after installation [RHEL 7.9.z] (cfu)
- Bugzilla Bug 2016773 - Directory authentication plugin requires directory
  admin password just for user authentication (rhel-7.9.z)
  (awnuk@purestorage.com, jmagne)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
%Wq[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-19a*@- ##########################################################################
- # RHEL 7.9 (Batch Update 11):
- ##########################################################################
- Bugzilla Bug 1998597 - TPS RA Separation Issues (cfu)
- Bugzilla Bug 2008319 - PKISpawn with ECC Signing Algorithms fail
  in FIPS Mode (cfu)
- Bugzilla Bug 2018608 - Invalid certificates with creation of subCA
  (pkispawn single step) [rhel-7.9.0.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
__XqIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-20bf@- ##########################################################################
- # RHEL 7.9 (Batch Update 14):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
"ZqDogtag Team <devel@lists.dogtagpki.org> 10.5.18-22co- #####################################################################7݅YYqCDogtag Team <devel@lists.dogtagpki.org> 10.5.18-21b@- ##########################################################################
- # RHEL 7.9 (Batch Update 15):
- ##########################################################################
- Bugzilla Bug #2074722 - user password and pkcs12 password exposure when
  debug level set to maximum [RHEL 7.9.z] (cfu)
- Bugzilla Bug #2082717 - SCEP manual approval failure (cfu)
- ##########################################################################
- # RHCS 9.7:
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)#####
- # RHEL 7.9 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 17):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)#####
- # RHEL 7.9 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- Bugzilla Bug #2111514 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhel-7.9] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 18):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)
- Bugzilla Bug #2111493 - CVE-2022-2393 pki-core: When using the
  caServerKeygen_DirUserCert profile, user can get certificates for other
  UIDs by entering name in Subject field [rhcs_9.7] (cfu, ckelley)
re\q[Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-24cY!@- ##########################################################################
- # RHEL 7.9 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107329 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [rhel-7.9.z] (ckelley, mharmsen)
- ##########################################################################
- # RHCS 9.7 (Batch Update 19):
- ##########################################################################
- Bugzilla Bug #2107325 - CVE-2022-2414 pki-core: access to external
  entities when parsing XML can lead to XXE [certificate_system_9.7.z]
  (ckelley, mharmsen)[qDogtag Team <devel@lists.dogtagpki.org> 10.5.18-23cD	@- #####################################################################7
__]qIDogtag Team <devel@lists.dogtagpki.org> 10.5.18-25c1- ##########################################################################
- # RHEL 7.9 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #2160355 - RA Separation by KeyType - Set Token Status
  [RHCS 9.7 bu 21] (cfu, ckelley)
- ##########################################################################
- # RHCS 9.7 (Batch Update 21):
- ##########################################################################
- Bugzilla Bug #1774177 - Rebase redhat-pki, redhat-pki-theme, pki-core, and
  pki-console to 10.5.18 in RHCS 9.7 (Batch Update 7)
H^q!Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-26d- ##########################################################################
- # RHEL 7.9 (Batch Update 22):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 22):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
QQ^`gYJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129H_q!Dogtag Team <devel@lists.dogtagpki.org> 10.5.18-27dO- ##########################################################################
- # RHEL 7.9 (Batch Update 23):
- ##########################################################################
- ##########################################################################
- # RHCS 9.7 (Batch Update 23):
- ##########################################################################
- Bugzilla Bug #2179305 - Unable to use the TPS UI "Token Filter" to filter
  a list of tokens [RHCS 9.7] (ckelley)
- Bugzilla Bug #2092522 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False [RHCS 9.7.z] (cfu)
- Bugzilla Bug #2176233 - TPS Not allowing Token Status Change based on
  Revoke True/False and Hold till last True/False (part 2) [RHCS 9.7.z] (cfu)
 1eiOJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560diJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Kci/Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441bgAJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[agQJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
NU:^jgYJan Grulich <jgrulich@redhat.com> - 4.11-19-7U|@- Requires: cpp
  Resolves: bz#1260129iiJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159hi5Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401tgiJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-fisJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
 1oiOJan Grulich <jgrulich@redhat.com> - 4.11.19-12Y@- Make sure that plasma screensaver is not used when previously configured
  Resolves: bz#1342560niJan Grulich <jgrulich@redhat.com> - 4.11.19-11Y- Disable plasma screensaver for security reasons
  Resolves: bz#1342560Kmi/Jan Grulich <jgrulich@redhat.com> - 4.11.19-10YA@- Fix grouping of tasks in taskmanager applet
  Resolves: bz#1348917
- Fix unlocking of kscreenlocker, unlock it just once
  Resolves: bz#1333441lgAJan Grulich <jgrulich@redhat.com> - 4.11.19-9Yz- Fix loading of get hot new stuff for KWin decorations and effects
  Resolves: bz#1422002[kgQJan Grulich <jgrulich@redhat.com> - 4.11.19-8V3- Powerdevil: do not notify about a non existent action
  Resolves: bz#1289149
- Plasma taskmanager: close context menu when task is closed
  Resolves: bz#1262603
'NU:'u]-Jan Rybar <jrybar@redhat.com> - 0.112-19\	@- Fix of CVE-2018-19788, priv escalation with high UIDs
- Resolves: rhbz#1656377t]/Jan Rybar <jrybar@redhat.com> - 0.112-18[a- Error message about getting authority is too elaborate
- Resolves: rhbz#1342855siJan Grulich <jgrulich@redhat.com> - 4.11.19-16_
@- KSysguard: Increase cpu buffer size in ksysguard
  Resolves: bz#1856159ri5Jan Grulich <jgrulich@redhat.com> - 4.11.19-15]- Fix curly bracket in the patch for Plastik decoration theme
  Resolves: bz#1779401tqiJan Grulich <jgrulich@redhat.com> - 4.11.19-14]H@- Do not show disabled buttons in Plastik decoration theme
  Resolves: bz#1677641

- Taskmanager: dismiss group when application is closed and there is enough space
  Resolve: bz#1698048-pisJan Grulich <jgrulich@redhat.com> - 4.11.19-13\b@- Sanitise notification HTML
  Resolves: bz#1568853

- Increase cpu buffer size in ksysguard
  Resolves: bz#1611762
L^?L|]5Jan Rybar <jrybar@redhat.com> - 0.112-26]@- Refined upstream fix of CVE-2018-1116 to avoid ABI changes
- Related: rhbz#1601411b{]kJan Rybar <jrybar@redhat.com> - 0.112-25]- fix of CVE-2018-1116
- Resolves: rhbz#1601411z]3Jan Rybar <jrybar@redhat.com> - 0.112-24]- pkttyagent: resetting terminal erases rest of input line
- Resolves: rhbz#1753037y]AJan Rybar <jrybar@redhat.com> - 0.112-23]'$- pkttyagent: process stopped by SIGTTOU if run in background job
- Resolves: rhbz#1724444x]GJan Rybar <jrybar@redhat.com> - 0.112-22\|- pkttyagent: polkit-agent-helper-1 timeout leaves tty echo disabled
- Resolves: rhbz#1325512w]3Jan Rybar <jrybar@redhat.com> - 0.112-21\Z@- Mitigation of regression caused by fix of CVE-2018-19788
- Resolves: rhbz#1656377|v]Jan Rybar <jrybar@redhat.com> - 0.112-20\E@- Fix of CVE-2019-6133, PID reuse via slow fork
- Resolves: rhbz#1667312
,taU,]AJan Rybar <jrybar@redhat.com> - 0.112-23]'$- pkttyagent: process stopped by SIGTTOU if run in background job
- Resolves: rhbz#1724444]GJan Rybar <jrybar@redhat.com> - 0.112-22\|- pkttyagent: polkit-agent-helper-1 timeout leaves tty echo disabled
- Resolves: rhbz#1325512]3Jan Rybar <jrybar@redhat.com> - 0.112-21\Z@- Mitigation of regression caused by fix of CVE-2018-19788
- Resolves: rhbz#1656377|]Jan Rybar <jrybar@redhat.com> - 0.112-20\E@- Fix of CVE-2019-6133, PID reuse via slow fork
- Resolves: rhbz#1667312]-Jan Rybar <jrybar@redhat.com> - 0.112-19\	@- Fix of CVE-2018-19788, priv escalation with high UIDs
- Resolves: rhbz#1656377~]/Jan Rybar <jrybar@redhat.com> - 0.112-18[a- Error message about getting authority is too elaborate
- Resolves: rhbz#1342855}a/Jan Rybar <jrybar@redhat.com> - 0.112-26.1a{- pkexec: argv overflow results in local privilege esc.
- Resolves: CVE-2021-4034
btkb|
]Jan Rybar <jrybar@redhat.com> - 0.112-20\E@- Fix of CVE-2019-6133, PID reuse via slow fork
- Resolves: rhbz#1667312	]-Jan Rybar <jrybar@redhat.com> - 0.112-19\	@- Fix of CVE-2018-19788, priv escalation with high UIDs
- Resolves: rhbz#1656377]/Jan Rybar <jrybar@redhat.com> - 0.112-18[a- Error message about getting authority is too elaborate
- Resolves: rhbz#1342855a/Jan Rybar <jrybar@redhat.com> - 0.112-26.1a{- pkexec: argv overflow results in local privilege esc.
- Resolves: CVE-2021-4034]5Jan Rybar <jrybar@redhat.com> - 0.112-26]@- Refined upstream fix of CVE-2018-1116 to avoid ABI changes
- Related: rhbz#1601411b]kJan Rybar <jrybar@redhat.com> - 0.112-25]- fix of CVE-2018-1116
- Resolves: rhbz#1601411]3Jan Rybar <jrybar@redhat.com> - 0.112-24]- pkttyagent: resetting terminal erases rest of input line
- Resolves: rhbz#1753037

er+V:eD(
3aff8eeef1e22685460bc0aabe262f29bc20ce164b68243c87e313c98c1e32e9D'
b20d6f1e46d161202c4ae45ba1ae9ed58e953a1d4ecbee1eb0acaf15da85fa78D&
66a4fd1fe3f059fdf718b2b6cfe2780550bd2ecc35fc7e05bfc971d08dda1d24D%
57cd2f70db38f1fa93cd1038f8b78c691635c9ffc591f01d4c77aef6482048e5D$
2ff70d59a80bb5a8d198a023ddeeddd3d158a43054e77660764247997d9d5529D#
a55f9423be083a88cde58065e6db2d37a2914f6a3c47d1e7691f1727476f4183D"
6afa61594c5b06f1ffc4710ba8533b869a889dfbfe0172d8e3cf6ea56d8269dfD!
189ac4f6255d2b5abc0708dbb15227064a2197770e4044055b575c335118f124D 
a374981fe49487005f6b444803f5ee027e4f454271acd10934c5612a37320bf3D
1a0a2c585f883eff1f329e4976169d243f39b899c3b430426cd6e1c996b89624D
ac4c7414d6a7541a5319e863c261155019d2a35737e18e635bc5522b6971141aD
22b030d124eaf33b5a95d386b50c0b6eb1b02dfa96a1333d4af435fedbe097b4D
416d63eed80ece67c95210f8579b267e2d49d197964c16f46abc57e43e2e7cb4
@tKY@a/Jan Rybar <jrybar@redhat.com> - 0.112-26.1a{- pkexec: argv overflow results in local privilege esc.
- Resolves: CVE-2021-4034]5Jan Rybar <jrybar@redhat.com> - 0.112-26]@- Refined upstream fix of CVE-2018-1116 to avoid ABI changes
- Related: rhbz#1601411b]kJan Rybar <jrybar@redhat.com> - 0.112-25]- fix of CVE-2018-1116
- Resolves: rhbz#1601411]3Jan Rybar <jrybar@redhat.com> - 0.112-24]- pkttyagent: resetting terminal erases rest of input line
- Resolves: rhbz#1753037
]AJan Rybar <jrybar@redhat.com> - 0.112-23]'$- pkttyagent: process stopped by SIGTTOU if run in background job
- Resolves: rhbz#1724444]GJan Rybar <jrybar@redhat.com> - 0.112-22\|- pkttyagent: polkit-agent-helper-1 timeout leaves tty echo disabled
- Resolves: rhbz#1325512]3Jan Rybar <jrybar@redhat.com> - 0.112-21\Z@- Mitigation of regression caused by fix of CVE-2018-19788
- Resolves: rhbz#1656377
,vmK,]3Jan Rybar <jrybar@redhat.com> - 0.112-24]- pkttyagent: resetting terminal erases rest of input line
- Resolves: rhbz#1753037]AJan Rybar <jrybar@redhat.com> - 0.112-23]'$- pkttyagent: process stopped by SIGTTOU if run in background job
- Resolves: rhbz#1724444]GJan Rybar <jrybar@redhat.com> - 0.112-22\|- pkttyagent: polkit-agent-helper-1 timeout leaves tty echo disabled
- Resolves: rhbz#1325512]3Jan Rybar <jrybar@redhat.com> - 0.112-21\Z@- Mitigation of regression caused by fix of CVE-2018-19788
- Resolves: rhbz#1656377|]Jan Rybar <jrybar@redhat.com> - 0.112-20\E@- Fix of CVE-2019-6133, PID reuse via slow fork
- Resolves: rhbz#1667312]-Jan Rybar <jrybar@redhat.com> - 0.112-19\	@- Fix of CVE-2018-19788, priv escalation with high UIDs
- Resolves: rhbz#1656377]/Jan Rybar <jrybar@redhat.com> - 0.112-18[a- Error message about getting authority is too elaborate
- Resolves: rhbz#1342855
b
nb]3Jan Rybar <jrybar@redhat.com> - 0.112-21\Z@- Mitigation of regression caused by fix of CVE-2018-19788
- Resolves: rhbz#1656377|]Jan Rybar <jrybar@redhat.com> - 0.112-20\E@- Fix of CVE-2019-6133, PID reuse via slow fork
- Resolves: rhbz#1667312]-Jan Rybar <jrybar@redhat.com> - 0.112-19\	@- Fix of CVE-2018-19788, priv escalation with high UIDs
- Resolves: rhbz#1656377]/Jan Rybar <jrybar@redhat.com> - 0.112-18[a- Error message about getting authority is too elaborate
- Resolves: rhbz#1342855a/Jan Rybar <jrybar@redhat.com> - 0.112-26.1a{- pkexec: argv overflow results in local privilege esc.
- Resolves: CVE-2021-4034]5Jan Rybar <jrybar@redhat.com> - 0.112-26]@- Refined upstream fix of CVE-2018-1116 to avoid ABI changes
- Related: rhbz#1601411b]kJan Rybar <jrybar@redhat.com> - 0.112-25]- fix of CVE-2018-1116
- Resolves: rhbz#1601411
DjKXD&c%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304%a/Jan Rybar <jrybar@redhat.com> - 0.112-26.1a{- pkexec: argv overflow results in local privilege esc.
- Resolves: CVE-2021-4034$]5Jan Rybar <jrybar@redhat.com> - 0.112-26]@- Refined upstream fix of CVE-2018-1116 to avoid ABI changes
- Related: rhbz#1601411b#]kJan Rybar <jrybar@redhat.com> - 0.112-25]- fix of CVE-2018-1116
- Resolves: rhbz#1601411"]3Jan Rybar <jrybar@redhat.com> - 0.112-24]- pkttyagent: resetting terminal erases rest of input line
- Resolves: rhbz#1753037!]AJan Rybar <jrybar@redhat.com> - 0.112-23]'$- pkttyagent: process stopped by SIGTTOU if run in background job
- Resolves: rhbz#1724444 ]GJan Rybar <jrybar@redhat.com> - 0.112-22\|- pkttyagent: polkit-agent-helper-1 timeout leaves tty echo disabled
- Resolves: rhbz#1325512
~L-cAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283o,cMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026+cSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504	*c1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+)cuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~(cMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961~'cMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304
+mi+	4c1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+3cuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~2cMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961~1cMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #16583040c%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304/sMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678}.cMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340
CaXMC~;cMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304:c%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #16583049sMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678}8cMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #18013407cAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283o6cMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #17330265cSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504
~@.}BcMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340AcAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283o@cMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026?cSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504	>c1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+=cuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~<cMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961
vl:	Hc1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+GcuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~FcMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961~EcMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304Dc%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304CsMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678
CaXMC~OcMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304Nc%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304MsMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678}LcMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340KcAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283oJcMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026IcSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504
~@.}VcMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340UcAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283oTcMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026ScSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504	Rc1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+QcuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~PcMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961
vl:	\c1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+[cuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~ZcMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961~YcMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304Xc%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304WsMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678
CaXMC~ccMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304bc%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304asMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678}`cMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340_cAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283o^cMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026]cSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504
~@.}jcMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340icAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283ohcMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026gcSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504	fc1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+ecuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~dcMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961
vl:	pc1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+ocuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~ncMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961~mcMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304lc%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304ksMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678
CaXMC~wcMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304vc%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304usMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678}tcMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340scAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283orcMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026qcSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504
~@.}~cMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340}cAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283o|cMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026{cSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504	zc1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+ycuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~xcMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961
vl:	c1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+cuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~cMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961~cMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304c%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304sMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678
CaXMC~cMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304
c%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304	sMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678}cMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340cAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283ocMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026cSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504

er+V:eD5
4979bbf79b86bc451b21e72cc74db0991153920063a30b01bef2f9334eed1607D4
7ab133f1d96805c9be74317d0b4bcea3e9eababb5fcc413f08dbe0176819a8c7D3
9a83d7998a3864c74ef1b2bf4f61a19da0f4c226c45f7a70d50c9c0f75da1207D2
1537999eab86e331b7616768bea67b873d68628c73c3287db0880ce0846cdbedD1
24699358bf47868256f0864e15068069f9dc2d6b473bfc07b8c40d1a5f0bf3edD0
c86aee9cf2e2da2f84035f7c561f1365eee34235321b9b4983b359b9f5cd8060D/
2f3a77bd6bf53c49e09304c30a934f3f38f8f85bb51455216f94ab7eeb5a0502D.
ea9dcf09763ae93b161230c20f7c1a05f3a8854c5c164594f7bcfbeefb4c4ffdD-
186d5436f6365f279482c72b48d2038d776476514615d06d9fbbf8a163f36dfbD,
00a2d48440baace65111ae56106256b8e047e95d4a9a467ebaed09dc73f03585D+
6f484446414072c482a1b896884d3548ebc69e39b5a32f1817778985ebfe7054D*
11c4d1e2b30e04a86c011ebc0edda9c30a6b0f8a2a4c493606247511a8a39184D)
36ff4ef5c9d824aa0dc623200d80aad9bf2bc1f5d992c7cfd42bd6eb14264c63
~@.}cMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340cAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283ocMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026cSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504	c1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+
cuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~cMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961
vl:	c1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+cuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~cMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961~cMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304c%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304sMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678
CaXMC~cMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304c%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304sMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678}cMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340cAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283ocMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026cSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504
~@.}&cMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340%cAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283o$cMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026#cSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504	"c1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+!cuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~ cMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961
vl:	,c1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575++cuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~*cMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961~)cMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304(c%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304'sMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678
CaXMC~3cMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #16583042c%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #16583041sMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678}0cMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340/cAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283o.cMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026-cSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504
~@.}:cMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #18013409cAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283o8cMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #17330267cSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504	6c1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+5cuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~4cMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961
vl:	@c1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+?cuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~>cMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961~=cMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304<c%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304;sMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678
CaXMC~GcMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304Fc%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304EsMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678}DcMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340CcAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283oBcMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026AcSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504
~@.}NcMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340McAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283oLcMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026KcSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504	Jc1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+IcuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~HcMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961
vl:	Tc1Marek Kasik <mkasik@redhat.com> - 0.26.5-39]R@- Check whether input is RGB in PSOutputDev::checkPageSlice()
- Resolves: #1697575+ScuMarek Kasik <mkasik@redhat.com> - 0.26.5-38\- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1688417~RcMarek Kasik <mkasik@redhat.com> - 0.26.5-37\+@- Fix tiling patterns when pattern cell is too far
- Resolves: #1378961~QcMarek Kasik <mkasik@redhat.com> - 0.26.5-36\A- Fix version from which PrintScaling is available
- Resolves: #1658304Pc%Marek Kasik <mkasik@redhat.com> - 0.26.5-35\@- Export PrintScaling viewer preference in glib frontend
- Related: #1658304OsMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678
/aXM/Z_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlYsMarek Kasik <mkasik@redhat.com> - 0.26.5-43.el7_9.1_[f- Handle bytestring representation of named dests
- Resolves: #1857678}XcMarek Kasik <mkasik@redhat.com> - 0.26.5-43^@- Fix crash on broken file in tilingPatternFill()
- Resolves: #1801340WcAMarek Kasik <mkasik@redhat.com> - 0.26.5-42]Γ@- Fix potential integer overflow and check length for negative values
- Resolves: #1757283oVcMarek Kasik <mkasik@redhat.com> - 0.26.5-41]RB- Ignore dict Length if it is broken
- Resolves: #1733026UcSMarek Kasik <mkasik@redhat.com> - 0.26.5-40]RA- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1723504
bsx	zam	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek`_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p_i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915^iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM]i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172\_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html[_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html
\nK\Mgi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172f_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmle_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmld_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlccm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
bm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895
yn_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlcmm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
lm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zkm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekj_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pii{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915hiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged user
0b)0cvm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
um/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895ztm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writeks_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pri{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915qiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMpi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172o_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html
(a(z~m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek}_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p|i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915{iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMzi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172y_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmlx_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html_wc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507
Kn.Kk_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895
&iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM
i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmlcAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_
c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507c	m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket write

er+V:eDB
d0e13c7b2d8069a8e53ad1f052d37d201f037564f4a6b8c6165af57ea91234a3DA
4d378775c38c6fc1f731d1861a287e0d217101b8afe07f3c8b0d015fc2a45e89D@
602cbf2e2644ca8e5ce215838f087adf2ca12992b3040f73b33fa5d3c4c91610D?
e55fe3806bd7c427b2a99d06f4cd6144b05e9c389c33efc7071369f9a633b952D>
89fe97926c4d82b3dbe9d1b08249e01972849f4771aa0ffff539f310b5c68178D=
ecf6cae26af65369af3f9a5e154c7224e8c19a7f2b087e7e89cde5eec6f6000dD<
2f972c76855cb2639dc2a960dd3b2ab524ab364a74e37c8962ab8772b4e8115dD;
cbbbf0c961b09325211c498b9b16d75a582a8a2c062653a5a8965090c1ea66acD:
b8d2de93054764674ee23673c18575b0b841cfa8e724e00499ab00ed583c6621D9
28a4c9399dcb130222cfa30fabd302b361ec8967c075e982a44603e492358e57D8
381a42f9ec21ac9b849c1cdd79e2900f003e44319a05a25427dce938f720c548D7
1d9aa0d9b3f62047faad0dd116b485d64442f569bc592a53a88f39ac5ba871c7D6
ca4ba17177c7df277d3b1d022543b4bad6f9ceff842f9b3d18126d3f7bc73149
\
C\Mi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915
&y&cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged user
uV[nuc&m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
%m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z$m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek#_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p"i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915!iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172UaMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869
TT,_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html+_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html*_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlU)aMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869(cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_'c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507
0(E504_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlc3m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
2m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z1m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek0_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p/i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915.iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM-i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172
0b)0c<m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
;m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z:m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek9_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p8i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-109157iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM6i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-121725_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html
4'D4
Dm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zCm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekB_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pAi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915@iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM?i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172>_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_=c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507
g6OTgzLm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekK_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pJi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915IiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMHi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172GcAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_Fc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cEm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
nR_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlUQaMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869PcAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_Oc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cNm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
Mm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895
bsx	zYm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekX_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pWi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915ViPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMUi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172T_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmlS_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html
\nK\M_i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172^_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html]_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html\_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlc[m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
Zm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895
yf_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlcem]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
dm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zcm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekb_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pai{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915`iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged user
0b)0cnm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
mm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zlm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekk_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pji{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMhi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172g_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html
(a(zvm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writeku_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pti{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915siPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMri5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172q_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmlp_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html_oc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507
Kn.Kk~_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p}i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915|iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM{i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172z_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_yc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cxm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
wm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895
&iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmlcAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket write
\
C\Mi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172
cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z	m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915

er+V:eDO
a72dca1881f486beecebc91ccadda2fe934171b30a0aa1ecdeed9af74f7778d9DN
9b01dd0b8e02a853dbc19ea531e09d6c0d39b454023c90e0b36c94a8d8fdd356DM
a2218b6da0ff7fbf1477f94aececde3dbb0c8dae25eaea7857803f8041d6f171DL
d67f0639fb490343c9abcb00e2620e6b3adbccb1d2fe315924eefec088757c1dDK
0926abec8c375e818901656da36c33757d3a3e3bf4baf9195278ae3f048fd8e5DJ
7ac006a9950b2c1cc710083732c5cc4a33e7c20c3699c50ad6f24318b5986edbDI
4085f09e7be4410758ded16aeb5fca59795cf4c2ad37a1afa78cddf45bef6806DH
dc486f913960456b5d2e5d97371e0ea044e845fd7daad4a9405caee17252a41aDG
118a4f0750f04814284ed67586a40ab0b954a4f4ab7d694596131eb54460a3e2DF
ab74d7b998e9fec54c2357c857d922e433b311d8164291884b6b827aa2d9a8efDE
088144b029dc1cc8f91996726bfc5e8a3ea03cb750f26a8038b554a33f1bc66dDD
b3eb25f000c6f150675f527c9303e23ee9dffdf1666a7746fa5d502bb01276e5DC
42bbeefe5d2da9855ecb5e645b7be4aacf43260cc22bd95b02da32fc849a989d
&y&cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged user
uV[nucm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172UaMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869
TT$_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html#_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html"_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlU!aMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869 cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507
0(E50,_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlc+m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
*m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z)m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek(_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p'i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915&iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM%i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172
0b)0c4m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
3m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z2m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek1_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p0i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915/iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM.i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172-_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html
4'D4
<m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z;m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek:_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p9i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-109158iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM7i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-121726_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_5c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507
g6OTgzDm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekC_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pBi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915AiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM@i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172?cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_>c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507c=m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
$nA$LFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 9.2.1002-2Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild{KU#Tom Lane <tgl@redhat.com> 9.2.1002-1P- Update to build 9.2-1002 (just to correct mispackaging of source tarball)pJU
Tom Lane <tgl@redhat.com> 9.2.1001-1P6@- Update to build 9.2-1001 for compatibility with PostgreSQL 9.2UIaMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869HcAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_Gc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cFm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
Em/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895
Lb)-LwSg	Ondrej Dubaj <odubaj@redhat.com> - 9.2.1002-8_ @- require explicitly jdk-1.7 due to ABI bytecode compatibilitybRgaOndrej Dubaj <odubaj@redhat.com> - 9.2.1002-7_@- fixed XXE vulnerability (CVE-2020-13692)$Qm]Pavel Raiskup <praiskup@redhat.com> - 9.2.1002-6Z@- fix incompatibility with 9.6+ (rhbz#1547424)
- it's unnecessary to depend on whole java (rhbz#1406931)OPc?Daniel Mach <dmach@redhat.com> - 9.2.1002-5Rk- Mass rebuild 2013-12-27SOm=Pavel Raiskup <praiskup@redhat.com> - 9.2.1002-4RA- add javadoc subpackage]NmOPavel Raiskup <praiskup@redhat.com> - 9.2.1002-4R@- don't use removed macro %add_to_maven_depmap (#992816)
- lint: trim-lines, reuse %{name} macro, fedora-review fixes
- merge cleanup changes by Stano OchotnickyMFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 9.2.1002-3QB@- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild
E
oEOZc?Daniel Mach <dmach@redhat.com> - 9.2.1002-5Rk- Mass rebuild 2013-12-27SYm=Pavel Raiskup <praiskup@redhat.com> - 9.2.1002-4RA- add javadoc subpackage]XmOPavel Raiskup <praiskup@redhat.com> - 9.2.1002-4R@- don't use removed macro %add_to_maven_depmap (#992816)
- lint: trim-lines, reuse %{name} macro, fedora-review fixes
- merge cleanup changes by Stano OchotnickyWFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 9.2.1002-3QB@- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_RebuildVFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 9.2.1002-2Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild{UU#Tom Lane <tgl@redhat.com> 9.2.1002-1P- Update to build 9.2-1002 (just to correct mispackaging of source tarball)pTU
Tom Lane <tgl@redhat.com> 9.2.1001-1P6@- Update to build 9.2-1001 for compatibility with PostgreSQL 9.2
WvX`_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html__UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html^_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlw]g	Ondrej Dubaj <odubaj@redhat.com> - 9.2.1002-8_ @- require explicitly jdk-1.7 due to ABI bytecode compatibilityb\gaOndrej Dubaj <odubaj@redhat.com> - 9.2.1002-7_@- fixed XXE vulnerability (CVE-2020-13692)$[m]Pavel Raiskup <praiskup@redhat.com> - 9.2.1002-6Z@- fix incompatibility with 9.6+ (rhbz#1547424)
- it's unnecessary to depend on whole java (rhbz#1406931)
(E5cgm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
fm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zem	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekd_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pci{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915biPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMai5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172bR8lRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{838:8@8G8N8	T8
Z8a8g8
n8v8~88888&8,848<8D8L8R8Y8_8f8n8 v8!~8"8#8%8&8'$8(,8)48*<8+D8,L8-S8.Z8/`80g82m83t84|858687898:$8;,8<28=:8>B8?J8@R8AX8B`8Ch8Dp8Ex8F~8G8H8I8K8L$8M*8N28O:8PB8QJ8RP8SW8T]8Ud8Vl8Wt8X|8Y8Z8[8]8^"8_*8`28a:8bB8cH8dP8eX8f`8gh8ho8iv8j~8k
ZDUZpmi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915liPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMki5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172j_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmli_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlh_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.html
|Mti5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172s_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmlr_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlcqm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
pm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zom	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekn_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154
y|_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html_{c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507czm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
ym/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zxm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekw_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pvi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915uiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged user
0b)0cm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM~i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172}_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html
4'D4
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek
_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p	i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507
G6*Gk_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmlcAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507c
m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208

er+V:eD\
704e68779e898e44b1324e899262e104a830680049fc89a0fc633372c94879d0D[
b0526855331c1bb15a63cd3241270a0c0330c224d607dfbf6bc5f4b2bc92a167DZ
a0ea2fe57948c676dcf2c0fbdebfa53f6faf41c7af4de552c31411ddf372859dDY
89663c4870645c61c09aa110191348cb2ce24502cea8c4fffd24cf917b5e31b9DX
5e632ae289a07749557d914455977eb18c0451d2f3b06c6f4482d91ce046ec68DW
ccca4bce0f9734afe3ffbbf8289dcde7d83df145008c78c72d9ab7affdddb8a3DV
a93a8dc3ff39c6f387f6ec4a439ce6ac3e94c0162375d5397c5b1d880d365031DU
af2767aa1b7983e412e5c57ff7c018c32283c328f7c297d91fde01ea5fc02e62DT
04b0f0e217513325d81caf263da9288d80eb720c931507ed120b0b99d52505adDS
f46d473dfbe5a0b5d02b3be921a86e5638354a09914341da2a7329751ea9632aDR
20df00700ce564462df55efddd738d3298f0144e75431e267025497928e55dd6DQ
cbb6af40c795f009b496be4951e5998ed66639496f46e7e7cff519014726e16cDP
0021c82540d24671074ea3ef5535b58a819c02dfddf7e05c15f9ae392ea8c199
D&?Dpi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket write
w!wM$i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172U#aMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869"cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_!c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507c m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154
&y&,cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_+c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507c*m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
)m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z(m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek'_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p&i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915%iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged user
uMu2iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM1i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-121720_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html/_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html._UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlU-aMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869

jM:i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-121729_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html8_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlc7m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
6m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z5m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek4_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p3i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915
yB_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_Ac_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507c@m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
?m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z>m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek=_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p<i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915;iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged user
k(E5k_Jc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cIm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
Hm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zGm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekF_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pEi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915DiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMCi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172
8j18cRm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
Qm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zPm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekO_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pNi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915MiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMLi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172KcAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b
TTX_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmlW_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlV_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlUUaMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869TcAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_Sc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507
0(E50`_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlc_m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
^m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z]m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek\_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p[i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915ZiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMYi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172
0b)0chm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
gm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zfm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writeke_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pdi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915ciPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMbi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172a_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html
4'D4
pm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zom	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekn_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pmi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915liPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMki5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172j_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_ic_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507
g6OTgzxm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekw_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pvi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915uiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMti5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172scAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_rc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cqm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
n~_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlU}aMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869|cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_{c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507czm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
ym/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895
bsx	zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html
nizpi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM
i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172	_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlcm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895
AAiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek
_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154

er+V:eDi
b3dcd6321521c266fd3fc743152c2fb5145426a5861f180609a075c9b1356d64Dh
8edd67ec853916a9acaf2fddad8db6c86590d7e4c9f7039a7a22270cf6eba4a4Dg
2df02b3bb45254d1541c757afacad26d93c7abaeb07503b155a89e9094ee1e18Df
0a621e3a587fb00080786a7b80616e9ce0fe3cfbf0131712ea44c6dee612c0a3De
842133034fea3edd8842d20f2ab2a87bc76f467525d1a38c9db15fab32ad4a5aDd
209916882b3c80523545c0e55445deecfae6f7a37cc100b47fc3ef29971078e6Dc
d4d33673f61182e94386c936d90db76b50dd75d08ee12591565c25dfe73cc1f7Db
dbab6f5f1c1f7222d48fde249b8f8b6ab3e0899028dd22c3a51b9c38eea6a20aDa
ff7e64392cb0525eb93067fe372af5efaf9fe58c81b8b7441f540801c817f214D`
faa6d60940c2b7406116f4f0516e03526f4e692a662e39080ecd2196b0b55f9bD_
f9d23d9aa39fc06d77ca52634c5687043798a77e8d556e2e1acc0ec503af693dD^
7d51d69ba5aa33fd5b306518dd99095ba3f2ff1d6747f56936b992042029875aD]
eaa6538f84c57debe1e4e618a3bc6f27c19d7cf0cec59ad717f487b978c10409
\
C\Mi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915
&y&$cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_#c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507c"m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
!m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged user
uMu*iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM)i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172(_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html'_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html&_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlU%aMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869

jM2i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-121721_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html0_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlc/m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
.m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z-m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek,_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p+i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915
y:_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_9c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507c8m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
7m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z6m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek5_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p4i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-109153iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged user
k(E5k_Bc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cAm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
@m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z?m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek>_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p=i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915<iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM;i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172
8j18cJm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
Im/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zHm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekG_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pFi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915EiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMDi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172CcAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b
TTP_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmlO_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlN_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlUMaMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869LcAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_Kc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507
(E5cWm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
Vm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zUm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekT_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pSi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915RiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMQi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172
ZDUZp]i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915\iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM[i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172Z_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmlY_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlX_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.html
|Mdi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172c_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmlb_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlcam]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
`m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z_m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek^_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154
yl_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html_kc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cjm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
im/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zhm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekg_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pfi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915eiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged user
0b)0ctm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
sm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zrm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekq_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154ppi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915oiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMni5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172m_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html
4'D4
|m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z{m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekz_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pyi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915xiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMwi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172v_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_uc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507
G6*Gk_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmlcAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_~c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507c}m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
D&?Dpi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM
i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172	cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket write
w!wMi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172UaMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek
_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154

er+V:eDv
f87dbce0436b2de45c2927d892e89fb44340ab9ee675d27c648fbe5c6ae4fdebDu
4a28543a74238167f9429cc3669d937bcf9dd1f1fbbac1543897abe810b13539Dt
fd8b80ddbac39b51ec642889d4f7007835aa7e1d353569778d00ad7dfdb85326Ds
e32d8d85dca546b68def9a0c2f007a2e17b1c0a6759ec1917fbd3848b1afdaf0Dr
2070f81e2419a997f63d16358fa5bce8d6ec0e00e5999fb5444e8c6f5fed72c7Dq
11eb54ccf2baedf7ad57449921954e6b13044b7677f41af6fba598987dda022fDp
2660a3b1922f5ae40d7ad5ae794ca536eef7602567dd9c6fdb63dc9e6eba432fDo
191e06199dad5d65a5b31df32a668436cf290b67dd7cdebea120791a8af5661aDn
02df0d560a1cd7208b8336532084570d73cca1c40562c74bcccd6e5aef84f343Dm
82a28484b658942b7c372b985b9758e0960b5693341a8ede58595d4285be2863Dl
08824226d21e7afa5b192b8623609503e7928c2f070b02660b7372a5fd8999b0Dk
f7adf614ea3e894e205363b2127216f22ee9c39ca71d8e74850d8e335e75be47Dj
8b9983515bad07afac7d8a923e4244430a10f0e33fb043f5940c02b4b63188b7
&y&cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged user
uMu"iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM!i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172 _UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.html_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlUaMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869

jM*i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172)_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html(_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlc'm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
&m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z%m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek$_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p#i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915
y2_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_1c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507c0m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
/m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z.m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek-_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p,i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915+iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged user
k(E5k_:c_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507c9m]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
8m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z7m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek6_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p5i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-109154iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM3i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172
8j18cBm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
Am/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z@m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek?_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p>i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915=iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM<i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172;cAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b
TTH_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.htmlG_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlF_UPetr Kubat <pkubat@redhat.com> - 9.2.21-1YR@- update to 9.2.21 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-21.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-20.html
  http://www.postgresql.org/docs/9.2/static/release-9-2-19.htmlUEaMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869DcAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_Cc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507
0(E50P_UPetr Kubat <pkubat@redhat.com> - 9.2.22-1Y- update to 9.2.22 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-22.htmlcOm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
Nm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zMm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekL_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pKi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915JiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMIi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172
0b)0cXm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
Wm/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895zVm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekU_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pTi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915SiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMRi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172Q_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html
4'D4
`m/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895z_m	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writek^_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154p]i{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915\iPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userM[i5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172Z_UPetr Kubat <pkubat@redhat.com> - 9.2.23-1YW@- update to 9.2.23 per release notes
  http://www.postgresql.org/docs/9.2/static/release-9-2-23.html_Yc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507
g6OTgzhm	Patrik Novotný <panovotn@redhat.com> - 9.2.24-4^*@- Patch fixing BZ#1754816: handle EAGAIN error on socket writekg_{Filip Januš <fjanus@redhat.com> 9.2.24-2]d@- Check if callback is already set
  Resolves: #1755154pfi{Pavel Raiskup <praiskup@redhat.com> - 9.2.24-1[r@- update to the latest 9.2 release
- fix CVE-2018-10915eiPavel Raiskup <praiskup@redhat.com> - 9.2.23-3ZN- setup: keep PGSETUP_* variables after switching to not-privileged userMdi5Pavel Raiskup <praiskup@redhat.com> - 9.2.23-2Y- fix CVE-2017-12172ccAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_bc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cam]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
n&xo_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
n_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548UmaMFilip Janus <fjanus@redhat.com> - 9.2.24-9eV@- Backport fix for CVE-2023-5869lcAFilip Januš <fjanus@redhat.com> - 9.2.24-8bT- Resolves: CVE-2022-1552
- Backport upstrem fix: a117cebd638dd02e5c2e791c25e43745f233111b_kc_Filip Januš <fjanus@redhat.com> - 9.2.24-7`- Fix CVE-2021-32027
- Resolves: #1964507cjm]Patrik Novotný <panovotn@redhat.com> - 9.2.24-6`v@- Patch fixing BZ#1741488 CVE-2019-10208
im/Patrik Novotný <panovotn@redhat.com> - 9.2.24-5_- Patch fixing CVE-2020-25694 BZ#1907894
- Patch fixing CVE-2020-25695 BZ#1907895
s:zsxvaWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#uagWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385ta#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036YsaUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036ZraWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036^q_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897ApiRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104
]~a#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036Y}aUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036Z|aWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036^{_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897AziRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104xy_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
x_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548lwa{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308
9Xla9^_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897AiRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104x_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548la{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308xaWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#agWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385
 E+ x
_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548la{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308x
aWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#	agWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385a#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036YaUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036ZaWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036
s:zsxaWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#agWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385a#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036YaUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036ZaWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036^_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897AiRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104
]a#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036YaUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036ZaWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036^_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897AiRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104x_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548la{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308

er+V:eD
8043266fac97f3c92dfeaa8fad590469ad37ab990d86e9ece87829bdd9e0c8aeD
29124a79cce7024da4f024131a66f80d78a70d73c5fafe6456617633e5b83560D
192e0475321fe56db4e9593f45ee8e350eefc332f30d7e62d1412741c38ef09bD
cd47da0bf7624d9af2d98aa4723dcdf7e0ce48932c9a21df223ff98c038a0e30D
11d2a53897da8b2f56ff7a088f863588c6608a98701a107ae5cbb6d5b7b2e588D~
4ec201776d93e717d898e90c7576b88da99dbbcc0c2c4e7a0088d155ac4678dbD}
438402ee92c25f036bd2deaa1cdeb1a00f4983754853d65bac78fd9adc101eabD|
f10fadd67898b87e6a2cff2133bfc00f51855894a26aec2b6bbd530aec018cc2D{
6f2e6d0fece31e7231bbaae7370f0f0edc484ea6e4bb69ce105819e1f85a83e5Dz
99f0c52a65a75ef09c13260211d703963aba5c4870dc9b32bbda82b9a3a9fe18Dy
1ba4f8757a2691d9efa669857ab5fb078e658b82755130941f6240d178c6b8eeDx
7feb97ca5ba81f62121c4d6fe734440acedc56ff87444880b72d989261a4148eDw
491db6a3e909d355ebf2f70d1e83753a0ca5ce5a0a294d1a7903cb2e82a228c8
9Xla9^#_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897A"iRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104x!_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
 _7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548la{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308xaWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#agWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385
 E+ x+_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
*_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548l)a{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308x(aWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#'agWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385&a#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036Y%aUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036Z$aWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036
s:zsx2aWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#1agWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #14573850a#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036Y/aUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036Z.aWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036^-_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897A,iRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104
]:a#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036Y9aUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036Z8aWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036^7_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897A6iRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104x5_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
4_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548l3a{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308
9Xla9^A_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897A@iRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104x?_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
>_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548l=a{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308x<aWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#;agWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385
 E+ xI_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
H_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548lGa{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308xFaWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#EagWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385Da#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036YCaUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036ZBaWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036
s:zsxPaWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#OagWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385Na#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036YMaUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036ZLaWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036^K_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897AJiRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104
]Xa#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036YWaUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036ZVaWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036^U_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897ATiRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104xS_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
R_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548lQa{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308
9Xla9^__aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897A^iRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104x]_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
\_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548l[a{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308xZaWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#YagWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385
 E+ xg_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
f_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548lea{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308xdaWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#cagWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385ba#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036YaaUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036Z`aWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036
s:zsxnaWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#magWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385la#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036YkaUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036ZjaWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036^i_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897AhiRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104
]va#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036YuaUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036ZtaWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036^s_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897AriRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104xq_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
p_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548loa{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308
9Xla9^}_aWim Taymans <wtaymans@redhat.com> - 6.0-8Wq@- update translations
- Resolves: #1272897A|iRex Dieter <rdieter@fedoraproject.org> - 6.0-7U- better autostart.patch, handle case were autospawn is disabled
  (or otherwise doesn't work, like for root user)
- Resolves: #1269104x{_Wim Taymans <wtaymans@redhat.com> - 6.0-6ULA- build against bluez5
- disable ofono backend
- Resolves: #1174548
z_7Wim Taymans <wtaymans@redhat.com> - 6.0-5UL@- Add more Requires to avoid testing multiple versions for qpaeq
- Resolves: #1174548lya{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308xxaWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#wagWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385
+E++reJakub Hrozek <jhrozek@redhat.com> - 1.1.26-1WYZ@- Resolves: rhbz#1320253 - Rebase libldb to version 1.1.26e'Jakub Hrozek <jhrozek@redhat.com> - 1.1.25-1Vb- Rebase libldb to 1.1.25
- Remove upstreamed patches
- Related: rhbz#1322691la{Wim Taymans <wtaymans@redhat.com> - 10.0-6_?@- Allow root owned home directory.
- Resolves: #1856308xaWim Taymans <wtaymans@redhat.com> - 10.0-5Z]@- Dist the new config file for Dell dock TB16
- Resolves: #1457385#agWim Taymans <wtaymans@redhat.com> - 10.0-4Y@- Add support for usb audio in the Dell dock TB16
- Add patches to improve default sinks
- Resolves: #1457385a#Wim Taymans <wtaymans@redhat.com> - 10.0-3XC- Add more Requires to avoid testing multiple versions
- Resolves: #1387036YaUWim Taymans <wtaymans@redhat.com> - 10.0-2XY- enable webrtc
- Resolves: #1387036Z~aWKalev Lember <klember@redhat.com> - 10.0-1X@- Update to 10.0
- Resolves: #1387036
GX7CGzcJakub Hrozek <jhrozek@redhat.com> - 1.5.4-1]B@- Resolves: rhbz#1736013 - Rebase libldb to version 1.5.4 for SambazcJakub Hrozek <jhrozek@redhat.com> - 1.4.2-1\?- Resolves: rhbz#1658758 - Rebase libldb to version 1.4.2 for Sambav
cJakub Hrozek <jhrozek@redhat.com> - 1.3.4-1[3|@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasev	cJakub Hrozek <jhrozek@redhat.com> - 1.3.3-1Z- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasevcJakub Hrozek <jhrozek@redhat.com> - 1.3.2-1Z̧@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebase"ccJakub Hrozek <jhrozek@redhat.com> - 1.2.2-1YM- Resolves: rhbz#1470056 - Rebase libldb to enable samba rebase to
                           version 4.7.x#ecJakub Hrozek <jhrozek@redhat.com> - 1.1.29-1X@- Resolves: rhbz#1393810 - Rebase libldb to enable samba rebase to
                           version 4.6.x
YMYvcJakub Hrozek <jhrozek@redhat.com> - 1.3.3-1Z- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasevcJakub Hrozek <jhrozek@redhat.com> - 1.3.2-1Z̧@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebase"ccJakub Hrozek <jhrozek@redhat.com> - 1.2.2-1YM- Resolves: rhbz#1470056 - Rebase libldb to enable samba rebase to
                           version 4.7.x#ecJakub Hrozek <jhrozek@redhat.com> - 1.1.29-1X@- Resolves: rhbz#1393810 - Rebase libldb to enable samba rebase to
                           version 4.6.xreJakub Hrozek <jhrozek@redhat.com> - 1.1.26-1WYZ@- Resolves: rhbz#1320253 - Rebase libldb to version 1.1.26e'Jakub Hrozek <jhrozek@redhat.com> - 1.1.25-1Vb- Rebase libldb to 1.1.25
- Remove upstreamed patches
- Related: rhbz#1322691`
e_Andreas Schneider <asn@redhat.com> - 1.5.4-2`Y@- resolves: #1941511 - Fix CVE-2021-20277
~&&~#ecJakub Hrozek <jhrozek@redhat.com> - 1.1.29-1X@- Resolves: rhbz#1393810 - Rebase libldb to enable samba rebase to
                           version 4.6.xreJakub Hrozek <jhrozek@redhat.com> - 1.1.26-1WYZ@- Resolves: rhbz#1320253 - Rebase libldb to version 1.1.26e'Jakub Hrozek <jhrozek@redhat.com> - 1.1.25-1Vb- Rebase libldb to 1.1.25
- Remove upstreamed patches
- Related: rhbz#1322691`e_Andreas Schneider <asn@redhat.com> - 1.5.4-2`Y@- resolves: #1941511 - Fix CVE-2021-20277zcJakub Hrozek <jhrozek@redhat.com> - 1.5.4-1]B@- Resolves: rhbz#1736013 - Rebase libldb to version 1.5.4 for SambazcJakub Hrozek <jhrozek@redhat.com> - 1.4.2-1\?- Resolves: rhbz#1658758 - Rebase libldb to version 1.4.2 for SambavcJakub Hrozek <jhrozek@redhat.com> - 1.3.4-1[3|@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebase

er+V:eD
697fc862a611518e9a75fc2d3bd296143b53d97834fbcd415d05c6cf3c77c118D
2c05f80ee0d06dcbfa8d83439b41cacb2acbe096d4994aed2e9a4b88d43c309cD
70e1c9c7b7313acc1ccb883850558645a0cb1025e1b3d02d84b62ac7a8bef574D

eacae6ba8f4fa9d2b666e28bad819c383c5eb197aa1aa5f5979c415530cf3376D
097333804cdbb8a534dabe56aeb0d3b2dbc4a9c4796ca5102c74fa94f597ff42D
f34c8bb09dee906565117017407530b10c48ef7eb3ccb89860689de03b8e4118D

ae536957e133aeb89aaad21eb5caebf2070b33547c21e967a1d51cc8ab213be4D	
a9b4ea25e0a41a0300195b07a478887cdc00b3c879db84a0cf5c31832d626194D
0c3ad35e059126bc405bb6ab3f4ae6d37fcb202c2192112ede3ec719d4c45554D
708ae9f5c9f58b7f03e17c41afccd5768e49cb8d182d52db3c83077d9a7294c8D
cf8845ef810f6cf39ce19f2a986496e8ae2fed2fe5d711309d0e91b72b693e29D
8f596e23215f48c31a9bb115c327431b21431ac93d7279b39dc998ca0bdfc6b8D
b3dbb953a4dc9b8b5ee95024d51d922488db5a0f0ec2ece9bf47d8d5cbbf24fa
Yem`!e_Andreas Schneider <asn@redhat.com> - 1.5.4-2`Y@- resolves: #1941511 - Fix CVE-2021-20277z cJakub Hrozek <jhrozek@redhat.com> - 1.5.4-1]B@- Resolves: rhbz#1736013 - Rebase libldb to version 1.5.4 for SambazcJakub Hrozek <jhrozek@redhat.com> - 1.4.2-1\?- Resolves: rhbz#1658758 - Rebase libldb to version 1.4.2 for SambavcJakub Hrozek <jhrozek@redhat.com> - 1.3.4-1[3|@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasevcJakub Hrozek <jhrozek@redhat.com> - 1.3.3-1Z- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasevcJakub Hrozek <jhrozek@redhat.com> - 1.3.2-1Z̧@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebase"ccJakub Hrozek <jhrozek@redhat.com> - 1.2.2-1YM- Resolves: rhbz#1470056 - Rebase libldb to enable samba rebase to
                           version 4.7.x
CvX7Cv(cJakub Hrozek <jhrozek@redhat.com> - 1.3.4-1[3|@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasev'cJakub Hrozek <jhrozek@redhat.com> - 1.3.3-1Z- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebasev&cJakub Hrozek <jhrozek@redhat.com> - 1.3.2-1Z̧@- Resolves: rhbz#1558497 - Rebase libldb to enable samba rebase"%ccJakub Hrozek <jhrozek@redhat.com> - 1.2.2-1YM- Resolves: rhbz#1470056 - Rebase libldb to enable samba rebase to
                           version 4.7.x#$ecJakub Hrozek <jhrozek@redhat.com> - 1.1.29-1X@- Resolves: rhbz#1393810 - Rebase libldb to enable samba rebase to
                           version 4.6.xr#eJakub Hrozek <jhrozek@redhat.com> - 1.1.26-1WYZ@- Resolves: rhbz#1320253 - Rebase libldb to version 1.1.26"e'Jakub Hrozek <jhrozek@redhat.com> - 1.1.25-1Vb- Rebase libldb to 1.1.25
- Remove upstreamed patches
- Related: rhbz#1322691
s$/s7/ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530v.ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600w-yyCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-82\-@- Updated fix for CVE-2019-9636
Resolves: rhbz#1689317x,y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-81\@- Security fix for CVE-2019-9636
Resolves: rhbz#1689317`+e_Andreas Schneider <asn@redhat.com> - 1.5.4-2`Y@- resolves: #1941511 - Fix CVE-2021-20277z*cJakub Hrozek <jhrozek@redhat.com> - 1.5.4-1]B@- Resolves: rhbz#1736013 - Rebase libldb to version 1.5.4 for Sambaz)cJakub Hrozek <jhrozek@redhat.com> - 1.4.2-1\?- Resolves: rhbz#1658758 - Rebase libldb to version 1.4.2 for Samba
vvv6ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600(5yYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481y4y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998y3y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773l2ycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551y1y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388x0y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#1704174
4DK^4(=yYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481y<y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998y;y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773l:ycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551y9y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388x8y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#170417477ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530
*O*lCycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yBy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xAy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747@ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530x?y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680>yiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494
=Y$=gIgkLumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917xHy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680GyiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(FyYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yEy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yDy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773
(OyY	Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yNy}	Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yMy}	Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lLyc	Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yKy}	Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xJy{	Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#1704174
jOjvSyw	Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-94e@- Security fix for CVE-2023-40217
Resolves: RHEL-9615gRgk	Lumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917xQy{	Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680Pyi	Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494
fftVm
David Lehman <dlehman@redhat.com> - 0.61.15.69-1Z_@- Fix accounting for metadata when growing lvm. (dlehman)-Umo
David Lehman <dlehman@redhat.com> - 0.61.15.68-1Z}@- Catch lvm metadata lookup failure in md post create. (dlehman)
  Related: rhbz#1223564
  Resolves: rhbz#1543579kTmk
David Lehman <dlehman@redhat.com> - 0.61.15.67-1Zz@- fcoe: remove /etc/fcoe dir if it exists before copying configuration
  (rvykydal)
  Resolves: rhbz#1482512
- Find and remove stale LVM metadata immediately after creating md array.
  (dlehman)
  Resolves: rhbz#1223564
- Add ability to specify vg by uuid for vgremove. (dlehman)
  Related: rhbz#1223564
kkWm5
David Lehman <dlehman@redhat.com> - 0.61.15.70-1[,- Deactivate incomplete VGs along with everything else. (dlehman)
  Resolves: rhbz#1554224
- Work around udev timing issues. (dlehman)
  Resolves: rhbz#1592253
  Resolves: rhbz#1592191
- nvdimm: don't crash on non-block devices (rvykydal)
  Related: rhbz#1280500
- Add NVDIMM detection to "addUdevDiskDevice" (vtrefny)
  Related: rhbz#1558942
- Add 'NVDIMMNamespaceDevice' device representing NVDIMM namespaces (vtrefny)
  Related: rhbz#1558942
- Add a function for identifying NVDIMM namespaces (vtrefny)
  Related: rhbz#1558942
- Add a singleton for NVDIMM namespaces management (vtrefny)
  Resolves: rhbz#1558942
- Backport DependencyGuard from master (vtrefny)
  Related: rhbz#1558942
- Ignore nvdimm devices unless configured in kickstart (rvykydal)
  Related: rhbz#1280500
- Do not ignore nvdimm (pmemX) devices (rvykydal)
  Related: rhbz#1280500
MYq+
Vojtech Trefny <vtrefny@redhat.com> - 0.61.15.72-1["@- Install ndctl when NVDIMMs are used. (dlehman)
  Related: rhbz#1600496
- Escape dots in lvm filter devices (vtrefny)
  Resolves: rhbz#1614039-Xmo
David Lehman <dlehman@redhat.com> - 0.61.15.71-1[Y- Remove dependency on libblockdev-nvdimm (vtrefny)
  Resolves: rhbz#1601557
- Do not try to load NVDIMM plugin on non-x86_64 architectures (vtrefny)
  Related: rhbz#1601557
- Add version to the LUKS format (vtrefny)
  Resolves: rhbz#1607830
""YZqC
Vojtech Trefny <vtrefny@redhat.com> - 0.61.15.73-1\@- Use --yes when calling pvresize (vtrefny)
  Related: rhbz#1657000
- Fix typo in partitioning test cleanup. (dlehman)
  Related: rhbz#1657000
- Remove selinux test that doesn't do anything meaningful. (dlehman)
  Related: rhbz#1657000
- Improve parsing of mdadm detail output. (dlehman)
  Related: rhbz#1657000
- Update btrfs tests to use sufficiently large loop devices. (dlehman)
  Related: rhbz#1657000
- vfat labels apparently cannot contain lower case characters. (dlehman)
  Related: rhbz#1657000
- Check label format regardless of mechanism used to set it. (dlehman)
  Related: rhbz#1657000
- Adapt to presence or absence of python-mock. (dlehman)
  Related: rhbz#1657000
- Fixed KS forcing zerombr onto RO disk (japokorn)
  Resolves: rhbz#1544425
- Tell LVM to wipe cachepool metadata when attaching the cachepool (vtrefny)
  Resolves: rhbz#1643531
- Add dependency on python-six (vtrefny)
  Resolves: rhbz#1647173
r^irw_yyCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-82\-@- Updated fix for CVE-2019-9636
Resolves: rhbz#1689317x^y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-81\@- Security fix for CVE-2019-9636
Resolves: rhbz#1689317p]qq
Vojtech Trefny <vtrefny@redhat.com> - 0.61.15.76-1_{
- edd: Fix UnboundLocalError when trying to close fd in collect_mbrs (vtrefny)
  Related: rhbz#1879920
- Close fd if it fails to read the device (nashok)
  Resolves: rhbz#1879920$\qY
Vojtech Trefny <vtrefny@redhat.com> - 0.61.15.75-1]R@- Always set default key size to 512 bits for ciphers with XTS mode (vtrefny)
  Resolves: rhbz#1716674t[m}
David Lehman <dlehman@redhat.com> - 0.61.15.74-1]@- Handle exceptions raised from parted.Disk ctor. (dlehman)
  Related: rhbz#1677383
- Recommend DASD disk label for disks with an existing DASD label (vtrefny)
  Resolves: rhbz#1677383
gNagyfy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yey}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773ldycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551ycy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xby{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747aywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530v`ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600
7S$7ymy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773llycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yky}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xjy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747iywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530vhywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600(gyYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
i%i7ryw
Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530xqy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680pyiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(oyYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yny}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998
(xyY
Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481ywy}
Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yvy}
Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773luyc
Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yty}
Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xsy{
Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#1704174
{Oh{l~ycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551y}y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388x|y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#1704174g{gk
Lumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917xzy{
Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680yyi
Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494
=Y$=ggkLumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917xy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680yiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(yYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773
`
Y`yy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388x
y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747	ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530vywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600wyyCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-82\-@- Updated fix for CVE-2019-9636
Resolves: rhbz#1689317xy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-81\@- Security fix for CVE-2019-9636
Resolves: rhbz#1689317vywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-94e@- Security fix for CVE-2023-40217
Resolves: RHEL-9615
7o7xy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530vywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600(yYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998y
y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551
7l70yiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(yYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388
eL_eyy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530xy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#1918168bR8RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{8m8n8p#8q+8r28s:8tA8uI8vP8wX8x_8yg8zn8{v8|}8}8~888!8(8/868=8C8I8O8S8V8W8Y8Z8_8f8m8r8x8~888888%8+828:8B8H8N8T8W8Z8[8\8]8`8c8d8e8f8i8l8m8n8o8r8u8v8w8x8{8~8888888	8
8‚
8Â8Ă8ł8Ƃ8ǂ8Ȃ8ʂ8˂!8̂$8͂'8΂*8ς-8Ђ.8т/8҂18ӂ3

er+V:eD
ba60b418779a0e59ca05c44a8a4e59cf92572aec1f631f59c0e2f6cdc8e7d1faD
c105b1034aff6f1bd9548d1cbb3a57a4f09c0231af2d0d033fcce3129be8f9beD
d2ad19a42ac73b25413d43fb03cf20d85cde9e294f4a5948192ea0c673669777D
4b286d1b4cb3c5b51e8b4cc94f6e08beb1728d48f042e99fb51808ba50156970D
0fb81dae84cc52ddf4eb6a080d15e4a750ae48a9057d60e0322152493282eab8D
a7053f493f8ef154d0522e27764a50fa296c0f260992b84a51066efb0c8e8138D
9988a58fd1793b7bc5fef2c748a853a2c83650e825e9d524d12cccb139f1068cD
0eaade45e4faa7e8e8b18e0ab2d01b531ee0b40d37435cff287a385b544dea75D
49fd4de23b8c381fa2c7fade2fcd21a022bd86e95b20a8657eacf9b0f27664d1D
3d130588e8e704895aa41cc1d3a57139effbcdabe57ea04b561e8d3b1d252e41D
237bcee37560d0ebf83c164ac3467d48d1c0e37558d2608e16c324a417061e16D
d26cb8a2b0d5538a5634e8042449259bf4e95598e113a4edfad93ec1ac17e831D
179d2c236a9c0fd2a6c44145f3d47c793b7450b2e9967fb4caa8fb636c2090f7
>S7>y%y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388x$y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#1704174g#gkLumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917x"y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680!yiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494( yYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
88x+y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680*yiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494()yYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481y(y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998y'y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773l&ycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551
dl2a{Eric Garver <egarver@redhat.com> - 0.6.3-7]- fix: Revert "ebtables: drop support for broute table"r1aEric Garver <egarver@redhat.com> - 0.6.3-6]nU- fix: direct: removeRules() not removing all rules in chaind0akEric Garver <egarver@redhat.com> - 0.6.3-5]QT- doc: add --default-config and --system-configr/aEric Garver <egarver@redhat.com> - 0.6.3-4]QT- fix: guarantee zone source dispatch is sorted by zone name<.aEric Garver <egarver@redhat.com> - 0.6.3-3]>- backport recent upstream stable fixes
- backport fix --remove-rules deleting all direct rules
- backport fix unable to delete rich rule forward-port
- backport fix forward-port for external zone hijacking internal zone
- backport fix testsuite iptables lockingv-ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-94e@- Security fix for CVE-2023-40217
Resolves: RHEL-9615g,gkLumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917
-9_r:aEric Garver <egarver@redhat.com> - 0.6.3-6]nU- fix: direct: removeRules() not removing all rules in chaind9akEric Garver <egarver@redhat.com> - 0.6.3-5]QT- doc: add --default-config and --system-configr8aEric Garver <egarver@redhat.com> - 0.6.3-4]QT- fix: guarantee zone source dispatch is sorted by zone name`7caEric Garver <egarver@redhat.com> - 0.6.3-12_Wr@- fix(zone): cache rule_str for rich rulesa6ccEric Garver <egarver@redhat.com> - 0.6.3-11^@- feat(service): add RH-Satellite-6-Capsule
5c3Eric Garver <egarver@redhat.com> - 0.6.3-10^- fix: add logrotate policy
- fix: checkIP6: strip leading/trailing square bracketsh4asEric Garver <egarver@redhat.com> - 0.6.3-9^9\- fix: firewalld not falling back to interface zonec3aiEric Garver <egarver@redhat.com> - 0.6.3-8]X- fix: failure to load modules no longer fatal
).eVBs=Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.2S- Resolves: rhbz#1125544nAc}Eric Garver <egarver@redhat.com> - 0.6.3-13`x*- doc: clarify --set-target values "default" vs "reject"`@caEric Garver <egarver@redhat.com> - 0.6.3-12_Wr@- fix(zone): cache rule_str for rich rulesa?ccEric Garver <egarver@redhat.com> - 0.6.3-11^@- feat(service): add RH-Satellite-6-Capsule
>c3Eric Garver <egarver@redhat.com> - 0.6.3-10^- fix: add logrotate policy
- fix: checkIP6: strip leading/trailing square bracketsh=asEric Garver <egarver@redhat.com> - 0.6.3-9^9\- fix: firewalld not falling back to interface zonec<aiEric Garver <egarver@redhat.com> - 0.6.3-8]X- fix: failure to load modules no longer fatall;a{Eric Garver <egarver@redhat.com> - 0.6.3-7]- fix: Revert "ebtables: drop support for broute table"
kgoHsoRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$GsWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.BFsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056nEsmRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
Ds)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992Cs/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056
\5nNsmRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
Ms)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992Ls/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056Ku;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500JuRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{IsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983
y9yTu;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500SuRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{RsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983oQsoRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$PsWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.BOsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056
s
Wo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTVo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]UuRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.12a@- Limit recursion in ri-records (CVE-2021-3622)
  resolves: rhbz#1976193
2ZowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|YoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tXo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y[oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A\oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-]omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
`o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target_qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down^oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2cowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|boAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tao{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YdoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AeoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-fomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?iq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)hqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downgoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2lowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|koAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tjo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YmoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AnoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-oomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?rq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downpoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2uowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|toAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hsqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YvoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AwoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-xomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?{q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)zqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downyoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2~owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|}q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h|qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A	oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-
omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?
q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.a}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]

er+V:eD*
c8476e1d935321320f812a72c05a7442201d6f34050996100637f18917d65923D)
a46868c4f685242ca769589626c8729cd89edd8240128f8b329e42dbf0398598D(
24a92c5b29a507c8439dd16dba779ab76d6b93fb7f92021e42f3de1dcdde9308D'
00c48e4de2e435d25917e5b12f697e6b79435fb251862569482e3c31793da0f8D&
d06a6708c5a849908340ed5c521556ec87aa647c040dfcefe01d9e5ef19ddcbaD%
06925f8c06ddc4e973f5d0c4eb2ea60c2c099d9608f354cf74311a817b75e734D$
714b86985ff8c757c1d759dc240539eb7226c4445ee4b6ed010da90d5449c6a6D#
82386943e7fd9af89f6c5d8dcb1845c1484cf6a8e11a055c062e3c11deb5110cD"
9db782d6307662cc280b48dbb9d5908c853c6f93c0175937ebbebb1942d0dbf1D!
ca696a4355291a8491772d196b5e4adac8a368af8fdbace8e9c9f75724d2e4b4D 
9750748b6d2332b552e8a31ec27de32bd9783d10d32bb22d09b4a112c4f25e2cD
bfa63f078bde4ea375db5cc30abe54fca1f2adb2bd5da3b8160c848844e31770D
d13e07cfe07df702ed4d93300184aab0f5cef8ffabf3d2182655dfd182050683
Tta	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)asAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yaAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
P!g;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_ c]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux$gAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p#g{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)"g'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-'isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}&iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..%gwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT*o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c)k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex(i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|-oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t,o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
+o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2.owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y/oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nx1i	 Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-0is Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
T3o; Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c2k] Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|6o Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t5o{ Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
4o' Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
27ow Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y8oE Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:x:i	!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationA9o Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
T<o;!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c;k]!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|?o!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t>o{!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
=o'!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2@ow!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YAoE!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ABo!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NTDkA"Tomas Mlcoch <tmlcoch at redhat.com> - 1.7.11-2T- Make tests port agnostic-Com!Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
tFk"Tomas Mlcoch <tmlcoch at redhat.com> - 1.7.13-1T7- Fix ABI compatibility (RhBug: 1185180)
- fastestmirror: Add LRO_FASTESTMIRRORTIMEOUT option
- downloader: Move broken mirror at the end of the list of mirrors (RhBug: 1183998)
- Make building tests and docs optional
- librepo: Don't download remote mirrorlist/metalink when LRO_LOCAL is specified (Resolves #41)iEki"Tomas Mlcoch <tmlcoch at redhat.com> - 1.7.12-1T@- downloader: Allow max one resume + nicer message if xattr cannot be set (RhBug: 1130685)
- downloader: Resume only files that were originaly downloaded by Librepo (RhBug: 1130685)
- downloader: Show also calculated checksums in error message about bad checksum
- Python: Return all strings in unicode
aajHkm"Tomas Mlcoch <tmlcoch at redhat.com> - 1.7.14-2TA- compat: fix ck_assert_msg() segfault in rhel-7,Gko"Tomas Mlcoch <tmlcoch at redhat.com> - 1.7.14-1T@- tests: Use g_assert_cmpuint instead of ck_assert_uint_eq (Pullrequest #43)
- Add LRO_OFFLINE
- Python: Handle: Raise ValueError instead of TypeError when an unknown option is specified
- Python: Result: Use ValueError instead of TypeError when an unknown option value is specified
- Add LR_VERSION constant with version string
- python: Import contants from C librepo module in a loop
- repoconf: Add support for failover and skip_if_unavailable options
- handle: Change of LRO_LOCAL causes invalidation of internal mirrorlist (related to RhBug: 1188600)
- Load local mirrorlists when LRO_LOCAL is on (related to RhBug: 1188600)
- util: Add lr_is_local_path()
- New module repoconf for reading *.repo files
- Add LRO_HTTPHEADER option (RhBug: 1181123)
JgC"Colin Walters <walters@redhat.com> - 1.7.15-2UQ@- Disable tests and drop python-flask build dependency on RHEL7, as
  it is not in the coresIk}"Tomas Mlcoch <tmlcoch at redhat.com> - 1.7.15-1U-@- Do not inlude header in the body output (RhBug: 1207685)
- metalink: Proper error handling
- New LRR_RPMMD_* contants
- Support for client certificates
- Use 'metadata in the rpm-md format' instead of 'yum metadata' (Issue #51)
- CMakeLists.txt: do not check for CXX
- build: Use solely pkg-config to find glib
..MKg5"Colin Walters <tmlcoch@redhat.com> - 1.7.16-1UhT- Add LRI_LOWSPEEDTIME and LRI_LOWSPEEDLIMIT
- downloader: Don't consider CURLE_RECV_ERROR and CURLE_SEND_ERROR as fatal errors (RhBug: 1219817)
- test_repoconf: Fix SIGSEGV in repoconf_assert_na (RhBug: 1222471)
- repoconf: Proper handling of gint64 and guint64 types
- build: Be compatible with cmake 2.8
- handle: Do not free temporary error msg if there is no one (RhBug: 1219822)
- utils/make_rpm.sh: Accept rpmbuild options as second argument (Issue #49)
- Python: call lr_global_init() during module initialization
- Add global function log_set_file that allow user to set a file where logs will be written (Issue #53)
- util: Honor RFC 3986 (Issue #55)
JJiM]y"Ales Matej <amatej@redhat.com> - 1.8.1-8_5+@- Validate paths read from repomd.xml (RhBug: 1866500)DL_+"Marek Blaha <mblaha@redhat.com> - 1.8.1-1[o- Add yumrecord substitution mechanism (mluscon)
- Fix a memory leak in signature verification (cwalters)
- Add new option LRO_FTPUSEEPSV
- downloader prepare_next_transfer(): simplify long line
- downloader prepare_next_transfer(): add missing error check
- downloader prepare_next_transfer(): cleanup error path
- downloader prepare_next_transfer() - fix memory leak on error path (Alan Jenkins)
- handle: Don't use proxy cache for downloads of metalink/mirrorlist
- handle: Don't set CURLOPT_HTTPHEADER into curl handle immediately when specified
- downloader: Implement logic for no_cache param in LrDownloadTarget (RhBug: 1297762)
- Add no_cache param to LrDownloadTarget and lr_downloadtarget_new()
- New test: always try to download from the fastest mirror (Alexander Todorov)
j	WjlTyc#Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551ySy}#Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xRy{#Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747Qyw#Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530vPyw#Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600wOyy#Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-82\-@- Updated fix for CVE-2019-9636
Resolves: rhbz#1689317xNy{#Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-81\@- Security fix for CVE-2019-9636
Resolves: rhbz#1689317
,Yb,7[yw$Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530vZyw$Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600wYyy$Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-82\-@- Updated fix for CVE-2019-9636
Resolves: rhbz#1689317xXy{$Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-81\@- Security fix for CVE-2019-9636
Resolves: rhbz#1689317(WyY#Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yVy}#Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yUy}#Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773
vvvbyw%Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600(ayY$Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481y`y}$Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998y_y}$Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773l^yc$Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551y]y}$Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388x\y{$Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#1704174
4DK^4(iyY%Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yhy}%Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998ygy}%Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lfyc%Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yey}%Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xdy{%Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747cyw%Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530
 O yoy}&Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xny{&Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747myw&Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530vlyw&Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600xky{%Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680jyi%Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494
88xuy{&Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680tyi&Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(syY&Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yry}&Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yqy}&Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lpyc&Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551
4DK^4(|yY'Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481y{y}'Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yzy}'Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lyyc'Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yxy}'Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xwy{'Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747vyw'Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530
/O(/yy}(Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xy{(Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747yw(Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530ggk'Lumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917x~y{'Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680}yi'Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494
88xy{(Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680yi(Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(yY(Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yy}(Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yy}(Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lyc(Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551
,2(yY)Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yy})Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998y
y})Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lyc)Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yy})Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388x
y{)Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#1704174g	gk(Lumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917
qOjqyy}*Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xy{*Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#1704174vyw)Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-94e@- Security fix for CVE-2023-40217
Resolves: RHEL-9615ggk)Lumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917xy{)Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680yi)Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494
88xy{*Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680yi*Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(yY*Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yy}*Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yy}*Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lyc*Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551
33
o'+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTo;+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]vyw*Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-94e@- Security fix for CVE-2023-40217
Resolves: RHEL-9615ggk*Lumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917

er+V:eD7
ba0ec772d06061df246b8969b37e4815a06dc47d41fc74a28df3a929e7acfd68D6
e4d97a37a80e7bde04e338c95d54a5872ecd63949d6cf626c567ad3c7a83b5b6D5
fd7b7df51401985176a27907f57d0a616ead620f53c6855fee58b0ca86fe8394D4
1211808e31a2f8b4a08003a44553ed8f98d1397772009e18d3edb51ea7c89fefD3
e0907ae58b30e07ab32bd9786cb264f46806e15e1e41ca13375f1a8601a9e283D2
fd61faa3534a72b2293194c7decb752ff356a8de561e126459a7e8d55d0c96ebD1
511bc16b7002a23d4c2365e7a369074e23ce6ac569f14b967ca4c8b20d29400aD0
5f884150b5350047089be49bfa331fcf0d8fbd783b21c01062b4f7a03626fecaD/
0050786ebb1c2b37bb1a4450e340b50786707ce8f2f8f01b356ea66cd305165bD.
161f535137bc7817d8e0950475afcc618e67819ad26590c829257f75ab51211cD-
08d77e2a53f45806fd7b82661a7ef4d17bedadab7f9241768695eafd2d8f6cf0D,
ae963ab8fb2fa512c2b276337b4855a49a8b73abd938e0edfcda3ef8eea4db57D+
a4b2a180e6418f7810ccfa0cbf722ce37a6133dc60adeb0ef64356a61444a32b
2"ow+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|!o+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t o{+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y#oE+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A$o+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-%om+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
(o',Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target'qO+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down&o+Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2+ow,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|*o,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t)o{,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y,oE,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A-o,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-.om,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?1q9,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)0qO,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down/o,Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
24ow-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|3o-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t2o{-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y5oE-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A6o-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-7om-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?:q9-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)9qO-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down8o-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2=ow.Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|<o.Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))h;qa-Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest updatebR9>RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{8Ղ78ւ88ׂ:8؂<8ق?8ڂ@8ۂA8܂B8݂D8ނF8߂H8J8K8M8T8[8b8i8o8u8|8888888"8#8$8%8(8+8,8-8.81848586878:9=9>9?9@9C9F9G9H9	I9
L9O9P9
Q9R9U9X9Z9[9^9a9d9g9i9l9o9r9u9v9w9y9{9 ~9!9"9#9$9%9&9'	9(
9)9*9+9,9-9/9091 94"95$96&97(99*9:,9;/9=0
""Y>oE.Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A?o.Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-@om.Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Cq9.Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)BqO.Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downAo.Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2Fow/Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Eq	.Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hDqa.Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YGoE/Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AHo/Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Iom/Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Lq9/Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)KqO/Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downJo/Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm OqQ/Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Nq	/Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hMqa/Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YPoE0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AQo0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Rom0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Uq90Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)TqO0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downSo0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm XqQ0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Wq	0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hVqa0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
AZo1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=Yq0Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-[om1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?^q91Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)]qO1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down\o1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm aqQ1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|`q	1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h_qa1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.da}2Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenDc}
1Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=bq1Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Ttga	2Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)fas2Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yea2Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pig;2Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_hc]2Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxlg2Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pkg{2Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)jg'2Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-ois3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}ni3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..mgw2Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTro;3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cqk]3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexpi	3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|uo3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tto{3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
so'3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2vow3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YwoE3Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nxyi	4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-xis4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
T{o;4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]czk]4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|~o4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t}o{4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
|o'4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoE4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xi	5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAo4Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
To;5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|o5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2ow5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y	oE5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A
o5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
Nyc6Nathan Scott <nathans@redhat.com> - 4.1.0-5[@- Missing values from short /proc/*/status file reads (BZ 1600262)-om5Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
##`c_6Nathan Scott <nathans@redhat.com> - 4.3.2-4]M`@- Fix a pmdaproc memory leak (BZ 1721107)
- Rebuild with selinux runtime dependency update (BZ 1714101)
- Update selinux-policy to latest upstream (BZs 1699830, 1700989)cU6Nathan Scott <nathans@redhat.com> - 4.3.2-2\!- Rework the pcp-libs ldconfig post-op (BZ 1705362)
- Resolve a QA file permissions diagnostic issueS
cE6Nathan Scott <nathans@redhat.com> - 4.3.2-1\- Numerous fixes in pmlogger daily scripts (BZs 1677848, 1697182, 1579881, 1603143)
- Update PCP selinux policy rules (BZs 1692305, 1695066)
- Adjust spec file /var/run/pcp settings (BZ 1533154)
- Fix pmdaproc kernel process misreporting (BZ 1673250)
- Fix pmdalinux SYSV IPC metric scalability (BZ 1699232)
- Ensure pmdaroot reaps all of its children (BZ 1698517)
- Corrections to python version dependencies (BZ 1676867)
- Fix pcp-atopsar(1) -A (all) option handling (BZ 1673996)
- Update to a more recent PCP bug fix release (BZ 1647308)
Gxe
6Nathan Scott <nathans@redhat.com> - 4.3.2-12^@- Fix pcp-atop dynamic memory initialization issues (BZ 1818710)4c6Nathan Scott <nathans@redhat.com> - 4.3.2-8^@- Fix rpm %post privilege escalation CVEs (BZs 1815249, 1815528)
- Resolve an selinux policy issue with pmlogger (BZ 1792859)5c	6Nathan Scott <nathans@redhat.com> - 4.3.2-7^J@- Fix hugepage metrics in pmdalinux (BZ 1730107)
- Fix NUMA nodes instance domain in pmdalinux (BZ 1730492)
- Several selinux policy fixes (BZs 1749870, 1756252, 1760750)
- Fix pcp-atopsar sample count command line argument (BZ 1764748)
- Fix pcp-atop sigsegv with certain process state changes (BZ 1765641)
- Add pcp-zeroconf pmieconf rule to enable per-thread logging (BZ 1775373)c%6Nathan Scott <nathans@redhat.com> - 4.3.2-6]fl- Improve libpcp corrupt archive handling in multi-archive mode (BZ 1673053)sc6Nathan Scott <nathans@redhat.com> - 4.3.2-5]^- Override tracefs_t presence in selinux-policy (BZ 1714856)
a."a<w7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}
7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]Me76Nathan Scott <nathans@redhat.com> - 4.3.2-13_- Fix pcp-atopsar memory allocation problem with some options (BZ 1857580)
- Fix __pmGetArchiveEnd_ctx sigsegv with corrupt PCP archives (BZ 1878754)
HK}7Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3e7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

tg7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]iQ7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]9.
-W7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
<<K }8Jan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]97Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L7Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}

er+V:eDD
f01aa14c280b18ae6d80cc559938fa75c648eb1537499db7841129684e2be5d9DC
6e01c854832108abd04704caf65fe4bafc23e70ae26e9cf272872718eee16d87DB
2308127baa502197469a17cef0a36622ccd5c528247af648e424284943e73572DA
9308a731a1aba4b9209f5cc4ee3e7f8bd57be5fa213ed219fd59941fb9b092cbD@
4f2b4a6fe32be5906b5f4c7f75b71adcae776bcea3e6698d3694791b316cf542D?
9937fd1ce7c6e05f160cf8f1d278aaa79cfe89f767f8122c9d3a05bf197f736fD>
b8f6f54bce094feadbc5ae893e955b1ec40d9dc16c1497c780f7215a7643291bD=
de3b8490416a13143355e8684c271fdc9f605d2dbf6ff8553f500f049a96f027D<
643e8a5dafaf596ced8be2e0be3e3edb692c0c81871c46db2a2541ee4de4aca2D;
850766245b53884b841d001909aa89898b167cf79a244d26c44c42dd775019c3D:
5c6e935d06978bc962ba371367424881edecc7735e2833f96a64554589179077D9
10d9cd406a9424d6ffedd18a738deca45a4e4eb8b3d7040d57bae575915dce5eD8
ef0aa34944c10f3dbe1446cc6ead8acf304187b1c4cc41baa0b1780ae5441018
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

t"g8Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]i!Q8Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]93
-$W8Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]M#8Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}
&98Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]L%8Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}
1(18Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_f98J'8Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<M*9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}?){8Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
NL,9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.101.1.el7]d@- cifs: fix a buffer leak in smb2_query_symlink (Jay Shin) [2166706]
- kernfs: Improve kernfs_notify() poll notification latency (Ian Kent) [1703180]
- netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (Florian Westphal) [2221720] {CVE-2023-35001}-+W9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.100.1.el7]d- bnxt: count Tx drops (Jamie Bainbridge) [2175062]
- bnxt: make sure xmit_more + errors does not miss doorbells (Jamie Bainbridge) [2175062]
- netfilter: nf_tables: skip deactivated anonymous sets during lookups (Florian Westphal) [2196159] {CVE-2023-32233}
- netfilter: nf_tables: do not allow SET_ID to refer to another table (Florian Westphal) [2196159]
/19Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.104.1.el7]e2k- CI: Remove unused kpet_tree_f9<J.9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.103.1.el7]e#@- net/sched: sch_qfq: account for stab overhead in qfq_enqueue (Davide Caratti) [2225555] {CVE-2023-3611}
- net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg (Davide Caratti) [2225555]
- net/sched: cls_fw: Fix improper refcount update leads to use-after-free (Davide Caratti) [2225639] {CVE-2023-3776}
- redhat: fix to be able to build with rpm 4.19.0 (Denys Vlasenko)-99Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.102.1.el7]ev@- net/sched: cls_u32: Fix reference counter leak leading to overflow (Davide Caratti) [2225486] {CVE-2023-3609}
- NFSv4.1: fix handling of backchannel binding in BIND_CONN_TO_SESSION (Benjamin Coddington) [2219604]amily (Nikolai Kondrashov)
- xen/x86: don't lose event interrupts (Vitaly Kuznetsov) [RHEL-1534]
- Documentation/x86: Fix backwards on/off logic about YMM support (Waiman Long) [2229893] {CVE-2022-40982}
- KVM: Add GDS_NO support to KVM (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Kconfig option for GDS (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add force option to GDS mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- x86/speculation: Add Gather Data Sampling mitigation (Waiman Long) [2229893] {CVE-2022-40982}
- Documentation/ABI: Mention retbleed vulnerability info file for sysfs (Waiman Long) [2229893]
- docs/kernel-parameters: Update descriptions for "mitigations=" param with retbleed (Waiman Long) [2229893]
- x86/speculation: Add missing srbds=off to the mitigations= help text (Waiman Long) [2229893]
- x86: Sync Intel family names & cpu_vuln_blacklist[] with upstream (Waiman Long) [2229893]
<<?0{9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.105.1.el7]eH@- net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
- net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free (Davide Caratti) [2228703] {CVE-2023-4128}
d1E9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
p,p73k9Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]O29Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
P5:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol9A^49:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
9997o:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] pow9Dt6e:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command9Berpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
yy97:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han9FX8-:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}dle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
f:I:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo;:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
o<Y:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q=]:Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
d>E;Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.106.1.el7]ee@- gfs2: Fix quota=quiet oversight (Bob Peterson) [2196280]
- gfs2: Free quota data objects synchronously (Andreas Gruenbacher) [2196280]
- gfs2: Fix initial quota data refcount (Andreas Gruenbacher) [2196280]
- gfs2: Factor out duplicate quota data disposal code (Andreas Gruenbacher) [2196280]
- gfs2: Use gfs2_qd_dispose in gfs2_quota_cleanup (Andreas Gruenbacher) [2196280]
- gfs2: Fix wrong quota shrinker return value (Andreas Gruenbacher) [2196280]
- gfs2: ignore negated quota changes (Bob Peterson) [2196280]
- gfs2: Introduce new quota=quiet mount option (Bob Peterson) [2196280]
- gfs2: Add quota_change type (Bob Peterson) [2196280]
- gfs2: Rename sd_{ glock => kill }_wait (Andreas Gruenbacher) [2196280]
- gfs2: Wake up when sd_glock_disposal becomes zero (Alexander Aring) [2196280]
o,po|Au;Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]7@k;Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.108.1.el7]e- net: usb: ax88179_178a: fix failed operations during ax88179_reset (Jose Ignacio Tornos Martinez) [RHEL-6302]O?;Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.107.1.el7]ez@- netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c (Phil Sutter) [RHEL-8433] {CVE-2023-42753}
Y}Dw;Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]BC;Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"BA;Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]
  ?G{;Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.2.el7]ef@- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}4Fe;Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^E9;Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
XBJ<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}"IA<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]|Hu<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.109.1.el7]e@- x86/speculation: Mark all Skylake CPUs as vulnerable to GDS (Waiman Long) [RHEL-17703]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (Oleksandr Natalenko) [2224973]
- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (Oleksandr Natalenko) [2224973]
}Kw<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]
4Me<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^L9<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bOA<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~Ny<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
%n%"RA=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.110.1.el7]e- gfs2: Fix glock recursion on withdraw during recovery (Andreas Gruenbacher) [RHEL-17223]Q7<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]P<Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens9S
}Tw=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.112.1.el7]e@- net: sched: sch_qfq: Use non-work-conserving warning handler (Davide Caratti) [RHEL-14397]
- net: sched: sch_qfq: Fix UAF in qfq_dequeue() (Davide Caratti) [RHEL-14397] {CVE-2023-4921}
- cpufreq: Initialize policy->kobj while allocating policy (Waiman Long) [2161654]
- net: bonding: fix possible NULL deref in rlb code (Hangbin Liu) [RHEL-17227]
- net: bonding: fix use-after-free after 802.3ad slave unbind (Hangbin Liu) [RHEL-17227]BS=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.111.1.el7]eM@- redhat: rewrite genlog and support Y- tags (Jan Stancek)
- scsi: zfcp: Fix double free of FSF request when qdio send fails (Tobias Huschle) [RHEL-16335]
- fbcon: set_con2fb_map needs to set con2fb_map! (Jocelyn Falempe) [RHEL-1204] {CVE-2023-38409}
4Ve=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.114.1.el7]e- netfilter: nf_tables: reject QUEUE/DROP verdict parameters (Florian Westphal) [RHEL-23500] {CVE-2024-1086}^U9=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.113.1.el7]e@- igb: set max size RX buffer when store bad packet is enabled (Wander Lairson Costa) [RHEL-15181] {CVE-2023-45871}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: Use separate L2CAP LE credit based connection result values (David Marlin) [RHEL-2742] {CVE-2022-42896}
- Bluetooth: L2CAP: Fix L2CAP_CR_SCID_IN_USE value (David Marlin) [RHEL-2742] {CVE-2022-42896}
bXA=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.116.1.el7]eq- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]~Wy=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.115.1.el7]e7@- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]ure inner classes have fsc curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- gfs2: Fix invalid metadata access in punch_hole (Andrew Price) [RHEL-28785]
- vt: vt_ioctl: fix race in VT_RESIZEX (Jay Shin) [RHEL-28639] {CVE-2020-36558}
- selinux: cleanup and consolidate the XFRM alloc/clone/delete/free code (Ondrej Mosnacek) [RHEL-27751]
- bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- bluetooth: Perform careful capability checks in hci_sock_ioctl() (David Marlin) [RHEL-3682] {CVE-2023-2002}
- cifs: fix panic in smb2_reconnect (Jay Shin) [RHEL-26301]
- af_unix: Fix null-ptr-deref in unix_stream_sendpage(). (Guillaume Nault) [RHEL-16144] {CVE-2023-4622}
- NFS: Set the stable writes BDI capability (Benjamin Coddington) [RHEL-22193]
- RDMA/i40iw: Prevent zero-length STAG registration (Kamal Heib) [RHEL-6299] {CVE-2023-25775}
- sched/membarrier: reduce the ability to hammer on sys_membarrier (Wander Lairson Costa) [RHEL-26402] {CVE-2024-26602}
n+[	M=Radomir Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.119.1.el7]f<- PCI: hv: Reinstate wrongfully dropped hv_pcibus_removing state (Vitaly Kuznetsov) [RHEL-22919]Z7=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.118.1.el7]f@- iommu/amd: Fix NULL dereference bug in match_hid_uid (Jerry Snitselaar) [RHEL-8721]Y=Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.117.1.el7]f
- tracing/perf: Fix double put of trace event when init fails (Michael Petlan) [RHEL-18052]
- tracing: Fix race in perf_trace_buf initialization (Michael Petlan) [RHEL-18052]
- net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Davide Caratti) [RHEL-16458] {CVE-2023-4623}
- net/sched: sch_hfsc: Ens9Xdle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/dump: Fix race while processing OPAL dump (Gustavo Duarte) [1873189]
- [powerpc] powernv: opal-dump: Use IRQ_HANDLED instead of numbers in interrupt handler (Gustavo Duarte) [1873189]
- [powerpc] opal_elog: Handle multiple writes to ack attribute (Gustavo Duarte) [1873189]
- [powerpc] powernv/elog: Fix race while processing OPAL error log event (Gustavo Duarte) [1873189]
- [powerpc] powernv Adapt opal-elog and opal-dump to new sysfs_remove_file_self (Gustavo Duarte) [1873189]
- [powerpc] powernv: Fix opal-elog interrupt handler (Gustavo Duarte) [1873189]
- [net] flow_dissector: switch to siphash (Davide Caratti) [1835614] {CVE-2019-18282}
- [fs] xfs: fix boundary test in xfs_attr_shortform_verify (Eric Sandeen) [1875317] {CVE-2020-14385}
- [fs] cifs: make 'nodfs' mount opt a superblock flag (Leif Sahlberg) [1873033]
- [crypto] crypto: authenc - fix parsing key with misaligned rta_len (Herbert Xu) [1846355] {CVE-2020-10769}
\7>Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.7.1.el7]_- [fs] xfs: fix off-by-one in inode alloc block reservation calculation (Brian Foster) [1857203]
- [fs] xfs: fix inode allocation block res calculation precedence (Brian Foster) [1857203]
- [powerpc] powernv/dump: Han9Z
f]I>Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.8.1.el7]_- [kernel] sched/fair: Fix RCU stall upon -ENOMEM in sched_create_group() (Kenneth Yin) [1878000]
- [security] selinux: do not report error on connect(AF_UNSPEC) (Paolo Abeni) [1886305]
- [kernel] timer: Fix lockup in __run_timers() caused by large jiffies/timer_jiffies delta (Waiman Long) [1849716]
- [mm] revert "mm/page_alloc: fix memmap_init_zone pageblock alignment" (Artem Savkov) [1878732]
- [mm] page_alloc: Make paranoid check in move_freepages a VM_BUG_ON (Artem Savkov) [1878732]
- [nvme] rdma: Avoid double freeing of async event data (Gopal Tiwari) [1878950]
- [pci] hv: Fix a timing issue which causes kdump to fail occasionally (Mohammed Gamal) [1846667]
oo^>Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.9.1.el7]_i- [hv] hv: vmbus: Only notify Hyper-V for die events that are oops (Vitaly Kuznetsov) [1868130]
- [uapi] include: do not export changes made to struct ip_ct_sctp (Florian Westphal) [1887975]
- [net] openvswitch: free vport unless register_netdevice() succeeds (Timothy Redaelli) [1869190]
- [net] openvswitch: do not free vport if register_netdevice() is failed (Timothy Redaelli) [1869190]
- [kernel] signals: avoid random wakeups in sigsuspend() (Oleg Nesterov) [1704650]
- [fs] nfs: Fix getxattr kernel panic and memory overflow (Benjamin Coddington) [1880893] {CVE-2020-25212}
o_Y>Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.10.1.el7]_- [md] dm-mirror: provide the merge method (Mikulas Patocka) [1890059]
- [nvme] nvme-rdma: cancel async events before freeing event struct (David Milburn) [1857397]
- [s390] dasd: Use struct_size() helper (Sterling Alexander) [1886477]
- [s390] dasd: fix inability to use DASD with DIAG driver (Sterling Alexander) [1886477]
- [hv] hv_utils: drain the timesync packets on onchannelcallback (Vitaly Kuznetsov) [1884735]
- [hv] hv_utils: return error if host timesysnc update is stale (Vitaly Kuznetsov) [1884735]
- [x86] cpu: Re-apply forced caps every time CPU caps are re-read (Herbert Xu) [1886792]
- [x86] cpu: Factor out application of forced CPU caps (Herbert Xu) [1886792]


q`]>Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.11.1.el7]_- [netdrv] hdlc_ppp: add range checks in ppp_cp_parse_cr() (Guillaume Nault) [1882078] {CVE-2020-25643}
- [fs] ext4: fix potential negative array index in do_split() (Pavel Reichl) [1846164] {CVE-2020-14314}
- [fs] nfsd: apply umask on fs without ACL support ("J. Bruce Fields") [1870215] {CVE-2020-24394}
- [kernel] watchdog/core: Remove the park_in_progress obfuscation (Waiman Long) [1860661]
- [mm] swap_slots: recheck cache->slots_ret under spin_lock_irq() protection (Rafael Aquini) [1862915]
- [netdrv] ethernet: i40e: Set RX_ONLY mode for unicast promiscuous on VLAN (Stefan Assmann) [1845677]
- [infiniband] mlx5: Fix use-after-free in dereg_mr() (Alaa Hleihel) [1880184]
--Rb>Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE9a^a7>Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
,,Oc>Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]
'e1>Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.2.el7]`	l- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]Td#>Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]
AAgs?Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check 9eJfs#?Jan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDis?Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}ohsm?Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjlsc?Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]ks1?Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []js7?Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5n+?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]Fms?Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
ps@Jan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check 9j^o9?Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDrs@Jan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}oqsm@Jan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjusc@Jan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]ts1@Jan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []ss7@Jan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5w+@Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]Fvs@Jan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
^x9@Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]
ww^z7AAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.12.1.el7]_@- [mm] mmap: relax file size limit for regular files (Rafael Aquini) [1855985]
- [mm] mmap: introduce sane default mmap limits (Rafael Aquini) [1855985]
- [of] Move dynamic node fixups out of powerpc and into common code (Laurent Vivier) [1866138]
- [fs] nfs: Fix double-free in filelayout_alloc_commit_info/filelayout_free_lseg (Benjamin Coddington) [1679980]
- [hid] HID: hid-plantronics: Re-resend Update to map button for PTT products (Torez Smith) [1769502]
- [fs] dlm: make posix locks interruptible (Alexander Aring) [1826858]!y?@Augusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.2.el7]_- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}RDEV_REQCNT ioctl (Philipp Rudo) [1896826]
- [block] block/diskstats: more accurate approximation of io_ticks for slow disks (Ming Lei) [1859364]
- [block] block: delete part_round_stats and switch to less precise counting (Ming Lei) [1859364]
- [md] dm: simplify start of block stats accounting for bio-based (Ming Lei) [1859364]
- [block] block/rsxx: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [block] drbd: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [md] md: use generic io stats accounting functions to simplify io stat accounting (Ming Lei) [1859364]
- [nvme] limit number of IO queues on Dell/Kioxia config (Gopal Tiwari) [1883403]
- [netdrv] hv_netvsc: make recording RSS hash depend on feature flag (Mohammed Gamal) [1898280]
- [netdrv] hv_netvsc: record hardware hash in skb (Mohammed Gamal) [1898280]
- [fs] block: Fix use-after-free in blkdev_get() (Ming Lei) [1902414] {CVE-2020-15436}
O|AAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.14.1.el7]_@- [fs] nfsd: fix incorrect umasks ("J. Bruce Fields") [1905208]
- [hv] vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1888979]
- [scsi] qla2xxx: Fix device loss on 4G and older HBAs (Nilesh Javali) [1889311]
- [s390] dasd: Fix zero write for FBA devices (Philipp Rudo) [1896839]
- [net] ipv6: use in6_dev_put in dad timer handler instead of __in6_dev_put (Xin Long) [1809519]R{AAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.13.1.el7]_S- [s390] zcrypt: Fix ZCRYPT_PE9p
?'?[~1AAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [19017979sT}#AAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b?AAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4cAAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}bR9RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{9?39@59C79E99G:9H;9I<9J=9K>9LA9MD9NG9OJ9PK9QM9RO9TR9UT9VV9WX9Y[9[\9\]9]^9^_9_`9`b9bc9ce9dg9fi9gl9hn9ip9kr9lu9mw9nx9oz9q|9r~9t9u9w9x9z9{9}9~99	9
9999999999999999 9!9"9#9$9%9'9)9+9-9/90919294969798999:9<9?9@9A9C9F9G9H9J9L9M
11JAAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11JAAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
AAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend9y
?'?[1BAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [19017979|T#BAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.15.1.el7]_=- [fs] ceph: quota: fix null pointer dereference in quota check (Jeff Layton) [1890386]
- [netdrv] revert "mlx5e: ethtool, Remove unsupported SFP EEPROM high pages query" (Alaa Hleihel) [1896756]
- [kernel] timekeeping_Force_unsigned_clocksource_to_nanoseconds_conversion (Waiman Long) [1890911]
- [kernel] exit: Optimize forget_original_parent() for large thread group exiting (Waiman Long) [1872110]
- [kernel] exit: reparent: call forget_original_parent() under tasklist_lock (Waiman Long) [1872110]
- [kernel] Disable tasklist_waiters when qrwlock is enabled (Waiman Long) [1872110]
- [fs] cifs: handle ERRBaduid for SMB1 (Leif Sahlberg) [1847041]]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b?BAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4cBAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11JBAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11J	BAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]

BAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend9
KK/YBAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|sBAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
`H`[1CAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.16.1.el7]`- [tty] Fix ->pgrp locking in tiocspgrp() (Chris von Recklinghausen) [1908193] {CVE-2020-29661}
- [net] fix struct pid memory leak (Jay Shin) [190179793
aBAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)]
- [hid] Fix assumption that devices have inputs (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: the driver now neeed MEMLESS_FF infrastructure (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Add rumble support for Xbox One S controller (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] microsoft: Convert private data to be a proper struct (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] revert "hid: microsoft: fix invalid rdesc for 3k kbd" (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] input: ignore System Control application usages if not System Controls (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [hid] hid-microsoft: Do the check for the ms usage page per device (Chris von Recklinghausen) [1821870] {CVE-2019-19532}
- [net] net-sysfs: take the rtnl lock when accessing xps_cpus_map and num_tc (Antoine Tenart) [1903819]
- [net] net-sysfs: take the rtnl lock when storing xps_cpus (Antoine Tenart) [1903819]
b?CAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.17.1.el7]`- [x86] kvm: svm: Initialize prev_ga_tag before use ("Dr. David Alan Gilbert") [1909036]
- [scsi] scsi_dh: fix scheduling while atomic and also missing unlock in error path (Mike Snitzer) [1619147]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1908896]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1908896]
- [scsi] target: iscsi: Fix cmd abort fabric stop race (Maurizio Lombardi) [1784540]
- [scsi] target/iscsi: Avoid iscsit_release_commands_from_conn() deadlock (Maurizio Lombardi) [1784540]
- [s390] kernel/uv: handle length extension properly (Claudio Imbrenda) [1899172]
4cCAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.18.1.el7]`- [fs] nfs: Fix security label length not being reset (Dave Wysochanski) [1917504]
- [target] scsi: Fix XCOPY NAA identifier lookup (Maurizio Lombardi) [1900469] {CVE-2020-28374}
- [ipc] sem.c: fully initialize sem_array before making it visible (Vladis Dronov) [1877264]
- [netdrv] geneve: add transport ports in route lookup for geneve (Sabrina Dubroca) [1885144] {CVE-2020-25645}
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1869936] {CVE-2020-14351}
11JCAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.19.1.el7]`"y@- [kernel] watchdog: use nmi registers snapshot in hardlockup handler (Prarit Bhargava) [1916589]
- [nvme] nvmet: allow Keep Alive for Discovery controller (Gopal Tiwari) [1910817]
- [net] netfilter: ctnetlink: add a range check for l3/l4 protonum (Florian Westphal) [1888296] {CVE-2020-25211}
- [net] icmp: randomize the global rate limiter (Antoine Tenart) [1896515] {CVE-2020-25705}
11JCAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.20.1.el7]`.V- [md] Set prev_flush_start and flush_bio in an atomic way (Xiao Ni) [1889372]
- [md] improve variable names in md_flush_request() (Xiao Ni) [1889372]
- [kernel] timer: Fix potential bug in requeue_timers() (Waiman Long) [1914011]
- [x86] kvm: reinstate vendor-agnostic check on SPEC_CTRL cpuid bits (Vitaly Kuznetsov) [1890669]
- [x86] kvm: avoid incorrect writes to host MSR_IA32_SPEC_CTRL (Vitaly Kuznetsov) [1890669]
- [md] dm-mirror: fix a crash if the underlying block device doesn't have merge_bvec_fn (Mikulas Patocka) [1916407]
- [gpu] drm/i915: Fix use-after-free when destroying GEM context (Dave Airlie) [1814731] {CVE-2020-7053} func_buf_lock to readers (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, simplify vt_kdgkbsent (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] keyboard, do not speculate on func_table index (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: fix write/write race in ioctl(KDSKBSENT) handler (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [iommu] amd: return error on real irq alloc failure (Jerry Snitselaar) [1918273]
- [iommu] amd: Set DTE[IntTabLen] to represent 512 IRTEs (Jerry Snitselaar) [1921187]
- [iommu] amd: Increase interrupt remapping table limit to 512 entries (Jerry Snitselaar) [1921187]
- [scsi] lpfc: Fix LUN loss after cable pull (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix NVMe rport deregister and registration during ADISC (Dick Kennedy) [1875961]
- [scsi] lpfc: Fix ADISC reception terminating login state if a NVME target (Dick Kennedy) [1875961]
- [netdrv] i40e: revert "i40e: don't report link up for a VF who hasn't enabled queues" (Stefan Assmann) [1901064]
CAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.21.1.el7]`3- [pinctrl] devicetree: Avoid taking direct reference to device name string (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [pinctrl] Delete an error message (Aristeu Rozanski) [1922902] {CVE-2020-0427}
- [tty] vt: keyboard, reorder user buffer handling in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, rename i to kb_func in vt_do_kdgkb_ioctl (Aristeu Rozanski) [1896775] {CVE-2020-25656}
- [tty] vt: keyboard, extend9
KK/YCAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|sCAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3aCAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
AA:oCAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
KK/YDAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.23.1.el7]`S@- tcm_loop: add WQ_MEM_RECLAIM and flush_work (Maurizio Lombardi) [1925652]
- net/mlx4_en: Handle TX error CQE (Alaa Hleihel) [1925691]
- net/mlx4_en: Avoid scheduling restart task if it is already running (Alaa Hleihel) [1925691]|sDAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.22.1.el7]`KW- mm: do not stall register_shrinker() (Rafael Aquini) [1926043]
- sched/rt: Fix PI handling vs. sched_setscheduler() (Phil Auld) [1928082]
- sched/rt: Simplify pull_rt_task() logic and remove .leaf_rt_rq_list (Phil Auld) [1928082]
- sched: Queue RT tasks to head when prio drops (Phil Auld) [1928082]
- sched/core: Use READ_ONCE()/WRITE_ONCE() in move_queued_task()/task_rq_lock() (Phil Auld) [1928082]
- mmc: block: handle complete_work on separate workqueue (Ming Lei) [1918916]
- tcp: fix to update snd_wl1 in bulk receiver fast path (Vladis Dronov) [1929804]
HH3aDAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.24.1.el7]`\{@- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [1930826] {CVE-2021-27365}
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [1930849] {CVE-2021-27363}
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Chris Leech) [1930807] {CVE-2021-27364}
- redhat: add CI file for kernel-private (Bruno Meneguele)
4A4DAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.26.1.el7]`~@- selinux: fix deadlock in security_set_bools() (Ondrej Mosnacek) [1939091]
- md: fix md io stats accounting broken (Ming Lei) [1927106]
- redhat: Fix realtime_check for -private (Juri Lelli):oDAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.25.1.el7]`u- redhat: Enable CKI RT verification for kernel-private (Juri Lelli)
- redhat: Enable CKI RT verification (Juri Lelli)
- RDMA/ipoib: Remove racy Subnet Manager sendonly join checks (Honggang Li) [1922460]
- net: sched: protect against stack overflow in TC act_mirred (Davide Caratti) [1916682]
- floppy: check_events callback should not return a negative number (Jay Shin) [1928576]
- floppy: fix lock_fdc() signal handling (Jay Shin) [1928576]
- ipv6: clean up anycast when an interface is destroyed (Xin Long) [1917700]
- virtio_net: fix virtnet_open and virtnet_probe competing for try_fill_recv (Laurent Vivier) [1895319]
//	DAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]@{DAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.27.1.el7]`N@- video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (Mohammed Gamal) [1941841]
- Drivers: hv: vmbus: enable VMBus protocol version 5.0 (Mohammed Gamal) [1941841]
- redhat: Add git suffix to realtime_check merge_tree (Juri Lelli)
==>wDAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
 #DAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M!DAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]

er+V:eDQ
f86fdc6c605d339bf653d5faa2de82748934dd460074eeb49f6832f2870c1190DP
10c12fcdffb2b2b7e1abf077db33b288fdffac49a4e0acff89864f7742b7dd65DO
15929d57409b9d810314750e5974d9d4d764c8cb7d06c8a05aa72c3a1e815adeDN
b1723c845eb0bd0f6313d26f5ab756da789229567920d005fec0525735b110a0DM
0709174e0519ec2d79dc3e1545a937fdee842ce5f5048538521cbcf27426440dDL
96fa85d78505fae4e97f91bb1f42605707a0acaa501c968c075924348581046fDK
1bc4e395f855f18adf61d113affcda6539558d534fd9b3ed379bfa03301bb5ddDJ
3a576a2d4c9d495a81817e62770bc36d792d089f36be65e81f5449f4f304415eDI
e0016f8f138d66a274153a7698e46c96dcb464b183d398ffed1911d528dbf7bdDH
d0654dfa758aa2f563a1f6f4f32f87d271d5f810da3218400fc7edc14c9af188DG
1a19777f00999ca9d5a879d29fb67c078a61e7584353514d1ff9875c172b83beDF
b5008882f07f8c6c00a0b544313ead5522d4d71ffce67d2a4c5c59a41e89e091DE
d1779b88b2029c7b3cd102334127e7013a0a71479581fd2f04f0d23bbc8a0463
tt"	EAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.28.1.el7]`7@- i40e: acquire VSI pointer only after VF is initialized (Stefan Assmann) [1886003]
- ACPICA: Store GPE register enable masks upfront (Al Stone) [1883174]
- netfilter: nf_tables: validate NFTA_SET_TABLE parameter (Phil Sutter) [1873171]
- sctp: change to hold/put transport for proto_unreach_timer (Xin Long) [1707184]
==>#wEAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.29.1.el7]`@- drm/i915: warn on guc enable about CVE (Dave Airlie) [1935277] {CVE-2020-12362}
- sched: prevent divide by zero error in scale_rt_power() (Phil Auld) [1910763]
- x86/efi: reset the correct tlb_state in efi_switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Turn off IRQs in switch_mm() (Rafael Aquini) [1837531]
- x86/mm, sched/core: Uninline switch_mm() (Rafael Aquini) [1837531]
- x86/mm: Build arch/x86/mm/tlb.c even on !SMP (Rafael Aquini) [1837531]
- hpsa: fix regression issue for old controllers (Joseph Szczypek) [1830268]
- scsi: hpsa: Correct dev cmds outstanding for retried cmds (Joseph Szczypek) [1830268]
$#EAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.30.1.el7]`- pf: Prohibit alu ops for pointer types not defining ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Add sanity check for upper ptr_limit (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Simplify alu_limit masking for pointer arithmetic (Jiri Olsa) [1942689] {CVE-2020-27170}
- bpf: Fix off-by-one for area size in creating mask to left (Jiri Olsa) [1942689] {CVE-2020-27170}
- netxen_nic: fix MSI/MSI-x interrupts (Tony Camuso) [1894274]
- block: fix use-after-free on cached last_lookup partition (Ming Lei) [1898596]
- mm: reduce struct page_cgroup overhead when page_owner is not enabled (Rafael Aquini) [1948451]
- vt: selection, close sel_buffer race (Chris von Recklinghausen) [1831034] {CVE-2020-8648}
..M%EAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.31.1.el7]`8@- mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (Philipp Rudo) [1917840]
- scsi: qla2xxx: Fix the call trace for flush workqueue (Nilesh Javali) [1937945]
- futex: Handle faults correctly for PI futexes (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Provide and use pi_state_update_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Replace pointless printk in fixup_owner() (Donghai Qiao) [1935108] {CVE-2021-3347}
- futex: Ensure the correct return value from futex_lock_pi() (Donghai Qiao) [1935108] {CVE-2021-3347}
- scsi: qla2xxx: Remove WARN_ON_ONCE in qla2x00_status_cont_entry() (Nilesh Javali) [1933784]
- scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path (Philipp Rudo) [1917839]
- net: netfilter: Avoid deadlock when loading logger backend (Phil Sutter) [1858329]
- net: netfilter: Link nfnetlink into bzImage (Phil Sutter) [1858329]messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+''EAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}H&EAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 9
SzS")?EAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663](}EAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
,,+-EAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.2.el7]`A- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]1*]EAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)messages with link address (Hangbin Liu) [1958339]
- hv_netvsc: remove ndo_poll_controller (Mohammed Gamal) [1953075]
- Fix double free in nvme_trans_log_temperature (Gopal Tiwari) [1946793]
- rcu: Call touch_nmi_watchdog() while printing stall warnings (Artem Savkov) [1924688]
- sched/fair: Use RCU accessors consistently for ->numa_group (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/fair: Don't free p->numa_faults with concurrent readers (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Simplify task_numa_compare() (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Fix task_numa_free() lockdep splat (Rafael Aquini) [1915635] {CVE-2019-20934}
- sched/numa: Move task_numa_free() to __put_task_struct() (Rafael Aquini) [1915635] {CVE-2019-20934}
- [s390] s390/dasd: fix diag 0x250 inline assembly (Philipp Rudo) [1910395]
- vsock/vmci: log once the failed queue pair allocation (Stefano Garzarella) [1892237]
- VMCI: Stop log spew when qp allocation isn't possible (Stefano Garzarella) [1892237]
+-'FAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.33.1.el7]`9@- CI: Disable result checking for realtime check (Veronika Kabatova)
- CI: Explicitly disable result checking for private CI (Veronika Kabatova)
- CI: Rename variable (Veronika Kabatova)
- mm: memcontrol: switch to rcu protection in drain_all_stock() (Waiman Long) [1957719]
- sctp: Don't add the shutdown timer if its already been added (Xin Long) [1953052]
- media: xirlink_cit: add missing descriptor sanity checks (Mark Langsdorf) [1826877] {CVE-2020-11668}H,FAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.32.1.el7]`@- Bluetooth: verify AMP hci_chan before amp_destroy (Gopal Tiwari) [1962532] {CVE-2021-33034}
- net: ipv4: route: Fix sending IGMP 9
SzS"/?FAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663].}FAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]
10]FAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
1FAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
2FAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..24_FAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]3'FAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\6}GAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.34.1.el7]`- futex: remove lockdep_assert_held() in pi_state_update_owner() (Donghai Qiao) [1965495]
- video: hyperv_fb: Add ratelimit on error message (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Increase wait time for VMbus unload (Mohammed Gamal) [1957803]
- Drivers: hv: vmbus: Initialize unload_event statically (Mohammed Gamal) [1957803]
- blk-mq: always allow reserved allocation in hctx_may_queue (Ming Lei) [1926825]
- s390/pci: fix out of bounds access during irq setup (Philipp Rudo) [1917943]
- s390/pci: improve irq number check for msix (Philipp Rudo) [1917943]59FAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
"7?GAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.35.1.el7]`@- CI: Merge configuration (Veronika Kabatova)
- [pci/aer] Work around use-after-free in pcie_do_fatal_recovery() (Al Stone) [1933663]
- [pci/aer] do not invoke error recovery with non-fatal errors (Al Stone) [1933663]
18]GAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.36.1.el7]`@- cipso,calipso: resolve a number of problems with the DOI refcounts (Antoine Tenart) [1967720]
- net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (Alaa Hleihel) [1962406]
- sched/debug: Fix cgroup_path[] serialization (Waiman Long) [1912221]
- sched/debug: Reset watchdog on all CPUs while processing sysrq-t (Waiman Long) [1912221]
- vt: vt_ioctl: fix use-after-free in vt_in_use() (Vladis Dronov) [1872778]
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console (Vladis Dronov) [1872778]
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (Vladis Dronov) [1872778]
- vt: selection, introduce vc_is_sel (Vladis Dronov) [1872778]
- redhat: genspec: generate changelog entries since last release (Augusto Caringi)
9GAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
:GAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2<_GAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499];'GAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\?9GAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]">?GAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]=9GAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
@HAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.37.1.el7]`- bluetooth: eliminate the potential race condition when removing the HCI controller (Gopal Tiwari) [1971457]
- net: Update window_clamp if SOCK_RCVBUF is set (Balazs Nemeth) [1962196]
- bpf, x86: Validate computation of branch displacements for x86-64 (Jiri Olsa) [1947249] {CVE-2021-29154}
- mm: vmalloc: add cond_resched() in __vunmap() (Rafael Aquini) [1896794]
- mm/vmalloc: __vmalloc_area_node(): avoid 32-bit overflow (Rafael Aquini) [1896794]
AHAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.38.1.el7]`]- seq_file: Disallow extremely large seq buffer allocations (Ian Kent) [1975251]
- memcg, slab: Fix incorrect placement of rcu_head in struct memcg_cache_params (Waiman Long) [1951810]
- netfilter: x_tables: Use correct memory barriers. (Phil Sutter) [1949087] {CVE-2021-29650}
- netfilter: nf_nat: don't bug when mapping already exists (Florian Westphal) [1972970]
- netfilter: don't setup nat info for confirmed ct (Florian Westphal) [1972970]
..2C_HAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.40.1.el7]a- redhat: ppc64: CONFIG_RTAS_FILTER (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Fix typo of ibm,open-errinjct in RTAS filter (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- powerpc/rtas: Restrict RTAS requests from userspace (Aristeu Rozanski) [1906443] {CVE-2020-27777}
- IB/mlx5: Fix initializing CQ fragments buffer (Alaa Hleihel) [1962499]B'HAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.39.1.el7]aF- netfilter: x_tables: fix compat match/target pad out-of-bound write (Florian Westphal) [1980489] {CVE-2021-22555}
- Revert "be2net: disable bh with spin_lock in be_process_mcc" (Petr Oros) [1971744]
- futex: futex_requeue can potentially free the pi_state structure twice (Donghai Qiao) [1966856]
- xfs: sync lazy sb accounting on quiesce of read-only mounts (Carlos Maiolino) [1921551]
- scsi: lpfc: Fix crash caused by switch reboot (Dick Kennedy) [1897576]
\F9HAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"E?HAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]D9HAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]
22IG
HAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmHHRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [183489
nnJ9IAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.41.1.el7]aS@- ixgbe: fix warning: sysfs: cannot create duplicate filename (Daniel Vacek) [1915449]iIQHRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
YL9IAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.2.el7]a.- net_sched: cls_route: remove the right filter from hashtable (Ivan Vecera) [1992926]"K?IAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.42.1.el7]a'@- [s390] s390/dasd: fix list corruption of lcu list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix list corruption of pavgroup group list (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: prevent inconsistent LCU device data (Claudio Imbrenda) [1889418]
- [s390] s390/dasd: fix hanging device offline processing (Claudio Imbrenda) [1889418]
22IM
IAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.43.1.el7]a;H- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2 (Mohammed Gamal) [1984128]
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message (Mohammed Gamal) [1984128]
- PCI: hv: Only queue new work items in hv_pci_devices_present() if necessary (Mohammed Gamal) [1984128]
- i40e: improve locking of mac_filter_hash (Stefan Assmann) [1993850]
- i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) [1993850]
- i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) [1993850]
- i40e: Remove scheduling while atomic possibility (Stefan Assmann) [1993850]
- scsi: lpfc: Fix pt2pt discovery on SLI3 HBAs (Dick Kennedy) [1922479]
- qed: Disable "MFW indication via attention" SPAM every 5 minutes (Manish Chopra) [1854544]
- NFS: Fix a performance regression caused by buffered IO locking (Benjamin Coddington) [1995649]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmNIRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [183489
iOQIRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_P=IRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7QmIRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!SAIRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7RmIRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]78]
- DLM: fix conversion deadlock when DLM_LKF_NODLCKWT flag is set (Bob Peterson) [1834878]
- DLM: use CF_CLOSE flag to stop dlm_send correctly (Bob Peterson) [1834878]
- DLM: Reanimate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_recoverd_stop and dlm_recoverd (Bob Peterson) [1834878]
- DLM: close othercon at send/receive error (Bob Peterson) [1834878]
- DLM: retry rcom when dlm_wait_function is timed out. (Bob Peterson) [1834878]
- DLM: fix to use sock_mutex correctly in xxx_accept_from_sock (Bob Peterson) [1834878]
- DLM: fix race condition between dlm_send and dlm_recv (Bob Peterson) [1834878]
- DLM: fix double list_del() (Bob Peterson) [1834878]
- DLM: Eliminate CF_WRITE_PENDING flag (Bob Peterson) [1834878]
- KVM: do not allow mapping valid but non-reference-counted pages (Jon Maloy) [1975511]
- vxlan: check return value of gro_cells_init() (Aristeu Rozanski) [1970618]
- KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow (Jon Maloy) [1988218] {CVE-2021-37576}
mmTJRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.44.1.el7]aHw- fs: dlm: change handling of reconnects (Bob Peterson) [1834878]
- DLM: fix NULL pointer dereference in send_to_sock() (Bob Peterson) [1834878]
- DLM: fix to reschedule rwork (Bob Peterson) [1834878]
- DLM: fix to use sk_callback_lock correctly (Bob Peterson) [1834878]
- DLM: fix overflow dlm_cb_seq (Bob Peterson) [183489
iUQJRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.45.1.el7]aM- CI: handle RT branches in a single config (Veronika Kabatova)
- CI: Drop private CI config (Veronika Kabatova)
- CI: extend template use (Veronika Kabatova)
- mm: page_counter: mitigate consequences of a page_counter underflow (Scott Wood) [2000973]
- KVM: nSVM: always intercept VMLOAD/VMSAVE when nested(CVE-2021-3656) (Jon Maloy) [1985425] {CVE-2021-3656}
- KVM: x86: Update vCPU's hv_clock before back to guest when tsc_offset is adjusted (Marcelo Tosatti) [1991856]
- KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653) (Jon Maloy) [1985408] {CVE-2021-3653}
- scsi: qedf: Initiate cleanup for ELS commands as well (Nilesh Javali) [1982702]
_V=JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.46.1.el7]a^@- RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix locking for ctx->events_reported (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Fix the locking of ctx->file (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/cma: Add missing locking to rdma_accept() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Add missing locking around rdma_leave_multicast() (Kamal Heib) [1978075] {CVE-2020-36385}
- RDMA/ucma: Put a lock around every call to the rdma_cm layer (Kamal Heib) [1978075] {CVE-2020-36385}
- nvme-pci: Unblock reset_work on IO failure (Gopal Tiwari) [1981610]
- nvme-pci: Don't disable on timeout in reset state (Gopal Tiwari) [1981610]
- nvme-pci: shutdown on timeout during deletion (Gopal Tiwari) [1981610]
DD7WmJRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.47.1.el7]ay?@- PCI: hv: Fix sleep while in non-sleep context when removing child devices from the bus (Mohammed Gamal) [1948961]
- PCI: hv: Remove bus device removal unused refcount/functions (Mohammed Gamal) [1948961]
- PCI: hv: Fix a race condition when removing the device (Mohammed Gamal) [1948961]
- scsi: qla2xxx: Fix use after free in eh_abort path (Nilesh Javali) [1899599]
!YAJRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.49.1.el7]ab- NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [2007465]7XmJRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.48.1.el7]ay- scsi: qedf: Add check to synchronize abort and flush (Nilesh Javali) [1941766]
- scsi: ibmvfc: Reinit target retries (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid move login if fast fail is enabled (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Handle move login failure (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Avoid link down on FS9100 canister reboot (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: don't check for failure from mempool_alloc() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (Desnes A. Nunes do Rosario) [1882627]
- scsi: ibmvfc: fix misdefined reserved field in ibmvfc_fcp_rsp_info (Desnes A. Nunes do Rosario) [1882627]
pepp[_JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]Z+JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}
!^+KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.50.1.el7]a@@- tcp: grow window for OOO packets only for SACK flows (Guillaume Nault) [1990665]
- scsi: mpt3sas: Fix unlock imbalance (Tomas Henzl) [2006536]
- pci-hyperv: Fix setting CPU affinity on Azure (Vitaly Kuznetsov) [2019272]
- media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() (Lucas Zampieri) [1956471] {CVE-2021-42739}n][JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig9ŃZ\3JRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]9et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush 9if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r9eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
,na[KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig9ʃZ`3KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.52.1.el7]a@- acpi-cpufreq: Honor _PSD table setting on new AMD CPUs (David Arcari) [2019588]
- x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (David Arcari) [2019218]
- x86/cpu/AMD: Fix erratum 1076 (CPB bit) (David Arcari) [2019218]
- i40e: Fix the conditional for i40e_vc_validate_vqs_bitmaps (Stefan Assmann) [1977246]
- i40e: Fix virtchnl_queue_select bitmap validation (Stefan Assmann) [1977246]p__KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.51.1.el7]a)@- mm, fs: Fix do_generic_file_read() error return (Carlos Maiolino) [2020857]
- perf/core: Fix a memory leak in perf_event_parse_addr_filter() (Michael Petlan) [1901932]9et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush 9if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r9eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
cKRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609ςb}KRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?eKRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<dwKRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
"Q"is1LJan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []hs7LJan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]%gIKRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]fKRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}
FksLJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]jjscLJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]
l+LAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.1.1.el7]_R,@- [net] netfilter: conntrack: allow sctp hearbeat after connection re-use (Florian Westphal) [1869751]
- [scsi] scsi: ses: don't ask for diagnostic pages repeatedly during probe (Maurizio Lombardi) [1855324]
PnLAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.3.1.el7]_p~- [net] net-sysfs: Call dev_hol9Յ^m9LAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.2.1.el7]_h- [edac] EDAC/i10nm: Update driver to support different bus number config register offsets (Aristeu Rozanski) [1840276]
- [edac] EDAC, {skx, i10nm}: Make some configurations CPU model specific (Aristeu Rozanski) [1840276]
- [net] test nouarg before dereferencing zerocopy pointers (Patrick Talbert) [1862273]
- [net] packet: copy user buffers before orphan or clone (Patrick Talbert) [1862273]
- [netdrv] net/mlx5e: Fix deallocation of non-fully init encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Allow concurrent creation of encap entries (Alaa Hleihel) [1874101]
- [netdrv] net/mlx5e: Protect encap hash table with mutex (Alaa Hleihel) [1874101]d always in rx_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: Call dev_hold always in netdev_queue_add_kobject (Hangbin Liu) [1846454] {CVE-2019-20811}
- [net] net-sysfs: call dev_hold if kobject_init_and_add success (Hangbin Liu) [1846454] {CVE-2019-20811}
- [netdrv] macvlan: Change status when lower device goes down (Hangbin Liu) [1848950]
- [netdrv] macvlan: make operstate and carrier more accurate (Hangbin Liu) [1848950]
- [infiniband] RDMA/ipoib: Fix ABBA deadlock with ipoib_reap_ah() (Kamal Heib) [1858707]
- [infiniband] RDMA/ipoib: Return void from ipoib_ib_dev_stop() (Kamal Heib) [1858707]
- [net] tcp: limit sk_write_qlen based on sndbuf size (Florian Westphal) [1847765]
- [netdrv] net/mlx5e: Modify uplink state on interface up/down (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Disable esw manager vport correctly (Alaa Hleihel) [1733181]
- [netdrv] net/mlx5: E-Switch, Properly refer to host PF vport as other vport (Alaa Hleihel) [1733181]" (Nilesh Javali) [1826127]
- [scsi] scsi: qla2xxx: Fix stale mem access on driver unload (Nilesh Javali) [1826127]
- [scsi] scsi: qedf: Fix crash when MFW calls for protocol stats while function is still probing (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Keep track of num of pending flogi (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix race betwen fipvlan request and response path (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Decrease the LL2 MTU size to 2500 (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Check for module unloading bit before processing link update AEN (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Initiator fails to re-login to switch after link down (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Fix crash during sg_reset (Nilesh Javali) [1836443]
- [scsi] scsi: qedf: Stop sending fipvlan request on unload (Nilesh Javali) [1836443]
- [message] scsi: mptscsih: Fix read sense data size (Tomas Henzl) [1829803]
- [scsi] scsi: megaraid_sas: Clear affinity hint (Tomas Henzl) [1828312]
999poLAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.5.1.el7]_9- [x86] x86/PCI: Mark Intel C620 MROMs as having non-compliant BARs (Myron Stowe) [1849223]
- [kernel] uprobes: Change handle_swbp() to send SIGTRAP with si_code=SI_KERNEL, to fix GDB regression (Oleg Nesterov) [1861396]
- [video] vgacon: Fix for missing check in scrollback handling (Lyude Paul) [1859468] {CVE-2020-14331}
- [pci] hv: Retry PCI bus D0 entry on invalid device state (Mohammed Gamal) [1846667]
- [pci] hv: Fix the PCI HyperV probe failure path to release resource properly (Mohammed Gamal) [1846667]
- [x86] xen: Add call of speculative_store_bypass_ht_init() to PV paths (Vladis Dronov) [1882468]
- [powerpc] pow9؉toeLAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.4.1.el7]_{
- [block] virtio-blk: handle block_device_operations callbacks after hot unplug (Stefan Hajnoczi) [1811893]
- [scsi] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command9erpc/smp: Use nid as fallback for package_id (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add Power9 scheduler topology (Desnes Augusto Nunes do Rosario) [1826306]
- [kernel] sched: Add a new SD_SHARE_POWERDOMAIN for sched_domain (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] sched, powerpc: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] sched, s390: Create a dedicated topology table (Desnes Augusto Nunes do Rosario) [1826306]
- [s390] s390/topology: Remove call to update_cpu_masks() (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Add cpu_l2_cache_map (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Rework CPU topology construction (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc/smp: Use cpu_to_chip_id() to find core siblings (Desnes Augusto Nunes do Rosario) [1826306]
- [powerpc] powerpc, hotplug: Avoid to touch non-existent cpumasks (Desnes Augusto Nunes do Rosario) [1826306]
33nr[MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.53.1.el7]a*@- fuse: fix live lock in fuse_ig9ڄXq-LAugusto Caringi <acaringi@redhat.com> [3.10.0-1160.6.1.el7]_"- [net] netfilter: nf_queue: place bridge physports into queue_entry struct (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: do not release refcouts until nf_reinject is done (Florian Westphal) [1885682]
- [net] netfilter: nf_queue: make nf_queue_entry_release_refs static (Florian Westphal) [1885682]
- [net] bluetooth: l2cap: Fix calling sk_filter on non-socket based channel (Gopal Tiwari) [1888253] {CVE-2020-12351}
- [net] bluetooth: a2mp: Fix not initializing all members (Gopal Tiwari) [1888797] {CVE-2020-12352}9et() (Miklos Szeredi) [1952046]
- fuse: fix bad inode (Miklos Szeredi) [1952046]
- GFS2: Truncate address space mapping when deleting an inode (Bob Peterson) [1364234]
- gfs2: Fix gfs2_testbit to use clone bitmaps (Bob Peterson) [1364234]
- gfs2: clear buf_in_tr when ending a transaction in sweep_bh_for_rgrps (Bob Peterson) [1364234]
- gfs2: Fix oversight in gfs2_ail1_flush (Bob Peterson) [1364234]
- gfs2: Additional information when gfs2_ail1_flush withdraws (Bob Peterson) [1364234]
- gfs2: leaf_dealloc needs to allocate one more revoke (Bob Peterson) [1364234]
- gfs2: allow journal replay to hold sd_log_flush_lock (Bob Peterson) [1364234]
- gfs2: don't allow releasepage to free bd still used for revokes (Bob Peterson) [1364234]
- gfs2: flesh out delayed withdraw for gfs2_log_flush (Bob Peterson) [1364234]
- gfs2: Do proper error checking for go_sync family of glops functions (Bob Peterson) [1364234]
- gfs2: drain the ail2 list after io errors (Bob Peterson) [1364234]
- gfs2: Withdraw in gfs2_ail1_flush 9if write_cache_pages fails (Bob Peterson) [1364234]
- gfs2: Do log_flush in gfs2_ail_empty_gl even if ail list is empty (Bob Peterson) [1364234]
- gfs2: Check for log write errors before telling dlm to unlock (Bob Peterson) [1364234]
- gfs2: Prepare to withdraw as soon as an IO error occurs in log write (Bob Peterson) [1364234]
- gfs2: Issue revokes more intelligently (Bob Peterson) [1364234]
- gfs2: Add verbose option to check_journal_clean (Bob Peterson) [1364234]
- gfs2: fix infinite loop when checking ail item count before go_inval (Bob Peterson) [1364234]
- gfs2: Force withdraw to replay journals and wait for it to finish (Bob Peterson) [1364234]
- gfs2: Allow some glocks to be used during withdraw (Bob Peterson) [1364234]
- gfs2: move check_journal_clean to util.c for future use (Bob Peterson) [1364234]
- gfs2: Ignore dlm recovery requests if gfs2 is withdrawn (Bob Peterson) [1364234]
- gfs2: Only complain the first time an io error occurs in quota or log (Bob Peterson) [1364234]
- gfs2: log error r9eform (Bob Peterson) [1364234]
- gfs2: Rework how rgrp buffer_heads are managed (Bob Peterson) [1364234]
- gfs2: clear ail1 list when gfs2 withdraws (Bob Peterson) [1364234]
- gfs2: Introduce concept of a pending withdraw (Bob Peterson) [1364234]
- gfs2: Return bool from gfs2_assert functions (Bob Peterson) [1364234]
- gfs2: Turn gfs2_consist into void functions (Bob Peterson) [1364234]
- gfs2: Remove usused cluster_wide arguments of gfs2_consist functions (Bob Peterson) [1364234]
- gfs2: Report errors before withdraw (Bob Peterson) [1364234]
- gfs2: Split gfs2_lm_withdraw into two functions (Bob Peterson) [1364234]
- gfs2: Fix incorrect variable name (Bob Peterson) [1364234]
- gfs2: Don't write log headers after file system withdraw (Bob Peterson) [1364234]
- gfs2: clean up iopen glock mess in gfs2_create_inode (Bob Peterson) [1364234]
- gfs2: Close timing window with GLF_INVALIDATE_IN_PROGRESS (Bob Peterson) [1364234]
- gfs2: fix infinite loop in gfs2_ail1_flush on io error (Bob Peterson) [1364234]
- gfs2: Introduce function gfs2_withdrawn (Bob Peterson) [1364234]
- gfs2: replace more printk with calls to fs_info and friends (Bob Peterson) [1364234]
- gfs2: dump fsid when dumping glock problems (Bob Peterson) [1364234]
- gfs2: simplify gfs2_freeze by removing case (Bob Peterson) [1364234]
- gfs2: Rename SDF_SHUTDOWN to SDF_WITHDRAWN (Bob Peterson) [1364234]
- gfs2: Warn when a journal replay overwrites a rgrp with buffers (Bob Peterson) [1364234]
- gfs2: log which portion of the journal is replayed (Bob Peterson) [1364234]
- gfs2: slow the deluge of io error messages (Bob Peterson) [1364234]
- gfs2: Don't withdraw under a spin lock (Bob Peterson) [1364234]
- GFS2: Clear gl_object when deleting an inode in gfs2_delete_inode (Bob Peterson) [1364234]
- gfs2: Use fs_* functions instead of pr_* function where we can (Bob Peterson) [1364234]
- GFS2: Use pr_<level> more consistently (Bob Peterson) [1364234]
b|b
tMRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.55.1.el7]a- SUNRPC: Fix null rpc_clnt dereference in rpc_task_queued tracepoint (Benjamin Coddington) [2039508]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609߂s}MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.54.1.el7]a- block: queue lock must be acquired when iterating over rls (Ming Lei) [2029574]
- Bluetooth: use correct lock to prevent UAF of hdev object (Chris von Recklinghausen) [1968211] {CVE-2021-3573}
- xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Carlos Maiolino) [2034857] {CVE-2021-4155}9]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- net: add READ_ONCE() annotation in __skb_wait_for_more_packets() (Sabrina Dubroca) [2033561]
- efi: Decode IA32/X64 Context Info structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 MS Check structure (Aristeu Rozanski) [1950302]
- efi: Decode additional IA32/X64 Bus Check fields (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Cache, TLB, and Bus Check structures (Aristeu Rozanski) [1950302]
- efi: Decode UEFI-defined IA32/X64 Error Structure GUIDs (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Info Structure (Aristeu Rozanski) [1950302]
- efi: Decode IA32/X64 Processor Error Section (Aristeu Rozanski) [1950302]
- efi: Fix IA32/X64 Processor Error Record definition (Aristeu Rozanski) [1950302]
- HID: core: Sanitize event code and type when mapping input (Aristeu Rozanski) [1920848] {CVE-2020-0465}
?vMRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330}<uwMRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.56.1.el7]a- RDMA/mlx5: Fix access to wrong pointer while performing flush due to error (Kamal Heib) [1984070]
- af_unix: fix garbage collect vs MSG_PEEK (William Zhao) [2031970] {CVE-2021-0920}
- selinux: fix race condition when computing ocontext SIDs (Ondrej Mosnacek) [2040196]
- Bluetooth: fix the erroneous flush_work() order (Chris von Recklinghausen) [1964556] {CVE-2021-3564}
QQ%xIMRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]wMRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\y7MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT9
PP+zUMRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S{%MRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
up%~INRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.59.1.el7]b@- Revert "Merge: Fix tasks stuck in IO waiting for buffer_head lock" (Rado Vrbovsky) [2030609]}NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.58.1.el7]b[@- Bluetooth: fix use-after-free error in lock_sock_nested() (Gopal Tiwari) [2005687]
- drm/vmwgfx: Fix stale file descriptors on failed usercopy (Dave Airlie) [2047597] {CVE-2022-22942}|NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.57.1.el7]ar@- fix regression in "epoll: Keep a reference on files added to the check list" (Carlos Maiolino) [2042760] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Carlos Maiolino) [2042760] {CVE-2020-0466}
- drm/i915: Flush TLBs before releasing backing store (Dave Airlie) [2044319] {CVE-2022-0330} is set (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs, fdtable: Add fget_task helper (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: add fget_many() and fput_many() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs/file.c: __fget() and dup2() atomicity rules (Miklos Szeredi) [2032478] {CVE-2021-4083}
- vfs: Don't let __fdget_pos() get FMODE_PATH files (Miklos Szeredi) [2032478] {CVE-2021-4083}
- get rid of fget_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- sockfd_lookup_light(): switch to fdget^W^Waway from fget_light (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: __fget_light() can use __fget() in slow path (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget_light() and fget_raw_light() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fs: factor out common code in fget() and fget_raw() (Miklos Szeredi) [2032478] {CVE-2021-4083}
- introduce __fcheck_files() to fix rcu_dereference_check_fdtable(), kill rcu_my_thread_group_empty() (Miklos Szeredi) [2032478] {CVE-2021-4083}
\7NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.60.1.el7]b!- svcrdma: Fix leak of svc_rdma_recv_ctxt objects (Benjamin Coddington) [2028740]
- sunrpc: Remove unneeded pointer dereference (Benjamin Coddington) [2028740]
- x86/platform/uv: Add more to secondary CPU kdump info (Frank Ramsay) [2042462]
- [s390] s390/AP: support new dynamic AP bus size limit (Claudio Imbrenda) [1997156]
- CI: Enable baseline realtime checks (Veronika Kabatova)
- CI: Rename pipelines to include release names (Veronika Kabatova)
- RDMA/cma: Do not change route.addr.src_addr.ss_family (Kamal Heib) [2032075] {CVE-2021-4028}
- fget: clarify and improve __fget_files() implementation (Miklos Szeredi) [2032478] {CVE-2021-4083}
- fget: check that the fd still exists after getting a ref to it (Miklos Szeredi) [2032478] {CVE-2021-4083}
- net: Set fput_needed iff FDPUT_FPUT9
PP+UNRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.61.1.el7]b%- x86/efi: reset the correct tlb_state when returning from efi_switch_mm() (Rafael Aquini) [2055587]
((S%NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpMNRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%INRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}NRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77DNRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
((S%ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.62.1.el7]b;- cifs: fix handling of DFS links where we can not access all components (Ronnie Sahlberg) [1937304]
- redhat: kernel.spec: install new kernel boot entry in posttrans, not post (Denys Vlasenko) [1893756]
- [s390] s390/cpumf: Support for CPU Measurement Facility CSVN 7 (Mete Durlu) [2048920]
- dm table: fix iterate_devices based device capability checks (Mike Snitzer) [2054743]
- buffer: eliminate the need to call free_more_memory() in __getblk_slow() (Carlos Maiolino) [2030609]
- buffer: grow_dev_page() should use __GFP_NOFAIL for all cases (Carlos Maiolino) [2030609]
- buffer: have alloc_page_buffers() use __GFP_NOFAIL (Carlos Maiolino) [2030609]
- mm: memcg: do not fail __GFP_NOFAIL charges (Rafael Aquini) [2054345]
- mm: filemap: do not drop action modifier flags from the gfp_mask passed to __add_to_page_cache_locked() (Rafael Aquini) [2054345]
- Added ZSTREAM=yes to makefile (Lucas Zampieri)
pBpM	ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.65.1.el7]bV@- CI: Remove deprecated option (Veronika Kabatova)
- RDMA/core: Fix panic when port_pkey_list isn't initialized (Kamal Heib) [2046571]%IORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.64.1.el7]bM- cgroup-v1: Require capabilities to set release_agent (Waiman Long) [2052162] {CVE-2022-0492}ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.63.1.el7]bDF@- NFSv4: Set the connection timeout to match the lease period (Benjamin Coddington) [2066699]
- SUNRPC: Allow changing of the TCP timeout parameters on the fly (Benjamin Coddington) [2066699]
- SUNRPC: Refactor TCP socket timeout code into a helper function (Benjamin Coddington) [2066699]
- SUNRPC: Remove unused function rpc_get_timeout() (Benjamin Coddington) [2066699]
- kernel/timer: Fix incorrect assertion in requeue_timers() (Waiman Long) [2048502]
77D
ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.66.1.el7]bi0@- net-sysfs: add check for netdevice being present to speed_show (William Zhao) [2055457]
- CI: Drop baseline runs (Veronika Kabatova)
- perf/x86/intel: Add more Icelake CPUIDs (Michael Petlan) [2072317]
- perf vendor events intel: Add Icelake V1.00 event file (Michael Petlan) [2072317]
- perf vendor events intel: Add core event list for Icelake Server (Michael Petlan) [2072317]
%v%LORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]	ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d
ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000])ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]
-ORado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
%v%LPRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.68.1.el7]bk- libceph: fix potential use-after-free on linger ping and resends (Ilya Dryomov) [2088025]
- xfs: use length to balance duplicate bno buffers in perag rb_tree (Brian Foster) [2050464]
- sock: sock_dequeue_err_skb() needs hard irq safety (Kenneth Yin) [2070408]	PRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.67.1.el7]b@- mm/rmap.c: explicitly reset vma->anon_vma in unlink_anon_vmas() (Rafael Aquini) [1824109 2069962]
- mm/rmap.c: don't reuse anon_vma if we just want a copy (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: rb_parent is not necessary in __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: extract __vma_unlink_list() as counterpart for __vma_link_list() (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: __vma_unlink_prev() is not necessary now (Rafael Aquini) [1824109 2069962]
- mm/mmap.c: prev could be retrieved from vma->vm_prev (Rafael Aquini) [1824109 2069962]
d&KPRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
PRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000])PRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.70.1.el7]bx@- perf: Fix sys_perf_event_open() race against self (Michael Petlan) [2087954]-PRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.69.1.el7]b@- mm: memcg: charge memsw as well in __GFP_NOFAIL case (Rafael Aquini) [2082564]
xx#PRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]lWPRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T'PRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 9
3^O$3lWQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&KQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]
QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.71.1.el7]b- netfilter: nf_tables: disallow non-stateful expression in sets earlier (Phil Sutter) [2093000] {CVE-2022-1966}
- netfilter: nf_tables: fix memory leak if expr init fails (Phil Sutter) [2093000]9PRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
ii#QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]bR:SRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{9O9P9Q9S9T9U9V9W9‚Y9Â[9Ă^9ɂa9΂c9Ђe9тi9҂k9ӂl9Ԃn9ׂp9قr9ނt9v9x9y9z9{9~9999999	9
9999999999 9#:&:':):,:.:/:1:4:5:6:8: ::!;:"=:#>:$@:&B:'C:(E:)F:*H:,K:-M:.N:/P:1T:2V:4Z:5^:6a:7d:8f::h:;k:?m:Ao:Br:Cw:D~:E:F
:G:H:I":J):L0:M8:N?:OF:PM:QU:R\cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T'QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for 9
G^G #QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]9QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B#QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]"QRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-238259+!UQRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}9 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV:E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 :CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227:] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}

er+V:eD^
e04dc4c0f21261a4b8f79045ccd056e8127d18e5487b1cb244df94daebd947efD]
6ead86e81280d56c02e90e7af54080a1b332b55814bf405227418471a84c582dD\
248b2b0bfb0de8b031b61088bfef62e0c0553e6fbfbf409774f977e6aa73b58eD[
e3787987f77c2d6216bcd7f8b59f521fa32928443f39660b17f98be3f0a684a0DZ
04aafce3a01a8ef79a286f4b1e46007f4ff2310784c8df59fa21c4b9ef862b84DY
d512375bde1aef7ba436074db5e9c21e9baa01feef514ddc544ada6efd20aa7eDX
ec5c24d5377fe314137f22aa6ce809acee1e0231e7772cd10fcb69dfd3c4bb00DW
0a7bd3f0caab514c1555ed06bde5524b4655f5fdc8b646492ded15867ea9f447DV
b89dfe0d8f7dd4115a1057dd176a0db69c4c6c947cd62369e8f6701a52c637ffDU
b87fbc79faea13909a981784d127aa69be3a440f342f46eb2f0ac3baa4c8fb1aDT
0ebed7ba324c9dd19b4c287a0d21bb0ff3631197a4d341dfff3705451356c18eDS
d81ef905a985548d803b0e6d1f1537c299d7d342e862ba4651ee9ccacb8b23eaDR
9f57641987fd36be4cd3915ab21939f74a4d1c79b1812b0469560179b445fb74
MM&#RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]l%WRRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.73.1.el7]b- qede: Reduce verbosity of ptp tx timestamp (Manish Chopra) [2080646]
- RDMA/cma: Fix unbalanced cm_id reference count during address resolve (Kamal Heib) [2085425]&$KRRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.72.1.el7]b@- sched,perf: Fix periodic timers (Valentin Schneider) [2077346]
- sched: debug: Remove the cfs bandwidth timer_active printout (Valentin Schneider) [2077346]
- sched: Cleanup bandwidth timers (Valentin Schneider) [2077346]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T''RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for :
G^G)#RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147](9RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B,RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]+RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825:	+*URRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}:
 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV:E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 :CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227:
] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
.#SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.74.1.el7]bγ- tracing: Fix bad use of igrab in trace_uprobe.c (Oleg Nesterov) [2096884]L-RRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]cpu_show_srbds() (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enable CPU Fill buffer clearing on idle (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/bugs: Group MDS, TAA & Processor MMIO Stale Data mitigations (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation: Add a common function for MD_CLEAR mitigation update (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Enumerate Processor MMIO Stale Data bug (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- Documentation: Add documentation for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- [s390] s390/zcrypt: use kvmalloc instead of kmalloc for 256k alloc (Mete Durlu) [2072970]
T/'SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.75.1.el7]b֜- xfs: fix up non-directory creation in SGID directories (Andrey Albershteyn) [2089360]
- x86/speculation/mmio: Print SMT warning (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- KVM: x86/speculation: Disable Fill buffer clear within guests (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Reuse SRBDS mitigation for SBDS (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/srbds: Update SRBDS mitigation selection (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- x86/speculation/mmio: Add sysfs reporting for Processor MMIO Stale Data (Rafael Aquini) [2090249] {CVE-2022-21123 CVE-2022-21125 CVE-2022-21166}
- cpu/speculation: Add prototype for :
G^G1#SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.77.1.el7]c@- net/mlx5: Add Fast teardown support (Jay Shin) [2077711]
- net/mlx5: Free IRQs in shutdown path (Jay Shin) [2077711]
- net/mlx5: Change teardown with force mode failure message to warning (Jay Shin) [2077711]
- net/mlx5: Cancel health poll before sending panic teardown command (Jay Shin) [2077711]
- net/mlx5: Add fast unload support in shutdown flow (Jay Shin) [2077711]
- net/mlx5: Expose command polling interface (Jay Shin) [2077711]
- posix-timers: Remove remaining uses of tasklist_lock (Oleg Nesterov) [2115147]
- posix-timers: Use sighand lock instead of tasklist_lock on timer deletion (Oleg Nesterov) [2115147]
- posix-cpu-timers: remove tasklist_lock in posix_cpu_clock_get() (Oleg Nesterov) [2115147]09SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.76.1.el7]b@- sfc: complete the next packet when we receive a timestamp (Íñigo Huguet) [1793280]
P(B4SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]3SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825:+2USRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.78.1.el7]c#- net_sched: cls_route: remove from list when handle is 0 (Davide Caratti) [2121809] {CVE-2022-2588}: CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV:E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 :CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227:] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
L5SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]
&&U6)SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
8TRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.79.1.el7]c,N@- x86/speculation: Add LFENCE to RSB fill sequence (Rafael Aquini) [2115073] {CVE-2022-26373}
- x86/speculation: Protect against userspace-userspace spectreRSB (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825:7SRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}: CVE-2022-29900 CVE-2022-29901}
- x86/speculation: cope with spectre_v2=retpoline cmdline on retbleed-affected Intel CPUs (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- KVM: emulate: do not adjust size of fastop and setcc subroutines (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: fix FASTOP_SIZE when return thunks are enabled (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/speculation: Disable RRSBA behavior (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kexec: Disable RET on kexec (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do not enable IBPB-on-entry when IBPB is not supported (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add Cannon lake to RETBleed affected CPU list (Rafael Aquini) [2090227] {CVE-2022-23816 CV:E-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Enumerate BTC_NO (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/common: Stamp out the stepping madness (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu/amd: Add Spectral Chicken (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Do IBPB fallback check only once (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add retbleed=ibpb (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report Intel retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Enable STIBP for JMP2RET (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Add AMD retbleed= boot parameter (Rafael Aquini) [2090227] {CVE-2022-23816 :CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/bugs: Report AMD retbleed vulnerability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Add magic AMD return-thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Use return-thunk in asm code (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/sev: Avoid using __x86_return_thunk (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vsyscall_emu/64: Don't use RET in vsyscall emulation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix SETcc emulation for return thunks (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86,objtool: Create .return_sites (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Undo return-thunk damage (Rafael Aquini) [2090227:] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/retpoline: Use -mfunction-return (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Move RETPOLINE flags to word 11 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- objtool: Add ELF writing capability (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare asm files for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86: Prepare inline-asm for straight-line-speculation (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Fix fastop function ELF metadata (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/kvm: Move kvm_fastop_exception to .fixup section (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/vdso: Fix vDSO build if a retpoline is emitted (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Combine word 11 and 12 into a new scattered features word (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Carve out CQM features retrieval (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeatures: Re-tabulate the X86_FEATURE definitions (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpufeature: Move processor tracing out of scattered features (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/cpu: Probe CPUID leaf 6 even when cpuid_level == 6 (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
- x86/alternatives: Cleanup DPRINTK macro (Rafael Aquini) [2090227] {CVE-2022-23816 CVE-2022-23825 CVE-2022-29900 CVE-2022-29901}
hhL:TRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]B9TRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.80.1.el7]cAf@- scsi: lpfc: Fix FCP I/O flush functionality for TMF routines (Dick Kennedy) [1969988]
- scsi: lpfc: Fix illegal memory access on Abort IOCBs (Dick Kennedy) [1969988]
- NFS: Fix extra call to dput() in nfs_prime_dcache (Benjamin Coddington) [2117856]
&&U;)TRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
i=QTRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]<TRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@>TRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7@mTRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc:%?1TRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
wwLBURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.81.1.el7]c\- [netdrv] bnxt: don't lock the tx queue from napi poll (Jamie Bainbridge) [2110869]
- [netdrv] bnxt_en: reverse order of TX disable and carrier off (Jamie Bainbridge) [2110869]
- [netdrv] qede: confirm skb is allocated before using (Jamie Bainbridge) [2131145]3AeTRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
&&UC)URado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.82.1.el7]c- net: usb: ax88179_178a: Fix packet receiving (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32 (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- net: usb: ax88179_178a: fix packet alignment padding (Jose Ignacio Tornos Martinez) [2120504] {CVE-2022-2964}
- mm: swap: disable swap_vma_readahead for PPC64 (Rafael Aquini) [2142455]
iEQURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]DURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@FURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7HmURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc:+G1URado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
E)E_K=URado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]J3URado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3IeURado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
iMQVRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.84.1.el7]c@- blk-mq: fix flush-rq race (Ming Lei) [2088029]
- scsi: target: iscsi: Fix a race condition between login_work and the login thread (Maurizio Lombardi) [2154243]LVRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.83.1.el7]cR@- x86/sme: avoid using __x86_return_thunk (Rafael Aquini) [2122158]
- scsi: core: Simplify control flow in scmd_eh_abort_handler() (Ewan D. Milne) [2128337]
- scsi: core: Avoid leaving shost->last_reset with stale value if EH does not run (Ewan D. Milne) [2128337]
- [netdrv] i40e: Fix freeing of uninitialized misc IRQ vector (Jamie Bainbridge) [2129248]
- x86/speculation: Use generic retpoline by default on AMD (Rafael Aquini) [2062165] {CVE-2021-26401}
;;@NVRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.85.1.el7]c0- sctp: do asoc update earlier in sctp_sf_do_dupcook_b (Xin Long) [2054037]
- sctp: do asoc update earlier in sctp_sf_do_dupcook_a (Xin Long) [2054037]
- sctp: handle errors when updating asoc (Xin Long) [2054037]
- sctp: no need to check assoc id before calling sctp_assoc_set_id (Xin Long) [2054037]
- s390/topology: fix warning when disabling cpus (Tobias Huschle) [2071980]
b7PmVRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc:0O1VRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
)ET7VRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_S=VRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]R3VRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3QeVRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]
WWV1WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.86.1.el7]cۥ- openvswitch: fix OOB access in reserve_sfa_size() (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- openvswitch: fix flow actions reallocation (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- gitlab-ci: use CI templates from production branch (Michael Hofmann)
- mm: prevent page_frag_alloc() from corrupting the memory (Rafael Aquini) [2141062]
- mm: Use fixed constant in page_frag_alloc instead of size + 1 (Rafael Aquini) [2141062]
- mm: page_alloc: fix ref bias in page_frag_alloc() for 1-byte allocs (Rafael Aquini) [2141062]
- x86/pat: Pass valid address to sanitize_phys() (Jeff Moyer) [1974485]UVRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]h: fix OOB access in reserve_sfa_size()" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- kvm/emulate: Fix SETcc emulation function offsets with SLS (Vitaly Kuznetsov) [2143438]
- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (Rafael Aquini) [2138620] {CVE-2022-42703}
- mm, rmap: handle anon_vma_prepare() common case inline (Rafael Aquini) [2138620] {CVE-2022-42703}
- proc: proc_skip_spaces() shouldn't think it is working on C strings (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- proc: avoid integer type confusion in get_proc_long (Wander Lairson Costa) [2152565] {CVE-2022-4378}
- scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts (Nilesh Javali) [2092105]
- fs: move S_ISGID stripping into the vfs_*() helpers (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: Add missing umask strip in vfs_tmpfile (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
- fs: add mode_strip_sgid() helper (Andrey Albershteyn) [2159946] {CVE-2018-13405 CVE-2021-4037}
<e_Z=WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]Y3WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.89.1.el7]cU@- usb: mon: make mmapped memory read only (Desnes Nunes) [2161212] {CVE-2022-43750}3XeWRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.88.1.el7]c- KVM: x86: add bit to indicate correct tsc_shift (Marcelo Tosatti) [2152838]
- KVM: x86: rewrite handling of scaled TSC for kvmclock (Marcelo Tosatti) [2152838]
- KVM: x86: rename argument to kvm_set_tsc_khz (Marcelo Tosatti) [2152838]7WmWRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.87.1.el7]c1- Revert "openvswitch: fix flow actions reallocation" (Rado Vrbovsky) [2141780] {CVE-2022-2639}
- Revert "openvswitc:3
_TH<^wWRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}]
WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]\WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556][7WRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]
Hda7XRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.91.1.el7]dBz- target: iscsi: use GFP_NOIO with loopback connections (Maurizio Lombardi) [2181931]_`=XRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.90.1.el7]dV@- NFSv4.1: Fix open stateid recovery (Benjamin Coddington) [2156890]
- NFS: Don't open code clearing of delegation state (Benjamin Coddington) [2156890]3_eWRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
((<dwXRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.94.1.el7]d@- netfilter: nf_tables: deactivate anonymous set from preparation phase (Florian Westphal) [2196159] {CVE-2023-32233}c
XRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]d}@- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
- proc/pagemap: walk page tables under pte lock (Rafael Aquini) [2190338]bXRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.92.1.el7]df@- packet: fix use-after-free in prb_retire_rx_blk_timer_expired() (Florian Westphal) [2182642]
- x86/bugs: Workaround for incorrectly set X86_BUG_RETBLEED under VMware (Waiman Long) [2189556]
HKf}XJan Stancek <jstancek@redhat.com> [3.10.0-1160.96.1.el7]d@- sched/fair: Eliminate bandwidth race between throttling and distribution (Phil Auld) [2180681]
- sched/fair: Fix race between runtime distribution and assignment (Phil Auld) [2180681]
- sched/fair: Don't assign runtime for throttled cfs_rq (Phil Auld) [2180681]3eeXRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.95.1.el7]d@- perf/s390x: Align the register list to what we support (Michael Petlan) [2207745]
- Revert "[tools] s390/perf: add perf register support for floating-point registers" (Michael Petlan) [2207745]
- s390/perf: add perf_regs support and user stack dump (Michael Petlan) [2207745]
- s390/zcrypt: handle new reply code FILTERED_BY_HYPERVISOR (Tobias Huschle) [2212672]
- netfilter: conntrack: connection timeout after re-register (Florian Westphal) [2128262]
- netfilter: conntrack: always store window size un-scaled (Florian Westphal) [2128262]
- netfilter: conntrack: work around exceeded receive window (Florian Westphal) [2128262]
- netfilter: conntrack: avoid misleading 'invalid' in log message (Florian Westphal) [2128262]
- netfilter: remove BUG_ON() after skb_header_pointer() (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: re-init for syn packets only (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options (Florian Westphal) [2128262]
- netfilter: conntrack: re-init state for retransmitted syn-ack (Florian Westphal) [2128262]
- netfilter: conntrack: move synack init code to helper (Florian Westphal) [2128262]
- netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state (Florian Westphal) [2128262]
- netfilter: nf_conntrack_tcp: Fix stack out of bounds when parsing TCP options (Florian Westphal) [2128262]

thgXRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.98.1.el7]d˖- GFS2: gfs2_dir_get_hash_table(): avoiding deferred vfree() is easy here... (Andrew Price) [2190450]
- GFS2: use kvfree() instead of open-coding it (Andrew Price) [2190450]igQXRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.97.1.el7]dg- net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (Davide Caratti) [2216982] {CVE-2023-35788}
- netfilter: conntrack: re-fetch conntrack after insertion (Florian Westphal) [2188190]
- netfilter: conntrack: handle tcp challenge acks during connection reuse (Florian Westphal) [2128262]
- netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst (Florian Westphal) [2128262]
- netfilter: conntrack: remove unneeded indent level (Florian Westphal) [2128262]
- netfilter: conntrack: ignore overly delayed tcp packets (Florian Westphal) [2128262]
- netfilter: conntrack: prepare tcp_in_window for ternary return value (Florian Westphal) [2128262]:9
ksYJan Stancek <jstancek@redhat.com> [3.10.0-1152.el7]^- [nvmem] nvmem: properly handle returned value nvmem_reg_read (Vladis Drono:=	js!YJan Stancek <jstancek@redhat.com> [3.10.0-1151.el7]^W@- [netdrv] qede: Fix multicast mac configuration (Michal Schmidt) [1740064]
- [scsi] sd_dif: avoid incorrect ref_tag errors on 4K devices larger than 2TB (Ewan Milne) [1833528]
- [hid] HID: hiddev: do clean:<MiXRado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.99.1.el7]d@- x86/cpu/amd: Add a Zenbleed fix (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu/amd: Move the errata checking functionality up (Waiman Long) [2226841] {CVE-2023-20593}
- x86/cpu: Restore AMD's DE_CFG MSR after resume (Waiman Long) [2226841] {CVE-2023-20593}up in failure of opening a device (Torez Smith) [1814257] {CVE-2019-19527}
- [hid] HID: hiddev: avoid opening a disconnected device (Torez Smith) [1814257] {CVE-2019-19527}
- [x86] x86: make mul_u64_u64_div_u64() "static inline" (Oleg Nesterov) [1845864]
- [mm] mm: page_isolation: fix potential warning from user (Rafael Aquini) [1845620]
- [s390] s390/mm: correct return value of pmd_pfn (Claudio Imbrenda) [1841106]
- [fs] fs/proc/vmcore.c:mmap_vmcore: skip non-ram pages reported by hypervisors (Lianbo Jiang) [1790799]
- [kernel] kernel/sysctl.c: ignore out-of-range taint bits introduced via kernel.tainted (Rafael Aquini) [1845356]
- [documentation] kernel: add panic_on_taint (Rafael Aquini) [1845356]
- [fs] ext4: Remove unwanted ext4_bread() from ext4_quota_write() (Lukas Czerner) [1845379]
- [scsi] scsi: sg: add sg_remove_request in sg_write ("Ewan D. Milne") [1840699] {CVE-2020-12770}
- [fs] fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (Donghai Qiao) [1832062] {CVE-2020-10732}:>v) [1844409]
- [mailbox] PCC: fix dereference of ERR_PTR (Vladis Dronov) [1844409]
- [kernel] futex: Unlock hb->lock in futex_wait_requeue_pi() error path (Vladis Dronov) [1844409]
- [fs] aio: fix inconsistent ring state (Jeff Moyer) [1845326]
- [vfio] vfio/mdev: make create attribute static (Vladis Dronov) [1837549]
- [vfio] treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Synchronize device create/remove with parent removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid creating sysfs remove file on stale device removal (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Improve the create/remove sequence (Vladis Dronov) [1837549]
- [vfio] treewide: Add SPDX license identifier - Makefile/Kconfig (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid inline get and put parent helpers (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Fix aborting mdev child device removal if one fails (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Follow correct remove sequence (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid masking error code to EBUSY (Vladis Dronov) [1837549]
- [include] vfio/mdev: Drop redundant extern for exported symbols (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Removed unused kref (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Avoid release parent reference during error path (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: Add iommu related member in mdev_device (Vladis Dronov) [1837549]
- [vfio] vfio/mdev: add static modifier to add_mdev_supported_type (Vladis Dronov) [1837549]
- [vfio] vfio: mdev: make a couple of functions and structure vfio_mdev_driver static (Vladis Dronov) [1837549]
- [char] tpm/tpm_tis: Free IRQ if probing fails (David Arcari) [1774698]
- [kernel] audit: fix a memleak caused by auditing load module (Richard Guy Briggs) [1843370]
- [kernel] audit: fix potential null dereference 'context->module.name' (Richard Guy Briggs) [1843370]
- [nvme] nvme: limit number of IO queues on Dell/Samsung config (David Milburn) [1837617]
AAmsYJan Stancek <jstancek@redhat.com> [3.10.0-1154.el7]^@- [fs] gfs2: move privileged user check :@Jls#YJan Stancek <jstancek@redhat.com> [3.10.0-1153.el7]^4- [x86] mm: Fix mremap not considering huge pmd devmap (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm, dax: check for pmd_none() after split_huge_pmd() (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: streamline move_page_tables()'s move_huge_pmd() corner case (Rafael Aquini) [1843437] {CVE-2020-10757}
- [mm] mm: mremap: validate input before taking lock (Rafael Aquini) [1843437] {CVE-2020-10757}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status() (Jarod Wilson) [1844070] {CVE-2020-12654}
- [wireless] mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv() (Jarod Wilson) [1844026] {CVE-2020-12653}
- [net] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 (Florian Westphal) [1845428]to gfs2_quota_lock_check (Robert S Peterson) [1798713]
- [fs] gfs2: Fix problems regarding gfs2_qa_get and _put (Robert S Peterson) [1798713]
- [fs] gfs2: don't call quota_unhold if quotas are not locked (Robert S Peterson) [1798713]
- [fs] gfs2: Remove unnecessary gfs2_qa_{get, put} pairs (Robert S Peterson) [1798713]
- [fs] gfs2: Split gfs2_rsqa_delete into gfs2_rs_delete and gfs2_qa_put (Robert S Peterson) [1798713]
- [fs] gfs2: Change inode qa_data to allow multiple users (Robert S Peterson) [1798713]
- [fs] gfs2: eliminate gfs2_rsqa_alloc in favor of gfs2_qa_alloc (Robert S Peterson) [1798713]
- [fs] gfs2: Switch to list_{first,last}_entry (Robert S Peterson) [1798713]
- [fs] gfs2: Clean up inode initialization and teardown (Robert S Peterson) [1798713]
- [fs] gfs2: Minor gfs2_alloc_inode cleanup (Robert S Peterson) [1798713]
- [fs] gfs2: Fix busy-on-umount in gfs2_atomic_open() (Andrew Price) [1812558]
CCDosYJan Stancek <jstancek@redhat.com> [3.10.0-1156.el7]_X@- [fs] gfs2: Fix regression due to unwanted gfs2_qa_put (Robert S Peterson) [1798713]
- [include] signal: Unfairly acquire tasklist_lock in send_sigio() if irq disabled (Waiman Long) [1838799]
- [fs] signal: Don't take tasklist_lock if PID type is PIDTYPE_PID (Waiman Long) [1838799]
- [vfio] vfio/pci: Fix SR-IOV VF handling with MMIO blocking (Alex Williamson) [1820632] {CVE-2020-12888}onsmYJan Stancek <jstancek@redhat.com> [3.10.0-1155.el7]_- [x86] Revert "x86: respect memory size limiting via mem= parameter" (Joel Savitz) [1851576]
- [mm] Revert "mm/memory_hotplug.c: only respect mem= parameter during boot stage" (Joel Savitz) [1851576]
- [fs] nfsd: only WARN once on unmapped errors ("J. Bruce Fields") [1850430]
- [powerpc] pci/of: Fix OF flags parsing for 64bit BARs (Greg Kurz) [1840114]
- [fs] cifs: fix NULL dereference in match_prepath (Leif Sahlberg) [1759852]
bgbjrscYJan Stancek <jstancek@redhat.com> [3.10.0-1159.el7]_+- [kernel] modsign: Import certificates from optional MokListRT (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Support multiple signatures in verify_pefile_signature (Lenny Szubowicz) [1862840]
- [crypto] crypto/pefile: Tolerate other pefile signatures after first (Lenny Szubowicz) [1862840]qs1YJan Stancek <jstancek@redhat.com> [3.10.0-1158.el7]_A@- [redhat] switch secureboot kernel image signing to release keys (Jan Stancek) []ps7YJan Stancek <jstancek@redhat.com> [3.10.0-1157.el7]_- [fs] signal: Don't send signals to tasks that don't exist (Vladis Dronov) [1856166]
5c]wuIZMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.Xvu?ZDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24ruusZMichal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#1001122Xtu?ZDaniel Mach <dmach@redhat.com> - 2.0.0-13.gitd1c6db8Rk- Mass rebuild 2013-12-27FssYJan Stancek <jstancek@redhat.com> [3.10.0-1160.el7]_;- [kernel] modsign: Add nomokvarconfig kernel parameter (Lenny Szubowicz) [1867857]
- [firmware] modsign: Add support for loading certs from the EFI MOK config table (Lenny Szubowicz) [1867857]
- [kernel] modsign: Move import of MokListRT certs to separate routine (Lenny Szubowicz) [1867857]
- [kernel] modsign: Avoid spurious error message after last MokListRTn (Lenny Szubowicz) [1867857]
ImO\IX~u?[Daniel Mach <dmach@redhat.com> - 2.0.0-13.gitd1c6db8Rk- Mass rebuild 2013-12-272}
WZCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{|
kZCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p{{iZLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&z{SZLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066oyumZMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.xu)ZMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.
).:){
k[Charalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p{i[Lumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&{S[Lumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066oum[Michal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.u)[Michal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]uI[Michal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.Xu?[Daniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24rus[Michal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#1001122
eIwe&
{S\Lumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066oum\Michal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.u)\Michal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]
uI\Michal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.X	u?\Daniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24rus\Michal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#10011222
W[Charalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522

Vd]uI]Michal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.Xu?]Daniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24rus]Michal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#1001122x{y\Lumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592
W\Charalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{
k\Charalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p{i\Lumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532
)mO\)x{y]Lumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592
W]Charalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{
k]Charalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p{i]Lumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&{S]Lumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066oum]Michal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.u)]Michal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.
C={"
k^Charalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p!{i^Lumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532& {S^Lumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066oum^Michal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.u)^Michal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]uI^Michal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.Xu?^Daniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24
IQo)um_Michal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.(u)_Michal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]'uI_Michal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.X&u?_Daniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24x%{y^Lumír Balhar <lbalhar@redhat.com> - 2.0.0-25gitd1c6db8e@- Security fix for CVE-2023-50447
Resolves: RHEL-22239x${y^Lumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592#
W^Charalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522

er+V:eDk
d815a590697b3df0167d56b28753612896111d06c6e033a0694f444261d23d09Dj
b5816382d23e2c39a1010248b904a92618f9140583546a2750585d023b31a97fDi
ec825c7e726b4f918e38b5d16c4713c4f73534bac35c94b116810482f92134c3Dh
137fd6acb013717c21df14d056e3aec78767919094b31181c949789add37ed5cDg
4ebc55a9954ac2afcab8fb9d5afd7de1ac28a66e18e635767c73d22ff0bb53eaDf
ddd375eab5397ba731106d9d1a805e9a2c6aa4e504e7487eea4ff54190770885De
647a613d1c2a1a76e224f9b2858aada971c346c973f46566c503a58ea2958063Dd
b2c1cdb60ecdd165581074138534e1d9c89d29286cfae22235a53418e6994f26Dc
375c6aec9492dfeb3bf49e8ed7cde201a8d10e0a725c713f6131c221f187519aDb
11baa7d4bdd8079b0a48c38698900636641b8648bcc0beed5948a501e512c0a8Da
d14497105b68ae6076141f696ba00d9f42a831aa982b7bbacae503f429464e72D`
4c0b51e89a2551de7942fb433c79d0f9aa1a872daee24a3859ba5e6e51888012D_
f6c5c1dd3e31927fa431f3f886053e4f234ec506a168fc28c7d537f9e6f5e4c9
WUb/WX0u?`Daniel Mach <dmach@redhat.com> - 2.0.0-13.gitd1c6db8Rk- Mass rebuild 2013-12-27x/{y_Lumír Balhar <lbalhar@redhat.com> - 2.0.0-25gitd1c6db8e@- Security fix for CVE-2023-50447
Resolves: RHEL-22239x.{y_Lumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592-
W_Charalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{,
k_Charalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p+{i_Lumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&*{S_Lumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066
).:){8
k`Charalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p7{i`Lumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&6{S`Lumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066o5um`Michal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.4u)`Michal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]3uI`Michal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.X2u?`Daniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24r1us`Michal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#1001122
Iw'o?umaMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.>u)aMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]=uIaMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.X<u?aDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24r;usaMichal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#1001122X:u?aDaniel Mach <dmach@redhat.com> - 2.0.0-13.gitd1c6db8Rk- Mass rebuild 2013-12-2729
W`Charalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522
xUb5x]FuIbMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.XEu?bDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24rDusbMichal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#10011222C
WaCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{B
kaCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527pA{iaLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&@{SaLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066
)mO\)xM{ybLumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592L
WbCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{K
kbCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527pJ{ibLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&I{SbLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066oHumbMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.Gu)bMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.
).:){U
kcCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527pT{icLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&S{ScLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066oRumcMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.Qu)cMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]PuIcMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.XOu?cDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24rNuscMichal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#1001122
_Iq}
_&\{SdLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066o[umdMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.Zu)dMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]YuIdMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.XXu?dDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24xW{ycLumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592V
WcCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522

V^]cuIeMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.Xbu?eDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24xa{ydLumír Balhar <lbalhar@redhat.com> - 2.0.0-25gitd1c6db8e@- Security fix for CVE-2023-50447
Resolves: RHEL-22239x`{ydLumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592_
WdCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{^
kdCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p]{idLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532
)mO\)xj{yeLumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592i
WeCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{h
keCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527pg{ieLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&f{SeLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066oeumeMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.du)eMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.
D(VbD&r{SfLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066oqumfMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.pu)fMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]ouIfMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.Xnu?fDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24rmusfMichal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#1001122Xlu?fDaniel Mach <dmach@redhat.com> - 2.0.0-13.gitd1c6db8Rk- Mass rebuild 2013-12-27xk{yeLumír Balhar <lbalhar@redhat.com> - 2.0.0-25gitd1c6db8e@- Security fix for CVE-2023-50447
Resolves: RHEL-22239

V#ozumgMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.yu)gMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]xuIgMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.Xwu?gDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24rvusgMichal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#10011222u
WfCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{t
kfCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527ps{ifLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532
rUb/r]uIhMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.Xu?hDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24x{ygLumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592~
WgCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{}
kgCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p|{igLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&{{SgLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066
)mO\)x{yhLumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592
WhCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{
khCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p{ihLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&{ShLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066oumhMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.u)hMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.
D(VbD&{SiLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066oumiMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.u)iMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]
uIiMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.Xu?iDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24rusiMichal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#1001122X
u?iDaniel Mach <dmach@redhat.com> - 2.0.0-13.gitd1c6db8Rk- Mass rebuild 2013-12-27x	{yhLumír Balhar <lbalhar@redhat.com> - 2.0.0-25gitd1c6db8e@- Security fix for CVE-2023-50447
Resolves: RHEL-22239

V#oumjMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.u)jMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]uIjMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.Xu?jDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24rusjMichal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#10011222
WiCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{
kiCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p{iiLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532
rUb/r]uIkMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.Xu?kDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24x{yjLumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592
WjCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{
kjCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p{ijLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&{SjLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066
)mO\)x&{ykLumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592%
WkCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{$
kkCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p#{ikLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&"{SkLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066o!umkMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs. u)kMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.
D(VbD&.{SlLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066o-umlMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.,u)lMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]+uIlMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.X*u?lDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24r)uslMichal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#1001122X(u?lDaniel Mach <dmach@redhat.com> - 2.0.0-13.gitd1c6db8Rk- Mass rebuild 2013-12-27x'{ykLumír Balhar <lbalhar@redhat.com> - 2.0.0-25gitd1c6db8e@- Security fix for CVE-2023-50447
Resolves: RHEL-22239

er+V:eDx
5c48f63f55884ffae342bab8da56b7300ef3a1c678ca2fd3ed60b450b739c9d0Dw
64577751243751eedbe850fc528ea04d250e8a953a86f23a1a44bf84dfdd8e77Dv
ea62e68511b809f9becc99bd815384ecd8f52c7abded5c1a0a143ce0c6f07f1eDu
e2a10703222e1811d5a65784d7297dc8909810f2a89b78d6c78a402ba28e7a22Dt
48122d3d4653fe0fc63133e91c130b529db55e9ff1940bca669fbe8d0e04f223Ds
24c85de4433c7d3441a0b4765cbe8e897ea5e9178eca2d1f545940ae96e7f940Dr
22c712c0742c37d17a067192cfa1bcc35a1d96fc1200fdddc0f752ba8df52d72Dq
4808002a70058c1d3b9c495b731f8403aaf27010bc15e1e5a808639ca82489a6Dp
9359973256508b24175ed9887851616fac8f922f2e55231ced8c44ff757ef828Do
f0b50f270ec1c14903fbb91ed28d0134d984399e67c5cab7709b5de27479c361Dn
6388020c7ae6967173c10e44d5542309498d0c339891675e68467cdd71ec93bfDm
587d17ef9061cf41b72bf1d3a0c8b1ef5bd5fd3f8fcb45fcc0b4af9023587f45Dl
f204489e33ce1fbb9eeba9986ed191914338380781d4fef1e6cb0b7256570389

V#o6ummMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.5u)mMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]4uImMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.X3u?mDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24r2usmMichal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#100112221
WlCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{0
klCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p/{ilLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532
rUb/r]=uInMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.X<u?nDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24x;{ymLumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592:
WmCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{9
kmCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p8{imLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&7{SmLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066
)mO\)xD{ynLumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592C
WnCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{B
knCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527pA{inLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&@{SnLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066o?umnMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.>u)nMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.
D(VbD&L{SoLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066oKumoMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.Ju)oMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]IuIoMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.XHu?oDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24rGusoMichal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#1001122XFu?oDaniel Mach <dmach@redhat.com> - 2.0.0-13.gitd1c6db8Rk- Mass rebuild 2013-12-27xE{ynLumír Balhar <lbalhar@redhat.com> - 2.0.0-25gitd1c6db8e@- Security fix for CVE-2023-50447
Resolves: RHEL-22239

V#oTumpMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.Su)pMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.]RuIpMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.XQu?pDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24rPuspMichal Minar <miminar@redhat.com> 2.0.0-14gitd1c6db8R&- Fixed memory corruption.
- Resolves: rhbz#10011222O
WoCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{N
koCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527pM{ioLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532
rUb/r][uIqMichal Minar <miminar@redhat.com> 2.0.0-17gitd1c6db8S?- Wiped out some memory leaks.XZu?qDaniel Mach <dmach@redhat.com> - 2.0.0-15.gitd1c6db8RU- Mass rebuild 2014-01-24xY{ypLumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592X
WpCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{W
kpCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527pV{ipLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&U{SpLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066
)mO\)xb{yqLumír Balhar <lbalhar@redhat.com> - 2.0.0-24gitd1c6db8eR- Security fix for CVE-2023-44271
Resolves: RHEL-154592a
WqCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-23gitd1c6db8bO- Fixup for CVE-2022-22817
- Security fixes for CVE-2022-22815, CVE-2022-22816
Resolves: rhbz#2042522{`
kqCharalampos Stratakis <cstratak@redhat.com> - 2.0.0-22gitd1c6db8a@- Fix for CVE-2022-22817
Resolves: rhbz#2042527p_{iqLumír Balhar <lbalhar@redhat.com> - 2.0.0-21gitd1c6db8^_@- Fix for CVE-2020-5313
Resolves: rhbz#1789532&^{SqLumír Balhar <lbalhar@redhat.com> - 2.0.0-20gitd1c6db8^C- Combined fixes for CVE-2020-5312 and CVE-2019-16865
Resolves: rhbz#1789533
Resolves: rhbz#1774066o]umqMichal Minar <miminar@redhat.com> 2.0.0-19gitd1c6db8T2@- Reenabled webp support on little endian archs.\u)qMichal Minar <miminar@redhat.com> 2.0.0-18gitd1c6db8S- Disabled webp support on ppc64le due to #962091 and #1127230.
- Updated URL.
*e3*irFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.5-7Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildlhqkrToshio Kuratomi <toshio@fedoraproject.org> - 2.5-6P@- Add a dep on python-imaging to process imagesgrFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.5-5P
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildfrFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.5-4On@- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_RebuilderFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.5-3MR- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuilddw
rKonstantin Ryabitsev <icon@fedoraproject.org> - 2.5-2M%- Update to version 2.5 of reportlab.
- Remove tabs in specfile.xc{yqLumír Balhar <lbalhar@redhat.com> - 2.0.0-25gitd1c6db8e@- Security fix for CVE-2023-50447
Resolves: RHEL-22239
1dc1qsFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.5-5P
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildpsFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.5-4On@- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_RebuildosFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.5-3MR- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuildnw
sKonstantin Ryabitsev <icon@fedoraproject.org> - 2.5-2M%- Update to version 2.5 of reportlab.
- Remove tabs in specfile.jm]{rMarek Kasik <mkasik@redhat.com> - 2.5-11ev@- Do not evaluate unichar element
- Resolves: RHEL-7011pl]rMarek Kasik <mkasik@redhat.com> - 2.5-10^@- Do not eval strings passed to toColor
- Resolves: #1788553JkY?rDaniel Mach <dmach@redhat.com> - 2.5-9RU- Mass rebuild 2014-01-24JjY?rDaniel Mach <dmach@redhat.com> - 2.5-8Rk- Mass rebuild 2013-12-27
Z[yZwyw{tMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb63-10Z؄- Add missing patch "tcmu: add control constructor arg"xuKtMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb63-9ZЛ- Support tcmu hw max sectors
- saveconfig: dump control string containing control=value tuplesjw]{sMarek Kasik <mkasik@redhat.com> - 2.5-11ev@- Do not evaluate unichar element
- Resolves: RHEL-7011pv]sMarek Kasik <mkasik@redhat.com> - 2.5-10^@- Do not eval strings passed to toColor
- Resolves: #1788553JuY?sDaniel Mach <dmach@redhat.com> - 2.5-9RU- Mass rebuild 2014-01-24JtY?sDaniel Mach <dmach@redhat.com> - 2.5-8Rk- Mass rebuild 2013-12-27ssFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.5-7Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildlrqksToshio Kuratomi <toshio@fedoraproject.org> - 2.5-6P@- Add a dep on python-imaging to process images
f.6fdq[tMaurizio Lombardi <mlombard@redhat.com> - 2.1.74-1_P- Rebase to the latest upstream versiondq[tMaurizio Lombardi <mlombard@redhat.com> - 2.1.72-1^%@- Update to the latest upstream versionutMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb69-3\ڭ- save_to_file() function breaks symbolic link when saving configurationg~u]tMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb69-2\eX@- report the correct size for partitionsk}uetMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb69-1\P@@- Rebase rtslib to upstream version 2.1.fb69w|w{tMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb63-13[j@- respin a new release to avoid problems with TPS testsy{wtMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb63-12[)- saveconfig: way to block-level save with delete commandgzw[tMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb63-11Z@- Fix a failure in absence of save file
\v~gu]uMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb69-2\eX@- report the correct size for partitionskueuMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb69-1\P@@- Rebase rtslib to upstream version 2.1.fb69ww{uMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb63-13[j@- respin a new release to avoid problems with TPS testsywuMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb63-12[)- saveconfig: way to block-level save with delete commandgw[uMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb63-11Z@- Fix a failure in absence of save fileww{uMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb63-10Z؄- Add missing patch "tcmu: add control constructor arg"uKuMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb63-9ZЛ- Support tcmu hw max sectors
- saveconfig: dump control string containing control=value tuples
	LsH>L
vFedora Release Engineering <releng@fedoraproject.org> - 0.1.10-2X- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_RebuildY1vFabio Alessandro Locati <fale@fedoraproject.org> - 0.1.10-1Xc@- Update to 0.1.10Pg=vMiro Hrončok <mhroncok@redhat.com> - 0.1.9-2XW- Rebuild for Python 3.6W/vFabio Alessandro Locati <fale@fedoraproject.org> - 0.1.9-1X@- Update to 0.1.9W
/vFabio Alessandro Locati <fale@fedoraproject.org> - 0.1.7-1W- Uodate to 0.1.7W/vFabio Alessandro Locati <fale@fedoraproject.org> - 0.1.5-1W- Update to 0.1.5dq[uMaurizio Lombardi <mlombard@redhat.com> - 2.1.74-1_P- Rebase to the latest upstream versiond
q[uMaurizio Lombardi <mlombard@redhat.com> - 2.1.72-1^%@- Update to the latest upstream version	uuMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb69-3\ڭ- save_to_file() function breaks symbolic link when saving configuration
QkQ	uvOyvind Albrigtsen <oalbrigt@redhat.com> - 0.1.13-1.2b@- Upgrade python-botocore to fix IMDSv2 support

  Resolves: rhbz#2050751nqmvOyvind Albrigtsen <oalbrigt@redhat.com> - 0.1.13-1[@- Fix "python2-s3transfer" from EPEL issue by adding it to Obsoletes
- Rebase to v0.1.13 to fix missing "max_bandwidth" issue

  Resolves: rhbz#1576985
  Resolves: rhbz#1578083q9vOyvind Albrigtsen <oalbrigt@redhat.com> - 0.1.10-8Z- Bundle python-futures, python-botocore and python-jmespath

  Resolves: rhbz#1509441
vFedora Release Engineering <releng@fedoraproject.org> - 0.1.10-3Yy- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
to{wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTo;wAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2owwAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YoEwAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omwAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
 o'xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetqOwAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2#owxAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|"oxAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t!o{xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y$oExAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A%oxAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-&omxAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?)q9xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)(qOxAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down'oxAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]

er+V:eD
cfdd7dc1c23cdb3468016785f9f50105c16d23f98222683011322bc94d444700D
463481903ff9ac36f08f2d63e5bce0da7c84afc7274e5f35ea4d39f73cc6873eD
6d31c249f4ea5cbb99f5d7d01050aeaa157ab3eb14d78071165578cf70934576D
88ab2f3a84ae0b670762548a3b07213bc1a96a8249ebb3ac49b9d659b4187823D
32da1842a79bb4ed02be3e6979ea97d79701733a3dadad668bf35bf4bc617e34D
ce32f7bf96aa04670b34d8d775667ca1ef2afcc5c614f240767eb7ef1968722aD
17a03afe739f681263e0d7a0e0adc83bc4c4a647094714cc9176e4e82ca51df0D~
edf5824c7caaf50e97ae8b83f252bc9a7263368eef75626da3749913eb217edaD}
0d7905c384f2eb08286c9eaf8161f50db1d1312363a1fe8b484962d4ed6e149bD|
d16c70a8d4f77c28cd4ccea87c2c453deab255c95d8267f88c3be5f925f8defbD{
14d9d53643fea7cc10917023b99621119465b51a9152b40c8803e3794b562f00Dz
a94dd20cc4d6f36d4c0e6369c1184936c60dfd226e51525275cc137526e1f229Dy
e5bbff1b2c6d054cc79f530eb0647fb1a04ec02c79c456548c0d9082b4d41037
2,owyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|+oyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t*o{yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y-oEyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A.oyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-/omyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?2q9yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)1qOyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down0oyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[25owzAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|4ozAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))h3qayAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y6oEzAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A7ozAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]bR:RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{:Tj:Ur:Vz:W:X:Y:Z:[:\&:].:_6:`=:aD:bL:cT:d[:eb:fi:gq:hy:i:j:k:l:m:n:o:p:q:r :s#:t$:u%:v&:w):y,:z-:{.:|/:}2:~5:6:7:8:;:>:?:@:A:D:G:H:I:J:M:P:R:S:V:Y:\:_:a:d:g:j:m:n:o:q:s:v:w:x:z:|::::::::	:
:::::::::::: :#
NN-8omzAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?;q9zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains):qOzAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down9ozAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2>ow{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|=q	zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h<qazAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y?oE{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A@o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Aom{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Dq9{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)CqO{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downBo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm GqQ{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Fq	{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hEqa{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YHoE|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AIo|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Jom|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Mq9|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)LqO|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downKo|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm PqQ|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Oq	|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hNqa|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
ARo}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=Qq|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-Som}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Vq9}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)UqO}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downTo}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm YqQ}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Xq	}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hWqa}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.\a}~Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD[}
}Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=Zq}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tt_a	~Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)^as~Alexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).y]a~Alexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pag;~Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_`c]~Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxdg~Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pcg{~Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)bg'~Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-gisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}fiAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..egw~Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTjo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cik]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexhi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|moAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tlo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
ko'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2nowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YooEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nxqi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-pisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
Tso;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]crk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|voAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tuo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
to'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2wowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YxoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xzi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAyoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
T|o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c{k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t~o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
}o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""Y	oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|? q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2#owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|"oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))h!qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y$oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A%oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-&omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?)q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)(qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down'oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2,owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|+q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h*qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update

er+V:eD
1177f8d43f71a392da046005c8e1d337cda1f625f0dd12ae28400acc668f6b53D
d65c68263d6673f69842bd0f97718ea1b27b0cfdef0dd093bccb847c4a9bdc14D
a43b680de14ef93acee1419d61cdc454bcfc9439bdacd573060f26937b5e2164D
e29dd1c6d36379f2cd4d51b34af58306f6334f7eef664b48361f0e5833bb90a7D
989f890ca6fa4ad9fb01ed7adf6b4b450bbb4b99745d1462d7fbb610298b96bbD

1006f493d08b88033474d82a195562d019c3fcf80328843dd0d8bb351e49ab25D
c83b382761599c654c4924c45b614f3f44705f0072d35ce4e89a498f643de93cD
45190bf945897c615199c3c6632ae316c3c9299a53118705ae10de934f61741fD

84eacac2027d38ab8ac05edb1c4325c192f14bb386175f2256239f2d4d9d32b8D	
fbdc480b9ba57d0d9e0972e4e60bb2e1de36296f91b120ddcc7d7abcbd955f94D
dd6b1ad5b433b7d1f74b7dd91b9b5cb0f241de67b3ac6e130a4577c5fcbfb7dbD
8f6430d25a368ef161d771713f41a8108fe1562d0f2f53e1a94254edcc76e656D
e8468f3515b06d1ca7bf5b19ef2db35762b8397bb1d841f2a9e8409ad97af8fa
""Y-oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A.oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-/omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?2q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)1qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down0oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 5qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|4q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h3qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y6oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A7oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-8omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?;q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains):qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down9oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm >qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|=q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h<qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
A@oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=?qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-AomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Dq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)CqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downBoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm GqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Fq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hEqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.Ja}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenDI}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=HqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
TtMa	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)LasAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yKaAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
POg;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_Nc]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxRgAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pQg{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)Pg'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-UisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}TiAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..SgwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTXo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cWk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is FalsexVi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|[oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tZo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Yo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2\owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y]oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nx_i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-^isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
Tao;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c`k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|doAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tco{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
bo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2eowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YfoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xhi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAgoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
Tjo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cik]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|moAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tlo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
ko'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2nowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YooEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ApoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-qomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
tto{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
so'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTro;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2vowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|uoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YwoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AxoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]bR;RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{:%:&:):,:-:.:/:‚2:Â5:Ă6:ł7:Ƃ8:ǂ;:Ȃ>:ɂ@:ʂA:˂D:̂G:͂J:΂M:ςO:ЂR:тU:҂X:ӂ[:Ԃ\:Ղ]:ւ_:ׂa:؂d:قe:ڂf:ۂh:܂j:݂m:ނn:߂o:p:q:t:v:w:x:y:|:::::::	:
:::::::::::: :#:$:%;&;);,;.;/;2;5;8;	;;
=;@;C;
F;I;J;K;M;O;R;S;T;V;X;[;\;];^;`;c;g
NN-yomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
|o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target{qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downzoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|~oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t}o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y	oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)
qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|? q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm #qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|"q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h!qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y$oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A%oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-&omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?)q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)(qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down'oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm ,qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|+q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h*qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
A.oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=-qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]

er+V:eD
493b003d3ae9b9c7add7127460997cc5a69ceef2b8884c9efa668bd7c7cda3a8D
a01c3e5e0175a052f36e32e6cf907b5d7095df8c8df47790e64f8dd8c741aff0D
5a07e58d6cda56dbd47d3a94fc14aba56df74cd39ba554ead4b6dee97ef05e5bD
946bfad55d48fe614e3519a074265c4e7c6b21d160e933e697f3ed783a7214c0D
9acf4764f875271e9b8edf93cb0f5241361a82fe81d1381df235edd88ffa4981D
e7c1b560ac8edc237347234d58d014ac60737500c37066f24b7f254871ccb2cdD
f465238db8cffd5b22112d022c74977b69d65ca1b414ece5ec29ff7b1f1c209aD
de7cfbe962bd72bff05eb5b687355c2d1b4e53a0affdf86ce99149c64c2d5d6bD
82fcde3856cc70e10a4bd10d93452cca394045a7afa452b0880881752f2c6b56D
e8c8f15154fb4dc69d8a6ed87e54bf5e6b084aa0153827e82cd2471889908402D
667a197939b4f8fb8e33219958fabfaa7eccce599d0e0a365514b76cb20d2a60D
c2b42f750a619815728e53e19957decfbf5dc33eb529eebf3fb6b9ecf562e320D
f5d06a0438f7a24578bc611af20cbc9e52844b6cfbb52579826da412b7050eaf
NN-/omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?2q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)1qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down0oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 5qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|4q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h3qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.8a}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD7}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=6qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tt;a	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization):asAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).y9aAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
P=g;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_<c]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux@gAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p?g{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)>g'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-CisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}BiAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..AgwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTFo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cEk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is FalsexDi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|IoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tHo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Go'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2JowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YKoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
NxMi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-LisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
TOo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cNk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|RoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tQo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Po'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2SowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YToEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xVi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAUoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
TXo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cWk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|[oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tZo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Yo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2\owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y]oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A^oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NJ`g/William Poteat <wpoteat@redhat.com> 1.24.36-1^U@- 1831104: When in Simple Content Access mode, subscription-manager should not
  complain that subscriptions aren't attached (wpoteat@redhat.com)-_omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
VV@coChristopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)nbgwWilliam Poteat <wpoteat@redhat.com> 1.24.38-1^V@- 1837244: Fix wrong version provided by subscription-manager version; ENT-2388
  (jhnidek@redhat.com)
- 1834792: Try to terminate rhsmd after timeout; ENT-2368 (jhnidek@redhat.com)maguWilliam Poteat <wpoteat@redhat.com> 1.24.37-1^I- 1830994: Fix warning messages in dnf/yum (jhnidek@redhat.com)
- 1823523: Detect rhsm-icon running without psutil (csnyder@redhat.com)
- 1771921: Package profiles sends too early when registering a client
  (wpoteat@redhat.com)
- 1688702: Generate redhat.repo in off-line mode; ENT-2302 (jhnidek@redhat.com)
CgoChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9foChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XegKWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)ydoChristopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)
,h	,XlgKWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)ykoChristopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)@joChristopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)igKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)hgAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)
BbpgKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)ogAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CnoChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9moChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)
+A9uoChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XtgKWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)}so
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)ro!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Pqo3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
" "zo!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Pyo3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)xgKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)wgAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CvoChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
YY9~oChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)}oCChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F|oChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}{o
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "o!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)gKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CoChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|oChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)oCChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FoChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "o!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
gKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)	gAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CoChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|oChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)oCChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FoChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}
o
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LgKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)'ekPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidek;(
+SoCChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FoChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)o!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
|oChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
KLKgAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)eamJiri Hnidek <jhnidek@redhat.com> 1.24.52-2d.@- 2229752: Fix D-Bus policy (jhnidek@redhat.com)'ekPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidek;,
c"oCChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F!oChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)} o
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)o!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)gKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
|#oChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'$ekPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidek;0
(o!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P'o3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)&gKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)p%e}Pino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
|,oChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)+oCChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F*oChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)})o
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'-ekPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidek;4
LCLw1yyCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-82\-@- Updated fix for CVE-2019-9636
Resolves: rhbz#1689317x0y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-81\@- Security fix for CVE-2019-9636
Resolves: rhbz#1689317C/Q7Pino Toscano <ptoscano@redhat.com>e@- tito: drop bz requirement (ptoscano@redhat.com)
- fix: 1.24 Add python-requests to the list of required RPMs
  (jhnidek@redhat.com)
- fix: Pin lxml to last version supporting Python 2 (mhorky@redhat.com)
- fix: Add missing package intltool to test script (jhnidek@redhat.com)p.e}Pino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)

er+V:eD,
31a17cc7c43aa0aefd3039a43028118f0ea8b11195c232e1310e14547c07b77dD+
13620c99b0846a322488107d5cc07d2d64ddc79b24d8cd7eb307378a759389deD*
93a29cb8a20d95092bbb437ad52a8901fb2b1e4d84591469dd4975622609cbeeD)
594dfccfe823bf2e7b0b092a49e9599e40606708a101de2e67c467258d6fd21eD(
29cf78c6548f65bd34d75b05924b962409425d231430172907211eab40e38cceD'
a9d0459586a325bd96baabc21fddbd37a71d0834a5f892c8ae85e543558e77f3D&
376c090acbd7598c0ec397a027eaa7db2374a09ecf6b7d78663cb04b5f928d57D%
c7da8cb6d16db2f0182ecd0e22414d98692b3d8ff0b8cdf1e790afd09f8825b3D$
0b1af8e104a87dcac9e19a39e5868fef98096447b8a8eafc1e3fe57711fabf57D#
9880e1f05df5dfa26e6a6348cf66b755758a4196fc03d93df208e7b2351e07d9D"
b6db83391c36a0ea8bba99215ea32a1b0cbff013b8b497b6fbef6ecfd3e1d880D!
2c11742cf173f5b0b9c866fa8aad7037f8fdb604c6cbbc7c9e373118871941dfD 
32249537b076dbba37c943b1b65d1fff2e87bb54365e3b33c003135dd728a178
gNagy8y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998y7y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773l6ycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551y5y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388x4y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#170417473ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530v2ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600
7S$7y?y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773l>ycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551y=y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388x<y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747;ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530v:ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600(9yYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
i%i7DywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530xCy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680ByiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(AyYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481y@y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998
(JyYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yIy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yHy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lGycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yFy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xEy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#1704174
{Oh{lPycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yOy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xNy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#1704174gMgkLumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917xLy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680KyiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494
=Y$=gVgkLumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917xUy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680TyiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(SyYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yRy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yQy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773
`
Y`y]y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388x\y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747[ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530vZywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600wYyyCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-82\-@- Updated fix for CVE-2019-9636
Resolves: rhbz#1689317xXy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-81\@- Security fix for CVE-2019-9636
Resolves: rhbz#1689317vWywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-94e@- Security fix for CVE-2023-40217
Resolves: RHEL-9615
7o7xdy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747cywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530vbywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600(ayYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481y`y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998y_y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773l^ycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551
7l70jyiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(iyYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yhy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998ygy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lfycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yey}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388
eL_eyqy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998ypy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773loycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yny}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xmy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747lywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530xky{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#1918168
>S7>ywy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xvy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#1704174gugkLumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917xty{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680syiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(ryYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
88x}y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680|yiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494({yYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yzy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yyy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lxycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551
	Vgr!VvywCharalampos Stratakis <cstratak@redhat.com> - 12.1.0-5W@- Fix HTTPoxy CVE-2016-1000111
Resolves: rhbz#1358792M_?Daniel Mach <dmach@redhat.com> - 12.1.0-4RU- Mass rebuild 2014-01-24M_?Daniel Mach <dmach@redhat.com> - 12.1.0-3Rk- Mass rebuild 2013-12-27Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 12.1.0-2P
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildU{3Julian Sikorski <belegdol@fedoraproject.org> - 12.1.0-1O- Updated to 12.1.0U{3Julian Sikorski <belegdol@fedoraproject.org> - 12.0.0-1O7- Updated to 12.0.0W{7Julian Sikorski <belegdol@fedoraproject.org> - 11.1.0-2O3- Rebuilt for gcc-4.7vywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-94e@- Security fix for CVE-2023-40217
Resolves: RHEL-9615g~gkLumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917
vM_?Daniel Mach <dmach@redhat.com> - 1.10.1-2Rk- Mass rebuild 2013-12-27c-Robert Kuska <rkuska@redhat.com> - 1.10.1-1RZ@- Update to v1.10.1 to deal with different securiy issue
Resolves: CVE-2013-1633e
amRobert Kuska <rkuska@redhat.com> - 1.9.1-2Q@- Delete bundled libraries of pip and setuptools	y?Charalampos Stratakis <cstratak@redhat.com> - 12.1.0-8b1@- Security fix for CVE-2022-24801: Possible http request smuggling
Resolves: rhbz#2073114YgMLumír Balhar <lbalhar@redhat.com> - 12.1.0-7^k@- Fix CVE-2020-10108 and CVE-2020-10109 multiple HTTP request smuggling vulnderabilities
Resolves: rhbz#1813439 rhbz#1813447
- Remove useless macros definitionsyCharalampos Stratakis <cstratak@redhat.com> - 12.1.0-6]D%- Fix CVE-2019-12387 (HTTP Header Injection)
Resolves: rhbz#1721518
oaomguLumír Balhar <lbalhar@redhat.com> - 15.1.0-3^@- Add three new patches for CVEs in bundled urllib3 and requests
CVE-2018-20060, CVE-2019-11236, CVE-2018-18074
Resolves: rhbz#1649153
Resolves: rhbz#1700824
Resolves: rhbz#1643829yCharalampos Stratakis <cstratak@redhat.com> - 15.1.0-2Y- Add back the versioned virtualenv script
Resolves: rhbz#14611540yiCharalampos Stratakis <cstratak@redhat.com> - 15.1.0-1Y- Rebase to version 15.1.0
- Disable automatic downloads from pypi on new venv creation
Resolves: rhbz#1461154vywCharalampos Stratakis <cstratak@redhat.com> - 1.10.1-4X@- Fix Python 3.4 compatibility
Resolves: rhbz#1411685c
ecTomas Orsava <torsava@redhat.com> - 1.10.1-3W0{- Added a patch that shows a custom error message when a FILE passed to
  virtualenv to be used as 'home dir' already exists and is NOT a directory.
Resolves: rhbz#1306513
wc*vywCharalampos Stratakis <cstratak@redhat.com> - 1.10.1-4X@- Fix Python 3.4 compatibility
Resolves: rhbz#1411685cecTomas Orsava <torsava@redhat.com> - 1.10.1-3W0{- Added a patch that shows a custom error message when a FILE passed to
  virtualenv to be used as 'home dir' already exists and is NOT a directory.
Resolves: rhbz#1306513M_?Daniel Mach <dmach@redhat.com> - 1.10.1-2Rk- Mass rebuild 2013-12-27c-Robert Kuska <rkuska@redhat.com> - 1.10.1-1RZ@- Update to v1.10.1 to deal with different securiy issue
Resolves: CVE-2013-1633yCharalampos Stratakis <cstratak@redhat.com> - 15.1.0-5a@- Use the system certs for the bundled pip
Resolves: rhbz#2015326g#Lumír Balhar <lbalhar@redhat.com> - 15.1.0-4^E:@- Bump
Resolves: rhbz#1649153
Resolves: rhbz#1700824
Resolves: rhbz#1643829
#KH#y9Charalampos Stratakis <cstratak@redhat.com> - 15.1.0-6b!- Require again python-setuptools instead of python2-setuptools
Resolves: rhbz#2054827yCharalampos Stratakis <cstratak@redhat.com> - 15.1.0-5a@- Use the system certs for the bundled pip
Resolves: rhbz#2015326g#Lumír Balhar <lbalhar@redhat.com> - 15.1.0-4^E:@- Bump
Resolves: rhbz#1649153
Resolves: rhbz#1700824
Resolves: rhbz#1643829mguLumír Balhar <lbalhar@redhat.com> - 15.1.0-3^@- Add three new patches for CVEs in bundled urllib3 and requests
CVE-2018-20060, CVE-2019-11236, CVE-2018-18074
Resolves: rhbz#1649153
Resolves: rhbz#1700824
Resolves: rhbz#1643829yCharalampos Stratakis <cstratak@redhat.com> - 15.1.0-2Y- Add back the versioned virtualenv script
Resolves: rhbz#14611540yiCharalampos Stratakis <cstratak@redhat.com> - 15.1.0-1Y- Rebase to version 15.1.0
- Disable automatic downloads from pypi on new venv creation
Resolves: rhbz#1461154
Mm#guLumír Balhar <lbalhar@redhat.com> - 15.1.0-3^@- Add three new patches for CVEs in bundled urllib3 and requests
CVE-2018-20060, CVE-2019-11236, CVE-2018-18074
Resolves: rhbz#1649153
Resolves: rhbz#1700824
Resolves: rhbz#1643829"yCharalampos Stratakis <cstratak@redhat.com> - 15.1.0-2Y- Add back the versioned virtualenv script
Resolves: rhbz#14611540!yiCharalampos Stratakis <cstratak@redhat.com> - 15.1.0-1Y- Rebase to version 15.1.0
- Disable automatic downloads from pypi on new venv creation
Resolves: rhbz#1461154v ywCharalampos Stratakis <cstratak@redhat.com> - 1.10.1-4X@- Fix Python 3.4 compatibility
Resolves: rhbz#1411685cecTomas Orsava <torsava@redhat.com> - 1.10.1-3W0{- Added a patch that shows a custom error message when a FILE passed to
  virtualenv to be used as 'home dir' already exists and is NOT a directory.
Resolves: rhbz#1306513M_?Daniel Mach <dmach@redhat.com> - 1.10.1-2Rk- Mass rebuild 2013-12-27
ZwRhZV+u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-45_X- fixes bugs bz#1785714V*u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-44_P- fixes bugs bz#1460657V)u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-43_P- fixes bugs bz#1460657V(u;Deepshikha Khandelwal <dkhandel@redhat.com> - 6.0-42_O@- fixes bugs bz#1785714'g1Lumír Balhar <lbalhar@redhat.com> - 15.1.0-7b@- Security fix for CVE-2019-20916 for the bundled pip wheel
Resolves: rhbz#1868135&y9Charalampos Stratakis <cstratak@redhat.com> - 15.1.0-6b!- Require again python-setuptools instead of python2-setuptools
Resolves: rhbz#2054827%yCharalampos Stratakis <cstratak@redhat.com> - 15.1.0-5a@- Use the system certs for the bundled pip
Resolves: rhbz#2015326$g#Lumír Balhar <lbalhar@redhat.com> - 15.1.0-4^E:@- Bump
Resolves: rhbz#1649153
Resolves: rhbz#1700824
Resolves: rhbz#1643829
	QOQb4;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.1`e@- fixes bugs bz#1927235`3;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56`v@- fixes bugs bz#1948547`2;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-55`T@- fixes bugs bz#1939372f1yWCentOS Sources <bugs@centos.org> - 6.0-49.1.el7.centos`P- remove vendor and/or packager linesb0;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49.1`/@- fixes bugs bz#1930561`/;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-49_G@- fixes bugs bz#1286171`.;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-48_- fixes bugs bz#1895301v-gGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-47_@- fixes bugs bz#1286171 bz#1821743 bz#1837926k,QGluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-46_"- fixes bugs bz#1873469 bz#1881823

er+V:eD9
d7e9e8eaabb6fc8e9c18b08b483a4a81d3edc3a4d0156c915353f0e5778870bcD8
6032cf77d642b54e8e24ecb96c2f6ffad12f9b165c3bfdeefdcdb469f79f5f25D7
0cd7aee9f2db00d6755f43fa30faafe7382aa8e438f5c11a40c90c0e5e8352d2D6
d2be459c9fddcb43bea87bad5b80c2656b90fede44f30c5bef1510d68feaef5bD5
557caeee2f6ed8008504fde4f489a621524ac25488986c4d163e7ea8b153e0c3D4
cef38591d6d987235d823aca0105ccdf5c702a3c16a3ad8301d64d8cc9b6ef5dD3
ab9cdb97c8451a96a6548a863ba8dbcf60034e7bf1ea6853b42a0451863a5ffdD2
51fbcbb6ee3318561a41b9335488c8645ebf76f62edb08fa951189b31ce14afdD1
458a2e4662739309c98eb0b79c83a8348f583ceb85c8d0889d5b32448cdf18bfD0
afbd81a2f863df61c3490f215bc72bad2c81fb0e7772ce5f4bc736703c22f6ddD/
6725bd1e0d020512b60182f153b95d2f6eebfc10cd5929625a7498254bd56f56D.
341b7f6c5352eee2a98665ce78feaf6c4a52626e0322ce9b65c82f9e08190f7eD-
8aac2519f49dcdc64ce5554ba02dde6b31912d07ee75f879d789a0439eeb22ec
69q6`:;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-61a- fixes bugs bz#1973566R9Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-60ad'@- fixes bugs bz#1668303 bz#1853631 bz#1901468 bz#1904137 bz#1911665 
  bz#1962972 bz#1973566 bz#1994593 bz#1995029 bz#1997447 bz#2006205`8;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-59`E- fixes bugs bz#1689375`7;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-58`- fixes bugs bz#1945143\61Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-57`[- fixes bugs bz#1600379 bz#1689375 bz#1782428 bz#1798897 bz#1815462 
  bz#1889966 bz#1891403 bz#1901468 bz#1903911 bz#1908635 bz#1917488 bz#1918018 
  bz#1919132 bz#1925425 bz#1927411 bz#1927640 bz#1928676 bz#1942816 bz#1943467 
  bz#1945143 bz#1946171 bz#1957191 bz#1957641b5;Gluster Jenkins <dkhandel+glusterjenkins@redhat.com> - 6.0-56.2`@- fixes bugs bz#1953901
<}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1d;uWCentOS Sources <bugs@centos.org> - 6.0-61.el7.centosbL/@- remove vendor and/or packager lines
VV ?;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;P}>}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv=}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|AuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm@UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.bR;RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{; p;!u;"z;#~;$;%;&;';);*;+;-;.";/#;1$;2(;3,;5-;61;88;9?;:D;;J;<P;=V;>];?d;@j;Aq;Bw;C};D;E;F;G;H;I#;J+;K4;M:;N<;O?;QA;SC;TF;UH;WJ;XL;YP;[S;\U;]W;^Z;`\;a^;b`;cb;de;eg;fi;gk;ho;iq;js;kx;lz;m|;n;o;s;t;u;v
;x
;|;};~;;;;;;;; ;!;";%;';*;+;.;0;3;4;7;9;;
k\C3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differBFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
"vF}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issue\E}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.10a*@- Roll in CentOS BrandingyDkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
 H;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;V}G}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|JuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmIUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\L3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differKFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
"$"}P}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offset\O}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.11b@- Roll in CentOS BrandingyNkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyMkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller rolether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
aa|SuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmRUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. Q;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;Z
k\U3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differTFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
yWkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyVkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
rr Z;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;_\Y}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.12cb[- Roll in CentOS Branding|XqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|\uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm[UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\^3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ]Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
y`kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy_kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
Vb%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|aqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
(|euFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmdUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.ac;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
k\g3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differfFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
yikFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyhkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
Vk%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|jqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
\o3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differnFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA servermFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakal;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
yqkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupypkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
Vs%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|rqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
\x3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ\w}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.16e- Roll in CentOS Branding|vsFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protectionuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakat;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
yzkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyykFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V|%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|{qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
S\}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.17ff- Roll in CentOS Branding8w{Julien Rische <jrische@redhat.com> - 4.6.8-5.el7_9.17f_- Resolves: RHEL-29926 ipa: user can obtain a hash of the passwords of all domain users and perform offline brute force|sFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protection~Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka};Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
UUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa;pP#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agentsaEFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-10.el7]- Resolves: #1728123 - EMBARGOED CVE-2019-10195 ipa: FreeIPA: batch API logging user passwords to /var/log/httpd/error_log [rhel-7]
  - CVE-2019-10195: Don't log passwords embedded in commands in calls using batch
- Resolves: #1773550 - IPA upgrade fails for latest ipa package when adtrust is installed
  - Do not run trust upgrade code if master lacks Samba bindings
- Resolves: #1767302 - EMBARGOED CVE-2019-14867 ipa: Denial of service in IPA server due to wrong use of ber_scanf() [rhel-7.8]
  - Make sure to have storage space for tag;q-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss;rd when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
o}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV 
;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;w}	}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
\\
Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa;yP#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agents[{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.4`P- Roll in CentOS Branding;z-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss;{d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
o}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
??Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa;[{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.5`- Roll in CentOS BrandingmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.;-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss;d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
o}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
//[{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.6`[- Roll in CentOS Branding|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
o }cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!!}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||"}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV %;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;}$}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv#}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|'uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm&UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k!*}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords[){?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.7`- Roll in CentOS Branding(Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
||+}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV .;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;}-}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv,}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|0uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm/UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
+k+[3{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.9aex- Roll in CentOS Branding\23Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ1Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server

er+V:eDF
e568d73cd1ea3df0a67fb17bceeae36b33a91af90d651ab33c4ae492f208ff32DE
d48a4b2fd37317e4545a3515a2c3d39cc3c64505924570c14b14d2c06007e7a6DD
e5f5632841ed822338ddb9d3ea6e1bf7785e6b1ba1d354993db1a5a47209507eDC
9b04004d36145ad375dfe9de28a7d55007514df412aad6adb55517e39c5d5a94DB
4efa7633b62075aef43851141d38c2ac3929b35c36aac708e648998975d72298DA
295c3de68a936013058598624efdd7c0f37f4f950b68746738fee46aab824fcfD@
9a67185543ce85b81ea0ba5ae659db50e1022125ba9f4e1bebe34933d399141bD?
7e3441543e04cea1f513eee2573e964910463f84549bdf1a6c50721b6528186aD>
7cf7e3e4798fd8a46b48e37fc7adc314491a938ee17b815dd3f5c0887cfb2f42D=
a5200800917686a6972452c153a94ec608f7f8111e13fd0ed1403eed10246930D<
c99acfec136e15a54620f53419e266691c0a771c09aa286798ab5aa047dfc846D;
d55b375f8c5f1486c544d95e93bbe9054f39c43705b029fc26b80f33c96e703bD:
55921bf220651db8e53c670393336486760efc2eb102ac7de7bc83f6731698f6
||4}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV 7;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;}6}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv5}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|9uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm8UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\;3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ:Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
"v>}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issue\=}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.10a*@- Roll in CentOS Brandingy<kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
 @;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;}?}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|BuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmAUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\D3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differCFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
"$"}H}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offset\G}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.11b@- Roll in CentOS BrandingyFkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyEkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller rolether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
aa|KuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmJUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. I;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;
k\M3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differLFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
yOkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyNkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
rr R;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;\Q}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.12cb[- Roll in CentOS Branding|PqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|TuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmSUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\V3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
yXkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyWkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
VZ%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|YqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
(|]uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm\UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.a[;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
k\_3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ^Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
yakFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy`kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
Vc%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|bqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
\g3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differfFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA servereFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakad;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
yikFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyhkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
Vk%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|jqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
\p3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ\o}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.16e- Roll in CentOS Branding|nsFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protectionmFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakal;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
yrkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyqkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
Vt%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|sqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
S\y}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.17ff- Roll in CentOS Branding8xw{Julien Rische <jrische@redhat.com> - 4.6.8-5.el7_9.17f_- Resolves: RHEL-29926 ipa: user can obtain a hash of the passwords of all domain users and perform offline brute force|wsFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protectionvFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakau;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
UU|Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa;P{#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agentsazEFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-10.el7]- Resolves: #1728123 - EMBARGOED CVE-2019-10195 ipa: FreeIPA: batch API logging user passwords to /var/log/httpd/error_log [rhel-7]
  - CVE-2019-10195: Don't log passwords embedded in commands in calls using batch
- Resolves: #1773550 - IPA upgrade fails for latest ipa package when adtrust is installed
  - Do not run trust upgrade code if master lacks Samba bindings
- Resolves: #1767302 - EMBARGOED CVE-2019-14867 ipa: Denial of service in IPA server due to wrong use of ber_scanf() [rhel-7.8]
  - Make sure to have storage space for tag;-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss;d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
o}}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!~}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
\\Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa;P#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agents[{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.4`P- Roll in CentOS Branding;-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss;d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
o}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;Ɂ}
}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv	}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
??Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa;[
{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.5`- Roll in CentOS BrandingmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.;-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss;d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
o}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;ҁ}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
//[{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.6`[- Roll in CentOS Branding|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
o}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;ف}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuebR<$RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{;@;B;D;H;K;M;O;R;T;V;X;Z;];_;a;c;g;i;k;p;r;t;y;|;};~;;;;ł;Ƃ;ǂ;Ȃ;ʂ;΂;ς;Ђ;т;ӂ;Ԃ;Ղ;ւ;ׂ;ڂ;ۂ";܂#;݂&;߂(;+;,;/;1;3;6;8;:;<;@;C;E;G;J;L;N;P;R;U;W;Y;[;_;a;c;h;j<l<q<t<u<v<w<	z<}<~<<<<<<<	<<<<< <!<#ther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k!"}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords[!{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.7`- Roll in CentOS Branding Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
||#}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV &;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;ށ}%}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv$}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|(uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm'UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
+k+[+{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.9aex- Roll in CentOS Branding\*3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ)Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
||,}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV /;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;}.}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv-}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|1uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm0UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\33Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ2Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
"v6}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issue\5}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.10a*@- Roll in CentOS Brandingy4kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role

er+V:eDS
1bdade2f19c49a1f75262e570473159eba076e5147708897ef26211f4c3e6253DR
69b52b527f2581aac941a0d4fa71d1bce28da1b79f2f313b12818e1090892dfbDQ
461a3ca0afeaa8e8ae87e2d1547a6874187f8e530bf5dbfc39b6c0c22d899d43DP
1d31499d687de8d016bd60a5b2fbacf8065dd426d5a48f4060f427cccd242680DO
89a42b57b8107e340a51b81c28d25743fa831b6a86f64bbbe3b811eba4226e53DN
0cdb951d2a540947e97b85a4754dcc8bbf1cb878e5dbd0f1bdad2a6a4626f694DM
99b96b570fc91fa44db61365343ee81cb62330dcb8c0e0c74bc140c218e7c02aDL
e3969bb97655724f00a321057ffa1c3761259a7544eb9024a813c22c09309f89DK
76c5012bb1a4018438b2d42ef73cd3f71d74224ce2b5eaba5a63f6a8e7daa068DJ
2e5a211202f039bf2713d7e2e1bc0fe2c8e9ca6d3e7ad3b3283b64df474b99e1DI
b0579fbf5f02ea45b706f77b73c1a248973966d8d1c97d2b3a5b63af1076dc30DH
dea5908065b3f9a0fbb1fdc5cae84e7dd1e61e274eb25e8a1c1bf2881f5cecf1DG
f23cd99f65fe05afff0761b481a6ae707428f006a7f8e5dc7c8c2f1c8a92a6e7
 8;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;}7}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|:uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm9UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\<3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
"$"}@}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offset\?}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.11b@- Roll in CentOS Brandingy>kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy=kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller rolether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
aa|CuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmBUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server. A;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;
k\E3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differDFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
yGkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyFkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
rr J;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o;\I}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.12cb[- Roll in CentOS Branding|HqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync pluginther means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|LuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmKUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k\N3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differMFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
yPkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyOkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
VR%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|QqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
(|UuFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmTUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.aS;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
k\W3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differVFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
yYkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyXkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
V[%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|ZqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
\_3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ^Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server]Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leaka\;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
yakFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupy`kFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
Vc%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|bqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
\h3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ\g}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.16e- Roll in CentOS Branding|fsFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protectioneFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakad;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
yjkFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11bzS- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
  - WebUI: Add confirmation dialog for changing default user/host groupyikFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10a@- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server 
  - Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
  - SMB: switch IPA domain controller role
Vl%Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13dJ- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
  - Defer creating the final krb5.conf on clients
  - Move client certificate request after krb5.conf is created
  - server install: remove error log about missing bkup file|kqFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12c=q- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
  - idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
  - ipa otptoken-sync: return error when sync fails
  - ipatests: add negative test for otptoken-sync
  - ipatests: python2 does not support f-strings
  - Fix otptoken_sync plugin
S\q}?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.17ff- Roll in CentOS Branding8pw{Julien Rische <jrische@redhat.com> - 4.6.8-5.el7_9.17f_- Resolves: RHEL-29926 ipa: user can obtain a hash of the passwords of all domain users and perform offline brute force|osFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16e\- Resolves: RHEL-12570 ipa: Invalid CSRF protectionnFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15d˖- Resolves: 2209636 libipa_otp_lasttoken plugin memory leakam;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14d?@- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
  - ipaserver: deepcopy objectclasses list from IPA config
UUtFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa<Ps#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agentsarEFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-10.el7]- Resolves: #1728123 - EMBARGOED CVE-2019-10195 ipa: FreeIPA: batch API logging user passwords to /var/log/httpd/error_log [rhel-7]
  - CVE-2019-10195: Don't log passwords embedded in commands in calls using batch
- Resolves: #1773550 - IPA upgrade fails for latest ipa package when adtrust is installed
  - Do not run trust upgrade code if master lacks Samba bindings
- Resolves: #1767302 - EMBARGOED CVE-2019-14867 ipa: Denial of service in IPA server due to wrong use of ber_scanf() [rhel-7.8]
  - Make sure to have storage space for tag<-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss<d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
ou}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!v}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||w}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV z;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o<
}y}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetvx}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
\\}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa<P|#Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-11.el7]- Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
  - trust upgrade: ensure that host is member of adtrust agents[{{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.4`P- Roll in CentOS Branding<
-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss<d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
o~}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o<}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
??Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.6-12.el7^y@- Resolves: #1754902 - Running ipa<[{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.5`- Roll in CentOS BrandingmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.<-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
- Resolves: #1404770 - ID Views: do not allow custom Views for the masters
  - idviews: prevent applying to a master
- Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
  - install/updates: move external members past schema compat update
- Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
  - pkinit setup: fix regression on master install
  - pkinit enable: use local dogtag only if host has CA
- Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
  - Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
- Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
  - ipa-cacert-manage man page: fix indentation
- Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
  - adtrust.py: mention restarting sss<d when adding trust agents
- Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
  - Use default ssh host key algorithms
- Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
  - smartcard: make the ipa-advise script compatible with authselect/authconfig
- Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
  - upgrade: fix ipakra people entry 'description' attribute
  - krainstance: set correct issuer DN in uid=ipakra entry
- Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
  - ipa-server-certinstall manpage: add missing options
- Resolves: #1206690 - UPG not being enforced properly
  - ipa user_add: do not check group if UPG is disabled
- Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
- Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
- Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
- Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
- Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
- Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
  - Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
- Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
  - WebUI: Fix notification area layout
- Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
  - Fix indentation levels
  - ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
  - ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
  - Don't save password history on non-Kerberos accounts
o}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||	}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o<}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv
}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
//[{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.6`[- Roll in CentOS Branding|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionm
UFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
o}cFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-1.el7^- Resolves: #1819725 - Rebase IPA to latest 4.6.x version
- Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
- Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
- Resolves: #1817922 - covscan memory leaks report
- Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
- Resolves: #1817918 - Secure tomcat AJP connector
- Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
- Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd
!}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords
||}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o<"}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
|uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
k!}GFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-2.el7^@- Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
  - Add interactive prompt for the LDAP bind password to ipa-getkeytab
  - CVE-2020-1722: prevent use of too long passwords[{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.7`- Roll in CentOS BrandingFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
||}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-3.el7^- Resolves: #1834385 Man page syntax issue detected by rpminspect
  - Man pages: fix syntax issues
- Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
  - Make check_required_principal() case-insensitive
- Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
  - ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
- Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
- Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
  - Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
VV ;Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.4`- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
  - wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by o<'}}Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7^W@- Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
  -  ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offsetv}qFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-4.el7^3- Resolves: #1842950 ipa-adtrust-install fails when replica is offline
  - ipa-adtrust-install: avoid failure when replica is offline
- Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
  - WebUI: Apply jQuery patch to fix htmlPrefilter issuether means than a directory presence, use pki-server subsystem-find
  - Improve PKI subsystem detection
  - ipatests: add test for PKI subsystem detection
  - ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
  - Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
  - fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
  - CAless installation: set the perms on KDC cert file
  - ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  - WebUI: Fix jQuery DOM manipulation issues
- Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
  - fix iPAddress cert issuance for >1 host/service
| uFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.6`q- Resolves: #1959349 - Need to bump pki + ds versionmUFlorence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.5`lM@- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
  - ipa-kdb: fix compiler warnings
  - ipa-kdb: add missing prototypes
  - ipa-kdb: reformat ipa_kdb_certauth
  - ipa-kdb: mark test functions as static
  - ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.
3k+3y%y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403w$w{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642[#{?CentOS Sources <bugs@centos.org> - 4.6.8-5.el7.centos.9aex- Roll in CentOS Branding\"3Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9a8- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
  - extdom: return LDAP_NO_SUCH_OBJECT if domains differ!Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7`- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
  - CA less installation: non ASCII chars in CA subject
  - ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
  - Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server
CgAC~,yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x+y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y*y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$)yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730y(y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774'y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908y&y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552
]sy]y2y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#17507741y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908y0y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552y/y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403w.w{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642
-y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926
MW^My8y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403
7y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~6yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x5y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y4y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$3yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730

er+V:eD`
0d3c2c589c5e9e3f8ffbf1a3ecab65c4237f0445ab4f8f1840daac3a9bde8e16D_
01da9776dbd5c2c0b5ee6d9e9020302a9007e6bf195079f25e6cf699c93e1decD^
0bfce88e921ad0a5fd946306ecf24c9d04e2662eaeaf728d05dbcdc32010c8eaD]
4e92d3195efccd7f140506a0902f4b658d5fed14a465e7c9aa46b8ecca2996acD\
1dcdc8db1818ed7523d6f6801be8434b3245034ec83d045632e076c4f10742c0D[
9006d58c6ebd992f1413230a4531d1584921f01326a875a717363abde71d6b03DZ
25afe9864fffab25d5ffab54abb193c47e76f577fe26ccdeeff50269d7b964ccDY
849380b5dd59adac484f86c0be1242d6fe1a44e5e1ad0f83c18bf6a82a4f531fDX
e47652fa5e7642d21ed5f8769fe5f4fa1d3e7f416afe2b8f600aaf2ad97b5e27DW
40e97878099ade8002e5833f16600e777791b1a319a702abc746d9b4194aa4daDV
4054f1d88ab29666683f77b8b9040e7fe11145c8e91bccaa37e202661206d524DU
a5d07ef113639a1ab8da7c6d2429a8232e1a1dd44504eef67d44e146ca863729DT
577ce44c27214c84f76d58a38be32a4a5f165af65c0e77afa334270e98b8008d
CgAC~?yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x>y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y=y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$<yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730y;y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774:y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908y9y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552
)?E)yEy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774Dy=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908yCy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552yBy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403*Ay]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
@y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926
W^*Ky]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
Jy#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~IyCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xHy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yGy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$FyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730
a;B~QyCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xPy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yOy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$NyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yMy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774Ly=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908
0?L0yWy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774Vy=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908uUyuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139vTywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139*Sy]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
Ry#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926
W^*]y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
\y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~[yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xZy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yYy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$XyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730
|
|ydy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774cy=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908yby}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552yay}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403w`w{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642u_yuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139v^ywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139
OW^Owjw{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642
iy#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~hyCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xgy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yfy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$eyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730
HgAHxqy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616ypy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$oyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yny}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774my=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908yly}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552yky}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403
V~lrVywy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774vy=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908yuy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552yty}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403
sy#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~ryCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459
W^*}y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
|y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~{yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xzy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yyy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$xyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730
HgAHxy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552y~y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403
~ly	y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908*y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459
W^*y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~
yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$
yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730
O
nHOxy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908uyuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139vywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139
O~lCOww{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642uyuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139vywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139*y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459
HgAHx#y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y"y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$!yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730y y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403
X~ltX)y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908y(y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552y'y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403w&w{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642
%y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~$yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459
M]_M
/y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~.yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x-y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y,y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$+yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730y*y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774
HgAHx6y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y5y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$4yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730y3y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#17507742y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908y1y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552y0y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403
$~l@$<y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908y;y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552y:y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403*9y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
8y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~7yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459

er+V:eDm
92d8d566c14d02ab87f59d48e5f011678c4d1ad1effce954445cfff6e2186ac9Dl
5562431c48cab67aa1da614c3d19c3f6becfbc386d29c7133f40bcd4ec21c3dcDk
f9e0e769bfa29d7f3fba358e5524c7245c425336886a47e1697aaa57c199fd16Dj
9640c5a912cb29c8938076ba00b4a29313f55ccd7e684dbbc133c330b71ec3aaDi
d6778189c30093bfbf953888db850ae1d4f311e8b24b88bced9f2ec61bc84479Dh
0321354f5886437064ddff4080e65e1ed1d6f5a4d8f78872893181b71f450938Dg
f53d0c4b2718fb2cccc1cce0666cef6323bd6fdb7b789f34a3fa3a744c3892ecDf
c0ba90dceb83ffcdd8192f4e130a324c73ac021f2a9b2ccdc98d58cdf26f727bDe
577c5f15aa7fe917fc8073ef1e9b96c46ff667b05714023b580aa56ba79395cbDd
8f060c38fbe87356d18b29d60da5dae1ab1bb783fbe9d75c1738ca0ab27b8ec6Dc
67ce50ba914619acce9365d0d7d6b3868526ac655a064b3e74819bd54992e79eDb
43ae4b92ba776ff7c0a7d9e6c5837380d87b103b8cafa435c922bb2e68bce68fDa
e14abc4dfd161e931b9099dce439db26a29175c166b124a14167a664a0d5a600
M]_M
By#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~AyCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x@y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y?y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$>yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730y=y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774
Q5xHy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yGy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$FyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yEy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774Dy=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908*Cy]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
+~lC+Ny=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908uMyuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139vLywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139*Ky]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
Jy#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~IyCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459
M]_M
Ty#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~SyCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xRy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yQy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$PyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yOy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774
JQ^fJ[y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908yZy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552yYy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403wXw{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642uWyuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139vVywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139*Uy]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
M]_M
ay#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~`yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x_y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y^y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$]yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730y\y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774
IoIyhy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$gyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yfy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774ey=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908ydy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552ycy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403wbw{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642
WsWny=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908ymy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552yly}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403
ky#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~jyCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xiy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616
M]_M
ty#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~syCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xry{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yqy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$pyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yoy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774
QW;$zyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yyy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774xy=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908ywy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552yvy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403*uy]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
%s%y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908*y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
~y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~}yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x|y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y{y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999
M]_M
y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774
Q^By
y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774
y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908u	yuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139vywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139*y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
NANuyuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139vywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139*y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616
IoIyy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403ww{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642bR<RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{<%<&<( <)%<*,<+2<,8<.?</E<0K<1Q<2W<3]<4d<5j<6q<7w<8}<9<:	<;<<<=<>#<?)<@/<A6<B<<DB<EH<FN<GT<H[<Ia<Jh<Kn<Lt<Mz<N<O<P
<Q<R<T <U&<V,<W2<X9<Y><[D<\K<]Q<^X<_^<`d<ak<bq<cw<d}<e<f	<g<h<i<j#<k)<l0<m5<n;<oB<qG<rH<sJ<uL<vM<wN<xQ<zS<{U<|V<}Y<~[<]<^<_<b<e<g<h<k<n<p<q<t<w<y<z<|
{u{y y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403ww{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642
y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616
a;B~&yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x%y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y$y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$#yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730y"y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774!y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908
/qU/$,yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730y+y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774*y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908y)y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552y(y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403
'y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926
GsGy2y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403*1y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
0y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~/yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x.y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y-y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999
CgAC~9yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x8y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y7y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$6yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730y5y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#17507744y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908y3y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552
z?#z$>yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730y=y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774<y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908*;y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
:y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926

er+V:eDz
d7798262e71fd5dd605dc0caee6bd51e2af8c6e1d8c23080eb215303d42d2c4fDy
5ca0ccb7e4af7c807c1f99c10409892524195addd4cfc1d830e5cc351643409fDx
e6273ad14c1f319502c24fe2004a6765421589ad83742d12e87a81b3c84c6d08Dw
4ad165c06922e2252a43f8ea8424a0e1ad01faa0b3cc0656d5e88a5bb3bc053fDv
49fee1d14c58251ceaf27e463d004b657ab809c483a44ab5c2bc0bf22a098086Du
ee179dac3f97636a2f35955ae764b090dd0723607221b2ff12cbd42907440344Dt
fc45ecc53eafb78138b2291907fb4463e871868f19476b0d29e6c42b9e2f42a3Ds
c9e8e27be0763433d2342ad0573164a56176f17826d8830f39d0e08518d54127Dr
44eb1405754fcd4ae144cb5025d91b3ac8759293ff1a0f187ca3a1e153137223Dq
c837dad26046c4672910508d3f90d5dca273c22c3503ded2f75eed49602908afDp
f5e54963c8d3735251b4501639c3af99731c36ad7de1884a62f8086d7546d5b1Do
c0f34781687d2456cffd35d278bdf12469af28f83cafc51ead4a756ded452bddDn
5ced3b05c339804924a538a2b874f1a95cbe14eb2973fd4bdd808a14f095fb07
JsJvDywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139*Cy]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
By#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~AyCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x@y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y?y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999
GkEG~KyCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xJy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yIy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$HyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yGy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774Fy=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908uEyuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139
T?LTyQy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403wPw{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642uOyuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139vNywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139*My]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
Ly#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926
CgAC~XyCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xWy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yVy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$UyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yTy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774Sy=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908yRy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552
]sy]y^y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774]y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908y\y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552y[y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403wZw{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642
Yy#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926
MW^Mydy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403
cy#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~byCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xay{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y`y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$_yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730
CgAC~kyCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xjy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yiy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$hyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730ygy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774fy=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908yey}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552
)?E)yqy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774py=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908yoy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552yny}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403*my]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
ly#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926
W^*wy]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
vy#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~uyCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xty{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616ysy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$ryQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730
a;B~}yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x|y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y{y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$zyQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yyy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774xy=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908
0?L0yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908uyuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139vywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139*y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
~y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926
W^*	y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730
|
|yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552y
y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403ww{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642uyuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139v
ywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139
OW^Oww{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-9\"- Security fix for CVE-2019-9948
Resolves: rhbz#1714642
y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459xy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730
HgAHxy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552yy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403
V~lrVy#y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774"y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908y!y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552y y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403
y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459
W^*)y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
(y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~'yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x&y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y%y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$$yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730
HgAHx0y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y/y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$.yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730y-y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774,y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908y+y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-11]e@- Security fix for CVE-2018-20852
Resolves: rhbz#1741552y*y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-10\- Security fix for CVE-2019-10160
Resolves: rhbz#1718403
~ly5y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#17507744y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908*3y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
2y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~1yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459
W^*;y]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
:y#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~9yCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459x8y{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616y7y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$6yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730
O
nHOxBy{Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-16^%@- Security fix for CVE-2020-8492
Resolves: rhbz#1810616yAy}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-15^ku- Security fix for CVE-2019-16935
Resolves: rhbz#1797999$@yQCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-14^g@- Provide and obsolete the python36-tools subpackage for EPEL compatibility
Resolves: rhbz#1763730y?y}Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-13]@- Security fix for CVE-2019-16056
Resolves: rhbz#1750774>y=Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-12]V- Add support for OpenSSL FIPS mode
- Fix faulthandler stack size
Resolves: rhbz#1732908u=yuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139v<ywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139

er+V:eD
ab886e520cf674bfa8b5efe8355f7150140a6f67d313e60090bd36049cdc6983D
59a052cd2596a592fc02e8e794d976aa238ae34da00d247445d0f51bb9e87bccD
9b43305f54731049c328c1576f320912a045534f33373113f5ec315e63e8f094D
4c928cbb9b34a074f2c249f56cfc152f8e285cd974e184b9f5ee05214cbecd42D
3805c7e453631cda2c446cb60a6ea941975f89b2d544824c96b37f874f6e5bacD
73ef9f5aba212c3f0d0e055cd597dbddc8d7752ec301de688be47c0a416b5a6dD
ae43349e074e7aa2c0178a464cfe5b1989f31fa0e61c787de99ec01e156ca556D
7f71841bd15ea189a3946e054f1c018051ce33de76170da0fa7a4ec172429517D
a56bfb4be6763b8f94a45cd667d3d9e26cc48d8d10f46fa025a15f345484167bD~
511a7fcece3cd644106c80e487095e7d8ab9fa20dc09168c489f175eb63f9636D}
deff998718fe21f42d80a710db70d787a484e432b9c7bd0e6a27a4751d9bd70bD|
3c93170cfdb435ab3bb64346b420376ebaa38ff8f2252277971e3b6117422fe5D{
a9bf1a1e052ad0142193049e1f988dbdbc601a8d37337ee06021e30f7eee7baf
~lCuGyuCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-21e7- Test fixups for CVE-2023-40217
Resolves: RHEL-3139vFywCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-20e@- Security fix for CVE-2023-40217
Resolves: RHEL-3139*Ey]Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-19dt- Security fix for CVE-2023-24329
- Fix the test suite support for Expat >= 2.4.5
Resolves: rhbz#2173917
Dy#Charalampos Stratakis <cstratak@redhat.com> - 3.6.8-18_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
- Resolve hash collisions for Pv4Interface and IPv6Interface (CVE-2020-14422)
Resolves: rhbz#1854926~CyCharalampos Stratakis <cstratak@redhat.com> - 3.6.8-17^- Overhaul python's FIPS mode support
Resolves: rhbz#1788459
SS(H{WMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-168.el7][- kvm-qxl-check-release-info-object.patch [bz#1712703]
- kvm-bswap.h-Remove-cpu_to_be16wu.patch [bz#1270166]
- kvm-net-Transmit-zero-UDP-checksum-as-0xFFFF.patch [bz#1270166]
- kvm-Fix-heap-overflow-in-ip_reass-on-big-packet-input.patch [bz#1734749]
- Resolves: bz#1270166
  (UDP packet checksum is not converted from 0x0000 to 0xffff with Qemu e1000 emulation.)
- Resolves: bz#1712703
  (CVE-2019-12155 qemu-kvm: QEMU: qxl: null pointer dereference while releasing spice resources [rhel-7])
- Resolves: bz#1734749
  (CVE-2019-14378 qemu-kvm: QEMU: slirp: heap buffer overflow during packet reassembly [rhel-7.8])
rJ{kMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-170.el7]@- kvm-Using-ip_deq-after-m_free-might-read-pointers-from-a.patch [bz#1749735]
- kvm-target-i386-Merge-feature-filtering-checking-functio.patch [bz#1709971]
- kvm-target-i386-Isola<tcI{MMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-169.el7]o@- kvm-target-i386-Support-invariant-tsc-flag.patch [bz#1626871]
- kvm-target-i386-block-migration-and-savevm-if-invariant-.patch [bz#1626871]
- kvm-i386-Don-t-copy-host-virtual-address-limit.patch [bz#1706658]
- Resolves: bz#1626871
  ([RFE] request for using TscInvariant feature with qemu-kvm.)
- Resolves: bz#1706658
  ([Intel 7.8 Bug] qemu-kvm fail with "err:kvm_init_vcpu() invalidate argumant" on ICX platform)te-KVM-specific-code-on-CPU-feature.patch [bz#1709971]
- kvm-i386-Add-new-MSR-indices-for-IA32_PRED_CMD-and-IA32_.patch [bz#1709971]
- kvm-i386-Add-CPUID-bit-and-feature-words-for-IA32_ARCH_C.patch [bz#1709971]
- kvm-Add-support-to-KVM_GET_MSR_FEATURE_INDEX_LIST-an.patch [bz#1709971]
- kvm-x86-Data-structure-changes-to-support-MSR-based-feat.patch [bz#1709971]
- kvm-x86-define-a-new-MSR-based-feature-word-FEATURE_WORD.patch [bz#1709971]
- kvm-Use-KVM_GET_MSR_INDEX_LIST-for-MSR_IA32_ARCH_CAP.patch [bz#1709971]
- kvm-i386-kvm-Disable-arch_capabilities-if-MSR-can-t-be-s.patch [bz#1709971]
- kvm-Remove-arch-capabilities-deprecation.patch [bz#1709971]
- kvm-target-i386-add-MDS-NO-feature.patch [bz#1714791]
- Resolves: bz#1709971
  ([Intel 7.8 Bug] [KVM][CLX] CPUID_7_0_EDX_ARCH_CAPABILITIES is not enabled in VM qemu-kvm)
- Resolves: bz#1714791
  ([Intel 7.8 FEAT] MDS_NO exposure to guest - qemu-kvm)
- Resolves: bz#1749735
  (CVE-2019-15890 qemu-kvm: QEMU: Slirp: use-after-free during packet reassembly [rhel-7])
6L{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])K{;Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-171.el7]- kvm-i386-Add-new-model-of-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-Disable-OSPKE-on-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-remove-the-INTEL_PT-CPUID-bit-from-Cascadelake-.patch [bz#1638471]
- kvm-Add-missing-brackets-to-CPUID-0x80000008-code.patch [bz#1760607]
- Resolves: bz#1638471
  ([Intel 7.8 Feat] qemu-kvm Introduce Cascade Lake (CLX) cpu model)
- Resolves: bz#1760607
  (Corrupted EAX values due to missing brackets at CPUID[0x800000008] code)
kkM{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])
FN{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`QoUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamyPg
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`Og[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])te-KVM-specific-code-on-CPU-feature.patch [bz#1709971]
- kvm-i386-Add-new-MSR-indices-for-IA32_PRED_CMD-and-IA32_.patch [bz#1709971]
- kvm-i386-Add-CPUID-bit-and-feature-words-for-IA32_ARCH_C.patch [bz#1709971]
- kvm-Add-support-to-KVM_GET_MSR_FEATURE_INDEX_LIST-an.patch [bz#1709971]
- kvm-x86-Data-structure-changes-to-support-MSR-based-feat.patch [bz#1709971]
- kvm-x86-define-a-new-MSR-based-feature-word-FEATURE_WORD.patch [bz#1709971]
- kvm-Use-KVM_GET_MSR_INDEX_LIST-for-MSR_IA32_ARCH_CAP.patch [bz#1709971]
- kvm-i386-kvm-Disable-arch_capabilities-if-MSR-can-t-be-s.patch [bz#1709971]
- kvm-Remove-arch-capabilities-deprecation.patch [bz#1709971]
- kvm-target-i386-add-MDS-NO-feature.patch [bz#1714791]
- Resolves: bz#1709971
  ([Intel 7.8 Bug] [KVM][CLX] CPUID_7_0_EDX_ARCH_CAPABILITIES is not enabled in VM qemu-kvm)
- Resolves: bz#1714791
  ([Intel 7.8 FEAT] MDS_NO exposure to guest - qemu-kvm)
- Resolves: bz#1749735
  (CVE-2019-15890 qemu-kvm: QEMU: Slirp: use-after-free during packet reassembly [rhel-7])
S{;Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-171.el7]- kvm-i386-Add-new-model-of-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-Disable-OSPKE-on-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-remove-the-INTEL_PT-CPUID-bit-from-Cascadelake-.patch [bz#1638471]
- kvm-Add-missing-brackets-to-CPUID-0x80000008-code.patch [bz#1760607]
- Resolves: bz#1638471
  ([Intel 7.8 Feat] qemu-kvm Introduce Cascade Lake (CLX) cpu model)
- Resolves: bz#1760607
  (Corrupted EAX values due to missing brackets at CPUID[0x800000008] code)rR{kMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-170.el7]@- kvm-Using-ip_deq-after-m_free-might-read-pointers-from-a.patch [bz#1749735]
- kvm-target-i386-Merge-feature-filtering-checking-functio.patch [bz#1709971]
- kvm-target-i386-Isola<y
00U{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])6T{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])
FV{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`YoUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamyXg
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`Wg[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
CC5[o}Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~ZoJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
6]{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])\{;Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-171.el7]- kvm-i386-Add-new-model-of-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-Disable-OSPKE-on-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-remove-the-INTEL_PT-CPUID-bit-from-Cascadelake-.patch [bz#1638471]
- kvm-Add-missing-brackets-to-CPUID-0x80000008-code.patch [bz#1760607]
- Resolves: bz#1638471
  ([Intel 7.8 Feat] qemu-kvm Introduce Cascade Lake (CLX) cpu model)
- Resolves: bz#1760607
  (Corrupted EAX values due to missing brackets at CPUID[0x800000008] code)
kk^{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])
F_{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`boUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamyag
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])``g[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
7C7eo!Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.4`+- kvm-ide-atapi-check-logical-block-address-and-read-size-.patch [bz#1917449]
- Resolves: bz#1917449
  (CVE-2020-29443 qemu-kvm: QEMU: ide: atapi: OOB access while processing read commands [rhel-7.9.z])5do}Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~coJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
00g{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])6f{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])
Fh{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`koUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamyjg
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`ig[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
7C7no!Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.4`+- kvm-ide-atapi-check-logical-block-address-and-read-size-.patch [bz#1917449]
- Resolves: bz#1917449
  (CVE-2020-29443 qemu-kvm: QEMU: ide: atapi: OOB access while processing read commands [rhel-7.9.z])5mo}Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~loJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
%p{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])Voo?Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.5aW@- kvm-dma-helpers-Initialize-DMAAIOCB-in_cancel-flag.patch [bz#2007036]
- Resolves: bz#2007036
  (Memory leak when using dma_read/write with virtio-scsi)
Fq{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`toUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamysg
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`rg[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
7C7wo!Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.4`+- kvm-ide-atapi-check-logical-block-address-and-read-size-.patch [bz#1917449]
- Resolves: bz#1917449
  (CVE-2020-29443 qemu-kvm: QEMU: ide: atapi: OOB access while processing read commands [rhel-7.9.z])5vo}Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~uoJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
a%a?yoJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.6b- kvm-rbd-avoid-qemu_rbd_snap_list-memory-leaks.patch [bz#2056725]
- Resolves: bz#2056725
  (qemu-kvm leaks on qemu_rbd_snap_list)Vxo?Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.5aW@- kvm-dma-helpers-Initialize-DMAAIOCB-in_cancel-flag.patch [bz#2007036]
- Resolves: bz#2007036
  (Memory leak when using dma_read/write with virtio-scsi)
SS(z{WMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-168.el7][- kvm-qxl-check-release-info-object.patch [bz#1712703]
- kvm-bswap.h-Remove-cpu_to_be16wu.patch [bz#1270166]
- kvm-net-Transmit-zero-UDP-checksum-as-0xFFFF.patch [bz#1270166]
- kvm-Fix-heap-overflow-in-ip_reass-on-big-packet-input.patch [bz#1734749]
- Resolves: bz#1270166
  (UDP packet checksum is not converted from 0x0000 to 0xffff with Qemu e1000 emulation.)
- Resolves: bz#1712703
  (CVE-2019-12155 qemu-kvm: QEMU: qxl: null pointer dereference while releasing spice resources [rhel-7])
- Resolves: bz#1734749
  (CVE-2019-14378 qemu-kvm: QEMU: slirp: heap buffer overflow during packet reassembly [rhel-7.8])
r|{kMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-170.el7]@- kvm-Using-ip_deq-after-m_free-might-read-pointers-from-a.patch [bz#1749735]
- kvm-target-i386-Merge-feature-filtering-checking-functio.patch [bz#1709971]
- kvm-target-i386-Isola<c{{MMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-169.el7]o@- kvm-target-i386-Support-invariant-tsc-flag.patch [bz#1626871]
- kvm-target-i386-block-migration-and-savevm-if-invariant-.patch [bz#1626871]
- kvm-i386-Don-t-copy-host-virtual-address-limit.patch [bz#1706658]
- Resolves: bz#1626871
  ([RFE] request for using TscInvariant feature with qemu-kvm.)
- Resolves: bz#1706658
  ([Intel 7.8 Bug] qemu-kvm fail with "err:kvm_init_vcpu() invalidate argumant" on ICX platform)te-KVM-specific-code-on-CPU-feature.patch [bz#1709971]
- kvm-i386-Add-new-MSR-indices-for-IA32_PRED_CMD-and-IA32_.patch [bz#1709971]
- kvm-i386-Add-CPUID-bit-and-feature-words-for-IA32_ARCH_C.patch [bz#1709971]
- kvm-Add-support-to-KVM_GET_MSR_FEATURE_INDEX_LIST-an.patch [bz#1709971]
- kvm-x86-Data-structure-changes-to-support-MSR-based-feat.patch [bz#1709971]
- kvm-x86-define-a-new-MSR-based-feature-word-FEATURE_WORD.patch [bz#1709971]
- kvm-Use-KVM_GET_MSR_INDEX_LIST-for-MSR_IA32_ARCH_CAP.patch [bz#1709971]
- kvm-i386-kvm-Disable-arch_capabilities-if-MSR-can-t-be-s.patch [bz#1709971]
- kvm-Remove-arch-capabilities-deprecation.patch [bz#1709971]
- kvm-target-i386-add-MDS-NO-feature.patch [bz#1714791]
- Resolves: bz#1709971
  ([Intel 7.8 Bug] [KVM][CLX] CPUID_7_0_EDX_ARCH_CAPABILITIES is not enabled in VM qemu-kvm)
- Resolves: bz#1714791
  ([Intel 7.8 FEAT] MDS_NO exposure to guest - qemu-kvm)
- Resolves: bz#1749735
  (CVE-2019-15890 qemu-kvm: QEMU: Slirp: use-after-free during packet reassembly [rhel-7])
6~{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])}{;Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-171.el7]- kvm-i386-Add-new-model-of-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-Disable-OSPKE-on-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-remove-the-INTEL_PT-CPUID-bit-from-Cascadelake-.patch [bz#1638471]
- kvm-Add-missing-brackets-to-CPUID-0x80000008-code.patch [bz#1760607]
- Resolves: bz#1638471
  ([Intel 7.8 Feat] qemu-kvm Introduce Cascade Lake (CLX) cpu model)
- Resolves: bz#1760607
  (Corrupted EAX values due to missing brackets at CPUID[0x800000008] code)
kk{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])
F{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`oUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamyg
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`g[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])te-KVM-specific-code-on-CPU-feature.patch [bz#1709971]
- kvm-i386-Add-new-MSR-indices-for-IA32_PRED_CMD-and-IA32_.patch [bz#1709971]
- kvm-i386-Add-CPUID-bit-and-feature-words-for-IA32_ARCH_C.patch [bz#1709971]
- kvm-Add-support-to-KVM_GET_MSR_FEATURE_INDEX_LIST-an.patch [bz#1709971]
- kvm-x86-Data-structure-changes-to-support-MSR-based-feat.patch [bz#1709971]
- kvm-x86-define-a-new-MSR-based-feature-word-FEATURE_WORD.patch [bz#1709971]
- kvm-Use-KVM_GET_MSR_INDEX_LIST-for-MSR_IA32_ARCH_CAP.patch [bz#1709971]
- kvm-i386-kvm-Disable-arch_capabilities-if-MSR-can-t-be-s.patch [bz#1709971]
- kvm-Remove-arch-capabilities-deprecation.patch [bz#1709971]
- kvm-target-i386-add-MDS-NO-feature.patch [bz#1714791]
- Resolves: bz#1709971
  ([Intel 7.8 Bug] [KVM][CLX] CPUID_7_0_EDX_ARCH_CAPABILITIES is not enabled in VM qemu-kvm)
- Resolves: bz#1714791
  ([Intel 7.8 FEAT] MDS_NO exposure to guest - qemu-kvm)
- Resolves: bz#1749735
  (CVE-2019-15890 qemu-kvm: QEMU: Slirp: use-after-free during packet reassembly [rhel-7])
{;Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-171.el7]- kvm-i386-Add-new-model-of-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-Disable-OSPKE-on-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-remove-the-INTEL_PT-CPUID-bit-from-Cascadelake-.patch [bz#1638471]
- kvm-Add-missing-brackets-to-CPUID-0x80000008-code.patch [bz#1760607]
- Resolves: bz#1638471
  ([Intel 7.8 Feat] qemu-kvm Introduce Cascade Lake (CLX) cpu model)
- Resolves: bz#1760607
  (Corrupted EAX values due to missing brackets at CPUID[0x800000008] code)r{kMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-170.el7]@- kvm-Using-ip_deq-after-m_free-might-read-pointers-from-a.patch [bz#1749735]
- kvm-target-i386-Merge-feature-filtering-checking-functio.patch [bz#1709971]
- kvm-target-i386-Isola<
00{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])6{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])
F{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`oUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamy
g
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`	g[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
CC5
o}Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~oJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
6{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8]){;Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-171.el7]- kvm-i386-Add-new-model-of-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-Disable-OSPKE-on-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-remove-the-INTEL_PT-CPUID-bit-from-Cascadelake-.patch [bz#1638471]
- kvm-Add-missing-brackets-to-CPUID-0x80000008-code.patch [bz#1760607]
- Resolves: bz#1638471
  ([Intel 7.8 Feat] qemu-kvm Introduce Cascade Lake (CLX) cpu model)
- Resolves: bz#1760607
  (Corrupted EAX values due to missing brackets at CPUID[0x800000008] code)
kk{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])
F{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`oUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamyg
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`g[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
7C7o!Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.4`+- kvm-ide-atapi-check-logical-block-address-and-read-size-.patch [bz#1917449]
- Resolves: bz#1917449
  (CVE-2020-29443 qemu-kvm: QEMU: ide: atapi: OOB access while processing read commands [rhel-7.9.z])5o}Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~oJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
00{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])6{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])
F{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`oUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamyg
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`g[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
7C7 o!Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.4`+- kvm-ide-atapi-check-logical-block-address-and-read-size-.patch [bz#1917449]
- Resolves: bz#1917449
  (CVE-2020-29443 qemu-kvm: QEMU: ide: atapi: OOB access while processing read commands [rhel-7.9.z])5o}Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~oJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
%"{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])V!o?Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.5aW@- kvm-dma-helpers-Initialize-DMAAIOCB-in_cancel-flag.patch [bz#2007036]
- Resolves: bz#2007036
  (Memory leak when using dma_read/write with virtio-scsi)
F#{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`&oUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamy%g
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`$g[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
7C7)o!Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.4`+- kvm-ide-atapi-check-logical-block-address-and-read-size-.patch [bz#1917449]
- Resolves: bz#1917449
  (CVE-2020-29443 qemu-kvm: QEMU: ide: atapi: OOB access while processing read commands [rhel-7.9.z])5(o}Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~'oJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
a%a?+oJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.6b- kvm-rbd-avoid-qemu_rbd_snap_list-memory-leaks.patch [bz#2056725]
- Resolves: bz#2056725
  (qemu-kvm leaks on qemu_rbd_snap_list)V*o?Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.5aW@- kvm-dma-helpers-Initialize-DMAAIOCB-in_cancel-flag.patch [bz#2007036]
- Resolves: bz#2007036
  (Memory leak when using dma_read/write with virtio-scsi)
SS(,{WMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-168.el7][- kvm-qxl-check-release-info-object.patch [bz#1712703]
- kvm-bswap.h-Remove-cpu_to_be16wu.patch [bz#1270166]
- kvm-net-Transmit-zero-UDP-checksum-as-0xFFFF.patch [bz#1270166]
- kvm-Fix-heap-overflow-in-ip_reass-on-big-packet-input.patch [bz#1734749]
- Resolves: bz#1270166
  (UDP packet checksum is not converted from 0x0000 to 0xffff with Qemu e1000 emulation.)
- Resolves: bz#1712703
  (CVE-2019-12155 qemu-kvm: QEMU: qxl: null pointer dereference while releasing spice resources [rhel-7])
- Resolves: bz#1734749
  (CVE-2019-14378 qemu-kvm: QEMU: slirp: heap buffer overflow during packet reassembly [rhel-7.8])
r.{kMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-170.el7]@- kvm-Using-ip_deq-after-m_free-might-read-pointers-from-a.patch [bz#1749735]
- kvm-target-i386-Merge-feature-filtering-checking-functio.patch [bz#1709971]
- kvm-target-i386-Isola<c-{MMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-169.el7]o@- kvm-target-i386-Support-invariant-tsc-flag.patch [bz#1626871]
- kvm-target-i386-block-migration-and-savevm-if-invariant-.patch [bz#1626871]
- kvm-i386-Don-t-copy-host-virtual-address-limit.patch [bz#1706658]
- Resolves: bz#1626871
  ([RFE] request for using TscInvariant feature with qemu-kvm.)
- Resolves: bz#1706658
  ([Intel 7.8 Bug] qemu-kvm fail with "err:kvm_init_vcpu() invalidate argumant" on ICX platform)te-KVM-specific-code-on-CPU-feature.patch [bz#1709971]
- kvm-i386-Add-new-MSR-indices-for-IA32_PRED_CMD-and-IA32_.patch [bz#1709971]
- kvm-i386-Add-CPUID-bit-and-feature-words-for-IA32_ARCH_C.patch [bz#1709971]
- kvm-Add-support-to-KVM_GET_MSR_FEATURE_INDEX_LIST-an.patch [bz#1709971]
- kvm-x86-Data-structure-changes-to-support-MSR-based-feat.patch [bz#1709971]
- kvm-x86-define-a-new-MSR-based-feature-word-FEATURE_WORD.patch [bz#1709971]
- kvm-Use-KVM_GET_MSR_INDEX_LIST-for-MSR_IA32_ARCH_CAP.patch [bz#1709971]
- kvm-i386-kvm-Disable-arch_capabilities-if-MSR-can-t-be-s.patch [bz#1709971]
- kvm-Remove-arch-capabilities-deprecation.patch [bz#1709971]
- kvm-target-i386-add-MDS-NO-feature.patch [bz#1714791]
- Resolves: bz#1709971
  ([Intel 7.8 Bug] [KVM][CLX] CPUID_7_0_EDX_ARCH_CAPABILITIES is not enabled in VM qemu-kvm)
- Resolves: bz#1714791
  ([Intel 7.8 FEAT] MDS_NO exposure to guest - qemu-kvm)
- Resolves: bz#1749735
  (CVE-2019-15890 qemu-kvm: QEMU: Slirp: use-after-free during packet reassembly [rhel-7])
60{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])/{;Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-171.el7]- kvm-i386-Add-new-model-of-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-Disable-OSPKE-on-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-remove-the-INTEL_PT-CPUID-bit-from-Cascadelake-.patch [bz#1638471]
- kvm-Add-missing-brackets-to-CPUID-0x80000008-code.patch [bz#1760607]
- Resolves: bz#1638471
  ([Intel 7.8 Feat] qemu-kvm Introduce Cascade Lake (CLX) cpu model)
- Resolves: bz#1760607
  (Corrupted EAX values due to missing brackets at CPUID[0x800000008] code)
kk1{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])
F2{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`5oUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamy4g
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`3g[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])te-KVM-specific-code-on-CPU-feature.patch [bz#1709971]
- kvm-i386-Add-new-MSR-indices-for-IA32_PRED_CMD-and-IA32_.patch [bz#1709971]
- kvm-i386-Add-CPUID-bit-and-feature-words-for-IA32_ARCH_C.patch [bz#1709971]
- kvm-Add-support-to-KVM_GET_MSR_FEATURE_INDEX_LIST-an.patch [bz#1709971]
- kvm-x86-Data-structure-changes-to-support-MSR-based-feat.patch [bz#1709971]
- kvm-x86-define-a-new-MSR-based-feature-word-FEATURE_WORD.patch [bz#1709971]
- kvm-Use-KVM_GET_MSR_INDEX_LIST-for-MSR_IA32_ARCH_CAP.patch [bz#1709971]
- kvm-i386-kvm-Disable-arch_capabilities-if-MSR-can-t-be-s.patch [bz#1709971]
- kvm-Remove-arch-capabilities-deprecation.patch [bz#1709971]
- kvm-target-i386-add-MDS-NO-feature.patch [bz#1714791]
- Resolves: bz#1709971
  ([Intel 7.8 Bug] [KVM][CLX] CPUID_7_0_EDX_ARCH_CAPABILITIES is not enabled in VM qemu-kvm)
- Resolves: bz#1714791
  ([Intel 7.8 FEAT] MDS_NO exposure to guest - qemu-kvm)
- Resolves: bz#1749735
  (CVE-2019-15890 qemu-kvm: QEMU: Slirp: use-after-free during packet reassembly [rhel-7])
7{;Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-171.el7]- kvm-i386-Add-new-model-of-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-Disable-OSPKE-on-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-remove-the-INTEL_PT-CPUID-bit-from-Cascadelake-.patch [bz#1638471]
- kvm-Add-missing-brackets-to-CPUID-0x80000008-code.patch [bz#1760607]
- Resolves: bz#1638471
  ([Intel 7.8 Feat] qemu-kvm Introduce Cascade Lake (CLX) cpu model)
- Resolves: bz#1760607
  (Corrupted EAX values due to missing brackets at CPUID[0x800000008] code)r6{kMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-170.el7]@- kvm-Using-ip_deq-after-m_free-might-read-pointers-from-a.patch [bz#1749735]
- kvm-target-i386-Merge-feature-filtering-checking-functio.patch [bz#1709971]
- kvm-target-i386-Isola<
009{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])68{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])
F:{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`=oUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamy<g
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`;g[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
CC5?o}Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~>oJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])

er+V:eD
a890176b2aa7995cdcca42b0e17be87bb8aae92260d663aa371f764d1a042638D
d5efe4a3fd7895b05dc1b8b045dc980999601e654844bd49e0d6400295ab6e81D
6d003f6bec920c3f0353f927a0e4ce5191ad4e906e1f42da6845c022fe42c6c5D
9cbd6eff83677c01360b1fef5a8c341cd87c5de0ad0732e7ac0d66ae86c24ef7D
ef450f18a4cbb4b3e2590e06da308d71a68963d41ea453f5a033f04eeb3d6af2D
0449fb732714886324a83ab5585589c4bff8fd81cfd32d8cc00260106295b33bD
7b7ec44f73e60f1826d6c1d04e2dd0dcdf55c7db06718558d74313208c397656D

5ea661034ba07766b55a6d64aeefb1af0d3e0e6608e4f50fca341a03abf1f701D
4602b5323f417a87240cc0e7d73bd59b5353a8e84649b1ddda629f812a651716D
63a41ccee737a4e9e6d6fb1b86ec39bafd39ebc8819e7fc387fbba943d9840f4D

0b35b40bf56766439cd4f160aa0bb3028afd3654b4df1a07cbe49d5a0c3642fbD	
8a1a847b55b0f0c7eb4ee01caaddbacba34459dac20fbc69bf3e33941d234f40D
b1195f160b7732b069a76d55a22f0c4f5d8a7a92506dd8ec030b713507963ae7
6A{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])@{;Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-171.el7]- kvm-i386-Add-new-model-of-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-Disable-OSPKE-on-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-remove-the-INTEL_PT-CPUID-bit-from-Cascadelake-.patch [bz#1638471]
- kvm-Add-missing-brackets-to-CPUID-0x80000008-code.patch [bz#1760607]
- Resolves: bz#1638471
  ([Intel 7.8 Feat] qemu-kvm Introduce Cascade Lake (CLX) cpu model)
- Resolves: bz#1760607
  (Corrupted EAX values due to missing brackets at CPUID[0x800000008] code)
kkB{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])
FC{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`FoUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamyEg
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`Dg[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
7C7Io!Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.4`+- kvm-ide-atapi-check-logical-block-address-and-read-size-.patch [bz#1917449]
- Resolves: bz#1917449
  (CVE-2020-29443 qemu-kvm: QEMU: ide: atapi: OOB access while processing read commands [rhel-7.9.z])5Ho}Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~GoJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
00K{'	Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])6J{s	Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])
FL{	Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`OoU	Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamyNg
	Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`Mg[	Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
7C7Ro!	Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.4`+- kvm-ide-atapi-check-logical-block-address-and-read-size-.patch [bz#1917449]
- Resolves: bz#1917449
  (CVE-2020-29443 qemu-kvm: QEMU: ide: atapi: OOB access while processing read commands [rhel-7.9.z])5Qo}	Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~Po	Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
%T{'
Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])VSo?	Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.5aW@- kvm-dma-helpers-Initialize-DMAAIOCB-in_cancel-flag.patch [bz#2007036]
- Resolves: bz#2007036
  (Memory leak when using dma_read/write with virtio-scsi)bR<RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{<<<<<<<<
<<<<<<<<< <"<#<&<)<+<,<.<0<1<2<5<7<9<:<=<?<A<B<C<F<I<K<L<O<R<T<U<‚X<Â[<Ă]<ł^<Ƃ`<Ȃb<ɂc<ʂd<˂g<͂i<΂k<ςl<Ђo<тq<҂s<ӂt<Ԃu<Ղx<ւ{<ׂ}<؂~<ق<ڂ<ۂ<܂<݂
<ނ
<߂<<<<!<%<)<-<1<5<<<C<J<R<Y<`<g<o<v<|<<<<<!<(<.
FU{
Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`XoU
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamyWg

Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`Vg[
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
7C7[o!
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.4`+- kvm-ide-atapi-check-logical-block-address-and-read-size-.patch [bz#1917449]
- Resolves: bz#1917449
  (CVE-2020-29443 qemu-kvm: QEMU: ide: atapi: OOB access while processing read commands [rhel-7.9.z])5Zo}
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~Yo
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
a%a?]o
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.6b- kvm-rbd-avoid-qemu_rbd_snap_list-memory-leaks.patch [bz#2056725]
- Resolves: bz#2056725
  (qemu-kvm leaks on qemu_rbd_snap_list)V\o?
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.5aW@- kvm-dma-helpers-Initialize-DMAAIOCB-in_cancel-flag.patch [bz#2007036]
- Resolves: bz#2007036
  (Memory leak when using dma_read/write with virtio-scsi)
SS(^{WMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-168.el7][- kvm-qxl-check-release-info-object.patch [bz#1712703]
- kvm-bswap.h-Remove-cpu_to_be16wu.patch [bz#1270166]
- kvm-net-Transmit-zero-UDP-checksum-as-0xFFFF.patch [bz#1270166]
- kvm-Fix-heap-overflow-in-ip_reass-on-big-packet-input.patch [bz#1734749]
- Resolves: bz#1270166
  (UDP packet checksum is not converted from 0x0000 to 0xffff with Qemu e1000 emulation.)
- Resolves: bz#1712703
  (CVE-2019-12155 qemu-kvm: QEMU: qxl: null pointer dereference while releasing spice resources [rhel-7])
- Resolves: bz#1734749
  (CVE-2019-14378 qemu-kvm: QEMU: slirp: heap buffer overflow during packet reassembly [rhel-7.8])
r`{kMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-170.el7]@- kvm-Using-ip_deq-after-m_free-might-read-pointers-from-a.patch [bz#1749735]
- kvm-target-i386-Merge-feature-filtering-checking-functio.patch [bz#1709971]
- kvm-target-i386-Isola<ǃc_{MMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-169.el7]o@- kvm-target-i386-Support-invariant-tsc-flag.patch [bz#1626871]
- kvm-target-i386-block-migration-and-savevm-if-invariant-.patch [bz#1626871]
- kvm-i386-Don-t-copy-host-virtual-address-limit.patch [bz#1706658]
- Resolves: bz#1626871
  ([RFE] request for using TscInvariant feature with qemu-kvm.)
- Resolves: bz#1706658
  ([Intel 7.8 Bug] qemu-kvm fail with "err:kvm_init_vcpu() invalidate argumant" on ICX platform)te-KVM-specific-code-on-CPU-feature.patch [bz#1709971]
- kvm-i386-Add-new-MSR-indices-for-IA32_PRED_CMD-and-IA32_.patch [bz#1709971]
- kvm-i386-Add-CPUID-bit-and-feature-words-for-IA32_ARCH_C.patch [bz#1709971]
- kvm-Add-support-to-KVM_GET_MSR_FEATURE_INDEX_LIST-an.patch [bz#1709971]
- kvm-x86-Data-structure-changes-to-support-MSR-based-feat.patch [bz#1709971]
- kvm-x86-define-a-new-MSR-based-feature-word-FEATURE_WORD.patch [bz#1709971]
- kvm-Use-KVM_GET_MSR_INDEX_LIST-for-MSR_IA32_ARCH_CAP.patch [bz#1709971]
- kvm-i386-kvm-Disable-arch_capabilities-if-MSR-can-t-be-s.patch [bz#1709971]
- kvm-Remove-arch-capabilities-deprecation.patch [bz#1709971]
- kvm-target-i386-add-MDS-NO-feature.patch [bz#1714791]
- Resolves: bz#1709971
  ([Intel 7.8 Bug] [KVM][CLX] CPUID_7_0_EDX_ARCH_CAPABILITIES is not enabled in VM qemu-kvm)
- Resolves: bz#1714791
  ([Intel 7.8 FEAT] MDS_NO exposure to guest - qemu-kvm)
- Resolves: bz#1749735
  (CVE-2019-15890 qemu-kvm: QEMU: Slirp: use-after-free during packet reassembly [rhel-7])
6b{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])a{;Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-171.el7]- kvm-i386-Add-new-model-of-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-Disable-OSPKE-on-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-remove-the-INTEL_PT-CPUID-bit-from-Cascadelake-.patch [bz#1638471]
- kvm-Add-missing-brackets-to-CPUID-0x80000008-code.patch [bz#1760607]
- Resolves: bz#1638471
  ([Intel 7.8 Feat] qemu-kvm Introduce Cascade Lake (CLX) cpu model)
- Resolves: bz#1760607
  (Corrupted EAX values due to missing brackets at CPUID[0x800000008] code)
kkc{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])
Fd{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`goUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamyfg
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`eg[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])te-KVM-specific-code-on-CPU-feature.patch [bz#1709971]
- kvm-i386-Add-new-MSR-indices-for-IA32_PRED_CMD-and-IA32_.patch [bz#1709971]
- kvm-i386-Add-CPUID-bit-and-feature-words-for-IA32_ARCH_C.patch [bz#1709971]
- kvm-Add-support-to-KVM_GET_MSR_FEATURE_INDEX_LIST-an.patch [bz#1709971]
- kvm-x86-Data-structure-changes-to-support-MSR-based-feat.patch [bz#1709971]
- kvm-x86-define-a-new-MSR-based-feature-word-FEATURE_WORD.patch [bz#1709971]
- kvm-Use-KVM_GET_MSR_INDEX_LIST-for-MSR_IA32_ARCH_CAP.patch [bz#1709971]
- kvm-i386-kvm-Disable-arch_capabilities-if-MSR-can-t-be-s.patch [bz#1709971]
- kvm-Remove-arch-capabilities-deprecation.patch [bz#1709971]
- kvm-target-i386-add-MDS-NO-feature.patch [bz#1714791]
- Resolves: bz#1709971
  ([Intel 7.8 Bug] [KVM][CLX] CPUID_7_0_EDX_ARCH_CAPABILITIES is not enabled in VM qemu-kvm)
- Resolves: bz#1714791
  ([Intel 7.8 FEAT] MDS_NO exposure to guest - qemu-kvm)
- Resolves: bz#1749735
  (CVE-2019-15890 qemu-kvm: QEMU: Slirp: use-after-free during packet reassembly [rhel-7])
i{;Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-171.el7]- kvm-i386-Add-new-model-of-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-Disable-OSPKE-on-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-remove-the-INTEL_PT-CPUID-bit-from-Cascadelake-.patch [bz#1638471]
- kvm-Add-missing-brackets-to-CPUID-0x80000008-code.patch [bz#1760607]
- Resolves: bz#1638471
  ([Intel 7.8 Feat] qemu-kvm Introduce Cascade Lake (CLX) cpu model)
- Resolves: bz#1760607
  (Corrupted EAX values due to missing brackets at CPUID[0x800000008] code)rh{kMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-170.el7]@- kvm-Using-ip_deq-after-m_free-might-read-pointers-from-a.patch [bz#1749735]
- kvm-target-i386-Merge-feature-filtering-checking-functio.patch [bz#1709971]
- kvm-target-i386-Isola<
00k{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])6j{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])
Fl{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`ooUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamyng
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`mg[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
CC5qo}Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~poJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
6s{s
Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])r{;
Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-171.el7]- kvm-i386-Add-new-model-of-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-Disable-OSPKE-on-Cascadelake-Server.patch [bz#1638471]
- kvm-i386-remove-the-INTEL_PT-CPUID-bit-from-Cascadelake-.patch [bz#1638471]
- kvm-Add-missing-brackets-to-CPUID-0x80000008-code.patch [bz#1760607]
- Resolves: bz#1638471
  ([Intel 7.8 Feat] qemu-kvm Introduce Cascade Lake (CLX) cpu model)
- Resolves: bz#1760607
  (Corrupted EAX values due to missing brackets at CPUID[0x800000008] code)
kkt{'
Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])
Fu{
Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`xoU
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamywg

Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`vg[
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
7C7{o!
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.4`+- kvm-ide-atapi-check-logical-block-address-and-read-size-.patch [bz#1917449]
- Resolves: bz#1917449
  (CVE-2020-29443 qemu-kvm: QEMU: ide: atapi: OOB access while processing read commands [rhel-7.9.z])5zo}
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~yo
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
00}{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])6|{sMiroslav Rezanina <mrezanin@redhat.com> - 1.5.3-172.el7]@- kvm-target-i386-Export-TAA_NO-bit-to-guests.patch [bz#1771961]
- kvm-target-i386-add-support-for-MSR_IA32_TSX_CTRL.patch [bz#1771961]
- Resolves: bz#1771961
  (CVE-2019-11135 qemu-kvm: hw: TSX Transaction Asynchronous Abort (TAA) [rhel-7.8])
F~{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`oUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamyg
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`g[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
7C7o!Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.4`+- kvm-ide-atapi-check-logical-block-address-and-read-size-.patch [bz#1917449]
- Resolves: bz#1917449
  (CVE-2020-29443 qemu-kvm: QEMU: ide: atapi: OOB access while processing read commands [rhel-7.9.z])5o}Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~oJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
%{'Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-173.el7^)- kvm-tcp_emu-Fix-oob-access.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-IRC-commands.patch [bz#1791560]
- kvm-slirp-use-correct-size-while-emulating-commands.patch [bz#1791560]
- Resolves: bz#1791560
  (CVE-2020-7039 qemu-kvm: QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [rhel-7.8])Vo?Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.5aW@- kvm-dma-helpers-Initialize-DMAAIOCB-in_cancel-flag.patch [bz#2007036]
- Resolves: bz#2007036
  (Memory leak when using dma_read/write with virtio-scsi)
F{Miroslav Rezanina <mrezanin@redhat.com> - 1.5.3-174.el7^s^- kvm-util-add-slirp_fmt-helpers2.patch [bz#1800515]
- kvm-tcp_emu-fix-unsafe-snprintf-usages2.patch [bz#1800515]
- kvm-slirp-disable-tcp_emu.patch [bz#1791679]
- kvm-gluster-Handle-changed-glfs_ftruncate-signature.patch [bz#1802215]
- kvm-gluster-the-glfs_io_cbk-callback-function-pointer-ad.patch [bz#1802215]
- kvm-seccomp-set-the-seccomp-filter-to-all-threads.patch [bz#1618503]
- Resolves: bz#1618503
  (qemu-kvm: Qemu: seccomp: blacklist is not applied to all threads [rhel-7])
- Resolves: bz#1791679
  (QEMU: Slirp: disable emulation of tcp programs like ftp IRC etc. [rhel-7])
- Resolves: bz#1800515
  (CVE-2020-8608 qemu-kvm: QEMU: Slirp: potential OOB access due to unsafe snprintf() usages [rhel-7.9])
- Resolves: bz#1802215
  (Add support for newer glusterfs)
`
oUJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.1_WrA- Fixing release number for z-streamy	g
Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_Wr@- kvm-Fix-use-afte-free-in-ip_reass-CVE-2020-1983.patch [bz#1837565]
- kvm-usb-check-RNDIS-message-length.patch [bz#1869693]
- kvm-usb-fix-setup_len-init-CVE-2020-14364.patch [bz#1869693]
- Resolves: bz#1837565
  (CVE-2020-1983 qemu-kvm: QEMU: slirp: use-after-free in ip_reass() function in ip_input.c [rhel-7])
- Resolves: bz#1869693
  (CVE-2020-14364 qemu-kvm: QEMU: usb: out-of-bounds r/w access issue while processing usb packets [rhel-7.9.z])`g[Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7^- kvm-vnc-fix-memory-leak-when-vnc-disconnect.patch [bz#1810408]
- Resolves: bz#1810408
  (CVE-2019-20382 qemu-kvm: QEMU: vnc: memory leakage upon disconnect [rhel-7])
7C7
o!Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.4`+- kvm-ide-atapi-check-logical-block-address-and-read-size-.patch [bz#1917449]
- Resolves: bz#1917449
  (CVE-2020-29443 qemu-kvm: QEMU: ide: atapi: OOB access while processing read commands [rhel-7.9.z])5o}Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.3_T- kvm-Suppress-prototype-warning-for-nss-headers.patch [bz#1884997]
- Resolves: bz#1884997
  (qemu-kvm FTBFS on rhel7.9)~oJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.2_@- kvm-hw-net-vmxnet_tx_pkt-fix-assertion-failure-in-vmxnet.patch [bz#1860960]
- kvm-hw-core-loader-Fix-possible-crash-in-rom_copy.patch [bz#1842923]
- Resolves: bz#1842923
  (CVE-2020-13765 qemu-kvm: QEMU: loader: OOB access while loading registered ROM may lead to code execution [rhel-7.9.z])
- Resolves: bz#1860960
  (CVE-2020-16092 qemu-kvm: QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c [rhel-7.9.z])
%aUsgJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862?oJon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.6b- kvm-rbd-avoid-qemu_rbd_snap_list-memory-leaks.patch [bz#2056725]
- Resolves: bz#2056725
  (qemu-kvm leaks on qemu_rbd_snap_list)Vo?Jon Maloy <jmaloy@redhat.com> - 1.5.3-175.el7_9.5aW@- kvm-dma-helpers-Initialize-DMAAIOCB-in_cancel-flag.patch [bz#2007036]
- Resolves: bz#2007036
  (Memory leak when using dma_read/write with virtio-scsi)
}qsgJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862sgJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862
}qsgJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862sgJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862

er+V:eD!
101d4c439d586a23bd095ccd9577412c6ab04356eb16a1563922718a2e88282fD 
66ff6d3d39c89b89cff9ea3640241dc426267d705caad62f73e5fb5ec36489daD
1006b3d0a088752eeb2598abc422708ea48c9813a37b05520a479db06e8b6d2cD
cf9c2b5f9dfcab24dece292fa32fbddfd9d7101708606617b5bc07bcc4a15756D
da19c51c2a6a05fd9cbc856b73aab1fda9c5974c9fd026652be8e555e60410ceD
ed85063f79df4dd6522878618ebc5308ad2d764ce401220c527ff0cca6d5f7d0D
a58d0d4575abce242db65f08764359915f175bed5665391d68c8b0848ca043e5D
d2e121f5577f678e6c3a8c113a90dec22cf3020128b6c0a00148ff5490889516D
075e649f6da15e063d52ce4d0d3ba406ef07fe22522b3b701f9577056c5cf18aD
4afd47d6a1f2abe50950226f0ebe58f8973c16a4aa727eadd72419fda729468fD
5d7e06887d90404f63aebfadc1d4b6b84280cfe7082d40d0288f3d973a586453D
06e5fb6ecf1b329364a643c5ede73c7f38229a9b7aee51b73806126d416f71e8D
b880a0b670e4d960e2f45b887ba9131d3fde1d7bb679f52407002490f974445b
}qsgJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862sgJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862
}qs!gJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297 g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862sgJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862
}qs%gJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297$g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862s#gJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297"g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862
}qs)gJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297(g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862s'gJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297&g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862
}qs-gJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297,g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862s+gJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297*g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862
}qs1g Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#18702970g) Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862s/gJan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870297.g)Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862
}qs5g"Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#18702974g)"Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862s3g!Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#18702972g)!Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862

er+V:eD.
51a53d551be2e1872620790737f76e64debc40419b8fd39d769e922deee5e6cfD-
e0a86a5b4129921e13dc76157dee997faa829d4d9a825ace7a0a53f87b4846d9D,
e5a0b645a5f31d68cab7845d9767b0fa6efa5b4d5b70698b58c9ce1f62421820D+
f583bf56ffb7c05d556141a0b44a90d47787543323e3780b29177cbad9e84c99D*
0e0057ab9e8cb8424689c8f6e05bb121fb1bd2f7a3e0fbec225b582428df0176D)
d63cfee88470e6abc2c1c016bfb5ec0aa462545cf7fb74bd3fb6432fde840057D(
14eeefbe453cdf299889c12f5ada3a9024e4bfa0a7a528348d4799660822a0d7D'
5640bc5d7f5bdc1cba31958835239b6e304ee9faabd531c630f74e9e6867e32bD&
6940a7ecc43ade6a78b801d66f177ded5fb4e3631de7f454dfee50cfca1694c4D%
dac3bbae30e7a82b68413ff66cde2cd6f8ebd5f1c4af294556c60e63c0e4246eD$
05b12f50d113b0a0d5208b907519a36a79df62b2d79ddbb1d4019332f3d7ff39D#
051767c8b8b2c33280f93fb2f1f60e7d9bdd8f44678ca6c68f5e2e59986a7ef8D"
9311ccab42970f1272cfc018419932b0fb8fe37ba50649863fba7a09fcb64c4b
S}NS<c$Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987r;c$Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^:c]$Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097b9ce$Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097c8cg$Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097s7g#Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-9_l@- Fix buffer overflow in XBM parser
  Resolves: bz#18702976g)#Jan Grulich <jgrulich@redhat.com> - 1:4.8.7-8]B- Fix QImage allocation failure in qgifhandler
  Resolves: bz#1667863

- Fix QTgaFile CPU exhaustion
  Resolves: bz#1667879

- Fix QBmpHandler segmentation fault on malformed BMP file
  Resolves: bz#1667862
>2R>bCce%Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097cBcg%Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097qAc$Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365M@c9$Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[?cU$Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680h>cq$Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^=c]$Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000
#(A#MJc9%Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[IcU%Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680hHcq%Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^Gc]%Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000Fc%Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987rEc%Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^Dc]%Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097
$\ahRcq&Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^Qc]&Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000Pc&Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987rOc&Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^Nc]&Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097bMce&Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097cLcg&Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097qKc%Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365
4 Nr4rYc'Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^Xc]'Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097bWce'Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097cVcg'Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097qUc&Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365MTc9&Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[ScU&Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680
{c`cg(Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097q_c'Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365M^c9'Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[]cU'Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680h\cq'Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^[c]'Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000Zc'Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987
8=o[gcU(Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680hfcq(Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^ec](Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000dc(Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987rcc(Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^bc](Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097bace(Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097
-.R-^oc])Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000nc)Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987rmc)Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^lc])Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097bkce)Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097cjcg)Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097qic(Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365Mhc9(Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685
>m>^vc]*Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097buce*Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097ctcg*Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097qsc)Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365Mrc9)Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[qcU)Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680hpcq)Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000
7WM|c9*Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[{cU*Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680hzcq*Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^yc]*Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000xc*Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987rwc*Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040
$\ahcq+Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^c]+Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000c+Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987rc+Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^c]+Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097bce+Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097c~cg+Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097q}c*Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365
4 Nr4rc,Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^
c],Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097b	ce,Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097ccg,Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097qc+Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365Mc9+Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[cU+Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680
{ccg-Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097qc,Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365Mc9,Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[cU,Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680hcq,Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^
c],Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000c,Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987
8=o[cU-Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680hcq-Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^c]-Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000c-Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987rc-Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^c]-Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097bce-Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097
-.R-^!c].Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000 c.Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987rc.Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^c].Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097bce.Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097ccg.Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097qc-Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365Mc9-Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685
>m>^(c]/Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097b'ce/Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097c&cg/Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097q%c.Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365M$c9.Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[#cU.Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680h"cq.Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000

er+V:eD;
8670eed5135654aa066965442ce0915cbf933f4742d0a6dab8b6dfc7ecc2f773D:
e653897f2dd6f84ab92a95f869a1a8b62ee9ab93e65633bab0f315f3b744c72aD9
24d9b1ac9ee09da7c86076a3d26116d0eff8b39fbd7ce382098d1fb81ce2481bD8
3358f19c8ca9746105376676f9d44c518ec567358ba86b5a92b874dbdb9c8a44D7
df7a357bd7450087019d5bb9f1bb2a2fb80ae9a9ee7a1a2a6117f7d9bbf995e7D6
f7db225b7e95f311ff6f6b1334882841ae105198666b212f6c134f496b5c2ea7D5
9e5e0690a1ca23a083173192c311f06da00d80fa4bc1fb9971a527571077eb0cD4
7a94ec0c411357ec66396223ab1a2614a6df7dcab88aacd0aeabf389ad033540D3
06dc7124955549934298d13f36f05d5c055ad9f2dc7291af7ea111042dff38c0D2
0d3a93f5635729a3341a43ad550bf5e1a022c431b725a9126b80bbb5bce8cdc2D1
2f3ecc42146a179224d79240ca93c8847a1d18a128540feb63355af3b7ac4a67D0
ca6596355a07541ba770e0a63ceee3a9117eed3bfcecff0d30b56b32bc0d6016D/
dd911d44d893c09a124700634046d5e3c9936eb30f6d85537e2f2aca791b4349
7WM.c9/Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[-cU/Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680h,cq/Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^+c]/Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000*c/Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987r)c/Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040
$\ah6cq0Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^5c]0Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#15640004c0Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987r3c0Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^2c]0Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097b1ce0Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097c0cg0Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097q/c/Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365
4 Nr4r=c1Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^<c]1Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097b;ce1Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097c:cg1Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097q9c0Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365M8c90Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[7cU0Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680
{cDcg2Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097qCc1Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365MBc91Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[AcU1Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680h@cq1Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^?c]1Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000>c1Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987
8=o[KcU2Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680hJcq2Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^Ic]2Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000Hc2Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987rGc2Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^Fc]2Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097bEce2Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097
-.R-^Sc]3Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000Rc3Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987rQc3Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^Pc]3Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097bOce3Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097cNcg3Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097qMc2Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365MLc92Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685
>m>^Zc]4Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097bYce4Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097cXcg4Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097qWc3Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365MVc93Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[UcU3Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680hTcq3Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000
7WM`c94Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[_cU4Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680h^cq4Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^]c]4Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000\c4Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987r[c4Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040
	ZCqZ^ic]5Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1482782^hc]5Jan Grulich <jgrulich@redhat.com> - 5.9.1-1Y- Update to 5.9.1
  Resolves: bz#1482782^gc]5Jan Grulich <jgrulich@redhat.com> - 5.6.2-1Xv@- Update to 5.6.2
  Resolves: bz#1384821
fe15Jan Grulich <jgrulich@redhat.com> - 5.6.1-10Wu@- Increase build version to have newer version than in EPEL
  Resolves: bz#1317404^ec]5Jan Grulich <jgrulich@redhat.com> - 5.6.1-1WX- Update to 5.6.1
  Resolves: bz#1317404cdcg5Jan Grulich <jgrulich@redhat.com> - 5.6.0-5W4- Enable documentation
  Resolves: bz#1317404gcco5Jan Grulich <jgrulich@redhat.com> - 5.6.0-4WK- Initial version for RHEL
  Resolves: bz#1317404Dbm5Rex Dieter <rdieter@fedoraproject.org> - 5.6.0-3V- rebuildqac4Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365
	:q^rc]6Jan Grulich <jgrulich@redhat.com> - 5.9.1-1Y- Update to 5.9.1
  Resolves: bz#1482782^qc]6Jan Grulich <jgrulich@redhat.com> - 5.6.2-1Xv@- Update to 5.6.2
  Resolves: bz#1384821
pe16Jan Grulich <jgrulich@redhat.com> - 5.6.1-10Wu@- Increase build version to have newer version than in EPEL
  Resolves: bz#1317404^oc]6Jan Grulich <jgrulich@redhat.com> - 5.6.1-1WX- Update to 5.6.1
  Resolves: bz#1317404cncg6Jan Grulich <jgrulich@redhat.com> - 5.6.0-5W4- Enable documentation
  Resolves: bz#1317404gmco6Jan Grulich <jgrulich@redhat.com> - 5.6.0-4WK- Initial version for RHEL
  Resolves: bz#1317404Dlm6Rex Dieter <rdieter@fedoraproject.org> - 5.6.0-3V- rebuild,kcw5Jan Grulich <jgrulich@redhat.com> - 5.9.7-2`- libwebp security fixes:
  Resolves: bz#1961742
  Resolves: bz#1961743
  Resolves: bz#1961744
  Resolves: bz#1961745^jc]5Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Update to 5.9.7
  Resolves: bz#1564007
	<Cq^{c]7Jan Grulich <jgrulich@redhat.com> - 5.6.2-1Xv@- Update to 5.6.2
  Resolves: bz#1384821
ze17Jan Grulich <jgrulich@redhat.com> - 5.6.1-10Wu@- Increase build version to have newer version than in EPEL
  Resolves: bz#1317404^yc]7Jan Grulich <jgrulich@redhat.com> - 5.6.1-1WX- Update to 5.6.1
  Resolves: bz#1317404cxcg7Jan Grulich <jgrulich@redhat.com> - 5.6.0-5W4- Enable documentation
  Resolves: bz#1317404gwco7Jan Grulich <jgrulich@redhat.com> - 5.6.0-4WK- Initial version for RHEL
  Resolves: bz#1317404Dvm7Rex Dieter <rdieter@fedoraproject.org> - 5.6.0-3V- rebuild,ucw6Jan Grulich <jgrulich@redhat.com> - 5.9.7-2`- libwebp security fixes:
  Resolves: bz#1961742
  Resolves: bz#1961743
  Resolves: bz#1961744
  Resolves: bz#1961745^tc]6Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Update to 5.9.7
  Resolves: bz#1564007^sc]6Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1482782
<)\rc8Jan Grulich <jgrulich@redhat.com> - 5.9.2-2ZWQ- Avoid error about unbound variable
  Resolves: bz#1533040^c]8Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1479097bce8Jan Grulich <jgrulich@redhat.com> - 5.9.1-3Y@A- Add more rpm macros
  Resolves: bz#1479097ccg8Jan Grulich <jgrulich@redhat.com> - 5.9.1-2Y@@- Enable documentation
  Resolves: bz#1479097,cw7Jan Grulich <jgrulich@redhat.com> - 5.9.7-2`- libwebp security fixes:
  Resolves: bz#1961742
  Resolves: bz#1961743
  Resolves: bz#1961744
  Resolves: bz#1961745^~c]7Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Update to 5.9.7
  Resolves: bz#1564007^}c]7Jan Grulich <jgrulich@redhat.com> - 5.9.2-1Yp@- Update to 5.9.2
  Resolves: bz#1482782^|c]7Jan Grulich <jgrulich@redhat.com> - 5.9.1-1Y- Update to 5.9.1
  Resolves: bz#1482782
{q	c8Jan Grulich <jgrulich@redhat.com> - 5.9.7-5_l@- Fix buffer overflow in XBM parser
  Resolves: bz#1870365Mc98Jan Grulich <jgrulich@redhat.com> - 5.9.7-4^@- Fix: Files placed by attacker can influence the working directory and lead to malicious code execution
  Resolves: bz#1814740
  Resolves: bz#1814685[cU8Jan Grulich <jgrulich@redhat.com> - 5.9.7-3^M#@- Fix multilib issue with qtcore-config.h header file
  Resolves: bz#1534528

- Move libQt5EglFSDeviceIntegration lib into correct subpackage
  Resolves: bz#1792680hcq8Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\\- Enable -doc subpkg on PPC
  Resolves: bz#1564000^c]8Jan Grulich <jgrulich@redhat.com> - 5.9.7-1\Yz- Update to 5.9.7
  Resolves: bz#1564000c8Jan Grulich <jgrulich@redhat.com> - 5.9.2-3Z]@- Rebuild due to missing RELRO (fixed in binutils)
  Resolves: bz#1534987
HC7H
[;9Honggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585VYU9Jarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296
Y)9Jarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541xY9Jarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426Y?9Jarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#16874268
Y9Jarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274
x"xY:Jarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426Y?:Jarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#16874268Y:Jarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274[O9Honggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699[C9Honggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
[;9Honggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482b[m9Honggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
{[C:Honggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
[;:Honggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482b[m:Honggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
[;:Honggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585VYU:Jarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296Y):Jarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541
>g>V"YU;Jarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296!Y);Jarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541x Y;Jarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426Y?;Jarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#16874268Y;Jarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274[O:Honggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699
q|P8(Y<Jarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274'[O;Honggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699&[C;Honggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
%[;;Honggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482b$[m;Honggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
#[;;Honggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585

er+V:eDH
cd0ee0b99212979ff9dd5d920ddf6f8d82ee56bbc646f1e3c3b7e62a102b1186DG
daae913efb6e4874bfa75dfcd0e5d7e7a5608566622349ab0a84cb1fb2583e70DF
afe9a7933f4656cf6daa79231cf44e96244592acfd586b9fbefcbbd00dbfa129DE
096e36a0f28a54f5ad7c593b2efd58ee933bf7f9c314927179a6d0244e0a596aDD
6800883f09c022594a86d5e180d107e71cc758c3f5f307af8b151a36b1f98818DC
623f1a82453fc1bd44617826a88974cd43fbbb30a2d72e47bd706b0deb895254DB
3b04769f0fca70f22717ac8026b0938bb9fbc4229eece6d24f30b72db5e9276dDA
2841663b99276082da78eea8a950fce8e865e7bca51a7bb46703fc30d76d9768D@
d94b31603d9a0603f9b8587d472ecc87593a0be74e3c99c956b06ed7a156102bD?
3aa4e1ccd9fd1a78767f931c25659037fc4cc3726f2bf2f979ed6ea52afe1815D>
08b1fcdb6cdc4ebc6e4b8009023baa7759c113cc1d67ef555df1cef33880d688D=
96ad2d995fd1cb55307d12d5cba4b02f11fe423d353b3a4e1479ccc4a628163dD<
351bd76d723a1fb9939e1e952f343ba53068b239d463ccd75fc7b724ffd4735b
pob.[m<Honggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
-[;<Honggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585V,YU<Jarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296+Y)<Jarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541x*Y<Jarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426)Y?<Jarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#1687426
TqE;Tb4]i=Sumit Bose <sbose@redhat.com> - 0.16.1-6Wrf- Resolves: rhbz#1258745
- Resolves: rhbz#1258488
- Resolves: rhbz#1267563
- Resolves: rhbz#1293390
- Resolves: rhbz#1273924
- Resolves: rhbz#1274368
- Resolves: rhbz#1291924v3_=Stef Walter <stefw@redhat.com> - 0.16.1-5V - Revert 0.16.1-4
- Use samba by default
- Resolves: rhbz#12716182_9=Stef Walter <stefw@redhat.com> - 0.16.1-4U@- Fix regressions in 0.16.x releases
- Resolves: rhbz#1258745
- Resolves: rhbz#12584881[O<Honggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#19376990[C<Honggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
/[;<Honggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482
 	n ;c=Sumit Bose <sbose@redhat.com> - 0.16.1-12.1_G@use 'additional dns hostnames' with net ads join
- Resolves: rhbz#1849696D:_+=Sumit Bose <sbose@redhat.com> - 0.16.1-12^IFixes for RHEL-7.9
- Resolves: rhbz#1625001
- Resolves: rhbz#1625005
- Resolves: rhbz#1638396
- Resolves: rhbz#1714223
- Resolves: rhbz#18321349_'=Sumit Bose <sbose@redhat.com> - 0.16.1-11[{Improve fix for rhbz#1370457 and fix Coverity issues
- Resolves: rhbz#1370457"8_g=Sumit Bose <sbose@redhat.com> - 0.16.1-10["XUse current Samba options and read NetBIOS name from keytab
- Resolves: rhbz#1484072
- Resolves: rhbz#1370457i7]y=Sumit Bose <sbose@redhat.com> - 0.16.1-9W@Rebuild to fix wrong doc path
- Resolves: rhbz#1360702{6]=Sumit Bose <sbose@redhat.com> - 0.16.1-8W@Fix man page reference in systemd service file
- Resolves: rhbz#1360702t5]
=Sumit Bose <sbose@redhat.com> - 0.16.1-7W@doc: add computer-name to realm man page
- Related: rhbz#1293390
piA]y>Sumit Bose <sbose@redhat.com> - 0.16.1-9W@Rebuild to fix wrong doc path
- Resolves: rhbz#1360702{@]>Sumit Bose <sbose@redhat.com> - 0.16.1-8W@Fix man page reference in systemd service file
- Resolves: rhbz#1360702t?]
>Sumit Bose <sbose@redhat.com> - 0.16.1-7W@doc: add computer-name to realm man page
- Related: rhbz#1293390b>]i>Sumit Bose <sbose@redhat.com> - 0.16.1-6Wrf- Resolves: rhbz#1258745
- Resolves: rhbz#1258488
- Resolves: rhbz#1267563
- Resolves: rhbz#1293390
- Resolves: rhbz#1273924
- Resolves: rhbz#1274368
- Resolves: rhbz#1291924v=_>Stef Walter <stefw@redhat.com> - 0.16.1-5V - Revert 0.16.1-4
- Use samba by default
- Resolves: rhbz#1271618<_9>Stef Walter <stefw@redhat.com> - 0.16.1-4U@- Fix regressions in 0.16.x releases
- Resolves: rhbz#1258745
- Resolves: rhbz#1258488
@Y	@?F_!?Pavel Cahyna <pcahyna@redhat.com> - 2.4-3\-@- Backport fixes for upstream bugs 1974 and 1975
- Apply upstream PR1954 (record permanent MAC address for bond members)
- Apply upstream PR2004 (support for custom network interface naming)
- Backport fix for upstream bug 1926 (support for LACP bonding and teaming)Ec>Sumit Bose <sbose@redhat.com> - 0.16.1-12.1_G@use 'additional dns hostnames' with net ads join
- Resolves: rhbz#1849696DD_+>Sumit Bose <sbose@redhat.com> - 0.16.1-12^IFixes for RHEL-7.9
- Resolves: rhbz#1625001
- Resolves: rhbz#1625005
- Resolves: rhbz#1638396
- Resolves: rhbz#1714223
- Resolves: rhbz#1832134C_'>Sumit Bose <sbose@redhat.com> - 0.16.1-11[{Improve fix for rhbz#1370457 and fix Coverity issues
- Resolves: rhbz#1370457"B_g>Sumit Bose <sbose@redhat.com> - 0.16.1-10["XUse current Samba options and read NetBIOS name from keytab
- Resolves: rhbz#1484072
- Resolves: rhbz#1370457
TTI_C?Pavel Cahyna <pcahyna@redhat.com> - 2.4-7\@- Backport fix for upstream bug 1913 (backup succeeds in case of tar error)
  Resolves: rhbz1631183
- Apply upstream patch PR1885
  Partition information recorded is unexpected when disk has 4K block size
  Resolves: rhbz1610638
- Apply upstream patch PR1887
  LPAR/PPC64 bootlist is incorrectly set when having multiple 'prep' partitions
  Resolves: rhbz1610647
- Apply upstream patch PR1993
  Automatically exclude $BUILD_DIR from the backup
  Resolves: rhbz1655956
- Require xorriso instead of genisoimage, it is now the preferred method
  and supports files over 4GB in size.
  Resolves: rhbz1462189H_K?Pavel Cahyna <pcahyna@redhat.com> - 2.4-5\- Apply upstream PR2065 (record permanent MAC address for team members)
  Resolves: rhbz1685166zG_?Pavel Cahyna <pcahyna@redhat.com> - 2.4-4\u*@- Apply upstream PR2034 (multipath optimizations for lots of devices)
KK4K_?Pavel Cahyna <pcahyna@redhat.com> - 2.4-9]A- Apply upstream PR2173 - Cannot restore using Bacula method
  due to "bconsole" not showing its prompt
  Resolves: rhbz1726982wJ_?Pavel Cahyna <pcahyna@redhat.com> - 2.4-8]@1@- Backport fix for upstream issue 2187 (disklayout.conf file contains
  duplicate lines, breaking recovery in migration mode or when
  thin pools are used). PR2194, 2196.
  Resolves: rhbz1732328
++PLaA?Pavel Cahyna <pcahyna@redhat.com> - 2.4-11]e@- Apply upstream PR2122: add additional NBU library path to fix support for
  NetBackup 8.
  Resolves: rhbz1700807
- Apply upstream PR212: Be safe against empty docker_root_dir (issue 1989)
  Resolves: rhbz1711123, where ReaR can not create a backup in rescue mode,
  because it thinks that the Docker daemon is running and hits the problem
  with empty docker_root_dir.
- Apply upstream PR2223 and commit 36cf20e to avoid an empty string in the
  list of users to clone, which can lead to bash overflow with lots of users
  and groups per user and to wrong passwd/group files in the rescue system.
  Resolves: rhbz1692575
- Backport of Upstream fix for issue 2035: /run is not mounted in the rescue
  chroot, which causes LVM to hang, especially if rebuilding initramfs.
  Resolves: rhbz1697815
- Backport upstream PR 2218: avoid keeping build dir on errors
  by default when used noninteractively
  Resolves: rhbz1693608
dNk7?Václav Doležal <vdolezal@redhat.com> - 2.4-13^@- Apply upstream PR2373: Skip Longhorn Engine replica devices
  Resolves: rhbz1842984MkE?Václav Doležal <vdolezal@redhat.com> - 2.4-12^- Apply upstream PR2346: Have '-iso-level 3' option also for ppc64le
  Resolves: rhbz1726043
zP_@Pavel Cahyna <pcahyna@redhat.com> - 2.4-4\u*@- Apply upstream PR2034 (multipath optimizations for lots of devices)eOak?Pavel Cahyna <pcahyna@redhat.com> - 2.4-15a*@- Backport PR2608:
  Fix setting boot path in case of UEFI partition (ESP) on MD RAID
  Resolves: rhbz1945869
- Backport PR2625 & 2675
  Prevents accidental backup removal in case of errors
  Resolves: rhbz1843585
- Fix rsync error and option handling
  Fixes metadata storage when rsync user is not root
  Resolves: rhbz1947064
- Changes for NetBackup (NBU) support, upstream PR2544
  Resolves: rhbz2031833
- On POWER add bootlist & ofpathname to the list of required programs
  conditionally (bootlist only if running under PowerVM, ofpathname
  always except on PowerNV) - upstream PR2665, add them to package
  dependencies
  Resolves: rhbz1983008
- On POWER mount /sys in the chroot, otherwise ofpathname does not work
  and we risk ending up with not instlaling the bootloader properly
  Resolves: rhbz1983000
gR_C@Pavel Cahyna <pcahyna@redhat.com> - 2.4-7\@- Backport fix for upstream bug 1913 (backup succeeds in case of tar error)
  Resolves: rhbz1631183
- Apply upstream patch PR1885
  Partition information recorded is unexpected when disk has 4K block size
  Resolves: rhbz1610638
- Apply upstream patch PR1887
  LPAR/PPC64 bootlist is incorrectly set when having multiple 'prep' partitions
  Resolves: rhbz1610647
- Apply upstream patch PR1993
  Automatically exclude $BUILD_DIR from the backup
  Resolves: rhbz1655956
- Require xorriso instead of genisoimage, it is now the preferred method
  and supports files over 4GB in size.
  Resolves: rhbz1462189Q_K@Pavel Cahyna <pcahyna@redhat.com> - 2.4-5\- Apply upstream PR2065 (record permanent MAC address for team members)
  Resolves: rhbz1685166
KK4T_@Pavel Cahyna <pcahyna@redhat.com> - 2.4-9]A- Apply upstream PR2173 - Cannot restore using Bacula method
  due to "bconsole" not showing its prompt
  Resolves: rhbz1726982wS_@Pavel Cahyna <pcahyna@redhat.com> - 2.4-8]@1@- Backport fix for upstream issue 2187 (disklayout.conf file contains
  duplicate lines, breaking recovery in migration mode or when
  thin pools are used). PR2194, 2196.
  Resolves: rhbz1732328
++PUaA@Pavel Cahyna <pcahyna@redhat.com> - 2.4-11]e@- Apply upstream PR2122: add additional NBU library path to fix support for
  NetBackup 8.
  Resolves: rhbz1700807
- Apply upstream PR212: Be safe against empty docker_root_dir (issue 1989)
  Resolves: rhbz1711123, where ReaR can not create a backup in rescue mode,
  because it thinks that the Docker daemon is running and hits the problem
  with empty docker_root_dir.
- Apply upstream PR2223 and commit 36cf20e to avoid an empty string in the
  list of users to clone, which can lead to bash overflow with lots of users
  and groups per user and to wrong passwd/group files in the rescue system.
  Resolves: rhbz1692575
- Backport of Upstream fix for issue 2035: /run is not mounted in the rescue
  chroot, which causes LVM to hang, especially if rebuilding initramfs.
  Resolves: rhbz1697815
- Backport upstream PR 2218: avoid keeping build dir on errors
  by default when used noninteractively
  Resolves: rhbz1693608
dWk7@Václav Doležal <vdolezal@redhat.com> - 2.4-13^@- Apply upstream PR2373: Skip Longhorn Engine replica devices
  Resolves: rhbz1842984VkE@Václav Doležal <vdolezal@redhat.com> - 2.4-12^- Apply upstream PR2346: Have '-iso-level 3' option also for ppc64le
  Resolves: rhbz1726043
  rYa@Pavel Cahyna <pcahyna@redhat.com> - 2.4-16bg- Apply upstream PR2237 to include multipath disks in backupeXak@Pavel Cahyna <pcahyna@redhat.com> - 2.4-15a*@- Backport PR2608:
  Fix setting boot path in case of UEFI partition (ESP) on MD RAID
  Resolves: rhbz1945869
- Backport PR2625 & 2675
  Prevents accidental backup removal in case of errors
  Resolves: rhbz1843585
- Fix rsync error and option handling
  Fixes metadata storage when rsync user is not root
  Resolves: rhbz1947064
- Changes for NetBackup (NBU) support, upstream PR2544
  Resolves: rhbz2031833
- On POWER add bootlist & ofpathname to the list of required programs
  conditionally (bootlist only if running under PowerVM, ofpathname
  always except on PowerNV) - upstream PR2665, add them to package
  dependencies
  Resolves: rhbz1983008
- On POWER mount /sys in the chroot, otherwise ofpathname does not work
  and we risk ending up with not instlaling the bootloader properly
  Resolves: rhbz1983000
g[_CAPavel Cahyna <pcahyna@redhat.com> - 2.4-7\@- Backport fix for upstream bug 1913 (backup succeeds in case of tar error)
  Resolves: rhbz1631183
- Apply upstream patch PR1885
  Partition information recorded is unexpected when disk has 4K block size
  Resolves: rhbz1610638
- Apply upstream patch PR1887
  LPAR/PPC64 bootlist is incorrectly set when having multiple 'prep' partitions
  Resolves: rhbz1610647
- Apply upstream patch PR1993
  Automatically exclude $BUILD_DIR from the backup
  Resolves: rhbz1655956
- Require xorriso instead of genisoimage, it is now the preferred method
  and supports files over 4GB in size.
  Resolves: rhbz1462189Z_KAPavel Cahyna <pcahyna@redhat.com> - 2.4-5\- Apply upstream PR2065 (record permanent MAC address for team members)
  Resolves: rhbz1685166
KK4]_APavel Cahyna <pcahyna@redhat.com> - 2.4-9]A- Apply upstream PR2173 - Cannot restore using Bacula method
  due to "bconsole" not showing its prompt
  Resolves: rhbz1726982w\_APavel Cahyna <pcahyna@redhat.com> - 2.4-8]@1@- Backport fix for upstream issue 2187 (disklayout.conf file contains
  duplicate lines, breaking recovery in migration mode or when
  thin pools are used). PR2194, 2196.
  Resolves: rhbz1732328
++P^aAAPavel Cahyna <pcahyna@redhat.com> - 2.4-11]e@- Apply upstream PR2122: add additional NBU library path to fix support for
  NetBackup 8.
  Resolves: rhbz1700807
- Apply upstream PR212: Be safe against empty docker_root_dir (issue 1989)
  Resolves: rhbz1711123, where ReaR can not create a backup in rescue mode,
  because it thinks that the Docker daemon is running and hits the problem
  with empty docker_root_dir.
- Apply upstream PR2223 and commit 36cf20e to avoid an empty string in the
  list of users to clone, which can lead to bash overflow with lots of users
  and groups per user and to wrong passwd/group files in the rescue system.
  Resolves: rhbz1692575
- Backport of Upstream fix for issue 2035: /run is not mounted in the rescue
  chroot, which causes LVM to hang, especially if rebuilding initramfs.
  Resolves: rhbz1697815
- Backport upstream PR 2218: avoid keeping build dir on errors
  by default when used noninteractively
  Resolves: rhbz1693608
d`k7AVáclav Doležal <vdolezal@redhat.com> - 2.4-13^@- Apply upstream PR2373: Skip Longhorn Engine replica devices
  Resolves: rhbz1842984_kEAVáclav Doležal <vdolezal@redhat.com> - 2.4-12^- Apply upstream PR2346: Have '-iso-level 3' option also for ppc64le
  Resolves: rhbz1726043
  rbaAPavel Cahyna <pcahyna@redhat.com> - 2.4-16bg- Apply upstream PR2237 to include multipath disks in backupeaakAPavel Cahyna <pcahyna@redhat.com> - 2.4-15a*@- Backport PR2608:
  Fix setting boot path in case of UEFI partition (ESP) on MD RAID
  Resolves: rhbz1945869
- Backport PR2625 & 2675
  Prevents accidental backup removal in case of errors
  Resolves: rhbz1843585
- Fix rsync error and option handling
  Fixes metadata storage when rsync user is not root
  Resolves: rhbz1947064
- Changes for NetBackup (NBU) support, upstream PR2544
  Resolves: rhbz2031833
- On POWER add bootlist & ofpathname to the list of required programs
  conditionally (bootlist only if running under PowerVM, ofpathname
  always except on PowerNV) - upstream PR2665, add them to package
  dependencies
  Resolves: rhbz1983008
- On POWER mount /sys in the chroot, otherwise ofpathname does not work
  and we risk ending up with not instlaling the bootloader properly
  Resolves: rhbz1983000
LdZL-jYBMark Huth <mhuth@redhat.com> - 0.9.7-6W{@- Resolves: rhbz#1314606 - show progress with addattachment
- Resolves: rhbz#1314607 - problem with addattachment -s switchiY5BMark Huth <mhuth@redhat.com> - 0.9.7-3T- Resolves: rhbz#1176473 - FTP upload via proxy
- Small changes to download progressrhk}BKeith Robertson <kroberts@redhat.com> - 0.9.7-0TD@- Proxy fix for file uploads
- Get a specific case groupWgkGBKeith Robertson <kroberts@redhat.com> - 0.9.6-3T	- Fix proxy upload attachmentdfkaBKeith Robertson <kroberts@redhat.com> - 0.9.6-1S- Display download progess for attachmentsIek+BKeith Robertson <kroberts@redhat.com> - 0.9.6-0S
@- Various fixesQdk;BKeith Robertson <kroberts@redhat.com> - 0.9.5-8R|- Resolves: rhbz#987168caOAPavel Cahyna <pcahyna@redhat.com> - 2.4-17dC@- Apply PR2431 to migrate XFS configuration files
- Fix typo in default.conf
  Resolves: #1882060
k%<krqk}CKeith Robertson <kroberts@redhat.com> - 0.9.7-0TD@- Proxy fix for file uploads
- Get a specific case groupWpkGCKeith Robertson <kroberts@redhat.com> - 0.9.6-3T	- Fix proxy upload attachmentdokaCKeith Robertson <kroberts@redhat.com> - 0.9.6-1S- Display download progess for attachmentsInk+CKeith Robertson <kroberts@redhat.com> - 0.9.6-0S
@- Various fixes/me{BPranita Ghole <pghole@redhat.com> - 0.13.0-0a@- Resolves: rhbz#1653574- Add support for handling JSON response from API's
- Resolves: rhbz#1765391- Add support to upload to and download from S3
- Resolves: rhbz#2030066- RHST should use new Red Hat Secure FTP instead of dropbox for attachmentsle)BPranita Ghole <pghole@redhat.com> - 0.12.1-1]c- Resolves: rhbz#1669454 - connection.py uses incorrect base64 encoding methodLkc9BVikas Rathee <vrathee@redhat.com> - 0.9.8-1Y&@- Correcting changelog
&us&	wc1CSwaraj Pande <spande@redhat.com> - 0.14.0-1e@- Resolves: RHEL-22245 - Deprecate the Basic Authentication in redhat-support-tool/ve{CPranita Ghole <pghole@redhat.com> - 0.13.0-0a@- Resolves: rhbz#1653574- Add support for handling JSON response from API's
- Resolves: rhbz#1765391- Add support to upload to and download from S3
- Resolves: rhbz#2030066- RHST should use new Red Hat Secure FTP instead of dropbox for attachmentsue)CPranita Ghole <pghole@redhat.com> - 0.12.1-1]c- Resolves: rhbz#1669454 - connection.py uses incorrect base64 encoding methodLtc9CVikas Rathee <vrathee@redhat.com> - 0.9.8-1Y&@- Correcting changelog-sYCMark Huth <mhuth@redhat.com> - 0.9.7-6W{@- Resolves: rhbz#1314606 - show progress with addattachment
- Resolves: rhbz#1314607 - problem with addattachment -s switchrY5CMark Huth <mhuth@redhat.com> - 0.9.7-3T- Resolves: rhbz#1176473 - FTP upload via proxy
- Small changes to download progress
!!@zY)DMark Huth <mhuth@redhat.com> - 0.9.8-6W{@- Resolves: rhbz#1104344 - add soscleaner
- Resolves: rhbz#1273976 - caches bad password
- Resolves: rhbz#1284306 - improve ? help
- Resolves: rhbz#1284308 - show attachment sizes
- Resolves: rhbz#1284309 - show attachment full path
- Resolves: rhbz#1284314 - differentiate diagnose and analyze
- Resolves: rhbz#1290909 - change case internal status
- Resolves: rhbz#1351141 - reverse severity listyY)DMark Huth <mhuth@redhat.com> - 0.9.7-4T- Resolves: rhbz#1196297 - typos in opencase
- Resolves: rhbz#1196316 - change menus when closing a case
- Fallback to ownerSSOName if associateSSOName filter gets 404 error in listcases
- Other small fixesxYIDMark Huth <mhuth@redhat.com> - 0.9.7-3T- Resolves: rhbz#1168414 - rhel7 vmcore offset
- Resolves: rhbz#1174461 - skip already downloaded attachments
- Resolves: rhbz#1176473 - fix addattachment via FTP and proxy
- Make debug_repos configurable via config option
7~eDVikas Rathee <vrathee@redhat.com> - 0.9.10-1Y- Resolves: rhbz#1342627 - List cases by group.
- Resolves: rhbz#1379619 - Inform when http_proxy environment variable is used.}c7DVikas Rathee <vrathee@redhat.com> - 0.9.9-3Y.@- Resolves: rhbz#1380109 - Correcting spacing in non-interactive mode search results.|cQDVikas Rathee <vrathee@redhat.com> - 0.9.9-2Y&@- Resolves: rhbz#1380109 - Include last modified date for solutions in non-interactive mode searchL{c7DVikas Rathee <vrathee@redhat.com> - 0.9.9-1Y@- Resolves: rhbz#1380109 - Include creation date and last modified date in Solution title details.
- Resolves: rhbz#1342628 - When opening a new case, offer a default product.
- Resolves: rhbz#1342632 - When opening a new case, offer to use the default case group of that user.
O0e}DPranita Ghole <pghole@redhat.com> - 0.13.0-0a- Resolves: rhbz#2030063- Add support for handling JSON response from API's 
- Resolves: rhbz#1765392- Add support to upload to and download from S3
- Resolves: rhbz#2030065- RHST should use new Red Hat Secure FTP instead of dropbox for attachments.eyDPranita Ghole <pghole@redhat.com> - 0.12.2-1]e@- Resolves: rhbz#1547763 - redhat-support-tool: UnboundLocalError: local variable 'timer' referenced before assignmentyeDPranita Ghole <pghole@redhat.com> - 0.9.11-1\- Resolves: rhbz#1418701 - [RFE] Add functionality to generate and send sosreport after selecting the case
- Resolves: rhbz#1592850 - [RFE] Generate and upload sosreport to case from cli
- Resolves: rhbz#1678347 - Update redhat-support-tool to use latest soscleaner
- Resolves: rhbz#1670033 - redhat-support-tool env var http_proxy does not work with user and password
- Resolves: rhbz#1457436 -  [RFE][RHEL7] Include Reason in cases of failed proxy
66@Y)EMark Huth <mhuth@redhat.com> - 0.9.8-6W{@- Resolves: rhbz#1104344 - add soscleaner
- Resolves: rhbz#1273976 - caches bad password
- Resolves: rhbz#1284306 - improve ? help
- Resolves: rhbz#1284308 - show attachment sizes
- Resolves: rhbz#1284309 - show attachment full path
- Resolves: rhbz#1284314 - differentiate diagnose and analyze
- Resolves: rhbz#1290909 - change case internal status
- Resolves: rhbz#1351141 - reverse severity listY)EMark Huth <mhuth@redhat.com> - 0.9.7-4T- Resolves: rhbz#1196297 - typos in opencase
- Resolves: rhbz#1196316 - change menus when closing a case
- Fallback to ownerSSOName if associateSSOName filter gets 404 error in listcases
- Other small fixesbR=dRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{<=<D=K=S=Z=`=i=r={==	=	=
=="=
(=.=4=;=A=F=I=K=L=N=P=R=T=U=W=Y=[=]= ^=!`="b=#j=$q=%w=&z='~=(=)=+=,
=-=.=/=0 =1&=2+=40=55=6;=7@=8F=9L=:Q=;V=<[==a=>f=?k=@p=Av=B{=C=D=E=F=G=H=I!=J&=K+=M1=N6=O;=P@=QF=RK=SP=TU=U[=V`=Wf=Xl=Yq=Zv=[{=\~=]=^=_
=`=a=b=c
7eEVikas Rathee <vrathee@redhat.com> - 0.9.10-1Y- Resolves: rhbz#1342627 - List cases by group.
- Resolves: rhbz#1379619 - Inform when http_proxy environment variable is used.c7EVikas Rathee <vrathee@redhat.com> - 0.9.9-3Y.@- Resolves: rhbz#1380109 - Correcting spacing in non-interactive mode search results.cQEVikas Rathee <vrathee@redhat.com> - 0.9.9-2Y&@- Resolves: rhbz#1380109 - Include last modified date for solutions in non-interactive mode searchLc7EVikas Rathee <vrathee@redhat.com> - 0.9.9-1Y@- Resolves: rhbz#1380109 - Include creation date and last modified date in Solution title details.
- Resolves: rhbz#1342628 - When opening a new case, offer a default product.
- Resolves: rhbz#1342632 - When opening a new case, offer to use the default case group of that user.
O0
e}EPranita Ghole <pghole@redhat.com> - 0.13.0-0a- Resolves: rhbz#2030063- Add support for handling JSON response from API's 
- Resolves: rhbz#1765392- Add support to upload to and download from S3
- Resolves: rhbz#2030065- RHST should use new Red Hat Secure FTP instead of dropbox for attachments.	eyEPranita Ghole <pghole@redhat.com> - 0.12.2-1]e@- Resolves: rhbz#1547763 - redhat-support-tool: UnboundLocalError: local variable 'timer' referenced before assignmentyeEPranita Ghole <pghole@redhat.com> - 0.9.11-1\- Resolves: rhbz#1418701 - [RFE] Add functionality to generate and send sosreport after selecting the case
- Resolves: rhbz#1592850 - [RFE] Generate and upload sosreport to case from cli
- Resolves: rhbz#1678347 - Update redhat-support-tool to use latest soscleaner
- Resolves: rhbz#1670033 - redhat-support-tool env var http_proxy does not work with user and password
- Resolves: rhbz#1457436 -  [RFE][RHEL7] Include Reason in cases of failed proxy
<ryM<u/FOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992wu}FOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'u[FOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121v
qFOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950{qFOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-60^@- nfsserver: fix NFSv4-only support

  Resolves: rhbz#1840750	c1ESwaraj Pande <spande@redhat.com> - 0.14.0-1e@- Resolves: RHEL-22246 - Deprecate the Basic Authentication in redhat-support-tool
~"vqGOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950w-FOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798|wFOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#1939282u/FOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151AuFOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936~u	FOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737
{YA{AuGOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936~u	GOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737u/GOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992wu}GOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'u[GOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121
ujTu' u[HOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121.wgGOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.13`]- SAPHana: use actual_mode from global.ini and fallback to mode when
  it's not set

  Resolves: rhbz#1855888w-GOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798|wGOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#1939282u/GOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151
m|&wHOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#1939282%u/HOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151A$uHOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936~#u	HOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737"u/HOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992w!u}HOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779
jK~+u	IOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737*u/IOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992Q)w-HOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.15a@- gcp-pd-move/gcp-vpc-move-route/gcp-vpc-move-vip: dont fail with
  configuration rc when it might be a network hickup

  Resolves: rhbz#2042070.(wgHOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.13`]- SAPHana: use actual_mode from global.ini and fallback to mode when
  it's not set

  Resolves: rhbz#1855888'w-HOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798

er+V:eDU
980d1c1b856c308eb7fb1dc1f32d4d5d9828a5ac152037e4fcb99050874e9506DT
3252927809ad349b76f38136eaa163f3abd94c46df6a5933f90e8bb2f0d633e3DS
3ef3e8c076f637b1c91f85480d4df87d7fe63a0aee8b42f8fc774dd84b683aa2DR
6d0aee209b29a68899270b50fbdb5657444b46017f3f4b39ff4652e77f30292cDQ
37e88e4bf1d956c4200c41a6b0592a43ed17ce9e8ba6f60c8856ef69516f2d52DP
d2d500ea0189e3f9d7f6ce3102af96d24e0a9a06f89ce42f89346c33e7d48100DO
69e3af51dee6dd3aca7ef07201a7beeaa6d764016a11afffdabce904928aee48DN
fd2db008a8253afbc54436a251251bbe5b6346f3c7a12892e6fe0b2aeb947358DM
b471f99ddcb78e386e77a4c7bf4a814b35fce51259b2f34d2daa9be4e09d6e98DL
9183798963f96d58d5fcaf70beb6047196f8bc9b1b7767de2b59e133fe27c94bDK
898a07f35eaa8781f7f96ee6666297c5864472115945d11efcee3bfabc801e33DJ
1f633f20c7b2aa6eafb4ac8894d9cd73727c40432189eee52f62aee11daf62e9DI
da05fbb9b8450a92e98610e675aa2f6b8d363493edbf91cc645a281adce116ff
:$.0wgIOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.13`]- SAPHana: use actual_mode from global.ini and fallback to mode when
  it's not set

  Resolves: rhbz#1855888/w-IOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798|.wIOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#1939282-u/IOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151A,uIOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936
*]A5uJOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936~4u	JOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737&3wWIOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.18cQ8@- db2: add PRIMARY/REMOTE_CATCHUP_PENDING/CONNECTED status to promote-check

  Resolves: rhbz#21274772wAIOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.17c@- awsvip: dont partially match similar IPs during monitor-action

  Resolves: rhbz#1940097Q1w-IOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.15a@- gcp-pd-move/gcp-vpc-move-route/gcp-vpc-move-vip: dont fail with
  configuration rc when it might be a network hickup

  Resolves: rhbz#2042070
+jT+;wAJOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.17c@- awsvip: dont partially match similar IPs during monitor-action

  Resolves: rhbz#1940097Q:w-JOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.15a@- gcp-pd-move/gcp-vpc-move-route/gcp-vpc-move-vip: dont fail with
  configuration rc when it might be a network hickup

  Resolves: rhbz#2042070.9wgJOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.13`]- SAPHana: use actual_mode from global.ini and fallback to mode when
  it's not set

  Resolves: rhbz#18558888w-JOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798|7wJOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#19392826u/JOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151
TUT5@q{KOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-56^- sap-hana-scaleout: set default timeouts based on recommendations
  and a couple of bugfixes

  Resolves: rhbz#1829081?q=KOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-55^- sap-cluster-connector: allow dashes/underscores in nodenames

  Resolves: rhbz#1829085>qOKOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-54^- aws-vpc-route53: new resource agent for AWS
- aws-vpc-move-ip: add "routing_table_role" parameter
- aws-vpc-move-ip: delete remaining route entries

  Resolves: rhbz#1759113
  Resolves: rhbz#1810466
  Resolves: rhbz#1828895=wJOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.20eM@- bundled pycryptodome: fix CVE-2023-52323

  Resolves: RHEL-20914&<wWJOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.18cQ8@- db2: add PRIMARY/REMOTE_CATCHUP_PENDING/CONNECTED status to promote-check

  Resolves: rhbz#2127477
6eW6wFu}KOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'Eu[KOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121vDqKOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950{CqKOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-60^@- nfsserver: fix NFSv4-only support

  Resolves: rhbz#1840750
Bq%KOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-59^ϧ- gcp-pd-move: new resource agent for Google Cloud

  Resolves: rhbz#1633249Aq=KOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-58^@- db2 (HADR): promote standby node when master node disappears

  Resolves: rhbz#1720283
ljzl{LqLOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-60^@- nfsserver: fix NFSv4-only support

  Resolves: rhbz#1840750
Kq%LOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-59^ϧ- gcp-pd-move: new resource agent for Google Cloud

  Resolves: rhbz#1633249Jq=LOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-58^@- db2 (HADR): promote standby node when master node disappears

  Resolves: rhbz#17202835Iq{LOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-56^- sap-hana-scaleout: set default timeouts based on recommendations
  and a couple of bugfixes

  Resolves: rhbz#1829081Hq=LOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-55^- sap-cluster-connector: allow dashes/underscores in nodenames

  Resolves: rhbz#1829085Gu/KOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992
ZI~Qu	LOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737Pu/LOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992wOu}LOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'Nu[LOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121vMqLOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950
#F#vVqMOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950{UqMOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-60^@- nfsserver: fix NFSv4-only support

  Resolves: rhbz#1840750
Tq%MOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-59^ϧ- gcp-pd-move: new resource agent for Google Cloud

  Resolves: rhbz#1633249Sq=MOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-58^@- db2 (HADR): promote standby node when master node disappears

  Resolves: rhbz#17202835Rq{MOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-56^- sap-hana-scaleout: set default timeouts based on recommendations
  and a couple of bugfixes

  Resolves: rhbz#1829081
{YA{A[uMOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936~Zu	MOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737Yu/MOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992wXu}MOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'Wu[MOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121
H`H~au	NOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737`u/NOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992w_u}NOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'^u[NOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121v]qNOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950{\qNOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-60^@- nfsserver: fix NFSv4-only support

  Resolves: rhbz#1840750
:$vfqOOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950ew-NOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798|dwNOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#1939282cu/NOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151AbuNOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936
{YA{AkuOOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936~ju	OOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737iu/OOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992whu}OOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'gu[OOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121
ujTu'pu[POyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121.owgOOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.13`]- SAPHana: use actual_mode from global.ini and fallback to mode when
  it's not set

  Resolves: rhbz#1855888nw-OOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798|mwOOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#1939282lu/OOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151
m|vwPOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#1939282uu/POyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151AtuPOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936~su	POyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737ru/POyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992wqu}POyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779
jK~{u	QOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737zu/QOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992Qyw-POyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.15a@- gcp-pd-move/gcp-vpc-move-route/gcp-vpc-move-vip: dont fail with
  configuration rc when it might be a network hickup

  Resolves: rhbz#2042070.xwgPOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.13`]- SAPHana: use actual_mode from global.ini and fallback to mode when
  it's not set

  Resolves: rhbz#1855888ww-POyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798
:$.wgQOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.13`]- SAPHana: use actual_mode from global.ini and fallback to mode when
  it's not set

  Resolves: rhbz#1855888w-QOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798|~wQOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#1939282}u/QOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151A|uQOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936
*]AuROyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936~u	ROyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737&wWQOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.18cQ8@- db2: add PRIMARY/REMOTE_CATCHUP_PENDING/CONNECTED status to promote-check

  Resolves: rhbz#2127477wAQOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.17c@- awsvip: dont partially match similar IPs during monitor-action

  Resolves: rhbz#1940097Qw-QOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.15a@- gcp-pd-move/gcp-vpc-move-route/gcp-vpc-move-vip: dont fail with
  configuration rc when it might be a network hickup

  Resolves: rhbz#2042070
+jT+wAROyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.17c@- awsvip: dont partially match similar IPs during monitor-action

  Resolves: rhbz#1940097Q
w-ROyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.15a@- gcp-pd-move/gcp-vpc-move-route/gcp-vpc-move-vip: dont fail with
  configuration rc when it might be a network hickup

  Resolves: rhbz#2042070.	wgROyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.13`]- SAPHana: use actual_mode from global.ini and fallback to mode when
  it's not set

  Resolves: rhbz#1855888w-ROyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798|wROyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#1939282u/ROyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151
TUT5q{SOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-56^- sap-hana-scaleout: set default timeouts based on recommendations
  and a couple of bugfixes

  Resolves: rhbz#1829081q=SOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-55^- sap-cluster-connector: allow dashes/underscores in nodenames

  Resolves: rhbz#1829085qOSOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-54^- aws-vpc-route53: new resource agent for AWS
- aws-vpc-move-ip: add "routing_table_role" parameter
- aws-vpc-move-ip: delete remaining route entries

  Resolves: rhbz#1759113
  Resolves: rhbz#1810466
  Resolves: rhbz#1828895
wROyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.20eM@- bundled pycryptodome: fix CVE-2023-52323

  Resolves: RHEL-20914&wWROyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.18cQ8@- db2: add PRIMARY/REMOTE_CATCHUP_PENDING/CONNECTED status to promote-check

  Resolves: rhbz#2127477
6eW6wu}SOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'u[SOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121vqSOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950{qSOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-60^@- nfsserver: fix NFSv4-only support

  Resolves: rhbz#1840750
q%SOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-59^ϧ- gcp-pd-move: new resource agent for Google Cloud

  Resolves: rhbz#1633249q=SOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-58^@- db2 (HADR): promote standby node when master node disappears

  Resolves: rhbz#1720283
ljzl{qTOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-60^@- nfsserver: fix NFSv4-only support

  Resolves: rhbz#1840750
q%TOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-59^ϧ- gcp-pd-move: new resource agent for Google Cloud

  Resolves: rhbz#1633249q=TOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-58^@- db2 (HADR): promote standby node when master node disappears

  Resolves: rhbz#17202835q{TOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-56^- sap-hana-scaleout: set default timeouts based on recommendations
  and a couple of bugfixes

  Resolves: rhbz#1829081q=TOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-55^- sap-cluster-connector: allow dashes/underscores in nodenames

  Resolves: rhbz#1829085u/SOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992
ZI~!u	TOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737 u/TOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992wu}TOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'u[TOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121vqTOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950
#F#v&qUOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950{%qUOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-60^@- nfsserver: fix NFSv4-only support

  Resolves: rhbz#1840750
$q%UOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-59^ϧ- gcp-pd-move: new resource agent for Google Cloud

  Resolves: rhbz#1633249#q=UOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-58^@- db2 (HADR): promote standby node when master node disappears

  Resolves: rhbz#17202835"q{UOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-56^- sap-hana-scaleout: set default timeouts based on recommendations
  and a couple of bugfixes

  Resolves: rhbz#1829081
{YA{A+uUOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936~*u	UOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737)u/UOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992w(u}UOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779''u[UOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121

er+V:eDb
573a2c4f5486b06a893fb7f1e7a97a45c7fe7c28b4314f367ca8116a785809baDa
e8d290b951820742ddb84f040482ef781da092f44db1523ea7d4b25d3674bd2bD`
98f3b8342ce89b923c57a4b705d3efa4f050f19a729aee47d0a57f765db515e0D_
c5f0f07eae306ab7f2f7b4798fc0f577aa6584d592fcf290ae03ea28e66a9ebaD^
cc89949280e927133ec7bcd3f3d4e2b299ae223f458650d04bc324a015418f95D]
259d7d947d78e3105849ae7a9929d030e772e103b7c652d987701a6a7d08f78dD\
7a120b5dad1d3423bed8b8972e2921ed34ecc22037b1ceae0e2a44fd7079bfe1D[
d03be814a86828be3841393ebfa51e9a8c3907a53dbae5960d470f20fd79d04cDZ
639a97b21ae7b51141fd76f2777d2f3ea1bd758549e53130764657fafe2daf7aDY
5950600c8fad63a2225e6de0a7ee94e2ae7e8d5131aa6b799923c80580f5f7d5DX
ce2b479d726968ea27bfbfd9dc3bf20a2ef62e6ab1f4d3b4a0e6d4230a9ef0ecDW
7f1d9434068b1dab6eb2d4673f1f11fee7c197500b464616bdb606f4cb097f8eDV
61c74a7c104da9dbf65e04e0cc9a97adda225fc72f10000914e503e0bae407ab
H`H~1u	VOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#19057370u/VOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992w/u}VOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'.u[VOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121v-qVOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950{,qVOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-60^@- nfsserver: fix NFSv4-only support

  Resolves: rhbz#1840750
:$v6qWOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#16019505w-VOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798|4wVOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#19392823u/VOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151A2uVOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936
{YA{A;uWOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936~:u	WOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#19057379u/WOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992w8u}WOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'7u[WOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121
ujTu'@u[XOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121.?wgWOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.13`]- SAPHana: use actual_mode from global.ini and fallback to mode when
  it's not set

  Resolves: rhbz#1855888>w-WOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798|=wWOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#1939282<u/WOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151
m|FwXOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#1939282Eu/XOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151ADuXOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936~Cu	XOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737Bu/XOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992wAu}XOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779
jK~Ku	YOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737Ju/YOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992QIw-XOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.15a@- gcp-pd-move/gcp-vpc-move-route/gcp-vpc-move-vip: dont fail with
  configuration rc when it might be a network hickup

  Resolves: rhbz#2042070.HwgXOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.13`]- SAPHana: use actual_mode from global.ini and fallback to mode when
  it's not set

  Resolves: rhbz#1855888Gw-XOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798
:$.PwgYOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.13`]- SAPHana: use actual_mode from global.ini and fallback to mode when
  it's not set

  Resolves: rhbz#1855888Ow-YOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798|NwYOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#1939282Mu/YOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151ALuYOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936
*]AUuZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936~Tu	ZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737&SwWYOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.18cQ8@- db2: add PRIMARY/REMOTE_CATCHUP_PENDING/CONNECTED status to promote-check

  Resolves: rhbz#2127477RwAYOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.17c@- awsvip: dont partially match similar IPs during monitor-action

  Resolves: rhbz#1940097QQw-YOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.15a@- gcp-pd-move/gcp-vpc-move-route/gcp-vpc-move-vip: dont fail with
  configuration rc when it might be a network hickup

  Resolves: rhbz#2042070
+jT+[wAZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.17c@- awsvip: dont partially match similar IPs during monitor-action

  Resolves: rhbz#1940097QZw-ZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.15a@- gcp-pd-move/gcp-vpc-move-route/gcp-vpc-move-vip: dont fail with
  configuration rc when it might be a network hickup

  Resolves: rhbz#2042070.YwgZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.13`]- SAPHana: use actual_mode from global.ini and fallback to mode when
  it's not set

  Resolves: rhbz#1855888Xw-ZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.11`- gcp-pd-move: dont stop partially matched "disk_name"

  Resolves: rhbz#1935798|WwZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.10`\{@- aws-vpc-move-ip: add ENI lookup

  Resolves: rhbz#1939282Vu/ZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.9`J@- azure-lb: redirect to avoid nc dying with EPIPE error

  Resolves: rhbz#1937151
TUT5`q{[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-56^- sap-hana-scaleout: set default timeouts based on recommendations
  and a couple of bugfixes

  Resolves: rhbz#1829081_q=[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-55^- sap-cluster-connector: allow dashes/underscores in nodenames

  Resolves: rhbz#1829085^qO[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-54^- aws-vpc-route53: new resource agent for AWS
- aws-vpc-move-ip: add "routing_table_role" parameter
- aws-vpc-move-ip: delete remaining route entries

  Resolves: rhbz#1759113
  Resolves: rhbz#1810466
  Resolves: rhbz#1828895]wZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.20eM@- bundled pycryptodome: fix CVE-2023-52323

  Resolves: RHEL-20914&\wWZOyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.18cQ8@- db2: add PRIMARY/REMOTE_CATCHUP_PENDING/CONNECTED status to promote-check

  Resolves: rhbz#2127477
6eW6wfu}[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'eu[[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121vdq[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950{cq[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-60^@- nfsserver: fix NFSv4-only support

  Resolves: rhbz#1840750
bq%[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-59^ϧ- gcp-pd-move: new resource agent for Google Cloud

  Resolves: rhbz#1633249aq=[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-58^@- db2 (HADR): promote standby node when master node disappears

  Resolves: rhbz#1720283
ljzl{lq\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-60^@- nfsserver: fix NFSv4-only support

  Resolves: rhbz#1840750
kq%\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-59^ϧ- gcp-pd-move: new resource agent for Google Cloud

  Resolves: rhbz#1633249jq=\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-58^@- db2 (HADR): promote standby node when master node disappears

  Resolves: rhbz#17202835iq{\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-56^- sap-hana-scaleout: set default timeouts based on recommendations
  and a couple of bugfixes

  Resolves: rhbz#1829081hq=\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-55^- sap-cluster-connector: allow dashes/underscores in nodenames

  Resolves: rhbz#1829085gu/[Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992
ZI~qu	\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737pu/\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992wou}\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'nu[\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121vmq\Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950
#F#vvq]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61^y- exportfs: add symlink support

  Resolves: rhbz#1601950{uq]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-60^@- nfsserver: fix NFSv4-only support

  Resolves: rhbz#1840750
tq%]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-59^ϧ- gcp-pd-move: new resource agent for Google Cloud

  Resolves: rhbz#1633249sq=]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-58^@- db2 (HADR): promote standby node when master node disappears

  Resolves: rhbz#17202835rq{]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-56^- sap-hana-scaleout: set default timeouts based on recommendations
  and a couple of bugfixes

  Resolves: rhbz#1829081
{YA{A{u]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.8`<@- gcp-vpc-move-route, gcp-vpc-move-vip: add project parameter and
  make vpc_network parameter optional

  Resolves: rhbz#1913936~zu	]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.5_@- AWS agents: add support for IMDSv2

  Resolves: rhbz#1905737yu/]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.4_w@- Upgrade bundled python-httplib2 to fix CVE-2020-11078

  Resolves: rhbz#1850992wxu}]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.2_FN- azure-lb: fix redirect issue

  Resolves: rhbz#1850779'wu[]Oyvind Albrigtsen <oalbrigt@redhat.com> - 4.1.1-61.1_'@- gcp-vpc-move-vip: add support for multiple alias IPs
- sybaseASE: run verify action during start action only
- azure-events: handle exceptions in urlopen

  Resolves: rhbz#1846732
  Resolves: rhbz#1848673
  Resolves: rhbz#1862121
1n~gw^William Poteat <wpoteat@redhat.com> 1.24.38-1^V@- 1837244: Fix wrong version provided by subscription-manager version; ENT-2388
  (jhnidek@redhat.com)
- 1834792: Try to terminate rhsmd after timeout; ENT-2368 (jhnidek@redhat.com)m}gu^William Poteat <wpoteat@redhat.com> 1.24.37-1^I- 1830994: Fix warning messages in dnf/yum (jhnidek@redhat.com)
- 1823523: Detect rhsm-icon running without psutil (csnyder@redhat.com)
- 1771921: Package profiles sends too early when registering a client
  (wpoteat@redhat.com)
- 1688702: Generate redhat.repo in off-line mode; ENT-2302 (jhnidek@redhat.com)J|g/^William Poteat <wpoteat@redhat.com> 1.24.36-1^U@- 1831104: When in Simple Content Access mode, subscription-manager should not
  complain that subscriptions aren't attached (wpoteat@redhat.com)
>a9o^Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XgK^William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)yo^Christopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)@o^Christopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)
> >@o_Christopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)gK^William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gA^William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)Co^Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
C
o_Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9	o_Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XgK_William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)yo_Christopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)
hj}o
_Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)o!_Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P
o3_Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)gK_William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gA_William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)
#egA`William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)Co`Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9o`Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XgK`William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)
coC`Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)Fo`Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
`Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)o!`Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3`Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)gK`William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
BbgKaWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gAaWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CoaChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9oaChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)
+S"oCaChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F!oaChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)} o
aChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)o!aChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3aChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
7%gAbWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)C$obChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)|#oaChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)
c+oCbChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F*obChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)})o
bChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)(o!bChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P'o3bChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)&gKbWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
|,obChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
L/gKcWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com).gAcWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)'-ekbPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidek=h

er+V:eDo
d850176c0a4cdf0424b72ae4e068e7464ebcaba44a41850c646e0e7b0e8b2ac7Dn
6055927e846079a3ce12f1dd26324dd574b3c9ee5586ac850d83353548a1f68cDm
6e90444675848a4c5c3119f364cbb66d41bf048c40ae4f2af79225fe2278dcb4Dl
e085961e3f16d1265f8327c5a41bf5ca2eea0419c2b09b20092466009a492983Dk
838de1ef14179e1a8bb9c6a1bab3b688e72d7571e8442fa520294f469817484eDj
a2f2af622884bf98fdf41e5b0a6ddb5e6e8b63443f213bbaecd8e9e08096de98Di
55a9b8612201e7db7b7823d8075e79401bb12973850ce1975a877189671c59f7Dh
f864e79dfe36d75d7556fb743ec1038d71b3a2297a830d51c78853475c425d76Dg
6999892560bc188d71af958078c8b9560ffeb626747978ac0a90a392c446598fDf
7ec2f032f1c9b576b66559472dbe5f59eff0b891da2e1c9a1794711b872c6cdbDe
5fb69356881606ecd95f99c9d00d35c86e20c4e0489e6983a59445f286cf8d70Dd
743d9e213a14ae1fa06bcef18a210a44805cb5da5b65c0f584ac8098ed4b81e6Dc
88d0132317540d77db005b570d44a340644516f643914b0a811161f3f3f83a7f
+S4oCcChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F3ocChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}2o
cChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)1o!cChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P0o3cChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
|5ocChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
KLK8gAdWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)e7amcJiri Hnidek <jhnidek@redhat.com> 1.24.52-2d.@- 2229752: Fix D-Bus policy (jhnidek@redhat.com)'6ekcPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidek=m
c>oCdChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F=odChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}<o
dChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com);o!dChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P:o3dChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)9gKdWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
|?odChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'@ekdPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidek=q
Do!eChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)PCo3eChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)BgKeWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)pAe}dPino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
|HoeChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)GoCeChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FFoeChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}Eo
eChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'IekePino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidek=u
CMfPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-38\|- Add flag to use strip -g instead of full strip on DSOs (#1663264)L#fPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-37\+@- Use user and group of the rpmbuild process or root for sources (#1572772)CKQ7ePino Toscano <ptoscano@redhat.com>e@- tito: drop bz requirement (ptoscano@redhat.com)
- fix: 1.24 Add python-requests to the list of required RPMs
  (jhnidek@redhat.com)
- fix: Pin lxml to last version supporting Python 2 (mhorky@redhat.com)
- fix: Add missing package intltool to test script (jhnidek@redhat.com)pJe}ePino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
uVW_ToSfMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchpSoufMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)RofPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xQmfPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)P}fPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)O%fPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)Ng'fTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)
h`_hp[ougMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)ZogPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xYmgPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)X}gPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)W%gPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)Vg'gTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)wUofMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)
["w[bg'hTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)ahPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-38\|- Add flag to use strip -g instead of full strip on DSOs (#1663264)`#hPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-37\+@- Use user and group of the rpmbuild process or root for sources (#1572772)r_oygMichal Domonkos <mdomonko@redhat.com> - 4.11.3-48a- Fix double-free in previously added patch (#2004228)^oAgMichal Domonkos <mdomonko@redhat.com> - 4.11.3-47aqV@- Improve range checks on signature and main header tags (#2004228)
- Fixes CVE-2021-20271w]ogMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_\oSgMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patch
fenwiohMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_hoShMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchpgouhMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)fohPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xemhPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)d}hPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)c%hPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)
uVW_poSiMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchpoouiMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)noiPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xmmiPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)l}iPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)k%iPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)jg'iTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)
$sI$w%jPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)vg'jTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)ujPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-38\|- Add flag to use strip -g instead of full strip on DSOs (#1663264)t#jPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-37\+@- Use user and group of the rpmbuild process or root for sources (#1572772)rsoyiMichal Domonkos <mdomonko@redhat.com> - 4.11.3-48a- Fix double-free in previously added patch (#2004228)roAiMichal Domonkos <mdomonko@redhat.com> - 4.11.3-47aqV@- Improve range checks on signature and main header tags (#2004228)
- Fixes CVE-2021-20271wqoiMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)
{|*~g'kTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)w}ojMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_|oSjMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchp{oujMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)zojPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xymjPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)x}jPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)
fenwokMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_oSkMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchpoukMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)okPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xmkPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)}kPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)%kPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)
dU9}lPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)%lPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)
g'lTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)	lPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-38\|- Add flag to use strip -g instead of full strip on DSOs (#1663264)#lPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-37\+@- Use user and group of the rpmbuild process or root for sources (#1572772)roykMichal Domonkos <mdomonko@redhat.com> - 4.11.3-48a- Fix double-free in previously added patch (#2004228)oAkMichal Domonkos <mdomonko@redhat.com> - 4.11.3-47aqV@- Improve range checks on signature and main header tags (#2004228)
- Fixes CVE-2021-20271
*mPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-38\|- Add flag to use strip -g instead of full strip on DSOs (#1663264)#mPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-37\+@- Use user and group of the rpmbuild process or root for sources (#1572772)wolMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_oSlMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchpoulMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)olPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)x
mlPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)
uVW_oSmMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchpoumMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)omPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xmmPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)}mPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)%mPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)g'mTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)
h`_hp!ounMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006) onPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xmnPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)}nPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)%nPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)g'nTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)womMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)
f"f(}oPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)'%oPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)&g'oTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)r%oynMichal Domonkos <mdomonko@redhat.com> - 4.11.3-48a- Fix double-free in previously added patch (#2004228)$oAnMichal Domonkos <mdomonko@redhat.com> - 4.11.3-47aqV@- Improve range checks on signature and main header tags (#2004228)
- Fixes CVE-2021-20271w#onMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_"oSnMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patch
*r/oyoMichal Domonkos <mdomonko@redhat.com> - 4.11.3-48a- Fix double-free in previously added patch (#2004228).oAoMichal Domonkos <mdomonko@redhat.com> - 4.11.3-47aqV@- Improve range checks on signature and main header tags (#2004228)
- Fixes CVE-2021-20271w-ooMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_,oSoMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchp+ouoMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)*ooPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)x)moPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)

er+V:eD|
dc47fdc3f4078f0e108d5906bf66ded4e5642cacf6309ac532e5e06c533878baD{
0f2573a885d17c39d3733cec678c69833ac6d49b29e7e65f7783644066ec0b8dDz
55f08ad739819e709de85f5c4527291e0f16eaae36d650b0616bbe2b34dda6cdDy
9d9440a2b4ed4979c7741c8ff246d32dd982cf24ff59fb679bee4516ab71f0d1Dx
5bf6acef9988011be2fdcbfe74a0c08dafb93852b5728854c765bf5d29f344b1Dw
bd8c7fed84bd9c96c9070953fff9bc087ea7a8ba8cd56bfd5fc956ef76df0492Dv
cdf297d87f9e31de2e54f1bf4d87339af059f5d4048b6160bee5114397b3fa21Du
4be78491df030e9fec9f5e5789c29611f39d783a9bf1e70cab686d996dc7f9eeDt
0474de8faa6866555281a93c12b25c1f8e532892f9dec72d0ccbaedaa2257d75Ds
d1937f2c7485f2270affb2fae284834c2bfb13cad80964b9cd2717fed8279cbcDr
2ebad179e5985efceb7d0129bf95c5bdb47be73f2fad61d7da432bf901ce14faDq
74d5c2dc05acd6045abc44a395a51bc278efcd90d8b9949118c7b18193eccde5Dp
0de926f65070e07d518fd6dde604c0aa41ed7aedee86e9dbd0db39abed1534cbv<JNTZ`flrx~ &,28>DJPV\bhntz
"(.4:@FLRX^djpv|HB<JJJu8ɤ*8792D9Q:^:Kk:^x:x:;;7,;L9;F;S<-`<Cm<Zz<p<<!<.<;=H=3U=Lb=jo=|=	==֧#=0>=>6J>VW>d>̧q>~???3%?K2?f??L?Y?f?Ψs??
@@2'@L4@fA@N@[@h@Ωu@AA)AF)A^6ACAPA]B;jB~wBūC
CPC+C۫8DEDbRD_DlE7yE}EF F0-F^:FGFTFaFnG2{GgGG˭"Gޭ/G<GIHVH(cHJpHl}H
HHЮ$H1I>I<KIXXImeIrIIIIد&I3J@JMJ1ZJGgJ]t
-gK,-6opPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)x5mpPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)4}pPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)3%pPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)2g'pTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)1pPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-38\|- Add flag to use strip -g instead of full strip on DSOs (#1663264)0#pPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-37\+@- Use user and group of the rpmbuild process or root for sources (#1572772)
)#x=mqPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)<}qPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590);%qPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181):g'qTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)w9opMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_8oSpMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchp7oupMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)
}	+D#rPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-37\+@- Use user and group of the rpmbuild process or root for sources (#1572772)rCoyqMichal Domonkos <mdomonko@redhat.com> - 4.11.3-48a- Fix double-free in previously added patch (#2004228)BoAqMichal Domonkos <mdomonko@redhat.com> - 4.11.3-47aqV@- Improve range checks on signature and main header tags (#2004228)
- Fixes CVE-2021-20271wAoqMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_@oSqMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchp?ouqMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)>oqPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)
RoJIRpKourMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)JorPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xImrPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)H}rPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)G%rPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)Fg'rTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)ErPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-38\|- Add flag to use strip -g instead of full strip on DSOs (#1663264)
N"mNR}sPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)Q%sPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)Pg'sTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)OsPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-38\|- Add flag to use strip -g instead of full strip on DSOs (#1663264)N#sPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-37\+@- Use user and group of the rpmbuild process or root for sources (#1572772)wMorMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_LoSrMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patch
*$Y%tPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)Xg'tTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)wWosMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_VoSsMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchpUousMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)TosPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xSmsPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)
{|*raoytMichal Domonkos <mdomonko@redhat.com> - 4.11.3-48a- Fix double-free in previously added patch (#2004228)`oAtMichal Domonkos <mdomonko@redhat.com> - 4.11.3-47aqV@- Improve range checks on signature and main header tags (#2004228)
- Fixes CVE-2021-20271w_otMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_^oStMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchp]outMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)\otPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)x[mtPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)Z}tPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)
uVW_hoSuMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchpgouuMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)fouPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xemuPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)d}uPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)c%uPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)bg'uTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)
$sI$o%vPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)ng'vTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)mvPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-38\|- Add flag to use strip -g instead of full strip on DSOs (#1663264)l#vPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-37\+@- Use user and group of the rpmbuild process or root for sources (#1572772)rkoyuMichal Domonkos <mdomonko@redhat.com> - 4.11.3-48a- Fix double-free in previously added patch (#2004228)joAuMichal Domonkos <mdomonko@redhat.com> - 4.11.3-47aqV@- Improve range checks on signature and main header tags (#2004228)
- Fixes CVE-2021-20271wiouMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)
{|*v#wPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-37\+@- Use user and group of the rpmbuild process or root for sources (#1572772)wuovMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_toSvMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchpsouvMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)rovPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xqmvPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)p}vPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)
RoJIRp}ouwMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)|owPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)x{mwPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)z}wPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)y%wPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)xg'wTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)wwPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-38\|- Add flag to use strip -g instead of full strip on DSOs (#1663264)
y"xyoxPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xmxPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)}xPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)%xPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)g'xTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)wowMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_~oSwMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patch
w)w%yPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)
g'yTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)r	oyxMichal Domonkos <mdomonko@redhat.com> - 4.11.3-48a- Fix double-free in previously added patch (#2004228)oAxMichal Domonkos <mdomonko@redhat.com> - 4.11.3-47aqV@- Improve range checks on signature and main header tags (#2004228)
- Fixes CVE-2021-20271woxMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_oSxMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchpouxMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)
{|*royyMichal Domonkos <mdomonko@redhat.com> - 4.11.3-48a- Fix double-free in previously added patch (#2004228)oAyMichal Domonkos <mdomonko@redhat.com> - 4.11.3-47aqV@- Improve range checks on signature and main header tags (#2004228)
- Fixes CVE-2021-20271woyMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_oSyMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchpouyMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)oyPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)x
myPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)}yPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)
-gK,-ozPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xmzPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)}zPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)%zPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)g'zTomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)zPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-38\|- Add flag to use strip -g instead of full strip on DSOs (#1663264)#zPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-37\+@- Use user and group of the rpmbuild process or root for sources (#1572772)bR=RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{=e%=f+=g,=i/=k4=l5=n8=o>=p?=r@=sD=tH=vI=wM=xT=y[=zb={i=|p=}w=~~=====!=(=/=6===D=K=R=Y=a=h=o=v=}=====!=(=/=6===D=K=R=Z=a=h=m=p=u=y=~========="='=+=0=5=8===@=E=I=N=R=W=\=_=d=ƒg=Ãj=ăo=Ńr=ƃw=ǃ{=ȃ=Ƀ=ʃ=˃
=̃=̓=΃=σ=Ѓ"
)#x!m{Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232) }{Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)%{Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)g'{Tomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)wozMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_oSzMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchpouzMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)
}	+(#|Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-37\+@- Use user and group of the rpmbuild process or root for sources (#1572772)r'oy{Michal Domonkos <mdomonko@redhat.com> - 4.11.3-48a- Fix double-free in previously added patch (#2004228)&oA{Michal Domonkos <mdomonko@redhat.com> - 4.11.3-47aqV@- Improve range checks on signature and main header tags (#2004228)
- Fixes CVE-2021-20271w%o{Michal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_$oS{Michal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchp#ou{Michal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)"o{Panu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)
RoJIRp/ou|Michal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006).o|Panu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)x-m|Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232),}|Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)+%|Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)*g'|Tomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402))|Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-38\|- Add flag to use strip -g instead of full strip on DSOs (#1663264)
y"xy6o}Panu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)x5m}Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)4}}Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)3%}Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)2g'}Tomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)w1o|Michal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_0oS|Michal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patch

er+V:eD	
10f4d4344b761febc0bc92621104b56e8002faba2566c0f27a1152a2951005edD
8bb3427e24cc96d1a03b8501420a96372b0121baf87a18de170d70b0423f324eD
65199e9ea2e12be16d067a95704c987d84ddb573ef4d2dca215c5cd3a28b3b2cD
6c7c9ba4877418093e491bb7d8133af21eb702e5e6c5220866cf64e6755dadb3D
87d2bce399fdc13d6471dbc90583d7e69c82b39679f9b844bea1a2f3051c3d10D
7040c353b5fb82abf2f6a8f2ca1f7dc6752192e19210070275d4676cc61318b3D
977e49aa36e447c99e215e9eeb2628e0e19cafb64eca4dbe1affffcfe2ad2c6fD
a90d954e0c0bebfc47ee93b810520648c177574c86546b7215d65bbd566e1850D
cb67d241eba9a27bbdc48cb45a7d59bf2fa393abbdd65778e51bb78396255ac4D
1204cfb28866866392e87bed4b27492fc16eb53791f205892fab3ad27a9bf935D
74820898155583309223b3ef4e3d5a41b76e9d492696051d4ec79f981d16febbD~
8dd767740e6b6382366fcbecc18ee6a8aa1e5cd856ce2b54b3611960dc3c297eD}
05cd5d302b4787e4b7f4d091ae0e2cfc78a0ad48883502cb3bc7ec1cf2c8601a
r)r=~Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-38\|- Add flag to use strip -g instead of full strip on DSOs (#1663264)<#~Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-37\+@- Use user and group of the rpmbuild process or root for sources (#1572772)r;oy}Michal Domonkos <mdomonko@redhat.com> - 4.11.3-48a- Fix double-free in previously added patch (#2004228):oA}Michal Domonkos <mdomonko@redhat.com> - 4.11.3-47aqV@- Improve range checks on signature and main header tags (#2004228)
- Fixes CVE-2021-20271w9o}Michal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_8oS}Michal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchp7ou}Michal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)
uVW_DoS~Michal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patchpCou~Michal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)Bo~Panu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xAm~Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)@}~Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)?%~Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)>g'~Tomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)
h`_hpKouMichal Domonkos <mdomonko@redhat.com> - 4.11.3-44^V@- Accept PGP public keys with missing EOL (#1840006)JoPanu Matilainen <pmatilai@redhat.com> - 4.11.3-43]4@- Fix packages getting removed on failed update via dnf (#1710691)xImPavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-42]]2@- Fix segfault on fingerprint symlink (#1660232)H}Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-41]V- Fix bogus if-condition in find-debuginfo.sh (#1720590)G%Pavlina Moravcova Varekova <pmoravco@redhat.com> - 4.11.3-40\- Remove only special perl dependencies provided in the same file (#1570181)Fg'Tomas Orsava <torsava@redhat.com> - 4.11.3-39\|- Fix brp-python-bytecompile script to work with Python 3 packages (#1691402)wEo~Michal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)
S"wSRc+Ville Skyttä <ville.skytta@iki.fi> - 8.3-1PCJ@- Update to 8.3.
- Drop specfile constructs no longer needed with Fedora's rpm.QFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 8.2-3P
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildPFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 8.2-2On@- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_RebuildrOoyMichal Domonkos <mdomonko@redhat.com> - 4.11.3-48a- Fix double-free in previously added patch (#2004228)NoAMichal Domonkos <mdomonko@redhat.com> - 4.11.3-47aqV@- Improve range checks on signature and main header tags (#2004228)
- Fixes CVE-2021-20271wMoMichal Domonkos <mdomonko@redhat.com> - 4.11.3-46aD@- Bump up the limit of signature header to 64MB (#1993242)_LoSMichal Domonkos <mdomonko@redhat.com> - 4.11.3-45^?@- Actually apply the previous patch
>z,%>dZ?Michal Ruprich - 3.0.9-18XA- Resolves: #1324754 -  rsyncd unit enters failed state on exit{YgMichal Domonkos <mdomonko@redhat.com> - 8.3-8_@- spectool: fix regression in URL fragment handling (RHBZ#1899112)jXgqMichal Domonkos <mdomonko@redhat.com> - 8.3-7^H- Actually apply the spectool patch (RHBZ#1337544)WgCMichal Domonkos <mdomonko@redhat.com> - 8.3-6^@- spectool: ignore query string in URL (RHBZ#1337544)
- Update upstream URLs (RHBZ#1502423)JVY?Daniel Mach <dmach@redhat.com> - 8.3-5Rk- Mass rebuild 2013-12-27UiThomas Woerner <twoerner@redhat.com> - 8.3-3.1Rq@- removed fakeroot requirement and all qa_robot scripts (RHBZ#840780)TFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 8.3-3Q- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildfSekThomas Woerner <twoerner@redhat.com> - 8.3-2P}L@- xemacs is not available on RHEL (RHBZ#866841)
EixEai9Michal Ruprich <mruprich@redhat.com> - 3.1.2-9]5@- Resolves: #1633850 - rsync is unable to preserve NFS v4 ACLs via extended attributes`iKMichal Ruprich <mruprich@redhat.com> - 3.1.2-8]4S- Resolves: #1566149 - rsync without --verbose still writes "(new) backup_dir is ..." to STDOUTx_i	Michal Ruprich <mruprich@redhat.com> - 3.1.2-7\@- Resolves: #1690786 - remove-source-files fails with symlinksq^i}Michal Ruprich <mruprich@redhat.com> - 3.1.2-6[zA- Related: #1615799 - reverting changes made in RHEL-7.6]i!Michal Ruprich <mruprich@redhat.com> - 3.1.2-5[z@- Resolves: #1615799 - Rsync built-in testsuite fails with selinux enabled\=uMichal Ruprich - 3.1.2-4YB@- Related: #1432899 - removing dependencies on perl
- using the bundled zlib.h(#1491582)
- turning on upstream testsm[=Michal Ruprich - 3.1.2-1Y- Resolves: #1432899 - Rebase rsync to version >= 3.1.0
- rebase to 3.1.2
2XI#2xhi	Michal Ruprich <mruprich@redhat.com> - 3.1.2-7\@- Resolves: #1690786 - remove-source-files fails with symlinksqgi}Michal Ruprich <mruprich@redhat.com> - 3.1.2-6[zA- Related: #1615799 - reverting changes made in RHEL-7.6fi!Michal Ruprich <mruprich@redhat.com> - 3.1.2-5[z@- Resolves: #1615799 - Rsync built-in testsuite fails with selinux enablede=uMichal Ruprich - 3.1.2-4YB@- Related: #1432899 - removing dependencies on perl
- using the bundled zlib.h(#1491582)
- turning on upstream testsmd=Michal Ruprich - 3.1.2-1Y- Resolves: #1432899 - Rebase rsync to version >= 3.1.0
- rebase to 3.1.2ckIMichal Ruprich <mruprich@redhat.com> - 3.1.2-11b- Resolves: #2111170 - remote arbitrary files write inside the directories of connecting peers#bk]Michal Ruprich <mruprich@redhat.com> - 3.1.2-10]_@- Resolves: #1672779 - Rsync bug resets modification time of every destination file that has not changed
b%mkEMichal Ruprich <mruprich@redhat.com> - 3.1.2-12cjD- Resolves: #2123815 - rsync error: protocol incompatibility when using rsync-3.1.2-11.el7_9lkIMichal Ruprich <mruprich@redhat.com> - 3.1.2-11b- Resolves: #2111170 - remote arbitrary files write inside the directories of connecting peers#kk]Michal Ruprich <mruprich@redhat.com> - 3.1.2-10]_@- Resolves: #1672779 - Rsync bug resets modification time of every destination file that has not changedji9Michal Ruprich <mruprich@redhat.com> - 3.1.2-9]5@- Resolves: #1633850 - rsync is unable to preserve NFS v4 ACLs via extended attributesiiKMichal Ruprich <mruprich@redhat.com> - 3.1.2-8]4S- Resolves: #1566149 - rsync without --verbose still writes "(new) backup_dir is ..." to STDOUT
[[?piJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!oi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566niJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"ui]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992tiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{siJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_riWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'qigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
JZJ?yiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!xi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856!wqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!vi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"~i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992}iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{|iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_{iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'zigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
TZT?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
ZziAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686qCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395
q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!	qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
[[?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566
iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
yZy!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
<_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171
pcp!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841
Z'"igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?!iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171! i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!'i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"&i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992%iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{$iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_#iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
NZN'+igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?*iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171)q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!(qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
22!0i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"/i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992.iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{-iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_,iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
LZ L65iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#17446824iAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#16966863qCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#20813952q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!1qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717

er+V:eD
4370607a6da65b16c10efee16a7e7dc47d3ca219e5adbb651ea25e3150d278f4D
b58cede57828d0966881342f8638cc0309f8064b70437b0adf9d649bfe1ade45D
92a1308d201f7d1061b56b28ce70c44b58e1f876568a1cd1ce0d04d71b4e616fD
763431d569a4717a132d38c72d98eb0656623f04155dc15baf5f8face7a581aaD
96d562d6852e65228f853d36aee7193ca56da0031cf09991e2d16e15f55f69ffD
a8df8c8e4de2b928926717150e1d011ee1c85226c1099e9ddabfe5b08e2d0d4eD
32e1c67e1aff171de13642d103f733792e12a4c17c9ee64aa931d2315b08e1ecD
8ece8095faf9fc05572d63b861d8bc795ed3d56a7c3235a44d3ee07d1403cde5D
af56985c8953b2fc45d7974249df068c6d8d965f223db2279293d3ff072df271D

fdec48655b5d576de07b5788ee9206ab7b71c6fb8374b3e7fa47f3b65bfea9f3D
786d9abb0444f4e1a0a27702f0bb4b6278bcf8c30e15093e909b111eae35842cD
99f7afea90a0a26964c80545f90fd551c442f1fdcb3ccdd6be042506650e78d5D

e3a12de0d6fa0c1cb65f6e6311428c947041d9751905ca6825693129f0d1e5a5
Z'8igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?7iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!6i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!=i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"<i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992;iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{:iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_9iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
[[?@iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!?i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566>iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"Ei]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992DiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{CiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_BiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'AigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
JZJ?IiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!Hi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856!GqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!Fi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"Ni]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992MiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{LiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_KiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'JigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
TZT?RiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171Qq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!PqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!Oi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"Wi]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992ViIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{UiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_TiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'SigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
Zz\iAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686[qCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395Zq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!YqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!Xi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
[[?_iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!^i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566]iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"di]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992ciIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{biJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_aiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'`igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
yZy!gi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566fiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682!ei[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
<_jiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'iigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?hiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171
pcp!oqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!ni[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"mi]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992liIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{kiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841
Z'rigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?qiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!pi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!wi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"vi]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992uiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{tiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_siWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
NZN'{igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?ziJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171yq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!xqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
22!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992~iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{}iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_|iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
LZ L6iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682iAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686qCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
Z'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!
i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{
iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_	iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
[[?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
JZJ?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
TZT?"iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505! qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"'i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992&iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{%iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_$iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'#igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
Zz,iAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686+qCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395*q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!)qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!(i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
[[?/iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!.i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566-iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"4i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#18439923iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{2iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_1iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'0igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
yZy!7i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#174485666iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682!5i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297

er+V:eD#
8480c9c162030638d7e1aeafac122629e6446c5a5c93910cdd0ea2bdc51c5597D"
68c911318f2dcbe594b8475d8adb5d700b385aded343fa7870ca41d70e302681D!
5d6548300fb6f193fc969c4a7b833ac0ebc9a04231decb2ff8f853bf5fe358e0D 
2825f16fd21e4445da86539295790890cabf52e583783c3a52aaa3c565dc6ecbD
998aeda730e4ca3c63ce73e2345ed6e97ec1682e90df490b0e96faff1ebf4665D
64beb126b2ee27d945966c6e8ed0eb93929053bfca0af0c12db4ed0a2219389cD
97de1dacbcdab0e2e4fb05e8ddc0616aa314dfa320e4635133391b3491d7cc95D
435f966aab54d076f8753e805379be8aab3e4bb69459fff3ce7c63cef6a043c8D
e19244daf20ce87cf283cadda5ea9d45bb6c17bfdb674dfeef35d29825c62af2D
4ad790401b462e49852b64d52ac831ef97ef989b5b507c46e6711cbffdc8e689D
de9c5a6a93ac35ebe471dd45b8186ff0a1ee0c2c80c9e122c072728aa4e603a7D
6d5044b286e25a56e8f05f0e476289cd678bdace8a5cdf6c00b7b99df760dd47D
412cf05f06bbad13dcf4147fd9d0fe36f85f1ac4e736a1e70cceb3317d6375ed
<_:iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'9igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?8iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171
pcp!?qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!>i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"=i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992<iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{;iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841
Z'BigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?AiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!@i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!Gi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"Fi]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992EiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{DiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_CiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
NZN'KigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?JiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171Iq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!HqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
22!Pi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"Oi]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992NiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{MiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_LiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
LZ L6UiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682TiAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686SqCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395Rq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!QqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
Z'XigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?WiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!Vi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!]i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"\i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992[iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{ZiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_YiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
[[?`iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!_i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566^iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"ei]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992diIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{ciJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_biWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'aigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
JZJ?iiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!hi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856!gqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!fi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"ni]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992miIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{liJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_kiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'jigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
TZT?riJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171qq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!pqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!oi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"wi]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992viIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{uiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_tiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'sigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
Zz|iAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686{qCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395zq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!yqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!xi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
[[?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!~i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566}iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
yZy!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
<_
iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'	igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171
pcp!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"
i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841
Z'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
NZN'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
22! i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
LZ L6%iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682$iAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686#qCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395"q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
Z'(igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?'iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!&i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!-i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297",i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992+iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{*iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_)iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
[[?0iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!/i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566.iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"5i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#18439924iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{3iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_2iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'1igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
JZJ?9iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!8i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856!7qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!6i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297

er+V:eD0
f5431ddb3fa8ee6d51952c046b560ee5619c84a6216a417156f99dd392045d24D/
db07f94b0ea8f757e8c7e4e9ab64552d472d4baf724499628c1d7447b4ce574bD.
3135fb73649247a469c3691a2239b2a4121aa0631f04e3bbb0f5c25bac9f93c7D-
edc739d70b417881fba0df26ea94231e859c67a681a92b7a79ac1c97f5bba817D,
2163bd81f1d4891e8048088136ac2e2285db8db7bf8cfe2aeb16b8fe1d7f8085D+
c81f90a03e1572c395b80f30a24efd34def63ec2a53550ae57b48380ded6bcd5D*
b03ee55965cce1d19f8f7a5b24672dccf097948e9345a8b8a66584397af9732eD)
f45ad8b56aec3746c319fed77321ec80808dbcf5aba0a01712c29bf922951edbD(
1fcad50692febc35d99fcc084dee4f58b8bcb6471e12072b6ea2bcf2cfe49dfdD'
093f80fc5d8e0da79a3979e52dfdc01e24389db68934cf76c4a575367b63914cD&
84ea46ab16a2d8ddddcb890ba2ccf11b3c873260b9756f1ed64d7aa1a779ac5eD%
c75b3f328720ad1b052e7621ddbf3ccfea04b35a21209225248e310d623b5644D$
836ae43529ca6681c98238726bad12871f01ac8436aa3e19605c87ec7aded177
,Tpp,">i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992=iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{<iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_;iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746':igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
TZT?BiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171Aq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!@qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!?i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"Gi]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992FiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{EiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_DiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'CigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
ZzLiAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686KqCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395Jq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!IqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!Hi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
[[?OiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!Ni[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566MiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"Ti]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992SiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{RiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_QiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'PigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
yZy!Wi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566ViJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682!Ui[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
<_ZiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'YigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?XiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171bR>9RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{=҃,=Ӄ/=ԃ4=Ճ7=׃:=؃?=كB=ڃG=ۃK=܃P=݃U=ރX=߃]=`=Ⴣe=⃃i=ッn=䃃r=僃w=惃|=烃=胄=郄=ꃄ
=냄=샄=탄== =%=(=-=0=5=9=>=B=G=L=O=T=W=Z>_>b>g>k>p>u>x>}>>	>
	>>>
>>>$>'>*>/>2>7>;>@>E>H>M>P>U>Y>^> b>!g>"l>#o>$t>%w>&z>'>(>)>*>+>,>->.>/ >0%>1)>2.>32>47>5<>7?>8D
pcp!_qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!^i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"]i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992\iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{[iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841
Z'bigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?aiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!`i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!gi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"fi]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992eiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{diJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_ciWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
NZN'kigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?jiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171iq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!hqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
22!pi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"oi]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992niIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{miJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_liWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
LZ L6uiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682tiAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686sqCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395rq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!qqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
Z'xigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?wiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!vi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!}i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"|i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992{iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{ziJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_yiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
[[?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566~iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
JZJ?	iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992
iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'
igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
TZT?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
ZziAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686qCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
[[?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"$i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992#iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{"iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_!iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746' igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
yZy!'i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566&iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682!%i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
<_*iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746')igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?(iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171
pcp!/qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!.i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"-i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992,iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{+iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841
Z'2igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?1iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!0i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!7i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"6i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#18439925iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{4iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_3iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
NZN';igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?:iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#16001719q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!8qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717

er+V:eD=
4435a2d66b8a1b83a30085a0be118a8b93bf7989d924736ce0ab0c1085446d8bD<
7fde0881297ab193f65e33fd5c8b564df7735f25fdee512b44a93fc5919686e3D;
7f98ddb94869395b5d09e7f387eb87ae1829dcd23a0e383391bf1b8f7b2a9dfbD:
ff6ddec249d0b0ae7fe315e3626507ee4cbcf1c98b1ef5a0b571846cfa67ac37D9
53ce8c9651b597aaf7b719c2d54b58fe264c394bd216587abb5e3c9981502c35D8
d1af2d4f355246306f9048649c71512ffc060b2884722d14e15d42ae54300524D7
1d9cb7ca8c804f9fa970b5e2df8cc163112c6d02f4769316009d22c080bddf91D6
6862243c7d4e91bdc68839fc5b50b2fe2d9be11cdc30df983b8506abd9bd00abD5
53785b577694f90da1cd6542ee6cd7b90b33ac6f11db3ae5b38c3a417ea82085D4
898e4f478919925f999cecc6d8765d5ca6196494ad8200b1c02607de58303982D3
13a2da96e0859c06d6b4b719445081c65053460547c38ccf8f0a2c1e06b039cbD2
295e1258aea3781299e6710ef8708bef6a5dd8bc6617af2cf2e7e205f45081b0D1
8dce1ab16065eccc2ffb9c5d0e51f15c77fa6e7e03bae26aa3ebbd9092a330a2
22!@i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"?i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992>iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{=iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_<iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
LZ L6EiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682DiAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686CqCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395Bq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!AqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
Z'HigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?GiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!Fi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!Mi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"Li]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992KiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{JiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_IiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
[[?PiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!Oi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566NiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"Ui]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992TiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{SiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_RiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'QigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
JZJ?YiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!Xi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856!WqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!Vi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"^i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992]iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{\iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_[iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'ZigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
TZT?biJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171aq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!`qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!_i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"gi]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992fiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{eiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_diWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'cigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
ZzliAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686kqCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395jq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!iqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!hi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
[[?oiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!ni[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566miJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"ti]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992siIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{riJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_qiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'pigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
yZy!wi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566viJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682!ui[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
<_ziWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'yigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?xiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171
pcp!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!~i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"}i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992|iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841
Z'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
NZN'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?
iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171	q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
22!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{
iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
LZ L6iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682iAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686qCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
Z'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
[[? iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"%i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992$iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{#iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_"iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'!igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
JZJ?)iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!(i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856!'qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!&i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,".i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992-iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{,iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_+iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'*igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
TZT?2iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#16001711q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!0qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!/i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"7i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#18439926iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{5iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_4iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'3igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
Zz<iAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686;qCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395:q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!9qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!8i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297

er+V:eDJ
621d13e7c135311f66ed8669c828821fa8da5c7b602afb4066d01bcdddf43bc3DI
25b4bbbd9ce981e8e49520f5c93c5c8ffc7b6d26b911440cb79a134719182d2cDH
4ee55b429ec95f43a7388f2b424b8db5a2a637fb009b640ffe07fc328900315eDG
0d30036d6a876fd21fc61439985a43f29d496b4089d41c5fa578c65ecde1d198DF
c52c2ec344adb35fb699f72d9fab8082e82e08caea1e844a3afc83b4ff564820DE
6ceb416b5532f415886858adab254c77f6774ca35e5bf9bb0d73e58fa794a0ffDD
aebed6c3e895ca3c142741fbc5d368ca8af370a2dcefaff98e3d2e596055f29eDC
5734c3f66c0d576c4dd6f560daf55c682f147e046ce312efb7cf7c0428164edeDB
5a7f183ea8444e1f7ef2ca3b7c8339565f6b19fb23f0968b9b3171b2d50a64ddDA
61151006ef84f2d4d9a7972cde6323a16d6ef02ce23105493ff8386ffb7d7708D@
d770a9ddaeae868ed4fb99212c73d0d42e4532aa0842040000775c829f11459fD?
a8c5b5cdea96dc06b0e2bfe64814361d7099d10d8c06277305f17129b0304233D>
67269c66b7c5a0c291c9f49a9ab7b1185370d1686cb0538cf41f90cbc4853472
[[??iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!>i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566=iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"Di]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992CiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{BiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_AiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'@igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
yZy!Gi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566FiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682!Ei[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
<_JiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'IigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?HiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171
pcp!OqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!Ni[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"Mi]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992LiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{KiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841
Z'RigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?QiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!Pi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!Wi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"Vi]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992UiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{TiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_SiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
NZN'[igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?ZiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171Yq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!XqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
22!`i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"_i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992^iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{]iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_\iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
LZ L6eiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682diAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686cqCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395bq?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!aqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
Z'higJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?giJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!fi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!mi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"li]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992kiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{jiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iiWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
[[?piJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!oi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566niJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"ui]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992tiIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{siJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_riWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'qigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
JZJ?yiJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!xi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856!wqSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!vi[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"~i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992}iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{|iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_{iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'zigJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
TZT?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
,Tpp,"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
ZziAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#1696686qCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#2081395
q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!	qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
[[?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566
iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682
,Tpp,"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)
yZy!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#17448566iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#1744682!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297
<_iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746'igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171
pcp!qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717!i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841
Z'"igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?!iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171! i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!'i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"&i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992%iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{$iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_#iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
NZN'+igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?*iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171)q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!(qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
22!0i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"/i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992.iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{-iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_,iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746
LZ L65iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-46]flRHEL 7.8 ERRATUM
- Support Intermediate Certificate Chains in rsyslog
  resolves: rhbz#1627799
- fixed WorAroundJournalBug patch to not cause leaks
  resolves: rhbz#1744617
- added patch fixing possible segfault in rate-limiter
  resolves: rhbz#17446824iAJiri Vymazal <jvymazal@redhat.com> - 8.24.0-45]QTRHEL 7.8 ERRATUM
- fixed fsync patch according to covscan results
  resolves: rhbz#16966863qCAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.3b{@- Address CVE-2022-24903, Heap-based overflow in TCP syslog server
  resolves: rhbz#20813952q?Attila Lakatos <alakatos@redhat.com> - 8.24.0-57.2b4t@RHEL 7.9.Z ERRATUM
- guard HUP signal processing in ompipe module
  resolves:rhbz#2062505!1qSAttila Lakatos <alakatos@redhat.com> - 8.24.0-57.1`dd@RHEL 7.9.Z ERRATUM
- added patch resolving theoretically "too large" groups
  resolves:rhbz#1944717
Z'8igJiri Vymazal <jvymazal@redhat.com> - 8.24.0-49]@RHEL 7.8 ERRATUM
- fixed fsync patch to actually revognize the new option
  resolves: rhbz#1696686 (failedQA)?7iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-48]µRHEL 7.8 ERRATUM
- added patch resolving crash on wrong MsgProperty
  resolves: rhbz#1549706
- added patch resolving CVE in pmaixforward module
  resolves: rhbz#1768320
- added patch resolving CVE in pmcisconames module
  resolves: rhbz#1768323
- added patch implementing file ID for imfile
  resolves: rhbz#1763746
- added patch fixing omelasticsearch with ES 6.X
  resolves: rhbz#1600171!6i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-47]pRHEL 7.8 ERRATUM
- edited imfile truncation detection patch with reression fix
  resolves: rhbz#1744856
22!=i[Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-57_:q@RHEL 7.9 ERRATUM
- added patch resolving buffer overflows in select() function
  resolves: rhbz#1858297"<i]Jiri Vymazal <jvymazal@redhat.com> - 8.24.0-55^yRHEL 7.9 ERRATUM
- edited imfile file-id patch to not segfault on selinux block
  resolves: rhbz#1843992;iIJiri Vymazal <jvymazal@redhat.com> - 8.24.0-54^@RHEL 7.9 ERRATUM
- edited cert chains patch to not cause memory leaks
  resolves: rhbz#1832087{:iJiri Vymazal <jvymazal@redhat.com> - 8.24.0-53^|@RHEL 7.9 ERRATUM
- one more fix for file ID patch to extend to offline behavior
  resolves: rhbz#1806493
- added patch resoving race in serialization resulting in crash
  resolves: rhbz#1778841_9iWJiri Vymazal <jvymazal@redhat.com> - 8.24.0-52]e@RHEL 7.8 ERRATUM
- edited patch file ID for imfile to not log useless errors
  also improved file-id behavior to adress newly found problems
  resolves: rhbz#1763746

er+V:eDW
c174e242620aa57f9c880faa05975ab8a1b3a70f3d6ea6ec30f58cfd3a0c11f8DV
3917b6cb3159c03532be12c75002a6b66aa15b5a026b3d9613b39cd118b668c1DU
06bec1b1e5fba64eb4e0e530da173b3bafb747f95f9629079d77f65567b15d42DT
254d3dd41b5b9214e5ff2838cf5688082478f2a5e8e8a104082720ea06bb1921DS
b0e87fb6b83f2d417585b8e9d2ba138a98dc6fcb1f21ac5485ddcdd9076cc90bDR
c75a27c33e9c743311271dde24228b03ec56642d945c2ce4bec9e63ef71d81a9DQ
fa07de67ceb878410ad9f1e78b5368935921fefc6de60e009128f1c94f70de52DP
163de5925a8b793540385ac13a1624df2bd90f757dcf6374adaabf2b88c60647DO
1802f181e6589961ea6d796ae4920da55d454d730791ccea8f2c37d1dc609c37DN
9e2c495e6129261f090cea872f60243d9dc4dde47a1a16137f85ddc7bebce41bDM
b9e13a24be722461646243414da9fe3046ae65baec41a7aad1670103307a6921DL
b135e72f01c1154da5b9255ee65113d9a344cc450c24d8b9e7174a0b731939ebDK
2185f211100a288fd632f43d7f2b186da452c6d0827eb87dea7ac3154a5e94f3
v}@o
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992m?mqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945>mPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\AoKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >X
VMVKEe3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >[DeQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^CoQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.LBo+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-HmPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720Go3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/FoqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch


}Jo
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992mImqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\KoKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >^
VMVKOe3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >aNeQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^MoQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.LLo+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-RmPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720Qo3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/PoqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch


}To
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992mSmqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\UoKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >d
VMVKYe3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >gXeQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^WoQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.LVo+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
]L]V\s=Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.2S- Resolves: rhbz#1125544[o3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/ZoqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch
kgobsoRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$asWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.B`sRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056n_smRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
^s)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992]s/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056
\5nhsmRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.6Ti@- Fix: typo in man page
  resolves: rhbz#1099286
gs)Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.4Td@- Fix: hivex missing checks for small/truncated files
  resolves: rhbz#1158992fs/Richard W.M. Jones <rjones@redhat.com> - 1.3.10-5.3T"@- Fix: hivexml generates "Argument list too long" error.
  resolves: rhbz#1145056eu;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500duRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{csRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983
y9ynu;Richard W.M. Jones <rjones@redhat.com> - 1.3.10-6.11`y|@- Bounds check for block exceeding page length (CVE-2021-3504)
  resolves: rhbz#1950500muRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.10^@- Increase limits on number of subkeys etc.
  resolves: rhbz#1822889{lsRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.9Yܶ@- Enable OCaml subpackage on s390x.
  resolves: rhbz#1447983oksoRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.8Y@- Rebuild for OCaml 4.05
  resolves: rhbz#1447983$jsWRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.8X- Tolerate corruption in some hives
  resolves: rhbz#1423436
- Switch to using git to manage patches.BisRichard W.M. Jones <rjones@redhat.com> - 1.3.10-5.7TiA- Fix: "Argument list too long" when using virt-v2v on Windows guest
  with French copy of Citrix installed
  related: rhbz#1145056bR>RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{>:J>;O><R>=W>>[>?`>@e>Ah>Bm>Cp>Du>Ey>F~>G>H>I>J>K>L>M>N>O">P'>Q+>R0>S5>T8>U=>W@>YA>ZE>\H>]J>_K>`O>bR>cT>eU>fY>h\>ib>jh>kn>mr>os>pw>rz>s|>u}>v>x>y>{>|>~>>>>>>>>">$>%>)>,>.>/>3>6>8>9>=>@>B>C>G>J>L>M>Q>T>V>W>[>^>`>a>e>h>j>k>o>r>v>z>
sx}ro
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992mqmqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945pmPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720ouRichard W.M. Jones <rjones@redhat.com> - 1.3.10-6.12a@- Limit recursion in ri-records (CVE-2021-3622)
  resolves: rhbz#1976193buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\soKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >n
VMVKwe3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >qveQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^uoQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.Lto+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-zmPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720yo3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/xoqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch


}|o
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992m{mqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\}oKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >t
VMVKe3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >weQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^oQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.L~o+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-mPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720o3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/oqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch


}o
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992mmqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\oKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >z
VMVKe3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >}
eQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^	oQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.Lo+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-mPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720
o3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/oqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch


}o
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992mmqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\oKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >
VMVKe3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >eQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^oQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.Lo+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-mPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720o3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/oqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch


}o
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992mmqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\oKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >
VMVKe3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >eQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^oQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.Lo+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-"mPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720!o3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/ oqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch


}$o
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992m#mqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\%oKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >
VMVK)e3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >(eQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^'oQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.L&o+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-,mPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720+o3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/*oqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch


}.o
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992m-mqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\/oKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >
VMVK3e3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >2eQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^1oQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.L0o+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-6mPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#11977205o3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/4oqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch


}8o
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992m7mqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\9oKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >
VMVK=e3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix ><eQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^;oQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.L:o+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-@mPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720?o3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/>oqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch

er+V:eDd
46a11b35c33059224764ebf871842b0fb284b2783875ccd819e16761e47dc4cbDc
16de628b418b1829da4235fe7e51f4fad2f0c73137e1c5cd7fe972ff2a960f53Db
7bc6360b4ac0650d8d43651e36f72b8c9c1a393ee315d2c1ee3d3e997ec61b5eDa
4b2789795e0561f07932d99dc35a224a5cb2e2fb4ffc4d3c3b1fb1c9256f2f25D`
f878599f24a0292058a13dbc96e35533360c55c1e4616d4db0cce5da1e4ed0e3D_
c763f6d47ed5f33b5810818fd094773ac77ca94070088529b832a5189debe293D^
e861c291ad02f4c05f77bcae1e8fdba63ab7eff4dbc48957941c33985baa04e1D]
19b2915a18191474719e65f30ae39ec3e32b24de808caf1144908d5905ec22dbD\
6f203af825d8187dfb775adef80a3622f5216a88db513e0ed31eafc3db4c7f54D[
cca2c300e4d60c107c6754108edbc965f0f6e66119848ecaa71eff8b4c7e5961DZ
a1ec1d1affcf4fc30a5337ef7012e0b57d8288af74888ea3b40f8aa781fff212DY
bc5370995408c827ead95c7505c7c12bd393b513d4e6dcd996f4149eeda69686DX
d0da9dd8f5ac62ff338820e4c82cef86962fbebc7eac9dcbcddcf8b7b61036ba


}Bo
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992mAmqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\CoKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >
VMVKGe3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >FeQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^EoQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.LDo+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-JmPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720Io3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/HoqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch


}Lo
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992mKmqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\MoKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >
VMVKQe3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >PeQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^OoQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.LNo+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-TmPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720So3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/RoqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch


}Vo
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992mUmqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\WoKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >
VMVK[e3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >ZeQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^YoQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.LXo+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-^mPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720]o3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/\oqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch


}`o
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992m_mqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\aoKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >
VMVKee3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >deQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^coQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.Lbo+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
-L-hmPavel Valena <pvalena@redhat.com> - 2.0.0.648-28WUe- Fix missing declaration of 'rb_frame_last_func'
  Related: rhbz#1197720go3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/foqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch


}jo
Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-30X- Fix test_npn_protocol_selection_ary and test_npn_protocol_selection_enum
  failures with newest openssl.
  Resolves: rhbz#1416123
- Add gemspec_add_dep and gemspec_remove_dep macros.
- Extend 'gem_' macros for pre-release version support.
  Resolves: rhbz#1397390
- Make symlinks for json gem.
  Resolves: rhbz#1308992mimqPavel Valena <pvalena@redhat.com> - 2.0.0.648-29WX- Fix hostname size limit
  Resolves: rhbz#1343945buffer underrun vulnerability in Kernel.sprintf (CVE-2017-0898).
  * ruby-2.2.8-Buffer-underrun-vulnerability-in-Kernel.sprintf.patch
  Resolves: CVE-2017-0898
- Escape sequence injection vulnerability in the Basic
    authentication of WEBrick (CVE-2017-10784).
  * ruby-2.2.8-sanitize-any-type-of-logs.patch
  Resolves: CVE-2017-10784
- Arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).
  * ruby-2.2.8-Fix-arbitrary-heap-exposure-during-a-JSON.generate-call.patch
  Resolves: CVE-2017-14064
- Command injection vulnerability in Net::FTP (CVE-2017-17405).
  * ruby-2.2.9-Fix-a-command-injection-vulnerability-in-Net-FTP.patch
  Resolves: CVE-2017-17405
- Buffer underrun in OpenSSL ASN1 decode (CVE-2017-14033).
  * ruby-2.2.8-asn1-fix-out-of-bounds-read-in-decoding-constructed-objects.patch
  Resolves: CVE-2017-14033
- Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code
    execution(CVE-2017-17790).
  * ruby-2.5.0-Fixed-command-Injection.patch
  Resolves: CVE-2017-17790
\koKVít Ondruch <vondruch@redhat.com> - 2.0.0.648-31Z\- Fix unsafe object deserialization in RubyGems (CVE-2017-0903).
  * ruby-2.4.3-CVE-2017-0903-Fix-unsafe-object-deserialization
      -vulnerability.patch
  Resolves: CVE-2017-0903
- Fix an ANSI escape sequence vulnerability (CVE-2017-0899).
  Resolves: CVE-2017-0899
- Fix a DOS vulernerability in the query command (CVE-2017-0900).
  Resolves: CVE-2017-0900
- Fix a vulnerability in the gem installer that allowed a malicious gem
    to overwrite arbitrary files (CVE-2017-0901).
  Resolves: CVE-2017-0901
- Fix a DNS request hijacking vulnerability (CVE-2017-0902).
  * ruby-2.2.8-lib-rubygems-fix-several-vulnerabilities-in-RubyGems.patch
  Resolves: CVE-2017-0902
- Fix >
VMVKoe3Jun Aruga <jaruga@redhat.com> - 2.0.0.648-35\X)@- Kill bundled certificates.
- Add macros to edit files lists in .gemspec
- Fix buffer under-read in String#unpack
  Resolves: CVE-2018-8778
- Fix HTTP response splitting in WEBrick
  Resolves: CVE-2017-17742
- Fix DoS by large request in WEBrick
  Resolves: CVE-2018-8777
- Fix >neQJun Aruga <jaruga@redhat.com> - 2.0.0.648-34[- CVE-2018-16395: Fix OpenSSL::X509::Name equality check does not work.
  Resolves: CVE-2018-16395^moQVít Ondruch <vondruch@redhat.com> - 2.0.0.648-33Z@- Fix always passing WEBrick test.Llo+Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-32Z- Add Psych.safe_load
  * ruby-2.1.0-there-should-be-only-one-exception.patch
  * ruby-2.1.0-Adding-Psych.safe_load.patch
  Related: CVE-2017-0903
- Disable Tokyo TZ tests broken by recen tzdata update.
  * ruby-2.5.0-Disable-Tokyo-TZ-tests.patch
  Related: CVE-2017-0903directory traversal by poisoned NULL byte in Dir.
  Resolves: CVE-2018-8780
- Fix file and directory creation with directory traversal.
  Resolves: CVE-2018-6914
- Fix socket creation by poisoned NULL byte.
  Resolves: CVE-2018-8779
- Fix: return default path with nonexistent home dir
- Fix flags not propagated in Array#pack and String#unpack.
  Resolves: CVE-2018-16396
- Fix strictly interpret octal fields in tar headers.
  Resolves: CVE-2018-1000075
- Fix a security error for duplicate files in a package.
  Resolves: CVE-2018-1000076
- Enforce URL validation on spec homepage attribute.
  Resolves: CVE-2018-1000077
- Mitigate XSS vulnerability in homepage attribute.
  Resolves: CVE-2018-1000078
- Prevent Path Traversal issue during gem installation.
  Resolves: CVE-2018-1000079
- Fix unsafe Object Deserialization Vulnerability in gem owner.
  Resolves: CVE-2018-1000074
- Refresh expired certificates.
- Fix path traversal when writing to a symlinked basedir outside of the root
  Resolves: CVE-2018-1000073
KLKhrikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16qo3Vít Ondruch <vondruch@redhat.com> - 2.0.0.648-39a?=@- Bump the release to fix the upgrade path from RHEL7 EUS.
  Resolves: rhbz#1993504/poqVít Ondruch <vondruch@redhat.com> - 2.0.0.648-36\- Introduce `Gem::UserInteraction#verbose` method as precondition to fix
  CVE-2019-8321.
  * rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
  Resolves: CVE-2019-8322
- Fix escape sequence injection vulnerability in API response handling.
  Resolves: CVE-2019-8323
- Prohibit arbitrary code execution when installing a malicious gem.
  Resolves: CVE-2019-8324
- Fix escape sequence injection vulnerability in errors.
  Resolves: CVE-2019-8325
  * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch
HcwvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvukIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgtiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3sk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
zkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockyk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskxiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspwiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%piyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew~kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv}kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg|iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires{kAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
!~!wkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks

kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock	k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc
k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{"k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z!kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3Qc(k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p'kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services&kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock%kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock$k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5#kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
~+~q-k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5,kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{+k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z*kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP)k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
zIz2kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP1k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc0k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p/kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services.kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
Fjz7kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c6k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q5k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind54kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{3k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{<k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z;kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP:k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc9k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p8kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
{Fjv{vBiAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrAk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z@kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c?k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q>k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5=kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict

er+V:eDq
47b080e5a77e0a4e64120cb62ee1a56fde234cd979ec9e29cfa1488c409e4a88Dp
24a29d91614a01ef8bac9bbf460d34163c334449765b6003400b4298035f4ac3Do
472b850598b3b222ab19456cea632da56a9a1a5433cbd99f43868e6e98595701Dn
babc2d4404f1281796b179a84267b81054e32776eea8769de35591c3971fe0feDm
04123c3387456fe96ccae3db4f1c8332ab30d6d0ddea9994b55a58e704a1d264Dl
9ff1593a282c3d42607507ffbc763ae17f3ae2a5896b8152f03b1dd8d3bebe51Dk
fc7476815d3e884a39b6216376b5758e79de7e6fa1e0d85ad7c4923a963f6e0dDj
7dae50109a258ad6094999bad1cf8de9bc680b967fcb221cf9e38f896f8cbf93Di
4cab2e9389c0bda9927bc8ffb3f5843f6888147fd2ee09109c97a50a8e313dfaDh
82d73a39a7efd415652fcfc12d6bf4b9c9213db0f32c9c81ec5b93e7020c715fDg
92fe5e925dcbbf773a6a9a67725a97c2ee05ba99988b7c569d34ea5485b8e2caDf
10c0a3e8cca4f6a5ac8100afa56a4ced7e149d3968dfd722f8895b6144463313De
75b8e9f03001f9908924df507ac906625eedad84d4f379872e8537a185488c11
@'I%@vJkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgIiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Hk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhGikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mFiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiEimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUDiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|CkIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*EvRkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgQiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Pk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhOikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mNiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiMimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileULiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wKkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
!hVikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kUiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspTiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewSkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
HcwZkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvYkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgXiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Wk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
^kAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock]k%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk\iqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp[iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%pciyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewbkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvakIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg`iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires_kAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
!~!wjkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagcik_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254phkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesgkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockfkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockek%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskdiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
nkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockmk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskliqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspkiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzskAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePrk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcqk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254ppkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesokAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
wkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockvk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskuiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksptiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz|kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP{k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlczk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pykwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesxkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk~iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{}k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3Qck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock	kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
~+~qk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP
k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
zIzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
FjzkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023ck_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{ k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
{Fjv{v&iAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesr%k}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z$kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c#k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q"k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5!kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
@'I%@v.kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg-iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3,k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh+ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m*iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi)imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU(iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|'kIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*Ev6kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg5iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires34k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh3ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m2iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi1imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU0iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057w/kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
!h:ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16k9iqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp8iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew7kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
Hcw>kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv=kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg<iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3;k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
BkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockAk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk@iqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp?iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zVqwHkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvGkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgFiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Ek}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhDikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16CkAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock

er+V:eD~
10051afb3f6d2fb5bf647ec9390076d0e4fdf72b804eaad8ed489a50c74d6237D}
659d1840568aaaa0890a8531c9387ac75d19acdb5849da0093220059585ae3c2D|
91353b8f07e3454295bdcd3066dd865de2413f8c9940caa28844124b3ccc2e2cD{
5f3727aea86f6f83c8535492e9334015510770ed19b3f3a98ab88000dfa6b9e6Dz
8d7b3ce7f953eba64eb5ea6f0a0fd7b8a9e05c1d43bd8fa681d19fe3a735e568Dy
a4645f394179a96fed5377b5fe20f2357bcc3d4c57000c4f11b2bd1c6d05a2e7Dx
ba296a88e1432d771cd920109f74098580b81344ab27e869815dfaf5cd73b1bdDw
7029af1412cd34983bc590c58b75f33a9bcb75cb2a5bdf5e6514f8ac4b8089e6Dv
5d4abbc89df8da961aa64935f5a986b89626f1f1e99a8728467557a6b761decfDu
594bfd4b3bb5ccb47a34df5c0220769ae40a50c53152652adbcf1803d747d0f3Dt
58dcbc8296bbbf5a241618ee45e73e4be9870a429bfea9339cb245b68523f7abDs
6334cfed646e36032d28600310824098963bf8c4a3d59a3dffaafae4184e1d56Dr
e5677937bcb75d7acb7f08f429bf9a0f982b23101f1c089b063117be1a84ccb1
LkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockKk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskJiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspIiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%pQiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewPkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvOkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgNiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequiresMkAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
1~1gXiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequirescWk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pVkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesUkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockTkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockSk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskRiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
]k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk\iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp[iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewZkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvYkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DC
ywbkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagcak_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p`kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services_kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock^kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
fkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockek%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskdiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspciyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagebR?'RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{>
>>ƒ>Ã>ă>Ń">ƃ(>ǃ->ȃ2>Ƀ7>ʃ<>˃B>̓J>΃R>σV>ЃZ>у^>҃c>Ӄj>ԃn>Ճs>փw>׃|>؃>ك>ڃ>ۃ>܃>݃>ރ >߃&>.>჊6>⃊:>ナ>>䃊B>僊H>烊L>胊Q>郊X>ꃊ]>냊b>샊f>l>p>u>y>~>>>
>>>>#>)>.>3>9>?>E?J?Q?W?^?d?l?t?y?	?
???
????#?(?-?2?8?=?B?G?L?R?Z?b?f?j? n?!t?"x?#}?$?%	?&
PzIPwlkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagzkkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePjk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcik_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254phkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesgkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
pkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockok%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskniqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspmiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzukAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePtk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcsk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254prkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesqkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
ykAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockxk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskwiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspviyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz~kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP}k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc|k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p{kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceszkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
DyDzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
~
kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk
iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{	k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
IFK>IpkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
FF5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
6tgr6P#k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc"k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p!kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
@S@)kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock(k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesq'k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5&kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{%k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z$kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
zIz.kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP-k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc,k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p+kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services*kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
VFKVp3kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services2kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockq1k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind50kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{/k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
FFq9k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind58kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{7k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z6kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP5k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc4k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
d9dP?k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc>k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p=kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services<kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockz;kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c:k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023
nSnzEkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cDk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qCk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5BkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Ak
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z@kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role

er+V:eD
801e9bca39684a29a84c368956ed668beef392b230692274c32ffbc1cb714b73D

c0cdfc6bfb60f09c2c483ee32a2e4b09104018a5e00d8f9d93e0c7532e31f72aD	
c57d7c3a751af63b1ff3aecc767463cb46fcfcea3212e2b6a04d39baa1975083D
5e9fa6a9c3dc6c925f58ce3d112f48e8d7a89835f56c85fdfa648a880246ebccD
ac7d75cd25f6bfa86cdc28cc1059d66db9ae1f53bd0df0d2e026116587b508b0D
a76f48da787342ed53a149870e65a5c17f6c5a2025f715b076686311a0255c64D
6b1f4e0b7d2eac0f0c87900cfe0b6ceee898b0e7fff0ea37a318fb2be0b794aeD
014111c7993e5c5c0c955d00c5e230799fda34ca92a9b109dd0a572200c4dbedD
c00c788573b1f8856547492b5c19c3b90b2452bcbf56003dee2b20426b79dab2D
bccc059b870905bea5990608d411cde04cf06ed6d3bfa76015aa73439a38a8b6D
611d2e194ff61bd1597a7136c77b1cf881bf1473268ee08ccf54184adcc4da79D
e59f39966b86233054daea322ee01721e6f8f1148e751fbc8fe36aa7381a0c3aD
de913afce451c42b905510d6c1260b853922e572f20edefc2488719a3c92770a
QQQ{Jk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zIkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePHk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcGk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pFkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
FjvcQk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pPkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesrOk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zNkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cMk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qLk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5KkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
+~cWk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qVk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5UkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Tk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zSkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePRk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
Z8Zm^iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi]imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU\iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|[kIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHELvZiAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrYk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zXkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023
q|vdiAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directorieswckIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvbkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgaiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3`k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh_ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16
@'I%@vlkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgkiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3jk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhiikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mhiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersigimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUfiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|ekIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*EvtkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgsiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3rk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhqikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mpiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersioimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUniEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wmkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
[![iyimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUxiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057kwiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspviyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewukIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
#kwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv~kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg}iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3|k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh{ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mziuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal users
x0x3k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
<<kiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires
tgwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv
kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequireskAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock	k%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
#kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock"k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk!iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz(kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP'k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc&k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p%kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services$kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~-k	Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock,k	Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock+k%	Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk*iq	Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{)k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{2k
	Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z1k	Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP0k7	Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc/k_	Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p.kw	Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3Qc8k_
Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p7kw
Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services6k
Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock5k
Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock4k%
Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues53k	Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
~+~q=k{
Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5<k
Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{;k

Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z:k
Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP9k7
Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
zIzBkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePAk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc@k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p?kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services>kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
FjzGkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cFk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qEk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5DkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Ck
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142

er+V:eD
04b897ee5a470f0fb0ecc0e412cc6d3910847f21d8a28f788c5515366e2ac15bD
2b65890542b472692e7023dc8a29b0b0fb54c80adcb4705c53d520b6c66c1c4bD
1e539eb940638371c11f0e077bf6396b4c0afe2d8a5e55e1a10d9e05b8865487D
84eb961185970d439cbddea77f57986510cc0e948d47a65f64173b75fa19949bD
46b7ac1c6e8834a1d46051b922ee8bd78569b89c91a40bac7b9886b7f75ed974D
21fa1a95375af231395873580adb9f748d65f91c14f7835244aed1cbf60db644D
9fd356bb83a32c07e83db458f3325d6bb9b9d294bf167987ff425f01ceec9bb3D
668aa02abd3ff0859bc87b987a759a3a31fbe34f12aac062a8c53a042ea273c7D
07a39b4944cc8d1c6e61f1ad215c744f685fcf1cf0494ce979a7f28539da66d6D
f87c2dd925c9d1309b2c16ad21f5c84cb1b2789d322aefb90bd02179185c3c04D
549ed9d000ddff74758b2c4266ac73c915179f78808cb685c1812d5cbe4d3c36D

2e4e3b337d65ebe2475a8b0c521957f5a723460fab8ee95aace9f4b6433d25c1D
e88c137e89be1334bc4b12c371f5d7a2513ff468e6b5530a069c0f42a2d803ea
QQQ{Lk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zKkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePJk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcIk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pHkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
{Fjv{vRi
Andreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrQk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zPkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cOk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qNk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5MkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
@'I%@vZk
Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgYii
Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Xk}
Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhWik
Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mViu
Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiUim
Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUTiE
Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|Sk
Isaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*EvbkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgaiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3`k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh_ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m^iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi]imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU\iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057w[k
Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
!hfikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16keiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspdiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewckIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
HcwjkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvikIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCghiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3gk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
nkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockmk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskliqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspkiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zVqwtkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvskIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgriiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3qk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhpikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16okAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
xkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockwk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskviqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspuiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%p}iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew|kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv{kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgziiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequiresykAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
1~1giiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requiresck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk~iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
	k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DC
ywkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagc
k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
PzIPwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz!kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
%kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock$k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk#iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp"iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz*kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP)k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc(k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p'kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services&kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
.k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk-iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp,iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage{+k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
DyDz4kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP3k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc2k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p1kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services0kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock/kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
~9kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock8kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock7k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk6iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{5k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{>k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z=kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP<k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc;k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p:kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
IFK>IpDkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesCkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockBkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockAk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk@iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks5?kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
FF5IkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Hk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zGkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePFk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcEk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254

er+V:eD%
1fb9ef577f0e9e4a896981792189019932788dd1325084e83bf11f422ec11e55D$
9fd94d3abf2eb974789a7462096058ddb3171ea77c08cd56496f956960a28322D#
48d7e4811a291ee31fea33ff56b5e11082ae3d2a0bee442c7ee6b29212f72b3eD"
9848ba3b7d2dcbf53d06c6dcd18ead76a0a0048e2222d60c5027b037fdd628a5D!
354a7f6dc710763963d56fba904430a98f75f770240185bd954597c4338b1d0eD 
59322a58bf2949a46807f44a970d90fdb94b2e15f2de040025b4cb5e17568171D
3c7a4b80b2ddae9fd2eea4d9ca2f112f0086b0f0366fe20bd37a1f21328467c9D
e528ea9bec7db57fa568791758764da431303a54e6189e0449c7b1f92756f230D
1f9b0f9eecf8b7a6008d7136a85ba783f0bc60894d8d724b0adb44f56d167728D
fffeb3e36d81e735ea56a95e6ac78d23c78c3ac7e4afb27bcdf91a835d7cb3b6D
1768bd5acb4d22e917fb9f3d2c5b2d56b9563f0d453dc52f436e8ee1fe717ab6D
21239c5b9999cc70790783421ae9dd4466f9017bc973479de248a20ed5447111D
efa06b2642e8d158f0e16bbaaa5d8d454be1db364722a3321c4cf61727e988d8
6tgr6POk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcNk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pMkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesLkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockKkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockJk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
@S@UkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockTk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesqSk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5RkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Qk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zPkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
zIzZkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePYk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcXk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pWkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesVkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
VFKVp_kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services^kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockq]k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5\kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{[k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
FFqek{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5dkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{ck
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zbkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePak7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc`k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
d9dPkk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcjk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pikwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceshkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockzgkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cfk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023
nSnzqkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cpk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qok{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5nkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{mk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zlkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
QQQ{vk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zukAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePtk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcsk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254prkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
Fjvc}k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p|kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesr{k}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zzkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cyk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qxk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5wkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
+~ck_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP~k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
Z8Zm
iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi	imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|kIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHELviAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023
q|vi Andreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directorieswkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg
iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16
@'I%@vk Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgii Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k} Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhik Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16miu Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiim Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiE Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|k Isaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*Ev k!Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgii!Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}!Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhik!Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16miu!Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiim!Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiE!Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wk Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
[![i%im"Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU$iE"Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057k#iq!Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp"iy!Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew!k!Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
#kw+k"Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv*k"Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg)ii"Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3(k}"Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh'ik"Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m&iu"Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal users
x0x3/k}#Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh.ik#Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16k-iq"Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp,iy"Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
<<k4iq#Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp3iy#Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew2k#Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv1k#Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg0ii#Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires
tgw:k$Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv9k$Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg8ii$Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires7k#Andreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock6k#Andreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock5k%#Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
>k$Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock=k%$Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk<iq$Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp;iy$Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zwBk%Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagcAk_$Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p@kw$Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services?k$Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
Fk%Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockEk%%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskDiq%Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspCiy%Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzKk%Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePJk7%Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcIk_%Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pHkw%Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesGk%Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock

er+V:eD2
15ba10efc121a3ed0a0eca1fa166dedb998e453bd44dfab80b4ea710432aa8c0D1
4c04f9c0edd59e74074f9a36500741821e912b6a5865fae5f59b76252ebba71fD0
fd9eac77800954e912c795b1baa2897a1255e8c44f1dcbe7f154da4bbb690fcdD/
793ed94885ccb91d3de9ac0ee3c6ae228181f6d4d90d6c2ba44aeecea596a647D.
5c3f57ee8f26430a0967dbc9fb3d9d5fc2c5dd13b98177359cedcda6874b3799D-
5f7b92aac28013990bf6ff5dfda904b49259d332381f6fd3a71b635df396f7e1D,
4002815b3af5011f39413ce958784b1f26655ab8f66ee5e65f83422aa955b381D+
ab13aa04aeb348258901773260b01891907dc2f1c189f183f4e44235a851f3afD*
aedb64f36af805dd8fb683d049561dd019fa2ef5e48b7562c0f91dbdb1fb951eD)
28c2a5051272af63a8edc3a8a14de5ce766ac890e9ece13f89e53bf7481f9f51D(
112b6e97fc16e295181066cb46ff1a9262b26431c1ac47354e7d5d67d3fc1615D'
46cf410604f7938205308a15957f49b1342c994799e461a129e01bd216d7a933D&
dc916d8fb8fa71e2b3598fd5f5d1544cc54745b116f27a7ab2ecadf3df918a7f
Ok&Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockNk%&Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskMiq&Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspLiy&Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzTk&Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePSk7&Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcRk_&Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pQkw&Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesPk&Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~Yk'Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockXk'Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockWk%'Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskViq'Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{Uk
&Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{^k
'Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z]k'Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP\k7'Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc[k_'Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pZkw'Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3Qcdk_(Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pckw(Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesbk(Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockak(Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock`k%(Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5_k'Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
~+~qik{(Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5hk(Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{gk
(Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zfk(Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePek7(Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
zIznk)Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePmk7)Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlclk_)Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkkw)Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesjk)Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
Fjzsk)Andreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023crk_)Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qqk{)Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5pk)Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{ok
)Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{xk
*Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zwk*Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePvk7*Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcuk_*Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254ptkw*Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesbR?RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{?(?)?*!?+%?,*?-.?.4?/9?0>?1D?2I?4O?5U?6Z?7_?8e?9k?:q?;v?<}?=?>
???@?A ?B%?C+?D/?E4?F:?G>?HB?IF?JK?LO?MT?NY?O^?Pd?Qi?Rn?Ss?Tx?V~?W?X?Y?Z?[?\?]&?^*?_/?`3?a8?b=?cB?dH?eM?gR?hW?i\?jb?kj?lr?mv?nz?o~?p?q
?r?s?t?u?v!?w&?x,?y1?z6?{;?|@?}F?~N?V?Z?^?b?h?l?q?x?}??????
{Fjv{v~i+Andreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesr}k}*Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z|k*Andreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c{k_*Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qzk{*Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5yk*Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
@'I%@vk+Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgii+Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}+Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhik+Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16miu+Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiim+Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiE+Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|k+Isaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*Evk,Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg
ii,Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k},Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhik,Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m
iu,Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi	im,Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiE,Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wk+Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
!hik-Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kiq,Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiy,Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewk,Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
Hcwk-Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvk-Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgii-Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}-Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
k-Andreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%-Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiq-Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiy-Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%piy.Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewk.Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvk.Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgii.Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requiresk-Andreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
!~!w&k/Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagc%k_.Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p$kw.Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services#k.Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock"k.Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock!k%.Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk iq.Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
*k/Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock)k%/Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk(iq/Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp'iy/Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz/k/Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP.k7/Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc-k_/Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p,kw/Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services+k/Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
3k0Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock2k%0Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk1iq0Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp0iy0Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz8k0Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP7k70Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc6k_0Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p5kw0Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services4k0Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~=k1Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock<k1Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock;k%1Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk:iq1Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{9k
0Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{Bk
1Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zAk1Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP@k71Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc?k_1Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p>kw1Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3QcHk_2Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pGkw2Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesFk2Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockEk2Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockDk%2Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5Ck1Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
~+~qMk{2Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5Lk2Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Kk
2Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zJk2Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePIk72Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl

er+V:eD?
836c3fcced9a9357e2eead69c55ef322cb19c6fed119b1eae1877c6b2bd51169D>
85b37a5fd5787e7ba6d0b814f2b7c0de2df1e314d12a9e9ec3fd2cd80e7dbf28D=
f2e6529205d5d5cda9ea3d5996514f86afdf1ddacc087c47d9f80362b885b94dD<
2272979129fdda737c2763fb9bb135cf5763b18ba685523ac289d17b110c0dfaD;
ec7d4d6f34f218c71ac4c95b8ae162cfa554d6f3285e389a230c52898b5df662D:
99fbbb592c991c048c088d31d6dc60cef74de08cfb469bfc81e440dd3938c4d4D9
0c9251da98f68e439285f3e9fe1d2564f460335667000f17d613cca5310aa954D8
1ac0a06d5f14e63729e4206d6934c71f032a9d594c6bbb5ecc1c0ceee1abc06dD7
0bc7a3258a261dafb1804614ca3e65cc202ca5a9607554f6524da136cb7c7ee6D6
4598455c105686eb7e3fd9bbe5dd3d1c3e012036441206b4a4b2c4cf8b732302D5
a4d493ddbcf031863d7df693b8bc739563ff7942f02210a63070f6e5f86aa7fcD4
1617a73a615b21a99cc94d4baf19a16b3e787c5cae853c5b1ca7340d1dfe84c9D3
a384513b0be353541f3730615409df1cd228cf1a4fef5a3c14bd1bfca576d8f9
zIzRk3Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePQk73Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcPk_3Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pOkw3Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesNk3Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
FjzWk3Andreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cVk_3Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qUk{3Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5Tk3Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Sk
3Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{\k
4Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z[k4Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePZk74Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcYk_4Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pXkw4Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
{Fjv{vbi5Andreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrak}4Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z`k4Andreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c_k_4Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q^k{4Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5]k4Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
@'I%@vjk5Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiii5Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3hk}5Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhgik5Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mfiu5Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersieim5Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUdiE5Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|ck5Isaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*Evrk6Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgqii6Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3pk}6Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhoik6Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mniu6Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersimim6Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUliE6Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wkk5Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
!hvik7Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kuiq6Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksptiy6Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewsk6Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
Hcwzk7Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvyk7Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgxii7Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3wk}7Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
~k7Andreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock}k%7Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk|iq7Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp{iy7Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%piy8Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewk8Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvk8Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgii8Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requiresk7Andreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
!~!w
k9Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagc	k_8Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkw8Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesk8Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockk8Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%8Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiq8Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
k9Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
k%9Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiq9Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiy9Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzk9Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk79Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_9Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkw9Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesk9Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
k:Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%:Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiq:Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiy:Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzk:Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7:Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_:Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkw:Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesk:Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~!k;Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock k;Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%;Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiq;Andreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{k
:Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{&k
;Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z%k;Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP$k7;Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc#k_;Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p"kw;Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3Qc,k_<Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p+kw<Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services*k<Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock)k<Andreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock(k%<Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5'k;Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
~+~q1k{<Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind50k<Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{/k
<Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z.k<Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP-k7<Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
zIz6k=Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP5k7=Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc4k_=Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p3kw=Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services2k=Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
Fjz;k=Andreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c:k_=Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q9k{=Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind58k=Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{7k
=Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{@k
>Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z?k>Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP>k7>Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc=k_>Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p<kw>Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
{Fjv{vFi?Andreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrEk}>Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zDk>Andreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cCk_>Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qBk{>Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5Ak>Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
@'I%@vNk?Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgMii?Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Lk}?Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhKik?Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mJiu?Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiIim?Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUHiE?Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|Gk?Isaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*EvVk@Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgUii@Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Tk}@Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhSik@Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mRiu@Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiQim@Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUPiE@Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wOk?Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag

er+V:eDL
7e7bc2ad7bb400736ea42cfba2ef80b5d0a56bc7d73625f692b8597a92251297DK
7380c6641a8e803a62e76e8af53969ed47f13f90aded491ee5e72f1947b0995bDJ
10a162b74ab12cba105a1556951bb59dc3a6fe0ead031488abf12f3017324716DI
6d1695ee0cacafe8f21952e32e2db02bc6e264eadd5e68c3e8db3612519ab13aDH
3bb061745bcab5ccdf7cac588403affcb1f45108fd78412872bc78b646404b98DG
6b416b00b5ef6cb53e5629184ff45e772a8c2a837a9e0bb69dc38ebdd07ec7f2DF
5a74a6ec4e7d6d8944913ada4270edb09c6f3b75a0b4caba77d076c07bc64964DE
f086e1ae057782a612a9146ab15a673cb1fc1c351507f164527a1561fe1017e1DD
434aa31c1e300108134248129540211cac97b9c972fee7b8a5c1247a8c318c2fDC
9384630d77721b9cf0583684ad152790662a117c211334438628621a8b12dec7DB
f8d72ec48ec0e1f77e42f4f2a5c6dbeabe6e13e680771e35008c6865faee59f6DA
c31f2747e3388b9d79c19442e86c3d4556be28b28509108ed5c494f7278e2a38D@
be1124e1f840cb866d332ff93aa0c138c358e7a5c45b54ab72d58a19da6c3a65
!hZikAAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kYiq@Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspXiy@Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewWk@Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
Hcw^kAIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv]kAIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg\iiAAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3[k}AIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
bkAAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockak%AAndreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk`iqAAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp_iyAAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zVqwhkBIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvgkBIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgfiiBAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3ek}BIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhdikBAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16ckAAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
lkBAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockkk%BAndreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskjiqBAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiiyBAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%pqiyCAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewpkCIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvokCIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgniiCAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequiresmkBAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
1~1gxiiDAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requirescwk_CAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pvkwCAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesukCAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode locktkCAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode locksk%CAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskriqCAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
}k%DAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk|iqDAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp{iyDAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewzkDIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvykDIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DC
ywkEIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagck_DAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwDAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskDAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock~kDAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
kEAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%EAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqEAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyEAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
PzIPwkFIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagzkEAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP
k7EAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc	k_EAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwEAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskEAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kFAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%FAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqFAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp
iyFAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzkFAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7FAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_FAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwFAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskFAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kGAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%GAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqGAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyGAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzkGAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7GAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_GAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwGAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskGAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
"k%HAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk!iqHAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp iyHAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage{k
GAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
DyDz(kHAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP'k7HAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc&k_HAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p%kwHAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services$kHAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock#kHAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
~-kIAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock,kIAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock+k%IAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk*iqIAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{)k
HAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{2k
IAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z1kIAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP0k7IAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc/k_IAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p.kwIAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
IFK>Ip8kwJAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services7kJAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock6kJAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock5k%JAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk4iqJAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks53kIAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
FF5=kJAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{<k
JAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z;kJAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP:k7JAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc9k_JAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
6tgr6PCk7KAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcBk_KAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pAkwKAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services@kKAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock?kKAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock>k%KAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
@S@IkLAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockHk%LAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesqGk{KAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5FkKAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Ek
KAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zDkKAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
zIzNkLAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePMk7LAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcLk_LAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pKkwLAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesJkLAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
VFKVpSkwMAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesRkMAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockqQk{LAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5PkLAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Ok
LAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142

er+V:eDY
a1d7425caccc9a966670aae472b941355eabfd2f097cd2e1f237f22cfe4a17abDX
df6e614866add11969ca0b65851bfa71c6bc9f4844246ad53138cc6918480108DW
18cd5d8d39b9aec1631228c86412a11eed902b967a26b6a64c816e4fcccaff89DV
88cbca784ae7af25ab7e769129e7fd6d1e91281dc714e9bc35a46dfde2da5624DU
a6776dea18957f42231f6c504897a29ef208e3c2b1f0ae2ca2b12d5f93fec583DT
0bc17855cc6640920597c449da532b260707f9f0446c2d6c601ace461632007eDS
05ab159708542ab7cbdc54eec74ffdbd8cb86dd12b6b0a5c10faff3414c5ddceDR
5259da8d02da50b7fa77e6a85337bd5b220b5a2f13fdffdf6bf2245e630017c8DQ
0d2d3cbaee9c9fdd4bf0e41db231e656141f296acbbf0480fb738b9c04e78268DP
8dbad9b74358ef443eacae1628f33b8cf52128bfd4a1e2ad38ef0ec9549a22c4DO
61c886355da15df816e8e94fb32990af3d0e4c89549b100c128c54b438924eb7DN
ef91b432545f513294a7b3949519656a6cd8b9d3ee0fc8217364537cfefde363DM
b31cc50cbf74e369bada216975078737e5f701111fb2ea5d0c97c5979d5c4db4
FFqYk{MAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5XkMAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Wk
MAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zVkMAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePUk7MAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcTk_MAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
d9dP_k7NAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc^k_NAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p]kwNAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services\kNAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockz[kMAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cZk_MAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023
nSnzekNAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cdk_NAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qck{NAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5bkNAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{ak
NAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z`kNAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
QQQ{jk
OAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zikOAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePhk7OAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcgk_OAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pfkwOAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
Fjvcqk_PAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254ppkwPAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesrok}OAndreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2znkOAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cmk_OAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qlk{OAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kkOAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
+~cwk_PAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qvk{PAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5ukPAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{tk
PAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zskPAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePrk7PAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
Z8Zm~iuQAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi}imQAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU|iEQAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|{kQIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHELvziQAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesryk}PAndreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zxkPAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023
q|viRAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directorieswkQIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkQIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiQAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}QIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhikQAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16
@'I%@vkRIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiRAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3
k}RIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh	ikRAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16miuRAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiimRAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiERAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|kRIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*EvkSIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiSAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}SIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhikSAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16miuSAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiimSAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiESAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057w
kRIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
[![iimTAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiETAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057kiqSAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiySAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewkSIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
#kwkTIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkTIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiTAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}TIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhikTAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16miuTAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal users
x0x3#k}UIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh"ikUAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16k!iqTAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp iyTAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
<<k(iqUAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp'iyUAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew&kUIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv%kUIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg$iiUAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires
tgw.kVIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv-kVIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg,iiVAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires+kUAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock*kUAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock)k%UAndreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
2kVAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock1k%VAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk0iqVAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp/iyVAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zw6kWIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagc5k_VAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p4kwVAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services3kVAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
:kWAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock9k%WAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk8iqWAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp7iyWAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz?kWAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP>k7WAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc=k_WAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p<kwWAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services;kWAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
CkXAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockBk%XAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskAiqXAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp@iyXAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzHkXAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePGk7XAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcFk_XAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pEkwXAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesDkXAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~MkYAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockLkYAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockKk%YAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskJiqYAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{Ik
XAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{Rk
YAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zQkYAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePPk7YAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcOk_YAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pNkwYAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3QcXk_ZAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pWkwZAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesVkZAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockUkZAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockTk%ZAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5SkYAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict

er+V:eDf
0d795cbf22fec282f02654f7712344c97027974130c274b8e837bec939303861De
0ebd7a7d93f6af20c4e8fff8d52032fda80556a14021adf330e1c9f9e8063482Dd
4aab05abd1b63222c6aa994c3754ec20a9d3258f4769449d5e105f718ba5f442Dc
1b20547bbbfca3c83fa9317da6351d845a3f6ee818efb377f5a74fe92ae5a2fdDb
25b247bcb5f601c204d1a8049befe95cc84a219558a504a5e7412cc129f8cceaDa
a9cc4d39a2d6ad848428798509620c583ee6ec0da4ca03fdc079133cea857364D`
113bbd026677c12bbfb0f6803e303c762606f5f0c0dd003dac3e57e0a598d8c9D_
6ab73b9be208b744fbb10e2b4b62ee6782dd5717e49b00d2c93994bf8c59e499D^
c7423e39173d9fe8056ef70f6214e1c4f4af271fa10cf07b321ec23fa5e89359D]
b989926a63d032134a604af73945bec5d655b1f56d71ee89b60cdd36ad43db7bD\
6a54b11f2a8b565659f8bbc6b4fdd6ea12732e30070c5a27c01336f48847fffcD[
d9b6c849e3f7bb3fa602d5b17cbfbda40ae131b42cc00f3c522157a30999d010DZ
3d3fa496232fa0f5bb5b56927dea03ee514808271edae94b35d550e3dbe54772
~+~q]k{ZAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5\kZAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{[k
ZAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zZkZAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePYk7ZAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
zIzbk[Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePak7[Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc`k_[Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p_kw[Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services^k[Andreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
Fjzgk[Andreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cfk_[Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qek{[Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5dk[Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{ck
[Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{lk
\Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkk\Andreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePjk7\Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcik_\Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254phkw\Andreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
{Fjv{vri]Andreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrqk}\Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zpk\Andreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cok_\Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qnk{\Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5mk\Andreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
@'I%@vzk]Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgyii]Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3xk}]Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhwik]Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mviu]Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiuim]Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUtiE]Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|sk]Isaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*Evk^Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgii^Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}^Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhik^Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m~iu^Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi}im^Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU|iE^Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057w{k]Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
!hik_Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kiq^Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiy^Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewk^Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
Hcw
k_Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv	k_Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgii_Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}_Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinbR?RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{?"?(?-?2?8?=?C?I?N?S?Y?_?e?j?q?w?~??????#?(?.?2?6?:???C?H?M?R?X?]?b?g?l?r?z???
?????ƒ$?Ã)?ă.?Ń2?ƃ8?ǃ<?ȃA?ɃE?ʃJ?˃N?̃T?̓Y?σ^?Ѓd?уi?҃o?Ӄu?ԃz?Ճ?փ?׃?؃?ك?ڃ?ۃ#?܃*?݃0?ރ8?߃@?E?ეK?⃔O?ピT?䃔Z?惔^?烔b?胔f?郔k?ꃔo?냔t?샔y?탔~??	?????&?.?2
k_Andreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
k%_Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiq_Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiy_Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zVqwk`Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvk`Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgii`Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}`Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhik`Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16k_Andreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
k`Andreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%`Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiq`Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiy`Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%piyaAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewkaIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkaIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiaAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requiresk`Andreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
1~1g$iibAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requiresc#k_aAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p"kwaAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services!kaAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock kaAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%aAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqaAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
)k%bAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk(iqbAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp'iybAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew&kbIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv%kbIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DC
yw.kcIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagc-k_bAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p,kwbAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services+kbAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock*kbAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
2kcAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock1k%cAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk0iqcAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp/iycAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
PzIPw8kdIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagz7kcAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP6k7cAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc5k_cAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p4kwcAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services3kcAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
<kdAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock;k%dAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk:iqdAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp9iydAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzAkdAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP@k7dAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc?k_dAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p>kwdAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services=kdAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
EkeAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockDk%eAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskCiqeAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspBiyeAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzJkeAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePIk7eAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcHk_eAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pGkweAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesFkeAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
Nk%fAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskMiqfAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspLiyfAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage{Kk
eAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
DyDzTkfAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePSk7fAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcRk_fAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pQkwfAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesPkfAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockOkfAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
~YkgAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockXkgAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockWk%gAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskViqgAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{Uk
fAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142

er+V:eDs
ac054a6cb21fb80c8fa5d92b7cfe026640f5eb200f4e353fa4faf2ec2c2a0cf9Dr
0f0241e556ea298645602911fe3d8280bc945bfbbbdf05c822cbe1fd63f1641cDq
dc829add4d45f5884e77bcd5570fa643f0a482815fe304ac97cf74eae7bf891dDp
71d5237e53d98bad084c2240820cd15af03b5f087119d5b59e92f1a002d4386cDo
e68322c77301aa109da2791f2c544f5933ba77ca4eb36116ea02fcc3d83c6209Dn
c37c5f2481d02ad5543d7d4d2dbddb16eba4ee2deed077d977114cf608f12247Dm
93a4cbbbc8b5c4b31b05ac687761f0f8f9699c2b5691192ad0f370b70ad1a30fDl
dddabe759540f01cb15424d35255ccfac26564331254e9757e3ad94869e2cf05Dk
3deb7d3a6136871ad159d05ae95e27d8d744b7e3ed0cdee2668d0f7c847daaa5Dj
79d7dc58c2f988ca4128c170279bb74b7e02f4d11996be672cb921db54e36161Di
69372e8180b47681712e917eeaf3777bfa1ae27641645b1797b5e61104693c4eDh
d78b8165e29e10002bc50adceb4a01bd56deec94d12fc30d4f3479c5ece32e38Dg
6f4992979d6450182615d2419ce9c9ce044361871407e1a88a1c9911fe497221
QQQ{^k
gAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z]kgAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP\k7gAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc[k_gAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pZkwgAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
IFK>IpdkwhAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesckhAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockbkhAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockak%hAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk`iqhAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks5_kgAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
FF5ikhAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{hk
hAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zgkhAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePfk7hAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcek_hAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
6tgr6Pok7iAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcnk_iAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pmkwiAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceslkiAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkkiAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockjk%iAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
@S@ukjAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode locktk%jAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesqsk{iAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5rkiAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{qk
iAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zpkiAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
zIzzkjAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePyk7jAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcxk_jAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pwkwjAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesvkjAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
VFKVpkwkAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services~kkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockq}k{jAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5|kjAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{{k
jAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
FFqk{kAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
kAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7kAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_kAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
d9dPk7lAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc
k_lAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p	kwlAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesklAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockzkkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023ck_kAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023
nSnzklAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023ck_lAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qk{lAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5klAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{
k
lAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zklAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
QQQ{k
mAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkmAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7mAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_mAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwmAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
Fjvck_nAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwnAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesrk}mAndreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zkmAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023ck_mAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qk{mAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kmAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
+~c#k_nAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q"k{nAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5!knAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{ k
nAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zknAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7nAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
Z8Zm*iuoAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi)imoAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU(iEoAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|'koIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHELv&ioAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesr%k}nAndreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z$knAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023
q|v0ipAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesw/koIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv.koIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg-iioAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3,k}oIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh+ikoAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16
@'I%@v8kpIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg7iipAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires36k}pIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh5ikpAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m4iupAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi3impAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU2iEpAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|1kpIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*Ev@kqIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg?iiqAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3>k}qIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh=ikqAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m<iuqAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi;imqAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU:iEqAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057w9kpIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
[![iEimrAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUDiErAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057kCiqqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspBiyqAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewAkqIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
#kwKkrIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvJkrIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgIiirAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Hk}rIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhGikrAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mFiurAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal users
x0x3Ok}sIsaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhNiksAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kMiqrAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspLiyrAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
<<kTiqsAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspSiysAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewRksIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvQksIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgPiisAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires
tgwZktIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvYktIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgXiitAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequiresWksAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lockVksAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockUk%sAndreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues

er+V:eD
dab8429bc58eb477c02d8eddb235455fe3be912176fb73b641187fb0ae7dfceeD
4b38bac5d80fcc0063946dca9ca07cf5eb6d0ed1e82eaa7df1715a790288016eD~
88ebbac297f77c53cd09a2f137fda3254023224d3da2a351b153770a4ada109fD}
4752988d38c83850c74c74ec19ca5b7e1c79f8817544be00ab3fbc407c01355aD|
27194ef3e88b3dacc48cebc87ff15160878a2198d33fb8689040549b6083a26cD{
70215dcd3ae55ef64ecc4091cf3625d634872ef001749ced33e1b98ccf7a9b10Dz
e931e9fe49a9a7c21e0cc3baa18262e5603d94fb11d0284564ceefad2eac5d87Dy
168aca43a6275ed770802ded267285a01db77e46803e6ec90dad47985d8145eaDx
223ee648bd84e6a7bd0e7a0a189113bd1a3af31a18ecd5529530b10979cd3328Dw
9a5fecf7eddf64da702208bc6b583307af8b3e3c8f80f0306e8eb58001ba5cdaDv
f2241666af94fe720a9238c276f97db47b1cb8737b678465e84924e2d3a8d6e1Du
b6e908a5877e75ecf0c9f0d2e6230660232dc1176edac5fab3ea2fc7d9185753Dt
ef7f2a44b28fe81a03c9c1d9ff9899b216bc95ee9f93b7647a5a07a655a990c2
^ktAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock]k%tAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk\iqtAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp[iytAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zwbkuIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagcak_tAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p`kwtAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services_ktAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
fkuAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockek%uAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskdiquAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspciyuAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzkkuAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePjk7uAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcik_uAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254phkwuAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesgkuAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
okvAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode locknk%vAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskmiqvAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspliyvAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIztkvAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePsk7vAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcrk_vAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pqkwvAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicespkvAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~ykwAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockxkwAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockwk%wAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskviqwAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{uk
vAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{~k
wAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z}kwAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP|k7wAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc{k_wAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pzkwwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3Qck_xAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwxAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskxAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkxAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%xAndreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5kwAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
~+~q	k{xAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kxAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
xAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkxAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7xAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
zIzkyAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP
k7yAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_yAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwyAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
kyAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
FjzkyAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023ck_yAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qk{yAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kyAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
yAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{k
zAndreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkzAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7zAndreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_zAndreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwzAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
{Fjv{vi{Andreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrk}zAndreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zkzAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023ck_zAndreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qk{zAndreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kzAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
@'I%@v&k{Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg%ii{Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3$k}{Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh#ik{Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m"iu{Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi!im{Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU iE{Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|k{Isaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*Ev.k|Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg-ii|Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3,k}|Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh+ik|Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m*iu|Andreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi)im|Andreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU(iE|Andreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057w'k{Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
!h2ik}Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16k1iq|Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp0iy|Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew/k|Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
Hcw6k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv5k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg4ii}Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires33k}}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
:k}Andreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock9k%}Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk8iq}Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp7iy}Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zVqw@k~Isaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv?k~Isaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg>ii~Andreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3=k}~Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh<ik~Andreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16;k}Andreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
Dk~Andreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockCk%~Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskBiq~Andreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspAiy~Andreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%pIiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewHkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvGkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgFiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequiresEk~Andreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
1~1gPiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequirescOk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pNkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesMkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockLkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockKk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskJiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
Uk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskTiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspSiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewRkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvQkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DC
ywZkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagcYk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pXkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesWkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockVkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock

er+V:eD

df2c03d36edd3da46dc78887ba0c21af48565b9a39893e1157cf83913aa1b361D
003c7635f8d23b7b12ec78287877a43a4ae9429260d34c92695eafb0df5d061aD
c40a42601b6e79bc8b02eba97fef14998961f2c034ebf3a2c9cf36acb94a8012D

cc4f393f3dc8376ae20557ef6ef4666627e5e582ff7ecd121164659a24781cfdD	
00056c9175a4ec1b58cad0e3b3b16cbd29712335001c85d5f270931b04d4bb6aD
1930ee508064d9fc5b82d42aba3062a28da268f293b47a7af9f89dfc9ff3fd1fD
8528777e2d5d089f809fd37c5c722627e07d23a1c4a116c83e8ff648c57058b9D
bd868619b7086e2a7d7b78b6c2fc753b70a71567880be1bb5c40f85ca1a88875D
a6aac81cd2d6ebe99abec53cff2653ecf43ba9a2c3087ea8406123927419b978D
009f1e5fdfe0287c2d456390aacab52be52e77247292e285d5caa965c2330dabD
a8f1e3373e10bfb45af34690456fb06dbf9cf8022362cfda341212c6841271dbD
fcfcf89049ecf9f09cbf47f552ddb936bf74e4cd3537825f1c463ce4d4d50c66D
622141e5636c218b10a59ecdbd66106cdad2a25b673f891edc0d4b61ac7965f8
^kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock]k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk\iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp[iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
PzIPwdkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagzckAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePbk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcak_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p`kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services_kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
hkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockgk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskfiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspeiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzmkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePlk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlckk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pjkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesikAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
qkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockpk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskoiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspniyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzvkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePuk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlctk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pskwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesrkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
zk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskyiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspxiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage{wk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
DyDzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc~k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p}kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services|kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock{kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
~kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{
k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z	kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
IFK>IpkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
FF5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
6tgr6Pk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
@S@!kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesqk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
zIz&kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP%k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc$k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p#kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services"kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
VFKVp+kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services*kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockq)k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5(kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{'k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
FFq1k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind50kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{/k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z.kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP-k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc,k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
d9dP7k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc6k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p5kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services4kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockz3kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c2k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023
nSnz=kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c<k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q;k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5:kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{9k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z8kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
QQQ{Bk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zAkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP@k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc?k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p>kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
FjvcIk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pHkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesrGk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zFkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cEk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qDk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5CkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
+~cOk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qNk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5MkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Lk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zKkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePJk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
Z8ZmViuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiUimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUTiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|SkIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHELvRiAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrQk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zPkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023
q|v\iAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesw[kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvZkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgYiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Xk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhWikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16

er+V:eD
4c1acd8485fdfe86cd47962474dfcb9f59d713caf6da198b738ec4fa3dd0c38bD
0f8617080bdf5906164380f70a90898bdb69a7910d8fedcf476ef4c3300ccc36D
65d95beebc4fa859daf899819187c19f9a0f248d4f60b30fed6a324c4ffda665D
8d95806a7fbf5e875e27f1dac6cd557d87cc508a301218b36c67eb9012718b1aD
5af10f82c939cf1b8c13d3064e3ddfe2de4add71af9db95263ae64050efcaef3D
c5c83afc05bf26a4cc57f6113c9a03a1c709f35aca39423aa00a65cde5710234D
40519a4b9f7188d9987ae8efcdcd2a6c382d6311c8aafae7cf914313e1d5eef3D
0c6ad74477b64388fb061cd59308e5053fb53c352648ac10728050169bb9ac48D
22822221e0cec5832d579c490f43f73da5575489c0b0fe6c53f5d0ca3ffda90cD
809f841a5c44ddbe609d0827d1562e3515efe0f58ca9a5b5495789e578e2f7cfD
66c9841543e52d2762a3f03b0bf340fa1bcf22e9038a8ad6659900270e97843aD
4c8d4ec39fdb607061601e0e4b1e5230323ad72c01643e17ec55ef571d886e49D
9c231e9b4e39bea78503148cf3642323271b9fdc99cef9271273ef16cfa78ef9
@'I%@vdkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgciiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3bk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhaikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m`iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi_imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU^iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|]kIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*EvlkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgkiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3jk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhiikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mhiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersigimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUfiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wekIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
[![iqimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUpiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057koiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspniyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewmkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
#kwwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCguiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3tk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhsikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mriuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal users
x0x3{k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhzikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kyiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspxiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
<<kiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew~kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv}kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg|iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires
tgwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequireskAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues

kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock	k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagc
k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagebR@_RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{?:?@?D?I?P?U?Z@^@d@h@m@q@v@z@@@	
@
@@@
!@&@+@1@7@=@B@I@O@V@\@d@l@q@w@{@@@ 
@!@"@#@$@& @'%@(*@)0@*5@+:@,?@-D@.J@/R@0Z@1^@3b@4f@5k@6r@7v@8{@9@:@;	@<@=@>@?@@#@A(@B.@C6@D>@EB@FF@GJ@HP@IT@JY@K`@Me@Nj@On@Pt@Qx@R}@S@T@U
@V@W@X@Y @Z%@[+@\1@]6@^;
zIz kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~%kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock$kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock#k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk"iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{!k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{*k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z)kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP(k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc'k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p&kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3Qc0k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p/kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services.kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock-kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock,k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5+kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
~+~q5k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind54kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{3k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z2kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP1k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
zIz:kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP9k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc8k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p7kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services6kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
Fjz?kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c>k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q=k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5<kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{;k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{Dk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zCkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePBk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcAk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p@kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
{Fjv{vJiAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrIk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zHkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cGk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qFk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5EkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
@'I%@vRkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgQiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Pk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhOikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mNiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiMimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileULiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|KkIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*EvZkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgYiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Xk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhWikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mViuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiUimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUTiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wSkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
!h^ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16k]iqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp\iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew[kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag

er+V:eD'
fa096ffba3dc527395eaeb5d48dee9df05e4ddb693f382a610b5b0527eb217d4D&
cd38869a69886ec7014b529b0a5e2a8c6f5cb941544d083216de2f68d1db8abfD%
e67d6b84ad7acb2955ee72b7ee68979e8e001bb2a5d5cd54e752f6d78ee327d9D$
496cf5c5ca7cdfa69a957f1fd58b42a7ca210246b35627830c2607273e22b7c0D#
af89fab6b1b6beba4655dab160a80e43f00d9a3eb59e3da5678d9caf8ca4b865D"
7383213f19577210f9167fcd27957f9bd4763d172ec1509e90329b4f69c04a81D!
4735272f88bc3a162accf0ab7bae821772bb319cd6b136ca5791eb1cef2eb048D 
cefaa998452e2e34b3a59dbbf972dd1e45e2bf1e4bad5a8df4b34529aab350b6D
284a8c6f38b53f8ec780e1374c2a59b687177b7be9e40b2a673f14675843b17bD
0159bd2e5e5911a949c27ecc4ee8003c3e2bdc4fe0074b1d0eb53e28360580faD
a7a8c48658f7054decf6176a5bd02e2d560ad065376f79744ce3f8843e7b5f6fD
0216cb555eb5ac8bb5f746370557652aa2a2e0814f298bdf4fe756f0f1cebcacD
ef6b1d6ee31b3645952263c7292d83ff8479a7e1fa07238da2994be9d38f266b
HcwbkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvakIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg`iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3_k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
fkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockek%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskdiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspciyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%pkiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewjkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvikIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCghiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequiresgkAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
!~!wrkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagcqk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254ppkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesokAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode locknkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockmk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskliqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
vkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockuk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesktiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspsiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz{kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePzk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcyk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pxkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceswkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock~k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk}iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp|iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~	kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z
kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p
kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3Qck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
~+~qk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
zIzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
Fjz#kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c"k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q!k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5 kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{(k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z'kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP&k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc%k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p$kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
{Fjv{v.iAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesr-k}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z,kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c+k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q*k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5)kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
@'I%@v6kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg5iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires34k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh3ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m2iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi1imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU0iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|/kIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*Ev>kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg=iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3<k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh;ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m:iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi9imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU8iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057w7kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
!hBikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kAiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp@iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew?kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
HcwFkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvEkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgDiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Ck}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
JkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockIk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskHiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspGiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zVqwPkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvOkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgNiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Mk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhLikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16KkAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
TkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockSk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskRiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspQiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%pYiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewXkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvWkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgViiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequiresUkAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
1~1g`iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requiresc_k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p^kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services]kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock\kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock[k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskZiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks

er+V:eD4
b772674f402708d7a9f5c7def69900c57b170e563c2d85cab68cb3c7dd011b4aD3
bdc9a186d8366629fb8cebd6f2da7e719bafe512cf237e1600cb799720208e34D2
2aebe9981726c0cb957fba5fd53f20dc834ae5db5bffd674f3e8dfd37e300569D1
80f7c4d43325e0eaf5c03d461abdecaa270e288f97e98c48b11ef953ac3c2ad7D0
21e025565c6df51abd78e6c98b69d9f5be23937f57c5a64c76d807474bb9cb0bD/
ebf6108e3363c7e97a710010b034bcd8756cb06bdb7dcad7f1cfd7b5d5b94925D.
1f08621d329170cddb192cd470d84cca45c4f102f80f2763f6ad12bcd7d94903D-
f1aac8f28d7b09a95684a3721602f0d75b800ec4446164425cbe36568cb5d9e6D,
92d0bc0edf07e6a5b24d5dcbe83924f7438ff5eaa170034fbde75f52fbbde969D+
166e3f5af4c284b83976badb2166ef9cbf7ee9204cc585ab900bfe28006a7917D*
bf842b8211bed6cacf365fa45198ae4376c511311e8e65daff8a87231424ed8fD)
bcabaf0d5da539b375bef6f5b408b4c4ec6fb3c207f79f771b9a4349431144f7D(
86b9d3e949b76b70e8c793f03ef07004f125e978056735b094814e3c282208a6
ek%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskdiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspciyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewbkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvakIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DC
ywjkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagcik_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254phkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesgkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockfkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
nkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockmk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskliqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspkiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
PzIPwtkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagzskAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePrk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcqk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254ppkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesokAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
xkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockwk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskviqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspuiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz}kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP|k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc{k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pzkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesykAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp~iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock

k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk	iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
DyDzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p
kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
~kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
IFK>Ip kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
FF5%kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{$k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z#kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP"k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc!k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
6tgr6P+k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc*k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p)kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services(kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock'kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock&k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
@S@1kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock0k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesq/k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5.kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{-k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z,kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
zIz6kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP5k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc4k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p3kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services2kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
VFKVp;kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services:kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockq9k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind58kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{7k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
FFqAk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5@kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{?k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z>kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP=k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc<k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
d9dPGk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcFk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pEkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesDkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockzCkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cBk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023
nSnzMkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cLk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qKk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5JkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Ik
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zHkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
QQQ{Rk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zQkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePPk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcOk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pNkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
FjvcYk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pXkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesrWk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zVkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cUk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qTk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5SkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
+~c_k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q^k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5]kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{\k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z[kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePZk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
Z8ZmfiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersieimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUdiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|ckIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHELvbiAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrak}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z`kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023

er+V:eDA
134ebbe6274a1c839f7532e6c8c356f561d28c58fcde4685da109f394c8081acD@
b2ef8a6d19b994c6cead1e1510c4b2f0abe8b34327fe6fbc1e106f3549ef5de9D?
26a68d26adb827543aeaad6e4d3d44e9427ff343621f03ac95b3ee77567a2791D>
085f2174502e709dad29fc828ef0fd2f5c027de6d68e07e337607b8c77e184cdD=
a6bfb1c5831155f91a3bad78a1830d94fefc2a73404bac0d0cd1818419a2bd97D<
87db2fe7caa5472a08068b5229089b79f46799961c76df49341071e86736a23eD;
9aaf0e40133fe06566b60b7c5045d71204f986d2fb7aef8c6375d03c80b89120D:
878e4a65ea92ff450fd8d2bd226c5bc9e55bcd148895af1d80aec4ad27528da7D9
410ce04c09d80f22a31d904271e83d196121736299e85e3eed33da09b5e99399D8
8408d0aca2bfcaaac96c7f2344996a46fdebe107dd0cb02f4af7dbdca094e232D7
377ad2aef6a59ddb2c292a6fac9feb315ee0b1fa109bd47f5aca3c6b7710e3b8D6
6384423635a67bb9f927be241ed3f67b1e101743ff36d4f239fdca3de98d1474D5
e3d6fe10b5be6ef1037244968642c245659e0a8f0dce997e92167e26158779cf
q|vliAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directorieswkkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvjkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3hk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhgikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16
@'I%@vtkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgsiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3rk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhqikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mpiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersioimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUniEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|mkIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*Ev|kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg{iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3zk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhyikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mxiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiwimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUviEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wukIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
[![iimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057kiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp~iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew}kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
#kwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16miuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal users
x0x3k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh
ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16k	iqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
<<kiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv
kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires
tgwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequireskAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
"kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock!k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz'kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP&k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc%k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p$kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services#kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
+kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock*k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk)iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp(iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz0kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP/k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc.k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p-kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services,kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~5kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock4kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock3k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk2iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{1k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{:k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z9kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP8k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc7k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p6kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3Qc@k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p?kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services>kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock=kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock<k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5;kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
~+~qEk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5DkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Ck
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zBkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePAk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
zIzJkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePIk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcHk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pGkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesFkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
FjzOkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cNk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qMk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5LkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{Kk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{Tk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zSkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePRk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcQk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pPkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
{Fjv{vZiAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrYk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zXkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023cWk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qVk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5UkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
@'I%@vbkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgaiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3`k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh_ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m^iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi]imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU\iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|[kIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*EvjkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3hk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhgikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mfiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersieimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUdiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wckIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag

er+V:eDN
78a505e2bcfc16a350b57ebc21548ec930762a04126892a45b3a16320eab40bfDM
4e82685863559181e2fb19cd0ab050ce5c0cc72aee0aa23484c3c8bd3233a2aeDL
6b8e84e40f76c1ccc98e60f6fc669dc338d056f42c48ba13b6a52100a4f94564DK
c5857421c619421bd4cd8ddb51736ad8d819352b2770078910fd43a33461df77DJ
90f1c235b87123f7d8a5ed0f7a6b6a246999326ece8c0c87c4412e41a67e4990DI
ea43fb93ee5477ce7a096f94c4c69775bd338911a252668b833ecc7ffe9f4452DH
5a4016edab2fb96b11729042f640f939d31bdd1eea435240f269d9ece5ab72d1DG
307213631a2c91a2525aabaa4c385612cf940c0756076d44a20f99ccf48fb1e3DF
4378731794448fc800d324e71a41beeae2b174ba078b23eb78ccff27fd8d5764DE
dfa0087b709a643d5c0cd08f474c7f4e2246be49e0ed748ef007f5903a31b544DD
0b321ea4f022bb7f3c34a1bd3f7d2b5cda3bc71f527d5d4e5af585464ef88de7DC
fee2103b6ba68f134bc8d706313e6d873b9ef2d803cbcb27234da184bd579eb1DB
d6ea0ca981efba600c4c9a961ef325d51932a90a277b9769a59c3a585824515d
!hnikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kmiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspliyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewkkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
HcwrkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvqkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgpiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3ok}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
vkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockuk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesktiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspsiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%p{iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewzkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvykIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgxiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM RequireswkAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
!~!wkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock~kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock}k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk|iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP
k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc	k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk
iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3Qc$k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p#kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services"kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock!kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
~+~q)k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5(kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{'k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z&kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP%k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlbR@RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{@`G@aM@bR@cY@d_@ef@gl@ht@i|@j@k@l@m@n@o@p@q"@r'@s+@t0@u5@v:@w@@xE@yJ@zO@{T@|Z@}b@~j@n@r@v@{@@@@@@@@$@)@.@3@8@>@F@N@R@V@Z@_@f@j@o@s@x@}@@@
@@@@"@*@2@6@:@>@C@J@N@S@W@\@a@f@l@q@v@{@@@@@@@"@(@,@1@ƒ8@Ã=@ăB@ŃF@ƃL
zIz.kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP-k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc,k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p+kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services*kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
Fjz3kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c2k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q1k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind50kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{/k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{8k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z7kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP6k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc5k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p4kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
{Fjv{v>iAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesr=k}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z<kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c;k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q:k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind59kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
@'I%@vFkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgEiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Dk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhCikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mBiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiAimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU@iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|?kIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*EvNkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgMiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Lk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhKikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mJiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiIimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUHiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wGkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
!hRikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kQiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspPiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewOkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
HcwVkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvUkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgTiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Sk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
ZkAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockYk%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskXiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspWiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%p_iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew^kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv]kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg\iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires[kAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
!~!wfkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagcek_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pdkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesckAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockbkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockak%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk`iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks

er+V:eD[
166d7341007094fcdf2e7262d74c699cb960d009945a221df4ba4a33d63ebc76DZ
2833f7d8c4764e2c4c247d5f95bf07698e64f2a6dc53aba92fe3fa1f92affe42DY
0adc9fe4603e83cc02d7181487b5982803e7d1ac319a09428f7f62c4b74d8d3dDX
672ffef35a04fe32b016bba89b95e6120a868c7d27c5054cb5fed31aca0fca0aDW
5cadd6d1e44a896802e1df30ac84a484345f572bfaaa938544b43458dc6d80bdDV
3a891b3b430fed933fb5c51f4dabf4aad4986782e238208490c03139368c40d4DU
fc626afc893b85c55f51d292c8bb06d0f31d54e62391e473e9fd5d070392c64cDT
ac1a64b7b78526de7991cf4af7c5df8f1b799a4c43b62277a17f7e6b5a8bb4e4DS
b08b52ab528346df18af0d47ce99984bb2bd02ac6801bb580534ff9d3274a0abDR
28000a91ccbcd79237e5ddae52f2c4002be7344262fc0e43ce86378d90823bd7DQ
c791e843e2fbae086343a6654618fae6ea425f37e0816212e9805136c98a236cDP
9b69e41e187f8c3cd3d73d8a8b89d8ee3e0237dbf11ca2481d2bb26444e5ed32DO
4985ef8243b405acb259897280bebdf83951ffe71af3db3fcf8140797602544b
jkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockik%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskhiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspgiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzokAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePnk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcmk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254plkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
skAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockrk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskqiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksppiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzxkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePwk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcvk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pukwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicestkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~}kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock|kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock{k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskziqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{yk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p~kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3Qck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
~+~q
k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z
kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP	k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
zIzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
FjzkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023ck_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
{Fjv{v"iAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesr!k}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023ck_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
@'I%@v*kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg)iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3(k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh'ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m&iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi%imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU$iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|#kIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*Ev2kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg1iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires30k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh/ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m.iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi-imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU,iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057w+kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
!h6ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16k5iqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp4iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew3kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
Hcw:kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv9kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg8iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires37k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
>kAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock=k%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk<iqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp;iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%pCiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewBkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvAkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg@iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires?kAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
!~!wJkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagcIk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pHkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesGkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockFkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockEk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskDiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
NkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockMk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskLiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspKiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzSkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePRk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcQk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pPkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesOkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
WkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockVk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskUiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspTiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz\kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP[k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcZk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pYkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesXkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
~akAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock`kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock_k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk^iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{]k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{fk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zekAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePdk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pbkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
QF3Qclk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesjkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockikAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockhk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues5gkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict

er+V:eDh
b4483eb8d3d6d68b68ad3e08c79385f43b0a40aa17c3681e16b53bdddfa10befDg
f85bf7e8f01a89ac772fea257536fa49cc0e71b925cccbf45c5bac62a6c37058Df
416e2bda192d4d2ef653af8a613b3317548b4dffe2455e834970d920976316a3De
e2f69cb9ce06dc6e440ee55d4de796bbf6daa032c04f11a93e33ceae0d79eb9cDd
fc095d80f336de3930ba83232f8684e5f27e20a6a90348f9746f9d4c65940aa4Dc
a94b2b0e58abe148cf3859a7fc971e0d1a559ce796f9f47b7450164810d65dc5Db
dfe0da66e34f229040771968adc12e53f3ef8575433da409ecd46a284495677eDa
4a0c264159f020e612793ba279b544a49c67ce5644e4673d6a1b7e01986d8c98D`
b0239f1e155c51adc55198eac03bc51b27badae7390b0220ca96829e87c6c759D_
f13bbe4b18a80136adc1b2b02ef61c69686b5b4b0437ee77f9ae29ee64542d8cD^
6c0b00e1f00b1bfb079fb63ec314dec78319b2c8c2820688cfdc033017e0dc14D]
1a7644fd57be2d7e96c28f3c6603e556bdb0d939164b61e085301064464d1aa7D\
c8c0d6d376e5a026cccec4e8a7f10de5f58b0178fb266a8f627d285ea803e25c
~+~qqk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5pkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{ok
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142znkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePmk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
zIzvkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePuk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlctk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pskwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesrkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
Fjz{kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023czk_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qyk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5xkAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{wk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
QQQ{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP~k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc}k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p|kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
{Fjv{viAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesrk}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2zkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023ck_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023qk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
@'I%@vkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg
iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16m
iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi	imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|kIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*EvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16miuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
!hikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16kiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
HcwkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-join
"kAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock!k%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk iqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zVqw(kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv'kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg&iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3%k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh$ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16#kAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
,kAndreas Schneider <asn@redhat.com> - 4.10.17-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock+k%Andreas Schneider <asn@redhat.com> - 4.10.17-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk*iqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp)iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
%z%p1iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew0kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv/kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg.iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires-kAndreas Schneider <asn@redhat.com> - 4.10.17-13`@- related: #1876839 - Fix double crash when requesting share mode lock
1~1g8iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requiresc7k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p6kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services5kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock4kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock3k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk2iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks
=k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesk<iqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp;iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagew:kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv9kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DC
ywBkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagcAk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p@kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services?kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock>kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
FkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockEk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskDiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspCiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
PzIPwLkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagzKkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePJk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcIk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pHkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesGkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
PkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockOk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskNiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspMiyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIzUkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePTk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcSk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pRkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesQkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
YkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockXk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskWiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunkspViyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
zIz^kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP]k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc\k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p[kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesZkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
bk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskaiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunksp`iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage{_k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
DyDzhkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePgk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcfk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pekwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesdkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockckAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock
~mkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode locklkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockkk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issueskjiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks{ik
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142

er+V:eDu
ec41eab909a34c37394e1bd1e2d8c1f86ed4342eb3aec006e4dce9be59094696Dt
a9f17b1fddb696d9e462b1c59846a76dfba2d99b26bfd9a07e461bcae6c41834Ds
b438e03eb4776904a5d3eda9f71311951963cace861385cb395c161e85901444Dr
3bd639121f6b04020233f7f81a713e0fdde89de7bd7b34c14ad4c211ad5b1560Dq
b16634b5890da4c94a654fa49d88e872174872df18ecfff9c897a547f2828abcDp
240ac23487f8ee37fa0e974ec81a99ac0f9ef344259c12e512cbca60992948bfDo
9cbc0d51860b18d2d4dad73f8fcd78a82a9751a94316cae1b852109e078f1b33Dn
1f353580c9e10d38968fb29d6afe568ae1887002f902073726b229aacd22921aDm
4d459fe6f652254e5a835c98f2be03ec668f7667a2f0789647fd5a2e1ec01e0dDl
30090b57be5124d284a1340b0f43017ad484be4f476f8f4103506d8736eef996Dk
0794a0f7d6a515b2cdfb8187e15d5605671a95d2ebabff7bdf87777d0c9530dcDj
63c934de1e5c85819654daeea796881641d8431d74c21df7d4cc109514cacb35Di
1d8a98543a1bf0ec8722595afa191584c9cba8432bcaa4234ae07105479c78c7
QQQ{rk
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zqkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePpk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcok_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pnkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
IFK>IpxkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceswkAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockvkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockuk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesktiqAndreas Schneider <asn@redhat.com> - 4.10.16-9_:- related: #1853272 - Add back missing patch hunks5skAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
FF5}kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{|k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z{kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePzk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlcyk_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
6tgr6Pk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockkAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lock~k%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issues
@S@	kAndreas Schneider <asn@redhat.com> - 4.10.16-11`@- resolves: #1876839 - Fix double crash when requesting share mode lockk%Andreas Schneider <asn@redhat.com> - 4.10.16-10_- resolves: #1868327 - Fix winbind in trust scenaries with connection issuesqk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
zIzkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP
k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
kAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lock
VFKVpkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockqk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142
FFqk{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142zkAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server rolePk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254
d9dPk7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlck_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254pkwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting serviceskAndreas Schneider <asn@redhat.com> - 4.10.16-13`@- related: #1876839 - Fix double crash when requesting share mode lockzkAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023ck_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023
nSnz%kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c$k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q#k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5"kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{!k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server role
QQQ{*k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z)kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP(k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idlc'k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p&kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting services
Fjvc1k_Andreas Schneider <asn@redhat.com> - 4.10.16-15`@- resolves: #1949444 - Fix CVE-2021-20254p0kwAndreas Schneider <asn@redhat.com> - 4.10.16-14`t6@- resolves: #1937867 - Fix possible core dump with printing support
- resolves: #1930747 - Ensure that libwbclient has been updated before
                       restarting servicesr/k}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z.kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023c-k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q,k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind5+kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict
+~c7k_Andreas Schneider <asn@redhat.com> - 4.10.16-23c@- resolves: #2154364 - Fix CVE-2022-38023q6k{Andreas Schneider <asn@redhat.com> - 4.10.16-20c
- resolves: #2119058 - Fix possible segfault in winbind55kAndreas Schneider <asn@redhat.com> - 4.10.16-19bzS- resolves: #2081649 - Fix idmap_rfc2307 and idmap_nss returning wrong
                       mapping for uid/gid conflict{4k
Andreas Schneider <asn@redhat.com> - 4.10.16-18a@- resolves: #2034800 - Fix usermap script regression caused by CVE-2020-25717
- resolves: #2036595 - Fix MIT realm regression caused by CVE-2020-25717
- resolves: #2046148 - Fix CVE-2021-44142z3kAndreas Schneider <asn@redhat.com> - 4.10.16-17aK- related: #2019673 - Add missing checks for IPA DC server roleP2k7Andreas Schneider <asn@redhat.com> - 4.10.16-16a@- resolves: #2019661 - Fix CVE-2016-2124
- resolves: #2019673 - Fix CVE-2020-25717
- resolves: #2021428 - Add missing PAC buffer types to krb5pac.idl
Z8Zm>iuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersi=imAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileU<iEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|;kIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHELv:iAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directoriesr9k}Andreas Schneider <asn@redhat.com> - 4.10.16-25d@- resolves: #2222250 - Fix netlogon capabilities level 2z8kAndreas Schneider <asn@redhat.com> - 4.10.16-24cʂ@- related: #2154364 - Add additional patches for CVE-2022-38023
q|vDiAndreas Schneider <asn@redhat.com> - 4.10.15-1^- related: #1785121 - Rebase to version 4.10.15
- resolves: #1828924 - Fix typo in pam_winbind documentation about require_membership_of
- resolves: #1801496 - Add missing ctdb directorieswCkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagvBkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgAiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3@k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh?ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16
@'I%@vLkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgKiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Jk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhIikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mHiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiGimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUFiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057|EkIsaac Boukris <iboukris@redhat.com> - 4.10.15-2^- resolves: #1825505 - Compilation of samba sources fails on RHEL
E,N*EvTkIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCgSiiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3Rk}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinhQikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mPiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal usersiOimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUNiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057wMkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
[![iYimAndreas Schneider <asn@redhat.com> - 4.10.15-4^@- resolves: #1813017 - Fix smbclient log to fileUXiEAndreas Schneider <asn@redhat.com> - 4.10.15-3^U@- Removed patch for #1634057kWiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunkspViyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpagewUkIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tag
#kw_kIsaac Boukris <iboukris@redhat.com> - 4.10.16-7_- related: #1852812 - trigger a rebuild to get the right tagv^kIsaac Boukris <iboukris@redhat.com> - 4.10.16-6_A@- resolves: #1852812 - Fix additioanl hostnames with win DCg]iiAndreas Schneider <asn@redhat.com> - 4.10-16-5^א- related: #1785121 - Add missing RPM Requires3\k}Isaac Boukris <iboukris@redhat.com> - 4.10.16-2^?@- resolves: #1828354 - add additioanl hostnames to the keytab
- resolves: #1836427 - add dnshostname option net-ads-joinh[ikAndreas Schneider <asn@redhat.com> - 4.10.16-1^˳@- related: #1785121 - Rebase to version 4.10.16mZiuAndreas Schneider <asn@redhat.com> - 4.10.15-5^@- resolves: #1831986 - Fix gencache for normal users
SS>c_Watson Sato <wsato@redhat.com> - 0.1.49-7^- Bug fixes on CIS profile (RHBZ#1821633)
  Added Ansible remediations
  Fixed CIS references
  Fixed integration issues with CIS profilebmVojtech Polasek <vpolasek@redhat.com> - 0.1.49-6^- Added a patch fixing audit_rules_privileged_commands (RHBZ#1691877)kaiqAndreas Schneider <asn@redhat.com> - 4.10.17-9_:- related: #1853272 - Add back missing patch hunksp`iyAndreas Schneider <asn@redhat.com> - 4.10.16-8_- resolves: #1878205 - Fix restarting winbind on package upgrade
- resolves: #1892632 - Fix CVE-2020-14318
- resolves: #1891687 - Fix CVE-2020-14323
- resolves: #1879834 - Fix CVE-2020-1472
- resolves: #1892313 - Fix memory leak in winbindd (wbinfo -u)
- resolves: #1868917 - Fix %U substitution for 'valid users' option
- resolves: #1853272 - Fix 'require_membership_of' documentation in
                       pam_winbind{.conf} manpage
))fhamWatson Sato <wsato@redhat.com> - 0.1.49-12^m@- CIS Profile (RHBZ#1821633)
  - Make sure boot target is multi-user.target when xorg package is removed
  - Add CIS Profile content attribution to Center for Internet SecuritygaYWatson Sato <wsato@redhat.com> - 0.1.49-11^- HIPAA Profile improvement (RHBZ#1513087)
  - Add Ansible remediation for audit_rules_system_shutdownEfa+Watson Sato <wsato@redhat.com> - 0.1.49-10^@- CIS Profile fixes (RHBZ#1821633)
  - Fix Ansible mount_option template
  - Re-order rpm_verify_permissions to avoid file permission conflictse_SWatson Sato <wsato@redhat.com> - 0.1.49-9^- CIS Profile fixes (RHBZ#1821633)
  - Fix Ansible mount_option template
  - Add Ansible for ensure_logrotate_activated
  - Add warnings to rpm_verify_permissions and ownership about findindings that may need further inspection`d_eWatson Sato <wsato@redhat.com> - 0.1.49-8^>@- Fix specfile to apply patch (RHBZ#1691877)
rlY<rEma+Watson Sato <wsato@redhat.com> - 0.1.49-10^@- CIS Profile fixes (RHBZ#1821633)
  - Fix Ansible mount_option template
  - Re-order rpm_verify_permissions to avoid file permission conflictsl_SWatson Sato <wsato@redhat.com> - 0.1.49-9^- CIS Profile fixes (RHBZ#1821633)
  - Fix Ansible mount_option template
  - Add Ansible for ensure_logrotate_activated
  - Add warnings to rpm_verify_permissions and ownership about findindings that may need further inspectionikkkGabriel Becker <ggasparb@redhat.com> - 0.1.52-2_@- Update RHEL7 DISA STIG to V3R1 (RHBZ#1665233)!jkYGabriel Becker <ggasparb@redhat.com> - 0.1.52-1_~@- Update to the latest upstream release (RHBZ#1665233)
- Update RHEL7 DISA STIG to V2R8 (RHBZ#1665233)ia?Watson Sato <wsato@redhat.com> - 0.1.49-13^- Add example kickstart for RHEL7 HIPAA (RHBZ#1513087)
- Fix Test Suite to run on Python3

er+V:eD
d40393b60950d71a26774d9b1e266fd5bb089196ab92a7c1d63bc4e09f86640cD
c1fb45bbf918990aa7c9459fcbcf058bc3b97c0e00ccf709693ef5cf9d26dd1dD
5dbc6a254bc8c77e947deecbb35eecf6dd6724e8271f52c60fabb83775d0653cD
ab57e2a2afb31039c65c93e0ca3680f1377080ea7d39ce5ba84007dbe8770b6fD~
4d3ff47c13cc9874693a7b3fa026f1ab176d6a2d2b0a14b6d2ce80773ed3fae9D}
a39b37b22a67c2fed32b45b2c75ceda293b7a59938dfb6d991ff59b639ae2aeaD|
e02972fac05c3f064d850d48bd37730bdc682a15ee48e9df9f51ad3d023e5115D{
1296d51c39d8f5be9667a1c80e53bc0edc3a1395b7d75cbce793d6ca7fc9648dDz
be9e5f7cee095463cb4d9b9f2109692cc190d7b3dd83fd149316ee244992293fDy
f7945628e8e698e802ec8e5135e5523626b0540472b6dbc6921ff39095ca55d1Dx
020558539740256bcdb84e7c5606c92c374e8b5d5af9021d52cb794b0f6131e1Dw
9f0008a88260081411e863e41debfe8067b201353ea3a2182eb3f16e4267d6e5Dv
cb86afe6203e0e076f646a698b5f55cc194b2523e731d2af6fad43073fedcf79
_t:irkkGabriel Becker <ggasparb@redhat.com> - 0.1.52-2_@- Update RHEL7 DISA STIG to V3R1 (RHBZ#1665233)!qkYGabriel Becker <ggasparb@redhat.com> - 0.1.52-1_~@- Update to the latest upstream release (RHBZ#1665233)
- Update RHEL7 DISA STIG to V2R8 (RHBZ#1665233)pa?Watson Sato <wsato@redhat.com> - 0.1.49-13^- Add example kickstart for RHEL7 HIPAA (RHBZ#1513087)
- Fix Test Suite to run on Python3foamWatson Sato <wsato@redhat.com> - 0.1.49-12^m@- CIS Profile (RHBZ#1821633)
  - Make sure boot target is multi-user.target when xorg package is removed
  - Add CIS Profile content attribution to Center for Internet SecuritynaYWatson Sato <wsato@redhat.com> - 0.1.49-11^- HIPAA Profile improvement (RHBZ#1513087)
  - Add Ansible remediation for audit_rules_system_shutdown
\ICwkGabriel Becker <ggasparb@redhat.com> - 0.1.54-5`[- Create subpackage to hold ansible playbooks per rule (RHBZ#1966589)
- Fix Bash remediation of dconf_gnome_login_retries (RHBZ#1967566)vmIVojtech Polasek <vpolasek@redhat.com> - 0.1.54-4` @- Update RHEL 7 STIG profile to V3R3 (RHBZ#1958789)
- Update ANSSI High Profile (RHBZ#1955180)pu_Watson Sato <wsato@redhat.com> - 0.1.54-3`6?- Realign PCI-DSS rules selection to v0.1.54 (RHBZ#1497415)7t_Watson Sato <wsato@redhat.com> - 0.1.54-2`-@- Remove Kickstart for not shipped profile (RHBZ#1497415)
- Fix STIG id reference format for sshd_x11_use_localhost (RHBZ#1921643)cs_iWatson Sato <wsato@redhat.com> - 0.1.54-1`@- Rebase to incorporate ANSSI Profile (RHBZ#1497415)
- Update RHEL7 STIG profile to V3R2 (RHBZ#1921643)
- Add Minimal, Intermediary and Enhanced ANSSI Profiles (RHBZ#1497415)
Bu),Bq~k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)q}k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)q|k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-3aqV@- Fix broken SELinux documentation links (RHBZ#1996678){kGabriel Becker <ggasparb@redhat.com> - 0.1.57-2ap- Fix auditd_overflow_action configuration path for RHEL7 (RHBZ#1996678)8zaJan Černý <jcerny@redhat.com> - 0.1.57-1a^@- Rebase to the 0.1.57 upstream release
- Update RHEL7 DISA STIG profile to v3r4 (RHBZ#1996678)
- Split CIS profile (RHBZ#1953787)
ym)Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-7`\- Generate HTML STIG reference tables also for stig_gui profile (RHBZ#1958789)xm!Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-6`P@- Add kickstart files for RHEL 7 stig and stig_gui profiles (RHBZ#1958789)
1z`1qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-3aqV@- Fix broken SELinux documentation links (RHBZ#1996678)kGabriel Becker <ggasparb@redhat.com> - 0.1.57-2ap- Fix auditd_overflow_action configuration path for RHEL7 (RHBZ#1996678)8aJan Černý <jcerny@redhat.com> - 0.1.57-1a^@- Rebase to the 0.1.57 upstream release
- Update RHEL7 DISA STIG profile to v3r4 (RHBZ#1996678)
- Split CIS profile (RHBZ#1953787)
m)Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-7`\- Generate HTML STIG reference tables also for stig_gui profile (RHBZ#1958789)m!Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-6`P@- Add kickstart files for RHEL 7 stig and stig_gui profiles (RHBZ#1958789)kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)
ZZ8aJan Černý <jcerny@redhat.com> - 0.1.57-1a^@- Rebase to the 0.1.57 upstream release
- Update RHEL7 DISA STIG profile to v3r4 (RHBZ#1996678)
- Split CIS profile (RHBZ#1953787)

m)Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-7`\- Generate HTML STIG reference tables also for stig_gui profile (RHBZ#1958789)q	_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)e_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)
4x4q_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)e_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)q
k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-3aqV@- Fix broken SELinux documentation links (RHBZ#1996678)kGabriel Becker <ggasparb@redhat.com> - 0.1.57-2ap- Fix auditd_overflow_action configuration path for RHEL7 (RHBZ#1996678)
OOkGabriel Becker <ggasparb@redhat.com> - 0.1.57-2ap- Fix auditd_overflow_action configuration path for RHEL7 (RHBZ#1996678)8aJan Černý <jcerny@redhat.com> - 0.1.57-1a^@- Rebase to the 0.1.57 upstream release
- Update RHEL7 DISA STIG profile to v3r4 (RHBZ#1996678)
- Split CIS profile (RHBZ#1953787)g_qWatson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)
1q_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)e_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-3aqV@- Fix broken SELinux documentation links (RHBZ#1996678)
g_qWatson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)
}g}q k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-3aqV@- Fix broken SELinux documentation links (RHBZ#1996678)kGabriel Becker <ggasparb@redhat.com> - 0.1.57-2ap- Fix auditd_overflow_action configuration path for RHEL7 (RHBZ#1996678)_;Watson Sato <wsato@redhat.com> - 0.1.66-1cw- Rebase to a new upstream release 0.1.66 (RHBZ#2158410)
- Update RHEL7 STIG profile to V3R10 (RHBZ#2152657)
- Align file_permissions_sshd_private_key with DISA Benchmark (RHBZ#2123284)
- Fix remediation of audit watch rules (RHBZ#2123367)
- Fix check firewalld_sshd_port_enabled (RHBZ#2158410)
- Fix accepted control flags for pam_pwhistory (RHBZ#2158410)
- Unselect rule logind_session_timeout (RHBZ#2158410)
- Add support rainer scripts in rsyslog rules (RHBZ#2170038)
q$_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)e#_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)"kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)q!k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)
g%_qWatson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)
''q(k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)N'a=Jan Černý <jcerny@redhat.com> - 0.1.69-1d@- Rebase to the latest upstream release (RHBZ#2221694)
- Make IPv6 related rules applicable only in case IPv6 is actually enabled. (RHBZ#2210276)
- update ANSSI BP-028 profiles to be aligned with version 2.0 (RHBZ#2155793)
- Correct URL used to download CVE checks. (RHBZ#2223817)&_;Watson Sato <wsato@redhat.com> - 0.1.66-1cw- Rebase to a new upstream release 0.1.66 (RHBZ#2158410)
- Update RHEL7 STIG profile to V3R10 (RHBZ#2152657)
- Align file_permissions_sshd_private_key with DISA Benchmark (RHBZ#2123284)
- Fix remediation of audit watch rules (RHBZ#2123367)
- Fix check firewalld_sshd_port_enabled (RHBZ#2158410)
- Fix accepted control flags for pam_pwhistory (RHBZ#2158410)
- Unselect rule logind_session_timeout (RHBZ#2158410)
- Add support rainer scripts in rsyslog rules (RHBZ#2170038)
q,_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)e+_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)*kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)q)k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)
g-_qWatson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)bRA/RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{@ȃU@ɃY@ʃ^@˃b@̃h@̓m@σr@Ѓx@у}@҃@Ӄ	@ԃ@Ճ@փ@׃@؃%@ك*@ڃ1@ۃ7@܃>@݃D@ރL@߃T@Y@პ_@⃞c@マh@䃞m@惞r@烞w@胞~@郟@ꃟ@냟@샟@탟@@ @$@%@(@,@-@/@5@6@8@>@@@B@H@L@QAVA[AbAiAoAvAyAA	A
AA	A
AAAAAAA"A)A/A2A6A:A;A>ABACAEAKA LA!NA"TA#ZA$`A%dA&iA'mA(rA*vA+yA,A-A.
N/a=Jan Černý <jcerny@redhat.com> - 0.1.69-1d@- Rebase to the latest upstream release (RHBZ#2221694)
- Make IPv6 related rules applicable only in case IPv6 is actually enabled. (RHBZ#2210276)
- update ANSSI BP-028 profiles to be aligned with version 2.0 (RHBZ#2155793)
- Correct URL used to download CVE checks. (RHBZ#2223817)._;Watson Sato <wsato@redhat.com> - 0.1.66-1cw- Rebase to a new upstream release 0.1.66 (RHBZ#2158410)
- Update RHEL7 STIG profile to V3R10 (RHBZ#2152657)
- Align file_permissions_sshd_private_key with DISA Benchmark (RHBZ#2123284)
- Fix remediation of audit watch rules (RHBZ#2123367)
- Fix check firewalld_sshd_port_enabled (RHBZ#2158410)
- Fix accepted control flags for pam_pwhistory (RHBZ#2158410)
- Unselect rule logind_session_timeout (RHBZ#2158410)
- Add support rainer scripts in rsyslog rules (RHBZ#2170038)
h2Mhq5_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)e4_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)3kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)q2k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)l1omMarcus Burghardt <maburgha@redhat.com> - 0.1.72-2eN@- Unlist profiles no longer maintained in RHEL8.I0o%Marcus Burghardt <maburgha@redhat.com> - 0.1.72-1e̫@- Rebase to a new upstream release 0.1.72 (RHEL-25251)
- Include filter to dracut files in audit_rules_privileged_commands rule (RHEL-11938)
g6_qWatson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)
N8a=Jan Černý <jcerny@redhat.com> - 0.1.69-1d@- Rebase to the latest upstream release (RHBZ#2221694)
- Make IPv6 related rules applicable only in case IPv6 is actually enabled. (RHBZ#2210276)
- update ANSSI BP-028 profiles to be aligned with version 2.0 (RHBZ#2155793)
- Correct URL used to download CVE checks. (RHBZ#2223817)7_;Watson Sato <wsato@redhat.com> - 0.1.66-1cw- Rebase to a new upstream release 0.1.66 (RHBZ#2158410)
- Update RHEL7 STIG profile to V3R10 (RHBZ#2152657)
- Align file_permissions_sshd_private_key with DISA Benchmark (RHBZ#2123284)
- Fix remediation of audit watch rules (RHBZ#2123367)
- Fix check firewalld_sshd_port_enabled (RHBZ#2158410)
- Fix accepted control flags for pam_pwhistory (RHBZ#2158410)
- Unselect rule logind_session_timeout (RHBZ#2158410)
- Add support rainer scripts in rsyslog rules (RHBZ#2170038)
`2EJ`e>_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)=kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)q<k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)y;aJan Černý <jcerny@redhat.com> - 0.1.73-1fL- Rebase scap-security-guide package to version 0.1.73 (RHEL-36739)l:omMarcus Burghardt <maburgha@redhat.com> - 0.1.72-2eN@- Unlist profiles no longer maintained in RHEL8.I9o%Marcus Burghardt <maburgha@redhat.com> - 0.1.72-1e̫@- Rebase to a new upstream release 0.1.72 (RHEL-25251)
- Include filter to dracut files in audit_rules_privileged_commands rule (RHEL-11938)
g@_qWatson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)q?_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)
NBa=Jan Černý <jcerny@redhat.com> - 0.1.69-1d@- Rebase to the latest upstream release (RHBZ#2221694)
- Make IPv6 related rules applicable only in case IPv6 is actually enabled. (RHBZ#2210276)
- update ANSSI BP-028 profiles to be aligned with version 2.0 (RHBZ#2155793)
- Correct URL used to download CVE checks. (RHBZ#2223817)A_;Watson Sato <wsato@redhat.com> - 0.1.66-1cw- Rebase to a new upstream release 0.1.66 (RHBZ#2158410)
- Update RHEL7 STIG profile to V3R10 (RHBZ#2152657)
- Align file_permissions_sshd_private_key with DISA Benchmark (RHBZ#2123284)
- Fix remediation of audit watch rules (RHBZ#2123367)
- Fix check firewalld_sshd_port_enabled (RHBZ#2158410)
- Fix accepted control flags for pam_pwhistory (RHBZ#2158410)
- Unselect rule logind_session_timeout (RHBZ#2158410)
- Add support rainer scripts in rsyslog rules (RHBZ#2170038)
2E`H_eWatson Sato <wsato@redhat.com> - 0.1.49-8^>@- Fix specfile to apply patch (RHBZ#1691877)>G_Watson Sato <wsato@redhat.com> - 0.1.49-7^- Bug fixes on CIS profile (RHBZ#1821633)
  Added Ansible remediations
  Fixed CIS references
  Fixed integration issues with CIS profileFmVojtech Polasek <vpolasek@redhat.com> - 0.1.49-6^- Added a patch fixing audit_rules_privileged_commands (RHBZ#1691877)yEaJan Černý <jcerny@redhat.com> - 0.1.73-1fL- Rebase scap-security-guide package to version 0.1.73 (RHEL-36739)lDomMarcus Burghardt <maburgha@redhat.com> - 0.1.72-2eN@- Unlist profiles no longer maintained in RHEL8.ICo%Marcus Burghardt <maburgha@redhat.com> - 0.1.72-1e̫@- Rebase to a new upstream release 0.1.72 (RHEL-25251)
- Include filter to dracut files in audit_rules_privileged_commands rule (RHEL-11938)
xfLamWatson Sato <wsato@redhat.com> - 0.1.49-12^m@- CIS Profile (RHBZ#1821633)
  - Make sure boot target is multi-user.target when xorg package is removed
  - Add CIS Profile content attribution to Center for Internet SecurityKaYWatson Sato <wsato@redhat.com> - 0.1.49-11^- HIPAA Profile improvement (RHBZ#1513087)
  - Add Ansible remediation for audit_rules_system_shutdownEJa+Watson Sato <wsato@redhat.com> - 0.1.49-10^@- CIS Profile fixes (RHBZ#1821633)
  - Fix Ansible mount_option template
  - Re-order rpm_verify_permissions to avoid file permission conflictsI_SWatson Sato <wsato@redhat.com> - 0.1.49-9^- CIS Profile fixes (RHBZ#1821633)
  - Fix Ansible mount_option template
  - Add Ansible for ensure_logrotate_activated
  - Add warnings to rpm_verify_permissions and ownership about findindings that may need further inspection
rlY<rEQa+Watson Sato <wsato@redhat.com> - 0.1.49-10^@- CIS Profile fixes (RHBZ#1821633)
  - Fix Ansible mount_option template
  - Re-order rpm_verify_permissions to avoid file permission conflictsP_SWatson Sato <wsato@redhat.com> - 0.1.49-9^- CIS Profile fixes (RHBZ#1821633)
  - Fix Ansible mount_option template
  - Add Ansible for ensure_logrotate_activated
  - Add warnings to rpm_verify_permissions and ownership about findindings that may need further inspectioniOkkGabriel Becker <ggasparb@redhat.com> - 0.1.52-2_@- Update RHEL7 DISA STIG to V3R1 (RHBZ#1665233)!NkYGabriel Becker <ggasparb@redhat.com> - 0.1.52-1_~@- Update to the latest upstream release (RHBZ#1665233)
- Update RHEL7 DISA STIG to V2R8 (RHBZ#1665233)Ma?Watson Sato <wsato@redhat.com> - 0.1.49-13^- Add example kickstart for RHEL7 HIPAA (RHBZ#1513087)
- Fix Test Suite to run on Python3
_t:iVkkGabriel Becker <ggasparb@redhat.com> - 0.1.52-2_@- Update RHEL7 DISA STIG to V3R1 (RHBZ#1665233)!UkYGabriel Becker <ggasparb@redhat.com> - 0.1.52-1_~@- Update to the latest upstream release (RHBZ#1665233)
- Update RHEL7 DISA STIG to V2R8 (RHBZ#1665233)Ta?Watson Sato <wsato@redhat.com> - 0.1.49-13^- Add example kickstart for RHEL7 HIPAA (RHBZ#1513087)
- Fix Test Suite to run on Python3fSamWatson Sato <wsato@redhat.com> - 0.1.49-12^m@- CIS Profile (RHBZ#1821633)
  - Make sure boot target is multi-user.target when xorg package is removed
  - Add CIS Profile content attribution to Center for Internet SecurityRaYWatson Sato <wsato@redhat.com> - 0.1.49-11^- HIPAA Profile improvement (RHBZ#1513087)
  - Add Ansible remediation for audit_rules_system_shutdown
\IC[kGabriel Becker <ggasparb@redhat.com> - 0.1.54-5`[- Create subpackage to hold ansible playbooks per rule (RHBZ#1966589)
- Fix Bash remediation of dconf_gnome_login_retries (RHBZ#1967566)ZmIVojtech Polasek <vpolasek@redhat.com> - 0.1.54-4` @- Update RHEL 7 STIG profile to V3R3 (RHBZ#1958789)
- Update ANSSI High Profile (RHBZ#1955180)pY_Watson Sato <wsato@redhat.com> - 0.1.54-3`6?- Realign PCI-DSS rules selection to v0.1.54 (RHBZ#1497415)7X_Watson Sato <wsato@redhat.com> - 0.1.54-2`-@- Remove Kickstart for not shipped profile (RHBZ#1497415)
- Fix STIG id reference format for sshd_x11_use_localhost (RHBZ#1921643)cW_iWatson Sato <wsato@redhat.com> - 0.1.54-1`@- Rebase to incorporate ANSSI Profile (RHBZ#1497415)
- Update RHEL7 STIG profile to V3R2 (RHBZ#1921643)
- Add Minimal, Intermediary and Enhanced ANSSI Profiles (RHBZ#1497415)
Bu),Bqbk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)qak{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)q`k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-3aqV@- Fix broken SELinux documentation links (RHBZ#1996678)_kGabriel Becker <ggasparb@redhat.com> - 0.1.57-2ap- Fix auditd_overflow_action configuration path for RHEL7 (RHBZ#1996678)8^aJan Černý <jcerny@redhat.com> - 0.1.57-1a^@- Rebase to the 0.1.57 upstream release
- Update RHEL7 DISA STIG profile to v3r4 (RHBZ#1996678)
- Split CIS profile (RHBZ#1953787)
]m)Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-7`\- Generate HTML STIG reference tables also for stig_gui profile (RHBZ#1958789)\m!Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-6`P@- Add kickstart files for RHEL 7 stig and stig_gui profiles (RHBZ#1958789)
1z`1qik{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)qhk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-3aqV@- Fix broken SELinux documentation links (RHBZ#1996678)gkGabriel Becker <ggasparb@redhat.com> - 0.1.57-2ap- Fix auditd_overflow_action configuration path for RHEL7 (RHBZ#1996678)8faJan Černý <jcerny@redhat.com> - 0.1.57-1a^@- Rebase to the 0.1.57 upstream release
- Update RHEL7 DISA STIG profile to v3r4 (RHBZ#1996678)
- Split CIS profile (RHBZ#1953787)
em)Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-7`\- Generate HTML STIG reference tables also for stig_gui profile (RHBZ#1958789)dm!Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-6`P@- Add kickstart files for RHEL 7 stig and stig_gui profiles (RHBZ#1958789)ckGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)
ZZ8oaJan Černý <jcerny@redhat.com> - 0.1.57-1a^@- Rebase to the 0.1.57 upstream release
- Update RHEL7 DISA STIG profile to v3r4 (RHBZ#1996678)
- Split CIS profile (RHBZ#1953787)
nm)Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-7`\- Generate HTML STIG reference tables also for stig_gui profile (RHBZ#1958789)qm_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)el_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)kkGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)qjk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)

er+V:eD
00d2bde49dfc19aa010c5926838900760b435bfe8f53e8d8ad0acefd762cafcfD
90862c0f721b1d5b253c6c69c26a15f9b8e4f492615fda39d9aa26a36263853dD

30b844415ba647e65a9810574f3ded5e1fc1edd02e28f73cc44ee2c35e97baeaD
878572277531168e4e6b34f6078224450001b713981b2781b0ccb572c1db7c3aD
5858767f54c2120e5d407542c3960c0bcdbe0ac20b7db144d540566f95fa03eeD

3f7f1d7529325771aca130abb3ada20b55752fb8168b35e388cf43ccaba01f5aD	
753153d2c6886bf4e0fd54f9652da1247fec1c0ab4d58a1aeb4bec8ebba28d9eD
0f031938a045f2ce246507b233ce7a53103a6051e0cda09aa7d2b4feab4e773bD
358ebccf9931f8222e5503aa6255be88b2b6862a1cff9b34c0622117c0fcfc97D
047afe9b60a6d1228931b215d26c7cc7dc637d69a40463e0a25163cd20c53b43D
f281eb4ce184ac0156ea4bb4999c5ac0071da44c1cb72f33d1fa6cfd57c1b932D
395a33a57a17338d844c031715190aa5f9cfe26cbff564eca64617c5328e167fD
d51829dbdacb88845a2597570d1a7102fbf961cce1be232b53e652c9e0877c17
4x4qv_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)eu_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)tkGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)qsk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)qrk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)qqk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-3aqV@- Fix broken SELinux documentation links (RHBZ#1996678)pkGabriel Becker <ggasparb@redhat.com> - 0.1.57-2ap- Fix auditd_overflow_action configuration path for RHEL7 (RHBZ#1996678)
OOykGabriel Becker <ggasparb@redhat.com> - 0.1.57-2ap- Fix auditd_overflow_action configuration path for RHEL7 (RHBZ#1996678)8xaJan Černý <jcerny@redhat.com> - 0.1.57-1a^@- Rebase to the 0.1.57 upstream release
- Update RHEL7 DISA STIG profile to v3r4 (RHBZ#1996678)
- Split CIS profile (RHBZ#1953787)gw_qWatson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)
1q_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)e~_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)}kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)q|k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)q{k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)qzk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-3aqV@- Fix broken SELinux documentation links (RHBZ#1996678)
g_qWatson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)
}g}qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-3aqV@- Fix broken SELinux documentation links (RHBZ#1996678)kGabriel Becker <ggasparb@redhat.com> - 0.1.57-2ap- Fix auditd_overflow_action configuration path for RHEL7 (RHBZ#1996678)_;Watson Sato <wsato@redhat.com> - 0.1.66-1cw- Rebase to a new upstream release 0.1.66 (RHBZ#2158410)
- Update RHEL7 STIG profile to V3R10 (RHBZ#2152657)
- Align file_permissions_sshd_private_key with DISA Benchmark (RHBZ#2123284)
- Fix remediation of audit watch rules (RHBZ#2123367)
- Fix check firewalld_sshd_port_enabled (RHBZ#2158410)
- Fix accepted control flags for pam_pwhistory (RHBZ#2158410)
- Unselect rule logind_session_timeout (RHBZ#2158410)
- Add support rainer scripts in rsyslog rules (RHBZ#2170038)
q_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)e_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)
g	_qWatson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)
''qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)Na=Jan Černý <jcerny@redhat.com> - 0.1.69-1d@- Rebase to the latest upstream release (RHBZ#2221694)
- Make IPv6 related rules applicable only in case IPv6 is actually enabled. (RHBZ#2210276)
- update ANSSI BP-028 profiles to be aligned with version 2.0 (RHBZ#2155793)
- Correct URL used to download CVE checks. (RHBZ#2223817)
_;Watson Sato <wsato@redhat.com> - 0.1.66-1cw- Rebase to a new upstream release 0.1.66 (RHBZ#2158410)
- Update RHEL7 STIG profile to V3R10 (RHBZ#2152657)
- Align file_permissions_sshd_private_key with DISA Benchmark (RHBZ#2123284)
- Fix remediation of audit watch rules (RHBZ#2123367)
- Fix check firewalld_sshd_port_enabled (RHBZ#2158410)
- Fix accepted control flags for pam_pwhistory (RHBZ#2158410)
- Unselect rule logind_session_timeout (RHBZ#2158410)
- Add support rainer scripts in rsyslog rules (RHBZ#2170038)
q_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)e_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)q
k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)
g_qWatson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)
Na=Jan Černý <jcerny@redhat.com> - 0.1.69-1d@- Rebase to the latest upstream release (RHBZ#2221694)
- Make IPv6 related rules applicable only in case IPv6 is actually enabled. (RHBZ#2210276)
- update ANSSI BP-028 profiles to be aligned with version 2.0 (RHBZ#2155793)
- Correct URL used to download CVE checks. (RHBZ#2223817)_;Watson Sato <wsato@redhat.com> - 0.1.66-1cw- Rebase to a new upstream release 0.1.66 (RHBZ#2158410)
- Update RHEL7 STIG profile to V3R10 (RHBZ#2152657)
- Align file_permissions_sshd_private_key with DISA Benchmark (RHBZ#2123284)
- Fix remediation of audit watch rules (RHBZ#2123367)
- Fix check firewalld_sshd_port_enabled (RHBZ#2158410)
- Fix accepted control flags for pam_pwhistory (RHBZ#2158410)
- Unselect rule logind_session_timeout (RHBZ#2158410)
- Add support rainer scripts in rsyslog rules (RHBZ#2170038)
h2Mhq_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)e_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)qk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)lomMarcus Burghardt <maburgha@redhat.com> - 0.1.72-2eN@- Unlist profiles no longer maintained in RHEL8.Io%Marcus Burghardt <maburgha@redhat.com> - 0.1.72-1e̫@- Rebase to a new upstream release 0.1.72 (RHEL-25251)
- Include filter to dracut files in audit_rules_privileged_commands rule (RHEL-11938)
g_qWatson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)
Na=Jan Černý <jcerny@redhat.com> - 0.1.69-1d@- Rebase to the latest upstream release (RHBZ#2221694)
- Make IPv6 related rules applicable only in case IPv6 is actually enabled. (RHBZ#2210276)
- update ANSSI BP-028 profiles to be aligned with version 2.0 (RHBZ#2155793)
- Correct URL used to download CVE checks. (RHBZ#2223817)_;Watson Sato <wsato@redhat.com> - 0.1.66-1cw- Rebase to a new upstream release 0.1.66 (RHBZ#2158410)
- Update RHEL7 STIG profile to V3R10 (RHBZ#2152657)
- Align file_permissions_sshd_private_key with DISA Benchmark (RHBZ#2123284)
- Fix remediation of audit watch rules (RHBZ#2123367)
- Fix check firewalld_sshd_port_enabled (RHBZ#2158410)
- Fix accepted control flags for pam_pwhistory (RHBZ#2158410)
- Unselect rule logind_session_timeout (RHBZ#2158410)
- Add support rainer scripts in rsyslog rules (RHBZ#2170038)
S2ES"m!Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-6`P@- Add kickstart files for RHEL 7 stig and stig_gui profiles (RHBZ#1958789)C!kGabriel Becker <ggasparb@redhat.com> - 0.1.54-5`[- Create subpackage to hold ansible playbooks per rule (RHBZ#1966589)
- Fix Bash remediation of dconf_gnome_login_retries (RHBZ#1967566) mIVojtech Polasek <vpolasek@redhat.com> - 0.1.54-4` @- Update RHEL 7 STIG profile to V3R3 (RHBZ#1958789)
- Update ANSSI High Profile (RHBZ#1955180)yaJan Černý <jcerny@redhat.com> - 0.1.73-1fL- Rebase scap-security-guide package to version 0.1.73 (RHEL-36739)lomMarcus Burghardt <maburgha@redhat.com> - 0.1.72-2eN@- Unlist profiles no longer maintained in RHEL8.Io%Marcus Burghardt <maburgha@redhat.com> - 0.1.72-1e̫@- Rebase to a new upstream release 0.1.72 (RHEL-25251)
- Include filter to dracut files in audit_rules_privileged_commands rule (RHEL-11938)
Gq,BG)kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)q(k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)q'k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)q&k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-3aqV@- Fix broken SELinux documentation links (RHBZ#1996678)%kGabriel Becker <ggasparb@redhat.com> - 0.1.57-2ap- Fix auditd_overflow_action configuration path for RHEL7 (RHBZ#1996678)8$aJan Černý <jcerny@redhat.com> - 0.1.57-1a^@- Rebase to the 0.1.57 upstream release
- Update RHEL7 DISA STIG profile to v3r4 (RHBZ#1996678)
- Split CIS profile (RHBZ#1953787)
#m)Vojtech Polasek <vpolasek@redhat.com> - 0.1.54-7`\- Generate HTML STIG reference tables also for stig_gui profile (RHBZ#1958789)
CF\/k	Gabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)q.k{	Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)q-k{	Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)q,k{	Gabriel Becker <ggasparb@redhat.com> - 0.1.57-3aqV@- Fix broken SELinux documentation links (RHBZ#1996678)+k	Gabriel Becker <ggasparb@redhat.com> - 0.1.57-2ap- Fix auditd_overflow_action configuration path for RHEL7 (RHBZ#1996678)8*a	Jan Černý <jcerny@redhat.com> - 0.1.57-1a^@- Rebase to the 0.1.57 upstream release
- Update RHEL7 DISA STIG profile to v3r4 (RHBZ#1996678)
- Split CIS profile (RHBZ#1953787)
55g2_q	Watson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)q1_	Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)e0_m	Watson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)
}g}q6k{
Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)q5k{
Gabriel Becker <ggasparb@redhat.com> - 0.1.57-3aqV@- Fix broken SELinux documentation links (RHBZ#1996678)4k
Gabriel Becker <ggasparb@redhat.com> - 0.1.57-2ap- Fix auditd_overflow_action configuration path for RHEL7 (RHBZ#1996678)3_;	Watson Sato <wsato@redhat.com> - 0.1.66-1cw- Rebase to a new upstream release 0.1.66 (RHBZ#2158410)
- Update RHEL7 STIG profile to V3R10 (RHBZ#2152657)
- Align file_permissions_sshd_private_key with DISA Benchmark (RHBZ#2123284)
- Fix remediation of audit watch rules (RHBZ#2123367)
- Fix check firewalld_sshd_port_enabled (RHBZ#2158410)
- Fix accepted control flags for pam_pwhistory (RHBZ#2158410)
- Unselect rule logind_session_timeout (RHBZ#2158410)
- Add support rainer scripts in rsyslog rules (RHBZ#2170038)
q:_
Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)e9_m
Watson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)8k
Gabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)q7k{
Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)
g;_q
Watson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)
''q>k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-4a(@- Update RHEL7 DISA STIG profile to v3r5 (RHBZ#1996678)N=a=
Jan Černý <jcerny@redhat.com> - 0.1.69-1d@- Rebase to the latest upstream release (RHBZ#2221694)
- Make IPv6 related rules applicable only in case IPv6 is actually enabled. (RHBZ#2210276)
- update ANSSI BP-028 profiles to be aligned with version 2.0 (RHBZ#2155793)
- Correct URL used to download CVE checks. (RHBZ#2223817)<_;
Watson Sato <wsato@redhat.com> - 0.1.66-1cw- Rebase to a new upstream release 0.1.66 (RHBZ#2158410)
- Update RHEL7 STIG profile to V3R10 (RHBZ#2152657)
- Align file_permissions_sshd_private_key with DISA Benchmark (RHBZ#2123284)
- Fix remediation of audit watch rules (RHBZ#2123367)
- Fix check firewalld_sshd_port_enabled (RHBZ#2158410)
- Fix accepted control flags for pam_pwhistory (RHBZ#2158410)
- Unselect rule logind_session_timeout (RHBZ#2158410)
- Add support rainer scripts in rsyslog rules (RHBZ#2170038)
qB_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)eA_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)@kGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)q?k{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)
gC_qWatson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)
NEa=Jan Černý <jcerny@redhat.com> - 0.1.69-1d@- Rebase to the latest upstream release (RHBZ#2221694)
- Make IPv6 related rules applicable only in case IPv6 is actually enabled. (RHBZ#2210276)
- update ANSSI BP-028 profiles to be aligned with version 2.0 (RHBZ#2155793)
- Correct URL used to download CVE checks. (RHBZ#2223817)D_;Watson Sato <wsato@redhat.com> - 0.1.66-1cw- Rebase to a new upstream release 0.1.66 (RHBZ#2158410)
- Update RHEL7 STIG profile to V3R10 (RHBZ#2152657)
- Align file_permissions_sshd_private_key with DISA Benchmark (RHBZ#2123284)
- Fix remediation of audit watch rules (RHBZ#2123367)
- Fix check firewalld_sshd_port_enabled (RHBZ#2158410)
- Fix accepted control flags for pam_pwhistory (RHBZ#2158410)
- Unselect rule logind_session_timeout (RHBZ#2158410)
- Add support rainer scripts in rsyslog rules (RHBZ#2170038)
h2MhqK_Watson Sato <wsato@redhat.com> - 0.1.57-8bq@- Remove warning how to override audit buffer (RHBZ#1993822)eJ_mWatson Sato <wsato@redhat.com> - 0.1.57-7bi0@- Add warning how to override audit buffer (RHBZ#1993822)
- Fix name of antivirus package in STIG profile (RHBZ#2066321)
- Update RHEL7 DISA STIG profile to v3r7 (RHBZ#2079217)IkGabriel Becker <ggasparb@redhat.com> - 0.1.57-6b- Fix bash remediation of sudo_require_reauthentication (RHBZ#2049532)qHk{Gabriel Becker <ggasparb@redhat.com> - 0.1.57-5b8- Update RHEL7 DISA STIG profile to v3r6 (RHBZ#2049532)lGomMarcus Burghardt <maburgha@redhat.com> - 0.1.72-2eN@- Unlist profiles no longer maintained in RHEL8.IFo%Marcus Burghardt <maburgha@redhat.com> - 0.1.72-1e̫@- Rebase to a new upstream release 0.1.72 (RHEL-25251)
- Include filter to dracut files in audit_rules_privileged_commands rule (RHEL-11938)
gL_qWatson Sato <wsato@redhat.com> - 0.1.63-1bL@- Update to the latest upstream release (RHBZ#2116359)
- Fix SSH Key permissions (RHBZ#2021258)
- Remove PCI-DSS Benchmark(RHBZ2038165)
- Updated source of CVE data feed(RHBZ#2028432)
- Improved alignment with DISA's RHEL7 STIG(RHBZ#1967950)
- Update RHEL7 STIG profile to v3r8 (RHBZ#2112939)
- Add warning how to override audit buffer (RHBZ#1993822)
- Fix smartcard_auth rule for systems installed without authconfig (RHBZ#2116359)
- Fix check of enable_fips_mode on s390x (RHBZ#2116359)
- Fix applicability of pam_pkcs11 and grub2 rules on s390x (RHBZ#2116359)
NNa=Jan Černý <jcerny@redhat.com> - 0.1.69-1d@- Rebase to the latest upstream release (RHBZ#2221694)
- Make IPv6 related rules applicable only in case IPv6 is actually enabled. (RHBZ#2210276)
- update ANSSI BP-028 profiles to be aligned with version 2.0 (RHBZ#2155793)
- Correct URL used to download CVE checks. (RHBZ#2223817)M_;Watson Sato <wsato@redhat.com> - 0.1.66-1cw- Rebase to a new upstream release 0.1.66 (RHBZ#2158410)
- Update RHEL7 STIG profile to V3R10 (RHBZ#2152657)
- Align file_permissions_sshd_private_key with DISA Benchmark (RHBZ#2123284)
- Fix remediation of audit watch rules (RHBZ#2123367)
- Fix check firewalld_sshd_port_enabled (RHBZ#2158410)
- Fix accepted control flags for pam_pwhistory (RHBZ#2158410)
- Unselect rule logind_session_timeout (RHBZ#2158410)
- Add support rainer scripts in rsyslog rules (RHBZ#2170038)
2Ey^TuI
Petr Hracek <phracek> - 4.1.0-0.20.20120314git3c2946U3@- Multiple packages are installing files under /etc/tmpfiles.d
- comply http://fedoraproject.org/wiki/Packaging:Guidelines#Tmpfiles.d
- Resolves: rhbz#1121958bS?
Daniel Mach <dmach@redhat.com> - 4.1.0-0.19.20120314git3c2946RU- Mass rebuild 2014-01-24bR?
Daniel Mach <dmach@redhat.com> - 4.1.0-0.18.20120314git3c2946Rk- Mass rebuild 2013-12-27yQaJan Černý <jcerny@redhat.com> - 0.1.73-1fL- Rebase scap-security-guide package to version 0.1.73 (RHEL-36739)lPomMarcus Burghardt <maburgha@redhat.com> - 0.1.72-2eN@- Unlist profiles no longer maintained in RHEL8.IOo%Marcus Burghardt <maburgha@redhat.com> - 0.1.72-1e̫@- Rebase to a new upstream release 0.1.72 (RHEL-25251)
- Include filter to dracut files in audit_rules_privileged_commands rule (RHEL-11938)
GYpGZ
Václav Doležal <vdolezal@redhat.com> - 4.1.0-0.26.2012314git3c2946^9\- Resolves: #1791793 - backport Bracketed Past Mode supportY
Josef Ridky <jridky@redhat.com> - 4.1.0-0.25.2012314git3c2946Y@- Resolves: #1423036 - fix issue with coloring when using caption paddingX
Petr Hracek <phracek@redhat.com> - 4.1.0-0.24.20120314git3c2946Wu	- Build has to be bigger then RHEL-7.2
- Related: #1196239.WQ
Petr Hracek <phracek@redhat.com> - 4.1.0-0.23.20120314git3c2946V@- screen does not log successful authentication messages with STIG GEN003660 
- Resolves: #1196239&VA
Petr Hracek <phracek@redhat.com> - 4.1.0-0.22.20120314git3c2946V@- cannot reattach to screen sessions (regression 'LoginName to long')
- Resolves: #1253697"U9
Petr Hracek <phracek@redhat.com> - 4.1.0-0.21.20120314git3c2946U- 'LoginName too long' with login name greater then 20 characters
- Resolves: #1119794
g<`iCLukas Vrabec <lvrabec@redhat.com> - 3.13.1-265]- Allow tmpreaper_t domain to getattr files labeled as mtrr_device_t
Resolves: rhbz#1765063 _iYLukas Vrabec <lvrabec@redhat.com> - 3.13.1-264]{A- Allow tmpwatch process labeled as tmpreaper_t domain to execute fuser command
Resolves: rhbz#1765063^iLukas Vrabec <lvrabec@redhat.com> - 3.13.1-263]{@- Update tmpreaper_t policy due to fuser command
Resolves: rhbz#1765063]i#Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-262]- Allow tmpreaper_t domain to read all domains state
Resolves: rhbz#1765063\iULukas Vrabec <lvrabec@redhat.com> - 3.13.1-261]c@- Update sudo_role_template() to allow caller domain to read syslog pid files
Resolves: rhbz#1651253h[K
Josef Ridky <jridky@redhat.com> - 4.1.0-0.27.2012314git3c2946`.V- fix CVE-2021-26937 (#1927063)
%i^%do!Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.1_V - Allow ssh-keygen create file in /var/lib/glusterd
Resolves: rhbz#1867995(ckgZdenek Pytela <zpytela@redhat.com> - 3.13.1-268^- Allow rhsmd read process state of all domains and kernel threads
Resolves: rhbz#1837461
- Allow ipa-adtrust-install restart sssd and dirsrv services
Resolves: rhbz#1820298
- Allow nagios_plugin_domain execute programs in bin directories
Resolves: rhbz#1824625
- selinux policy: add the right context for org.freeipa.server.trust-enable-agent
Related: rhbz#1820298bk#Zdenek Pytela <zpytela@redhat.com> - 3.13.1-267^x- Allow chronyd_t domain to exec shell
Resolves: rhbz#1775573
- Allow pmie daemon to send signal pcmd daemon
Resolves: rhbz#1770123
- Allow auditd poweroff or switch to single mode
Resolves: rhbz#1780332ai=Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-266]µ- Dontaudit tmpreaper_t getting attributes from sysctl_type files
Resolves: rhbz#1765063
ff iiYLukas Vrabec <lvrabec@redhat.com> - 3.13.1-264]{A- Allow tmpwatch process labeled as tmpreaper_t domain to execute fuser command
Resolves: rhbz#1765063hiLukas Vrabec <lvrabec@redhat.com> - 3.13.1-263]{@- Update tmpreaper_t policy due to fuser command
Resolves: rhbz#1765063gi#Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-262]- Allow tmpreaper_t domain to read all domains state
Resolves: rhbz#1765063fiULukas Vrabec <lvrabec@redhat.com> - 3.13.1-261]c@- Update sudo_role_template() to allow caller domain to read syslog pid files
Resolves: rhbz#1651253=eo
Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.2_- Allow certmonger add new entries in a generic certificates directory
Resolves: rhbz#1879496
- Allow slapd add new entries in ldap certificates directory
Resolves: rhbz#1879496
- Add miscfiles_add_entry_generic_cert_dirs() interface
Resolves: rhbz#1879496
f(mkgZdenek Pytela <zpytela@redhat.com> - 3.13.1-268^- Allow rhsmd read process state of all domains and kernel threads
Resolves: rhbz#1837461
- Allow ipa-adtrust-install restart sssd and dirsrv services
Resolves: rhbz#1820298
- Allow nagios_plugin_domain execute programs in bin directories
Resolves: rhbz#1824625
- selinux policy: add the right context for org.freeipa.server.trust-enable-agent
Related: rhbz#1820298lk#Zdenek Pytela <zpytela@redhat.com> - 3.13.1-267^x- Allow chronyd_t domain to exec shell
Resolves: rhbz#1775573
- Allow pmie daemon to send signal pcmd daemon
Resolves: rhbz#1770123
- Allow auditd poweroff or switch to single mode
Resolves: rhbz#1780332ki=Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-266]µ- Dontaudit tmpreaper_t getting attributes from sysctl_type files
Resolves: rhbz#1765063jiCLukas Vrabec <lvrabec@redhat.com> - 3.13.1-265]- Allow tmpreaper_t domain to getattr files labeled as mtrr_device_t
Resolves: rhbz#1765063
t2riLukas Vrabec <lvrabec@redhat.com> - 3.13.1-263]{@- Update tmpreaper_t policy due to fuser command
Resolves: rhbz#1765063qi#Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-262]- Allow tmpreaper_t domain to read all domains state
Resolves: rhbz#1765063piULukas Vrabec <lvrabec@redhat.com> - 3.13.1-261]c@- Update sudo_role_template() to allow caller domain to read syslog pid files
Resolves: rhbz#1651253=oo
Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.2_- Allow certmonger add new entries in a generic certificates directory
Resolves: rhbz#1879496
- Allow slapd add new entries in ldap certificates directory
Resolves: rhbz#1879496
- Add miscfiles_add_entry_generic_cert_dirs() interface
Resolves: rhbz#1879496no!Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.1_V - Allow ssh-keygen create file in /var/lib/glusterd
Resolves: rhbz#1867995

er+V:eD
607a56f5829235f4d97bd2c9135a74f23a25422c6eb8e64ad1a207404f8ce181D
13134e2ba51f0808b8c80f28f0f4a95f367f1ecef286a2a63576e93a76453a03D
1c844415d79cf4e5509e9b7ea70274ecad4b7e52cd6d0810f0df2dda40106afcD
e9cf08af12886825c6d69d18bf973a365efea2397256411d55daa08c561f2b04D
0cb96b04da1187dc59c06a37d73082671753740008c7d0f948693e3929f1b1a4D
44b24b7b0c7aa6f549efcc0d2d645424850f626003bf441a5cd992eaf86c7fd3D
f9a6ea022ebc4cdade8272e421cc47f8c54d66a2ad1efefff8e7486fa6802399D
406370b48821a02c6cd77913d2bbfb9b1c8a38d584ee789492dbdbda1796c482D
0884e384499ad64f6f25f663be6d416d9290f010f743e6eed115ceae93d81f8bD
7d33a7b50c3e3166f40ccd88712ae894914a62c9c8468f2b8145876e20f92bf9D
eda7c72438a02feaa87b0471bad982e64322ca96392f353cea98f6fac51c34ceD
9827101cf4d8dcc1d15f1fb432105b7bb92fc32f4674ff6e1b053110b96810c5D
48c7292215b233ddce0ec673e57163a6f867a0e6557f4d3d0ae79f6155792fd3
[*vk#Zdenek Pytela <zpytela@redhat.com> - 3.13.1-267^x- Allow chronyd_t domain to exec shell
Resolves: rhbz#1775573
- Allow pmie daemon to send signal pcmd daemon
Resolves: rhbz#1770123
- Allow auditd poweroff or switch to single mode
Resolves: rhbz#1780332ui=Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-266]µ- Dontaudit tmpreaper_t getting attributes from sysctl_type files
Resolves: rhbz#1765063tiCLukas Vrabec <lvrabec@redhat.com> - 3.13.1-265]- Allow tmpreaper_t domain to getattr files labeled as mtrr_device_t
Resolves: rhbz#1765063 siYLukas Vrabec <lvrabec@redhat.com> - 3.13.1-264]{A- Allow tmpwatch process labeled as tmpreaper_t domain to execute fuser command
Resolves: rhbz#1765063
S=yo
Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.2_- Allow certmonger add new entries in a generic certificates directory
Resolves: rhbz#1879496
- Allow slapd add new entries in ldap certificates directory
Resolves: rhbz#1879496
- Add miscfiles_add_entry_generic_cert_dirs() interface
Resolves: rhbz#1879496xo!Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.1_V - Allow ssh-keygen create file in /var/lib/glusterd
Resolves: rhbz#1867995(wkgZdenek Pytela <zpytela@redhat.com> - 3.13.1-268^- Allow rhsmd read process state of all domains and kernel threads
Resolves: rhbz#1837461
- Allow ipa-adtrust-install restart sssd and dirsrv services
Resolves: rhbz#1820298
- Allow nagios_plugin_domain execute programs in bin directories
Resolves: rhbz#1824625
- selinux policy: add the right context for org.freeipa.server.trust-enable-agent
Related: rhbz#1820298
w]Mwi=Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-266]µ- Dontaudit tmpreaper_t getting attributes from sysctl_type files
Resolves: rhbz#1765063~iCLukas Vrabec <lvrabec@redhat.com> - 3.13.1-265]- Allow tmpreaper_t domain to getattr files labeled as mtrr_device_t
Resolves: rhbz#1765063 }iYLukas Vrabec <lvrabec@redhat.com> - 3.13.1-264]{A- Allow tmpwatch process labeled as tmpreaper_t domain to execute fuser command
Resolves: rhbz#1765063|iLukas Vrabec <lvrabec@redhat.com> - 3.13.1-263]{@- Update tmpreaper_t policy due to fuser command
Resolves: rhbz#1765063{i#Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-262]- Allow tmpreaper_t domain to read all domains state
Resolves: rhbz#1765063ziULukas Vrabec <lvrabec@redhat.com> - 3.13.1-261]c@- Update sudo_role_template() to allow caller domain to read syslog pid files
Resolves: rhbz#1651253
Ho!Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.1_V - Allow ssh-keygen create file in /var/lib/glusterd
Resolves: rhbz#1867995(kgZdenek Pytela <zpytela@redhat.com> - 3.13.1-268^- Allow rhsmd read process state of all domains and kernel threads
Resolves: rhbz#1837461
- Allow ipa-adtrust-install restart sssd and dirsrv services
Resolves: rhbz#1820298
- Allow nagios_plugin_domain execute programs in bin directories
Resolves: rhbz#1824625
- selinux policy: add the right context for org.freeipa.server.trust-enable-agent
Related: rhbz#1820298k#Zdenek Pytela <zpytela@redhat.com> - 3.13.1-267^x- Allow chronyd_t domain to exec shell
Resolves: rhbz#1775573
- Allow pmie daemon to send signal pcmd daemon
Resolves: rhbz#1770123
- Allow auditd poweroff or switch to single mode
Resolves: rhbz#1780332
ff iYLukas Vrabec <lvrabec@redhat.com> - 3.13.1-264]{A- Allow tmpwatch process labeled as tmpreaper_t domain to execute fuser command
Resolves: rhbz#1765063iLukas Vrabec <lvrabec@redhat.com> - 3.13.1-263]{@- Update tmpreaper_t policy due to fuser command
Resolves: rhbz#1765063i#Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-262]- Allow tmpreaper_t domain to read all domains state
Resolves: rhbz#1765063iULukas Vrabec <lvrabec@redhat.com> - 3.13.1-261]c@- Update sudo_role_template() to allow caller domain to read syslog pid files
Resolves: rhbz#1651253=o
Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.2_- Allow certmonger add new entries in a generic certificates directory
Resolves: rhbz#1879496
- Allow slapd add new entries in ldap certificates directory
Resolves: rhbz#1879496
- Add miscfiles_add_entry_generic_cert_dirs() interface
Resolves: rhbz#1879496
f(kgZdenek Pytela <zpytela@redhat.com> - 3.13.1-268^- Allow rhsmd read process state of all domains and kernel threads
Resolves: rhbz#1837461
- Allow ipa-adtrust-install restart sssd and dirsrv services
Resolves: rhbz#1820298
- Allow nagios_plugin_domain execute programs in bin directories
Resolves: rhbz#1824625
- selinux policy: add the right context for org.freeipa.server.trust-enable-agent
Related: rhbz#1820298
k#Zdenek Pytela <zpytela@redhat.com> - 3.13.1-267^x- Allow chronyd_t domain to exec shell
Resolves: rhbz#1775573
- Allow pmie daemon to send signal pcmd daemon
Resolves: rhbz#1770123
- Allow auditd poweroff or switch to single mode
Resolves: rhbz#1780332	i=Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-266]µ- Dontaudit tmpreaper_t getting attributes from sysctl_type files
Resolves: rhbz#1765063iCLukas Vrabec <lvrabec@redhat.com> - 3.13.1-265]- Allow tmpreaper_t domain to getattr files labeled as mtrr_device_t
Resolves: rhbz#1765063
t2iLukas Vrabec <lvrabec@redhat.com> - 3.13.1-263]{@- Update tmpreaper_t policy due to fuser command
Resolves: rhbz#1765063i#Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-262]- Allow tmpreaper_t domain to read all domains state
Resolves: rhbz#1765063iULukas Vrabec <lvrabec@redhat.com> - 3.13.1-261]c@- Update sudo_role_template() to allow caller domain to read syslog pid files
Resolves: rhbz#1651253=
o
Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.2_- Allow certmonger add new entries in a generic certificates directory
Resolves: rhbz#1879496
- Allow slapd add new entries in ldap certificates directory
Resolves: rhbz#1879496
- Add miscfiles_add_entry_generic_cert_dirs() interface
Resolves: rhbz#1879496o!Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.1_V - Allow ssh-keygen create file in /var/lib/glusterd
Resolves: rhbz#1867995
[*k#Zdenek Pytela <zpytela@redhat.com> - 3.13.1-267^x- Allow chronyd_t domain to exec shell
Resolves: rhbz#1775573
- Allow pmie daemon to send signal pcmd daemon
Resolves: rhbz#1770123
- Allow auditd poweroff or switch to single mode
Resolves: rhbz#1780332i=Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-266]µ- Dontaudit tmpreaper_t getting attributes from sysctl_type files
Resolves: rhbz#1765063iCLukas Vrabec <lvrabec@redhat.com> - 3.13.1-265]- Allow tmpreaper_t domain to getattr files labeled as mtrr_device_t
Resolves: rhbz#1765063 iYLukas Vrabec <lvrabec@redhat.com> - 3.13.1-264]{A- Allow tmpwatch process labeled as tmpreaper_t domain to execute fuser command
Resolves: rhbz#1765063
S=o
Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.2_- Allow certmonger add new entries in a generic certificates directory
Resolves: rhbz#1879496
- Allow slapd add new entries in ldap certificates directory
Resolves: rhbz#1879496
- Add miscfiles_add_entry_generic_cert_dirs() interface
Resolves: rhbz#1879496o!Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.1_V - Allow ssh-keygen create file in /var/lib/glusterd
Resolves: rhbz#1867995(kgZdenek Pytela <zpytela@redhat.com> - 3.13.1-268^- Allow rhsmd read process state of all domains and kernel threads
Resolves: rhbz#1837461
- Allow ipa-adtrust-install restart sssd and dirsrv services
Resolves: rhbz#1820298
- Allow nagios_plugin_domain execute programs in bin directories
Resolves: rhbz#1824625
- selinux policy: add the right context for org.freeipa.server.trust-enable-agent
Related: rhbz#1820298
w]Mwi=Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-266]µ- Dontaudit tmpreaper_t getting attributes from sysctl_type files
Resolves: rhbz#1765063iCLukas Vrabec <lvrabec@redhat.com> - 3.13.1-265]- Allow tmpreaper_t domain to getattr files labeled as mtrr_device_t
Resolves: rhbz#1765063 iYLukas Vrabec <lvrabec@redhat.com> - 3.13.1-264]{A- Allow tmpwatch process labeled as tmpreaper_t domain to execute fuser command
Resolves: rhbz#1765063iLukas Vrabec <lvrabec@redhat.com> - 3.13.1-263]{@- Update tmpreaper_t policy due to fuser command
Resolves: rhbz#1765063i#Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-262]- Allow tmpreaper_t domain to read all domains state
Resolves: rhbz#1765063iULukas Vrabec <lvrabec@redhat.com> - 3.13.1-261]c@- Update sudo_role_template() to allow caller domain to read syslog pid files
Resolves: rhbz#1651253
H o!Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.1_V - Allow ssh-keygen create file in /var/lib/glusterd
Resolves: rhbz#1867995(kgZdenek Pytela <zpytela@redhat.com> - 3.13.1-268^- Allow rhsmd read process state of all domains and kernel threads
Resolves: rhbz#1837461
- Allow ipa-adtrust-install restart sssd and dirsrv services
Resolves: rhbz#1820298
- Allow nagios_plugin_domain execute programs in bin directories
Resolves: rhbz#1824625
- selinux policy: add the right context for org.freeipa.server.trust-enable-agent
Related: rhbz#1820298k#Zdenek Pytela <zpytela@redhat.com> - 3.13.1-267^x- Allow chronyd_t domain to exec shell
Resolves: rhbz#1775573
- Allow pmie daemon to send signal pcmd daemon
Resolves: rhbz#1770123
- Allow auditd poweroff or switch to single mode
Resolves: rhbz#1780332
P-2PO%s/Alexander Bokovoy <abokovoy@redhat.com> - 0.56.0-10\e- Fixed: #1435663
$q%Alexander Bokovoy <abokovoy@redhat.com> - 0.56.0-9\- Fixed: #1502429
- Update upstream reference to http://pagure.io/slapi-nis/v#q}Alexander Bokovoy <abokovoy@redhat.com> - 0.56.0-8Z*~- Fixed: #1473572
- Changes of ID overrides now force clearing of affected SSSD cache entries on IPA master
- Related: #1473577
- Synchronize timeout-enabled code with ipa-extdom-extop"q)Alexander Bokovoy <abokovoy@redhat.com> - 0.56.0-7ZN- Related: #1473577
- Force at least SSSD 1.16.0-3 for timeout-enabled NSS API=!o
Zdenek Pytela <zpytela@redhat.com> - 3.13.1-268.2_- Allow certmonger add new entries in a generic certificates directory
Resolves: rhbz#1879496
- Allow slapd add new entries in ldap certificates directory
Resolves: rhbz#1879496
- Add miscfiles_add_entry_generic_cert_dirs() interface
Resolves: rhbz#1879496
>l{>z*qAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-2^- Initialize map lock in NIS plugin
- Resolves: rhbz#1832190:)qAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-1^- Upstream release 0.56.5
- Resolves: rhbz#1820124 When sync-repl is enabled, slapi-nis can deadlock during retrochanglog trimming
- Resolves: rhbz#1820122 ERR - schemacompat - map rdlock: old way MAP_MONITOR_DISABLED
- Resolves: rhbz#1819018 ipa slapi-nis stack traces review request for LDAP server deadlock
- Resolves: rhbz#1830894 Memory leak during search of idview overrides(sAlexander Bokovoy <abokovoy@redhat.com> - 0.56.0-13]V- Fixed: #1725845
  ns-slapd is crashing intermittently
- Compiler fixesa'sSAlexander Bokovoy <abokovoy@redhat.com> - 0.56.0-12\@- Related: #1435663
  Covscan fixes&s-Alexander Bokovoy <abokovoy@redhat.com> - 0.56.0-11\e- Fixed: #1435663
  Additional set of fixes for conflicts over cn=config updates
{0sAlexander Bokovoy <abokovoy@redhat.com> - 0.56.0-13]V- Fixed: #1725845
  ns-slapd is crashing intermittently
- Compiler fixesa/sSAlexander Bokovoy <abokovoy@redhat.com> - 0.56.0-12\@- Related: #1435663
  Covscan fixes.s-Alexander Bokovoy <abokovoy@redhat.com> - 0.56.0-11\e- Fixed: #1435663
  Additional set of fixes for conflicts over cn=config updatesO-s/Alexander Bokovoy <abokovoy@redhat.com> - 0.56.0-10\e- Fixed: #1435663
,q%Alexander Bokovoy <abokovoy@redhat.com> - 0.56.0-9\- Fixed: #1502429
- Update upstream reference to http://pagure.io/slapi-nis/+qAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-3`- Fix memory leaks in ID views processing
- Resolves: rhbz#1866113
A>,4qiAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-4`m- CVE 2021-3480:  slapi-nis: NULL dereference (DoS) with specially crafted Binding DN
- Resolves: rhbz#19429373qAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-3`- Fix memory leaks in ID views processing
- Resolves: rhbz#1866113z2qAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-2^- Initialize map lock in NIS plugin
- Resolves: rhbz#1832190:1qAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-1^- Upstream release 0.56.5
- Resolves: rhbz#1820124 When sync-repl is enabled, slapi-nis can deadlock during retrochanglog trimming
- Resolves: rhbz#1820122 ERR - schemacompat - map rdlock: old way MAP_MONITOR_DISABLED
- Resolves: rhbz#1819018 ipa slapi-nis stack traces review request for LDAP server deadlock
- Resolves: rhbz#1830894 Memory leak during search of idview overrides
8sAlexander Bokovoy <abokovoy@redhat.com> - 0.56.0-13]V- Fixed: #1725845
  ns-slapd is crashing intermittently
- Compiler fixesa7sSAlexander Bokovoy <abokovoy@redhat.com> - 0.56.0-12\@- Related: #1435663
  Covscan fixes6s-Alexander Bokovoy <abokovoy@redhat.com> - 0.56.0-11\e- Fixed: #1435663
  Additional set of fixes for conflicts over cn=config updatesk5qgAlexander Bokovoy <abokovoy@redhat.com> - 0.60.0-1c*- upstream release 0.60.0
- Change license from GPLv2 to GPLv3+ to follow 389-ds licensing
- Resolves: rhbz#1978748
  Release adds following fixes:
  - Fix ID views integration
  - Fix base scope lookups
  - Bump NIS max dgram size to 8KB by default instead of 1KB
  - Allow to rebuild the compat tree
A>,<qiAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-4`m- CVE 2021-3480:  slapi-nis: NULL dereference (DoS) with specially crafted Binding DN
- Resolves: rhbz#1942937;qAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-3`- Fix memory leaks in ID views processing
- Resolves: rhbz#1866113z:qAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-2^- Initialize map lock in NIS plugin
- Resolves: rhbz#1832190:9qAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-1^- Upstream release 0.56.5
- Resolves: rhbz#1820124 When sync-repl is enabled, slapi-nis can deadlock during retrochanglog trimming
- Resolves: rhbz#1820122 ERR - schemacompat - map rdlock: old way MAP_MONITOR_DISABLED
- Resolves: rhbz#1819018 ipa slapi-nis stack traces review request for LDAP server deadlock
- Resolves: rhbz#1830894 Memory leak during search of idview overrides
xAsAlexander Bokovoy <abokovoy@redhat.com> - 0.56.0-13]V- Fixed: #1725845
  ns-slapd is crashing intermittently
- Compiler fixesa@sSAlexander Bokovoy <abokovoy@redhat.com> - 0.56.0-12\@- Related: #1435663
  Covscan fixes	?q#Alexander Bokovoy <abokovoy@redhat.com> - 0.60.0-3dJc- Also handle base searches within the compat tree
- Resolves: rhbz#2168893>qAlexander Bokovoy <abokovoy@redhat.com> - 0.60.0-2d- Fix base DN searches outside the compat tree
- Resolves: rhbz#2168893k=qgAlexander Bokovoy <abokovoy@redhat.com> - 0.60.0-1c*- upstream release 0.60.0
- Change license from GPLv2 to GPLv3+ to follow 389-ds licensing
- Resolves: rhbz#1978748
  Release adds following fixes:
  - Fix ID views integration
  - Fix base scope lookups
  - Bump NIS max dgram size to 8KB by default instead of 1KB
  - Allow to rebuild the compat tree
A>,EqiAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-4`m- CVE 2021-3480:  slapi-nis: NULL dereference (DoS) with specially crafted Binding DN
- Resolves: rhbz#1942937DqAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-3`- Fix memory leaks in ID views processing
- Resolves: rhbz#1866113zCqAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-2^- Initialize map lock in NIS plugin
- Resolves: rhbz#1832190:BqAlexander Bokovoy <abokovoy@redhat.com> - 0.56.5-1^- Upstream release 0.56.5
- Resolves: rhbz#1820124 When sync-repl is enabled, slapi-nis can deadlock during retrochanglog trimming
- Resolves: rhbz#1820122 ERR - schemacompat - map rdlock: old way MAP_MONITOR_DISABLED
- Resolves: rhbz#1819018 ipa slapi-nis stack traces review request for LDAP server deadlock
- Resolves: rhbz#1830894 Memory leak during search of idview overrides
:x:pJ[Jan Jansky <jjansky@redhat.com> = 3.8-4]A- [man] describe --allow-system-changes
  Resolves: bz1630028EIqAlexander Bokovoy <abokovoy@redhat.com> - 0.60.0-4e7- Ignore updates from non-tracked subtrees during modify/modrdn/update
  to avoid deadlocks with retro changelog
- Resolves: RHEL-11869	Hq#Alexander Bokovoy <abokovoy@redhat.com> - 0.60.0-3dJc- Also handle base searches within the compat tree
- Resolves: rhbz#2168893GqAlexander Bokovoy <abokovoy@redhat.com> - 0.60.0-2d- Fix base DN searches outside the compat tree
- Resolves: rhbz#2168893kFqgAlexander Bokovoy <abokovoy@redhat.com> - 0.60.0-1c*- upstream release 0.60.0
- Change license from GPLv2 to GPLv3+ to follow 389-ds licensing
- Resolves: rhbz#1978748
  Release adds following fixes:
  - Fix ID views integration
  - Fix base scope lookups
  - Bump NIS max dgram size to 8KB by default instead of 1KB
  - Allow to rebuild the compat tree
xP[Jan Jansky <jjansky@redhat.com> = 3.9-2^V@- [rabbitmq] emulate TTY via timeout foreground
  Resolves: bz1840571PO[IJan Jansky <jjansky@redhat.com> = 3.9-1^@- New upstream release sos-3.9!N[iJan Jansky <jjansky@redhat.com> = 3.8-8^S- Added Obsolete for leapp-repository-sos-plugin to solve
  conflicts during install/upgrade/downgrade of RPM.sM[
Jan Jansky <jjansky@redhat.com> = 3.8-7^M#@- [networking] options to limit namespaces
  Resolves: bz1683904Lc)Pavel Moravec <pmoravec@redhat.com> = 3.8-6]@- [foreman] cast dynflow_execution_plans.uuid as varchar
  Resolves: bz1781148qK[	Jan Jansky <jjansky@redhat.com> = 3.8-5]- [Plugin, kernel] interim sysroot fixes
  Resolves: bz1767445
BXBAU_%Jan Jansky <jjansky@redhat.com> = 3.9-5.3`Gc@- [candlepin/foreman] psql with --no-password
  Resolves: bz1932772
- [foreman] proxy_password scrub in installer logs
  Resolves: bz1785813T_'Jan Jansky <jjansky@redhat.com> = 3.9-5.2`	l- [networking] 'ethtool -e <device>' conditionally only
  Resolves: bz1917074WSs?CentOS Sources <bugs@centos.org> - 3.9-4.el7.centos_s!- Roll in CentOS BrandingjR[}Jan Jansky <jjansky@redhat.com> = 3.9-4_A@- [gluster] remove only dump files
  Resolves: bz1856417#Q[mJan Jansky <jjansky@redhat.com> = 3.9-3_c- [gluster] fix gluster volume splitlines iteration
  Resolves: bz1843520
- [block] proper parsing of luks partition on self device
  Resolves: bz1850544
- [pci] Update gating for lspci commands
  Resolves: bz1853701
- [foreman] collects stats of some tables from foreman DB
  Resolves: bz1853235
- [logs] collect also non-persistent journal logs
  Resolves: bz1850925
gDgiY_wJan Jansky <jjansky@redhat.com> = 3.9-5.7au- [migrationresults] new plugin
  Resolves: bz1959781lX_}Jan Jansky <jjansky@redhat.com> = 3.9-5.6`- [pulpcore] add plugin for pulp-3
  Resolves: bz1956672W_3Jan Jansky <jjansky@redhat.com> = 3.9-5.5`P@- [sssd] Add individual SSSD log files
  Resolves: bz1938932
- [sssd] sssd plugin when sssd-common
  Resolves: bz1946641
- [foreman] fix unmatched group in scrubbing installer logs
  Resolves: bz1956817
- [foreman] Sizelimit foreman-maintain and installer logs
  Resolves: bz1964000
- [pulpcore] add plugin for pulp-3
  Resolves: bz1956672*V_wJan Jansky <jjansky@redhat.com> = 3.9-5.4`S@- [candlepin/foreman] psql with --no-password
  Resolves: bz1932772
- [pacemaker] password scrub fix
  Resolves: bz1903144
- [filesys] never collect panfs
  Resolves: bz1886784
- [openstack_ceilometer] backend_url protected
  Resolves: bz1892692
'rzV'*__wJan Jansky <jjansky@redhat.com> = 3.9-5.4`S@- [candlepin/foreman] psql with --no-password
  Resolves: bz1932772
- [pacemaker] password scrub fix
  Resolves: bz1903144
- [filesys] never collect panfs
  Resolves: bz1886784
- [openstack_ceilometer] backend_url protected
  Resolves: bz1892692A^_%Jan Jansky <jjansky@redhat.com> = 3.9-5.3`Gc@- [candlepin/foreman] psql with --no-password
  Resolves: bz1932772
- [foreman] proxy_password scrub in installer logs
  Resolves: bz1785813Z]y?CentOS Sources <bugs@centos.org> - 3.9-5.el7.centos.10b@- Roll in CentOS Branding\k!Barbora Vassova <bvassova@redhat.com = 3.9-5.10a+@- [report] Handle exceptionally old pexpect versions
  Resolves: bz2011337j[ioBarbora Vassova <bvassova@redhat.com = 3.9-5.9aL- [Red Hat] SFTP api change
  Resolves: bz2011337	Ze/Pavel Moravec <pmoravec@redhat.com = 3.9-5.8ap- [Red Hat] Update policy to use SFTP instead of legacy FTP
  Resolves: bz2011337
sjdioBarbora Vassova <bvassova@redhat.com = 3.9-5.9aL- [Red Hat] SFTP api change
  Resolves: bz2011337	ce/Pavel Moravec <pmoravec@redhat.com = 3.9-5.8ap- [Red Hat] Update policy to use SFTP instead of legacy FTP
  Resolves: bz2011337ib_wJan Jansky <jjansky@redhat.com> = 3.9-5.7au- [migrationresults] new plugin
  Resolves: bz1959781la_}Jan Jansky <jjansky@redhat.com> = 3.9-5.6`- [pulpcore] add plugin for pulp-3
  Resolves: bz1956672`_3Jan Jansky <jjansky@redhat.com> = 3.9-5.5`P@- [sssd] Add individual SSSD log files
  Resolves: bz1938932
- [sssd] sssd plugin when sssd-common
  Resolves: bz1946641
- [foreman] fix unmatched group in scrubbing installer logs
  Resolves: bz1956817
- [foreman] Sizelimit foreman-maintain and installer logs
  Resolves: bz1964000
- [pulpcore] add plugin for pulp-3
  Resolves: bz1956672
v*i_wJan Jansky <jjansky@redhat.com> = 3.9-5.4`S@- [candlepin/foreman] psql with --no-password
  Resolves: bz1932772
- [pacemaker] password scrub fix
  Resolves: bz1903144
- [filesys] never collect panfs
  Resolves: bz1886784
- [openstack_ceilometer] backend_url protected
  Resolves: bz1892692Ah_%Jan Jansky <jjansky@redhat.com> = 3.9-5.3`Gc@- [candlepin/foreman] psql with --no-password
  Resolves: bz1932772
- [foreman] proxy_password scrub in installer logs
  Resolves: bz1785813Zgy?CentOS Sources <bugs@centos.org> - 3.9-5.el7.centos.11b@- Roll in CentOS Brandingfm5Barbora Vassova <bvassova@redhat.com> = 3.9-5.11bM- [foreman] Use psql-msgpack-decode wrapper for dynflow >= 1.6
  Resolves: bz2043103ek!Barbora Vassova <bvassova@redhat.com = 3.9-5.10a+@- [report] Handle exceptionally old pexpect versions
  Resolves: bz2011337
sjnioBarbora Vassova <bvassova@redhat.com = 3.9-5.9aL- [Red Hat] SFTP api change
  Resolves: bz2011337	me/Pavel Moravec <pmoravec@redhat.com = 3.9-5.8ap- [Red Hat] Update policy to use SFTP instead of legacy FTP
  Resolves: bz2011337il_wJan Jansky <jjansky@redhat.com> = 3.9-5.7au- [migrationresults] new plugin
  Resolves: bz1959781lk_}Jan Jansky <jjansky@redhat.com> = 3.9-5.6`- [pulpcore] add plugin for pulp-3
  Resolves: bz1956672j_3Jan Jansky <jjansky@redhat.com> = 3.9-5.5`P@- [sssd] Add individual SSSD log files
  Resolves: bz1938932
- [sssd] sssd plugin when sssd-common
  Resolves: bz1946641
- [foreman] fix unmatched group in scrubbing installer logs
  Resolves: bz1956817
- [foreman] Sizelimit foreman-maintain and installer logs
  Resolves: bz1964000
- [pulpcore] add plugin for pulp-3
  Resolves: bz1956672
gv
g!s[iJan Jansky <jjansky@redhat.com> = 3.8-8^S- Added Obsolete for leapp-repository-sos-plugin to solve
  conflicts during install/upgrade/downgrade of RPM.sr[
Jan Jansky <jjansky@redhat.com> = 3.8-7^M#@- [networking] options to limit namespaces
  Resolves: bz1683904XqmEBarbora Vassova <bvassova@redhat.com> = 3.9-5.12ed@- [redhat] Change authentication method for RHEL
  Resolves: RHEL-21176
- [rpm] Capture the output of 'rpm --showrc'
  Resolves: RHEL-2357
- [candlepin] collect information about SCA
  Resolves: RHEL-22263
- [foreman] scrub admin init password in installer logs
  Resolves: RHEL-22264pm5Barbora Vassova <bvassova@redhat.com> = 3.9-5.11bM- [foreman] Use psql-msgpack-decode wrapper for dynflow >= 1.6
  Resolves: bz2043103ok!Barbora Vassova <bvassova@redhat.com = 3.9-5.10a+@- [report] Handle exceptionally old pexpect versions
  Resolves: bz2011337

er+V:eD)
45af49fe978be47c6b7dc1d84f54b54ddf45d39e67431887ec68d47802feb0ccD(
dc97c23964c8ec5ec9543fb0bb7c476a1deca4202929a65f43265b1ae8ccf0adD'
0913430ac82b85ff2505f1428fd1ee1c2cbdf9c4b58cc447ab469fccea954369D&
eabc52b09196e354f58fd80ffdc7a2ac038da61c3a8d783f6064cc3031bc9fccD%
27e3e327ceafc04ea5e9faed37c22dbb650fa79b11eebea73713df7e611dfcb8D$
60c42c4261b381295acac9b8bad53e4d11b07aa44a6886d268acdf68415fb2e3D#
facd76c3134bc61acc238804781421a124627264ef3476cf551ab5fdf5edf584D"
7614360f2f41c4a9acb375c65afe79453a28906b14eb8088a9a89a96d3374218D!
9980a8413abfc3a1135efb5094b967176ab339e1f12d5eca6b6bab8d981b0391D 
fefe08dca680fa571c295cf0d51d266aa3aa3a357dc1bdb87dd804e1fe5179fdD
f53f33bb25947de42ac961faa1b3edbf1207b3e8028e8c283c139b943b66ed73D
3cacb30cdf9cf8886bd3adabfb82541a6334ec3b33f75528e73c4d209bb76917D
96c48318b9e9154def4e98ffc6c16ef9c9663b6dd5fd0a35de6a541ab73ea684
0jw[}Jan Jansky <jjansky@redhat.com> = 3.9-4_A@- [gluster] remove only dump files
  Resolves: bz1856417#v[mJan Jansky <jjansky@redhat.com> = 3.9-3_c- [gluster] fix gluster volume splitlines iteration
  Resolves: bz1843520
- [block] proper parsing of luks partition on self device
  Resolves: bz1850544
- [pci] Update gating for lspci commands
  Resolves: bz1853701
- [foreman] collects stats of some tables from foreman DB
  Resolves: bz1853235
- [logs] collect also non-persistent journal logs
  Resolves: bz1850925xu[Jan Jansky <jjansky@redhat.com> = 3.9-2^V@- [rabbitmq] emulate TTY via timeout foreground
  Resolves: bz1840571Pt[IJan Jansky <jjansky@redhat.com> = 3.9-1^@- New upstream release sos-3.9
0:]0x}[Jan Jansky <jjansky@redhat.com> = 3.9-2^V@- [rabbitmq] emulate TTY via timeout foreground
  Resolves: bz1840571P|[IJan Jansky <jjansky@redhat.com> = 3.9-1^@- New upstream release sos-3.9Y{w?CentOS Sources <bugs@centos.org> - 3.9-5.el7.centos.2`>- Roll in CentOS Brandingz_'Jan Jansky <jjansky@redhat.com> = 3.9-5.2`	l- [networking] 'ethtool -e <device>' conditionally only
  Resolves: bz1917074Ry_IJan Jansky <jjansky@redhat.com> = 3.9-5.1_@- Adjusting .1 zstream versionAx[)Jan Jansky <jjansky@redhat.com> = 3.9-5_- [gluster] remove generated state files
  Resolves: bz1857697
- [kubernetes] ignore blank+empty lines
  Resolves: bz1859885
- [networking] remove 'ethtool -e' option for bnx2x NICs
  Resolves: bz1870379
- [auditd] collect /etc/audisp
  Resolves: bz1871207
- [policy] Fix several failure conditions with upload
  Resolves: bz1886432
- [postgresql] reorganize postgres from SCL
  Resolves: bz1897903
$X$A[)Jan Jansky <jjansky@redhat.com> = 3.9-5_- [gluster] remove generated state files
  Resolves: bz1857697
- [kubernetes] ignore blank+empty lines
  Resolves: bz1859885
- [networking] remove 'ethtool -e' option for bnx2x NICs
  Resolves: bz1870379
- [auditd] collect /etc/audisp
  Resolves: bz1871207
- [policy] Fix several failure conditions with upload
  Resolves: bz1886432
- [postgresql] reorganize postgres from SCL
  Resolves: bz1897903j[}Jan Jansky <jjansky@redhat.com> = 3.9-4_A@- [gluster] remove only dump files
  Resolves: bz1856417#~[mJan Jansky <jjansky@redhat.com> = 3.9-3_c- [gluster] fix gluster volume splitlines iteration
  Resolves: bz1843520
- [block] proper parsing of luks partition on self device
  Resolves: bz1850544
- [pci] Update gating for lspci commands
  Resolves: bz1853701
- [foreman] collects stats of some tables from foreman DB
  Resolves: bz1853235
- [logs] collect also non-persistent journal logs
  Resolves: bz1850925
c#].cj[}Jan Jansky <jjansky@redhat.com> = 3.9-4_A@- [gluster] remove only dump files
  Resolves: bz1856417Yw?CentOS Sources <bugs@centos.org> - 3.9-5.el7.centos.4`- Roll in CentOS Branding*_wJan Jansky <jjansky@redhat.com> = 3.9-5.4`S@- [candlepin/foreman] psql with --no-password
  Resolves: bz1932772
- [pacemaker] password scrub fix
  Resolves: bz1903144
- [filesys] never collect panfs
  Resolves: bz1886784
- [openstack_ceilometer] backend_url protected
  Resolves: bz1892692A_%Jan Jansky <jjansky@redhat.com> = 3.9-5.3`Gc@- [candlepin/foreman] psql with --no-password
  Resolves: bz1932772
- [foreman] proxy_password scrub in installer logs
  Resolves: bz1785813_'Jan Jansky <jjansky@redhat.com> = 3.9-5.2`	l- [networking] 'ethtool -e <device>' conditionally only
  Resolves: bz1917074R_IJan Jansky <jjansky@redhat.com> = 3.9-5.1_@- Adjusting .1 zstream version
:]A
_%Jan Jansky <jjansky@redhat.com> = 3.9-5.3`Gc@- [candlepin/foreman] psql with --no-password
  Resolves: bz1932772
- [foreman] proxy_password scrub in installer logs
  Resolves: bz1785813	_'Jan Jansky <jjansky@redhat.com> = 3.9-5.2`	l- [networking] 'ethtool -e <device>' conditionally only
  Resolves: bz1917074R_IJan Jansky <jjansky@redhat.com> = 3.9-5.1_@- Adjusting .1 zstream versionA[)Jan Jansky <jjansky@redhat.com> = 3.9-5_- [gluster] remove generated state files
  Resolves: bz1857697
- [kubernetes] ignore blank+empty lines
  Resolves: bz1859885
- [networking] remove 'ethtool -e' option for bnx2x NICs
  Resolves: bz1870379
- [auditd] collect /etc/audisp
  Resolves: bz1871207
- [policy] Fix several failure conditions with upload
  Resolves: bz1886432
- [postgresql] reorganize postgres from SCL
  Resolves: bz1897903
gDgi_wJan Jansky <jjansky@redhat.com> = 3.9-5.7au- [migrationresults] new plugin
  Resolves: bz1959781l
_}Jan Jansky <jjansky@redhat.com> = 3.9-5.6`- [pulpcore] add plugin for pulp-3
  Resolves: bz1956672_3Jan Jansky <jjansky@redhat.com> = 3.9-5.5`P@- [sssd] Add individual SSSD log files
  Resolves: bz1938932
- [sssd] sssd plugin when sssd-common
  Resolves: bz1946641
- [foreman] fix unmatched group in scrubbing installer logs
  Resolves: bz1956817
- [foreman] Sizelimit foreman-maintain and installer logs
  Resolves: bz1964000
- [pulpcore] add plugin for pulp-3
  Resolves: bz1956672*_wJan Jansky <jjansky@redhat.com> = 3.9-5.4`S@- [candlepin/foreman] psql with --no-password
  Resolves: bz1932772
- [pacemaker] password scrub fix
  Resolves: bz1903144
- [filesys] never collect panfs
  Resolves: bz1886784
- [openstack_ceilometer] backend_url protected
  Resolves: bz1892692
g_s Jan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage _c Jan Friesse <jfriesse@redhat.com> 2.4.3-5\|- Resolves: rhbz#1376819
- Resolves: rhbz#1634710

- configure: add --with-initconfigdir option (rhbz#1376819)
- merge upstream commit c0d8af0c7b247df16a90850b0edab4f978cb8192 (rhbz#1376819)
- Use RuntimeDirectory instead of tmpfiles.d (rhbz#1376819)
- merge upstream commit fde7fa0c6408709ccdd090aa9064e6a78232498a (rhbz#1376819)
- totemcrypto: Fix importing of the private key (rhbz#1634710)
- merge upstream commit 3f3e6b62719a263cb221c19a06d9a2c570234caa (rhbz#1634710)
- qnetd: Check existence of NSS DB dir before fork (rhbz#1376819)
- merge upstream commit eac28dffdf7f060f41f2b2e95bb0f4c6c033425d (rhbz#1376819)Yw?CentOS Sources <bugs@centos.org> - 3.9-5.el7.centos.7a.- Roll in CentOS Branding
c`cjcu Jan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/c} Jan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definitionV_O Jan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)_Y Jan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5
ttj_w Jan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)_S Jan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)
\"B7\V_O!Jan Friesse <jfriesse@redhat.com> 2.4.5-2]@1A- Resolves: rhbz#1656492

- totem: Increase ring_id seq after load (rhbz#1656492)
- merge upstream commit 1061804d09565363aba73e369faf310a7d2c4d86 (rhbz#1656492)_Y!Jan Friesse <jfriesse@redhat.com> 2.4.5-1]@1@- Resolves: rhbz#1732039
- Resolves: rhbz#1153818
- Resolves: rhbz#1647120

- Rebase to Corosync 2.4.5g_s!Jan Friesse <jfriesse@redhat.com> 2.4.3-6\|- Resolves: rhbz#1542703

- Add spausedd subpackage[cU Jan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)Y_U Jan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)
L_S!Jan Friesse <jfriesse@redhat.com> 2.4.5-5^y@- Resolves: rhbz#1679792
- Resolves: rhbz#1780134

- votequorum: Ignore the icmap_get_* return value (rhbz#1780134)
- merge upstream commit 8ad3c6bbb4556332c5a6b7fecdab73310c045b24 (rhbz#1780134)
- votequorum: Reflect runtime change of 2Node to WFA (rhbz#1780134)
- merge upstream commit bfbed8c320b0c0c5d3db48630f3de77e5fd62b75 (rhbz#1780134)
- votequorum: set wfa status only on startup (rhbz#1679792)
- merge upstream commit 6894792d76b1e8932bc822bb040933ae17e1a0c7 (rhbz#1679792)jcu!Jan Friesse <jfriesse@redhat.com> - 2.4.5-4]J@- Related: rhbz#1737884

- Enhance spausedd makefile/c}!Jan Friesse <jfriesse@redhat.com> - 2.4.5-3]Ik- Resolves: rhbz#1737884
- Resolves: rhbz#1737887

- Do not set exec permission for service file
- Fix CFLAGS definition
::#cG!Jan Friesse <jfriesse@redhat.com> 2.4.5-7.2av@- Resolves: rhbz#2001969

- totem: Add cancel_hold_on_retransmit config option (rhbz#2001969)["cU!Jan Friesse <jfriesse@redhat.com> 2.4.5-7.1`- Resolves: rhbz#1896311
- Resolves: rhbz#1897087

- spausedd: Fix log_perror (rhbz#1896311)
- spausedd: Add ability to move process into root cgroup (rhbz#1897087)Y!_U!Jan Friesse <jfriesse@redhat.com> 2.4.5-7^3- Related: rhbz#1835885

- main: Make schedmiss in cmap and log equal (rhbz#1835885)
- merge upstream commit 44c1c8ea31f981bdd7856d4eb8f4ac49f95a85e3 (rhbz#1835885)j _w!Jan Friesse <jfriesse@redhat.com> 2.4.5-6^ϧ- Resolves: rhbz#1835885

- stats: Add basic schedule-miss stats to needle (rhbz#1835885)
- merge upstream commit 274fda334a84253222e01b779349784ec552921b (rhbz#1835885)
- main: Add schedmiss timestamp into message (rhbz#1835885)
- merge upstream commit 3166a87749fa4817d90ed335f3c5843fc38e7304 (rhbz#1835885)
,^t+e"Victor Toso <victortoso@redhat.com> - 0.35-4\- Fix bad channel-reset on usbredir
  Resolves: rhbz#1625550{*g"Frediano Ziglio <fziglio@redhat.com> - 0.35-3[- Fix insufficient encoding checks for LZ
  Resolves: rhbz#1598652v)g"Frediano Ziglio <fziglio@redhat.com> - 0.35-2[m~@- Fix flexible array buffer overflow
  Resolves: rhbz#1596008`(e_"Victor Toso <victortoso@redhat.com> - 0.35-1[d@- Rebase to 0.35
  Resolves: rhbz#1562126j'gq"Frediano Ziglio <fziglio@redhat.com> - 0.34-3Z;@- Fix stride misalignment
  Resolves: rhbz#1508847\&eW"Victor Toso <victortoso@redhat.com> - 0.34-2Z
- Enable lz4
  Resolves: rhbz#1460198`%e_"Victor Toso <victortoso@redhat.com> - 0.34-1Y@- Rebase to 0.34
  Resolves: rhbz#1472730l$kq"Jonathon Jongsma <jjongsma@redhat.com> - 0.33-7Yh@- build with opus support
  Resolves: rhbz#1456849
CSS!Cv3g#Frediano Ziglio <fziglio@redhat.com> - 0.35-2[m~@- Fix flexible array buffer overflow
  Resolves: rhbz#1596008`2e_#Victor Toso <victortoso@redhat.com> - 0.35-1[d@- Rebase to 0.35
  Resolves: rhbz#1562126j1gq#Frediano Ziglio <fziglio@redhat.com> - 0.34-3Z;@- Fix stride misalignment
  Resolves: rhbz#1508847\0eW#Victor Toso <victortoso@redhat.com> - 0.34-2Z
- Enable lz4
  Resolves: rhbz#1460198`/e_#Victor Toso <victortoso@redhat.com> - 0.34-1Y@- Rebase to 0.34
  Resolves: rhbz#1472730l.kq#Jonathon Jongsma <jjongsma@redhat.com> - 0.33-7Yh@- build with opus support
  Resolves: rhbz#1456849-k-"Frediano Ziglio <fziglio@redhat.com> - 0.35-5.1_O@- Fix multiple buffer overflows in QUIC decoding code
  Resolves: CVE-2020-14355(,em"Victor Toso <victortoso@redhat.com> - 0.35-5]- Keepalive fix
  Resolves: rhbz#1719736
- Fix hang on migration after password expired
  Resolves: rhbz#1761776
*	\\*j;gq$Frediano Ziglio <fziglio@redhat.com> - 0.34-3Z;@- Fix stride misalignment
  Resolves: rhbz#1508847\:eW$Victor Toso <victortoso@redhat.com> - 0.34-2Z
- Enable lz4
  Resolves: rhbz#1460198`9e_$Victor Toso <victortoso@redhat.com> - 0.34-1Y@- Rebase to 0.34
  Resolves: rhbz#1472730l8kq$Jonathon Jongsma <jjongsma@redhat.com> - 0.33-7Yh@- build with opus support
  Resolves: rhbz#14568497k-#Frediano Ziglio <fziglio@redhat.com> - 0.35-5.1_O@- Fix multiple buffer overflows in QUIC decoding code
  Resolves: CVE-2020-14355(6em#Victor Toso <victortoso@redhat.com> - 0.35-5]- Keepalive fix
  Resolves: rhbz#1719736
- Fix hang on migration after password expired
  Resolves: rhbz#1761776t5e#Victor Toso <victortoso@redhat.com> - 0.35-4\- Fix bad channel-reset on usbredir
  Resolves: rhbz#1625550{4g#Frediano Ziglio <fziglio@redhat.com> - 0.35-3[- Fix insufficient encoding checks for LZ
  Resolves: rhbz#1598652
"+~~`Ce_%Victor Toso <victortoso@redhat.com> - 0.34-1Y@- Rebase to 0.34
  Resolves: rhbz#1472730lBkq%Jonathon Jongsma <jjongsma@redhat.com> - 0.33-7Yh@- build with opus support
  Resolves: rhbz#1456849Ak-$Frediano Ziglio <fziglio@redhat.com> - 0.35-5.1_O@- Fix multiple buffer overflows in QUIC decoding code
  Resolves: CVE-2020-14355(@em$Victor Toso <victortoso@redhat.com> - 0.35-5]- Keepalive fix
  Resolves: rhbz#1719736
- Fix hang on migration after password expired
  Resolves: rhbz#1761776t?e$Victor Toso <victortoso@redhat.com> - 0.35-4\- Fix bad channel-reset on usbredir
  Resolves: rhbz#1625550{>g$Frediano Ziglio <fziglio@redhat.com> - 0.35-3[- Fix insufficient encoding checks for LZ
  Resolves: rhbz#1598652v=g$Frediano Ziglio <fziglio@redhat.com> - 0.35-2[m~@- Fix flexible array buffer overflow
  Resolves: rhbz#1596008`<e_$Victor Toso <victortoso@redhat.com> - 0.35-1[d@- Rebase to 0.35
  Resolves: rhbz#1562126
 2T] Kk-%Frediano Ziglio <fziglio@redhat.com> - 0.35-5.1_O@- Fix multiple buffer overflows in QUIC decoding code
  Resolves: CVE-2020-14355(Jem%Victor Toso <victortoso@redhat.com> - 0.35-5]- Keepalive fix
  Resolves: rhbz#1719736
- Fix hang on migration after password expired
  Resolves: rhbz#1761776tIe%Victor Toso <victortoso@redhat.com> - 0.35-4\- Fix bad channel-reset on usbredir
  Resolves: rhbz#1625550{Hg%Frediano Ziglio <fziglio@redhat.com> - 0.35-3[- Fix insufficient encoding checks for LZ
  Resolves: rhbz#1598652vGg%Frediano Ziglio <fziglio@redhat.com> - 0.35-2[m~@- Fix flexible array buffer overflow
  Resolves: rhbz#1596008`Fe_%Victor Toso <victortoso@redhat.com> - 0.35-1[d@- Rebase to 0.35
  Resolves: rhbz#1562126jEgq%Frediano Ziglio <fziglio@redhat.com> - 0.34-3Z;@- Fix stride misalignment
  Resolves: rhbz#1508847\DeW%Victor Toso <victortoso@redhat.com> - 0.34-2Z
- Enable lz4
  Resolves: rhbz#1460198
,^tSe&Victor Toso <victortoso@redhat.com> - 0.35-4\- Fix bad channel-reset on usbredir
  Resolves: rhbz#1625550{Rg&Frediano Ziglio <fziglio@redhat.com> - 0.35-3[- Fix insufficient encoding checks for LZ
  Resolves: rhbz#1598652vQg&Frediano Ziglio <fziglio@redhat.com> - 0.35-2[m~@- Fix flexible array buffer overflow
  Resolves: rhbz#1596008`Pe_&Victor Toso <victortoso@redhat.com> - 0.35-1[d@- Rebase to 0.35
  Resolves: rhbz#1562126jOgq&Frediano Ziglio <fziglio@redhat.com> - 0.34-3Z;@- Fix stride misalignment
  Resolves: rhbz#1508847\NeW&Victor Toso <victortoso@redhat.com> - 0.34-2Z
- Enable lz4
  Resolves: rhbz#1460198`Me_&Victor Toso <victortoso@redhat.com> - 0.34-1Y@- Rebase to 0.34
  Resolves: rhbz#1472730lLkq&Jonathon Jongsma <jjongsma@redhat.com> - 0.33-7Yh@- build with opus support
  Resolves: rhbz#1456849
CSS!Cv[g'Frediano Ziglio <fziglio@redhat.com> - 0.35-2[m~@- Fix flexible array buffer overflow
  Resolves: rhbz#1596008`Ze_'Victor Toso <victortoso@redhat.com> - 0.35-1[d@- Rebase to 0.35
  Resolves: rhbz#1562126jYgq'Frediano Ziglio <fziglio@redhat.com> - 0.34-3Z;@- Fix stride misalignment
  Resolves: rhbz#1508847\XeW'Victor Toso <victortoso@redhat.com> - 0.34-2Z
- Enable lz4
  Resolves: rhbz#1460198`We_'Victor Toso <victortoso@redhat.com> - 0.34-1Y@- Rebase to 0.34
  Resolves: rhbz#1472730lVkq'Jonathon Jongsma <jjongsma@redhat.com> - 0.33-7Yh@- build with opus support
  Resolves: rhbz#1456849Uk-&Frediano Ziglio <fziglio@redhat.com> - 0.35-5.1_O@- Fix multiple buffer overflows in QUIC decoding code
  Resolves: CVE-2020-14355(Tem&Victor Toso <victortoso@redhat.com> - 0.35-5]- Keepalive fix
  Resolves: rhbz#1719736
- Fix hang on migration after password expired
  Resolves: rhbz#1761776
*	\\*jcgq(Frediano Ziglio <fziglio@redhat.com> - 0.34-3Z;@- Fix stride misalignment
  Resolves: rhbz#1508847\beW(Victor Toso <victortoso@redhat.com> - 0.34-2Z
- Enable lz4
  Resolves: rhbz#1460198`ae_(Victor Toso <victortoso@redhat.com> - 0.34-1Y@- Rebase to 0.34
  Resolves: rhbz#1472730l`kq(Jonathon Jongsma <jjongsma@redhat.com> - 0.33-7Yh@- build with opus support
  Resolves: rhbz#1456849_k-'Frediano Ziglio <fziglio@redhat.com> - 0.35-5.1_O@- Fix multiple buffer overflows in QUIC decoding code
  Resolves: CVE-2020-14355(^em'Victor Toso <victortoso@redhat.com> - 0.35-5]- Keepalive fix
  Resolves: rhbz#1719736
- Fix hang on migration after password expired
  Resolves: rhbz#1761776t]e'Victor Toso <victortoso@redhat.com> - 0.35-4\- Fix bad channel-reset on usbredir
  Resolves: rhbz#1625550{\g'Frediano Ziglio <fziglio@redhat.com> - 0.35-3[- Fix insufficient encoding checks for LZ
  Resolves: rhbz#1598652
"+~~`ke_)Victor Toso <victortoso@redhat.com> - 0.34-1Y@- Rebase to 0.34
  Resolves: rhbz#1472730ljkq)Jonathon Jongsma <jjongsma@redhat.com> - 0.33-7Yh@- build with opus support
  Resolves: rhbz#1456849ik-(Frediano Ziglio <fziglio@redhat.com> - 0.35-5.1_O@- Fix multiple buffer overflows in QUIC decoding code
  Resolves: CVE-2020-14355(hem(Victor Toso <victortoso@redhat.com> - 0.35-5]- Keepalive fix
  Resolves: rhbz#1719736
- Fix hang on migration after password expired
  Resolves: rhbz#1761776tge(Victor Toso <victortoso@redhat.com> - 0.35-4\- Fix bad channel-reset on usbredir
  Resolves: rhbz#1625550{fg(Frediano Ziglio <fziglio@redhat.com> - 0.35-3[- Fix insufficient encoding checks for LZ
  Resolves: rhbz#1598652veg(Frediano Ziglio <fziglio@redhat.com> - 0.35-2[m~@- Fix flexible array buffer overflow
  Resolves: rhbz#1596008`de_(Victor Toso <victortoso@redhat.com> - 0.35-1[d@- Rebase to 0.35
  Resolves: rhbz#1562126bRARY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{A0A1A2A3A4 A5%A6*A70A84A98A:<A;AA<EA=JA>PA?UA@YAA_ABdACiADnAEsAGwAH}AIAJAK
ALAMANAOAPAQAR#AS+AT3AU;AVCAWKAXSAY[AZcA[kA]sA_{A`Aa
Ab
AcAdAeAfAg Ah$Ai'Aj+Ak-Al0Am4An6Ao9Ap=Aq?ArBAsEAtGAuIAvNAwPAxRAyVAzYA{[A|_A}cA~fAjAmAqAsAvAzA|AAAAAA
AAAAAAA!A%A)
 2T] sk-)Frediano Ziglio <fziglio@redhat.com> - 0.35-5.1_O@- Fix multiple buffer overflows in QUIC decoding code
  Resolves: CVE-2020-14355(rem)Victor Toso <victortoso@redhat.com> - 0.35-5]- Keepalive fix
  Resolves: rhbz#1719736
- Fix hang on migration after password expired
  Resolves: rhbz#1761776tqe)Victor Toso <victortoso@redhat.com> - 0.35-4\- Fix bad channel-reset on usbredir
  Resolves: rhbz#1625550{pg)Frediano Ziglio <fziglio@redhat.com> - 0.35-3[- Fix insufficient encoding checks for LZ
  Resolves: rhbz#1598652vog)Frediano Ziglio <fziglio@redhat.com> - 0.35-2[m~@- Fix flexible array buffer overflow
  Resolves: rhbz#1596008`ne_)Victor Toso <victortoso@redhat.com> - 0.35-1[d@- Rebase to 0.35
  Resolves: rhbz#1562126jmgq)Frediano Ziglio <fziglio@redhat.com> - 0.34-3Z;@- Fix stride misalignment
  Resolves: rhbz#1508847\leW)Victor Toso <victortoso@redhat.com> - 0.34-2Z
- Enable lz4
  Resolves: rhbz#1460198

er+V:eD6
0d57fe6a1b4c3013d7384f4d0457ff6aacdaf60ec4bcad0624f3d41fbaeb80c4D5
d5b8118e51ac12c714bac62344ad5e2f4caebfee78da0c525e284f1a1334bd7dD4
69aa633d0d57b2f5e92a58731547bb1ae2b44fa1f61b2a529c041ce27a603f2dD3
1ed3b35b8ed762f11879c5cfa1d97f379a6268de2ed28fb8c9b9c0cfae430cc7D2
7e0f590ddcedeebdbcdd4b72907bb5cb9affb7ffdc5d55c89e57dfc3eae94eb3D1
d71161880783b5c75a2c86c86ecd65a9b1c075f8f6ae57b1c22186db3a0e482bD0
d8997cf26edabd8e589ab76bac92e5421bf78eb3fde42b9e071f81183dcc3b2bD/
f84f146908408a42a5ca58fda595d715329febfea19773c4ce12227022c0a0feD.
f5ee3ffceb6d3dc9e61ef0f7f67a18dcd1934d4331e74fa1ae157538a284020dD-
b6bfd04cfc31afc2ac3f06d27918b98d44851172acf977da0dd12062ad342af4D,
8beccf052a2dbefb6d4d3598f864bc4c75f6f3a8b74ae1959275af52a7a8f4c0D+
33aea343791620e71f600e75789b92a84ee5b9007aaa3aa71b3cea849c8c069eD*
8cddf6415beefe785c3a074c6907be271292411506ead04f691c5b753a40fb9c
,^t{e*Victor Toso <victortoso@redhat.com> - 0.35-4\- Fix bad channel-reset on usbredir
  Resolves: rhbz#1625550{zg*Frediano Ziglio <fziglio@redhat.com> - 0.35-3[- Fix insufficient encoding checks for LZ
  Resolves: rhbz#1598652vyg*Frediano Ziglio <fziglio@redhat.com> - 0.35-2[m~@- Fix flexible array buffer overflow
  Resolves: rhbz#1596008`xe_*Victor Toso <victortoso@redhat.com> - 0.35-1[d@- Rebase to 0.35
  Resolves: rhbz#1562126jwgq*Frediano Ziglio <fziglio@redhat.com> - 0.34-3Z;@- Fix stride misalignment
  Resolves: rhbz#1508847\veW*Victor Toso <victortoso@redhat.com> - 0.34-2Z
- Enable lz4
  Resolves: rhbz#1460198`ue_*Victor Toso <victortoso@redhat.com> - 0.34-1Y@- Rebase to 0.34
  Resolves: rhbz#1472730ltkq*Jonathon Jongsma <jjongsma@redhat.com> - 0.33-7Yh@- build with opus support
  Resolves: rhbz#1456849
CSS!Cvg+Frediano Ziglio <fziglio@redhat.com> - 0.35-2[m~@- Fix flexible array buffer overflow
  Resolves: rhbz#1596008`e_+Victor Toso <victortoso@redhat.com> - 0.35-1[d@- Rebase to 0.35
  Resolves: rhbz#1562126jgq+Frediano Ziglio <fziglio@redhat.com> - 0.34-3Z;@- Fix stride misalignment
  Resolves: rhbz#1508847\eW+Victor Toso <victortoso@redhat.com> - 0.34-2Z
- Enable lz4
  Resolves: rhbz#1460198`e_+Victor Toso <victortoso@redhat.com> - 0.34-1Y@- Rebase to 0.34
  Resolves: rhbz#1472730l~kq+Jonathon Jongsma <jjongsma@redhat.com> - 0.33-7Yh@- build with opus support
  Resolves: rhbz#1456849}k-*Frediano Ziglio <fziglio@redhat.com> - 0.35-5.1_O@- Fix multiple buffer overflows in QUIC decoding code
  Resolves: CVE-2020-14355(|em*Victor Toso <victortoso@redhat.com> - 0.35-5]- Keepalive fix
  Resolves: rhbz#1719736
- Fix hang on migration after password expired
  Resolves: rhbz#1761776
U	\WUh
sa,Christophe Fergeau <cfergeau@redhat.com> - 0.14.0-3Zl- Disable TLSv1.0
  Resolves: rhbz#1521053	s1,Christophe Fergeau <cfergeau@redhat.com> - 0.14.0-2YY@- Add streaming patches for use with spice-streaming-agent
  Related: rhbz#1478356qss,Christophe Fergeau <cfergeau@redhat.com> - 0.14.0-1Y- Rebase to 0.14.0 release
  Resolves: rhbz#1472948k-+Frediano Ziglio <fziglio@redhat.com> - 0.35-5.1_O@- Fix multiple buffer overflows in QUIC decoding code
  Resolves: CVE-2020-14355(em+Victor Toso <victortoso@redhat.com> - 0.35-5]- Keepalive fix
  Resolves: rhbz#1719736
- Fix hang on migration after password expired
  Resolves: rhbz#1761776te+Victor Toso <victortoso@redhat.com> - 0.35-4\- Fix bad channel-reset on usbredir
  Resolves: rhbz#1625550{g+Frediano Ziglio <fziglio@redhat.com> - 0.35-3[- Fix insufficient encoding checks for LZ
  Resolves: rhbz#1598652


x
k,Frediano Ziglio <fziglio@redhat.com> - 0.14.0-6[l,- Fix flexible array buffer overflow
  Resolves: rhbz#1596008Hs,Christophe Fergeau <cfergeau@redhat.com> - 0.14.0-5[*A- Don't mute Record channel on client reconnection
  Resolves: rhbz#1549132
- Allow to configure TLS protocol versions and ciphers which SPICE will use for
  TLS communications
  Resolves: rhbz#1562213
- Enable ECDH ciphers with OpenSSL 1.0
  Resolves: rhbz#1566597%sY,Christophe Fergeau <cfergeau@redhat.com> - 0.14.0-4Z- Revert back to spice 0.12 behaviour where QXL guest resources for cursor
  commands are only released when the current cursor is replaced. This avoids
  a QEMU regression causing crashes during migration
  Resolves: rhbz#1567944
dkdqss-Christophe Fergeau <cfergeau@redhat.com> - 0.14.0-1Y- Rebase to 0.14.0 release
  Resolves: rhbz#1472948
o-,Frediano Ziglio <fziglio@redhat.com> - 0.14.0-9.1_O@- Fix multiple buffer overflows in QUIC decoding code
  Resolves: CVE-2020-14355k7,Frediano Ziglio <fziglio@redhat.com> - 0.14.0-9]- Always enable latency monitor to keep tcp connection alive
  Resolves: rhbz#1719736k,Frediano Ziglio <fziglio@redhat.com> - 0.14.0-8]u@- Avoid potential crash from buggy guest driver
  Resolves: rhbz#1582137ssu,Christophe Fergeau <cfergeau@redhat.com> - 0.14.0-7\@- Fix off-by-one error during guest-to-host memory address conversion
  Resolves: CVE-2019-3813
- Add patch for upstream commit 48179332d9da0. This should help with corrupted
  spice-html5 displays
  Resolves: rhbz#1573739
- Add missing minimum openssl version Requires for patch #24
  Resolves: rhbz#1627693
jHs-Christophe Fergeau <cfergeau@redhat.com> - 0.14.0-5[*A- Don't mute Record channel on client reconnection
  Resolves: rhbz#1549132
- Allow to configure TLS protocol versions and ciphers which SPICE will use for
  TLS communications
  Resolves: rhbz#1562213
- Enable ECDH ciphers with OpenSSL 1.0
  Resolves: rhbz#1566597%sY-Christophe Fergeau <cfergeau@redhat.com> - 0.14.0-4Z- Revert back to spice 0.12 behaviour where QXL guest resources for cursor
  commands are only released when the current cursor is replaced. This avoids
  a QEMU regression causing crashes during migration
  Resolves: rhbz#1567944hsa-Christophe Fergeau <cfergeau@redhat.com> - 0.14.0-3Zl- Disable TLSv1.0
  Resolves: rhbz#1521053s1-Christophe Fergeau <cfergeau@redhat.com> - 0.14.0-2YY@- Add streaming patches for use with spice-streaming-agent
  Related: rhbz#1478356
]]
o--Frediano Ziglio <fziglio@redhat.com> - 0.14.0-9.1_O@- Fix multiple buffer overflows in QUIC decoding code
  Resolves: CVE-2020-14355k7-Frediano Ziglio <fziglio@redhat.com> - 0.14.0-9]- Always enable latency monitor to keep tcp connection alive
  Resolves: rhbz#1719736k-Frediano Ziglio <fziglio@redhat.com> - 0.14.0-8]u@- Avoid potential crash from buggy guest driver
  Resolves: rhbz#1582137ssu-Christophe Fergeau <cfergeau@redhat.com> - 0.14.0-7\@- Fix off-by-one error during guest-to-host memory address conversion
  Resolves: CVE-2019-3813
- Add patch for upstream commit 48179332d9da0. This should help with corrupted
  spice-html5 displays
  Resolves: rhbz#1573739
- Add missing minimum openssl version Requires for patch #24
  Resolves: rhbz#1627693xk-Frediano Ziglio <fziglio@redhat.com> - 0.14.0-6[l,- Fix flexible array buffer overflow
  Resolves: rhbz#1596008
LcqW.Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel/qo.Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption
 )  u7.Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgijua.Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoningRu1.Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gateway
Q6Q$iQ.Stepan Broz <sbroz@redhat.com> - 7:3.5.20-17.9eB=- Resolves: RHEL-14789 - squid: Denial of Service in HTTP Digest Authentication
  (CVE-2023-46847)#wI.Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.8c47@- Resolves: #2130254 - CVE-2022-41318 squid: buffer-over-read in SSPI and SMB
  authentication"wA.Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.7b@- Resolves: #2100778 - CVE-2021-46784 squid: DoS when processing gopher server
  responsesE!u.Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request Smuggling
"4"}'s	/Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-10X:@- Resolves: #1445219 - [RFE] Add rock cache directive to squid&q)/Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-9XӸ- Resolves: #1290404 - wrong names of components in man page, section SEE ALSOG%k%.Stepan Broz <sbroz@redhat.com> - 7:3.5.20-17.10e@- Resolves: RHEL-16779 - squid: NULL pointer dereference in the gopher protocol
  code -- Remove support for Gopher protocol (CVE-2023-46728)
- Resolves: RHEL-18176 - squid: Buffer over-read in the HTTP Message processing
  feature (CVE-2023-49285)
- Resolves: RHEL-18171 - squid: Incorrect Check of Function Return Value In
  Helper Process management (CVE-2023-49286)
- Resolves: RHEL-16758 - squid: Denial of Service in SSL Certificate validation
  (CVE-2023-46724)
- Resolves: RHEL-19557 - squid: denial of service in HTTP request parsing
  (CVE-2023-50269)
- Resolves: RHEL-26082 - squid: denial of service in HTTP header parser
  (CVE-2024-25617)
NzN6+q}/Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flawsp*sq/Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidy)s/Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-12Y*A- Resolves: #1471140 - Missing detailed configuration file(s/Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-11Y*@- Resolves: #1452200 - Include kerberos_ldap_group helper in squid
Lc-qW/Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel/,qo/Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption
9)9}0s	0Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-10X:@- Resolves: #1445219 - [RFE] Add rock cache directive to squidj/ua/Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoningR.u1/Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gateway
NzN64q}0Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flawsp3sq0Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidy2s0Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-12Y*A- Resolves: #1471140 - Missing detailed configuration file1s0Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-11Y*@- Resolves: #1452200 - Include kerberos_ldap_group helper in squid
Lc6qW0Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel/5qo0Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption
 ) 9u70Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgij8ua0Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoningR7u10Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gateway
NzN6=q}1Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flawsp<sq1Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidy;s1Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-12Y*A- Resolves: #1471140 - Missing detailed configuration file:s1Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-11Y*@- Resolves: #1452200 - Include kerberos_ldap_group helper in squid
Lc?qW1Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel/>qo1Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption
 ) Bu71Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgijAua1Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoningR@u11Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gateway
E6EpEsq2Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidyDs2Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-12Y*@- Resolves: #1471140 - Missing detailed configuration fileECu1Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request Smuggling
/Gqo2Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption6Fq}2Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flaws
RIu12Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP GatewaycHqW2Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel
-pNsq3Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidMwA2Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.7b@- Resolves: #2100778 - CVE-2021-46784 squid: DoS when processing gopher server
  responsesELu2Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request SmugglingKu72Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgijJua2Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoning
/Pqo3Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption6Oq}3Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flaws
RRu13Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP GatewaycQqW3Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel
-VwA3Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.7b@- Resolves: #2100778 - CVE-2021-46784 squid: DoS when processing gopher server
  responsesEUu3Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request SmugglingTu73Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgijSua3Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoning
m\!m/Yqo4Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption6Xq}4Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flawsWwI3Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.8c47@- Resolves: #2130254 - CVE-2022-41318 squid: buffer-over-read in SSPI and SMB
  authentication
R[u14Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP GatewaycZqW4Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel
-_wA4Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.7b@- Resolves: #2100778 - CVE-2021-46784 squid: DoS when processing gopher server
  responsesE^u4Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request Smuggling]u74Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgij\ua4Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoning
\ccqW5Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel/bqo5Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruptionaiQ4Stepan Broz <sbroz@redhat.com> - 7:3.5.20-17.9eB=- Resolves: RHEL-14789 - squid: Denial of Service in HTTP Digest Authentication
  (CVE-2023-46847)`wI4Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.8c47@- Resolves: #2130254 - CVE-2022-41318 squid: buffer-over-read in SSPI and SMB
  authentication
 ) fu75Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgijeua5Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoningRdu15Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gateway
Q6QjiQ5Stepan Broz <sbroz@redhat.com> - 7:3.5.20-17.9eB=- Resolves: RHEL-14789 - squid: Denial of Service in HTTP Digest Authentication
  (CVE-2023-46847)iwI5Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.8c47@- Resolves: #2130254 - CVE-2022-41318 squid: buffer-over-read in SSPI and SMB
  authenticationhwA5Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.7b@- Resolves: #2100778 - CVE-2021-46784 squid: DoS when processing gopher server
  responsesEgu5Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request Smuggling
"4"}ms	6Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-10X:@- Resolves: #1445219 - [RFE] Add rock cache directive to squidlq)6Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-9XӸ- Resolves: #1290404 - wrong names of components in man page, section SEE ALSOGkk%5Stepan Broz <sbroz@redhat.com> - 7:3.5.20-17.10e@- Resolves: RHEL-16779 - squid: NULL pointer dereference in the gopher protocol
  code -- Remove support for Gopher protocol (CVE-2023-46728)
- Resolves: RHEL-18176 - squid: Buffer over-read in the HTTP Message processing
  feature (CVE-2023-49285)
- Resolves: RHEL-18171 - squid: Incorrect Check of Function Return Value In
  Helper Process management (CVE-2023-49286)
- Resolves: RHEL-16758 - squid: Denial of Service in SSL Certificate validation
  (CVE-2023-46724)
- Resolves: RHEL-19557 - squid: denial of service in HTTP request parsing
  (CVE-2023-50269)
- Resolves: RHEL-26082 - squid: denial of service in HTTP header parser
  (CVE-2024-25617)
NzN6qq}6Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flawsppsq6Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidyos6Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-12Y*A- Resolves: #1471140 - Missing detailed configuration filens6Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-11Y*@- Resolves: #1452200 - Include kerberos_ldap_group helper in squid
LcsqW6Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel/rqo6Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption
9)9}vs	7Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-10X:@- Resolves: #1445219 - [RFE] Add rock cache directive to squidjuua6Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoningRtu16Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gateway

er+V:eDC
44f231fe5f62541a6b45943aaab6e3541465a25fd0a14bd3c846d9df73cdcd9bDB
a23725495610dce574aa0dd65ab70ebc49af45d253cb2c031fcb4f8050ef9174DA
61a8eaa6a0f98be8585a74fd7663aa37fdb6f542080f0ee3e6b96844e82564a5D@
af7e93ece536de48118743c25ba2dc36958cb213c049a71bf622da7992e28132D?
147f560470dacac3f89bc4c5cfaa3c9d32364fc302511f2bf1a13025a5875621D>
6cac781f27cb3127831f0723bbd81603bf1aa948ef07042576138eded250dafaD=
d13a43c2f72be1aac5c18bee475d4bf325e04b8cc511f75df749c29fb616adc1D<
8c9ca7fef03b651b6cf4439fc8f4e9406e901baac07b1d86a9d94eedeb2b84ccD;
263ab19ddbf99ff851e5ec348f81b1a2fd27b14a82e84c024b8df1092fff99a7D:
00f44bddea556d6114fd545f221ce9393e2498132e40d8c7e1ba1b4015de0671D9
3fe92e24b021f0064189e1c7e735a79fffdf4d33994fb8e504bcdbbd19dacb33D8
05b86a6126cc85e6e214a09707b886a17df5b705f5cb7dab4c86228f6b2ad4d2D7
f7db305710a65de9955170c92aeba72e62fb979802464b4239b0b607d6adc2a0
NzN6zq}7Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flawspysq7Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidyxs7Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-12Y*A- Resolves: #1471140 - Missing detailed configuration filews7Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-11Y*@- Resolves: #1452200 - Include kerberos_ldap_group helper in squid
Lc|qW7Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel/{qo7Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption
 ) u77Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgij~ua7Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoningR}u17Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gateway
NzN6q}8Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flawspsq8Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidys8Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-12Y*A- Resolves: #1471140 - Missing detailed configuration files8Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-11Y*@- Resolves: #1452200 - Include kerberos_ldap_group helper in squid
LcqW8Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel/qo8Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption
 ) u78Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgijua8Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoningRu18Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gateway
E6Epsq9Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidy
s9Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-12Y*@- Resolves: #1471140 - Missing detailed configuration fileE	u8Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request Smuggling
/
qo9Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption6q}9Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flaws
Ru19Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP GatewaycqW9Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel
-psq:Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidwA9Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.7b@- Resolves: #2100778 - CVE-2021-46784 squid: DoS when processing gopher server
  responsesEu9Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request Smugglingu79Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgijua9Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoning
/qo:Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption6q}:Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flaws
Ru1:Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP GatewaycqW:Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel
-wA:Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.7b@- Resolves: #2100778 - CVE-2021-46784 squid: DoS when processing gopher server
  responsesEu:Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request Smugglingu7:Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgijua:Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoning
m\!m/qo;Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption6q};Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flawswI:Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.8c47@- Resolves: #2130254 - CVE-2022-41318 squid: buffer-over-read in SSPI and SMB
  authentication
R!u1;Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gatewayc qW;Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel
-%wA;Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.7b@- Resolves: #2100778 - CVE-2021-46784 squid: DoS when processing gopher server
  responsesE$u;Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request Smuggling#u7;Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgij"ua;Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoning
\c)qW<Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel/(qo<Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption'iQ;Stepan Broz <sbroz@redhat.com> - 7:3.5.20-17.9eB=- Resolves: RHEL-14789 - squid: Denial of Service in HTTP Digest Authentication
  (CVE-2023-46847)&wI;Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.8c47@- Resolves: #2130254 - CVE-2022-41318 squid: buffer-over-read in SSPI and SMB
  authentication
 ) ,u7<Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgij+ua<Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoningR*u1<Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gateway
Q6Q0iQ<Stepan Broz <sbroz@redhat.com> - 7:3.5.20-17.9eB=- Resolves: RHEL-14789 - squid: Denial of Service in HTTP Digest Authentication
  (CVE-2023-46847)/wI<Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.8c47@- Resolves: #2130254 - CVE-2022-41318 squid: buffer-over-read in SSPI and SMB
  authentication.wA<Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.7b@- Resolves: #2100778 - CVE-2021-46784 squid: DoS when processing gopher server
  responsesE-u<Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request Smuggling
"4"}3s	=Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-10X:@- Resolves: #1445219 - [RFE] Add rock cache directive to squid2q)=Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-9XӸ- Resolves: #1290404 - wrong names of components in man page, section SEE ALSOG1k%<Stepan Broz <sbroz@redhat.com> - 7:3.5.20-17.10e@- Resolves: RHEL-16779 - squid: NULL pointer dereference in the gopher protocol
  code -- Remove support for Gopher protocol (CVE-2023-46728)
- Resolves: RHEL-18176 - squid: Buffer over-read in the HTTP Message processing
  feature (CVE-2023-49285)
- Resolves: RHEL-18171 - squid: Incorrect Check of Function Return Value In
  Helper Process management (CVE-2023-49286)
- Resolves: RHEL-16758 - squid: Denial of Service in SSL Certificate validation
  (CVE-2023-46724)
- Resolves: RHEL-19557 - squid: denial of service in HTTP request parsing
  (CVE-2023-50269)
- Resolves: RHEL-26082 - squid: denial of service in HTTP header parser
  (CVE-2024-25617)
NzN67q}=Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flawsp6sq=Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidy5s=Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-12Y*A- Resolves: #1471140 - Missing detailed configuration file4s=Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-11Y*@- Resolves: #1452200 - Include kerberos_ldap_group helper in squid
Lc9qW=Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel/8qo=Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption
9)9}<s	>Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-10X:@- Resolves: #1445219 - [RFE] Add rock cache directive to squidj;ua=Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoningR:u1=Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gateway
NzN6@q}>Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flawsp?sq>Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidy>s>Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-12Y*A- Resolves: #1471140 - Missing detailed configuration file=s>Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-11Y*@- Resolves: #1452200 - Include kerberos_ldap_group helper in squid
LcBqW>Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel/Aqo>Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption
 ) Eu7>Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgijDua>Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoningRCu1>Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gateway
NzN6Iq}?Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flawspHsq?Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidyGs?Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-12Y*A- Resolves: #1471140 - Missing detailed configuration fileFs?Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-11Y*@- Resolves: #1452200 - Include kerberos_ldap_group helper in squid
LcKqW?Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel/Jqo?Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption
 ) Nu7?Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgijMua?Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoningRLu1?Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gateway
E6EpQsq@Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidyPs@Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-12Y*@- Resolves: #1471140 - Missing detailed configuration fileEOu?Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request Smuggling
/Sqo@Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption6Rq}@Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flaws
RUu1@Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP GatewaycTqW@Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel
-pZsqALuboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-13\	@- Resolves: #1620546 - migration of upstream squidYwA@Luboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.7b@- Resolves: #2100778 - CVE-2021-46784 squid: DoS when processing gopher server
  responsesEXu@Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request SmugglingWu7@Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgijVua@Lubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoning
/\qoALubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption6[q}ALubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flaws
R^u1ALubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP Gatewayc]qWALubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel
-bwAALuboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.7b@- Resolves: #2100778 - CVE-2021-46784 squid: DoS when processing gopher server
  responsesEauALubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request Smuggling`u7ALubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgij_uaALubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoning
m\!m/eqoBLubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-16^}- Resolves: #1738582 - CVE-2019-12525 squid: parsing of header 
  Proxy-Authentication leads to memory corruption6dq}BLubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-15]9- Resolves: #1690551 - Squid cache_peer DNS lookup failed when not all lower
  case
- Resolves: #1680022 - squid can't display download/upload packet size for HTTPS
  sites
- Resolves: #1717430 - Excessive memory usage when running out of descriptors
- Resolves: #1676420 - Cache siblings return wrongly cached gateway timeouts
- Resolves: #1729435 - CVE-2019-13345 squid: XSS via user_name or auth parameter
  in cachemgr.cgi
- Resolves: #1582301 - CVE-2018-1000024 CVE-2018-1000027 squid: various flawscwIALuboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.8c47@- Resolves: #2130254 - CVE-2022-41318 squid: buffer-over-read in SSPI and SMB
  authentication
Rgu1BLubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.2_$- Resolves: #1802516 - CVE-2020-8449 squid: Improper input validation issues
  in HTTP Request processing
- Resolves: #1802515 - CVE-2020-8450 squid: Buffer overflow in a Squid acting
  as reverse-proxy
- Resolves: #1853129 - CVE-2020-15049 squid: request smuggling and poisoning
  attack against the HTTP cache
- Resolves: #1802517 - CVE-2019-12528 squid: Information Disclosure issue in
  FTP GatewaycfqWBLubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17^- Resolves: #1828361 - CVE-2020-11945 squid: improper access restriction upon
  Digest Authentication nonce replay could lead to remote code execution
- Resolves: #1828362 - CVE-2019-12519 squid: improper check for new member in
  ESIExpression::Evaluate allows for stack buffer overflow [rhel
-kwABLuboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.7b@- Resolves: #2100778 - CVE-2021-46784 squid: DoS when processing gopher server
  responsesEjuBLubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.6`dd@- Resolves: #1944256 - CVE-2020-25097 squid: improper input validation may allow
  a trusted client to perform HTTP Request Smugglingiu7BLubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.5_@- Resolves: #1890581 - Fix for CVE 2019-13345 breaks authentication in
  cachemgr.cgijhuaBLubos Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.4_H- Resolves: #1872349 - CVE-2020-24606 squid: Improper Input Validation could
  result in a DoS
- Resolves: #1872327 - CVE-2020-15810 squid: HTTP Request Smuggling could
  result in cache poisoning
- Resolves: #1872342 - CVE-2020-15811 squid: HTTP Request Splitting could
  result in cache poisoning
m\nmqY)CJarod Wilson <jarod@redhat.com> 22.3-1]e@- Update to v22.3 stable release
- Unclamp IPoIP MTUs
- Resolves: rhbz#1647541xpYCJarod Wilson <jarod@redhat.com> 22.1-3\- Actually apply ConnectX-6 DX device ID patch
- Related: rhbz#1687426oY?CJarod Wilson <jarod@redhat.com> 22.1-2\- Refresh stable-v22 branch fixes
- Add ConnectX-6 DX device IDs
- Resolves: rhbz#16874268nYCJarod Wilson <jarod@redhat.com> 22.1-1\e- Update to upstream v22.1 release with stable-v22 branch fixes
- Add support for Broadcom 57500 RoCE adapter
- Resolves: rhbz#1678274miQBStepan Broz <sbroz@redhat.com> - 7:3.5.20-17.9eB=- Resolves: RHEL-14789 - squid: Denial of Service in HTTP Digest Authentication
  (CVE-2023-46847)lwIBLuboš Uhliarik <luhliari@redhat.com> - 7:3.5.20-17.8c47@- Resolves: #2130254 - CVE-2022-41318 squid: buffer-over-read in SSPI and SMB
  authentication
u%0uw[OCHonggang Li <honli@redhat.com> - 22.4-6`t6@- rdma-ndd: fix udev racy issue for system with multiple InfiniBand HCAs
- Resolves: rhbz#1937699v[CCHonggang Li <honli@redhat.com> - 22.4-5^ۅ@- libibverbs: Fix ABI_placeholder1 and ABI_placeholder2 assignment
- Resolves: rhbz#1843221
u[;CHonggang Li <honli@redhat.com> - 22.4-4^- libbnxt_re support for some new device ids and generation id
- Resolves: rhbz#1828482bt[mCHonggang Li <honli@redhat.com> - 22.4-3^@- Restore three patches
- Resolves: rhbz#1817412
s[;CHonggang Li <honli@redhat.com> - 22.4-2^M#@- Fix ibacm segfault for dual port HCA support IB and Ethernet
- Resolves: rhbz#1793585VrYUCJarod Wilson <jarod@redhat.com> 22.4-1]|@- Update to v22.4 stable release
- Support mlx5 scatter to CQE over DCT QP
- Fix ibacm segfault on non-IB hardware
- Resolves: rhbz#1715489
- Resolves: rhbz#1712296

er+V:eDP
77c36db32c50f15916ca53f42fba6ef0360314d11a2d6e929276d3f8890dcf99DO
ff3b468571e583e09e30108bb68b5b52e5aa7c6c634076708aa4dbbf6d6a6c7eDN
7f6c1ee79dd230a85336204331bee68c57e6de3879ff35719632a2132c9d3c75DM
0cc9ba42a15c78ffcce2049a61fd84727a2586eca9d5215f1ca32e1a24b02bfeDL
542aab85e68ca0ec1ae3084cd0af6195d78adc16d93c4be11b237a264eedb1bcDK
1fe72164363f910c775d358dbfd20b12da516c49d28c4a4388ff663a5f4291dcDJ
3bbbdec13d548901746ce3f8e2bf282000598614b5b70523edb80f329ec935e0DI
152dbbf3f7f9f134af6da2865820367d78a9a9699d7a81d9166fbe3415389719DH
aee634ff6dd524953bce90ba54a52b06711539a2df4b6da94cd10b418b71b0adDG
f4b81bba6d36049eb10ff5bb2d20310de20be1048a6d3e39a65a860939563c6fDF
3579555a0a1408bf0ffc0c41aa84d2045a42a0fc9536c5b03f837ea3080086a2DE
8ada58179dcbbef50383829ff646e8482d88b3597602d1e89527ff2801adc78bDD
96e8afde7554bf087d7015345cb62d8833fcecf0f4165e71ec3a77681591973d
tzo{DAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
yo'DAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTxo;DAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2|owDAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|{oDAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""Y}oEDAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A~oDAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omDAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
o'EAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetqODAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoDAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2owEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{EAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoEEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9EAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)
qOEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down	oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2owFAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|
oFAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{FAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoEFAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoFAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omFAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9FAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOFAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoFAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2owGAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oGAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hqaFAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoEGAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoGAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omGAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]bRARY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{A0A3A7A9A<A@ABAEAIAKANAQASAUAZA\A^AbAeAgAkAqAwAzA|A}A~AAAAAAAAAAAAAAAAƒAăAŃ Aƃ!Aǃ"Aȃ#AɃ&Aʃ)A˃*Ã+A̓,A΃/Aσ2AЃ4Aу5A҃8AӃ;Aԃ>AՃAAփCA׃FA؃IAكLAڃOAۃPA܃QA݃SAރUA߃XAYAქZA⃥\Aュ^A䃥aA僥bA惥cA烥dA胥eA郥hAꃥjA냥kA샥lA탥mApAsAtAuAvAyA|A}A~AAAA
?|?q9GAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOGAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoGAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2 owHAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|q	GAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaGAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y!oEHAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A"oHAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-#omHAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?&q9HAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)%qOHAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down$oHAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm )qQHAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|(q	HAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h'qaHAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y*oEIAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A+oIAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-,omIAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?/q9IAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains).qOIAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down-oIAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 2qQIAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|1q	IAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h0qaIAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
A4oJAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=3qIAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-5omJAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?8q9JAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)7qOJAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down6oJAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm ;qQJAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|:q	JAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h9qaJAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.>a}KAlexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD=}
JEduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=<qJAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
TtAa	KAlexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)@asKAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).y?aKAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
PCg;KAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_Bc]KAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxFgKAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pEg{KAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)Dg'KAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-IisLAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}HiLAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..GgwKAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTLo;LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cKk]LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is FalsexJi	LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|OoLAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tNo{LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Mo'LAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2PowLAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YQoELAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
NxSi	MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-RisMAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
TUo;MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cTk]MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|XoMAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tWo{MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Vo'MAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2YowMAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YZoEMAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:x\i	NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationA[oMAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
T^o;NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c]k]NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|aoNAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t`o{NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
_o'NAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2bowNAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YcoENAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AdoNAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-eomNAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
tho{OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
go'OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTfo;OAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2jowOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|ioOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YkoEOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AloOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-momOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
po'PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetoqOOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downnoOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2sowPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|roPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tqo{PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YtoEPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AuoPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-vomPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?yq9PAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)xqOPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downwoPAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]

er+V:eD]
44366b0b7affba7de64323741418475b4e65ac775871a7709bdc2230e592c5afD\
75ce644c70ec9964e32bce8017125212233496a086225b0503cf1810e717e333D[
fbd39d1a8897fa30ac649d4e1c6652bada403accff15f98abb244507a91a8494DZ
772df4394d584927dcf77fefe3909f14263b4a632dfec53f011d34b412b30d8cDY
24374c0fbadcce0d6917a2e88255f302cb3f4a155216a45c8492da80d78ae47aDX
20693e146f5e799d72526af73b57a86d3d7d316b6f7e0678460e69cc3c684e1eDW
cd7a7f077489d8e2a9dd46b53fdf41995243a699f3fa2bbb47093c9bfd7d9266DV
5343570a081f4c1fbce42a13f928cc48ab03be8c1c68a418094e37927e1b78d5DU
90d24b11f08fa24d41c2102a917044b252760ee28a2d70c68a1ff4f9043c7464DT
b55dfb902c51c301e4075cc32658c8a11145de6ede53d43aeaf2057090a9bdcfDS
9fe7f82ad271dad01797d8671e72b30eaa56799b8b56946e3a6091de48af5ea7DR
5272882f683e83a910d603b0d6b4d2bb3031f9b793b125f6df3208740a29d2adDQ
9d64772c1a50450f231fb3e75179eecc94b9aa1ff2a18fe00a4322da5b873623
2|owQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|{oQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tzo{QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y}oEQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A~oQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9QAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2owRAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oRAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hqaQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoERAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoRAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omRAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)
qORAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down	oRAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2owSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|
q	RAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaRAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoESAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	SAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaSAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoETAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm  qQTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	TAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
A"oUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=!qTAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-#omUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?&q9UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)%qOUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down$oUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm )qQUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|(q	UAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h'qaUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.,a}VAlexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD+}
UEduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=*qUAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tt/a	VAlexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization).asVAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).y-aVAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
P1g;VAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_0c]VAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux4gVAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p3g{VAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)2g'VAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-7isWAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}6iWAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..5gwVAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT:o;WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c9k]WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex8i	WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|=oWAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t<o{WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
;o'WAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2>owWAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y?oEWAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
NxAi	XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-@isXAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
TCo;XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cBk]XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|FoXAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tEo{XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Do'XAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2GowXAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YHoEXAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xJi	YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAIoXAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
TLo;YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cKk]YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|OoYAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tNo{YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Mo'YAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2PowYAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YQoEYAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ARoYAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-SomYAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
tVo{ZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Uo'ZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTTo;ZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2XowZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|WoZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YYoEZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AZoZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-[omZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]bRBaRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{AAABBBBBBBBBB	 B
"B#B&B
)B,B/B1B4B7B:B=B>B?BABCBFBGBHBJBLBOBPB QB!RB"SB#VB$XB%YB&ZB'[B)^B*aB+bB,cB-dB.eB/hB0kB1lB2mB3nB4qB5tB6uB7vB8wB9xB:{B<~B=B>B?B@BABBBC	BD
BEBFBGBHBIBJBKBLBMBNBOBPBQ!BR$BS%BT&BU'BV*BW-BX.BY/BZ0B[1B\4B]7B^8B_9B`:
|T^o;[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]]qOZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down\oZAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|ao[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t`o{[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
_o'[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2bow[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YcoE[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ado[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-eom[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
ho'\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetgqO[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downfo[Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2kow\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|jo\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tio{\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YloE\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Amo\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-nom\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?qq9\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)pqO\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoo\Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|to]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tso{]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
ro']Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2uow]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YvoE]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Awo]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-xom]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?{q9]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)zqO]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downyo]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]

er+V:eDj
9bf2751a28e0695d59bf5c8e1ac8a371b4f65b45751daac5745c15803ecb05e8Di
5a7cdc99b9d090c26ee5c769f9c02bcc2598cf3c5ebb4b9e0d041e33a5f8334cDh
9349658aa8b7d4b836a718f62cdaf519b05370897881d1661e16c4ca039a4fcfDg
db24348500eb9dbf5298596dfe2e37ca3bc54a7bacc1db758d4a433d37f486a4Df
c3b34b85ae893b22977e8dfafa61a01dd6b4c787c7b37cab2e89df863cc94330De
67464059f8d9ef6bdaaabcff4bd255af5760b16b8ca9af7c4e194e78ab73d9e9Dd
375ebea7e1dcf98b38f838956b03b236dd23db4b665522d9268223ed9b4e8d3dDc
0f5a8848daead9b08962772ffcfea5205ed58cc1314cf39de5639e4757359ea6Db
e3da9cf446dbbd5a2b65cf4a7f59080bf53067a5b3c1c938582a6c2e7874a819Da
60e80bc431d4065eaaeb5d133dd160c01f64d7e9543d7cbfdc49c8799a6b079fD`
402c8ad0ef6726c780c90655a28c409b5f0ea3b0d5b2e1562caeb06dd9062e22D_
4abd16c4ab5141d33e867b7f35275398808b6ec6c8b49a01a8fe2836089ca1edD^
3f9b0f657dd2581e1dd7b33d31ff3179c309539c7fadc4275ca679411bbd4f7d
2~ow^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|}o^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t|o{^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoE^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|o_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)hqa^Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2ow_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y	oE_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A
o_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)
qO_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2ow`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|o`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hqa_Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoE`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::Ao`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-om`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qO`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downo`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|oaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))|q	`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqa`Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2owaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?!q9aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains) qOaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2$owbAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|#q	aAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h"qaaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y%oEbAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A&obAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-'ombAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?*q9bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains))qObAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down(obAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm -qQbAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|,q	bAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h+qabAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2.owcAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y/oEcAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A0ocAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-1omcAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?4q9cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)3qOcAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down2ocAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 7qQcAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|6q	cAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h5qacAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y8oEdAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A9odAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-:omdAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?=q9dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)<qOdAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down;odAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm @qQdAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|?q	dAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h>qadAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
=AqdAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
""YBoEeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ACoeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-DomeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Gq9eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)FqOeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downEoeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm JqQeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Iq	eAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hHqaeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
ALofAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=KqeAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-MomfAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Pq9fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)OqOfAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downNofAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm SqQfAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Rq	fAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hQqafAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
//AVogAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]DU}
fEduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=TqfAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-WomgAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Zq9gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)YqOgAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downXogAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm ]qQgAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|\q	gAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h[qagAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.`a}hAlexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD_}
gEduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=^qgAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Ttca	hAlexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)bashAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yaahAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Peg;hAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_dc]hAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxhghAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pgg{hAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)fg'hAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
ykaiAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..ja}iAlexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen.igwhAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
Rtma	iAlexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)lasiAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
Pog;iAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_nc]iAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxrgiAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pqg{iAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)pg'iAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-uisjAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}tijAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..sgwiAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTxo;jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cwk]jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexvi	jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|{ojAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tzo{jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
yo'jAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2|owjAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y}oEjAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]

er+V:eDw
bf742dc3dc34fd5e59a231bfb252573f70d7b5a840803d31e860e52fe35f902eDv
a2766b83b6a876469856708425fef7119bad6779d4b9ed448fcb9ea454b97420Du
bbcc65876a2808fc3b0866365675ccaee30c914a03af4a86bac11a13ac2192e1Dt
b4f318de6ef0eb132e4123f8b5fe5520c45b79417dc124c993f2ae8570bd2ea4Ds
58a27b52c09a126948ce6287661318459d3416d0cd51071d3b438cd6b8b6f5eaDr
4501c2327452af05f97c309a9269b764df7c26f9118e1c6cc2594f1660aefb89Dq
da8db8418933d315b0ed79893d80242ae95d51f00cabe099162d09d07124d15bDp
b0d0a9428e29aa54f6cf8736a355da73553cc5c4e20f0795d6faf0e6cab0ce49Do
84338ef31ca6974b5061ab6de6f266737dfa9cd9bfd5636c91498adb8d422130Dn
9030c370aec5edcb0723952a2989c5012de7aea238458f7f55ec1a6b9a24962aDm
6574b4b68f18c25488f8d81b6428bc0c2d58438c98a5e53c49f813717763e9ecDl
2085e16e3688337145397ad071965596e29a2b506f9ed495de26bab6e9ad7e4eDk
bebf3e1f9a460eb53ffa76825f7941c604da28361997c54fd39f0224ef015391
Lxi	kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-iskAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}~ikAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
To;kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|okAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'kAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owkAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEkAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nx	i	lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-islAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
To;lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c
k]lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|olAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t
o{lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'lAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owlAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoElAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:-ismAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).AolAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
CCTo;mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexi	mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'mAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owmAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEmAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]bRBRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{Bb@BcABdBBeCBfDBgGBhJBiLBjMBkPBlSBmVBnWBoZBp]Bq`BrcBseBthBukBvmBwoBxrByuBzxB{{B||B}}BBBBBB	BBBBBBBBBBBB!B"B#B$B&B(B+B,B-B.B/B2B4B5B6B7B:B=B>B?B@BCBFBGBHBIBLBOBPBQBRBUBXBYBZB[B^BaBbBcBdBgBjBlBmBpBsBvByBƒ{BÃ~BăBƃ
:xi	nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
To;nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|!onAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t o{nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'nAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2"ownAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y#oEnAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A$onAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
Nx&i	oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-%omnAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
T(o;oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c'k]oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|+ooAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t*o{oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
)o'oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2,owoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y-oEoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A.ooAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-/omoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
t2o{pAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
1o'pAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetT0o;pAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
24owpAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|3opAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""Y5oEpAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A6opAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-7ompAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
:o'qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target9qOpAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down8opAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2=owqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|<oqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t;o{qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y>oEqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A?oqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-@omqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Cq9qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)BqOqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downAoqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2FowrAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|EorAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tDo{rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YGoErAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AHorAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-IomrAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Lq9rAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)KqOrAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downJorAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2OowsAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|NosAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hMqarAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YPoEsAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AQosAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-RomsAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Uq9sAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)TqOsAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downSosAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2XowtAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Wq	sAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hVqasAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YYoEtAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AZotAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-[omtAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?^q9tAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)]qOtAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down\otAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm aqQtAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|`q	tAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h_qatAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YboEuAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AcouAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-domuAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?gq9uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)fqOuAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downeouAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm jqQuAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|iq	uAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hhqauAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
AlovAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=kquAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-momvAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?pq9vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)oqOvAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downnovAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm sqQvAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|rq	vAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqqavAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.va}wAlexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenDu}
vEduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=tqvAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Ttya	wAlexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)xaswAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).ywawAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
P{g;wAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_zc]wAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux~gwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p}g{wAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)|g'wAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-isxAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}ixAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..gwwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target

er+V:eD
6b5e660e5d0921510f1a69a4692a914101958749fe11fe52afc2dfb4f09213c4D
c14a2c1aedcaa3d699f1c72757981d99ea27868828762056492a78d9705d6011D
ef4964d104e49faae860fc6c639d7d643ba1785fc33508588d20d8486431c33fD
d13238ab1217026e026ff8cdb5a027315b909e6962176287bb83b326f33c5f80D
f9676ddcb0d16744e15c0dea1da0d19db48f65f8b002b815347953e2a4f2bed8D
bacfb2cae8fa0a136505d13d9ba4f457a70110c92d232123563b0978aace5648D~
dbbd36394253b7a5eeea86bfcbbe4f0ab7aa133c3e762b34f7a4b0e3d3b138f4D}
00685f713fa548fd7e60ef95a370789739c4ef8bf55c1102f6d251548a251ed2D|
4cf77513a445cacd9183e8004a68488a4038ea670b7d8afe41da213c440c508aD{
826c87462956fa022a02326f271d542600fd73a7be32feb4eb7108cbc8b45eeeDz
1b2a2bdcb8f8539c6b2c875f6eb99acd1ce16f662f02b83d2dc3dd8e3408c5f6Dy
d7438560c82cb351cd0c021c2a6a0dc12a8235905b6ad52fac1aa4dfa0cb347fDx
6f44954e7559753b1cb37504f1b6070062ebd03b2055d1a1becc6179569b8472
CCTo;xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexi	xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|oxAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'xAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owxAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y	oExAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nxi	yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-
isyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
T
o;yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|oyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'yAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xi	zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAoyAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
To;zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|ozAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'zAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owzAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEzAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AozAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omzAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
t o{{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTo;{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2"ow{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|!o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""Y#oE{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A$o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-%om{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
(o'|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target'qO{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down&o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2+ow|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|*o|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t)o{|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y,oE|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A-o|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-.om|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?1q9|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)0qO|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down/o|Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
24ow}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|3o}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t2o{}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y5oE}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A6o}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-7om}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?:q9}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)9qO}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down8o}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2=ow~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|<o~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))h;qa}Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y>oE~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A?o~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-@om~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Cq9~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)BqO~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downAo~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2FowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Eq	~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hDqa~Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YGoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AHoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-IomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Lq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)KqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downJoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm OqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Nq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hMqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YPoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AQoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]bRC,RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{BȃBɃ	BʃB˃
B̃B̓B΃BσBЃBуB҃BӃBԃBՃBփ B׃"B؃#Bك$Bڃ%Bۃ(B܃+B݃,Bރ-B߃.B1Bჩ4B⃩5Bラ6B䃩7B僩:B惩=B烩>B胩?B郩@BꃩCB냩FB샩GB탩HBIBLBOBPBQBRBUBXBZB[B^BaBdBgBiBlBoCrCuCvCwCyC{C~CCC	CCC
C	C
CCCCCCCCCCCCC"C#C$C%C (C!+C",C#-C$.C%1C&4C'5C(6C)7C*:C+=
NN-RomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Uq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)TqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downSoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm XqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Wq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hVqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
AZoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=YqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-[omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?^q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)]qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down\oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm aqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|`q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h_qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.da}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenDc}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=bqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Ttga	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)fasAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yeaAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pig;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_hc]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxlgAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pkg{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)jg'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-oisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}niAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..mgwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTro;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cqk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexpi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|uoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tto{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
so'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2vowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YwoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nxyi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-xisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
T{o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]czk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|~oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t}o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
|o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]

er+V:eD
ddd921add46e38c9947a1be713846fcb866f41a25bf6671f3a81e65cc5ae6906D
c7826779aa132803da82be7ea0e99d8799ff4ebc7f93d26dee0731d8c1c9f25fD
f9b5b8e607b0475317be118a94288240012fe680504fba887596246d7173029fD
c4cc0146e823c14ccfdfc6e0d5991b3b44a23d81a1bc4c2e84d9dd55bed96730D

6764ea39a74b1ccba4e77eeb2236358817368cb8f0b3064e3a6fda6da289f363D
70d4d64cd1a4bf0b8b9ccc8e2cb0e8bc239ffd0632a796d2c869f55b6626defeD
7aa980726f441dcbdcee2948aec3a75da1f5fef953faeb2e9aa52c3d5818a4e8D

27381d0aaac8bd4271fb0d07366118b74445a7c2e330a29bed462dcbe88fad16D	
f0af2e9f5541fb785da048e6b6711cfb336457efd4dbe07344c3ed34aaacbea7D
8a5fd0b970dc3eb282790ae8ea380ab02a73599a63846085865e041e8624d19bD
1df29b4610f51702868338437a84151544ec5f149b1abd3299bec1abd9aebb57D
65a42ec733799dc8d274d0582c47380210b9ba82d7d6c4e9bb2f2cc9e93e54aeD
80846d26d36affb3de74ab705faf20f1ccf2d552bf0f63a19314ff38efed5522
To;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y	oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)

o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2"owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|!oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y#oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A$oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-%omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?(q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)'qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down&oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2+owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|*oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))h)qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y,oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A-oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-.omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?1q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)0qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down/oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[24owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|3q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h2qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y5oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A6oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-7omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?:q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)9qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down8oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm =qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|<q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h;qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y>oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A?oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-@omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Cq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)BqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downAoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm FqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Eq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hDqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
AHoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=GqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-IomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Lq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)KqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downJoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm OqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Nq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hMqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.Ra}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenDQ}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=PqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
TtUa	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)TasAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).ySaAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
PWg;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_Vc]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxZgAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pYg{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)Xg'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-]isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}\iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..[gwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT`o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c_k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex^i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|coAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tbo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
ao'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2dowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YeoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nxgi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-fisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
Tio;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]chk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|loAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tko{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
jo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2mowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YnoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xpi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAooAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
Tro;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cqk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|uoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tto{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
so'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2vowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YwoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AxoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-yomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
t|o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
{o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTzo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2~owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|}oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]

er+V:eD
f30bed050378d0ff2aec7c2fe523d1b6505bc116cce61a59687efe5e1d2a0014D
75d06c1bd614e9afb5bb7ee3df0687c26dd805b2c3b4430087f9db6565d30371D
62e79c444efc16b710b9f1e149bb3fee5abb2dea036b57e363ce6cc8d48b4c6dD
86216059235592e65e7652d91f110d715907836ae9f6759187c8cf877a851e69D
05ca51bffce88a4ceee7e70a17f2e81e550cbe1f0573836e157840cea3610e88D
979c4dddfa5465daad9544c21ea318624da5d9cd9873a573d52cbdeaaa74d14dD
0f278d26606d17a63d5e0da05a7bd5983a694993f71d76ab6409e00238f2d71bD
ab5ba7db71da82b8f11f7725428c46b6cf857fa74755c8a4626182781ec2a388D
7a8603cbba23f0fcd47e61e17dd4bc37f62141da71555814f5e89555fe2eb8f3D
26f837f65c41f6f8f28c88fd6f276825f409b924d8a0007694a7b9c158cc8d83D
3dc3c0c7d9f3c7865360c72790fdc0bb19b96e9e07fe98300e5e7443b0c5eec8D
f1543bd7c42d040f29b768234c950b37aba8c48f0e6347079bc3d83cd152f2b5D
efeaab4045eee3dabd94e6ae1b90d46bc4bc41180b4e0b8ceec3e018edace11d
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A	oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-
omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?
q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]bRCRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{C-?C.@C/CC0FC1HC2IC3LC4OC5RC6UC7WC8ZC9]C:`C;cC<dC=eC>gC?iC@lCAmCBnCCpCDrCEuCFvCGwCHxCIyCJ|CK~CLCMCNCOCQCRCS	CT
CU
CVCWCXCZC[C\C]C^C_C`Ca"Cb#Cc$Cd%Ce(Cf+Cg,Ch-Ci.Cj1Ck4Cl6Cm7Cn:Co=Cp@CqCCrECsHCtKCuNCvQCwRCxSCyUCzWC{ZC|[C}\C~^C`CcCdCeCfCgCjClCmCnCoCrCuCvCwCxC{C~
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2"owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|!q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y#oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A$oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-%omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?(q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)'qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down&oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm +qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|*q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h)qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y,oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A-oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-.omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?1q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)0qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down/oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 4qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|3q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h2qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
A6oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=5qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-7omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?:q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)9qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down8oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm =qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|<q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h;qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.@a}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD?}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=>qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
TtCa	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)BasAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yAaAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
PEg;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_Dc]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxHgAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pGg{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)Fg'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-KisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}JiAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..IgwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTNo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cMk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is FalsexLi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|QoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tPo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Oo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2RowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YSoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
NxUi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-TisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
TWo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cVk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|ZoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tYo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Xo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2[owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y\oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:x^i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationA]oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
T`o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c_k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|coAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tbo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
ao'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2dowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YeoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AfoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-gomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
tjo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
io'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTho;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2lowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|koAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YmoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AnoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-oomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
ro'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetqqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downpoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2uowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|toAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tso{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YvoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AwoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-xomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?{q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)zqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downyoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2~owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|}oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t|o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update

er+V:eD+
f3232baca2103d254d79671daddcba0c012aa020484304adc85d7cceaa00fab4D*
952a5dbe4255ec430a5d16b0eaadd30ef55d670c83a068d7b76ddc39ab2fd146D)
9a755fccab500090f9f294ce722c9245f42f0f67ffbc27667a08f8c94f0e706bD(
32c5eb73c64b93d71f0a965e4b0d4b50cc2363ac261d96c97b1440fb668e3e0fD'
a488570f9d11e747c97f57e3754398d4b317a95c8b12a89765afa51f7a8d5b3cD&
59316b28cf9e6cac60f1962177c09c08777c01cdecf6df02042c2f6d1ec3b15eD%
9c872d363d18d15dca6ce6002298b5b4812a2ca3a8743939cc98972ed12f7051D$
562d2ea97d59915b01db3a45495b50c8986b34604a13ff652057a9548b0b8c30D#
e4e12b73d5732eaf8ad672f5c847ce8d4099eb0f3f222ea7785a84bbb5c28f75D"
7c35e147b314a2db86256a9a76e58c2eb54bc2c62f2acdbcc0dafe986f0caff8D!
b8f63d0b7b046b2e21566cd9b7a99d818dc33c5c9b5f6176fcdeb296a99ad731D 
a33439122e1d6221585c619440d965d09ad0e9e2269f086ead9ef7cf4b84aaaaD
50933b6c70f520be21299ca43c2f9714dd3359dc1c4ac8f96290b572eea4c093
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A	oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-
omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?
q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm "qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|!q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
A$oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=#qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-%omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?(q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)'qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down&oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm +qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|*q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h)qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
..a}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD-}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=,qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tt1a	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)0asAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).y/aAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
P3g;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_2c]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux6gAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p5g{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)4g'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-9isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}8iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..7gwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT<o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c;k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex:i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|?oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t>o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
=o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2@owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YAoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
NxCi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-BisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
TEo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cDk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|HoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tGo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Fo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2IowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YJoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xLi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAKoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
TNo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cMk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|QoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tPo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Oo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2RowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YSoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AToAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]bRCRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{CCCCCC	C
C
CCCCCCCCCCC"C$C%C(C+C.C1C3C6C9C<C?C@CACCCECHCICJCLCNCQCRCSCTCUCXCZCƒ[CÃ\Că]CŃ`CƃcCǃdCȃeCɃfCʃiC˃lC̃mC̓nC΃oCσrCЃuCуvC҃wCӃxCԃ{CՃ~CփC׃C؃CكCڃC܃C݃	Cރ
C߃
CCჭC⃭CロC䃭C僭C惭C热!C胭$C郭'Cꃭ*C냭-C샭.C탭/C1C3C6C7C8C:C<C?C@
NN-UomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
tXo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Wo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTVo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2ZowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|YoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""Y[oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A\oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-]omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
`o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target_qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down^oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2cowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|boAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tao{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YdoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AeoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-fomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?iq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)hqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downgoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2lowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|koAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tjo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YmoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AnoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-oomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?rq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downpoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2uowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|toAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hsqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YvoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AwoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-xomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?{q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)zqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downyoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2~owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|}q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h|qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update

er+V:eD8
af95b47579ae105bbe84721bd483e536b8a004d3301c4efd6dc43296bb5dc441D7
8f47718dafddfb7d6dc1a738692f3af308d282de65b923b319975a317ee602d3D6
c0008274bc972c590974f8fd638093aa709f6a43093fe6fba3de63f4d87c0dc9D5
641422dc7cee4f12cf22bee612253cc8d91ac4de59d08779329152d5b123cecfD4
fdc3d5723bc3c1ed88713853d0c264f40ff05adf61533cdf99fc13598c015d19D3
42f4a67a0204be33ee75b48a1f31717570a6e3cf9551930351d405cd614f5ecbD2
0e83fd6b33039ac7fda9317c440371d5e1d6e4173afb995bd498be0589efbf51D1
c2704f809e155e3001e594ac90307613511c21fe04bb1d9422c1476b935f42faD0
0e2027754d28d80891f36030409114272ec237f698e5ff38e5ab7268da1dce52D/
68163138ff814f89bcf82178fed4293a777a5b62ff3a006bf4f80cc95692ff51D.
7213d0af79ee2d01cc5036dbcf46247c7d1adf8bfe1cf77ec8fb28e3b0dcc05cD-
61d2fe31693bd543dd103cf15e107e060b04ebfad13d914865e704aef9a7bfbcD,
04c9f6e177144af377d7c3b0185efb36ce85abfaba270ab01faefaf1cfa6837b
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A	oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-
omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?
q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.a}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tta	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)asAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yaAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
P!g;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_ c]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux$gAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p#g{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)"g'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-'isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}&iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..%gwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT*o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c)k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex(i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|-oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t,o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
+o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2.owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y/oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nx1i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-0isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
T3o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c2k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|6oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t5o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
4o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
27owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y8oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:x:i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationA9oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
T<o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c;k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|?oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t>o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
=o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2@owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YAoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ABoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-ComAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
tFo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Eo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTDo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2HowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|GoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YIoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AJoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-KomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
No'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetMqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downLoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2QowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|PoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tOo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YRoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ASoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-TomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Wq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)VqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downUoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2ZowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|YoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tXo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y[oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A\oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-]omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?`q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)_qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down^oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2cowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|boAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))haqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YdoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AeoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-fomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?iq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)hqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downgoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2lowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|kq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hjqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YmoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AnoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-oomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?rq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downpoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm uqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|tq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hsqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YvoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AwoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-xomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?{q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)zqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downyoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm ~qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|}q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h|qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.
a}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD	}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]

er+V:eDE
4da4812c211785ed6403e9aa77dbffbe1dd3d4a923d331a118e097ee72e34831DD
eed9c32dd42309910cb6b2852ea885380fc1241a6f30a2cfe2b358fb417a433aDC
82cc32e8088438f5d4fc7f78b91aff778d193cc5d296a1afeec04f69ee1134a3DB
3e3655960230e1c13e294b6c96c6ba573e155deb76a3ee8c62d3d2ff7b5bbc06DA
e7909f526d0702267a79ed10cb3c92dbaf4f95ac7cfc1fed8313c4c13a955925D@
69c508f0e20fb539180c31753dac2b1ea06cc63302811dd4f870628b72cc3f78D?
a8405254acf23fb0843ab4e7c57f3684eb7ec1a6feb932b5dd00185927c7d7adD>
ccec65f2954ca1f6ef27f02d35bd7687f0c4b6e784e48233282a82c2e5f53b7aD=
e65eedfb0130d1f3e59f5a4547b25b0e1994042c06fb9833816fdb384c062165D<
69af040152db8a48f4976d9b63fb954fae461308585661d36105e126da985f47D;
4b5b55c14d140a53eea4285b441202dc50e0ea78ec297bd568befaf65e5582faD:
cfa48cdc2568095e4f3d0e92a8d3efdec6838bb0b3f6920c55320674e7a2a3e3D9
7fceeee6972a71bd87c407e8be73b29da2cb7fdd6f2197b3e49fe3be552b0f0d
Tt
a	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)asAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yaAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pg;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_c]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxgAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pg{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)g'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..gwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper targetbRD\RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{CBCCCFCHCICJCKCNDQDRDSDTDWDZD[D\D]D	`D
cDdDeD
fDiDlDmDnDoDrDuDvDwDxD{D~DDDDD
D 
D!D"D#D%D&D'D(D)D*!D+$D,%D-&D.(D/*D0-D1.D2/D30D41D54D66D77D88D99D:<D;?D<@D=AD>BD?ED@HDAIDBJDCKDDNDEQDFRDGSDHTDIWDJZDK[DL\DM]DN`DOcDPdDQeDRfDSiDTlDUnDVoDWrDXuDYxDZ{D[}
CCTo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nxi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
T!o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|$oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t#o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
"o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2%owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y&oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:x(i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationA'oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
T*o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c)k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|-oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t,o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
+o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2.owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y/oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A0oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-1omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
t4o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
3o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetT2o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
26owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|5oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""Y7oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A8oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-9omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
<o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target;qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down:oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2?owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|>oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t=o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y@oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AAoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-BomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Eq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)DqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downCoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2HowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|GoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tFo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YIoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AJoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-KomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Nq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)MqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downLoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2QowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|PoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hOqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YRoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ASoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-TomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Wq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)VqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downUoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2ZowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Yq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hXqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y[oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A\oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-]omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?`q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)_qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down^oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm cqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|bq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]haqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YdoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AeoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-fomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?iq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)hqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downgoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm lqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|kq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hjqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
AnoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=mqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-oomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?rq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downpoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm uqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|tq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hsqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.xa}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenDw}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=vqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tt{a	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)zasAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yyaAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
P}g;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_|c]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxgAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pg{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)~g'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..gwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|	oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2
owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]

er+V:eDR
14c340f0dd683525dbfa9cc780253e123ac8b40391caeeaf7b12d5f35f96d7c0DQ
08fbafcced5e9e1b471e4e7dfdaf102a8d2a4b77e5322e88d818828f064c5242DP
30d6b8cd40a40000166c63a1a2cf163a33883ee83f065a500e90f56de33f8e1aDO
7733397737d974f9005123481470b631bef4144d428a07acd29c461f8073d83eDN
21f326e5f1282a6a5e71862e6a10e53257b80f7942532b86fc740c5060bd5d66DM
5a78d8d35284262a7fc70c262cad28716a7f9f4557e122fef43cf18904efeec0DL
874d8d26f7b80bc0f9296f56fd0bce77ced84db38f8562499930d8c065c0c040DK
6f9f0808ad0d78d8f4557bb41258ee0a449509e5f0cd09b1ef99660661d29109DJ
5a97b7da594519145c772a191ec16781f3e65f7befa1cb1697ae9bae09c6be3eDI
d06dbbf76b8b169c1b023c46e3216cb5da8af23e885d61da4c9547057c30c45cDH
d12ea2121d6e19b9305bc2887e981903b907ef5b7969c1672e397a125e33f070DG
844cd40a498923147207285c6be1f1005d82c0c81ce3d61538110f24c99a8732DF
2d56375cfa3857fe31113c74ef70da90917d1f03086e295520df01f2c0424fcb
Nx
i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
To;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
To;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
t"o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
!o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetT o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2$owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|#oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""Y%oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A&oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-'omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
*o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down(oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2-owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|,oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t+o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y.oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A/oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-0omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?3q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)2qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down1oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
26owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|5oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t4o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y7oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A8oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-9omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?<q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains);qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down:oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2?owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|>oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))h=qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y@oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AAoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-BomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Eq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)DqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downCoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2HowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Gq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hFqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YIoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AJoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-KomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Nq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)MqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downLoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]bRDRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{D]D^D_	D`
DaDc
DdDeDfDgDhDiDjDkDlDmDnDo"Dp$Dq%Dr&Ds'Dt*Du-Dv.Dw/Dx0Dy3Dz6D{7D|8D}9D~<D?D@DADBDEDHDIDJDKDNDQDRDSDTDWDZD\D]D`DcDfDiDkDnDqDtDwDxDyD{D}DDDDDD	D
DDD
DDDDDDDDDDDD"D%D&D'D(D+D.D/D0D1D2D5D8
mm QqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Pq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hOqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YRoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ASoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-TomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Wq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)VqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downUoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm ZqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|Yq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hXqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
A\oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=[qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-]omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?`q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)_qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down^oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm cqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|bq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]haqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.fa}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenDe}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=dqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Ttia	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)hasAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).ygaAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pkg;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_jc]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxngAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pmg{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)lg'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-qisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}piAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..ogwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTto;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]csk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexri	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|woAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tvo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
uo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2xowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YyoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nx{i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-zisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
T}o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c|k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
~o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
To;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|	oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2
owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-
omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]

er+V:eD_
39eda1390e30c1d89d4a235798a2680748e9b2b95ad2b6a7c76d547977b8afa3D^
9e05956f580c985a939dbd279aa13ca665ba62cb3985fe2751b38a299b82115dD]
5cbbd37d7f37600583b60a26e2cd6b0287db9cbef15816447152aa601ab00a32D\
6461bbe99176941777ad3a8221e32a189aa802b7e481a45accd4ea4f5b8b1377D[
aa3af962872bcc364488d71c63463081dff2f68de76fd90b78d2d47d65c9f42aDZ
fbc77f001aab9462525aa44d833841b0d3687718322240a9c0df2ea113689697DY
2cece1860f84d0ba0608689920352f54328bbb5bd72c2369c2023db772c8d3b5DX
ecfb16cf527793f6ec8118a181cf88df17babbdd3805563e4cd5e75bfa4846d1DW
250a28dac3da0fc3f250e7d3e7690254c46a1dd5d2663f2573ba5efdae5e0909DV
79f38750b9d405228c1da2c38370aaa60d7421ed5671c4a1dbd4e0c5308606b7DU
d382251ecdf030132bcf5b89fcc80c1ec3dfeb1e41cca0d840d735c44e371ed4DT
b554c183bd7760a4c29b178039f5b3746c8549c6a6d40686cd8b4f7a5314ba26DS
c72baaba3b68e23ad5857f22697380908c1ca9201e4bbe875f13601fc99a9465
to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
|To;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
"o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target!qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2%owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|$oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t#o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y&oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A'oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-(omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?+q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)*qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down)oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
wqxw|.oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t-o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
,o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2/owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y0oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A1oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-2omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?5q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)4qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down3oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
28owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|7oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t6o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y9oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A:oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-;omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?>q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)=qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down<oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t@o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)h?qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2BowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YCoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ADoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-EomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Hq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)GqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downFoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2KowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|JoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hIqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YLoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AMoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-NomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Qq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)PqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downOoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
|ToAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))|Sq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hRqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2UowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YVoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AWoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-XomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?[q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)ZqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downYoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2^owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|]q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h\qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y_oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A`oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-aomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?dq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)cqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downboAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm gqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|fq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]heqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
2howAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YioEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AjoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-komAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?nq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)mqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downloAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|pq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hoqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YroEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AsoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-tomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?wq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)vqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downuoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm zqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|yq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hxqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
={qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
""Y|oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A}oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-~omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest updatebRE'RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{DÃ:Dă;DŃ>DƃADǃBDȃCDɃDDʃED˃HD̃KD̓LD΃MDσNDЃQDуTD҃UDӃVDԃWDՃXDփ[D׃^D؃_Dك`DڃaDۃdD܃gD݃hDރiD߃jDkDჰnD⃰qDヰrD䃰sD僰tD惰wD烰zD胰{D郰|Dꃰ}D냰~D샱D탱DDD
D
DDDDDDDD"D%D'D)D,E/E2E5E6E7E:E<E?E@E	AE
CEEEHE
IEJELEOERESETEVEXE[E\E]E^E`EbEeEfEgEhE iE!lE"nE#oE$pE%qE&t
AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?
q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)	qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 
qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
//AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]D}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]

er+V:eDl
d7513536c9026fa249a909d4498e9e94991fd98da6b1a4b02d60b054ce605018Dk
90ee404ae7f217e125818a3a078d8727a3d722574a1fe488df803a8e74e702b8Dj
a7fd672c3ffb0bf842870e9f89f527fa381c0095f942e64501bc861b9e8f3d67Di
cbe559a32b73c61ade8a92a3d95bf1f0a39b70082feed6bbf79aaff46a5ddf19Dh
4daf83f9424e98f68f851994a49d811bd5721394db482d92ed7f2062337bafd9Dg
4e67706fef5e2721101385bb71163dd6a70a46cdc7b46ca2c10b2007847ad2f0Df
c6779b89961037e58b7567513d65d8d4840f1a7a23bade7e22a9b02e8b3af7b6De
c1655691384373ba1d496ebdba513f6a4f1ad2c2e6ffd5b7985a6702890f6d58Dd
f03348b00055f767dc054a8e674751bceb513c92df57c9bdfdd52dbc987da25aDc
ff9511b80fc18b09e37c9c11c984d322a95ec84172a9fafabc4b068d7d854bc4Db
413133e05ac7cf1be0030800e9f11f9f92b4cfd832e8cd453bf6a9b75994fe86Da
c1cd4eb34426e59fd5e537c63a1cf87b0239c01779661465731ea826a0cbe7d8D`
bea336c1c8f050927b1a639ba83b0ad350d97d65f1c37c25a38e1418af07f9e4
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.a}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tta	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)asAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yaAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pg;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_c]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux"gAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p!g{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete) g'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
y%aAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..$a}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen.#gwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
Rt'a	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)&asAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
P)g;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_(c]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux,gAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p+g{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)*g'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-/isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}.iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..-gwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT2o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c1k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex0i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|5oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t4o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
3o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
26owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y7oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Lx:i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-9isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}8iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
T<o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c;k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|?oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t>o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
=o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2@owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YAoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
NxCi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-BisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
TEo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cDk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|HoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tGo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Fo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2IowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YJoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:-LisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).AKoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
CCTOo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cNk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is FalsexMi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|RoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tQo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Po'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2SowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YToEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xVi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAUoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
TXo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cWk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|[oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tZo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Yo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2\owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y]oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A^oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
Nx`i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-_omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
Tbo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cak]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|eoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tdo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
co'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2fowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YgoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AhoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-iomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
tlo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
ko'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTjo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2nowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|moAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YooEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ApoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-qomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
to'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetsqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downroAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2wowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|voAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tuo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YxoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AyoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-zomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?}q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)|qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down{oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t~o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2	owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y
oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update

er+V:eDy
bd8a86b08520baae3c12fc08ce56e105878e1607594deb88f00c1675d75ef7d1Dx
53566f9e1bd64ce95963cf88dab607767e896835057ff6634b9a8518b3310365Dw
33d941826eff0dae2edb97052b2bc115956b725729096f5428d558679c2c50b1Dv
67a0b1ce4f650123760a584297eade73a87e8a5cd69ee80b0de1e46c6734c7e0Du
bf168312334f60bf2d480510b014eddac0d80a449ec219c38682ae29ad20259dDt
4d57a9eb757639f05691dc0a674b6cde76770c459608cab6a9a6bc054d091f7fDs
c86d5aac322f831336236ac7648dc4aad9c1aba665e21ec635d36c1ca14d7092Dr
3e3ebfa1eb1b1cf926276a074c1b8bf839ea1353d1334f5304dbd50d4721979fDq
81ccbdfa61dd66d66bcfc3a8b2aa34c860aeeca888655db0c4a47cfc4855210cDp
05a0c90006b42933811046c1278ba1584b25ae8404694f0d692582422b132360Do
48a43cbf24e5cc56899ebdd66e5c0f3d2fe213629ce3c7debc96435077102d8dDn
e027d56a8d05e8044b59f1f1d0ff564fabaec69db38c5a78c6eedad992bd0ca0Dm
d38b342552cd6a20a2dfc066035f36eb0359a01a38100cddf5da31c8b7880c92
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?!q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains) qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm $qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|#q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h"qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
A&oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=%qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-'omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?*q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains))qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down(oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm -qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|,q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h+qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.0a}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD/}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=.qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tt3a	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)2asAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).y1aAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
P5g;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_4c]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux8gAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p7g{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)6g'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-;isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}:iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..9gwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT>o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c=k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex<i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t@o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
?o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2BowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YCoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
NxEi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-DisAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
TGo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cFk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|JoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tIo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Ho'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2KowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YLoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]bRERY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{E(xE)yE*zE+}E,E-E.E/E0E1	E2
E3E4E5E6E8E9E:E;E<E=E>E?E@!EA$EB&EC'ED*EE-EF0EG3EH5EI8EJ;EK>ELAEMBENCEOEEPGEQJERKESLEUNEVPEWSEXTEYUEZVE[WE\ZE]\E^]E_^E`_EabEbeEcfEdgEehEfkEgnEhoEipEjqEktElwEmxEnyEozEp}EqErEsEtEuEv	Ew
ExEyEzE{E|E~EEEE!E#E&E)E,E/E0E1E3E5E8
:xNi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAMoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
TPo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]cOk]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|SoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tRo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Qo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2TowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YUoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AVoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-WomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
tZo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Yo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTXo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2\owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|[oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""Y]oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A^oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-_omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
bo'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetaqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down`oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2eowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|doAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tco{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YfoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AgoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-homAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?kq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)jqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downioAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2nowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|moAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tlo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YooEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ApoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-qomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?tq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)sqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downroAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2wowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|voAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))huqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YxoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AyoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-zomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?}q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)|qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down{oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h~qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm 	qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y
oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down
oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]

er+V:eD
4e8a4eb320294b8d3f17b50efaf7163b718c714032a6266f8778c53722127d3cD
0e9f601a50df8e60748b538e0a74fbb3fe326ce3a54a551b7a254c64afcf272fD
4f3a3cf03d964bc88b6358c7506edcacfae9e90eca37a578abe76cb85f497a8eD
08863f9fce74c908ee529b7d6877678e4993d6800fa0e1f5ee19afd4c79373a6D
d5777f8c7d443792e6a87299514e3e7da9cb0ffc7ebac5512e40867a84aa7427D
bac160608046f1b8a53fee2478c1cf5eacbd98780405257d17db4aa0e88221e9D
8ab724702b39a664d2114819b5f3c29149c945a1f5443d7e7e4672d694b15c90D
d1505aaf07075307e949adfd5133dbffded6e90d371bddf5dd1e04c913a8a7b7D~
da5e7ca2931d95eff55acb5a19e8a5281ca44689ee64bfee2a30b12163c91f83D}
879103353158ba94017ff99828895da2eeec60fae6276746aa90627aa3867891D|
aca852521c8ca141634a0215e5e3383f36ca6fe54031a695fd5bae627b1891ecD{
3a2ad8e88cf0956c1a2c89acc48514e79526a2cfa14023dee71a714c83ea1779Dz
fa23e5ba8d9b56049a550f17e94cd3178b35786e85c7098ea8f409f9cd1bd8c2
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.a}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tt!a	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization) asAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).yaAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
P#g;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_"c]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
ux&gAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))p%g{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)$g'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-)isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}(iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..'gwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCT,o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c+k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsex*i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|/oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t.o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
-o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
20owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y1oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nx3i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-2isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
T5o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c4k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|8oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t7o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
6o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
29owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y:oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:x<i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationA;oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
T>o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c=k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t@o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
?o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2BowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YCoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ADoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-EomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
tHo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
Go'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetTFo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
2JowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|IoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""YKoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ALoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-MomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
Po'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetOqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downNoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2SowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|RoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tQo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YToEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AUoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-VomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Yq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)XqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downWoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2\owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|[oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tZo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""Y]oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A^oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-_omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?bq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)aqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down`oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2eowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|doAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hcqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YfoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AgoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-homAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?kq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)jqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downioAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2nowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|mq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hlqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YooEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ApoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-qomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?tq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)sqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downroAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm wqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|vq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]huqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YxoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AyoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-zomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?}q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)|qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down{oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]h~qaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
AoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?q9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)qOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]bRERY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{E:E<E>EAEBECEDEEEHEJEKELEMEPESETEUEVEYE\E]E^E_EbEeEfEgEhEkEnEoEpEqEtEwExEyEzE}EEEEE	EEEEEEEƒEÃEăEŃ!Eƃ#Eǃ&Eȃ'EɃ(Eʃ*E˃,Ẽ/E̓0E΃1Eσ2EЃ3Eу6E҃8EӃ9Eԃ:EՃ;Eփ>E׃AE؃BEكCEڃDEۃGE܃JE݃KEރLE߃MEPEჴSE⃴TEヴUE䃴VE僴YE惴\E烴]E胴^E郴_EꃴbE냴eE샴fE탴gEhEkEnEp
mm 	qQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|q	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.a}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenD}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=
qAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tta	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)asAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).y
aAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pg;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_c]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxgAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pg{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)g'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..gwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target

er+V:eD
5df1c4a4149790ce8d3fed738d0a047014ad764f90ad0dcf2d4fb022afde1ac4D
39c2715a2db8a65b7a5d313ddb5b14fd5c9c71fa1a03989786099e82c0e41522D
8d3bcb06b72e062aa3717dc899aa7260d669eb53ff0fc27e1090f66617498a96D
8eb970d9067e83d78cc7fabc26ab7bd356ac7bdd924f37cc65f1880942065026D
9f7d0b1438c902e19bff1151a338f2bc62e101701aa2cc4c684d09ef8a941fe7D
6cd845a6c8f106877b1240c8be24cc3b931a354a08536833f36917d64f2c3a8aD

85419f90d3d3f07662a30384cc8ac45f87402b540d725dd0f8c9705d2c814733D
31a00a78690dbd25c399c0d6dc257233ed9c90313969f69bafac3ab599e0a3f5D
76ef31892a454a03675c6f23a831bedd4e585942eccd9b529c271b8ad2e600dbD

9e34155e9955877814c45bc4c249bf6c38112821f536ccc4baefe4ed42298b48D	
e6594c28667d65623967ed4dcb33fb0e473593cd3c65b2b17b0828490986f908D
20f4ac29a67806ff93314f45fbaeb1158df4cfcdc8bcedf26aa23f8d8449da24D
56bf7e797eed9d37f2dce5d87422a5e569612928a7a5e9eebbca059550ad9245
CCTo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nx!i	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
T#o;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c"k]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|&oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t%o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
$o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2'owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y(oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:x*i		Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationA)oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
T,o;	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]c+k]	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|/o	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t.o{	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
-o'	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
20ow	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y1oE	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A2o	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-3om	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
t6o{
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
5o'
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper targetT4o;
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
28ow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|7o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
""Y9oE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A:o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-;om
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
I|I
>o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target=qO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down<o
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2AowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|@oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t?o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YBoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ACoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-DomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Gq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)FqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downEoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
2JowAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|IoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))tHo{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
""YKoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::ALoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-MomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Pq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)OqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downNoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2Sow
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|Ro
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))hQqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YToE
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AUo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-Vom
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?Yq9
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)XqO
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downWo
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
[[2\owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target|[q	
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hZqa
Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""Y]oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A^oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-_omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?bq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)aqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down`oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm eqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|dq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hcqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
""YfoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::AgoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
NN-homAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?kq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)jqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downioAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm nqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|mq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]hlqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
ApoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]=oqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
NN-qomAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
?|?tq9Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.11a(@- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot.
- Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline
- Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)sqOAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.10a- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is downroAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.9a- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z]
- Resolves: rhbz#1968330 - id lookup is failing intermittently
- Resolves: rhbz#1964415 - Memory leak in the simple access provider
- Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]
mm wqQAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.14cs@- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z]
- Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z]
- Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]|vq	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.13b2@- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z]
- Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]huqaAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.12a@- Resolves: rhbz#2006382 - IPA Intermittence fetching groups
- Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name
- Resolves: rhbz#2031729 - IPA clients fail to resolve override group names.
- Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update
.za}Alexey Tikhonov <Alexey Tikhonov> 1.16.5-6^- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading
- Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screenDy}
Eduardo Lima (Etrunko) <etrunko@redhat.com> 1.16.5-10.16eV@- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]=xqAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.15c
@- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z]
- Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]
Tt}a	Alexey Tikhonov <Alexey Tikhonov> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization)|asAlexey Tikhonov <Alexey Tikhonov> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).y{aAlexey Tikhonov <Alexey Tikhonov> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.
Pg;Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]_~c]Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
uxgAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))pg{Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)g'Alexey Tikhonov <Alexey Tikhonov> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
-isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).}iAlexey Tikhonov <atikhono@redhat.com> 1.16.5-7^m@- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing
- Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process..gwAlexey Tikhonov <Alexey Tikhonov> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
CCTo;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is Falsexi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization
wqxw|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))t
o{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
	o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""Y
oEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
Nxi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization-isAlexey Tikhonov <atikhono@redhat.com> 1.16.5-8^V@- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration.
- Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers.
                           It is done in two steps (two different nsupdate messages).
To;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
:xi	Alexey Tikhonov <atikhono@redhat.com> 1.16.5-9^@- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 LocalizationAoAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]

er+V:eD 
7506ca728020b82295ffed2418c27fbcdc236ff1ef18d4ad5b231beae0f3defeD
42d201c11113e97e1033dde57dbe80c43d0b96fe2894ca9d7448018fc605c871D
c97d7ef5a7b53916750b597fabf99dee5bcb2c1e382ef0e3d179ca285ccaefd7D
ffb599a2b9c5f8a8a237f321581e0fdbab30bb4d57604ff0a504dd1222938ebfD
e73fb6987d2e8000602d878eae68fcb1f8b4dce3a67fe1e988767ef5a8c5677cD
cb0dd1d2921d86e3d93f0eded02f6d9dd60ff0961589b65e59561cf10654d493D
5fe799d217f2dcf27b8e40b81b8417542ff242f26f79a7436f2f1834b7ed2461D
efe92dccaf584ac534e20c985a62a2b2030dbbc1cac6586eb9de81ac5dcc7acdD
f2c9f87c9483b4181bdafd6a1753e97a9f5dcfc18ea6c72e9295ea06d7048933D
55c1b8836656a45aac1437e8175add10dff725b5c7b26b850730b4562282349cD
ad45990c26c50265b45cd64260502befba1696f09e6e431e28ae011baab8f4abD
7c03b652e1b0cb7c5ebe1d7b4c4e230bff7b2cc8cb68a40c51541d017458d4acD
708afa796fdb709f3e98d685f94be58af8cefd4ff05ab6d0a215d63d47cff237
To;Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.1_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]ck]Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10^3- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management
- Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information
- Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card
- Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False
wqxw|oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.4_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))to{Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.3_=@- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete)
o'Alexey Tikhonov <atikhono@redhat.com> 1.16.5-10.2_;- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z]
- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
- just bumping the version to build for proper target
2owAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.5_H- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]
  (Previous attempt to fix this issue was incomplete (again))
- just bumping the version to build for proper target
""YoEAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.6_G@- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z]
- Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z]
- Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z]
- Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z]
- Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z]
- Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z]
- Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z]
- Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]
::A oAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.7_
- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z]
- Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z]
- Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]
]N]c#k_Eugene Syromiatnikov <esyr@redhat.com> - 4.12-8[P}@- Update membarrier constants. (#1600210)"k!Eugene Syromiatnikov <esyr@redhat.com> - 4.12-7Z@- Return non-zero exit code if no processes have been attached. (#1573034)-!omAlexey Tikhonov <atikhono@redhat.com> 1.16.5-10.8`@- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z]
- Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z]
- Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z)
- Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z]
- Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]
7'k;Eugene Syromiatnikov <esyr@redhat.com> - 4.24-3]i- Include commit v4.26~65 "s390x: beautify sthyi data tail prints"
- Resolves: #17474754&kEugene Syromiatnikov <esyr@redhat.com> - 4.24-2]g@- Copy over changes in tests/ioctl_evdev-success.c (from cdd8206a
  "tests: test evdev bitset decoding more thoroughly")
  to tests-m32/ioctl_evdev-success.c and tests-mx32/ioctl_evdev-success.c
- Copy over changes in tests/ioctl_evdev.c (from 5ee385e2
  "evdev: fix decoding of EVIOCGBIT(0, ...)") to tests-m32/ioctl_evdev.c
  and tests-mx32/ioctl_evdev.c
- Resolves: #1746478%k5Eugene Syromiatnikov <esyr@redhat.com> - 4.24-1]B@- Rebase to strace 4.24. (#1659983)
- Enable stack unwinding (-k option). (#1655856)x$kEugene Syromiatnikov <esyr@redhat.com> - 4.12-9[S @- Patch files in tests-m32 and tests-mx32 as well. (#1600210)
M<Mj*kkEugene Syromiatnikov <esyr@redhat.com> - 4.24-6^H- Fix expected alignment for IPC tests (#1795261):
  4377e3a1 "tests: fix expected output for some ipc tests", and
  a75c7c4b "tests: fix -a argument in ipc_msgbuf-Xraw test"._)kUEugene Syromiatnikov <esyr@redhat.com> - 4.24-5^H- Fix printing stack traces for early syscalls on process attach (#1790052):
  69b2c33a "unwind-libdw: fix initialization of libdwfl cache" and
  8e515c74 "tests: add strace-k-p test".
- Add commit v5.4~97 "xlat: use unsgined type for mount_flags fallback values"
  (A leftover for #1747524).[(kMEugene Syromiatnikov <esyr@redhat.com> - 4.24-4]i- Include upstream patches that fix issues reported by covscan:
  91281fec "v4l2: avoid shifting left a signed number by 31 bit",
  522ad3a0 "syscall.c: avoid infinite loop in subcalls parsing", and
  9446038e "kvm: avoid bogus vcpu_info assignment in vcpu_register".
- Resolves: #1747524
L}n.gwWilliam Poteat <wpoteat@redhat.com> 1.24.38-1^V@- 1837244: Fix wrong version provided by subscription-manager version; ENT-2388
  (jhnidek@redhat.com)
- 1834792: Try to terminate rhsmd after timeout; ENT-2368 (jhnidek@redhat.com)m-guWilliam Poteat <wpoteat@redhat.com> 1.24.37-1^I- 1830994: Fix warning messages in dnf/yum (jhnidek@redhat.com)
- 1823523: Detect rhsm-icon running without psutil (csnyder@redhat.com)
- 1771921: Package profiles sends too early when registering a client
  (wpoteat@redhat.com)
- 1688702: Generate redhat.repo in off-line mode; ENT-2302 (jhnidek@redhat.com)J,g/William Poteat <wpoteat@redhat.com> 1.24.36-1^U@- 1831104: When in Simple Content Access mode, subscription-manager should not
  complain that subscriptions aren't attached (wpoteat@redhat.com)/+kuEugene Syromiatnikov <esyr@redhat.com> - 4.24-7aՈ@- Fix incorrect ifname printing buffer size (#2028146):
  e27b0677 "print_ifindex: fix IFNAME_QUOTED_SZ definition".
>a92oChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)X1gKWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)y0oChristopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)@/oChristopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)
> >@6oChristopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)5gKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)4gAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)C3oChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
C:oChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)99oChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)X8gKWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)y7oChristopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)
hj}?o
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)>o!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P=o3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)<gKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com);gAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)
#eCgAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CBoChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9AoChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)X@gKWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)
cIoCChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FHoChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}Go
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)Fo!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)PEo3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)DgKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
BbMgKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)LgAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CKoChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9JoChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)
+SRoCChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FQoChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}Po
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)Oo!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)PNo3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
7UgAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CToChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)|SoChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)
c[oCChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FZoChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}Yo
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)Xo!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)PWo3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)VgKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
|\oChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
L_gKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)^gAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)']ekPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
+SdoCChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FcoChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}bo
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)ao!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P`o3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
|eoChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
KLKhgAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)egamJiri Hnidek <jhnidek@redhat.com> 1.24.52-2d.@- 2229752: Fix D-Bus policy (jhnidek@redhat.com)'fekPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
cnoCChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FmoChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}lo
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)ko!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Pjo3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)igKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
|ooChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)bRFeRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{EtEwEzE}EEEEEEE
EEFFFFFFFFF	 F
#F'F*F
.F2F6F:F?FCFIFMFRFUF[F\F_FdFeFhFnF oF#pF$tF%xF'yF(|F)F*F+F,F-F.F/F1F2#F3(F4,F6/F74F85F:8F;>F<?F>@F?DF@HFBIFCLFDOFESFFXFG\FHaFIfFJjFKoFLsFMxFN|FPFQFRFTFUFVFXFYFZF\F]F_F`#Fa(Fb,Fc1Fd6@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'pekPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF"
to!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Pso3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)rgKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)pqe}Pino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
|xoChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)woCChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FvoChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}uo
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'yekPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF&
tCtJ|g/William Poteat <wpoteat@redhat.com> 1.24.36-1^U@- 1831104: When in Simple Content Access mode, subscription-manager should not
  complain that subscriptions aren't attached (wpoteat@redhat.com)C{Q7Pino Toscano <ptoscano@redhat.com>e@- tito: drop bz requirement (ptoscano@redhat.com)
- fix: 1.24 Add python-requests to the list of required RPMs
  (jhnidek@redhat.com)
- fix: Pin lxml to last version supporting Python 2 (mhorky@redhat.com)
- fix: Add missing package intltool to test script (jhnidek@redhat.com)pze}Pino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
VV@oChristopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)n~gwWilliam Poteat <wpoteat@redhat.com> 1.24.38-1^V@- 1837244: Fix wrong version provided by subscription-manager version; ENT-2388
  (jhnidek@redhat.com)
- 1834792: Try to terminate rhsmd after timeout; ENT-2368 (jhnidek@redhat.com)m}guWilliam Poteat <wpoteat@redhat.com> 1.24.37-1^I- 1830994: Fix warning messages in dnf/yum (jhnidek@redhat.com)
- 1823523: Detect rhsm-icon running without psutil (csnyder@redhat.com)
- 1771921: Package profiles sends too early when registering a client
  (wpoteat@redhat.com)
- 1688702: Generate redhat.repo in off-line mode; ENT-2302 (jhnidek@redhat.com)
CoChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9oChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XgKWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)yoChristopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)
,h	,XgKWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)yoChristopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)@oChristopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)gKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)
BbgKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)C
oChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9	oChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)
+A9o Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XgK William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)}o
Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)o!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P
o3Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
" "o! Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3 Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)gK William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gA William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)Co Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
YY9o!Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)oC Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)Fo Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
 Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)

er+V:eD-
0894834781a35f76e011fd41d9cf3bae6d4a47dcb32589aea06d68f2b07ad20eD,
9fd5c36a0b8c70c04630c8224b3fcace1a47b80691c908ee62b4bcabac65bf5fD+
d062a6b1a3c9142376097e0924927205723ac2f41ee8c930c3758a81a1d31221D*
14ceaab30f17021789efedfc14f87608192f961f1318dd5bdb9c1278c54aad96D)
3a214c9b7993ff445157cc339c9a34103eea57c31ad42b15dba0db83b51bcda9D(
06cf0f65aa64e614d4aa2f4b52af2b2c2e8e6420e1a748807f9d326ed353d4b6D'
08c0606b2ec5ba2bb66a3ee30f97a269ff8da7cdfc8a081d621411fc68286e09D&
f84205da14142e8d12abc39e3d5796ac7bb70e93f90df0226c6de1e7ee119da1D%
da38341360f5d41b718df71ed8a4ab57fe1fb09ba331c4f1da5fd6729ab4d567D$
7ffb232f1c8d11186c79f3208453ffcfe309aa5cb3a09181ea598fc82f582228D#
18ced00cd6c1f923fc88ba96abb6a1ffa4ccb1baa01b41e22d2c729310d6def7D"
e6780d4f50b1f42151e1c147e42bdba85660cca20eb7f459aa271886818f9058D!
fa313558117870b2ad9b85826be67b6ecce53baa6ddcbf99024428840d38fba7
" "o!!Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3!Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)gK!William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gA!William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)Co!Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|#o!Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)"oC!Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F!o!Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)} o
!Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "(o!"Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P'o3"Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)&gK"William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)%gA"William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)C$o"Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|,o"Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)+oC"Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F*o"Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)})o
"Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
L/gK#William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com).gA#William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)'-ek"Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF5
+S4oC#Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F3o#Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}2o
#Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)1o!#Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P0o3#Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
|5o#Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
KLK8gA$William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)e7am#Jiri Hnidek <jhnidek@redhat.com> 1.24.52-2d.@- 2229752: Fix D-Bus policy (jhnidek@redhat.com)'6ek#Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF9
c>oC$Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F=o$Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}<o
$Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com);o!$Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P:o3$Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)9gK$William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
|?o$Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'@ek$Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF=
Do!%Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)PCo3%Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)BgK%William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)pAe}$Pino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
|Ho%Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)GoC%Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FFo%Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}Eo
%Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'Iek%Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekFA
tCtJLg/&William Poteat <wpoteat@redhat.com> 1.24.36-1^U@- 1831104: When in Simple Content Access mode, subscription-manager should not
  complain that subscriptions aren't attached (wpoteat@redhat.com)CKQ7%Pino Toscano <ptoscano@redhat.com>e@- tito: drop bz requirement (ptoscano@redhat.com)
- fix: 1.24 Add python-requests to the list of required RPMs
  (jhnidek@redhat.com)
- fix: Pin lxml to last version supporting Python 2 (mhorky@redhat.com)
- fix: Add missing package intltool to test script (jhnidek@redhat.com)pJe}%Pino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
VV@Oo&Christopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)nNgw&William Poteat <wpoteat@redhat.com> 1.24.38-1^V@- 1837244: Fix wrong version provided by subscription-manager version; ENT-2388
  (jhnidek@redhat.com)
- 1834792: Try to terminate rhsmd after timeout; ENT-2368 (jhnidek@redhat.com)mMgu&William Poteat <wpoteat@redhat.com> 1.24.37-1^I- 1830994: Fix warning messages in dnf/yum (jhnidek@redhat.com)
- 1823523: Detect rhsm-icon running without psutil (csnyder@redhat.com)
- 1771921: Package profiles sends too early when registering a client
  (wpoteat@redhat.com)
- 1688702: Generate redhat.repo in off-line mode; ENT-2302 (jhnidek@redhat.com)
CSo&Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9Ro&Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XQgK&William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)yPo&Christopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)
,h	,XXgK'William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)yWo'Christopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)@Vo'Christopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)UgK&William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)TgA&William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)
Bb\gK'William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)[gA'William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CZo'Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9Yo'Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)
+A9ao(Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)X`gK(William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)}_o
'Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)^o!'Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P]o3'Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
" "fo!(Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Peo3(Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)dgK(William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)cgA(William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)Cbo(Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
YY9jo)Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)ioC(Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)Fho(Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}go
(Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "oo!)Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Pno3)Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)mgK)William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)lgA)William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)Cko)Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|so)Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)roC)Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)Fqo)Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}po
)Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "xo!*Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Pwo3*Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)vgK*William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)ugA*William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)Cto*Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
||o*Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com){oC*Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)Fzo*Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}yo
*Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LgK+William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)~gA+William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)'}ek*Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekFO
+SoC+Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)Fo+Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
+Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)o!+Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3+Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
|o+Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
KLKgA,William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)eam+Jiri Hnidek <jhnidek@redhat.com> 1.24.52-2d.@- 2229752: Fix D-Bus policy (jhnidek@redhat.com)'ek+Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekFS
coC,Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F
o,Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
,Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)o!,Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P
o3,Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)	gK,William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
|o,Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'ek,Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekFW
o!-Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3-Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)gK-William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)pe},Pino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
|o-Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)oC-Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)Fo-Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
-Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'ek-Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF[
tCtJg/.William Poteat <wpoteat@redhat.com> 1.24.36-1^U@- 1831104: When in Simple Content Access mode, subscription-manager should not
  complain that subscriptions aren't attached (wpoteat@redhat.com)CQ7-Pino Toscano <ptoscano@redhat.com>e@- tito: drop bz requirement (ptoscano@redhat.com)
- fix: 1.24 Add python-requests to the list of required RPMs
  (jhnidek@redhat.com)
- fix: Pin lxml to last version supporting Python 2 (mhorky@redhat.com)
- fix: Add missing package intltool to test script (jhnidek@redhat.com)pe}-Pino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)

er+V:eD:
3120b8ac49c833eac5d65d84950dd53543736014e6974e6d7d1939f63c988544D9
81962e4767ff3bdd232b266847805d5a9914ba7ee1f405ee6212d3e9a2ea45d0D8
7712f39d03fe27ce44ff48e5aea72a3011bc46509644b864641c2f3fd7d54e15D7
d684dd221be8f63b6422400e18992182df125fe9108dd93f3afba9a92561c1ecD6
ce1840da43b758b433ff86f3ea7b59008e2d64a9f66fed798463409de17511c4D5
0de8a90ff171bad788a3e83dfb9e880aedf1440a7e0e201037073ea3c6af5caeD4
5ecc9b46e51b23acaedd89900ee220b11e9dfca92b98fe38fe0234b8ff122142D3
7c74b103220013bb9c00f724937c12e143a5ce16e2b00ff71a37c5201ed308e0D2
b3c76329ae932f3e67af5a1fe06c2e761c855d1039dd424d7c441f8c548f297eD1
758b00bfddac1117f7a640983316c5c512053334e60eb19cc2b8b9bd616cc341D0
d5d036f0277fc2ae76a968b607924ea30394398f7a0e5d8a355d14f7c35960f5D/
92d0aa22a8ae445d70ea7fb4531c9e4056b5c852123fd61e665f8a3007539408D.
709d5075348bcccbd422a85b699ee6d907bff4255b77146b10e04b6ed5924e09
VV@o.Christopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)ngw.William Poteat <wpoteat@redhat.com> 1.24.38-1^V@- 1837244: Fix wrong version provided by subscription-manager version; ENT-2388
  (jhnidek@redhat.com)
- 1834792: Try to terminate rhsmd after timeout; ENT-2368 (jhnidek@redhat.com)mgu.William Poteat <wpoteat@redhat.com> 1.24.37-1^I- 1830994: Fix warning messages in dnf/yum (jhnidek@redhat.com)
- 1823523: Detect rhsm-icon running without psutil (csnyder@redhat.com)
- 1771921: Package profiles sends too early when registering a client
  (wpoteat@redhat.com)
- 1688702: Generate redhat.repo in off-line mode; ENT-2302 (jhnidek@redhat.com)
C#o.Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9"o.Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)X!gK.William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)y o.Christopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)
,h	,X(gK/William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)y'o/Christopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)@&o/Christopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)%gK.William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)$gA.William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)
Bb,gK/William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)+gA/William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)C*o/Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9)o/Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)
+A91o0Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)X0gK0William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)}/o
/Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com).o!/Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P-o3/Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
" "6o!0Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P5o30Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)4gK0William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)3gA0William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)C2o0Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
YY9:o1Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)9oC0Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F8o0Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}7o
0Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "?o!1Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P>o31Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)=gK1William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)<gA1William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)C;o1Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|Co1Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)BoC1Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FAo1Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}@o
1Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "Ho!2Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)PGo32Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)FgK2William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)EgA2William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CDo2Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|Lo2Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)KoC2Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FJo2Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}Io
2Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LOgK3William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)NgA3William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)'Mek2Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekFj
+SToC3Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FSo3Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}Ro
3Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)Qo!3Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)PPo33Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
|Uo3Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
KLKXgA4William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)eWam3Jiri Hnidek <jhnidek@redhat.com> 1.24.52-2d.@- 2229752: Fix D-Bus policy (jhnidek@redhat.com)'Vek3Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekFn
c^oC4Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F]o4Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}\o
4Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)[o!4Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)PZo34Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)YgK4William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
|_o4Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'`ek4Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekFr
do!5Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Pco35Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)bgK5William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)pae}4Pino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
|ho5Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)goC5Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)Ffo5Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}eo
5Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'iek5Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekFv
tCtJlg/6William Poteat <wpoteat@redhat.com> 1.24.36-1^U@- 1831104: When in Simple Content Access mode, subscription-manager should not
  complain that subscriptions aren't attached (wpoteat@redhat.com)CkQ75Pino Toscano <ptoscano@redhat.com>e@- tito: drop bz requirement (ptoscano@redhat.com)
- fix: 1.24 Add python-requests to the list of required RPMs
  (jhnidek@redhat.com)
- fix: Pin lxml to last version supporting Python 2 (mhorky@redhat.com)
- fix: Add missing package intltool to test script (jhnidek@redhat.com)pje}5Pino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
VV@oo6Christopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)nngw6William Poteat <wpoteat@redhat.com> 1.24.38-1^V@- 1837244: Fix wrong version provided by subscription-manager version; ENT-2388
  (jhnidek@redhat.com)
- 1834792: Try to terminate rhsmd after timeout; ENT-2368 (jhnidek@redhat.com)mmgu6William Poteat <wpoteat@redhat.com> 1.24.37-1^I- 1830994: Fix warning messages in dnf/yum (jhnidek@redhat.com)
- 1823523: Detect rhsm-icon running without psutil (csnyder@redhat.com)
- 1771921: Package profiles sends too early when registering a client
  (wpoteat@redhat.com)
- 1688702: Generate redhat.repo in off-line mode; ENT-2302 (jhnidek@redhat.com)
Cso6Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9ro6Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XqgK6William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)ypo6Christopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)
,h	,XxgK7William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)ywo7Christopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)@vo7Christopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)ugK6William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)tgA6William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)
Bb|gK7William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com){gA7William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)Czo7Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9yo7Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)
+A9o8Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XgK8William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)}o
7Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)~o!7Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P}o37Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
" "o!8Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po38Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)gK8William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gA8William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)Co8Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
YY9
o9Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)	oC8Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)Fo8Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
8Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "o!9Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po39Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
gK9William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gA9William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)Co9Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|o9Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)oC9Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)Fo9Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
9Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "o!:Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3:Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)gK:William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gA:William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)Co:Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|o:Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)oC:Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)Fo:Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
:Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LgK;William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gA;William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)'ek:Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF

er+V:eDG
f83ef096b0d758bfec621ecd1c7467134e6ea814c4941955dcba2bb7e59529a7DF
8c2f38d98708ff0e8889fa8f45f759f08f4ec491e20d77dfbd8b7ad4a6bc79b2DE
cc45c070a71c4c4e81aafc430379ec90092af6bb68d3db667d3bc265f3e79eceDD
b0a46bb86e33be0981c1f64d814536e0aa1b9fde2bf106fea068c4252e33e8a7DC
5fbc333de175a0adcac5bba533d0d772ecd8d8c92ec3a872c294bc9c25c7dae2DB
30f3aba3a19b56a1f1c066cc1e427359fec9c66a1a27eac68b33d9e207a2c25bDA
7213e6e2bfdc556860c8f1e0dbd57dcd1201fe9556912fc6ed9c972b00af8306D@
2be7029195f42dbcdd8ba97e167624b401660f10618f61457b3a4c7a18a0add5D?
dbf4ca6d02e1dc4d99cd9b7dd3a4c943d4209115d0f33ec526d0e4338623bfe3D>
ddcdf775af5a3b6b701817a264a8052171cb2eeb71ee4ee1901bffcb91e5d74bD=
45e140c5fc3aa4f6210be1b434e86df569f40a99aa8d64401a5ee00649f3b677D<
9cdcbe724241177f459023cb17fbe80d807010b1ab85f44514ed06b6a1a0abc3D;
18fbc0b4bb2aefb2e3524107d2daa21178d1d96eeb51a3421ac5e3aaae21aaa6
+S$oC;Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F#o;Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}"o
;Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)!o!;Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P o3;Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
|%o;Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
KLK(gA<William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)e'am;Jiri Hnidek <jhnidek@redhat.com> 1.24.52-2d.@- 2229752: Fix D-Bus policy (jhnidek@redhat.com)'&ek;Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
c.oC<Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F-o<Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)},o
<Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)+o!<Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P*o3<Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com))gK<William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
|/o<Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'0ek<Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
4o!=Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P3o3=Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)2gK=William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)p1e}<Pino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
|8o=Christopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)7oC=Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F6o=Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}5o
=Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'9ek=Pino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
tCtJ<g/>William Poteat <wpoteat@redhat.com> 1.24.36-1^U@- 1831104: When in Simple Content Access mode, subscription-manager should not
  complain that subscriptions aren't attached (wpoteat@redhat.com)C;Q7=Pino Toscano <ptoscano@redhat.com>e@- tito: drop bz requirement (ptoscano@redhat.com)
- fix: 1.24 Add python-requests to the list of required RPMs
  (jhnidek@redhat.com)
- fix: Pin lxml to last version supporting Python 2 (mhorky@redhat.com)
- fix: Add missing package intltool to test script (jhnidek@redhat.com)p:e}=Pino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
VV@?o>Christopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)n>gw>William Poteat <wpoteat@redhat.com> 1.24.38-1^V@- 1837244: Fix wrong version provided by subscription-manager version; ENT-2388
  (jhnidek@redhat.com)
- 1834792: Try to terminate rhsmd after timeout; ENT-2368 (jhnidek@redhat.com)m=gu>William Poteat <wpoteat@redhat.com> 1.24.37-1^I- 1830994: Fix warning messages in dnf/yum (jhnidek@redhat.com)
- 1823523: Detect rhsm-icon running without psutil (csnyder@redhat.com)
- 1771921: Package profiles sends too early when registering a client
  (wpoteat@redhat.com)
- 1688702: Generate redhat.repo in off-line mode; ENT-2302 (jhnidek@redhat.com)
CCo>Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9Bo>Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XAgK>William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)y@o>Christopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)
,h	,XHgK?William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)yGo?Christopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)@Fo?Christopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)EgK>William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)DgA>William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)
BbLgK?William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)KgA?William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CJo?Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9Io?Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)
+A9Qo@Christopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XPgK@William Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)}Oo
?Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)No!?Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)PMo3?Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
" "Vo!@Christopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)PUo3@Christopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)TgK@William Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)SgA@William Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CRo@Christopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)bRFRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{Ff?FgCFhHFiLFkOFlTFmUFoXFp^Fq_Fs`FtdFuhFwiFxlFyoFzsF{xF||F}F~F
FFFFFF$F%F(F.F/F0F4F8F9F<F?FCFHFLFQFVFZF_FcFhFlFoFtFuFxF~FFFFF	FFFFFF!F&F*F/F3F8F<F?FDFEFHFNFƒOFăPFŃTFƃXFȃYFɃ\Fʃ_F˃cF̃hF̓lF΃qFσvFЃzFуF҃FӃFԃFփF׃F؃FڃFۃF܃
YY9ZoAChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)YoC@Christopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FXo@Christopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}Wo
@Christopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "_o!AChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P^o3AChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)]gKAWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)\gAAWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)C[oAChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|coAChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)boCAChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FaoAChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}`o
AChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "ho!BChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Pgo3BChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)fgKBWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)egABWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CdoBChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|loBChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)koCBChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FjoBChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}io
BChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LogKCWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)ngACWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)'mekBPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
+StoCCChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FsoCChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}ro
CChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)qo!CChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Ppo3CChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
|uoCChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
KLKxgADWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)ewamCJiri Hnidek <jhnidek@redhat.com> 1.24.52-2d.@- 2229752: Fix D-Bus policy (jhnidek@redhat.com)'vekCPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
c~oCDChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F}oDChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}|o
DChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com){o!DChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Pzo3DChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)ygKDWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
|oDChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'ekDPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
o!EChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3EChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)gKEWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)pe}DPino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
|oEChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)oCEChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FoEChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
EChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'	ekEPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
tCtJg/FWilliam Poteat <wpoteat@redhat.com> 1.24.36-1^U@- 1831104: When in Simple Content Access mode, subscription-manager should not
  complain that subscriptions aren't attached (wpoteat@redhat.com)CQ7EPino Toscano <ptoscano@redhat.com>e@- tito: drop bz requirement (ptoscano@redhat.com)
- fix: 1.24 Add python-requests to the list of required RPMs
  (jhnidek@redhat.com)
- fix: Pin lxml to last version supporting Python 2 (mhorky@redhat.com)
- fix: Add missing package intltool to test script (jhnidek@redhat.com)p
e}EPino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
VV@oFChristopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)ngwFWilliam Poteat <wpoteat@redhat.com> 1.24.38-1^V@- 1837244: Fix wrong version provided by subscription-manager version; ENT-2388
  (jhnidek@redhat.com)
- 1834792: Try to terminate rhsmd after timeout; ENT-2368 (jhnidek@redhat.com)m
guFWilliam Poteat <wpoteat@redhat.com> 1.24.37-1^I- 1830994: Fix warning messages in dnf/yum (jhnidek@redhat.com)
- 1823523: Detect rhsm-icon running without psutil (csnyder@redhat.com)
- 1771921: Package profiles sends too early when registering a client
  (wpoteat@redhat.com)
- 1688702: Generate redhat.repo in off-line mode; ENT-2302 (jhnidek@redhat.com)
CoFChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9oFChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XgKFWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)yoFChristopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)
,h	,XgKGWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)yoGChristopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)@oGChristopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)gKFWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gAFWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)
BbgKGWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gAGWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CoGChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9oGChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)
+A9!oHChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)X gKHWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)}o
GChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)o!GChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3GChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)

er+V:eDT
6f66883f6d03f79791c375ff0cdc81d646922c4276e97e30803dff62b55b566dDS
6a0c97cc57949a9e0b7e374e73c9631bdb4a96d91de5560c68e054144df60d8aDR
746af4568fbd4f2bb6981f2e903fd2f1917f331b5c6fc90f7504882525070fa4DQ
f97d96977b7b2e8e4ab1dfcae63bf6275503575c3a994ebfdf713ecee262b899DP
854eda8da3ba3e3e7ccc94e40250bb1351aa11df12f57ddce1e307ae0bf448e9DO
f24ecb14a77ec32e37ced96fada59ef24d4cd88eb3684963738eff6c0f73f73cDN
a8910c1e5eb6bae266e091a6d736d6d9cf6ee0d2019caf753c767a0798425bb4DM
0e5624fbb0590aa72e8ae21556cd6ed2655b7a7955c181db303cdd39320028f1DL
1e8f86c76054032814d84435dbde30e74557bf6a1f7136131394674bde65ad63DK
421c0198c864523a8a97b579662dd5f24971d1c8a60d7b2146b913582652afa9DJ
8ffaad6b295a49f6f99b79f05ff9da300f9ed61b1611dbc6384efd5e0d7384d0DI
0d2891caee1b493f9b544af0495b535e91b27d243df3f653a39ffeafe3e16dbeDH
11c70debdf0d39261740ffb0a5c8d3cfb7a03d7eb9be61a0ab8b83fec450f182
" "&o!HChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P%o3HChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)$gKHWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)#gAHWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)C"oHChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
YY9*oIChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com))oCHChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F(oHChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}'o
HChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "/o!IChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P.o3IChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)-gKIWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com),gAIWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)C+oIChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|3oIChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)2oCIChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F1oIChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}0o
IChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "8o!JChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P7o3JChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)6gKJWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)5gAJWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)C4oJChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|<oJChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com);oCJChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F:oJChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}9o
JChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
L?gKKWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)>gAKWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)'=ekJPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
+SDoCKChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FCoKChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}Bo
KChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)Ao!KChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P@o3KChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
|EoKChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
KLKHgALWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)eGamKJiri Hnidek <jhnidek@redhat.com> 1.24.52-2d.@- 2229752: Fix D-Bus policy (jhnidek@redhat.com)'FekKPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
cNoCLChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FMoLChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}Lo
LChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)Ko!LChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)PJo3LChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)IgKLWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
|OoLChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'PekLPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
To!MChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)PSo3MChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)RgKMWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)pQe}LPino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
|XoMChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)WoCMChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FVoMChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}Uo
MChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL'YekMPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
tCtJ\g/NWilliam Poteat <wpoteat@redhat.com> 1.24.36-1^U@- 1831104: When in Simple Content Access mode, subscription-manager should not
  complain that subscriptions aren't attached (wpoteat@redhat.com)C[Q7MPino Toscano <ptoscano@redhat.com>e@- tito: drop bz requirement (ptoscano@redhat.com)
- fix: 1.24 Add python-requests to the list of required RPMs
  (jhnidek@redhat.com)
- fix: Pin lxml to last version supporting Python 2 (mhorky@redhat.com)
- fix: Add missing package intltool to test script (jhnidek@redhat.com)pZe}MPino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
VV@_oNChristopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)n^gwNWilliam Poteat <wpoteat@redhat.com> 1.24.38-1^V@- 1837244: Fix wrong version provided by subscription-manager version; ENT-2388
  (jhnidek@redhat.com)
- 1834792: Try to terminate rhsmd after timeout; ENT-2368 (jhnidek@redhat.com)m]guNWilliam Poteat <wpoteat@redhat.com> 1.24.37-1^I- 1830994: Fix warning messages in dnf/yum (jhnidek@redhat.com)
- 1823523: Detect rhsm-icon running without psutil (csnyder@redhat.com)
- 1771921: Package profiles sends too early when registering a client
  (wpoteat@redhat.com)
- 1688702: Generate redhat.repo in off-line mode; ENT-2302 (jhnidek@redhat.com)
CcoNChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9boNChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XagKNWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)y`oNChristopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)
,h	,XhgKOWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)ygoOChristopher Snyder <csnyder@redhat.com> 1.24.40-1^?A- 1725525: Update keys for translations (csnyder@redhat.com)@foOChristopher Snyder <csnyder@redhat.com> 1.24.39-1^?@- 1789457: Syspurpose exception message parsing (wpoteat@redhat.com)
- 1725525: Mark one string for translation; ENT-1680 (jhnidek@redhat.com)
- 1796833: Fix a few broken fr translations (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)egKNWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)dgANWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)
BblgKOWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)kgAOWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CjoOChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)9ioOChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)
+A9qoPChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)XpgKPWilliam Poteat <wpoteat@redhat.com> 1.24.41-1^W@- 1842474: Update local and cache file during sync(); ENT-2433
  (jhnidek@redhat.com)
- 1838012: prevent redundant remote syspurpose sync (pmoravec@redhat.com)}oo
OChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)no!OChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Pmo3OChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
" "vo!PChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Puo3PChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)tgKPWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)sgAPWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CroPChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
YY9zoQChristopher Snyder <csnyder@redhat.com> 1.24.42-1^- 1848636, 1849074: Update insights machine-id path (csnyder@redhat.com)
- 1796833: Update translations (csnyder@redhat.com)yoCPChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FxoPChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}wo
PChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "o!QChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P~o3QChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)}gKQWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)|gAQWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)C{oQChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|oQChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)oCQChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FoQChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
QChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)
" "o!RChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3RChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)gKRWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gARWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)CoRChristopher Snyder <csnyder@redhat.com> 1.24.43-1_@- 1826300: Ignore auto-attach, when SCA mode is used
  (jhnidek@redhat.com)
- 1850919: False positive log "rhsmd process exceeded runtime and was killed."
  (wpoteat@redhat.com)
- 1868936: Do not print traceback, when profile upload failed
  (wpoteat@redhat.com)
|oRChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)oCRChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F
oRChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}	o
RChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LgKSWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)gASWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)'
ekRPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
+SoCSChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FoSChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
SChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)o!SChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3SChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)
|oSChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
KLKgATWilliam Poteat <wpoteat@redhat.com> 1.24.44-1_@- 1826300: Better messages for attach --auto for SCA mode; ENT-3175
  (jhnidek@redhat.com)eamSJiri Hnidek <jhnidek@redhat.com> 1.24.52-2d.@- 2229752: Fix D-Bus policy (jhnidek@redhat.com)'ekSPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
coCTChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)FoTChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}o
TChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)o!TChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)Po3TChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)gKTWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)
|oTChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL' ekTPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
$o!UChristopher Snyder <csnyder@redhat.com> 1.24.47-1`v@- 1886772: Clear content access mode cache on refresh (csnyder@redhat.com)P#o3UChristopher Snyder <csnyder@redhat.com> 1.24.46-1`lM@- 1896715: Set proper read permissions on certs (#2466) (wpoteat@redhat.com)
- 1935592: Fix getting releases, when SCA is used (jhnidek@redhat.com)"gKUWilliam Poteat <wpoteat@redhat.com> 1.24.45-1_- 1890080: Handle IOErrors and Exceptions when looking for process names
  (csnyder@redhat.com)p!e}TPino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)

er+V:eDa
e786b3b03097afeace07b7db363528e3c435b3fe280d06c8e864a93b15a8448fD`
8862347f9d7582ff00f24363fe2ec9973c30d8b3a4bb2acbaffe35de8e6b6dc0D_
2c799ceaa86c1f7b721be3e99bb1bb146d316ec6fb045e1a75d03e2bd335a85eD^
e841a2a32725b0c2d0447c0dda8ba50326219acf4722bc6f864e23dd416cd272D]
1e46c617c397ebf4bddf22b24fc3c9121739db329c756295e2c7fac068c4aab1D\
0d39c362f6c9f3279419ed4315d754b3944058bc88a48263152b512ed67f0ddaD[
a2f8ab9e5767d2ec29dc6571b88d28e1d256bd0aaf2b7a447de4187709d699faDZ
03e57a64f56503f6e79a1fc2c5923cb7b7c844a98479ed62503b92933057832dDY
d60d364eab2fcbe5b73378922674c904aa0843d27145c8b5ab2bc29462a3ddc0DX
ca324724b8cd304f2f0526d1276c77c5ee70b667d98887859d364faeda98e532DW
d877319028506f8c2fdc203339535f7dc588bc67e02079adf6bb0e73b4690c97DV
78721775026f8ae9ad659054bb6aa8c453a791cc260f66e1ea959649a8f8d922DU
2ccb9266c84a96525ac6a03cd1a8a0e14b45062bede6bb3bfe7c4e72a5b63280
|(oUChristopher Snyder <csnyder@redhat.com> 1.24.51-1b]R- 1.24 Add gcp_license_codes to system facts. (jhnidek@redhat.com)
- 1.24 Fix of automatic registration (jhnidek@redhat.com)
- [1.24] Backport support for GCP marketplace ID (jhnidek@redhat.com)
- [1.24] Backported automatic registration (jhnidek@redhat.com)
- Back-ported cloud-what for Python 2.7 (jhnidek@redhat.com)'oCUChristopher Snyder <csnyder@redhat.com> 1.24.50-1aqV@- 2010137: Newer versions of the rpm tooling expect __python defined
  (csnyder@redhat.com)F&oUChristopher Snyder <csnyder@redhat.com> 1.24.49-1ap- 2010137: Fix redundant API calls to Candlepin (hyu@redhat.com)
- [1.24] Added support for marketplace ID on RHEL7. (jhnidek@redhat.com)}%o
UChristopher Snyder <csnyder@redhat.com> 1.24.48-1`x*- 1886772: check is_consumer_cert_key_valid (csnyder@redhat.com)@redhat.com)
- cache: fix typo in debug message (ptoscano@redhat.com)
- 2182768: Disallowed attaching using D-Bus in SCA mode (jhnidek@redhat.com)
- 2182768: Disallowed attaching pool in SCA mode: (jhnidek@redhat.com)
- 1928072: Print warning message and don't do auto-attach (jhnidek@redhat.com)
- managercli: add a local get_current_owner() helper (ptoscano@redhat.com)
- [1.24] Fix issue with locale and D-Bus method GetStatus; (jhnidek@redhat.com)
- Make code Python 2 compatible. (jhnidek@redhat.com)
- 2060101: [1.24] Print correct status, when access mode has changed
  (jhnidek@redhat.com)
- ENT-5542: Build package using GitHub Actions (mhorky@redhat.com)
- Fix failing tests (mhorky@redhat.com)
- tests: drop test_po_files.py (ptoscano@redhat.com)
- Ignore failing tests (mhorky@redhat.com)
- ENT-3759: Test on GitHub Actions (mhorky@redhat.com)
- Alter import of rhsm.config functions (mhorky@redhat.com)
- Add dependency constraints (mhorky@redhat.com)
- Handle tests in containers better (mhorky@redhat.com)
LL')ekUPino Toscano <ptoscano@redhat.com> 1.24.52-1d@- tito: update rhel-7.9 releaser (ptoscano@redhat.com)
- managercli: fix RestlibException reporting for get_current_owner()
  (ptoscano@redhat.com)
- refresh: avoid ExceptionMapper in case of RestlibException
  (ptoscano@redhat.com)
- tests: repair attach cases in SCA mode (ptoscano@redhat.com)
- 2097672: Fixed expected message for manual attach case (jajerome@redhat.com)
- 2097672: [1.28] Improve warning message (auto-attach in SCA mode)
  (jhnidek@redhat.com)
- 2097672: [RFE][1.28] Improve the message, when SCA is enabled
  (jhnidek@redhat.com)
- Reverting disabling AutoAttach() and PoolAttach() in SCA mode
  (jhnidekF
CCC+Q7UPino Toscano <ptoscano@redhat.com>e@- tito: drop bz requirement (ptoscano@redhat.com)
- fix: 1.24 Add python-requests to the list of required RPMs
  (jhnidek@redhat.com)
- fix: Pin lxml to last version supporting Python 2 (mhorky@redhat.com)
- fix: Add missing package intltool to test script (jhnidek@redhat.com)p*e}UPino Toscano <ptoscano@redhat.com> 1.24.53-1e
- 2229752: [1.24] Hotfix of D-Bus policy (jhnidek@redhat.com)
- Collect GCP Project information as cloud facts (chambrid@redhat.com)
- Collect Azure Subscription ID as a cloud fact (#3285) (chambrid@redhat.com)
- Stop requiring M2crypto (ptoscano@redhat.com)
- tests: make M2Crypto optional (ptoscano@redhat.com)
<./ksVMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-5]QT- RHEL-7.8 erratum
  Resolves: rhbz#1711997 sudo is super slow when /etc/security/limits.conf contains many entriesR.aEVRadovan Sroka <rsroka@redhat.com> 1.8.23-4\mA@- RHEL-7.7 erratum
  Resolves: rhbz#1672876 - Backporting sudo bug with expired passwords
  Resolves: rhbz#1665285 - Problem with sudo-1.8.23 and 'who am i'-gCVDaniel Kopecek <dkopecek@redhat.com> 1.8.23-3[- RHEL-7.6 erratum
  Resolves: rhbz#1547974 - Rebase sudo to latest stable upstream versionO,g9VDaniel Kopecek <dkopecek@redhat.com> 1.8.23-2[@- RHEL-7.6 erratum
  Resolves: rhbz#1533964 - sudo skips PAM account module in case NOPASSWD is used in sudoers
  Resolves: rhbz#1506025 - Latest update broke sudo for ldap users.
  Resolves: rhbz#1502630 - inclusion of system-auth for session hooks missing in sudo PAM snippets
)RD<)6gCWDaniel Kopecek <dkopecek@redhat.com> 1.8.23-3[- RHEL-7.6 erratum
  Resolves: rhbz#1547974 - Rebase sudo to latest stable upstream versionv5kVRadovan Sroka <rsroka@redhat.com> - 1.8.23-10.1`@- RHEL 7.9.Z ERRATUM
- CVE-2021-3156
Resolves: rhbz#19177294gCVRadovan Sroka <rsroka@redhat.com> - 1.8.23-10^{G- RHEL-7.9
- sudo allows privilege escalation with expire password
  Resolves: rhbz#1788196k3euVRadovan Sroka <rsroka@redhat.com> - 1.8.23-9^:@- RHEL-7.8
- CVE-2019-18634
  Resolves: rhbz#1798095u2kVMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-8]W- RHEL-7.8
- fixed CVE-2019-14287
  Resolves: rhbz#17606951k7VMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-7]^- RHEL-7.8 erratum
  Resolves: rhbz#1738841 Crash in do_syslog() while doing sudoedit)0kiVMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-6]Z@- RHEL-7.8 erratum
  Resolves: rhbz#1647678 sudo access denied with pam_access and pts terminal configurations
K)v3Kk<euWRadovan Sroka <rsroka@redhat.com> - 1.8.23-9^:@- RHEL-7.8
- CVE-2019-18634
  Resolves: rhbz#1798095u;kWMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-8]W- RHEL-7.8
- fixed CVE-2019-14287
  Resolves: rhbz#1760695:k7WMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-7]^- RHEL-7.8 erratum
  Resolves: rhbz#1738841 Crash in do_syslog() while doing sudoedit)9kiWMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-6]Z@- RHEL-7.8 erratum
  Resolves: rhbz#1647678 sudo access denied with pam_access and pts terminal configurations.8ksWMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-5]QT- RHEL-7.8 erratum
  Resolves: rhbz#1711997 sudo is super slow when /etc/security/limits.conf contains many entriesR7aEWRadovan Sroka <rsroka@redhat.com> 1.8.23-4\mA@- RHEL-7.7 erratum
  Resolves: rhbz#1672876 - Backporting sudo bug with expired passwords
  Resolves: rhbz#1665285 - Problem with sudo-1.8.23 and 'who am i'
g5^.AksXMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-5]QT- RHEL-7.8 erratum
  Resolves: rhbz#1711997 sudo is super slow when /etc/security/limits.conf contains many entriesR@aEXRadovan Sroka <rsroka@redhat.com> 1.8.23-4\mA@- RHEL-7.7 erratum
  Resolves: rhbz#1672876 - Backporting sudo bug with expired passwords
  Resolves: rhbz#1665285 - Problem with sudo-1.8.23 and 'who am i'3?k}WRadovan Sroka <rsroka@redhat.com> - 1.8.23-10.2`:@- RHEL 7.9.Z ERRATUM
- defaults use_pty plus SELinux ROLE in user specification breaks terminal
  Resolves: rhbz#1972820v>kWRadovan Sroka <rsroka@redhat.com> - 1.8.23-10.1`@- RHEL 7.9.Z ERRATUM
- CVE-2021-3156
Resolves: rhbz#1917729=gCWRadovan Sroka <rsroka@redhat.com> - 1.8.23-10^{G- RHEL-7.9
- sudo allows privilege escalation with expire password
  Resolves: rhbz#1788196
RD<vGkXRadovan Sroka <rsroka@redhat.com> - 1.8.23-10.1`@- RHEL 7.9.Z ERRATUM
- CVE-2021-3156
Resolves: rhbz#1917729FgCXRadovan Sroka <rsroka@redhat.com> - 1.8.23-10^{G- RHEL-7.9
- sudo allows privilege escalation with expire password
  Resolves: rhbz#1788196kEeuXRadovan Sroka <rsroka@redhat.com> - 1.8.23-9^:@- RHEL-7.8
- CVE-2019-18634
  Resolves: rhbz#1798095uDkXMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-8]W- RHEL-7.8
- fixed CVE-2019-14287
  Resolves: rhbz#1760695Ck7XMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-7]^- RHEL-7.8 erratum
  Resolves: rhbz#1738841 Crash in do_syslog() while doing sudoedit)BkiXMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-6]Z@- RHEL-7.8 erratum
  Resolves: rhbz#1647678 sudo access denied with pam_access and pts terminal configurations
H=KgCYDaniel Kopecek <dkopecek@redhat.com> 1.8.23-3[- RHEL-7.6 erratum
  Resolves: rhbz#1547974 - Rebase sudo to latest stable upstream versionOJg9YDaniel Kopecek <dkopecek@redhat.com> 1.8.23-2[@- RHEL-7.6 erratum
  Resolves: rhbz#1533964 - sudo skips PAM account module in case NOPASSWD is used in sudoers
  Resolves: rhbz#1506025 - Latest update broke sudo for ldap users.
  Resolves: rhbz#1502630 - inclusion of system-auth for session hooks missing in sudo PAM snippets2Ik{XRadovan Sroka <rsroka@redhat.com> - 1.8.23-10.3cRHEL 7.9.Z ERRATUM
- CVE-2023-22809 sudo: arbitrary file write with privileges of the RunAs user
Resolves: rhbz#21612223Hk}XRadovan Sroka <rsroka@redhat.com> - 1.8.23-10.2`:@- RHEL 7.9.Z ERRATUM
- defaults use_pty plus SELinux ROLE in user specification breaks terminal
  Resolves: rhbz#1972820
K)v3KkQeuYRadovan Sroka <rsroka@redhat.com> - 1.8.23-9^:@- RHEL-7.8
- CVE-2019-18634
  Resolves: rhbz#1798095uPkYMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-8]W- RHEL-7.8
- fixed CVE-2019-14287
  Resolves: rhbz#1760695Ok7YMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-7]^- RHEL-7.8 erratum
  Resolves: rhbz#1738841 Crash in do_syslog() while doing sudoedit)NkiYMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-6]Z@- RHEL-7.8 erratum
  Resolves: rhbz#1647678 sudo access denied with pam_access and pts terminal configurations.MksYMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-5]QT- RHEL-7.8 erratum
  Resolves: rhbz#1711997 sudo is super slow when /etc/security/limits.conf contains many entriesRLaEYRadovan Sroka <rsroka@redhat.com> 1.8.23-4\mA@- RHEL-7.7 erratum
  Resolves: rhbz#1672876 - Backporting sudo bug with expired passwords
  Resolves: rhbz#1665285 - Problem with sudo-1.8.23 and 'who am i'
)g)RVaEZRadovan Sroka <rsroka@redhat.com> 1.8.23-4\mA@- RHEL-7.7 erratum
  Resolves: rhbz#1672876 - Backporting sudo bug with expired passwords
  Resolves: rhbz#1665285 - Problem with sudo-1.8.23 and 'who am i'UgCZDaniel Kopecek <dkopecek@redhat.com> 1.8.23-3[- RHEL-7.6 erratum
  Resolves: rhbz#1547974 - Rebase sudo to latest stable upstream versionOTg9ZDaniel Kopecek <dkopecek@redhat.com> 1.8.23-2[@- RHEL-7.6 erratum
  Resolves: rhbz#1533964 - sudo skips PAM account module in case NOPASSWD is used in sudoers
  Resolves: rhbz#1506025 - Latest update broke sudo for ldap users.
  Resolves: rhbz#1502630 - inclusion of system-auth for session hooks missing in sudo PAM snippetsvSkYRadovan Sroka <rsroka@redhat.com> - 1.8.23-10.1`@- RHEL 7.9.Z ERRATUM
- CVE-2021-3156
Resolves: rhbz#1917729RgCYRadovan Sroka <rsroka@redhat.com> - 1.8.23-10^{G- RHEL-7.9
- sudo allows privilege escalation with expire password
  Resolves: rhbz#1788196
M
"\gCZRadovan Sroka <rsroka@redhat.com> - 1.8.23-10^{G- RHEL-7.9
- sudo allows privilege escalation with expire password
  Resolves: rhbz#1788196k[euZRadovan Sroka <rsroka@redhat.com> - 1.8.23-9^:@- RHEL-7.8
- CVE-2019-18634
  Resolves: rhbz#1798095uZkZMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-8]W- RHEL-7.8
- fixed CVE-2019-14287
  Resolves: rhbz#1760695Yk7ZMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-7]^- RHEL-7.8 erratum
  Resolves: rhbz#1738841 Crash in do_syslog() while doing sudoedit)XkiZMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-6]Z@- RHEL-7.8 erratum
  Resolves: rhbz#1647678 sudo access denied with pam_access and pts terminal configurations.WksZMarek Tamaskovic <mtamasko@redhat.com> 1.8.23-5]QT- RHEL-7.8 erratum
  Resolves: rhbz#1711997 sudo is super slow when /etc/security/limits.conf contains many entries
 c bk7[Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-7]^- RHEL-7.8 erratum
  Resolves: rhbz#1738841 Crash in do_syslog() while doing sudoedit)aki[Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-6]Z@- RHEL-7.8 erratum
  Resolves: rhbz#1647678 sudo access denied with pam_access and pts terminal configurations.`ks[Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-5]QT- RHEL-7.8 erratum
  Resolves: rhbz#1711997 sudo is super slow when /etc/security/limits.conf contains many entriesR_aE[Radovan Sroka <rsroka@redhat.com> 1.8.23-4\mA@- RHEL-7.7 erratum
  Resolves: rhbz#1672876 - Backporting sudo bug with expired passwords
  Resolves: rhbz#1665285 - Problem with sudo-1.8.23 and 'who am i'^gC[Daniel Kopecek <dkopecek@redhat.com> 1.8.23-3[- RHEL-7.6 erratum
  Resolves: rhbz#1547974 - Rebase sudo to latest stable upstream versionv]kZRadovan Sroka <rsroka@redhat.com> - 1.8.23-10.1`@- RHEL 7.9.Z ERRATUM
- CVE-2021-3156
Resolves: rhbz#1917729
MhgC\Daniel Kopecek <dkopecek@redhat.com> 1.8.23-3[- RHEL-7.6 erratum
  Resolves: rhbz#1547974 - Rebase sudo to latest stable upstream version3gk}[Radovan Sroka <rsroka@redhat.com> - 1.8.23-10.2`:@- RHEL 7.9.Z ERRATUM
- defaults use_pty plus SELinux ROLE in user specification breaks terminal
  Resolves: rhbz#1972820vfk[Radovan Sroka <rsroka@redhat.com> - 1.8.23-10.1`@- RHEL 7.9.Z ERRATUM
- CVE-2021-3156
Resolves: rhbz#1917729egC[Radovan Sroka <rsroka@redhat.com> - 1.8.23-10^{G- RHEL-7.9
- sudo allows privilege escalation with expire password
  Resolves: rhbz#1788196kdeu[Radovan Sroka <rsroka@redhat.com> - 1.8.23-9^:@- RHEL-7.8
- CVE-2019-18634
  Resolves: rhbz#1798095uck[Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-8]W- RHEL-7.8
- fixed CVE-2019-14287
  Resolves: rhbz#1760695
K)v3Kkneu\Radovan Sroka <rsroka@redhat.com> - 1.8.23-9^:@- RHEL-7.8
- CVE-2019-18634
  Resolves: rhbz#1798095umk\Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-8]W- RHEL-7.8
- fixed CVE-2019-14287
  Resolves: rhbz#1760695lk7\Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-7]^- RHEL-7.8 erratum
  Resolves: rhbz#1738841 Crash in do_syslog() while doing sudoedit)kki\Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-6]Z@- RHEL-7.8 erratum
  Resolves: rhbz#1647678 sudo access denied with pam_access and pts terminal configurations.jks\Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-5]QT- RHEL-7.8 erratum
  Resolves: rhbz#1711997 sudo is super slow when /etc/security/limits.conf contains many entriesRiaE\Radovan Sroka <rsroka@redhat.com> 1.8.23-4\mA@- RHEL-7.7 erratum
  Resolves: rhbz#1672876 - Backporting sudo bug with expired passwords
  Resolves: rhbz#1665285 - Problem with sudo-1.8.23 and 'who am i'
g5^.sks]Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-5]QT- RHEL-7.8 erratum
  Resolves: rhbz#1711997 sudo is super slow when /etc/security/limits.conf contains many entriesRraE]Radovan Sroka <rsroka@redhat.com> 1.8.23-4\mA@- RHEL-7.7 erratum
  Resolves: rhbz#1672876 - Backporting sudo bug with expired passwords
  Resolves: rhbz#1665285 - Problem with sudo-1.8.23 and 'who am i'3qk}\Radovan Sroka <rsroka@redhat.com> - 1.8.23-10.2`:@- RHEL 7.9.Z ERRATUM
- defaults use_pty plus SELinux ROLE in user specification breaks terminal
  Resolves: rhbz#1972820vpk\Radovan Sroka <rsroka@redhat.com> - 1.8.23-10.1`@- RHEL 7.9.Z ERRATUM
- CVE-2021-3156
Resolves: rhbz#1917729ogC\Radovan Sroka <rsroka@redhat.com> - 1.8.23-10^{G- RHEL-7.9
- sudo allows privilege escalation with expire password
  Resolves: rhbz#1788196
RD<vyk]Radovan Sroka <rsroka@redhat.com> - 1.8.23-10.1`@- RHEL 7.9.Z ERRATUM
- CVE-2021-3156
Resolves: rhbz#1917729xgC]Radovan Sroka <rsroka@redhat.com> - 1.8.23-10^{G- RHEL-7.9
- sudo allows privilege escalation with expire password
  Resolves: rhbz#1788196kweu]Radovan Sroka <rsroka@redhat.com> - 1.8.23-9^:@- RHEL-7.8
- CVE-2019-18634
  Resolves: rhbz#1798095uvk]Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-8]W- RHEL-7.8
- fixed CVE-2019-14287
  Resolves: rhbz#1760695uk7]Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-7]^- RHEL-7.8 erratum
  Resolves: rhbz#1738841 Crash in do_syslog() while doing sudoedit)tki]Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-6]Z@- RHEL-7.8 erratum
  Resolves: rhbz#1647678 sudo access denied with pam_access and pts terminal configurations
YHY)~ki^Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-6]Z@- RHEL-7.8 erratum
  Resolves: rhbz#1647678 sudo access denied with pam_access and pts terminal configurations.}ks^Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-5]QT- RHEL-7.8 erratum
  Resolves: rhbz#1711997 sudo is super slow when /etc/security/limits.conf contains many entriesR|aE^Radovan Sroka <rsroka@redhat.com> 1.8.23-4\mA@- RHEL-7.7 erratum
  Resolves: rhbz#1672876 - Backporting sudo bug with expired passwords
  Resolves: rhbz#1665285 - Problem with sudo-1.8.23 and 'who am i'2{k{]Radovan Sroka <rsroka@redhat.com> - 1.8.23-10.3cRHEL 7.9.Z ERRATUM
- CVE-2023-22809 sudo: arbitrary file write with privileges of the RunAs user
Resolves: rhbz#21612223zk}]Radovan Sroka <rsroka@redhat.com> - 1.8.23-10.2`:@- RHEL 7.9.Z ERRATUM
- defaults use_pty plus SELinux ROLE in user specification breaks terminal
  Resolves: rhbz#1972820
kp3k}^Radovan Sroka <rsroka@redhat.com> - 1.8.23-10.2`:@- RHEL 7.9.Z ERRATUM
- defaults use_pty plus SELinux ROLE in user specification breaks terminal
  Resolves: rhbz#1972820vk^Radovan Sroka <rsroka@redhat.com> - 1.8.23-10.1`@- RHEL 7.9.Z ERRATUM
- CVE-2021-3156
Resolves: rhbz#1917729gC^Radovan Sroka <rsroka@redhat.com> - 1.8.23-10^{G- RHEL-7.9
- sudo allows privilege escalation with expire password
  Resolves: rhbz#1788196keu^Radovan Sroka <rsroka@redhat.com> - 1.8.23-9^:@- RHEL-7.8
- CVE-2019-18634
  Resolves: rhbz#1798095uk^Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-8]W- RHEL-7.8
- fixed CVE-2019-14287
  Resolves: rhbz#1760695k7^Marek Tamaskovic <mtamasko@redhat.com> 1.8.23-7]^- RHEL-7.8 erratum
  Resolves: rhbz#1738841 Crash in do_syslog() while doing sudoedit
3IP3goc_Michal Sekletar <msekleta@redhat.com> - 10.1.5-16[,- apply previously added patches (#1543238)}
o
_Michal Sekletar <msekleta@redhat.com> - 10.1.5-15[,- backport some more follow-up bugfixes related to -F (#1543238)		o%_Michal Sekletar <msekleta@redhat.com> - 10.1.5-14[+@- backport -F switch for monitoring currently mounted filesystems (#1543238)oO_Michal Sekletar <msekleta@redhat.com> - 10.1.5-13Z- fix output of pidstat -p $PID (#1448489)
- improve reading of /proc/cpuinfo on Power (#1440000)o_Michal Sekletar <msekleta@redhat.com> - 10.1.5-12Xۡ- sar: output timestamps when running with ko_KR.UTF-8 locale (#1381128)kmm_Peter Schiffer <pschiffe@redhat.com> - 10.1.5-11WN@- related: #1332662
  fixed more coverity issues2k{^Radovan Sroka <rsroka@redhat.com> - 1.8.23-10.3cRHEL 7.9.Z ERRATUM
- CVE-2023-22809 sudo: arbitrary file write with privileges of the RunAs user
Resolves: rhbz#2161222
N~|NFc-`Nils Philippsen <nils@redhat.com> - 1.3.1-1P- tighten policyQcC`Nils Philippsen <nils@redhat.com> - 1.3.0-1P- pull updated translations
k+_Lukáš Zaoral <lzaoral@redhat.com> - 10.1.5-20cn9@- do not cap %usr to 100% in `pidstat -I` for multithreaded programs (#1763579)|q	_Michal Sekletár <msekleta@redhat.com> - 10.1.5-19^%@- fix possible segfault when appending to data file (#1774590)}
q_Michal Sekletár <msekleta@redhat.com> - 10.1.5-18\@- add -f flag to force fdatasync() after sa file update (#1662094)
- don't call filesystem count functions when we are not collecting fs statistics (#1670060)
- skip autofs when gathering filesystem statistics (#1670060)
- fix use of incorrect preposition in sar man page (#1624410)
- fix CPU usage reporting (#1618688)~o_Michal Sekletar <msekleta@redhat.com> - 10.1.5-17[0@- fix potential buffer overflow identified by cppcheck (#1543238)
6PBU3`Than Ngo <than@redhat.com> - 1.3.5-4[`O@- Related: #1502438nU	`Than Ngo <than@redhat.com> - 1.3.5-3ZЛ- Resolves: #1563896 - don't use exec in pkexec wrapper scriptL]?`Daniel Mach <dmach@redhat.com> - 1.3.5-2Rk- Mass rebuild 2013-12-27cA`Nils Philippsen <nils@redhat.com> - 1.3.5-1R
- cope with changes handling empty shadow fields in libuser (patches by
  Miloslav Trmač)Fc+`Nils Philippsen <nils@redhat.com> - 1.3.4-1QJ@- don't ask libuser to create a home directory over an existing one (#908852,
  patch by Miloslav Trmač)
- correct check if SELinux is enabledc%`Nils Philippsen <nils@redhat.com> - 1.3.3-1P @- fix editing group properties (#885147)
- pull updated and new translationssc`Nils Philippsen <nils@redhat.com> - 1.3.2-1P- avoid deleting primary groups of remaining users (#881022)
}q}	/asystemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?	uasystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)
e1aLukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
UA`Than Ngo <than@redhat.com> - 1.3.5-5_u- Resolves: #1825765, dialog appears when minimizing system-config-users window on Apr 1stF57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9 masystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qasystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mWasystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);qasystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17F
..#	asystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X"	'asystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f!Iasystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)

er+V:eDn
d62663db9bfe5188b678168ce54fbc9a25029291dad7f25e911dca2b4745ad8fDm
a450c1170181a3ff18ece403ab9cd454a3f2fbe440d5f9b595bd3f0de9b1dd08Dl
5490d928d2dc55d285caa5eaf9606be884605bf43d81604819679bc307219d29Dk
e18ea59775bba4c1bd311fdb9225cf287d5862c29e8b3199c4ad3bf57a00b83eDj
dd83fab8ff66edc9c2eb4cce6304324d64c9a9f43b6f394c7886c2bbb9f6c689Di
a529f2b782f1a8ac2c40f6c193c7b680debbe16131700642d20f5c3c7792165fDh
aa2d737429489d52bcd0751bd1e48ba6c8f71eb071120236b9ab47a5ae3b3ebdDg
4d766c79e706152df781ac169a04106c6cc571faea5ad9beef0fcae6481c3a5cDf
12c5efd45c7ef298bfb73822c8f3f30c767fb03f40e504e94e3519f825ce6216De
518634909b8077578379878100a6cc50c82ef6ffa0726ef538f628609f07e436Dd
b3629bade8ef787d20012f38cc73971fd4d755469722b2aa65b093f247fe10ccDc
40f5419ef2f5f5628caafd1966853e3ed258c5f6cb1984c8471c853323bd793bDb
555f6ee454fa312fb09d6fafbe3c2aa2f876b4599c73856eff9aa4d9f1b2f06c
<%	/bsystemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?$	ubsystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9)mbsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q(bsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m'Wbsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);&qbsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17F
.
-	bsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908),	bsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X+	'bsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f*Ibsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/91mcsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q0csystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m/Wcsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);.qcsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
.
5	csystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)4	csystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X3	'csystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f2Icsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
*(R*f:Idsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)99mdsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q8dsystemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291).7	Scsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) 6	7csystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
=	dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)<	dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X;	'dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
(	fBIesystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
A	dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)@	
dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).?	Sdsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) >	7dsystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
E	esystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)D	esystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)XC	'esystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
u(	uJ	esystemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
I	esystemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)H	
esystemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).G	Sesystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) F	7esystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
nbnN	/fsystemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?M	ufsystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)
Le1fLukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)K	)esystemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9Rmfsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)QQfsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mPWfsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);Oqfsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G

.
Ve1gLukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)U	fsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)XT	'fsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fSIfsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<X	/gsystemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?W	ugsystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9\mgsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q[gsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mZWgsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);Yqgsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
.._	gsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X^	'gsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f]Igsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<a	/hsystemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?`	uhsystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)bRGkRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{F߃$Fჺ(Fヺ)F䃺+F僺/F惺6F烺<F胺AF郺GFꃺKF냺QF샺VF탺\FbFhFnFsFyF~FFFFFF F#F%G)G-G1G5G:G=G	BG
EGJGNGRGVGXG\G_GaGeGiGkGoG sG#wG${G%~G(G)G*G+G,G-G.G/G0$G1(G3-G41G55G89G9;G<?G=CG@GGAKGBPGCSGDXGE[GF`GGdGJhGKlGLnGOrGPuGQwGT{GUGVGYGZ	G]
G^G_GbGcGd!Ge$Gf*Gh-Gi2Gj5G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9emhsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qdhsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mcWhsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);bqhsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
.
i	hsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)h	hsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)Xg	'hsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)ffIhsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<k	/isystemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?j	uisystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9omisystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qnisystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mmWisystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);lqisystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
.
s	isystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)r	isystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)Xq	'isystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fpIisystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)G"57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9wmjsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qvjsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)muWjsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);tqjsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G!
.
{	jsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)z	jsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)Xy	'jsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fxIjsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
\(\;~qksystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G&.}	Sjsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) |	7jsystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)G'57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
X	'ksystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fIksystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9mksystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qksystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mWksystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744)
u 	7ksystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
	ksystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	ksystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)
rMwOrX	'lsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f
Ilsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9	mlsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qlsystemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291).	Sksystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361)
u 	7lsystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)

	lsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	lsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)
0M.X0fImsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9mmsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qmsystemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)
	lsystemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)	
lsystemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).	Slsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361)
#
	msystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	msystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'msystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
(	fInsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
	msystemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)	
msystemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).	Smsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) 	7msystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
	nsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	nsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'nsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
u(	u$	nsystemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
#	nsystemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)"	
nsystemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).!	Snsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361)  	7nsystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
b(	osystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X'	'osystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f&Iosystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)%	)nsystemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)

er+V:eD{
43b09300e3cae57123f6afdd23ac7e88411c687be6f131ff215ea718f5933e1cDz
c39c2b1f50d0ee1b0b3edd4f05c23ffa2f7d0cf847b1f78fc6f36f9f4bb83c8fDy
89ba59bcc18f02cf622a16a2b4485ddbebf2c0e577d2b9cc5b891f7f18b2b729Dx
01fb3a26a807a59931faaaabe295041a8fa40561ac74f13c180818145c68eae4Dw
22f6e0dc0621a93077ed64c276366eb9c44393ec755722b64a175a9ef296b112Dv
4b1fd0ab7ed6265d09954241b71684d0db26d624318d6cbb227909a3ca804bfcDu
82b1d1dfa51bb5a8958691fdfa3bcacef757cb4afe47f1a082dab853cf9650d3Dt
bcfb391f7881055ca608ff7eb04d4957ec6829b99a6cf0fad156e59165558f0bDs
1aa7058dfddcf6000119e4d89f90da91d35b7562587f5a8c91a2db80781c6303Dr
bea5901fa1364aca49ab785c08b8debad25fab28cdc3793bf3925cb1cd91f136Dq
920dd1baf1fd31b9436ff47d0be39b0142c33dfb36ef0255aaf0e2c529756a9bDp
34ce748bf1845ac8f646607f3776e2995f16c3c1b8ed68775327e24981f1c217Do
3ba273d4314760eb122b0661daa6126b87cb2ccfa2ee5813199419415261ca9f
wnIw
-	osystemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544),	
osystemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).+	Sosystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) *	7osystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
)	osystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)
{l?{?1	upsystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)
0e1pLukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)/	)osystemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164).	osystemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
L_"LQ5psystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m4Wpsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);3qpsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G62	/psystemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)G757704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
pBp9	psystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X8	'psystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f7Ipsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)96mpsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)
<;	/qsystemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?:	uqsystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)G;57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9?mqsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q>qsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m=Wqsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);<qqsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G:
.
C	qsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)B	qsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)XA	'qsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f@Iqsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)G?57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9Gmrsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)QFrsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mEWrsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);Dqrsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G>
.
K	rsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)J	rsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)XI	'rsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fHIrsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
*(R*fPIssystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9Omssystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)QNssystemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291).M	Srsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) L	7rsystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
S	ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)R	ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)XQ	'ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
(	fXItsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
W	ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)V	
ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).U	Sssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) T	7ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
[	tsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)Z	tsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)XY	'tsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
u(	u`	tsystemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
_	tsystemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)^	
tsystemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).]	Stsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) \	7tsystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
nbnd	/usystemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?c	uusystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)
be1uLukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)a	)tsystemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)GI57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9hmusystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qgusystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mfWusystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);equsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17GH
.
le1vLukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)k	usystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)Xj	'usystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fiIusystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<n	/vsystemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?m	uvsystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)GN57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9rmvsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qqvsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mpWvsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);oqvsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17GM
..u	vsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)Xt	'vsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fsIvsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<w	/wsystemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?v	uwsystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)GS57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9{mwsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qzwsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)myWwsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);xqwsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17GR
.
	wsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)~	wsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X}	'wsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f|Iwsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<	/xsystemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?	uxsystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)GX57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9mxsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qxsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mWxsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);qxsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17GW
.
		xsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	xsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'xsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fIxsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)G\57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9
mysystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qysystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mWysystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);
qysystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G[
.
	ysystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	ysystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'ysystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fIysystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
\(\;qzsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G`.	Sysystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) 	7ysystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)Ga57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
X	'zsystemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fIzsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9mzsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qzsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mWzsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744)
u 	7zsystemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
	zsystemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	zsystemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)
rMwOrX!	'{systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f I{systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9m{systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q{systemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291).	Szsystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361)
u $	7{systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#	{systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)"	{systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)
0M.X0f*I|systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9)m|systemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q(|systemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)
'	{systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)&	
{systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).%	S{systemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361)

er+V:eD
3bbea9323c322a5179cd1dc270e81ca0b7012086d4d12c606d5f71993e272e7eD
eb5d1459a1ed3b55d3a45f58f61633509ffca8700fc3dc3f1935cde74eb204c0D
de628f3727cacb859cd8375cb35493f4ee9c74aeb3751c1ba0c049341d84eb2eD
c3df19c15f8ddba5346c826fd07ba66f82958ff47801b4b8f2b8842525aec713D
b22820dc39c9c681f704d5e7b608b6d1aecc2fb1a4181df605e69e8a30e70237D
c84bd4cd2d437d984953f25e00196fba34b6d1f25cb29da168b9469d4969236eD
c3df4151777a268106f45f068f7a6e09e974ef1222fd6ccbafd4fd2f7307e011D
7a957336373214b86e031556081bbbfea7f560af4a8ad2dbd60475b20bc824d2D
0ed523747db652e84c5b5a87d2207d7410229587204a4fbc5f477091cf0e9706D
efd9d7f9ca4a7ab583fb075ecf7b7abda7fa92b4657a5d14c6e3ea7f67c30608D~
65584369e0052524a4788078e14f671f1ab55c3f0e2f3ea69702c77b5242d309D}
179672f8c8746404f915bf9e8645d88839973a7f5e024e6b7c6a3e00ce2c6f98D|
a6d9b567ef1b06e195132a506e27e02e6e7b6768d0d22c13cd692ffbbc8acec3
#
-	|systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908),	|systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X+	'|systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
(	f2I}systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
1	|systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)0	
|systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544)./	S|systemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) .	7|systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
5	}systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)4	}systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X3	'}systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
u(	u:	}systemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
9	}systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)8	
}systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).7	S}systemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) 6	7}systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
b>	~systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X=	'~systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f<I~systemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816);	)}systemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)
wnIw
C	~systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)B	
~systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).A	S~systemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) @	7~systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
?	~systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)
{l?{?G	usystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)
Fe1Lukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)E	)~systemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)D	~systemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
L_"LQKsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mJWsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);Iqsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17GpH	/systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)Gq57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
pBpO	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)XN	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fMIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9Lmsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)
<Q	/systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?P	usystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)Gu57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9Umsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)QTsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mSWsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);Rqsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17Gt
.
Y	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)X	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)XW	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fVIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)Gy57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9]msystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q\systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m[Wsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);Zqsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17Gx
.
a	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)`	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X_	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f^Isystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
*(R*ffIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9emsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qdsystemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291).c	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) b	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
i	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)h	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)Xg	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
(	fnIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
m	systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)l	
systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).k	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) j	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
q	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)p	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)Xo	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
u(	uv	systemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
u	systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)t	
systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).s	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) r	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
nbnz	/systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?y	usystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)
xe1Lukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)w	)systemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9~msystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q}systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m|Wsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);{qsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
..	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<	/systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?	usystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9msystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mWsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);qsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
.
	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)
	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X		'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9msystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m
Wsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);qsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
.
	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
*(R*fIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9msystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qsystemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291).	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) 	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
(	f Isystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
	systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)	
systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) 	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
#	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)"	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X!	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
u(	u(	systemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
'	systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)&	
systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).%	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) $	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
nbn,	/systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?+	usystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)
*e1Lukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149))	)systemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)

er+V:eD
5597c86554e7f88c701acbd24766aa87c93c449673c10e38cbd74b8bbf5e84faD
58f957357894f41ea8dce27b4768e570d26ebe184ba29202236806ebd3286af2D
45e4431fa6444a15d0292df48fe285761bee76d70d5eda0b7e810f4052b8ed92D
49113267f534c7bd5e707eaf237fd29c16d11aae9ee70d8a16d8dd33edb75084D
fbdd5b5415f56af9b9ab84c65d8ccf11fa14c3f554904f46a117fa7e039d2a92D
badc986837eca92a61c46a7beb9bd700e04af6d84681d4ca53417eb37b7eeac4D
6f7cd47756fa8dfb7b6cb88b9a65c779de1981cf1b2707b6326ba27ddea5138dD
45631c9c56e97ad1c34577b8df4c774f108693f67b52f45cfe6915a3e3f40208D

53f19e6a64582f844301bdf853863da54891f234bc44dc77426164612697903dD
bfbaa306ef62a274da0c3a7df6f2c28ed78243d6d6b8fc3c909b90fec19c16baD
1cf3973fb3523d1d1a511479268703611131014d54aec79f628f19fb4b486117D

99d7ab7cf207e1519d1bc9faa0e9cce19f934bf8db21f3946902e8b76737c8a7D	
147bc1295714b7317e539c11b0c800234b512dc4c8c7c1a62598b5f4204f4d68G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/90msystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q/systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m.Wsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);-qsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
.
4e1Lukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)3	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X2	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f1Isystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<6	/systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?5	usystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9:msystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q9systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m8Wsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);7qsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
..=	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X<	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f;Isystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<?	/systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?>	usystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9Cmsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)QBsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mAWsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);@qsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
.
G	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)F	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)XE	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fDIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
<I	/systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?H	usystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9Mmsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)QLsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mKWsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);Jqsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
.
Q	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)P	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)XO	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fNIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9Umsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)QTsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mSWsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);Rqsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
.
Y	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)X	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)XW	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fVIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
\(\;\qsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G.[	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) Z	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)bRGRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{Gl>GmCGnGGoKGrOGsQGvUGwYGz]G{aG|fG}iG~nGqGvGzG~GGGGGGGGG G#G(G,G0G4G6G:G=G?GCGGGIGMGQGUGYG\GaGdGiGlGrGuGzG}GGGGGGGGăGŃ!Gȃ%GɃ)Gʃ.G̃1G̓6G΃9Gσ>GЃCGуIG҃LGӃRGԃYGՃ_GփeG׃oG؃zGكGڃGۃG܃&G݃1G߃;GEGPG[GfGpGzGGGG(G4G@GKGVGaGlG57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
Xa	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f`Isystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9_msystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q^systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m]Wsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744)
u d	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
c	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)b	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)
rMwOrXi	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fhIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9gmsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qfsystemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291).e	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361)
u l	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
k	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)j	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)
0M.X0frIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9qmsystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qpsystemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)
o	systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)n	
systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).m	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361)
#
u	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)t	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)Xs	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
(	fzIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
y	systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)x	
systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).w	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) v	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
}	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)|	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X{	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
u(	u	systemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
	systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)	
systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) ~	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
b	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)	)systemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)
wnIw
	systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)
	
systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).		Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) 	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)
{l?{?	usystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)
e1Lukas Nykryn <lnykryn@redhat.com> - 219-73.1]@- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
	)systemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)	systemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
L_"LQsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mWsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);qsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G	/systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
pBp	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9msystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)
<	/systemd maintenance team <systemd-maint@redhat.com> - 219-73.3^`- journal: do not trigger assertion when journal_file_close() get NULL (#1807798)?	usystemd maintenance team <systemd-maint@redhat.com> - 219-73.2^K- core: when restarting services, don't close fds (#1803802)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1803802)
- tests: add basic journal test (#1803802)
- tests: add regression test for `systemctl restart systemd-journald` (#1803802)
- tests: add test that journald keeps fds over termination by signal (#1803802)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9msystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Qsystemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)mWsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);qsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
.
!	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908) 	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)fIsystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)G57704)
- tests: add regression test for `systemctl restart systemd-journald` (#1757704)
- tests: add test that journald keeps fds over termination by signal (#1757704)
- nss-util: silence warning about deprecated RES_USE_INET6 (#1799002)
- journal: do not trigger assertion when journal_file_close() get NULL (#1786046)
- mount: don't propagate errors from mount_setup_unit() further up (#1804757)
- mount: when allocating a Mount object based on /proc/self/mountinfo mark it so (#1804757)
- fix the fix for #1691511 (#1804757)
- v3: Properly parsing SCSI Hyperv devices (#8509) (#1809053)
- Consider smb3 as remote filesystem (#1811700)
- mount: don't add Requires for tmp.mount (#1813270)
- sd-bus: when attached to an sd-event loop, disconnect on processing errors (#1769928)
- sd-journal: close journal files that were deleted by journald before we've setup inotify watch (#1812889)
- sd-journal: remove the dead code and actually fix #14695 (#1812889)
- swap: adjust swap.c in a similar way to what we just did to mount.c (#1749621)
- swap: finish the secondary swap units' jobs if deactivation of the primary swap unit fails (#1749621)
- core: add a new unit file setting CollectMode= for tweaking the GC logic (#1817576)
- run: add "-G" as shortcut for "--property=CollectMode=inactive-or-failed" (#1817576)
- core: clarify that the CollectMode bus property is constant (#1817576)
- udev-rules: make tape-changers also apprear in /dev/tape/by-path/ (#1814028)
- logind: check PolicyKit before allowing VT switch (#1797672)
- timer: don't use persietent file timestamps from the future (#6823) (#1769923)
- core: transition to FINAL_SIGTERM state after ExecStopPost= (#1766477)
- bus_open leak sd_event_source when udevadm trigger。 (#1798503)
- journal-remote: split-mode=host, remove port from journal filename (#1244691)
- core: downgrade log message about inability to propagate cgroup release message (#1679934)
- units: move Before deps for quota services to remote-fs.target (#5627) (#1693374)
- set kptr_restrict=1 (#1689344)
/4/9%msystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q$systemd maintenance team <systemd-maint@redhat.com> - 219-76^lA- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291)m#Wsystemd maintenance team <systemd-maint@redhat.com> - 219-75^l@- journal: break recursion (#1778744);"qsystemd maintenance team <systemd-maint@redhat.com> - 219-74^- sd-bus: bump message queue size again (#1770158)
- unit: fix potential use of cgroup_path after free() when freeing unit (#1760149)
- add test for ExecStopPost (#1733998)
- core: when restarting services, don't close fds (#1757704)
- unit: rework a bit how we keep the service fdstore from being destroyed during service restart (#1757704)
- tests: add basic journal test (#17G
.
)	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)(	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X'	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)f&Isystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
*(R*f.Isystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)9-msystemd maintenance team <systemd-maint@redhat.com> - 219-77^- core: coldplug possible nop_job (#1829754)
- core: make sure to restore the control command id, too (#1828953)Q,systemd maintenance team <systemd-maint@redhat.com> - 219-76^l@- core: enforce a ratelimiter when stopping units due to StopWhenUnneeded=1 (#1775291)
- core: rework StopWhenUnneeded= logic (#1775291).+	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) *	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)

er+V:eD"
24039275da54c6bead07277fc20529befb42b1c310557cb1598abc0ae73b37f4D!
2438f52168e5bd5317e5aae571902a59d445fde074f9fe592ad04c60e7fb4d82D 
365bf20a36b4781a7a21bb79b446907366fe135f7e5616c550b20d174cc96d1dD
ac89e7436d5ce48c8bfe654ce6d2c7aa605cdb568aaad5d7088f3e36ffc915e9D
61357d6eb9ca6e939f89412cfa01e3e26beeb6e28a3f90998db4cd5808430a6dD
fe63730a873042e3f6763ad2922d8d1c714e93fe81d223bc2ae7454b4803f1fdD
18d655d9234417eb4a995a66801cb9c7ac35362aadaa734d8674f8e744986b8fD
94d47b782d9d01f589874cfe848688d584d291d216cca5e37b467e4d747dd75eD
100f1234d4c5782b5913aa69ba66a3d90098ad06808fb39b4433d80beb94075dD
280bc79dccb9b2223e4216b8dc257b35f8686cebd950a724747d1722af5d8582D
a5909e444b1d27c443afbbb9a2c128c3ee271e86aed9bea120cceb657e7bc326D
87bd7b630c33f8be6348fd87af02cdb167d891fac4dc956b41cfd5911def169aD
27d4858f1741f00448f919a33388f3a4ce77d65c758523ac1aaa6845fcf67c97
#
1	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)0	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X/	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
(	f6Isystemd maintenance team <systemd-maint@redhat.com> - 219-78^- avoid double free (#1832816)
5	systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)4	
systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).3	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) 2	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
#
9	systemd maintenance team <systemd-maint@redhat.com> - 219-78.3`- core: Detect initial timer state from serialized data (#1764908)8	systemd maintenance team <systemd-maint@redhat.com> - 219-78.2_- core: don't update unit description if it is already set to the same value (#1793527)
- unit: don't emit PropertiesChanged signal if adding a dependency to a unit is a no-op (#1793527)
- core: fix unnecessary fallback to the rescue mode caused by initrd-switch-root.service's exit status judgment error (#1825232)X7	'systemd maintenance team <systemd-maint@redhat.com> - 219-78.1_3- device: make sure we emit PropertiesChanged signal once we set sysfs (#1793527)
- device: don't emit PropetiesChanged needlessly (#1793527)
u(	u>	systemd maintenance team <systemd-maint@redhat.com> - 219-78.8e- fstab-generator: Chase symlinks where possible (#6293) (RHEL-6223)
=	systemd maintenance team <systemd-maint@redhat.com> - 219-78.7b- resolve: introduce reference counting on DnsStream (#2110544)<	
systemd maintenance team <systemd-maint@redhat.com> - 219-78.6b- resolved: pin stream while calling callbacks for it (#2110544).;	Ssystemd maintenance team <systemd-maint@redhat.com> - 219-78.5a@- install: fix a potential crash (#1828758)
- acl-util: only set the mask if not present (#2026361) :	7systemd maintenance team <systemd-maint@redhat.com> - 219-78.4a- test: add a test/reproducer for BZ#1989245 (#1989245)
- strv: fix buffer size calculation in strv_join_quoted() (#1989245)
- install: refactor find_symlinks() and don't search for symlinks recursively (#1828758)
?b4?CuMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb46-7[j@- Respin a new release of targetcli to avoid problems with TPS tests.gBu]Maurizio Lombardi <mlombard@redhat.com> - 2.1.fb46-6[!@- handle backups with block-level deletezAuMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb46-5[)- saveconfig: way for block-level save with delete command+@ucMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb46-4Z- Properly detect errors when writing backup files. (Closes: #80) (#81)
- Read number of backup files to keep from file
- config: defend on '/etc/target/backup' directory
- config: backup when current config is different from recent backup copy
- config: rename key 'kept_backups' as 'max_backup_files'
- backup: global option to tune max no. of backup conf files?	)systemd maintenance team <systemd-maint@redhat.com> - 219-78.9e]@- Revert "fstab-generator: Chase symlinks where possible (#6293)" (RHEL-17164)
dFdxIqMaurizio Lombardi <mlombard@redhat.com> - 2.1.53-1_P- Rebase the targetcli package to fix some security issuesbHqWMaurizio Lombardi <mlombard@redhat.com> - 2.1.51-2^- Add the interactive daemon console.aGuQMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb51-1^%@- Update to a new upstream versioncFuUMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb49-3^{G- Respin a new release of targetcli.EuMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb49-2]v>- Get a lock to avoid the issues with concurrent backstore creationbDuSMaurizio Lombardi <mlombard@redhat.com> - 2.1.fb49-1\P@@- Rebase to latest upstream version
G$L}MDavid Kaspar [Dee'Kej] <dkaspar@redhat.com> - 6.18.01-11W9@- Fix regression introduced in tcsh-6.18.01-quote-backslashes-properly.patch
  Related: #1319816K})David Kaspar [Dee'Kej] <dkaspar@redhat.com> - 6.18.01-10WK- Handle the ^C interrupt correctly when using the 'eval' built-in. (#1273500)J}?David Kaspar [Dee'Kej] <dkaspar@redhat.com> -  6.18.01-9Vn@- 'if statement' parsing fixed when the space is missing after ')'. (#1273892)
- Quote backslashes properly to preserve them in `...` expressions. (#1319816)
- Fix for tcsh being interruptible while waiting for child process. (#1269370)
- Fix of memory leak when using the 'source' built-in command.      (#1273513)
- Print error message on stderr (instead of stdout).                (#1273498)
- Use GLIBC's malloc instead of builtin malloc.                     (#1315713)
^/Rc=Jan Macku <jamacku@redhat.com> - 6.18.01-17^y- fix regression caused by backported patch, command var is now set as before (#1842722)QcJan Macku <jamacku@redhat.com> - 6.18.01-16]- fix for rapid memory consumption caused by corrupted history (#1598502)P}!David Kaspar [Dee'Kej] <dkaspar@redhat.com> - 6.18.01-15X@- fix for memory leak when cdpath fails to find a matching path (#1325346)O}3David Kaspar [Dee'Kej] <dkaspar@redhat.com> - 6.18.01-14X- fix hanging of tcsh when .history file is located on remote filesystem (#1388426)%N}ODavid Kaspar [Dee'Kej] <dkaspar@redhat.com> - 6.18.01-13W~- Fix yet another regression in tcsh-6.18.01-quote-backslashes-properly.patch
  Related: #1334751sM}kDavid Kaspar [Dee'Kej] <dkaspar@redhat.com> - 6.18.01-12WF@- Fix another regression in tcsh-6.18.01-quote-backslashes-properly.patch
  Related: #1334751

- Fix regression in tcsh-6.18.01-use-stderr-upon-error.patch
  Related: #1273498
qt?qYm+Michal Ruprich <mruprich@redhat.com> - 1:0.17-62X@- Related: #1367415 - No option to specify IPv6 or IPv4 explicitly must be usedXm-Michal Ruprich <mruprich@redhat.com> - 1:0.17-61XX- Resolves: #1367415 - No option to specify IPv6 or IPv4 explicitly must be used(WqaMartin Sehnoutka <msehnout@redhat.com> - 1:0.17-60Wv[@- Introduce new -i switch
- ip addresses will be logged into utmp instead of hostname
- Resolves: #1323094NVa?Daniel Mach <dmach@redhat.com> - 1:0.17-59RU- Mass rebuild 2014-01-24NUa?Daniel Mach <dmach@redhat.com> - 1:0.17-58Rk- Mass rebuild 2013-12-27To+Michal Sekletar <msekleta@redhat.com> - 1:0.17-57Q@- enable hardened build
- fix dates in changelog
- add systemd to BuildRequiresSo!Jan Macku <jamacku@redhat.com> - 6.18.01-17.el7.1_
@- fix regression caused by corrupted history (#1846271)
- fix typo in spec
I9],IN_a?Daniel Mach <dmach@redhat.com> - 1:0.17-58Rk- Mass rebuild 2013-12-27^o+Michal Sekletar <msekleta@redhat.com> - 1:0.17-57Q@- enable hardened build
- fix dates in changelog
- add systemd to BuildRequires]mMichal Ruprich <mruprich@redhat.com> - 1:0.17-66_i@- Resolves: #1853102 - in.telnetd needs to tolerate temporary EIO errors#\uSMichal Ruprich <michalruprich@gmail.com> - 1:0.17-65^|@- Resolves: #1814476 - Arbitrary remote code execution in utility.c via short writes or urgent dataW[AoMichal Ruprich - 1:0.17-64XQA- Related: #1367415 - No option to specify IPv6 or IPv4 explicitly must be used
                    - more clear formulation of man page note - previous note was a bit ambiguousBZmMichal Ruprich <mruprich@redhat.com> - 1:0.17-63XQ@- Related: #1367415 - No option to specify IPv6 or IPv4 explicitly must be used
                    - additional info added to manpage
=p=WeAoMichal Ruprich - 1:0.17-64XQA- Related: #1367415 - No option to specify IPv6 or IPv4 explicitly must be used
                    - more clear formulation of man page note - previous note was a bit ambiguousBdmMichal Ruprich <mruprich@redhat.com> - 1:0.17-63XQ@- Related: #1367415 - No option to specify IPv6 or IPv4 explicitly must be used
                    - additional info added to manpagecm+Michal Ruprich <mruprich@redhat.com> - 1:0.17-62X@- Related: #1367415 - No option to specify IPv6 or IPv4 explicitly must be usedbm-Michal Ruprich <mruprich@redhat.com> - 1:0.17-61XX- Resolves: #1367415 - No option to specify IPv6 or IPv4 explicitly must be used(aqaMartin Sehnoutka <msehnout@redhat.com> - 1:0.17-60Wv[@- Introduce new -i switch
- ip addresses will be logged into utmp instead of hostname
- Resolves: #1323094N`a?Daniel Mach <dmach@redhat.com> - 1:0.17-59RU- Mass rebuild 2014-01-24

5X|)05QocCEike Rathke <erack@redhat.com> - 102.10.0-1d.@- Update to 102.10.0 build1OnaAEike Rathke <erack@redhat.com> - 102.9.0-2d@- Update to 102.9.0 build1OmaAEike Rathke <erack@redhat.com> - 102.8.0-2c@- Update to 102.8.0 build2OlaAEike Rathke <erack@redhat.com> - 102.8.0-1c1- Update to 102.8.0 build1OkaAEike Rathke <erack@redhat.com> - 102.7.1-2c- Update to 102.7.1 build2OjaAEike Rathke <erack@redhat.com> - 102.7.1-1c@- Update to 102.7.1 build1OiaAEike Rathke <erack@redhat.com> - 102.7.0-1c<@- Update to 102.7.0 build1OhaAEike Rathke <erack@redhat.com> - 102.6.0-2ci@- Update to 102.6.0 build2gmMichal Ruprich <mruprich@redhat.com> - 1:0.17-66_i@- Resolves: #1853102 - in.telnetd needs to tolerate temporary EIO errors#fuSMichal Ruprich <michalruprich@gmail.com> - 1:0.17-65^|@- Resolves: #1814476 - Arbitrary remote code execution in utility.c via short writes or urgent data
\MT[\QzcCEike Rathke <erack@redhat.com> - 102.11.0-1dS@- Update to 102.11.0 build1QycCEike Rathke <erack@redhat.com> - 102.10.0-2d5K- Update to 102.10.0 build2QxcCEike Rathke <erack@redhat.com> - 102.10.0-1d.@- Update to 102.10.0 build1OwaAEike Rathke <erack@redhat.com> - 102.9.0-2d@- Update to 102.9.0 build1OvaAEike Rathke <erack@redhat.com> - 102.8.0-2c@- Update to 102.8.0 build2OuaAEike Rathke <erack@redhat.com> - 102.8.0-1c1- Update to 102.8.0 build1OtaAEike Rathke <erack@redhat.com> - 102.7.1-2c- Update to 102.7.1 build2OsaAEike Rathke <erack@redhat.com> - 102.7.1-1c@- Update to 102.7.1 build1OraAEike Rathke <erack@redhat.com> - 102.7.0-1c<@- Update to 102.7.0 build1Zq};CentOS Sources <bugs@centos.org> - 102.10.0-2.el7.centosd=4- rebrand default prefsQpcCEike Rathke <erack@redhat.com> - 102.10.0-2d5K- Update to 102.10.0 build2
QOVYQZ};CentOS Sources <bugs@centos.org> - 102.12.0-1.el7.centosd- rebrand default prefsQcCEike Rathke <erack@redhat.com> - 102.12.0-1d}@- Update to 102.12.0 build1QcCEike Rathke <erack@redhat.com> - 102.11.0-1dS@- Update to 102.11.0 build1QcCEike Rathke <erack@redhat.com> - 102.10.0-2d5K- Update to 102.10.0 build2QcCEike Rathke <erack@redhat.com> - 102.10.0-1d.@- Update to 102.10.0 build1OaAEike Rathke <erack@redhat.com> - 102.9.0-2d@- Update to 102.9.0 build1OaAEike Rathke <erack@redhat.com> - 102.8.0-2c@- Update to 102.8.0 build2O~aAEike Rathke <erack@redhat.com> - 102.8.0-1c1- Update to 102.8.0 build1O}aAEike Rathke <erack@redhat.com> - 102.7.1-2c- Update to 102.7.1 build2O|aAEike Rathke <erack@redhat.com> - 102.7.1-1c@- Update to 102.7.1 build1Z{};CentOS Sources <bugs@centos.org> - 102.11.0-1.el7.centosdcp@- rebrand default prefs
VZ]^	VQcCEike Rathke <erack@redhat.com> - 102.10.0-1d.@- Update to 102.10.0 build1Z};CentOS Sources <bugs@centos.org> - 102.13.0-2.el7.centosd@- rebrand default prefsQcCEike Rathke <erack@redhat.com> - 102.13.0-2d@- Update to 102.13.0 build2Q
cCEike Rathke <erack@redhat.com> - 102.13.0-1d[@- Update to 102.13.0 build1QcCEike Rathke <erack@redhat.com> - 102.12.0-1d}@- Update to 102.12.0 build1QcCEike Rathke <erack@redhat.com> - 102.11.0-1dS@- Update to 102.11.0 build1Q
cCEike Rathke <erack@redhat.com> - 102.10.0-2d5K- Update to 102.10.0 build2Q	cCEike Rathke <erack@redhat.com> - 102.10.0-1d.@- Update to 102.10.0 build1OaAEike Rathke <erack@redhat.com> - 102.9.0-2d@- Update to 102.9.0 build1OaAEike Rathke <erack@redhat.com> - 102.8.0-2c@- Update to 102.8.0 build2OaAEike Rathke <erack@redhat.com> - 102.8.0-1c1- Update to 102.8.0 build1
UVW]UQcCEike Rathke <erack@redhat.com> - 102.11.0-1dS@- Update to 102.11.0 build1QcCEike Rathke <erack@redhat.com> - 102.10.0-2d5K- Update to 102.10.0 build2Z};CentOS Sources <bugs@centos.org> - 102.14.0-3.el7.centosd- rebrand default prefsKc7Eike Rathke <erack@redhat.com> - 102.14.0-3d- Bump NVR to rebuildRaGJan Horak <jhorak@redhat.com> - 102.14.0-2d- Rebuild due to rhbz#2228948QcCEike Rathke <erack@redhat.com> - 102.14.0-1d- Update to 102.14.0 build1QcCEike Rathke <erack@redhat.com> - 102.13.0-2d@- Update to 102.13.0 build2QcCEike Rathke <erack@redhat.com> - 102.13.0-1d[@- Update to 102.13.0 build1QcCEike Rathke <erack@redhat.com> - 102.12.0-1d}@- Update to 102.12.0 build1QcCEike Rathke <erack@redhat.com> - 102.11.0-1dS@- Update to 102.11.0 build1QcCEike Rathke <erack@redhat.com> - 102.10.0-2d5K- Update to 102.10.0 build2
[VVT[O&aAEike Rathke <erack@redhat.com> - 91.12.0-1bޅ- Update to 91.12.0 build1O%aAEike Rathke <erack@redhat.com> - 91.11.0-2b@- Update to 91.11.0 build2O$aAEike Rathke <erack@redhat.com> - 91.11.0-1bU- Update to 91.11.0 build1Z#};CentOS Sources <bugs@centos.org> - 102.15.0-1.el7.centosd- rebrand default prefsQ"cCEike Rathke <erack@redhat.com> - 102.15.0-1d@- Update to 102.15.0 build1K!c7Eike Rathke <erack@redhat.com> - 102.14.0-3d- Bump NVR to rebuildR aGJan Horak <jhorak@redhat.com> - 102.14.0-2d- Rebuild due to rhbz#2228948QcCEike Rathke <erack@redhat.com> - 102.14.0-1d- Update to 102.14.0 build1QcCEike Rathke <erack@redhat.com> - 102.13.0-2d@- Update to 102.13.0 build2QcCEike Rathke <erack@redhat.com> - 102.13.0-1d[@- Update to 102.13.0 build1QcCEike Rathke <erack@redhat.com> - 102.12.0-1d}@- Update to 102.12.0 build1
a[_\
aO1aAEike Rathke <erack@redhat.com> - 102.4.0-1cMC- Update to 102.4.0 build1R0_IJan Horak <jhorak@redhat.com> - 102.3.0-4cF@- Fix for expat CVE-2022-40674N/_AJan Horak <jhorak@redhat.com> - 102.3.0-3c$e@- Update to 102.3.0 build1O.aAEike Rathke <erack@redhat.com> - 91.13.0-1b{@- Update to 91.13.0 build1Y-{;CentOS Sources <bugs@centos.org> - 102.5.0-2.el7.centosc{h@- rebrand default prefsO,aAEike Rathke <erack@redhat.com> - 102.5.0-2cs@- Update to 102.5.0 build2O+aAEike Rathke <erack@redhat.com> - 102.5.0-1cn9@- Update to 102.5.0 build1O*aAEike Rathke <erack@redhat.com> - 102.4.0-1cMC- Update to 102.4.0 build1R)_IJan Horak <jhorak@redhat.com> - 102.3.0-4cF@- Fix for expat CVE-2022-40674N(_AJan Horak <jhorak@redhat.com> - 102.3.0-3c$e@- Update to 102.3.0 build1O'aAEike Rathke <erack@redhat.com> - 91.13.0-1b{@- Update to 91.13.0 build1

er+V:eD/
bb7eaa756f5d42c513cfe946f0f1ba45130c482c2f40200c3e68e01181b80fedD.
de56cf10dbbabd9a55f388bacf02eb1f5bb04b430bbad9a217d6dc57141aaeb5D-
852bab23cc3bdff5b4cdf1f101f36a4d1fd4e8d3e570d399b4ef0b06e0e29536D,
4c0ef9ca78331cc0b0d030d525a258c4b4b7b48e388c2a3e3c8cf104d2f410efD+
b218ab101b70c9d78787a08804e407030dfd24d15979db45116e871686e88c92D*
70fef3e281063a882efee9c52f35d342cd008f1417571c2af4e4f52c5a4439acD)
f6e16caafd938158d5d693a73fc21601fae109452acfff7e3b9ed72d940a89b7D(
3edc5c8d5cf1dd51b987f3178aa2e996847bacf9b48d9d5f96f0831a21c48b97D'
2ea9b64c6b87755ded68455e09101ffd22979b77f06e55588e58f91c9a0155d1D&
5a404e4d0261a2aa45188a169969665640124c8587bfaff7eaa4706a5f16727dD%
d56ae1d4e0d4b0be63156bddcdb2f72700d55124efafecb654bbb436fd36eca5D$
a5589b3ed616bfece0771799ef3774cb33d200e987dba38dc365b6df40958657D#
6cc9689dc7dfe51e1de149a22559946854b93c2f46f3d9f68ea4bc070cc665ae

Z.{(O;aAEike Rathke <erack@redhat.com> - 102.5.0-2cs@- Update to 102.5.0 build2O:aAEike Rathke <erack@redhat.com> - 102.5.0-1cn9@- Update to 102.5.0 build1O9aAEike Rathke <erack@redhat.com> - 102.4.0-1cMC- Update to 102.4.0 build1R8_IJan Horak <jhorak@redhat.com> - 102.3.0-4cF@- Fix for expat CVE-2022-40674Y7{;CentOS Sources <bugs@centos.org> - 102.6.0-2.el7.centosc@- rebrand default prefsO6aAEike Rathke <erack@redhat.com> - 102.6.0-2ci@- Update to 102.6.0 build2O5aAEike Rathke <erack@redhat.com> - 102.6.0-1c#@- Update to 102.6.0 build14_%Jan Horak <jhorak@redhat.com> - 102.5.0-3c@- Use openssl for the librnp crypto backend to enable the openpgp encryptionO3aAEike Rathke <erack@redhat.com> - 102.5.0-2cs@- Update to 102.5.0 build2O2aAEike Rathke <erack@redhat.com> - 102.5.0-1cn9@- Update to 102.5.0 build1

Rz'.~+RE_%Jan Horak <jhorak@redhat.com> - 102.5.0-3c@- Use openssl for the librnp crypto backend to enable the openpgp encryptionODaAEike Rathke <erack@redhat.com> - 102.5.0-2cs@- Update to 102.5.0 build2OCaAEike Rathke <erack@redhat.com> - 102.5.0-1cn9@- Update to 102.5.0 build1OBaAEike Rathke <erack@redhat.com> - 102.4.0-1cMC- Update to 102.4.0 build1YA{;CentOS Sources <bugs@centos.org> - 102.7.1-1.el7.centosc- rebrand default prefsO@aAEike Rathke <erack@redhat.com> - 102.7.1-1c@- Update to 102.7.1 build1O?aAEike Rathke <erack@redhat.com> - 102.7.0-1c<@- Update to 102.7.0 build1O>aAEike Rathke <erack@redhat.com> - 102.6.0-2ci@- Update to 102.6.0 build2O=aAEike Rathke <erack@redhat.com> - 102.6.0-1c#@- Update to 102.6.0 build1<_%Jan Horak <jhorak@redhat.com> - 102.5.0-3c@- Use openssl for the librnp crypto backend to enable the openpgp encryption
2Za+2OPaAEike Rathke <erack@redhat.com> - 102.7.0-1c<@- Update to 102.7.0 build1OOaAEike Rathke <erack@redhat.com> - 102.6.0-2ci@- Update to 102.6.0 build2ONaAEike Rathke <erack@redhat.com> - 102.6.0-1c#@- Update to 102.6.0 build1M_%Jan Horak <jhorak@redhat.com> - 102.5.0-3c@- Use openssl for the librnp crypto backend to enable the openpgp encryptionOLaAEike Rathke <erack@redhat.com> - 102.5.0-2cs@- Update to 102.5.0 build2YK{;CentOS Sources <bugs@centos.org> - 102.7.1-2.el7.centosc- rebrand default prefsOJaAEike Rathke <erack@redhat.com> - 102.7.1-2c- Update to 102.7.1 build2OIaAEike Rathke <erack@redhat.com> - 102.7.1-1c@- Update to 102.7.1 build1OHaAEike Rathke <erack@redhat.com> - 102.7.0-1c<@- Update to 102.7.0 build1OGaAEike Rathke <erack@redhat.com> - 102.6.0-2ci@- Update to 102.6.0 build2OFaAEike Rathke <erack@redhat.com> - 102.6.0-1c#@- Update to 102.6.0 build1
2ZW~+2O[aAEike Rathke <erack@redhat.com> - 102.7.1-2c- Update to 102.7.1 build2OZaAEike Rathke <erack@redhat.com> - 102.7.1-1c@- Update to 102.7.1 build1OYaAEike Rathke <erack@redhat.com> - 102.7.0-1c<@- Update to 102.7.0 build1OXaAEike Rathke <erack@redhat.com> - 102.6.0-2ci@- Update to 102.6.0 build2OWaAEike Rathke <erack@redhat.com> - 102.6.0-1c#@- Update to 102.6.0 build1V_%Jan Horak <jhorak@redhat.com> - 102.5.0-3c@- Use openssl for the librnp crypto backend to enable the openpgp encryptionYU{;CentOS Sources <bugs@centos.org> - 102.8.0-2.el7.centosc`- rebrand default prefsOTaAEike Rathke <erack@redhat.com> - 102.8.0-2c@- Update to 102.8.0 build2OSaAEike Rathke <erack@redhat.com> - 102.8.0-1c1- Update to 102.8.0 build1ORaAEike Rathke <erack@redhat.com> - 102.7.1-2c- Update to 102.7.1 build2OQaAEike Rathke <erack@redhat.com> - 102.7.1-1c@- Update to 102.7.1 build1
bZW[bOfaAEike Rathke <erack@redhat.com> - 115.8.0-1eB- Update to 115.8.0 build1OeaAEike Rathke <erack@redhat.com> - 115.7.0-1eX- Update to 115.7.0 build1OdaAEike Rathke <erack@redhat.com> - 115.6.0-1e4@- Update to 115.6.0 build2OcaAEike Rathke <erack@redhat.com> - 115.5.0-1e\- Update to 115.5.0 build1ObaAEike Rathke <erack@redhat.com> - 115.4.1-1e9@- Update to 115.4.1 build1RagAAnton Bobrov <abobrov@redhat.com> - 115.4.0-3e7- Update to 115.4.0 build3O`aAEike Rathke <erack@redhat.com> - 115.4.0-2e3@- Update to 115.4.0 build2Y_{;CentOS Sources <bugs@centos.org> - 102.9.0-1.el7.centosd- rebrand default prefsO^aAEike Rathke <erack@redhat.com> - 102.9.0-1d@- Update to 102.9.0 build1O]aAEike Rathke <erack@redhat.com> - 102.8.0-2c@- Update to 102.8.0 build2O\aAEike Rathke <erack@redhat.com> - 102.8.0-1c1- Update to 102.8.0 build1

bov#bjpawEike Rathke <erack@redhat.com> - 115.9.0-1e,- Update to 115.9.0 build1
- Fix expat CVE-2023-52425OoaAEike Rathke <erack@redhat.com> - 115.8.0-1eB- Update to 115.8.0 build1OnaAEike Rathke <erack@redhat.com> - 115.7.0-1eX- Update to 115.7.0 build1OmaAEike Rathke <erack@redhat.com> - 115.6.0-1e4@- Update to 115.6.0 build2OlaAEike Rathke <erack@redhat.com> - 115.5.0-1e\- Update to 115.5.0 build1OkaAEike Rathke <erack@redhat.com> - 115.4.1-1e9@- Update to 115.4.1 build1RjgAAnton Bobrov <abobrov@redhat.com> - 115.4.0-3e7- Update to 115.4.0 build3QicCEike Rathke <erack@redhat.com> - 115.10.0-2f- Update to 115.10.0 build2thcEike Rathke <erack@redhat.com> - 115.10.0-1f"@- Update to 115.10.0 build1
- Revert expat CVE-2023-52425 fixjgawEike Rathke <erack@redhat.com> - 115.9.0-1e,- Update to 115.9.0 build1
- Fix expat CVE-2023-52425

U38wUQzcCEike Rathke <erack@redhat.com> - 115.11.0-1fB- Update to 115.11.0 build2QycCEike Rathke <erack@redhat.com> - 115.10.0-2f- Update to 115.10.0 build2txcEike Rathke <erack@redhat.com> - 115.10.0-1f"@- Update to 115.10.0 build1
- Revert expat CVE-2023-52425 fixjwawEike Rathke <erack@redhat.com> - 115.9.0-1e,- Update to 115.9.0 build1
- Fix expat CVE-2023-52425OvaAEike Rathke <erack@redhat.com> - 115.8.0-1eB- Update to 115.8.0 build1OuaAEike Rathke <erack@redhat.com> - 115.7.0-1eX- Update to 115.7.0 build1OtaAEike Rathke <erack@redhat.com> - 115.6.0-1e4@- Update to 115.6.0 build2QscCEike Rathke <erack@redhat.com> - 115.11.0-1fB- Update to 115.11.0 build2QrcCEike Rathke <erack@redhat.com> - 115.10.0-2f- Update to 115.10.0 build2tqcEike Rathke <erack@redhat.com> - 115.10.0-1f"@- Update to 115.10.0 build1
- Revert expat CVE-2023-52425 fix
 Vaos OaAEike Rathke <erack@redhat.com> - 115.5.0-1e\- Update to 115.5.0 build1OaAEike Rathke <erack@redhat.com> - 115.4.1-1e9@- Update to 115.4.1 build1RgAAnton Bobrov <abobrov@redhat.com> - 115.4.0-3e7- Update to 115.4.0 build3OaAEike Rathke <erack@redhat.com> - 115.4.0-2e3@- Update to 115.4.0 build2OaAEike Rathke <erack@redhat.com> - 115.4.0-1e2k- Update to 115.4.0 build1OaAEike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1 build1Ha3Eike Rathke <erack@redhat.com> - 115.3.0-1e@- Update to 115.3.0G_3Jan Horak <jhorak@redhat.com> - 115.2.1-5d- Update to 115.2.1Q~cCEike Rathke <erack@redhat.com> - 102.11.0-1dS@- Update to 102.11.0 build1Q}cCEike Rathke <erack@redhat.com> - 115.12.1-1fqv- Update to 115.12.1 build1Q|cCEike Rathke <erack@redhat.com> - 115.12.0-2fh<@- Update to 115.12.0 build2Q{cCEike Rathke <erack@redhat.com> - 115.12.0-1ff- Update to 115.12.0 build1
/bpt!{/Ha3Eike Rathke <erack@redhat.com> - 115.3.0-1e@- Update to 115.3.0OaAEike Rathke <erack@redhat.com> - 115.7.0-1eX- Update to 115.7.0 build1OaAEike Rathke <erack@redhat.com> - 115.6.0-1e4@- Update to 115.6.0 build2OaAEike Rathke <erack@redhat.com> - 115.5.0-1e\- Update to 115.5.0 build1OaAEike Rathke <erack@redhat.com> - 115.4.1-1e9@- Update to 115.4.1 build1R
gAAnton Bobrov <abobrov@redhat.com> - 115.4.0-3e7- Update to 115.4.0 build3OaAEike Rathke <erack@redhat.com> - 115.4.0-2e3@- Update to 115.4.0 build2OaAEike Rathke <erack@redhat.com> - 115.4.0-1e2k- Update to 115.4.0 build1O
aAEike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1 build1H	a3Eike Rathke <erack@redhat.com> - 115.3.0-1e@- Update to 115.3.0G_3Jan Horak <jhorak@redhat.com> - 115.2.1-5d- Update to 115.2.1OaAEike Rathke <erack@redhat.com> - 115.6.0-1e4@- Update to 115.6.0 build2
lZ^elOaAEike Rathke <erack@redhat.com> - 115.4.0-1e2k- Update to 115.4.0 build1OaAEike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1 build1OaAEike Rathke <erack@redhat.com> - 115.8.0-1eB- Update to 115.8.0 build1OaAEike Rathke <erack@redhat.com> - 115.7.0-1eX- Update to 115.7.0 build1OaAEike Rathke <erack@redhat.com> - 115.6.0-1e4@- Update to 115.6.0 build2OaAEike Rathke <erack@redhat.com> - 115.5.0-1e\- Update to 115.5.0 build1OaAEike Rathke <erack@redhat.com> - 115.4.1-1e9@- Update to 115.4.1 build1RgAAnton Bobrov <abobrov@redhat.com> - 115.4.0-3e7- Update to 115.4.0 build3OaAEike Rathke <erack@redhat.com> - 115.4.0-2e3@- Update to 115.4.0 build2OaAEike Rathke <erack@redhat.com> - 115.4.0-1e2k- Update to 115.4.0 build1OaAEike Rathke <erack@redhat.com> - 115.3.1-1e@- Update to 115.3.1 build1
fW^JfF(_1Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1F'_1Eike Rathke <erack@redhat.com> - 78.6.0-1_إ@- Update to 78.6.0L&]?Jan Horak <jhorak@redhat.com> - 78.5.1-1_$- Update to 78.5.1 build1j%awEike Rathke <erack@redhat.com> - 115.9.0-1e,- Update to 115.9.0 build1
- Fix expat CVE-2023-52425O$aAEike Rathke <erack@redhat.com> - 115.8.0-1eB- Update to 115.8.0 build1O#aAEike Rathke <erack@redhat.com> - 115.7.0-1eX- Update to 115.7.0 build1O"aAEike Rathke <erack@redhat.com> - 115.6.0-1e4@- Update to 115.6.0 build2O!aAEike Rathke <erack@redhat.com> - 115.5.0-1e\- Update to 115.5.0 build1O aAEike Rathke <erack@redhat.com> - 115.4.1-1e9@- Update to 115.4.1 build1RgAAnton Bobrov <abobrov@redhat.com> - 115.4.0-3e7- Update to 115.4.0 build3OaAEike Rathke <erack@redhat.com> - 115.4.0-2e3@- Update to 115.4.0 build2
Ie_5IM4_?Eike Rathke <erack@redhat.com> - 78.9.0-1`X- Update to 78.9.0 build1M3_?Eike Rathke <erack@redhat.com> - 78.8.0-1`/@- Update to 78.8.0 build1F2_1Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0F1_1Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1F0_1Eike Rathke <erack@redhat.com> - 78.6.0-1_إ@- Update to 78.6.0H/a3Eike Rathke <erack@redhat.com> - 78.10.0-1`- Update to 78.10.0F._1Eike Rathke <erack@redhat.com> - 78.9.1-1`t6@- Update to 78.9.1`-_eEike Rathke <erack@redhat.com> - 78.9.0-3`Y@- Update to 78.9.0 build2, updated langpacksM,_?Eike Rathke <erack@redhat.com> - 78.9.0-2`X- Update to 78.9.0 build2M+_?Eike Rathke <erack@redhat.com> - 78.9.0-1`X- Update to 78.9.0 build1M*_?Eike Rathke <erack@redhat.com> - 78.8.0-1`/@- Update to 78.8.0 build1F)_1Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0

er+V:eD<
70147742c172a9a706e38cf38eb04c08145498f9822bed40df6a19a4dd171abfD;
89b015eb0d04659b187b7cae8d68fd38cdfd6ebc31ef6a4cc9432e777fe5c452D:
412317b2522f388f60a8b9846d99020fa2c884e8557b0552ad09b4218e97803dD9
2079fcbe2c07aa0485612a667be1c81504654629f2931e7110664db306550787D8
111c3beab8a3058046e42edddf8655dcd4e30d6e71bf5aa80d2a92dac1df6951D7
9d6dba1f2b69d9a60186e25386f8b45c69cd3fc28e58774151905a0edfac5a82D6
de7c7cd5bd6465116843083e7515695b436a00a145d6c705355b3e74a55e2b6bD5
f57d7074e8e50a23c9a10a230c6edbd1f48bc3130046704525be72e10c371656D4
228b8ee7bdee5b627106d8959417f2a8b8b2a44b8b631203b220ccb5bf160b83D3
6576a71997c6b88e455bd9405164a03375ea03ef6dfbfc8c070d29e8de1f5324D2
d358a86339e24e16bfcc77c61f6f12dea5c1485847a4bd5eee6a6e06c3634ff2D1
8739cf31df198902b5c4e96ff918fdcbce1f988373e266baf0f5836a83776919D0
4fb95ce0e3bb960c9c63b40c2398ead5b921b09764ee630c5e15c83ef4569e24
+Kbv%w+H@a3Eike Rathke <erack@redhat.com> - 78.10.0-1`- Update to 78.10.0F?_1Eike Rathke <erack@redhat.com> - 78.9.1-1`t6@- Update to 78.9.1`>_eEike Rathke <erack@redhat.com> - 78.9.0-3`Y@- Update to 78.9.0 build2, updated langpacksM=_?Eike Rathke <erack@redhat.com> - 78.9.0-2`X- Update to 78.9.0 build2M<_?Eike Rathke <erack@redhat.com> - 78.9.0-1`X- Update to 78.9.0 build1M;_?Eike Rathke <erack@redhat.com> - 78.8.0-1`/@- Update to 78.8.0 build1F:_1Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0O9aAEike Rathke <erack@redhat.com> - 78.11.0-1`- Update to 78.11.0 build1H8a3Eike Rathke <erack@redhat.com> - 78.10.0-1`- Update to 78.10.0F7_1Eike Rathke <erack@redhat.com> - 78.9.1-1`t6@- Update to 78.9.1`6_eEike Rathke <erack@redhat.com> - 78.9.0-3`Y@- Update to 78.9.0 build2, updated langpacksM5_?Eike Rathke <erack@redhat.com> - 78.9.0-2`X- Update to 78.9.0 build2
rZekrOKaAEike Rathke <erack@redhat.com> - 78.12.0-2`.- Update to 78.12.0 build2OJaAEike Rathke <erack@redhat.com> - 78.12.0-1`- Update to 78.12.0 build1OIaAEike Rathke <erack@redhat.com> - 78.11.0-1`- Update to 78.11.0 build1HHa3Eike Rathke <erack@redhat.com> - 78.10.0-1`- Update to 78.10.0FG_1Eike Rathke <erack@redhat.com> - 78.9.1-1`t6@- Update to 78.9.1`F_eEike Rathke <erack@redhat.com> - 78.9.0-3`Y@- Update to 78.9.0 build2, updated langpacksME_?Eike Rathke <erack@redhat.com> - 78.9.0-2`X- Update to 78.9.0 build2MD_?Eike Rathke <erack@redhat.com> - 78.9.0-1`X- Update to 78.9.0 build1OCaAEike Rathke <erack@redhat.com> - 78.12.0-2`.- Update to 78.12.0 build2OBaAEike Rathke <erack@redhat.com> - 78.12.0-1`- Update to 78.12.0 build1OAaAEike Rathke <erack@redhat.com> - 78.11.0-1`- Update to 78.11.0 build1
ZX^eZ_V_cJan Horak <jhorak@redhat.com> - 78.13.0-2aS@- Use the right name for the appstream fileOUaAEike Rathke <erack@redhat.com> - 78.13.0-1a
@- Update to 78.13.0 build1QT_GJan Horak <jhorak@redhat.com> - 78.12.0-3`t- Rebuild to pickup older nssOSaAEike Rathke <erack@redhat.com> - 78.12.0-2`.- Update to 78.12.0 build2ORaAEike Rathke <erack@redhat.com> - 78.12.0-1`- Update to 78.12.0 build1OQaAEike Rathke <erack@redhat.com> - 78.11.0-1`- Update to 78.11.0 build1HPa3Eike Rathke <erack@redhat.com> - 78.10.0-1`- Update to 78.10.0FO_1Eike Rathke <erack@redhat.com> - 78.9.1-1`t6@- Update to 78.9.1`N_eEike Rathke <erack@redhat.com> - 78.9.0-3`Y@- Update to 78.9.0 build2, updated langpacksOMaAEike Rathke <erack@redhat.com> - 78.13.0-1a
@- Update to 78.13.0 build1QL_GJan Horak <jhorak@redhat.com> - 78.12.0-3`t- Rebuild to pickup older nss
7]
kw7ba_iEike Rathke <erack@redhat.com> - 78.4.0-1_"- Update to 78.4.0 build1
- Disabled telemetryL`]?Jan Horak <jhorak@redhat.com> - 78.3.1-1_s!- Update to 78.3.1 build1_]/Jan Horak <jhorak@redhat.com> - 78.3.0-3_e- Update to 78.3.0 build1
- Remove librdp.so as long as we cannot ship it in RHELL^]?Jan Horak <jhorak@redhat.com> - 78.2.1-1_Wr@- Update to 78.2.1 build1N]_AJan Horak <jhorak@redhat.com> - 68.12.0-1_O@- Update to 68.12.0 build1N\_AJan Horak <jhorak@redhat.com> - 68.11.0-1_)M- Update to 68.11.0 build1N[_AJan Horak <jhorak@redhat.com> - 68.10.0-1_@- Update to 68.10.0 build1LZ]?Jan Horak <jhorak@redhat.com> - 68.9.0-1^3- Update to 68.9.0 build1LY]?Jan Horak <jhorak@redhat.com> - 68.8.0-1^U@- Update to 68.8.0 build2LX]?Jan Horak <jhorak@redhat.com> - 68.7.0-1^- Update to 68.7.0 build1OWaAEike Rathke <erack@redhat.com> - 78.14.0-1a0- Update to 78.14.0 build1
=^j*=Nl_AJan Horak <jhorak@redhat.com> - 68.11.0-1_)M- Update to 68.11.0 build1Mk_?Eike Rathke <erack@redhat.com> - 78.5.0-1_- Update to 78.5.0 build3Fj_1Eike Rathke <erack@redhat.com> - 78.4.3-1_#- Update to 78.4.3bi_iEike Rathke <erack@redhat.com> - 78.4.0-1_"- Update to 78.4.0 build1
- Disabled telemetryLh]?Jan Horak <jhorak@redhat.com> - 78.3.1-1_s!- Update to 78.3.1 build1g]/Jan Horak <jhorak@redhat.com> - 78.3.0-3_e- Update to 78.3.0 build1
- Remove librdp.so as long as we cannot ship it in RHELLf]?Jan Horak <jhorak@redhat.com> - 78.2.1-1_Wr@- Update to 78.2.1 build1Ne_AJan Horak <jhorak@redhat.com> - 68.12.0-1_O@- Update to 68.12.0 build1Nd_AJan Horak <jhorak@redhat.com> - 68.11.0-1_)M- Update to 68.11.0 build1Nc_AJan Horak <jhorak@redhat.com> - 68.10.0-1_@- Update to 68.10.0 build1Lb]?Jan Horak <jhorak@redhat.com> - 68.9.0-1^3- Update to 68.9.0 build1
G^3GLw]?Jan Horak <jhorak@redhat.com> - 78.2.1-1_Wr@- Update to 78.2.1 build1Nv_AJan Horak <jhorak@redhat.com> - 68.12.0-1_O@- Update to 68.12.0 build1Fu_1Eike Rathke <erack@redhat.com> - 78.6.0-1_إ@- Update to 78.6.0Lt]?Jan Horak <jhorak@redhat.com> - 78.5.1-1_$- Update to 78.5.1 build1Ms_?Eike Rathke <erack@redhat.com> - 78.5.0-1_- Update to 78.5.0 build3Fr_1Eike Rathke <erack@redhat.com> - 78.4.3-1_#- Update to 78.4.3bq_iEike Rathke <erack@redhat.com> - 78.4.0-1_"- Update to 78.4.0 build1
- Disabled telemetryLp]?Jan Horak <jhorak@redhat.com> - 78.3.1-1_s!- Update to 78.3.1 build1o]/Jan Horak <jhorak@redhat.com> - 78.3.0-3_e- Update to 78.3.0 build1
- Remove librdp.so as long as we cannot ship it in RHELLn]?Jan Horak <jhorak@redhat.com> - 78.2.1-1_Wr@- Update to 78.2.1 build1Nm_AJan Horak <jhorak@redhat.com> - 68.12.0-1_O@- Update to 68.12.0 build1

gv&v%Ag]/Jan Horak <jhorak@redhat.com> - 78.3.0-3_e- Update to 78.3.0 build1
- Remove librdp.so as long as we cannot ship it in RHELL]?Jan Horak <jhorak@redhat.com> - 78.2.1-1_Wr@- Update to 78.2.1 build1F_1Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1F~_1Eike Rathke <erack@redhat.com> - 78.6.0-1_إ@- Update to 78.6.0L}]?Jan Horak <jhorak@redhat.com> - 78.5.1-1_$- Update to 78.5.1 build1M|_?Eike Rathke <erack@redhat.com> - 78.5.0-1_- Update to 78.5.0 build3F{_1Eike Rathke <erack@redhat.com> - 78.4.3-1_#- Update to 78.4.3bz_iEike Rathke <erack@redhat.com> - 78.4.0-1_"- Update to 78.4.0 build1
- Disabled telemetryLy]?Jan Horak <jhorak@redhat.com> - 78.3.1-1_s!- Update to 78.3.1 build1x]/Jan Horak <jhorak@redhat.com> - 78.3.0-3_e- Update to 78.3.0 build1
- Remove librdp.so as long as we cannot ship it in RHEL
AJ_Ab_iEike Rathke <erack@redhat.com> - 78.4.0-1_"- Update to 78.4.0 build1
- Disabled telemetryL]?Jan Horak <jhorak@redhat.com> - 78.3.1-1_s!- Update to 78.3.1 build1
]/Jan Horak <jhorak@redhat.com> - 78.3.0-3_e- Update to 78.3.0 build1
- Remove librdp.so as long as we cannot ship it in RHELF	_1Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0F_1Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1F_1Eike Rathke <erack@redhat.com> - 78.6.0-1_إ@- Update to 78.6.0L]?Jan Horak <jhorak@redhat.com> - 78.5.1-1_$- Update to 78.5.1 build1M_?Eike Rathke <erack@redhat.com> - 78.5.0-1_- Update to 78.5.0 build3F_1Eike Rathke <erack@redhat.com> - 78.4.3-1_#- Update to 78.4.3b_iEike Rathke <erack@redhat.com> - 78.4.0-1_"- Update to 78.4.0 build1
- Disabled telemetryL]?Jan Horak <jhorak@redhat.com> - 78.3.1-1_s!- Update to 78.3.1 build1
ge7KgF_1Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1F_1Eike Rathke <erack@redhat.com> - 78.6.0-1_إ@- Update to 78.6.0L]?Jan Horak <jhorak@redhat.com> - 78.5.1-1_$- Update to 78.5.1 build1M_?Eike Rathke <erack@redhat.com> - 78.5.0-1_- Update to 78.5.0 build3F_1Eike Rathke <erack@redhat.com> - 78.4.3-1_#- Update to 78.4.3M_?Eike Rathke <erack@redhat.com> - 78.8.0-1`/@- Update to 78.8.0 build1F_1Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0F_1Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1F_1Eike Rathke <erack@redhat.com> - 78.6.0-1_إ@- Update to 78.6.0L]?Jan Horak <jhorak@redhat.com> - 78.5.1-1_$- Update to 78.5.1 build1M_?Eike Rathke <erack@redhat.com> - 78.5.0-1_- Update to 78.5.0 build3F
_1Eike Rathke <erack@redhat.com> - 78.4.3-1_#- Update to 78.4.3
>e_t*>M$_?Eike Rathke <erack@redhat.com> - 78.9.0-1`X- Update to 78.9.0 build1M#_?Eike Rathke <erack@redhat.com> - 78.8.0-1`/@- Update to 78.8.0 build1F"_1Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0F!_1Eike Rathke <erack@redhat.com> - 78.6.1-1_@- Update to 78.6.1F _1Eike Rathke <erack@redhat.com> - 78.6.0-1_إ@- Update to 78.6.0L]?Jan Horak <jhorak@redhat.com> - 78.5.1-1_$- Update to 78.5.1 build1M_?Eike Rathke <erack@redhat.com> - 78.5.0-1_- Update to 78.5.0 build3`_eEike Rathke <erack@redhat.com> - 78.9.0-3`Y@- Update to 78.9.0 build2, updated langpacksM_?Eike Rathke <erack@redhat.com> - 78.9.0-2`X- Update to 78.9.0 build2M_?Eike Rathke <erack@redhat.com> - 78.9.0-1`X- Update to 78.9.0 build1M_?Eike Rathke <erack@redhat.com> - 78.8.0-1`/@- Update to 78.8.0 build1F_1Eike Rathke <erack@redhat.com> - 78.7.0-1`@- Update to 78.7.0
7K_s)7L0]?Jan Horak <jhorak@redhat.com> - 91.9.1-1bw@- Update to 91.9.1 build1M/_?Eike Rathke <erack@redhat.com> - 91.9.0-3bq@- Update to 91.9.0 build3M._?Eike Rathke <erack@redhat.com> - 91.9.0-2bo- Update to 91.9.0 build2F-_1Eike Rathke <erack@redhat.com> - 91.9.0-1bj- Update to 91.9.0F,_1Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0M+_?Eike Rathke <erack@redhat.com> - 91.7.0-2b'E@- Update to 91.7.0 build2M*_?Eike Rathke <erack@redhat.com> - 91.7.0-1b - Update to 91.7.0 build1M)_?Eike Rathke <erack@redhat.com> - 91.6.0-1b	- Update to 91.6.0 build1M(_?Eike Rathke <erack@redhat.com> - 91.5.0-1a+@- Update to 91.5.0 build1F'_1Eike Rathke <erack@redhat.com> - 78.9.1-1`t6@- Update to 78.9.1`&_eEike Rathke <erack@redhat.com> - 78.9.0-3`Y@- Update to 78.9.0 build2, updated langpacksM%_?Eike Rathke <erack@redhat.com> - 78.9.0-2`X- Update to 78.9.0 build2
;\w&2;M<_?Eike Rathke <erack@redhat.com> - 91.7.0-2b'E@- Update to 91.7.0 build2O;aAEike Rathke <erack@redhat.com> - 91.11.0-2b@- Update to 91.11.0 build2O:aAEike Rathke <erack@redhat.com> - 91.11.0-1bU- Update to 91.11.0 build1O9aAEike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1L8]?Jan Horak <jhorak@redhat.com> - 91.9.1-1bw@- Update to 91.9.1 build1M7_?Eike Rathke <erack@redhat.com> - 91.9.0-3bq@- Update to 91.9.0 build3M6_?Eike Rathke <erack@redhat.com> - 91.9.0-2bo- Update to 91.9.0 build2F5_1Eike Rathke <erack@redhat.com> - 91.9.0-1bj- Update to 91.9.0F4_1Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0M3_?Eike Rathke <erack@redhat.com> - 91.7.0-2b'E@- Update to 91.7.0 build2M2_?Eike Rathke <erack@redhat.com> - 91.7.0-1b - Update to 91.7.0 build1O1aAEike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1

er+V:eDI
2949f6a1f906f0892e15a8ee8c20f69ae5d4957c01b49b14336b97a39682d8d2DH
7c759545a38cb6f7d1990533a397e63777b0f5056c0fdbb807b6d6972e8512adDG
b8af2291b240e6adee1241ffbbc596bcb08dc54cfa7eec97883a3840e21871caDF
fe536bc26d329494e0702e1ea45051bf8d51d2c5bd6f3d8f4810b32b738f7d54DE
d75ace9160c666f8c11b19909fd788117c9134c9ec1c12c636f6a45ee642ed18DD
079057e8ac08393331b2846ec1d9b56021f2e524cf0eb682c033f6348fcf31daDC
151bddd3018c3cf341e45301fea7e855900839a749c197c0037edde602eaef35DB
0b185730ee6a43395cfa0f8cd6a7a6749386e567da85ed56e884df2ca709923fDA
36259b436231dc4bfc0fb0c9db4b4bcb6693260e26b5c858fed3e11c71a5be0aD@
69ae41a6c3ac23339ec68078341f79bf409340725c4349483ba59ace78f79028D?
1c34f59825eecb09675665b804b5fed5cfba3340912d9fd887d39770e7d0ae60D>
f009c9c18a2c60a9c998051c6c0a08500ac08b6f4d0b3e130aec02f0bac6afe5D=
097675babe2d377b7544507d5d63c4df6766f7bfa3508a1288be59444b79ef19
Ilz'.IMH_?Eike Rathke <erack@redhat.com> - 91.9.0-2bo- Update to 91.9.0 build2FG_1Eike Rathke <erack@redhat.com> - 91.9.0-1bj- Update to 91.9.0FF_1Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0OEaAEike Rathke <erack@redhat.com> - 91.12.0-1bޅ- Update to 91.12.0 build1ODaAEike Rathke <erack@redhat.com> - 91.11.0-2b@- Update to 91.11.0 build2OCaAEike Rathke <erack@redhat.com> - 91.11.0-1bU- Update to 91.11.0 build1OBaAEike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1LA]?Jan Horak <jhorak@redhat.com> - 91.9.1-1bw@- Update to 91.9.1 build1M@_?Eike Rathke <erack@redhat.com> - 91.9.0-3bq@- Update to 91.9.0 build3M?_?Eike Rathke <erack@redhat.com> - 91.9.0-2bo- Update to 91.9.0 build2F>_1Eike Rathke <erack@redhat.com> - 91.9.0-1bj- Update to 91.9.0F=_1Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0
r_fmrQS_GJan Horak <jhorak@redhat.com> - 78.12.0-3`t- Rebuild to pickup older nssORaAEike Rathke <erack@redhat.com> - 78.12.0-2`.- Update to 78.12.0 build2OQaAEike Rathke <erack@redhat.com> - 78.12.0-1`- Update to 78.12.0 build1OPaAEike Rathke <erack@redhat.com> - 78.11.0-1`- Update to 78.11.0 build1OOaAEike Rathke <erack@redhat.com> - 91.13.0-1b{@- Update to 91.13.0 build1ONaAEike Rathke <erack@redhat.com> - 91.12.0-1bޅ- Update to 91.12.0 build1OMaAEike Rathke <erack@redhat.com> - 91.11.0-2b@- Update to 91.11.0 build2OLaAEike Rathke <erack@redhat.com> - 91.11.0-1bU- Update to 91.11.0 build1OKaAEike Rathke <erack@redhat.com> - 91.10.0-1b- Update to 91.10.0 build1LJ]?Jan Horak <jhorak@redhat.com> - 91.9.1-1bw@- Update to 91.9.1 build1MI_?Eike Rathke <erack@redhat.com> - 91.9.0-3bq@- Update to 91.9.0 build3
UJW^UO^aAEike Rathke <erack@redhat.com> - 78.14.0-1a0- Update to 78.14.0 build1_]_cJan Horak <jhorak@redhat.com> - 78.13.0-2aS@- Use the right name for the appstream fileO\aAEike Rathke <erack@redhat.com> - 78.13.0-1a
@- Update to 78.13.0 build1Q[_GJan Horak <jhorak@redhat.com> - 78.12.0-3`t- Rebuild to pickup older nssOZaAEike Rathke <erack@redhat.com> - 78.12.0-2`.- Update to 78.12.0 build2MY_?Eike Rathke <erack@redhat.com> - 91.2.0-1aZ- Update to 91.2.0 build1LX]?Jan Horak <jhorak@redhat.com> - 91.1.2-1aTU@- Update to 91.1.2 build1LW]?Jan Horak <jhorak@redhat.com> - 91.1.0-1a7T@- Update to 91.1.0 build2OVaAEike Rathke <erack@redhat.com> - 78.14.0-1a0- Update to 78.14.0 build1_U_cJan Horak <jhorak@redhat.com> - 78.13.0-2aS@- Use the right name for the appstream fileOTaAEike Rathke <erack@redhat.com> - 78.13.0-1a
@- Update to 78.13.0 build1
$`m
gu$Mj_?Eike Rathke <erack@redhat.com> - 91.3.0-2a(@- Update to 91.3.0 build2Mi_?Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1Mh_?Eike Rathke <erack@redhat.com> - 91.2.0-1aZ- Update to 91.2.0 build1Lg]?Jan Horak <jhorak@redhat.com> - 91.1.2-1aTU@- Update to 91.1.2 build1Lf]?Jan Horak <jhorak@redhat.com> - 91.1.0-1a7T@- Update to 91.1.0 build2OeaAEike Rathke <erack@redhat.com> - 78.14.0-1a0- Update to 78.14.0 build1_d_cJan Horak <jhorak@redhat.com> - 78.13.0-2aS@- Use the right name for the appstream fileMc_?Eike Rathke <erack@redhat.com> - 91.3.0-2a(@- Update to 19.3.0 build2Mb_?Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1Ma_?Eike Rathke <erack@redhat.com> - 91.2.0-1aZ- Update to 91.2.0 build1L`]?Jan Horak <jhorak@redhat.com> - 91.1.2-1aTU@- Update to 91.1.2 build1L_]?Jan Horak <jhorak@redhat.com> - 91.1.0-1a7T@- Update to 91.1.0 build2
2^iw&2Nv_AEike Rathke <erack@redhat.com> - 91.4.0-3aL- Bump NVR for ppc64 buildMu_?Eike Rathke <erack@redhat.com> - 91.4.0-2a@- Update to 91.4.0 build2Mt_?Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1Ms_?Eike Rathke <erack@redhat.com> - 91.3.0-2a(@- Update to 91.3.0 build2Mr_?Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1Mq_?Eike Rathke <erack@redhat.com> - 91.2.0-1aZ- Update to 91.2.0 build1Lp]?Jan Horak <jhorak@redhat.com> - 91.1.2-1aTU@- Update to 91.1.2 build1Lo]?Jan Horak <jhorak@redhat.com> - 91.1.0-1a7T@- Update to 91.1.0 build2OnaAEike Rathke <erack@redhat.com> - 78.14.0-1a0- Update to 78.14.0 build1Nm_AEike Rathke <erack@redhat.com> - 91.4.0-3aL- Bump NVR for ppc64 buildMl_?Eike Rathke <erack@redhat.com> - 91.4.0-2a@- Update to 91.4.0 build2Mk_?Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1
5_mz(5M_?Eike Rathke <erack@redhat.com> - 91.2.0-1aZ- Update to 91.2.0 build1M_?Eike Rathke <erack@redhat.com> - 91.6.0-1b	- Update to 91.6.0 build1M_?Eike Rathke <erack@redhat.com> - 91.5.0-1a+@- Update to 91.5.0 build1N_AEike Rathke <erack@redhat.com> - 91.4.0-3aL- Bump NVR for ppc64 buildM~_?Eike Rathke <erack@redhat.com> - 91.4.0-2a@- Update to 91.4.0 build2M}_?Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1M|_?Eike Rathke <erack@redhat.com> - 91.3.0-2a(@- Update to 91.3.0 build2M{_?Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1Mz_?Eike Rathke <erack@redhat.com> - 91.2.0-1aZ- Update to 91.2.0 build1Ly]?Jan Horak <jhorak@redhat.com> - 91.1.2-1aTU@- Update to 91.1.2 build1Lx]?Jan Horak <jhorak@redhat.com> - 91.1.0-1a7T@- Update to 91.1.0 build2Mw_?Eike Rathke <erack@redhat.com> - 91.5.0-1a+@- Update to 91.5.0 build1
3^
jw&3M_?Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1M
_?Eike Rathke <erack@redhat.com> - 91.3.0-2a(@- Update to 91.3.0 build2M_?Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1M_?Eike Rathke <erack@redhat.com> - 91.7.0-2b'E@- Update to 91.7.0 build2M
_?Eike Rathke <erack@redhat.com> - 91.7.0-1b - Update to 91.7.0 build1M	_?Eike Rathke <erack@redhat.com> - 91.6.0-1b	- Update to 91.6.0 build1M_?Eike Rathke <erack@redhat.com> - 91.5.0-1a+@- Update to 91.5.0 build1N_AEike Rathke <erack@redhat.com> - 91.4.0-3aL- Bump NVR for ppc64 buildM_?Eike Rathke <erack@redhat.com> - 91.4.0-2a@- Update to 91.4.0 build2M_?Eike Rathke <erack@redhat.com> - 91.4.0-1ac- Update to 91.4.0 build1M_?Eike Rathke <erack@redhat.com> - 91.3.0-2a(@- Update to 91.3.0 build2M_?Eike Rathke <erack@redhat.com> - 91.3.0-1a- Update to 91.3.0 build1
9]j~,9M_?Eike Rathke <erack@redhat.com> - 91.7.0-1b - Update to 91.7.0 build1M_?Eike Rathke <erack@redhat.com> - 91.6.0-1b	- Update to 91.6.0 build1M_?Eike Rathke <erack@redhat.com> - 91.5.0-1a+@- Update to 91.5.0 build1N_AEike Rathke <erack@redhat.com> - 91.4.0-3aL- Bump NVR for ppc64 buildM_?Eike Rathke <erack@redhat.com> - 91.4.0-2a@- Update to 91.4.0 build2F_1Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0M_?Eike Rathke <erack@redhat.com> - 91.7.0-2b'E@- Update to 91.7.0 build2M_?Eike Rathke <erack@redhat.com> - 91.7.0-1b - Update to 91.7.0 build1M_?Eike Rathke <erack@redhat.com> - 91.6.0-1b	- Update to 91.6.0 build1M_?Eike Rathke <erack@redhat.com> - 91.5.0-1a+@- Update to 91.5.0 build1N_AEike Rathke <erack@redhat.com> - 91.4.0-3aL- Bump NVR for ppc64 buildM_?Eike Rathke <erack@redhat.com> - 91.4.0-2a@- Update to 91.4.0 build2
Pey(5PF&_1Eike Rathke <erack@redhat.com> - 91.9.0-1bj- Update to 91.9.0F%_1Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0M$_?Eike Rathke <erack@redhat.com> - 91.7.0-2b'E@- Update to 91.7.0 build2M#_?Eike Rathke <erack@redhat.com> - 91.7.0-1b - Update to 91.7.0 build1M"_?Eike Rathke <erack@redhat.com> - 91.6.0-1b	- Update to 91.6.0 build1M!_?Eike Rathke <erack@redhat.com> - 91.5.0-1a+@- Update to 91.5.0 build1M _?Eike Rathke <erack@redhat.com> - 91.4.0-2a@- Update to 91.4.0 build2M_?Eike Rathke <erack@redhat.com> - 91.9.0-3bq@- Update to 91.9.0 build3M_?Eike Rathke <erack@redhat.com> - 91.9.0-2bo- Update to 91.9.0 build2F_1Eike Rathke <erack@redhat.com> - 91.9.0-1bj- Update to 91.9.0F_1Eike Rathke <erack@redhat.com> - 91.8.0-1bL/@- Update to 91.8.0M_?Eike Rathke <erack@redhat.com> - 91.7.0-2b'E@- Update to 91.7.0 build2
Q^hQ.eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801-e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889p,eJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#14916080+e}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889y*eJan Grulich <jgrulich@redhat.com> - 1.8.0-13[- Add one remaining option to Xvnc manpage
  Resolves: bz#1601880L)]?Jan Horak <jhorak@redhat.com> - 91.9.1-1bw@- Update to 91.9.1 build1M(_?Eike Rathke <erack@redhat.com> - 91.9.0-3bq@- Update to 91.9.0 build3M'_?Eike Rathke <erack@redhat.com> - 91.9.0-2bo- Update to 91.9.0 build2
jL1e5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
0e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191/_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342
-nNF-8_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#16703427eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#16648016e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889p5eJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#149160804e}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889g3emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
2e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822

er+V:eDV
1b79cf7e51fdd270ad47abaf4877bf5ef54856e2842af27bf476d4129bf130cbDU
52f37df997426edd5eb1185b3069bb6f0cbf59be802e98607beb40e5a32434f3DT
2716e4ffcbb6db566a73fd0c27d1df83f2082b07e88c85e2e3382e086a9d8294DS
3da02ed3dc4e5e3639e3507426c68050a9d7e1896480c46dd9016e2bfde917a8DR
e56d1ffa341be20d595bbecff5b341080ab023c5d8420ce4a03813df47621344DQ
626a2e289d1c398ebfec878eca2a5a697890c2e6865f803db0f2579642b2b421DP
e1197686e2dde2402bf2c97fffaafc2a53e90a49b640a6fa6272c09b15d1bcb7DO
0e15a4084dc2ccf63f0b0ad4073f81fdd2a5a9137184d9fd3f72e558dadcb56eDN
8b700371dc8370c8630ae79ceb9e1fea3cdcdc691595db63eb30d8a874968077DM
46bb7deb87e89f41a59af551779c4df4a4f0afad8e7966438568b1534c02fc3bDL
d8331a6dfd4b2d434a4ff55b8287d92617ce478e81f9d0efed00c4b7fea39196DK
c8b6abc5626065638f17e289f7fb74fa496ecaff7832cc8ba0a863022187702fDJ
d1d5c6c9105983f9ee30842fcf4a13fb9df2c9ee2104e6df95600984d8d0c9ed
#q #g<emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
;e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822L:e5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
9e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
>'A_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342@eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801?e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889p>eJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#1491608I=e/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #gEemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
De7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822LCe5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
Be1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
D-J_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342IeJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801He;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889jGesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532IFe/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #gNemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
Me7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822LLe5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
Ke1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
GDG
Re1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191jQesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291jPesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532IOe/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
gUemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
Te7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822LSe5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
D,YeuJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223jXesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291jWesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532IVe/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
44I]e/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)g\emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158A[eJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415HZe-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427
$Hae-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427,`euJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223j_esJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j^esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532
Z:ZdeWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-204369ceJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212AbeJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
*7[*,heuJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223jgesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291jfesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532Dee%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-20587
AjeJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415Hie-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427
W WDme%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-20587leWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-204369keJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212
)NR)preJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#14916080qe}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889ypeJan Grulich <jgrulich@redhat.com> - 1.8.0-13[- Add one remaining option to Xvnc manpage
  Resolves: bz#1601880{oeJan Grulich <jgrulich@redhat.com> - 1.8.0-33fA- Fix crash caused by fix for CVE-2024-31083
  Resolves: RHEL-30976-newJan Grulich <jgrulich@redhat.com> - 1.8.0-32f@- Fix CVE-2024-31080 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIGetSelectedEvents
  Resolves: RHEL-31006
- Fix CVE-2024-31083 tigervnc: xorg-x11-server: User-after-free in ProcRenderAddGlyphs
  Resolves: RHEL-30976
- Fix CVE-2024-31081 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice
  Resolves: RHEL-30993
lS
ve1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191u_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342teJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801se;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889
gyemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
xe7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Lwe5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
KC*
e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191~_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342}eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801|e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889p{eJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#14916080ze}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889
gemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Le5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
>'_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889peJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#1491608Ie/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #gemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822L	e5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
D-_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889j
esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532Ie/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #gemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Le5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
GDG
e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191jesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291jesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532Ie/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
gemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Le5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996bRHYRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{GGGG$G0G<GHGSG^GjGvGGHH&H.H1H8H<HAHEH	JH
NHRHUH
YH]HaHdHhHjHmHrHvHyHHHHHHHHH H!#H"'H#*H$.H%0H&3H'8H)<H*?H+EH,HH-MH.QH/VH0ZH1^H2aH3eH4iH5mH6pH7tH8vH9yH:~H;H<H=H>H?H@HAHB HC$HD'HE+HF/HG3HH6HI:HK<HL?HMDHNHHOKHPQHQTHRYHS]HTbHUfHVjHWmHXq
D,euJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223jesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291jesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532Ie/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
44I#e/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)g"emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158A!eJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415H e-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427
$H'e-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427,&euJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223j%esJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j$esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532
Z:Z*eWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-204369)eJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212A(eJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
*7[*,.euJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223j-esJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j,esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532D+e%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-20587
A0eJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415H/e-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427
W WD3e%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-205872eWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-2043691eJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212
)NR)p8eJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#149160807e}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889y6eJan Grulich <jgrulich@redhat.com> - 1.8.0-13[- Add one remaining option to Xvnc manpage
  Resolves: bz#1601880{5eJan Grulich <jgrulich@redhat.com> - 1.8.0-33fA- Fix crash caused by fix for CVE-2024-31083
  Resolves: RHEL-30976-4ewJan Grulich <jgrulich@redhat.com> - 1.8.0-32f@- Fix CVE-2024-31080 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIGetSelectedEvents
  Resolves: RHEL-31006
- Fix CVE-2024-31083 tigervnc: xorg-x11-server: User-after-free in ProcRenderAddGlyphs
  Resolves: RHEL-30976
- Fix CVE-2024-31081 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice
  Resolves: RHEL-30993

er+V:eDc
63b1ab146204798dae708a4ea6d4d6f395bf1e1c9926c9fa14e4498aa40b071dDb
2524b4985525aeeba914c2536aa270d378e6159677fc4a6e6c2d0f5e10cf03b7Da
87841863f56822350511aa76203106e84213cbf0f0d73dbadb356aac7fe91054D`
5a75bd391a4b8675246d8051d4d1a0e28e7ba932456d922c9e6dfe78320bf4ddD_
73aa4d41c028013891614d9b96e424d2511ce51af87ead1125bd84075eba4b04D^
8a45d170c2b696356237faac6e20f84a8fe83b9b0d0990de4c51df8c043ae548D]
e33353c1f5c8cd09778ece298733e91964fae61ddc04af20b7b6eec95035236cD\
ce1ab686b3cc8d98f3fa3f3c27de632d04b3076d3a9573953d36d0cc337b62c3D[
d7991efb2314af20970eb2c8f5ccbf757b66f3b4443f904f07638d6729d87951DZ
97b7678d75ee215e9c9c2485e486af9ec549e3cc4a432b3c7070cd8b737ab439DY
acf66eaf4814c700b8d03668188f2b09be1df06f54e8dfc7159e8377313b08d1DX
472c45bad9fc5ff6c17193d9dfb942a7291f6edc650f2c9c6c14dbd3dbd515b0DW
1a53c3292a73f1254003ddafa161c57842ace3830adbe515eebac0b44ee7d99a
lS
<e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191;_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342:eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#16648019e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889
g?emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
>e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822L=e5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
KC*
Ee1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191D_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342CeJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801Be;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889pAeJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#14916080@e}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889
gHemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
Ge7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822LFe5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
>'M_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342LeJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801Ke;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889pJeJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#1491608IIe/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #gQemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
Pe7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822LOe5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
Ne1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
D-V_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342UeJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801Te;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889jSesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532IRe/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #gZemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
Ye7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822LXe5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
We1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
GDG
^e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191j]esJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j\esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532I[e/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
gaemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
`e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822L_e5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
D,eeuJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223jdesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291jcesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532Ibe/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
44Iie/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)ghemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158AgeJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415Hfe-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427
$Hme-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427,leuJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223jkesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291jjesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532
Z:ZpeWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-204369oeJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212AneJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
*7[*,teuJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223jsesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291jresJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532Dqe%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-20587
AveJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415Hue-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427
W WDye%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-20587xeWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-204369weJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212
)NR)p~eJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#14916080}e}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889y|eJan Grulich <jgrulich@redhat.com> - 1.8.0-13[- Add one remaining option to Xvnc manpage
  Resolves: bz#1601880{{eJan Grulich <jgrulich@redhat.com> - 1.8.0-33fA- Fix crash caused by fix for CVE-2024-31083
  Resolves: RHEL-30976-zewJan Grulich <jgrulich@redhat.com> - 1.8.0-32f@- Fix CVE-2024-31080 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIGetSelectedEvents
  Resolves: RHEL-31006
- Fix CVE-2024-31083 tigervnc: xorg-x11-server: User-after-free in ProcRenderAddGlyphs
  Resolves: RHEL-30976
- Fix CVE-2024-31081 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice
  Resolves: RHEL-30993
lS
e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889
gemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Le5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
KC*
e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342	eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889peJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#14916080e}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889
gemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158

e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Le5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
>'_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889peJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#1491608Ie/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #gemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Le5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
D-_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889jesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532Ie/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #g emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Le5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
GDG
$e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191j#esJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j"esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532I!e/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
g'emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
&e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822L%e5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
D,+euJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223j*esJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j)esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532I(e/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
44I/e/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)g.emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158A-eJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415H,e-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427
$H3e-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427,2euJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223j1esJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j0esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532
Z:Z6eWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-2043695eJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212A4eJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
*7[*,:euJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223j9esJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j8esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532D7e%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-20587

er+V:eDp
4e89a2934346fd031ae25135a0e99fcabcba01ba6e6d9efece1eaa54d9929e59Do
075385572952a26db77d6708c6b4866e1a5b4e1fcef8f0f9e2ff1918b13c4439Dn
24769d4968eb49e6106e6ccec86baf5eeb3e053dfd03158fb385fd0bfd8b3cd7Dm
81ec5721e33cf86aa5a19edb4af8269a95b79b41d2afc6f593319894b7fd8cf4Dl
5f044c5e59d547e3073ad6d5da425845c091f6e24a072716c7f61b3ecc5688b6Dk
2ad5877d7f45633aac8fe2c12d2a6f3490fa224374fff1161e930b4f55896467Dj
f689ef5286607afcfe9eb7c26a9d7f07776b7313883081a2f3da3e14867271b4Di
c0eafbce155d39e1994ca8d23ba73f0a3e34259c7ce6e24278493c4f837c0075Dh
0b33ebe4a47333d7d3cfb619025360776f080666c4ca5b9dd7a539591cc58c9aDg
f7d0605e20c9b7a067014b7687865aa1141217958d73b9b8d83a71b4da504dafDf
ca2161cc3876646306f0db5c0e9ef5cbff21e55e209ba8bb3bea3329c4748d0aDe
55a90d093b44adee52d01531fa0e512335d53d71c5d5b988d4bc903982900cd6Dd
6ca8c118a949900b7ee2de435dfa29344feecf178d19d4852cfd3f958da2ac14
A<eJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415H;e-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427
W WD?e%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-20587>eWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-204369=eJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212
)NR)pDeJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#14916080Ce}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889yBeJan Grulich <jgrulich@redhat.com> - 1.8.0-13[- Add one remaining option to Xvnc manpage
  Resolves: bz#1601880{AeJan Grulich <jgrulich@redhat.com> - 1.8.0-33fA- Fix crash caused by fix for CVE-2024-31083
  Resolves: RHEL-30976-@ewJan Grulich <jgrulich@redhat.com> - 1.8.0-32f@- Fix CVE-2024-31080 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIGetSelectedEvents
  Resolves: RHEL-31006
- Fix CVE-2024-31083 tigervnc: xorg-x11-server: User-after-free in ProcRenderAddGlyphs
  Resolves: RHEL-30976
- Fix CVE-2024-31081 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice
  Resolves: RHEL-30993
lS
He1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191G_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342FeJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801Ee;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889
gKemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
Je7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822LIe5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
KC*
Qe1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191P_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342OeJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801Ne;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889pMeJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#14916080Le}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889
gTemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
Se7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822LRe5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
>'Y_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342XeJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801We;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889pVeJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#1491608IUe/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #g]emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
\e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822L[e5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
Ze1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
D-b_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342aeJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801`e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889j_esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532I^e/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #gfemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
ee7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Lde5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
ce1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
GDG
je1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191jiesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291jhesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532Ige/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
gmemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
le7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Lke5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
D,qeuJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223jpesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291joesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532Ine/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
44Iue/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)gtemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158AseJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415Hre-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427
$Hye-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427,xeuJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223jwesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291jvesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532
Z:Z|eWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-204369{eJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212AzeJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
*7[*,euJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223jesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j~esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532D}e%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-20587
AeJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415He-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427
W WDe%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-20587eWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-204369eJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212
)NR)p
eJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#14916080	e}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889yeJan Grulich <jgrulich@redhat.com> - 1.8.0-13[- Add one remaining option to Xvnc manpage
  Resolves: bz#1601880{eJan Grulich <jgrulich@redhat.com> - 1.8.0-33fA- Fix crash caused by fix for CVE-2024-31083
  Resolves: RHEL-30976-ewJan Grulich <jgrulich@redhat.com> - 1.8.0-32f@- Fix CVE-2024-31080 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIGetSelectedEvents
  Resolves: RHEL-31006
- Fix CVE-2024-31083 tigervnc: xorg-x11-server: User-after-free in ProcRenderAddGlyphs
  Resolves: RHEL-30976
- Fix CVE-2024-31081 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice
  Resolves: RHEL-30993
lS
e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889
gemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Le5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
KC*
e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889peJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#14916080e}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889
gemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Le5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
>'_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889peJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#1491608Ie/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #g#emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
"e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822L!e5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
 e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
D-(_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342'eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801&e;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889j%esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532I$e/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #g,emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
+e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822L*e5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
)e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
GDG
0e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191j/esJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j.esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532I-e/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
g3emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
2e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822L1e5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
D,7euJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223j6esJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j5esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532I4e/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
44I;e/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)g:emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158A9eJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415H8e-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427

er+V:eD}
3f7e486965cffc49635b45bdebd92b770f1cf0549894d2014fa5b8ac030c214cD|
4ac5393de035d7805106e39277a7b7b6ab0713a00553bee6342fb42b71e80ac3D{
16cbd958b4cd93617722d3eda68b3a078e46f235e47a40ceca9a90151e5ee683Dz
2a26d447506a770f081b5fb28e25fb0f7666bbfffc7c5f065c200fda418823eaDy
7fd90181b9a3e062d087509d186c4ef8394aec39ce24e0670b0a4c7b21d8c381Dx
ee75c5b0a2710a2f96753bcdc8e8b106f33c7eb00f1997b39950eff703900bf2Dw
f86c6c90299668354041eda67783846766ed3c5050562845c55de4a2ebe33c85Dv
05ff5981a0c8f962a35dd854d2cf3aabccd82881efc4d700b5add509d6f0f289Du
7af082c81c1d06e353c77f01f35f6d3cd695a765a542d309f406079af5f14000Dt
d4212ad62f054bb8defbdd91f8b8be6d7cd36ab2c646d79f0ec7c7e36b8a2409Ds
bccabcae0cba84cc84cbbe98ef845532c6d35b342a05aa650c421cfcecc269acDr
37ac533da616e343432c0f1378f9e585ef3a6d8ad632bf56c45e59e7cbb1076aDq
beb197d7c2f90fd69f5bfa094f8d100c9477cf8f5bee05d5d87ab41cff92c6fe
$H?e-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427,>euJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223j=esJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j<esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532
Z:ZBeWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-204369AeJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212A@eJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
*7[*,FeuJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223jEesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291jDesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532DCe%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-20587
AHeJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415HGe-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427
W WDKe%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-20587JeWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-204369IeJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212
)NR)pPeJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#14916080Oe}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889yNeJan Grulich <jgrulich@redhat.com> - 1.8.0-13[- Add one remaining option to Xvnc manpage
  Resolves: bz#1601880{MeJan Grulich <jgrulich@redhat.com> - 1.8.0-33fA- Fix crash caused by fix for CVE-2024-31083
  Resolves: RHEL-30976-LewJan Grulich <jgrulich@redhat.com> - 1.8.0-32f@- Fix CVE-2024-31080 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIGetSelectedEvents
  Resolves: RHEL-31006
- Fix CVE-2024-31083 tigervnc: xorg-x11-server: User-after-free in ProcRenderAddGlyphs
  Resolves: RHEL-30976
- Fix CVE-2024-31081 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice
  Resolves: RHEL-30993
lS
Te1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191S_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342ReJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801Qe;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889
gWemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
Ve7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822LUe5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
KC*
]e1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191\_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342[eJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801Ze;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889pYeJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#14916080Xe}Jan Grulich <jgrulich@redhat.com> - 1.8.0-14\<y- Fix rendering on big endian system
  Resolves: bz#1618777

  Do not automatically kill sessions
  Resolves: bz#1646889
g`emJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
_e7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822L^e5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
>'e_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342deJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801ce;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889pbeJan Grulich <jgrulich@redhat.com> - 1.8.0-15\<y- Reduce size of context menu hint
  Resolves: bz#1491608Iae/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #giemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
he7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Lge5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
fe1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
D-n_EAdam Jackson <ajax@redhat.com> - 1.8.0-18]R@- Rebuild against newer X server to pick up backing store crash fixes
  Resolves: bz#1670342meJan Grulich <jgrulich@redhat.com> - 1.8.0-17\j@- Release pointer grab when cursor leaves window
  Resolves: bz#1664801le;Jan Grulich <jgrulich@redhat.com> - 1.8.0-16\E@- Automatically kill session only when gnome or kde is installed
  Resolves: bz#1646889jkesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532Ije/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
#q #gremJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
qe7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Lpe5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
oe1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191
GDG
ve1Jan Grulich <jgrulich@redhat.com> - 1.8.0-19]@- Use vncserver wrapper script to workaround systemd issues
  Resolves: bz#1747191juesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291jtesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532Ise/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
gyemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158
xe7Jan Grulich <jgrulich@redhat.com> - 1.8.0-21^1- Add upstream patch needed because of previous security fixes
  Resolves: bz#1826822Lwe5Jan Grulich <jgrulich@redhat.com> - 1.8.0-20^O@- Fix stack buffer overflow in CMsgReader::readSetCursor
  Resolves: bz#1791773

- Fix heap buffer overflow in DecodeManager::decodeRect
  Resolves: bz#1791768

- Fix heap buffer overflow in TightDecoder::FilterGradient
  Resolves: bz#1791763

- Fix heap-based buffer overflow triggered from CopyRectDecoder
  Resolves: bz#1791747

- Fix stack use-after-return due to incorrect usage of stack memory in ZRLEDecoder
  Resolves: bz#1791759

- Add option to fallback to empty port when the specified one is taken
  Resolves: bz#1791996
D,}euJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223j|esJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j{esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532Ize/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)
44Ie/Jan Grulich <jgrulich@redhat.com> - 1.8.0-23c]- Rebuild for xorg-x11-server CVEs
  Resolves: CVE-2022-4283 (bz#2154267)
  Resolves: CVE-2022-46340 (bz#2154261)
  Resolves: CVE-2022-46341 (bz#2154264)
  Resolves: CVE-2022-46342 (bz#2154262)
  Resolves: CVE-2022-46343 (bz#2154265)
  Resolves: CVE-2022-46344 (bz#2154266)gemJan Grulich <jgrulich@redhat.com> - 1.8.0-22_- Region handling refresh
  Resolves: bz#1753158AeJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415H~e-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427
$He-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427,euJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223jesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291jesJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532
Z:ZeWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-204369eJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212AeJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
*7[*,euJan Grulich <jgrulich@redhat.com> - 1.8.0-26eB=- Fix CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow
  Resolves: RHEL-15235
- Fix CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty
  Resolves: RHEL-15223jesJan Grulich <jgrulich@redhat.com> - 1.8.0-25d!@- CVE fix for: CVE-2023-1393
  Resolves: bz#2180291j
esJan Grulich <jgrulich@redhat.com> - 1.8.0-24c@- CVE fix for: CVE-2023-0494
  Resolves: bz#2166532D	e%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-20587
AeJan Grulich <jgrulich@redhat.com> - 1.8.0-28ey- Updated fix for CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415H
e-Jan Grulich <jgrulich@redhat.com> - 1.8.0-27es@- Fix CVE-2023-6377 tigervnc: xorg-x11-server: out-of-bounds memory reads/writes in XKB button actions
  Resolves: RHEL-18415
- CVE-2023-6478 tigervnc: xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty
  Resolves: RHEL-18427
W WDe%Jan Grulich <jgrulich@redhat.com> - 1.8.0-31eM@- Fix use after free related to CVE-2024-21886
  Resolves: RHEL-20436
- Fix copy/paste error in the DeviceStateNotify
  Resolves: RHEL-20587eWJan Grulich <jgrulich@redhat.com> - 1.8.0-30ed@- Don't try to get pointer position when the pointer becomes a floating device
  Resolves: RHEL-204369eJan Grulich <jgrulich@redhat.com> - 1.8.0-29e)- Fix CVE-2024-21886 tigervnc: xorg-x11-server: heap buffer overflow in DisableDevice
  Resolves: RHEL-20436
- Fix CVE-2024-21885 tigervnc: xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent
  Resolves: RHEL-20427
- Fix CVE-2024-0229 tigervnc: xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
  Resolves: RHEL-20587
- Fix CVE-2023-6816 tigervnc: xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer
  Resolves: RHEL-21212
^NS^vywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600wyyCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-82\-@- Updated fix for CVE-2019-9636
Resolves: rhbz#1689317xy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-81\@- Security fix for CVE-2019-9636
Resolves: rhbz#1689317{eJan Grulich <jgrulich@redhat.com> - 1.8.0-33fA- Fix crash caused by fix for CVE-2024-31083
  Resolves: RHEL-30976-ewJan Grulich <jgrulich@redhat.com> - 1.8.0-32f@- Fix CVE-2024-31080 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIGetSelectedEvents
  Resolves: RHEL-31006
- Fix CVE-2024-31083 tigervnc: xorg-x11-server: User-after-free in ProcRenderAddGlyphs
  Resolves: RHEL-30976
- Fix CVE-2024-31081 tigervnc: xorg-x11-server: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice
  Resolves: RHEL-30993
4DK^4(yYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481yy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998yy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773lycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551yy}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388xy{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530bRHRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{HZyH[|H\H]H^H_
H`HaHbHcHdHe#Hf(Hg,Hh0Hi3Hj7Hk;Hm?HnBHoFHpHHqKHrPHsTHtWHu]Hv`HweHxiHynHzrH{vH|yH}}H~HHHHHHHH$H)H/H6H<H=H>HBHGHHHLHQHRHVH[H\H`HeHfHjHoHpHtHyHzH~HHHH
HHHHHH H&H*H0H4H9H=HBHFHLHPHVHZH_HcHgHlHpHuHy
gNagy$y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998y#y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773l"ycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551y!y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388x y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530vywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-83\@- Remove unversioned obsoletes
Resolves: rhbz#1703600
jSjx)y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#17041747(ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-84\@- Disallow control chars in http URLs
- Fixes CVE-2019-9740 and CVE-2019-9947
Resolves: rhbz#1704362 and rhbz#1703530x'y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#19181680&yiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(%yYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481
7l70/yiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(.yYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481y-y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998y,y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773l+ycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551y*y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388
 3y6y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-89^t@- Security fix for CVE-2019-16935
Resolves: rhbz#1797998y5y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-88]V- Security fix for CVE-2019-16056
Resolves: rhbz#1750773l4ycCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-87]e@- Fix CVE-2018-20852
Resolves: rhbz#1741551y3y}Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-86\- Security fix for CVE-2019-10160
Resolves: rhbz#1718388x2y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-85\"- Security fix for CVE-2019-9948
Resolves: rhbz#1704174g1gkLumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917x0y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#1918168
/S7/	<q#Jean-Frederic Clere <jclere@redhat.com> 0:7.0.76-7[W- Resolves: rhbz#1602060 Deadlock occurs while sending to a closing sessionv;ywCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-94e@- Security fix for CVE-2023-40217
Resolves: RHEL-9615g:gkLumír Balhar <lbalhar@redhat.com> - 2.7.5-93doM- Fix for CVE-2023-24329
Resolves: rhbz#2173917x9y{Charalampos Stratakis <cstratak@redhat.com> - 2.7.5-92b- Security fix for CVE-2021-3177
Resolves: rhbz#191816808yiCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-91b@- Security fixes for CVE-2020-26116, CVE-2020-26137 and CVE-2022-0391
- Test fixes for the latest expat security release
- Update the certificates utilized in the test suite
Resolves: rhbz#1883014, rhbz#1883632, rhbz#2047376, rhbz#1896494(7yYCharalampos Stratakis <cstratak@redhat.com> - 2.7.5-90_$- Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907)
Resolves: rhbz#1856481

er+V:eD

996fe95f2ff819a29dac70f925ca8ea28c9dd6245d7ec72ffd1ea497c1ac2225D	
564f2d36422f90238f6c163afa40b0bd03b7f8ed4505e447cc0161f41b6507d5D
314863a27a19049fe9480f37f1d931ad115a3966777cfe9685ce45f0eaf763a2D
7c0a15ef78a1950328029433601564ae9606ccc8e17e7470a5e84088ce0cd908D
b7b726f83f6133f92e0037c54e043aa50a4cdcd0b17600cdcd827769833b0ae2D
4f2b6dd685c3fa625585b5fe41f9b3277cb8925b675a3b8add0c89efb81b9de9D
7013395de5d70b992ff1cb20c5fcc916c7f545ed46a9021f6f2105e575039bfcD
821d095b31cdbab402488cd14bacefa75cb451e7fbd956f61a6bc92a68d59f68D
199014d97d9be442d1dce91e30112d132e8c5ac82003d8631976c1607ad2e159D
93d3b99f0fd9bf0940325c81b2d8cadba8f402c03b3b36117a666eb53a39d4aeD
94003135dce2fc46854f2202251cb46b096bbabd25f6b98e55704280bf4d77d8D
a1a79207d7fe88ceb95e5e7c1c63bd1c59cb5a98169680429a87fdd1ee285abaD~
3d1a72d4d1f896acb82915d2121ccc8032a2e15e43ba9390abbf0c6e1ddfdb81
ff=m?Coty Sutherland <csutherl@redhat.com> 0:7.0.76-8[- Resolves: rhbz#1608607 CVE-2018-1336 tomcat: A bug in the UTF 8 decoder can lead to DoS
``>mKCoty Sutherland <csutherl@redhat.com> 0:7.0.76-9\b@- Resolves: rhbz#1641873 CVE-2018-11784 tomcat: Open redirect in default servlet
- Resolves: rhbz#1552375 CVE-2018-1304 tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources
- Resolves: rhbz#1552374 CVE-2018-1305 tomcat: Late application of security constraints can lead to resource exposure for unauthorised users
- Resolves: rhbz#1590182 CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
- Resolves: rhbz#1608609 CVE-2018-8034 tomcat: host name verification missing in WebSocket client
- Resolves: rhbz#1588703 Backport of Negative maxCookieCount value causes exception for Tomcat
- Resolves: rhbz#1472950 shutdown_wait option is not working for Tomcat
- Resolves: rhbz#1455483 Add support for characters "<" and ">" to the possible whitelist values
..
Bo-Coty Sutherland <csutherl@redhat.com> 0:7.0.76-13^- Revert rhbz#1367492 because it caused issues with ipa-server, see rhbz#1831127;Ao	Coty Sutherland <csutherl@redhat.com> 0:7.0.76-12^- Resolves: rhbz#1367492 harden package permissions
- Resolves: rhbz#1523112 tomcat systemd does not cope with - in service names
- Resolves: rhbz#1629162 tomcat-dbcp.jar is missing from tomcat package
- Resolves: rhbz#1822453 Tomcat parses a request having an absolute URI path incorrectly and returns 404 Not Found
- Resolves: rhbz#1795645 connection leak with StatementCache, SlowQueryReport or StatementDecoratorInterceptor
- Resolves: CVE-2019-17563 tomcat: session fixation when using FORM authentication@o#Coty Sutherland <csutherl@redhat.com> 0:7.0.76-11^^F- CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerabilityo?osCoty Sutherland <csutherl@redhat.com> 0:7.0.76-10]nU- Resolves: rhbz#1748541 Bump tomcat release number
x
QxGm?Coty Sutherland <csutherl@redhat.com> 0:7.0.76-8[- Resolves: rhbz#1608607 CVE-2018-1336 tomcat: A bug in the UTF 8 decoder can lead to DoS	Fq#Jean-Frederic Clere <jclere@redhat.com> 0:7.0.76-7[W- Resolves: rhbz#1602060 Deadlock occurs while sending to a closing session,E]}Hui Wang <huwang@redhat.com> 0:7.0.76-16_k8- Resolves: rhbz#1814315 CVE-2020-1935 tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling4Do{Coty Sutherland <csutherl@redhat.com> 0:7.0.76-15_- Resolves: CVE-2020-13935 tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoSqCouCoty Sutherland <csutherl@redhat.com> 0:7.0.76-14^m@- Revert rhbz#1814315 because it caused other issues with ipa-server, see rhbz#1831127
- Resolves: CVE-2020-9484 tomcat: Apache Tomcat Remote Code Execution via session persistence
``HmKCoty Sutherland <csutherl@redhat.com> 0:7.0.76-9\b@- Resolves: rhbz#1641873 CVE-2018-11784 tomcat: Open redirect in default servlet
- Resolves: rhbz#1552375 CVE-2018-1304 tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources
- Resolves: rhbz#1552374 CVE-2018-1305 tomcat: Late application of security constraints can lead to resource exposure for unauthorised users
- Resolves: rhbz#1590182 CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
- Resolves: rhbz#1608609 CVE-2018-8034 tomcat: host name verification missing in WebSocket client
- Resolves: rhbz#1588703 Backport of Negative maxCookieCount value causes exception for Tomcat
- Resolves: rhbz#1472950 shutdown_wait option is not working for Tomcat
- Resolves: rhbz#1455483 Add support for characters "<" and ">" to the possible whitelist values
..
Lo-Coty Sutherland <csutherl@redhat.com> 0:7.0.76-13^- Revert rhbz#1367492 because it caused issues with ipa-server, see rhbz#1831127;Ko	Coty Sutherland <csutherl@redhat.com> 0:7.0.76-12^- Resolves: rhbz#1367492 harden package permissions
- Resolves: rhbz#1523112 tomcat systemd does not cope with - in service names
- Resolves: rhbz#1629162 tomcat-dbcp.jar is missing from tomcat package
- Resolves: rhbz#1822453 Tomcat parses a request having an absolute URI path incorrectly and returns 404 Not Found
- Resolves: rhbz#1795645 connection leak with StatementCache, SlowQueryReport or StatementDecoratorInterceptor
- Resolves: CVE-2019-17563 tomcat: session fixation when using FORM authenticationJo#Coty Sutherland <csutherl@redhat.com> 0:7.0.76-11^^F- CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion VulnerabilityoIosCoty Sutherland <csutherl@redhat.com> 0:7.0.76-10]nU- Resolves: rhbz#1748541 Bump tomcat release number
x
QxQm?Coty Sutherland <csutherl@redhat.com> 0:7.0.76-8[- Resolves: rhbz#1608607 CVE-2018-1336 tomcat: A bug in the UTF 8 decoder can lead to DoS	Pq#Jean-Frederic Clere <jclere@redhat.com> 0:7.0.76-7[W- Resolves: rhbz#1602060 Deadlock occurs while sending to a closing session,O]}Hui Wang <huwang@redhat.com> 0:7.0.76-16_k8- Resolves: rhbz#1814315 CVE-2020-1935 tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling4No{Coty Sutherland <csutherl@redhat.com> 0:7.0.76-15_- Resolves: CVE-2020-13935 tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoSqMouCoty Sutherland <csutherl@redhat.com> 0:7.0.76-14^m@- Revert rhbz#1814315 because it caused other issues with ipa-server, see rhbz#1831127
- Resolves: CVE-2020-9484 tomcat: Apache Tomcat Remote Code Execution via session persistence
``RmKCoty Sutherland <csutherl@redhat.com> 0:7.0.76-9\b@- Resolves: rhbz#1641873 CVE-2018-11784 tomcat: Open redirect in default servlet
- Resolves: rhbz#1552375 CVE-2018-1304 tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources
- Resolves: rhbz#1552374 CVE-2018-1305 tomcat: Late application of security constraints can lead to resource exposure for unauthorised users
- Resolves: rhbz#1590182 CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
- Resolves: rhbz#1608609 CVE-2018-8034 tomcat: host name verification missing in WebSocket client
- Resolves: rhbz#1588703 Backport of Negative maxCookieCount value causes exception for Tomcat
- Resolves: rhbz#1472950 shutdown_wait option is not working for Tomcat
- Resolves: rhbz#1455483 Add support for characters "<" and ">" to the possible whitelist values
..
Vo-Coty Sutherland <csutherl@redhat.com> 0:7.0.76-13^- Revert rhbz#1367492 because it caused issues with ipa-server, see rhbz#1831127;Uo	Coty Sutherland <csutherl@redhat.com> 0:7.0.76-12^- Resolves: rhbz#1367492 harden package permissions
- Resolves: rhbz#1523112 tomcat systemd does not cope with - in service names
- Resolves: rhbz#1629162 tomcat-dbcp.jar is missing from tomcat package
- Resolves: rhbz#1822453 Tomcat parses a request having an absolute URI path incorrectly and returns 404 Not Found
- Resolves: rhbz#1795645 connection leak with StatementCache, SlowQueryReport or StatementDecoratorInterceptor
- Resolves: CVE-2019-17563 tomcat: session fixation when using FORM authenticationTo#Coty Sutherland <csutherl@redhat.com> 0:7.0.76-11^^F- CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion VulnerabilityoSosCoty Sutherland <csutherl@redhat.com> 0:7.0.76-10]nU- Resolves: rhbz#1748541 Bump tomcat release number
x
Qx[m?Coty Sutherland <csutherl@redhat.com> 0:7.0.76-8[- Resolves: rhbz#1608607 CVE-2018-1336 tomcat: A bug in the UTF 8 decoder can lead to DoS	Zq#Jean-Frederic Clere <jclere@redhat.com> 0:7.0.76-7[W- Resolves: rhbz#1602060 Deadlock occurs while sending to a closing session,Y]}Hui Wang <huwang@redhat.com> 0:7.0.76-16_k8- Resolves: rhbz#1814315 CVE-2020-1935 tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling4Xo{Coty Sutherland <csutherl@redhat.com> 0:7.0.76-15_- Resolves: CVE-2020-13935 tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoSqWouCoty Sutherland <csutherl@redhat.com> 0:7.0.76-14^m@- Revert rhbz#1814315 because it caused other issues with ipa-server, see rhbz#1831127
- Resolves: CVE-2020-9484 tomcat: Apache Tomcat Remote Code Execution via session persistence
``\mKCoty Sutherland <csutherl@redhat.com> 0:7.0.76-9\b@- Resolves: rhbz#1641873 CVE-2018-11784 tomcat: Open redirect in default servlet
- Resolves: rhbz#1552375 CVE-2018-1304 tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources
- Resolves: rhbz#1552374 CVE-2018-1305 tomcat: Late application of security constraints can lead to resource exposure for unauthorised users
- Resolves: rhbz#1590182 CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
- Resolves: rhbz#1608609 CVE-2018-8034 tomcat: host name verification missing in WebSocket client
- Resolves: rhbz#1588703 Backport of Negative maxCookieCount value causes exception for Tomcat
- Resolves: rhbz#1472950 shutdown_wait option is not working for Tomcat
- Resolves: rhbz#1455483 Add support for characters "<" and ">" to the possible whitelist values
..
`o-Coty Sutherland <csutherl@redhat.com> 0:7.0.76-13^- Revert rhbz#1367492 because it caused issues with ipa-server, see rhbz#1831127;_o	Coty Sutherland <csutherl@redhat.com> 0:7.0.76-12^- Resolves: rhbz#1367492 harden package permissions
- Resolves: rhbz#1523112 tomcat systemd does not cope with - in service names
- Resolves: rhbz#1629162 tomcat-dbcp.jar is missing from tomcat package
- Resolves: rhbz#1822453 Tomcat parses a request having an absolute URI path incorrectly and returns 404 Not Found
- Resolves: rhbz#1795645 connection leak with StatementCache, SlowQueryReport or StatementDecoratorInterceptor
- Resolves: CVE-2019-17563 tomcat: session fixation when using FORM authentication^o#Coty Sutherland <csutherl@redhat.com> 0:7.0.76-11^^F- CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerabilityo]osCoty Sutherland <csutherl@redhat.com> 0:7.0.76-10]nU- Resolves: rhbz#1748541 Bump tomcat release number
x
Qxem?Coty Sutherland <csutherl@redhat.com> 0:7.0.76-8[- Resolves: rhbz#1608607 CVE-2018-1336 tomcat: A bug in the UTF 8 decoder can lead to DoS	dq#Jean-Frederic Clere <jclere@redhat.com> 0:7.0.76-7[W- Resolves: rhbz#1602060 Deadlock occurs while sending to a closing session,c]}Hui Wang <huwang@redhat.com> 0:7.0.76-16_k8- Resolves: rhbz#1814315 CVE-2020-1935 tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling4bo{Coty Sutherland <csutherl@redhat.com> 0:7.0.76-15_- Resolves: CVE-2020-13935 tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoSqaouCoty Sutherland <csutherl@redhat.com> 0:7.0.76-14^m@- Revert rhbz#1814315 because it caused other issues with ipa-server, see rhbz#1831127
- Resolves: CVE-2020-9484 tomcat: Apache Tomcat Remote Code Execution via session persistence
``fmKCoty Sutherland <csutherl@redhat.com> 0:7.0.76-9\b@- Resolves: rhbz#1641873 CVE-2018-11784 tomcat: Open redirect in default servlet
- Resolves: rhbz#1552375 CVE-2018-1304 tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources
- Resolves: rhbz#1552374 CVE-2018-1305 tomcat: Late application of security constraints can lead to resource exposure for unauthorised users
- Resolves: rhbz#1590182 CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
- Resolves: rhbz#1608609 CVE-2018-8034 tomcat: host name verification missing in WebSocket client
- Resolves: rhbz#1588703 Backport of Negative maxCookieCount value causes exception for Tomcat
- Resolves: rhbz#1472950 shutdown_wait option is not working for Tomcat
- Resolves: rhbz#1455483 Add support for characters "<" and ">" to the possible whitelist values
..
jo-Coty Sutherland <csutherl@redhat.com> 0:7.0.76-13^- Revert rhbz#1367492 because it caused issues with ipa-server, see rhbz#1831127;io	Coty Sutherland <csutherl@redhat.com> 0:7.0.76-12^- Resolves: rhbz#1367492 harden package permissions
- Resolves: rhbz#1523112 tomcat systemd does not cope with - in service names
- Resolves: rhbz#1629162 tomcat-dbcp.jar is missing from tomcat package
- Resolves: rhbz#1822453 Tomcat parses a request having an absolute URI path incorrectly and returns 404 Not Found
- Resolves: rhbz#1795645 connection leak with StatementCache, SlowQueryReport or StatementDecoratorInterceptor
- Resolves: CVE-2019-17563 tomcat: session fixation when using FORM authenticationho#Coty Sutherland <csutherl@redhat.com> 0:7.0.76-11^^F- CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion VulnerabilityogosCoty Sutherland <csutherl@redhat.com> 0:7.0.76-10]nU- Resolves: rhbz#1748541 Bump tomcat release number
x
Qxom?Coty Sutherland <csutherl@redhat.com> 0:7.0.76-8[- Resolves: rhbz#1608607 CVE-2018-1336 tomcat: A bug in the UTF 8 decoder can lead to DoS	nq#Jean-Frederic Clere <jclere@redhat.com> 0:7.0.76-7[W- Resolves: rhbz#1602060 Deadlock occurs while sending to a closing session,m]}Hui Wang <huwang@redhat.com> 0:7.0.76-16_k8- Resolves: rhbz#1814315 CVE-2020-1935 tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling4lo{Coty Sutherland <csutherl@redhat.com> 0:7.0.76-15_- Resolves: CVE-2020-13935 tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoSqkouCoty Sutherland <csutherl@redhat.com> 0:7.0.76-14^m@- Revert rhbz#1814315 because it caused other issues with ipa-server, see rhbz#1831127
- Resolves: CVE-2020-9484 tomcat: Apache Tomcat Remote Code Execution via session persistence
``pmKCoty Sutherland <csutherl@redhat.com> 0:7.0.76-9\b@- Resolves: rhbz#1641873 CVE-2018-11784 tomcat: Open redirect in default servlet
- Resolves: rhbz#1552375 CVE-2018-1304 tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources
- Resolves: rhbz#1552374 CVE-2018-1305 tomcat: Late application of security constraints can lead to resource exposure for unauthorised users
- Resolves: rhbz#1590182 CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
- Resolves: rhbz#1608609 CVE-2018-8034 tomcat: host name verification missing in WebSocket client
- Resolves: rhbz#1588703 Backport of Negative maxCookieCount value causes exception for Tomcat
- Resolves: rhbz#1472950 shutdown_wait option is not working for Tomcat
- Resolves: rhbz#1455483 Add support for characters "<" and ">" to the possible whitelist values
..
to-Coty Sutherland <csutherl@redhat.com> 0:7.0.76-13^- Revert rhbz#1367492 because it caused issues with ipa-server, see rhbz#1831127;so	Coty Sutherland <csutherl@redhat.com> 0:7.0.76-12^- Resolves: rhbz#1367492 harden package permissions
- Resolves: rhbz#1523112 tomcat systemd does not cope with - in service names
- Resolves: rhbz#1629162 tomcat-dbcp.jar is missing from tomcat package
- Resolves: rhbz#1822453 Tomcat parses a request having an absolute URI path incorrectly and returns 404 Not Found
- Resolves: rhbz#1795645 connection leak with StatementCache, SlowQueryReport or StatementDecoratorInterceptor
- Resolves: CVE-2019-17563 tomcat: session fixation when using FORM authenticationro#Coty Sutherland <csutherl@redhat.com> 0:7.0.76-11^^F- CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion VulnerabilityoqosCoty Sutherland <csutherl@redhat.com> 0:7.0.76-10]nU- Resolves: rhbz#1748541 Bump tomcat release number
x
Qxym?Coty Sutherland <csutherl@redhat.com> 0:7.0.76-8[- Resolves: rhbz#1608607 CVE-2018-1336 tomcat: A bug in the UTF 8 decoder can lead to DoS	xq#Jean-Frederic Clere <jclere@redhat.com> 0:7.0.76-7[W- Resolves: rhbz#1602060 Deadlock occurs while sending to a closing session,w]}Hui Wang <huwang@redhat.com> 0:7.0.76-16_k8- Resolves: rhbz#1814315 CVE-2020-1935 tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling4vo{Coty Sutherland <csutherl@redhat.com> 0:7.0.76-15_- Resolves: CVE-2020-13935 tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoSquouCoty Sutherland <csutherl@redhat.com> 0:7.0.76-14^m@- Revert rhbz#1814315 because it caused other issues with ipa-server, see rhbz#1831127
- Resolves: CVE-2020-9484 tomcat: Apache Tomcat Remote Code Execution via session persistence
``zmKCoty Sutherland <csutherl@redhat.com> 0:7.0.76-9\b@- Resolves: rhbz#1641873 CVE-2018-11784 tomcat: Open redirect in default servlet
- Resolves: rhbz#1552375 CVE-2018-1304 tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources
- Resolves: rhbz#1552374 CVE-2018-1305 tomcat: Late application of security constraints can lead to resource exposure for unauthorised users
- Resolves: rhbz#1590182 CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
- Resolves: rhbz#1608609 CVE-2018-8034 tomcat: host name verification missing in WebSocket client
- Resolves: rhbz#1588703 Backport of Negative maxCookieCount value causes exception for Tomcat
- Resolves: rhbz#1472950 shutdown_wait option is not working for Tomcat
- Resolves: rhbz#1455483 Add support for characters "<" and ">" to the possible whitelist values
..
~o-Coty Sutherland <csutherl@redhat.com> 0:7.0.76-13^- Revert rhbz#1367492 because it caused issues with ipa-server, see rhbz#1831127;}o	Coty Sutherland <csutherl@redhat.com> 0:7.0.76-12^- Resolves: rhbz#1367492 harden package permissions
- Resolves: rhbz#1523112 tomcat systemd does not cope with - in service names
- Resolves: rhbz#1629162 tomcat-dbcp.jar is missing from tomcat package
- Resolves: rhbz#1822453 Tomcat parses a request having an absolute URI path incorrectly and returns 404 Not Found
- Resolves: rhbz#1795645 connection leak with StatementCache, SlowQueryReport or StatementDecoratorInterceptor
- Resolves: CVE-2019-17563 tomcat: session fixation when using FORM authentication|o#Coty Sutherland <csutherl@redhat.com> 0:7.0.76-11^^F- CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerabilityo{osCoty Sutherland <csutherl@redhat.com> 0:7.0.76-10]nU- Resolves: rhbz#1748541 Bump tomcat release number
x
Qxm?Coty Sutherland <csutherl@redhat.com> 0:7.0.76-8[- Resolves: rhbz#1608607 CVE-2018-1336 tomcat: A bug in the UTF 8 decoder can lead to DoS	q#Jean-Frederic Clere <jclere@redhat.com> 0:7.0.76-7[W- Resolves: rhbz#1602060 Deadlock occurs while sending to a closing session,]}Hui Wang <huwang@redhat.com> 0:7.0.76-16_k8- Resolves: rhbz#1814315 CVE-2020-1935 tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling4o{Coty Sutherland <csutherl@redhat.com> 0:7.0.76-15_- Resolves: CVE-2020-13935 tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoSqouCoty Sutherland <csutherl@redhat.com> 0:7.0.76-14^m@- Revert rhbz#1814315 because it caused other issues with ipa-server, see rhbz#1831127
- Resolves: CVE-2020-9484 tomcat: Apache Tomcat Remote Code Execution via session persistence
``mKCoty Sutherland <csutherl@redhat.com> 0:7.0.76-9\b@- Resolves: rhbz#1641873 CVE-2018-11784 tomcat: Open redirect in default servlet
- Resolves: rhbz#1552375 CVE-2018-1304 tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources
- Resolves: rhbz#1552374 CVE-2018-1305 tomcat: Late application of security constraints can lead to resource exposure for unauthorised users
- Resolves: rhbz#1590182 CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
- Resolves: rhbz#1608609 CVE-2018-8034 tomcat: host name verification missing in WebSocket client
- Resolves: rhbz#1588703 Backport of Negative maxCookieCount value causes exception for Tomcat
- Resolves: rhbz#1472950 shutdown_wait option is not working for Tomcat
- Resolves: rhbz#1455483 Add support for characters "<" and ">" to the possible whitelist values
..
o-Coty Sutherland <csutherl@redhat.com> 0:7.0.76-13^- Revert rhbz#1367492 because it caused issues with ipa-server, see rhbz#1831127;o	Coty Sutherland <csutherl@redhat.com> 0:7.0.76-12^- Resolves: rhbz#1367492 harden package permissions
- Resolves: rhbz#1523112 tomcat systemd does not cope with - in service names
- Resolves: rhbz#1629162 tomcat-dbcp.jar is missing from tomcat package
- Resolves: rhbz#1822453 Tomcat parses a request having an absolute URI path incorrectly and returns 404 Not Found
- Resolves: rhbz#1795645 connection leak with StatementCache, SlowQueryReport or StatementDecoratorInterceptor
- Resolves: CVE-2019-17563 tomcat: session fixation when using FORM authenticationo#Coty Sutherland <csutherl@redhat.com> 0:7.0.76-11^^F- CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion VulnerabilityoosCoty Sutherland <csutherl@redhat.com> 0:7.0.76-10]nU- Resolves: rhbz#1748541 Bump tomcat release number
x
Qx
m?Coty Sutherland <csutherl@redhat.com> 0:7.0.76-8[- Resolves: rhbz#1608607 CVE-2018-1336 tomcat: A bug in the UTF 8 decoder can lead to DoS	q#Jean-Frederic Clere <jclere@redhat.com> 0:7.0.76-7[W- Resolves: rhbz#1602060 Deadlock occurs while sending to a closing session,]}Hui Wang <huwang@redhat.com> 0:7.0.76-16_k8- Resolves: rhbz#1814315 CVE-2020-1935 tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling4
o{Coty Sutherland <csutherl@redhat.com> 0:7.0.76-15_- Resolves: CVE-2020-13935 tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoSq	ouCoty Sutherland <csutherl@redhat.com> 0:7.0.76-14^m@- Revert rhbz#1814315 because it caused other issues with ipa-server, see rhbz#1831127
- Resolves: CVE-2020-9484 tomcat: Apache Tomcat Remote Code Execution via session persistence
``mKCoty Sutherland <csutherl@redhat.com> 0:7.0.76-9\b@- Resolves: rhbz#1641873 CVE-2018-11784 tomcat: Open redirect in default servlet
- Resolves: rhbz#1552375 CVE-2018-1304 tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources
- Resolves: rhbz#1552374 CVE-2018-1305 tomcat: Late application of security constraints can lead to resource exposure for unauthorised users
- Resolves: rhbz#1590182 CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
- Resolves: rhbz#1608609 CVE-2018-8034 tomcat: host name verification missing in WebSocket client
- Resolves: rhbz#1588703 Backport of Negative maxCookieCount value causes exception for Tomcat
- Resolves: rhbz#1472950 shutdown_wait option is not working for Tomcat
- Resolves: rhbz#1455483 Add support for characters "<" and ">" to the possible whitelist values
..
o-Coty Sutherland <csutherl@redhat.com> 0:7.0.76-13^- Revert rhbz#1367492 because it caused issues with ipa-server, see rhbz#1831127;o	Coty Sutherland <csutherl@redhat.com> 0:7.0.76-12^- Resolves: rhbz#1367492 harden package permissions
- Resolves: rhbz#1523112 tomcat systemd does not cope with - in service names
- Resolves: rhbz#1629162 tomcat-dbcp.jar is missing from tomcat package
- Resolves: rhbz#1822453 Tomcat parses a request having an absolute URI path incorrectly and returns 404 Not Found
- Resolves: rhbz#1795645 connection leak with StatementCache, SlowQueryReport or StatementDecoratorInterceptor
- Resolves: CVE-2019-17563 tomcat: session fixation when using FORM authenticationo#Coty Sutherland <csutherl@redhat.com> 0:7.0.76-11^^F- CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion VulnerabilityoosCoty Sutherland <csutherl@redhat.com> 0:7.0.76-10]nU- Resolves: rhbz#1748541 Bump tomcat release number
x
Qxm?Coty Sutherland <csutherl@redhat.com> 0:7.0.76-8[- Resolves: rhbz#1608607 CVE-2018-1336 tomcat: A bug in the UTF 8 decoder can lead to DoS	q#Jean-Frederic Clere <jclere@redhat.com> 0:7.0.76-7[W- Resolves: rhbz#1602060 Deadlock occurs while sending to a closing session,]}Hui Wang <huwang@redhat.com> 0:7.0.76-16_k8- Resolves: rhbz#1814315 CVE-2020-1935 tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling4o{Coty Sutherland <csutherl@redhat.com> 0:7.0.76-15_- Resolves: CVE-2020-13935 tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoSqouCoty Sutherland <csutherl@redhat.com> 0:7.0.76-14^m@- Revert rhbz#1814315 because it caused other issues with ipa-server, see rhbz#1831127
- Resolves: CVE-2020-9484 tomcat: Apache Tomcat Remote Code Execution via session persistence
``mKCoty Sutherland <csutherl@redhat.com> 0:7.0.76-9\b@- Resolves: rhbz#1641873 CVE-2018-11784 tomcat: Open redirect in default servlet
- Resolves: rhbz#1552375 CVE-2018-1304 tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources
- Resolves: rhbz#1552374 CVE-2018-1305 tomcat: Late application of security constraints can lead to resource exposure for unauthorised users
- Resolves: rhbz#1590182 CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
- Resolves: rhbz#1608609 CVE-2018-8034 tomcat: host name verification missing in WebSocket client
- Resolves: rhbz#1588703 Backport of Negative maxCookieCount value causes exception for Tomcat
- Resolves: rhbz#1472950 shutdown_wait option is not working for Tomcat
- Resolves: rhbz#1455483 Add support for characters "<" and ">" to the possible whitelist values
..
o-Coty Sutherland <csutherl@redhat.com> 0:7.0.76-13^- Revert rhbz#1367492 because it caused issues with ipa-server, see rhbz#1831127;o	Coty Sutherland <csutherl@redhat.com> 0:7.0.76-12^- Resolves: rhbz#1367492 harden package permissions
- Resolves: rhbz#1523112 tomcat systemd does not cope with - in service names
- Resolves: rhbz#1629162 tomcat-dbcp.jar is missing from tomcat package
- Resolves: rhbz#1822453 Tomcat parses a request having an absolute URI path incorrectly and returns 404 Not Found
- Resolves: rhbz#1795645 connection leak with StatementCache, SlowQueryReport or StatementDecoratorInterceptor
- Resolves: CVE-2019-17563 tomcat: session fixation when using FORM authenticationo#Coty Sutherland <csutherl@redhat.com> 0:7.0.76-11^^F- CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion VulnerabilityoosCoty Sutherland <csutherl@redhat.com> 0:7.0.76-10]nU- Resolves: rhbz#1748541 Bump tomcat release number
s
Qs( s_Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-1\|- new release
  - rebased tuned to latest upstream
    related: rhbz#1643654
  - used dmidecode only on x86 architectures
    resolves: rhbz#1688371
  - recommend: fixed to work without tuned daemon running
    resolves: rhbz#1687397,]}Hui Wang <huwang@redhat.com> 0:7.0.76-16_k8- Resolves: rhbz#1814315 CVE-2020-1935 tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling4o{Coty Sutherland <csutherl@redhat.com> 0:7.0.76-15_- Resolves: CVE-2020-13935 tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoSqouCoty Sutherland <csutherl@redhat.com> 0:7.0.76-14^m@- Revert rhbz#1814315 because it caused other issues with ipa-server, see rhbz#1831127
- Resolves: CVE-2020-9484 tomcat: Apache Tomcat Remote Code Execution via session persistence
1n<'1q&sqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}%s	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213$o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595#oEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230"o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
!o-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375
g2
*o-	Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375D)uJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253g(s]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664's7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016
*l:*0s7	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016q/sq	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}.s		Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213-o1	Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595,oE	Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230+o1	Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
'4o1
Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#17061713uK	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984D2u	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253g1s]	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
bMW9s7
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016q8sq
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}7s	
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#16722136o1
Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#17145955oE
Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230
'=u
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-12bz@- disk: added support for the nvme devices
  Resolves: rhbz#1981618<uK
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984D;u
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253g:s]
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664

er+V:eD
662cd360391f504282c0f422539c52fe0554845bd065148bec2cc7ca32f09fceD
488bba15bc1daaf393fe105bb25934f4e99b57cd9d0774beeb3fb7bcd72df936D
a5a85314f27feb920e411ab6a9683cb3e8fd4b1ecc404906653cd728abed4bcbD
0479d5709839258211df37f5f528182b35422b740c858e9fee588961f3067033D
e0e135c635d6d7b7cc130fbb412e09c42992d3447f2a5ee0356a07ef5d6489a9D
17bb69c6badb60ea50ca06dd905f5cf912769e8d8394ed0f28e46698ce95540eD
53dc295cff436bce362e2f1ff515b0cf2e97a55b54554ce10fcc04a18e480028D
aee92b7dc0fa366fb7dc58ba38778eaa69c633a74ec730c35144be5c00ad5baeD
b8fb9ea2d60a9b5cadcc413c18b5359c3c36bee78234865951f0d9441fcd344aD
960bfdc3d9c1208a97afc3a7f003cb7b1890daa08e77d317bc572d4b563e272eD

3f5e731ad10b48db0b27227b5dc172665bd2f7df987c4805e234a12851c320faD
bc48b6efaada693fbc4334eb4916585c339309ea27b400a73cdea90049477bf7D
6ee3e1f10e89d75ee121580fdd4238d1a9c783a16450d6b30b08f4dae782c4b6
{A{Bo1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595AoEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230@o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
?o-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375(>s_Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-1\|- new release
  - rebased tuned to latest upstream
    related: rhbz#1643654
  - used dmidecode only on x86 architectures
    resolves: rhbz#1688371
  - recommend: fixed to work without tuned daemon running
    resolves: rhbz#1687397
gFs]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664Es7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qDsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}Cs	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213
^7s^}Ls	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213Ko1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595JoEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230Io1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
Ho-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375DGuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253
<
q<DPuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253gOs]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664Ns7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qMsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418
\*qVsq
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}Us	
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213To1
Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595SoE
Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230Ro1
Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171QuKJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984
g2ZuK
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984DYu
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253gXs]
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664Ws7
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016
xK%_oEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230^o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
]o-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375(\s_Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-1\|- new release
  - rebased tuned to latest upstream
    related: rhbz#1643654
  - used dmidecode only on x86 architectures
    resolves: rhbz#1688371
  - recommend: fixed to work without tuned daemon running
    resolves: rhbz#1687397[u
Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-12bz@- disk: added support for the nvme devices
  Resolves: rhbz#1981618
\l\cs7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qbsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}as	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213`o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595
9go1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
fo-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375DeuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253gds]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
bMWls7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qksqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}js	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213io1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595hoEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230
'po1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171ouKJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984DnuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253gms]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
bMWus7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qtsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}ss	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213ro1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595qoEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230
'yuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-12bz@- disk: added support for the nvme devices
  Resolves: rhbz#1981618xuKJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984DwuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253gvs]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
{A{~o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595}oEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230|o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
{o-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375(zs_Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-1\|- new release
  - rebased tuned to latest upstream
    related: rhbz#1643654
  - used dmidecode only on x86 architectures
    resolves: rhbz#1688371
  - recommend: fixed to work without tuned daemon running
    resolves: rhbz#1687397
gs]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664s7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}s	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213
^7s^}s	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595oEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
o-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375DuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253
<
q<DuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253gs]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
s7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016q	sqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418
\*qsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}s	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595oEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
uKJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984
g2uKJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984DuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253gs]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664s7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016
xK%oEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
o-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375(s_Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-1\|- new release
  - rebased tuned to latest upstream
    related: rhbz#1643654
  - used dmidecode only on x86 architectures
    resolves: rhbz#1688371
  - recommend: fixed to work without tuned daemon running
    resolves: rhbz#1687397uJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-12bz@- disk: added support for the nvme devices
  Resolves: rhbz#1981618
\l\s7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}s	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595
9#o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
"o-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375D!uJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253g s]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
bMW(s7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016q'sqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}&s	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213%o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595$oEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230
',o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171+uKJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984D*uJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253g)s]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
bMW1s7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016q0sqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}/s	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213.o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595-oEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230
'5uJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-12bz@- disk: added support for the nvme devices
  Resolves: rhbz#19816184uKJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984D3uJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253g2s]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
{A{:o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#17145959oEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#17112308o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
7o-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375(6s_Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-1\|- new release
  - rebased tuned to latest upstream
    related: rhbz#1643654
  - used dmidecode only on x86 architectures
    resolves: rhbz#1688371
  - recommend: fixed to work without tuned daemon running
    resolves: rhbz#1687397
g>s]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664=s7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016q<sqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418};s	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213
^7s^}Ds	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213Co1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595BoEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230Ao1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
@o-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375D?uJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253

er+V:eD$
d43f51759f659c79abdf2a56831458fa8cf1af488cfda2fae914b1dd04bbaba0D#
7e3d2b8310ef0375992c9db512db676147c1e9c655d571aff4a18539c7617b44D"
3345891d8547aab466be25914ccc742f1c11210c09ab84648527d4d266971c3cD!
72a96620c19fb6a9a585ba00fc0f399375dda07b85a42c151bddb6c1323b81c9D 
197c0516912c709ff341d1764b675758fd47d18d35c0f69234271e78366dbad5D
df3f0112c83d6ec1425240197c85476b62397067d6ac0c7e5040adae2a01ff93D
0226602f67b7037375bd2d1258c099113d59cdda599052241225ce267656959fD
268b5774f4a3a55f845738bad78c64c2e69fcd2089e893ce164ec299ecf563caD
2d969a1909d01ab5b4127c7c6dd5f7523026eadbe9500b658c5c3749db47612dD
9a14b340b2f3db002dcaa100cc68ebbcef4cd379500165da1b2fe3276e963ea6D
ece1ae02259706cdcec7364ec892760537f5ace9a72c3942a8fe38bc4c185099D
93ba9f06a5d98fa7404897fad897da748076dbca3329d102d3792d9b20bf8c4dD
cde329dfeb5e14ef8d11d694202b0c974945910ba3f73f3790e665927fce7c52
<
q<DHuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253gGs]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664Fs7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qEsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418
\*qNsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}Ms	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213Lo1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595KoEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230Jo1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171IuKJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984
g2RuKJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984DQuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253gPs]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664Os7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016
xK%WoEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230Vo1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
Uo-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375(Ts_Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-1\|- new release
  - rebased tuned to latest upstream
    related: rhbz#1643654
  - used dmidecode only on x86 architectures
    resolves: rhbz#1688371
  - recommend: fixed to work without tuned daemon running
    resolves: rhbz#1687397SuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-12bz@- disk: added support for the nvme devices
  Resolves: rhbz#1981618
\l\[s7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qZsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}Ys	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213Xo1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595
9_o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
^o-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375D]uJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253g\s]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
bMWds7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qcsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}bs	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213ao1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595`oEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230
'ho1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171guKJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984DfuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253ges]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
bMWms7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qlsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}ks	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213jo1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595ioEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230
'quJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-12bz@- disk: added support for the nvme devices
  Resolves: rhbz#1981618puKJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984DouJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253gns]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
{A{vo1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595uoEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230to1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
so-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375(rs_Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-1\|- new release
  - rebased tuned to latest upstream
    related: rhbz#1643654
  - used dmidecode only on x86 architectures
    resolves: rhbz#1688371
  - recommend: fixed to work without tuned daemon running
    resolves: rhbz#1687397
gzs]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664ys7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qxsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}ws	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213
^7s^}s	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595~oEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230}o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
|o-Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375D{uJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253
<
q<DuJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253gs]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664s7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qsqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418
\*q
sqJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}	s	Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595oEOndřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230o1Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171uKJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984
g2uKJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984D
uJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253gs]Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664s7Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016
xK%oE Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230o1 Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
o- Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375(s_ Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-1\|- new release
  - rebased tuned to latest upstream
    related: rhbz#1643654
  - used dmidecode only on x86 architectures
    resolves: rhbz#1688371
  - recommend: fixed to work without tuned daemon running
    resolves: rhbz#1687397uJaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-12bz@- disk: added support for the nvme devices
  Resolves: rhbz#1981618
\l\s7 Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qsq Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}s	 Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213o1 Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595
9o1!Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171
o-!Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-2\@- Fix setting force_latency in the virtual-host profile
- Resolves: rhbz#1569375Du Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253gs] Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
bMW s7!Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016qsq!Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}s	!Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213o1!Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595oE!Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230
'$o1"Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-3\ڭ- Fixed assertion that isolated_cores contain online CPUs
- Resolves: rhbz#1706171#uK!Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984D"u!Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253g!s]!Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
bMW)s7"Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-8]S- realtime-virtual-guest/host: enabled ktimer-lockless-check
  Resolves: rhbz#1730016q(sq"Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-7]M`@- plugin_sysctl: fixed traceback when assignments modifiers ('<', '>')
  are used with sysctl and the current sysctl value is the same as
  the new value
  Resolves: rhbz#1739418}'s	"Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-6]@1@- sap-hana-vmware: deprecated profile
  Resolves: rhbz#1672213&o1"Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-5\Q- Ignore non-existent settings from system sysctl configs
- Resolves: rhbz#1714595%oE"Ondřej Lysoněk <olysonek@redhat.com> - 2.11.0-4\ޢ@- Fixed verification of sysctl parameters whose values contain tabs
- Resolves: rhbz#1711230
'-u"Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-12bz@- disk: added support for the nvme devices
  Resolves: rhbz#1981618,uK"Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-11_S- sap-netweaver: Use static values for kernel.shmall and kernel.shmmax
  Resolves: rhbz#1904984D+u"Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-10_3- realtime-virtual-host: remove lapic advancement calculation and
  related qemu-kvm-tools-rhev requirement
  Resolves: rhbz#1852253g*s]"Jaroslav Škarvada <jskarvad@redhat.com> - 2.11.0-9^`- Fixed SIGHUP handling
  Resolves: rhbz#1702724
- Tune irqbalance service
  Resolves: rhbz#1720042
- Added netcat requirement
  Resolves: rhbz#1746436
- sysctl: made reapply_sysctl ignore configs from /usr
  Resolves: rhbz#1776149
- profiles: define variables before use
  Resolves: rhbz#1781664
44S0aG#Patsy Griffin <patsy@redhat.com> - 2019c-1]x- Rebase to tzdata-2019c
  - Fiji will observe DST from 2019-11-10 to 2020-01-12.
  - Norfolk Island will begin observing Australian-style DST on 2019-10-06.K/a7#Patsy Griffin <patsy@redhat.com> - 2019b-1]- Rebase to tzdata-2019b
  - Brazil will no longer observe DST going forward.
  - The 2019 spring transition for Palestine occurred 03-29, not 03-30..sM#Patsy Griffin Franklin <patsy@redhat.com> - 2019a-1\@- Rebase to tzdata-2019a
  - Palestine will start DST on 2019-03-30, rather than 2019-03-23 as
    previously predicted.
  - Metlakatla rejoined Alaska time on 2019-01-20, ending its observances
    of Pacific standard time.
Y3aU#Patsy Griffin <patsy@redhat.com> - 2020b-2_P- Need to rebuild, bump the release.V2aM#Patsy Griffin <patsy@redhat.com> - 2020b-1_}- Rebase to tzdata-2020b
  - Yukon timezones represented by America/Whitehorse and
    America/Dawson will change time zone rules from -08/-07 to
    permanent -07 on 2020-11-01, not on 2020-03-08 as 2020a had it.
  - The most recent winter(+08)/summer(+11) transition for Casey Station,
    Antarctica was 2020-10-04 00:01.
  - Remove obsolete files pacificnew, systemv, and yearistype.sh
    from the distribution.01a#Patsy Griffin <patsy@redhat.com> - 2020a-1^- Rebase to tzdata-2020a
  - Morocco will spring forward on 2020-05-31 rather than
    previously predicted 2020-05-24.
  - Canada's Yukon region changed to year round UTC -07
    effective 2020-03-08.
  - America/Godthab was renamed to America/Nuuk.
~@PN~K8a7$Patsy Griffin <patsy@redhat.com> - 2019b-1]- Rebase to tzdata-2019b
  - Brazil will no longer observe DST going forward.
  - The 2019 spring transition for Palestine occurred 03-29, not 03-30.R7aG#Patsy Griffin <patsy@redhat.com> - 2020d-2_"- Update release and rebuild.'6ao#Patsy Griffin <patsy@redhat.com> - 2020d-1_"- Rebase to tzdata-2020d
 - Palestine will end summer time on 2020-10-24 rather than the
   predicted 2020-10-31.k5aw#Patsy Griffin <patsy@redhat.com> - 2020c-1_- Rebase to tzdata-2020c
  - Fiji starts DST later than usual, on 2020-12-20.
  - Rearguard now provides an empty file pacificnew to support
    downstream software that expects it.;4a#Patsy Griffin <patsy@redhat.com> - 2020b-3_- Include the upstream patch to support pacificnew for java tzupdater.
- Set POSIXRULES macro to continue installing posixrules file.
(V;aM$Patsy Griffin <patsy@redhat.com> - 2020b-1_}- Rebase to tzdata-2020b
  - Yukon timezones represented by America/Whitehorse and
    America/Dawson will change time zone rules from -08/-07 to
    permanent -07 on 2020-11-01, not on 2020-03-08 as 2020a had it.
  - The most recent winter(+08)/summer(+11) transition for Casey Station,
    Antarctica was 2020-10-04 00:01.
  - Remove obsolete files pacificnew, systemv, and yearistype.sh
    from the distribution.0:a$Patsy Griffin <patsy@redhat.com> - 2020a-1^- Rebase to tzdata-2020a
  - Morocco will spring forward on 2020-05-31 rather than
    previously predicted 2020-05-24.
  - Canada's Yukon region changed to year round UTC -07
    effective 2020-03-08.
  - America/Godthab was renamed to America/Nuuk.S9aG$Patsy Griffin <patsy@redhat.com> - 2019c-1]x- Rebase to tzdata-2019c
  - Fiji will observe DST from 2019-11-10 to 2020-01-12.
  - Norfolk Island will begin observing Australian-style DST on 2019-10-06.
GR@aG$Patsy Griffin <patsy@redhat.com> - 2020d-2_"- Update release and rebuild.'?ao$Patsy Griffin <patsy@redhat.com> - 2020d-1_"- Rebase to tzdata-2020d
 - Palestine will end summer time on 2020-10-24 rather than the
   predicted 2020-10-31.k>aw$Patsy Griffin <patsy@redhat.com> - 2020c-1_- Rebase to tzdata-2020c
  - Fiji starts DST later than usual, on 2020-12-20.
  - Rearguard now provides an empty file pacificnew to support
    downstream software that expects it.;=a$Patsy Griffin <patsy@redhat.com> - 2020b-3_- Include the upstream patch to support pacificnew for java tzupdater.
- Set POSIXRULES macro to continue installing posixrules file.Y<aU$Patsy Griffin <patsy@redhat.com> - 2020b-2_P- Need to rebuild, bump the release.bRI'RY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{HHƒHÃHăHŃHƃHǃHȃ#HɃ(Hʃ,H˃1H̃5H̓:H΃>HσDHуHH҃NHӃRHԃWHՃ[Hփ_H׃dH؃hHكmHڃqHۃvH܃zH݃HރH߃
HHHHH H$H)H-H0H3H8H;H@HCHGHLHPHRHTHXHZH\H`HcHeHiHkHmHqHtIvIzI}IIIIIII	I
II I
$I(I-I1I4I:I=IBIEIIINIRITIVIZI\I^IbI eI!gI"kI#mI$oI%sI&v
0=e00Ca%Patsy Griffin <patsy@redhat.com> - 2020a-1^- Rebase to tzdata-2020a
  - Morocco will spring forward on 2020-05-31 rather than
    previously predicted 2020-05-24.
  - Canada's Yukon region changed to year round UTC -07
    effective 2020-03-08.
  - America/Godthab was renamed to America/Nuuk.SBaG%Patsy Griffin <patsy@redhat.com> - 2019c-1]x- Rebase to tzdata-2019c
  - Fiji will observe DST from 2019-11-10 to 2020-01-12.
  - Norfolk Island will begin observing Australian-style DST on 2019-10-06.>Aa$Patsy Griffin <patsy@redhat.com> - 2020f-1_@- Rebase to tzdata-2020f including changes for tzdata-2020e
  - tzdata-2020f fixes a bug in tzdata-2020e that caused an
    invalid zi file in rearguard format
  - Volgograd changes time zone from UTC+04 to UTC+03 on 2020-12-27.
  - Australia/Currie is identical to Australia/Hobart for all
    timestamps since 1970 and was therefore created by mistake,
    now moved to the "backward" file.

er+V:eD1
3598bf42bdc531b55ad9bbe89ca716bd42b7f2e4ff19fa4082235369c9a26303D0
2729d48cb21bb132a7a1c8ea58f36f1994b4d757d2752e75e27d2266774a0de0D/
84b67246d4b4d43e8127de0275d0f6e2904295a58a879e7d64b8a9d7890561e9D.
94f2a00b93b3f897df457012da67dd3358c6c280b2c7b40b81b965f4420ce5b1D-
4af524ef4c3174e29991b9c0e236ba3d89b8d2c935d9359910aca965ba5001caD,
82eb45d206c4798cbb97d743814081a5b2e5621151b5d0be9cb94ebcdb32447aD+
77f8b56d670e17fdf230395120c7cac1c190ab7df682f7afe91f4299ef0e0357D*
0f63545c1582739bc1542a1eaf0c5dce4c4ef0527df85045f95f6e3e58f7dc1aD)
249f14138ea4a9e978acfe243db005efa9310dc87776a7c89364e9d0332dc70bD(
ef535692955e3b9dc14a633b487f86ba36720866a39c354e86275b7f23d6adbaD'
62fb9bed135072100886d8af661320bffe7159a6a42c55a6edc43a35171437d3D&
717d93d915b4145b601363d9eea5ba57a7d532d16a4390f52cb99c069c612c19D%
4b0430168f86ed2d3205e156f91cb895de8e9f80a08f08355aaaed21286d7be5
%kGaw%Patsy Griffin <patsy@redhat.com> - 2020c-1_- Rebase to tzdata-2020c
  - Fiji starts DST later than usual, on 2020-12-20.
  - Rearguard now provides an empty file pacificnew to support
    downstream software that expects it.;Fa%Patsy Griffin <patsy@redhat.com> - 2020b-3_- Include the upstream patch to support pacificnew for java tzupdater.
- Set POSIXRULES macro to continue installing posixrules file.YEaU%Patsy Griffin <patsy@redhat.com> - 2020b-2_P- Need to rebuild, bump the release.VDaM%Patsy Griffin <patsy@redhat.com> - 2020b-1_}- Rebase to tzdata-2020b
  - Yukon timezones represented by America/Whitehorse and
    America/Dawson will change time zone rules from -08/-07 to
    permanent -07 on 2020-11-01, not on 2020-03-08 as 2020a had it.
  - The most recent winter(+08)/summer(+11) transition for Casey Station,
    Antarctica was 2020-10-04 00:01.
  - Remove obsolete files pacificnew, systemv, and yearistype.sh
    from the distribution.
PT;PYLaU&Patsy Griffin <patsy@redhat.com> - 2020b-2_P- Need to rebuild, bump the release.	Ka3%Patsy Griffin <patsy@redhat.com> - 2021a-1`
a@- Rebase to tzdata-2021a
  - South Sudan will change from +03 to +02 on 2021-02-01.>Ja%Patsy Griffin <patsy@redhat.com> - 2020f-1_@- Rebase to tzdata-2020f including changes for tzdata-2020e
  - tzdata-2020f fixes a bug in tzdata-2020e that caused an
    invalid zi file in rearguard format
  - Volgograd changes time zone from UTC+04 to UTC+03 on 2020-12-27.
  - Australia/Currie is identical to Australia/Hobart for all
    timestamps since 1970 and was therefore created by mistake,
    now moved to the "backward" file.RIaG%Patsy Griffin <patsy@redhat.com> - 2020d-2_"- Update release and rebuild.'Hao%Patsy Griffin <patsy@redhat.com> - 2020d-1_"- Rebase to tzdata-2020d
 - Palestine will end summer time on 2020-10-24 rather than the
   predicted 2020-10-31.
N@PNRPaG&Patsy Griffin <patsy@redhat.com> - 2020d-2_"- Update release and rebuild.'Oao&Patsy Griffin <patsy@redhat.com> - 2020d-1_"- Rebase to tzdata-2020d
 - Palestine will end summer time on 2020-10-24 rather than the
   predicted 2020-10-31.kNaw&Patsy Griffin <patsy@redhat.com> - 2020c-1_- Rebase to tzdata-2020c
  - Fiji starts DST later than usual, on 2020-12-20.
  - Rearguard now provides an empty file pacificnew to support
    downstream software that expects it.;Ma&Patsy Griffin <patsy@redhat.com> - 2020b-3_- Include the upstream patch to support pacificnew for java tzupdater.
- Set POSIXRULES macro to continue installing posixrules file.
=	Ra3&Patsy Griffin <patsy@redhat.com> - 2021a-1`
a@- Rebase to tzdata-2021a
  - South Sudan will change from +03 to +02 on 2021-02-01.>Qa&Patsy Griffin <patsy@redhat.com> - 2020f-1_@- Rebase to tzdata-2020f including changes for tzdata-2020e
  - tzdata-2020f fixes a bug in tzdata-2020e that caused an
    invalid zi file in rearguard format
  - Volgograd changes time zone from UTC+04 to UTC+03 on 2020-12-27.
  - Australia/Currie is identical to Australia/Hobart for all
    timestamps since 1970 and was therefore created by mistake,
    now moved to the "backward" file.
QQTTaK&Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.RSaE&Patsy Griffin <patsy@redhat.com> - 2021b-1aO@- Rebase to tzdata-2021b
  - Innclude patch for Mayen
  - Jordan now starts DST on February's last Thursday.
  - Samoa no longer observes DST.
  - Merge more location-based Zones whose timestamps agree since 1970.
  - Move some backward-compatibility links to 'backward'.
  - Rename Pacific/Enderbury to Pacific/Kanton.
  - Correct many pre-1993 transitions in Malawi, Portugal, etc.
  - zic now creates each output file or link atomically.
  - zic -L no longer omits the POSIX TZ string in its output.
  - zic fixes for truncation and leap second table expiration.
  - zic now follows POSIX for TZ strings using all-year DST.
  - Fix some localtime crashes and bugs in obscure cases.
  - zdump -v now outputs more-useful boundary cases.
  - tzfile.5 better matches a draft successor to RFC 8536.
 tRXaG'Patsy Griffin <patsy@redhat.com> - 2020d-2_"- Update release and rebuild.'Wao'Patsy Griffin <patsy@redhat.com> - 2020d-1_"- Rebase to tzdata-2020d
 - Palestine will end summer time on 2020-10-24 rather than the
   predicted 2020-10-31.kVaw'Patsy Griffin <patsy@redhat.com> - 2020c-1_- Rebase to tzdata-2020c
  - Fiji starts DST later than usual, on 2020-12-20.
  - Rearguard now provides an empty file pacificnew to support
    downstream software that expects it.kUaw&Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.
=	Za3'Patsy Griffin <patsy@redhat.com> - 2021a-1`
a@- Rebase to tzdata-2021a
  - South Sudan will change from +03 to +02 on 2021-02-01.>Ya'Patsy Griffin <patsy@redhat.com> - 2020f-1_@- Rebase to tzdata-2020f including changes for tzdata-2020e
  - tzdata-2020f fixes a bug in tzdata-2020e that caused an
    invalid zi file in rearguard format
  - Volgograd changes time zone from UTC+04 to UTC+03 on 2020-12-27.
  - Australia/Currie is identical to Australia/Hobart for all
    timestamps since 1970 and was therefore created by mistake,
    now moved to the "backward" file.
QQT\aK'Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.R[aE'Patsy Griffin <patsy@redhat.com> - 2021b-1aO@- Rebase to tzdata-2021b
  - Innclude patch for Mayen
  - Jordan now starts DST on February's last Thursday.
  - Samoa no longer observes DST.
  - Merge more location-based Zones whose timestamps agree since 1970.
  - Move some backward-compatibility links to 'backward'.
  - Rename Pacific/Enderbury to Pacific/Kanton.
  - Correct many pre-1993 transitions in Malawi, Portugal, etc.
  - zic now creates each output file or link atomically.
  - zic -L no longer omits the POSIX TZ string in its output.
  - zic fixes for truncation and leap second table expiration.
  - zic now follows POSIX for TZ strings using all-year DST.
  - Fix some localtime crashes and bugs in obscure cases.
  - zdump -v now outputs more-useful boundary cases.
  - tzfile.5 better matches a draft successor to RFC 8536.
bJb'`ao(Patsy Griffin <patsy@redhat.com> - 2020d-1_"- Rebase to tzdata-2020d
 - Palestine will end summer time on 2020-10-24 rather than the
   predicted 2020-10-31.7_a'Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.A^a#'Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".k]aw'Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.
YY	ca3(Patsy Griffin <patsy@redhat.com> - 2021a-1`
a@- Rebase to tzdata-2021a
  - South Sudan will change from +03 to +02 on 2021-02-01.>ba(Patsy Griffin <patsy@redhat.com> - 2020f-1_@- Rebase to tzdata-2020f including changes for tzdata-2020e
  - tzdata-2020f fixes a bug in tzdata-2020e that caused an
    invalid zi file in rearguard format
  - Volgograd changes time zone from UTC+04 to UTC+03 on 2020-12-27.
  - Australia/Currie is identical to Australia/Hobart for all
    timestamps since 1970 and was therefore created by mistake,
    now moved to the "backward" file.RaaG(Patsy Griffin <patsy@redhat.com> - 2020d-2_"- Update release and rebuild.
QQTeaK(Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.RdaE(Patsy Griffin <patsy@redhat.com> - 2021b-1aO@- Rebase to tzdata-2021b
  - Innclude patch for Mayen
  - Jordan now starts DST on February's last Thursday.
  - Samoa no longer observes DST.
  - Merge more location-based Zones whose timestamps agree since 1970.
  - Move some backward-compatibility links to 'backward'.
  - Rename Pacific/Enderbury to Pacific/Kanton.
  - Correct many pre-1993 transitions in Malawi, Portugal, etc.
  - zic now creates each output file or link atomically.
  - zic -L no longer omits the POSIX TZ string in its output.
  - zic fixes for truncation and leap second table expiration.
  - zic now follows POSIX for TZ strings using all-year DST.
  - Fix some localtime crashes and bugs in obscure cases.
  - zdump -v now outputs more-useful boundary cases.
  - tzfile.5 better matches a draft successor to RFC 8536.
Jmia{(Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data7ha(Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.Aga#(Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".kfaw(Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.
=	ka3)Patsy Griffin <patsy@redhat.com> - 2021a-1`
a@- Rebase to tzdata-2021a
  - South Sudan will change from +03 to +02 on 2021-02-01.>ja)Patsy Griffin <patsy@redhat.com> - 2020f-1_@- Rebase to tzdata-2020f including changes for tzdata-2020e
  - tzdata-2020f fixes a bug in tzdata-2020e that caused an
    invalid zi file in rearguard format
  - Volgograd changes time zone from UTC+04 to UTC+03 on 2020-12-27.
  - Australia/Currie is identical to Australia/Hobart for all
    timestamps since 1970 and was therefore created by mistake,
    now moved to the "backward" file.
QQTmaK)Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.RlaE)Patsy Griffin <patsy@redhat.com> - 2021b-1aO@- Rebase to tzdata-2021b
  - Innclude patch for Mayen
  - Jordan now starts DST on February's last Thursday.
  - Samoa no longer observes DST.
  - Merge more location-based Zones whose timestamps agree since 1970.
  - Move some backward-compatibility links to 'backward'.
  - Rename Pacific/Enderbury to Pacific/Kanton.
  - Correct many pre-1993 transitions in Malawi, Portugal, etc.
  - zic now creates each output file or link atomically.
  - zic -L no longer omits the POSIX TZ string in its output.
  - zic fixes for truncation and leap second table expiration.
  - zic now follows POSIX for TZ strings using all-year DST.
  - Fix some localtime crashes and bugs in obscure cases.
  - zdump -v now outputs more-useful boundary cases.
  - tzfile.5 better matches a draft successor to RFC 8536.
Jmqa{)Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data7pa)Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.Aoa#)Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".knaw)Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.
II	ta3*Patsy Griffin <patsy@redhat.com> - 2021a-1`
a@- Rebase to tzdata-2021a
  - South Sudan will change from +03 to +02 on 2021-02-01.bsae)Patsy Griffin <patsy@redhat.com> - 2022c-1b- Rebase to tzdata-2022c - supersedes tzdata-2022b
  - Add a work-around for an awk bug in FreeBSD, macOS, etc.
  - Improve tzselect with respect to intercontinental Zones.=ra)Patsy Griffin <patsy@redhat.com> - 2022b-1b- Rebase to tzdata-2022b
  - Chile transitions to DST on 2022-09-11, not 2022-09-04
  - 'make install' now defaults LOCALTIME to Factory rather than GMT
  - More zones that are the same since 1970 have been moved to backzone.
  - Include patch for awk workaround.
QQTvaK*Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.RuaE*Patsy Griffin <patsy@redhat.com> - 2021b-1aO@- Rebase to tzdata-2021b
  - Innclude patch for Mayen
  - Jordan now starts DST on February's last Thursday.
  - Samoa no longer observes DST.
  - Merge more location-based Zones whose timestamps agree since 1970.
  - Move some backward-compatibility links to 'backward'.
  - Rename Pacific/Enderbury to Pacific/Kanton.
  - Correct many pre-1993 transitions in Malawi, Portugal, etc.
  - zic now creates each output file or link atomically.
  - zic -L no longer omits the POSIX TZ string in its output.
  - zic fixes for truncation and leap second table expiration.
  - zic now follows POSIX for TZ strings using all-year DST.
  - Fix some localtime crashes and bugs in obscure cases.
  - zdump -v now outputs more-useful boundary cases.
  - tzfile.5 better matches a draft successor to RFC 8536.
Jmza{*Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data7ya*Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.Axa#*Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".kwaw*Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.
g}ao*Patsy Griffin <patsy@redhat.com> - 2022d-1c1@- Rebase to tzdata-2022d
  - Palestine's DST transition will be on October 29, 2022,
    not October 28, 2022.
  - Europe/Uzhgorod and Europe/Zaporozhye are moved to 'backzone'.b|ae*Patsy Griffin <patsy@redhat.com> - 2022c-1b- Rebase to tzdata-2022c - supersedes tzdata-2022b
  - Add a work-around for an awk bug in FreeBSD, macOS, etc.
  - Improve tzselect with respect to intercontinental Zones.={a*Patsy Griffin <patsy@redhat.com> - 2022b-1b- Rebase to tzdata-2022b
  - Chile transitions to DST on 2022-09-11, not 2022-09-04
  - 'make install' now defaults LOCALTIME to Factory rather than GMT
  - More zones that are the same since 1970 have been moved to backzone.
  - Include patch for awk workaround.
QQTaK+Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.R~aE+Patsy Griffin <patsy@redhat.com> - 2021b-1aO@- Rebase to tzdata-2021b
  - Innclude patch for Mayen
  - Jordan now starts DST on February's last Thursday.
  - Samoa no longer observes DST.
  - Merge more location-based Zones whose timestamps agree since 1970.
  - Move some backward-compatibility links to 'backward'.
  - Rename Pacific/Enderbury to Pacific/Kanton.
  - Correct many pre-1993 transitions in Malawi, Portugal, etc.
  - zic now creates each output file or link atomically.
  - zic -L no longer omits the POSIX TZ string in its output.
  - zic fixes for truncation and leap second table expiration.
  - zic now follows POSIX for TZ strings using all-year DST.
  - Fix some localtime crashes and bugs in obscure cases.
  - zdump -v now outputs more-useful boundary cases.
  - tzfile.5 better matches a draft successor to RFC 8536.
Jma{+Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data7a+Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.Aa#+Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".kaw+Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.
,,:a+Patsy Griffin <patsy@redhat.com> - 2022e-1cF@- Rebase to tzdata-2022e
  - Jordan and Syria cancelled the DST transition planned
    for 2022-10-28, remaining at +03 permanently.gao+Patsy Griffin <patsy@redhat.com> - 2022d-1c1@- Rebase to tzdata-2022d
  - Palestine's DST transition will be on October 29, 2022,
    not October 28, 2022.
  - Europe/Uzhgorod and Europe/Zaporozhye are moved to 'backzone'.bae+Patsy Griffin <patsy@redhat.com> - 2022c-1b- Rebase to tzdata-2022c - supersedes tzdata-2022b
  - Add a work-around for an awk bug in FreeBSD, macOS, etc.
  - Improve tzselect with respect to intercontinental Zones.=a+Patsy Griffin <patsy@redhat.com> - 2022b-1b- Rebase to tzdata-2022b
  - Chile transitions to DST on 2022-09-11, not 2022-09-04
  - 'make install' now defaults LOCALTIME to Factory rather than GMT
  - More zones that are the same since 1970 have been moved to backzone.
  - Include patch for awk workaround.
7a,Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.A
a#,Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".k	aw,Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.TaK,Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.
bae,Patsy Griffin <patsy@redhat.com> - 2022c-1b- Rebase to tzdata-2022c - supersedes tzdata-2022b
  - Add a work-around for an awk bug in FreeBSD, macOS, etc.
  - Improve tzselect with respect to intercontinental Zones.=
a,Patsy Griffin <patsy@redhat.com> - 2022b-1b- Rebase to tzdata-2022b
  - Chile transitions to DST on 2022-09-11, not 2022-09-04
  - 'make install' now defaults LOCALTIME to Factory rather than GMT
  - More zones that are the same since 1970 have been moved to backzone.
  - Include patch for awk workaround.ma{,Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data
uUeukaw-Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.kaw,Patsy Griffin <patsy@redhat.com> - 2022f-1c_- Rebase to tzdata-2022f
  - Mexico will stop observing DST except near the US border.
  - Chihuahua moved to -06 year round starting on 2022-10-30.
  - Fiji no longer observes DST.:a,Patsy Griffin <patsy@redhat.com> - 2022e-1cF@- Rebase to tzdata-2022e
  - Jordan and Syria cancelled the DST transition planned
    for 2022-10-28, remaining at +03 permanently.gao,Patsy Griffin <patsy@redhat.com> - 2022d-1c1@- Rebase to tzdata-2022d
  - Palestine's DST transition will be on October 29, 2022,
    not October 28, 2022.
  - Europe/Uzhgorod and Europe/Zaporozhye are moved to 'backzone'.
:ma{-Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data7a-Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.Aa#-Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
,,:a-Patsy Griffin <patsy@redhat.com> - 2022e-1cF@- Rebase to tzdata-2022e
  - Jordan and Syria cancelled the DST transition planned
    for 2022-10-28, remaining at +03 permanently.gao-Patsy Griffin <patsy@redhat.com> - 2022d-1c1@- Rebase to tzdata-2022d
  - Palestine's DST transition will be on October 29, 2022,
    not October 28, 2022.
  - Europe/Uzhgorod and Europe/Zaporozhye are moved to 'backzone'.bae-Patsy Griffin <patsy@redhat.com> - 2022c-1b- Rebase to tzdata-2022c - supersedes tzdata-2022b
  - Add a work-around for an awk bug in FreeBSD, macOS, etc.
  - Improve tzselect with respect to intercontinental Zones.=a-Patsy Griffin <patsy@redhat.com> - 2022b-1b- Rebase to tzdata-2022b
  - Chile transitions to DST on 2022-09-11, not 2022-09-04
  - 'make install' now defaults LOCALTIME to Factory rather than GMT
  - More zones that are the same since 1970 have been moved to backzone.
  - Include patch for awk workaround.
ma{.Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data&am-Patsy Griffin <patsy@redhat.com> - 2022g-1c@- Rebase to tzdata-2022g
  - The northern edge of the Mexican state of Chihuahua will
    change time zone to agree with nearby US locations on
    2022-11-30.
  - Added a new Zone America/Ciudad_Juarez that splits from
    America/Ojinaga.kaw-Patsy Griffin <patsy@redhat.com> - 2022f-1c_- Rebase to tzdata-2022f
  - Mexico will stop observing DST except near the US border.
  - Chihuahua moved to -06 year round starting on 2022-10-30.
  - Fiji no longer observes DST.
,,: a.Patsy Griffin <patsy@redhat.com> - 2022e-1cF@- Rebase to tzdata-2022e
  - Jordan and Syria cancelled the DST transition planned
    for 2022-10-28, remaining at +03 permanently.gao.Patsy Griffin <patsy@redhat.com> - 2022d-1c1@- Rebase to tzdata-2022d
  - Palestine's DST transition will be on October 29, 2022,
    not October 28, 2022.
  - Europe/Uzhgorod and Europe/Zaporozhye are moved to 'backzone'.bae.Patsy Griffin <patsy@redhat.com> - 2022c-1b- Rebase to tzdata-2022c - supersedes tzdata-2022b
  - Add a work-around for an awk bug in FreeBSD, macOS, etc.
  - Improve tzselect with respect to intercontinental Zones.=a.Patsy Griffin <patsy@redhat.com> - 2022b-1b- Rebase to tzdata-2022b
  - Chile transitions to DST on 2022-09-11, not 2022-09-04
  - 'make install' now defaults LOCALTIME to Factory rather than GMT
  - More zones that are the same since 1970 have been moved to backzone.
  - Include patch for awk workaround.
]]$aE.Patsy Griffin <patsy@redhat.com> - 2023b-1d- Rebase to tzdata-2023b
  - Lebanon will transition to DST on April 20/21, not March 25/26.l#ay.Patsy Griffin <patsy@redhat.com> - 2023a-1d- Rebase to tzdata-2023a
  - Egypt reintroduced DST, from April through October.
  - Morocco springs forward April 23, not April 30.
  - Palestine delayed the start of DST this year.&"am.Patsy Griffin <patsy@redhat.com> - 2022g-1c@- Rebase to tzdata-2022g
  - The northern edge of the Mexican state of Chihuahua will
    change time zone to agree with nearby US locations on
    2022-11-30.
  - Added a new Zone America/Ciudad_Juarez that splits from
    America/Ojinaga.k!aw.Patsy Griffin <patsy@redhat.com> - 2022f-1c_- Rebase to tzdata-2022f
  - Mexico will stop observing DST except near the US border.
  - Chihuahua moved to -06 year round starting on 2022-10-30.
  - Fiji no longer observes DST.
vk(aw/Patsy Griffin <patsy@redhat.com> - 2022f-1c_- Rebase to tzdata-2022f
  - Mexico will stop observing DST except near the US border.
  - Chihuahua moved to -06 year round starting on 2022-10-30.
  - Fiji no longer observes DST.:'a/Patsy Griffin <patsy@redhat.com> - 2022e-1cF@- Rebase to tzdata-2022e
  - Jordan and Syria cancelled the DST transition planned
    for 2022-10-28, remaining at +03 permanently.g&ao/Patsy Griffin <patsy@redhat.com> - 2022d-1c1@- Rebase to tzdata-2022d
  - Palestine's DST transition will be on October 29, 2022,
    not October 28, 2022.
  - Europe/Uzhgorod and Europe/Zaporozhye are moved to 'backzone'.%a+.Patsy Griffin <patsy@redhat.com> - 2023c-1d"- Rebase to tzdata-2023c
  - Lebanon reversed the change added in tzdata-2023b.
OMOp-a/Patsy Griffin <patsy@redhat.com> - 2023c-2d@- Bump release to test recent process changes. (RHEL-1328),a+/Patsy Griffin <patsy@redhat.com> - 2023c-1d"- Rebase to tzdata-2023c
  - Lebanon reversed the change added in tzdata-2023b.+aE/Patsy Griffin <patsy@redhat.com> - 2023b-1d- Rebase to tzdata-2023b
  - Lebanon will transition to DST on April 20/21, not March 25/26.l*ay/Patsy Griffin <patsy@redhat.com> - 2023a-1d- Rebase to tzdata-2023a
  - Egypt reintroduced DST, from April through October.
  - Morocco springs forward April 23, not April 30.
  - Palestine delayed the start of DST this year.&)am/Patsy Griffin <patsy@redhat.com> - 2022g-1c@- Rebase to tzdata-2022g
  - The northern edge of the Mexican state of Chihuahua will
    change time zone to agree with nearby US locations on
    2022-11-30.
  - Added a new Zone America/Ciudad_Juarez that splits from
    America/Ojinaga.

K1a70Patsy Griffin <patsy@redhat.com> - 2019b-1]- Rebase to tzdata-2019b
  - Brazil will no longer observe DST going forward.
  - The 2019 spring transition for Palestine occurred 03-29, not 03-30.0sM0Patsy Griffin Franklin <patsy@redhat.com> - 2019a-1\@- Rebase to tzdata-2019a
  - Palestine will start DST on 2019-03-30, rather than 2019-03-23 as
    previously predicted.
  - Metlakatla rejoined Alaska time on 2019-01-20, ending its observances
    of Pacific standard time.^/a]/Patsy Griffin <patsy@redhat.com> - 2024a-1e- Rebase to tzdata-2024a
  - Kazakhstan will transition from UTC+6 to UTC+5 on 2024-03-01.
  - Palestine will spring forward a week later than previously
    predicted..a7/Patsy Griffin <patsy@redhat.com> - 2023d-1e@- Rebase to tzdata-2023d
  - Include time zone changes for Ittoqqortoormiit, Greenland
    and Vostok, Antarctica.
  - Update the expiration date for the leap-seconds.list file.
    No new leap seconds were added.
(V4aM0Patsy Griffin <patsy@redhat.com> - 2020b-1_}- Rebase to tzdata-2020b
  - Yukon timezones represented by America/Whitehorse and
    America/Dawson will change time zone rules from -08/-07 to
    permanent -07 on 2020-11-01, not on 2020-03-08 as 2020a had it.
  - The most recent winter(+08)/summer(+11) transition for Casey Station,
    Antarctica was 2020-10-04 00:01.
  - Remove obsolete files pacificnew, systemv, and yearistype.sh
    from the distribution.03a0Patsy Griffin <patsy@redhat.com> - 2020a-1^- Rebase to tzdata-2020a
  - Morocco will spring forward on 2020-05-31 rather than
    previously predicted 2020-05-24.
  - Canada's Yukon region changed to year round UTC -07
    effective 2020-03-08.
  - America/Godthab was renamed to America/Nuuk.S2aG0Patsy Griffin <patsy@redhat.com> - 2019c-1]x- Rebase to tzdata-2019c
  - Fiji will observe DST from 2019-11-10 to 2020-01-12.
  - Norfolk Island will begin observing Australian-style DST on 2019-10-06.
!G!K:a71Patsy Griffin <patsy@redhat.com> - 2019b-1]- Rebase to tzdata-2019b
  - Brazil will no longer observe DST going forward.
  - The 2019 spring transition for Palestine occurred 03-29, not 03-30.R9aG0Patsy Griffin <patsy@redhat.com> - 2020d-2_"- Update release and rebuild.'8ao0Patsy Griffin <patsy@redhat.com> - 2020d-1_"- Rebase to tzdata-2020d
 - Palestine will end summer time on 2020-10-24 rather than the
   predicted 2020-10-31.k7aw0Patsy Griffin <patsy@redhat.com> - 2020c-1_- Rebase to tzdata-2020c
  - Fiji starts DST later than usual, on 2020-12-20.
  - Rearguard now provides an empty file pacificnew to support
    downstream software that expects it.;6a0Patsy Griffin <patsy@redhat.com> - 2020b-3_- Include the upstream patch to support pacificnew for java tzupdater.
- Set POSIXRULES macro to continue installing posixrules file.Y5aU0Patsy Griffin <patsy@redhat.com> - 2020b-2_P- Need to rebuild, bump the release.
(V=aM1Patsy Griffin <patsy@redhat.com> - 2020b-1_}- Rebase to tzdata-2020b
  - Yukon timezones represented by America/Whitehorse and
    America/Dawson will change time zone rules from -08/-07 to
    permanent -07 on 2020-11-01, not on 2020-03-08 as 2020a had it.
  - The most recent winter(+08)/summer(+11) transition for Casey Station,
    Antarctica was 2020-10-04 00:01.
  - Remove obsolete files pacificnew, systemv, and yearistype.sh
    from the distribution.0<a1Patsy Griffin <patsy@redhat.com> - 2020a-1^- Rebase to tzdata-2020a
  - Morocco will spring forward on 2020-05-31 rather than
    previously predicted 2020-05-24.
  - Canada's Yukon region changed to year round UTC -07
    effective 2020-03-08.
  - America/Godthab was renamed to America/Nuuk.S;aG1Patsy Griffin <patsy@redhat.com> - 2019c-1]x- Rebase to tzdata-2019c
  - Fiji will observe DST from 2019-11-10 to 2020-01-12.
  - Norfolk Island will begin observing Australian-style DST on 2019-10-06.
GRBaG1Patsy Griffin <patsy@redhat.com> - 2020d-2_"- Update release and rebuild.'Aao1Patsy Griffin <patsy@redhat.com> - 2020d-1_"- Rebase to tzdata-2020d
 - Palestine will end summer time on 2020-10-24 rather than the
   predicted 2020-10-31.k@aw1Patsy Griffin <patsy@redhat.com> - 2020c-1_- Rebase to tzdata-2020c
  - Fiji starts DST later than usual, on 2020-12-20.
  - Rearguard now provides an empty file pacificnew to support
    downstream software that expects it.;?a1Patsy Griffin <patsy@redhat.com> - 2020b-3_- Include the upstream patch to support pacificnew for java tzupdater.
- Set POSIXRULES macro to continue installing posixrules file.Y>aU1Patsy Griffin <patsy@redhat.com> - 2020b-2_P- Need to rebuild, bump the release.
0=e00Ea2Patsy Griffin <patsy@redhat.com> - 2020a-1^- Rebase to tzdata-2020a
  - Morocco will spring forward on 2020-05-31 rather than
    previously predicted 2020-05-24.
  - Canada's Yukon region changed to year round UTC -07
    effective 2020-03-08.
  - America/Godthab was renamed to America/Nuuk.SDaG2Patsy Griffin <patsy@redhat.com> - 2019c-1]x- Rebase to tzdata-2019c
  - Fiji will observe DST from 2019-11-10 to 2020-01-12.
  - Norfolk Island will begin observing Australian-style DST on 2019-10-06.>Ca1Patsy Griffin <patsy@redhat.com> - 2020f-1_@- Rebase to tzdata-2020f including changes for tzdata-2020e
  - tzdata-2020f fixes a bug in tzdata-2020e that caused an
    invalid zi file in rearguard format
  - Volgograd changes time zone from UTC+04 to UTC+03 on 2020-12-27.
  - Australia/Currie is identical to Australia/Hobart for all
    timestamps since 1970 and was therefore created by mistake,
    now moved to the "backward" file.

er+V:eD>
317a76559462ea9c4e676627bc07ad51cdeabb16ed71de9e1006e9136d921666D=
edcb7daa302df852d996cca8fd843525c686219264ba83f606c7566c191682c4D<
10bf18711ec31e124e08d12cfe9942edc9e512ce03fb9b9ab9a4a20d6d665b83D;
98918dc25b41bec2b5ac51e8782f6207f2389722d5bceec6f30c41eaeb02e336D:
d9de662df6b2d06baba19d02a89453bc264c7daa9c6fefb8214e3a084eca6e1bD9
7f22cccc77b46b6d72fc3cd7f68664be248f5c21b739751c0122fc7846687306D8
b39d7efe820971e3e85469fa528f6b8608b9fc3e46fd50fbfb19bf2bd8ca1a0bD7
948dadcdb6a107784d457eb7291106200038a0a93fe476580a9a43cd45652b47D6
05190e91801f134ec5c33d7636671a93327e2f26dc018ed5ef24541b0c91c9feD5
69bfe28a120aa3364ed2beefdae50126ff4e6b20ea1caf0f1054904964676724D4
738674ab7d423fde7ddc0d251b0d8c8447088a4f7f39ef36b39ba26c41f4a83eD3
6dce221414fb5a6fc2d69f0e321ab26390708d0c5ae297b2b4a9886bc5ba834cD2
f89e78370bd25ce90933cc003b71d1a2bcb2d53f73c8919389825731abc97807
%kIaw2Patsy Griffin <patsy@redhat.com> - 2020c-1_- Rebase to tzdata-2020c
  - Fiji starts DST later than usual, on 2020-12-20.
  - Rearguard now provides an empty file pacificnew to support
    downstream software that expects it.;Ha2Patsy Griffin <patsy@redhat.com> - 2020b-3_- Include the upstream patch to support pacificnew for java tzupdater.
- Set POSIXRULES macro to continue installing posixrules file.YGaU2Patsy Griffin <patsy@redhat.com> - 2020b-2_P- Need to rebuild, bump the release.VFaM2Patsy Griffin <patsy@redhat.com> - 2020b-1_}- Rebase to tzdata-2020b
  - Yukon timezones represented by America/Whitehorse and
    America/Dawson will change time zone rules from -08/-07 to
    permanent -07 on 2020-11-01, not on 2020-03-08 as 2020a had it.
  - The most recent winter(+08)/summer(+11) transition for Casey Station,
    Antarctica was 2020-10-04 00:01.
  - Remove obsolete files pacificnew, systemv, and yearistype.sh
    from the distribution.
PT;PYNaU3Patsy Griffin <patsy@redhat.com> - 2020b-2_P- Need to rebuild, bump the release.	Ma32Patsy Griffin <patsy@redhat.com> - 2021a-1`
a@- Rebase to tzdata-2021a
  - South Sudan will change from +03 to +02 on 2021-02-01.>La2Patsy Griffin <patsy@redhat.com> - 2020f-1_@- Rebase to tzdata-2020f including changes for tzdata-2020e
  - tzdata-2020f fixes a bug in tzdata-2020e that caused an
    invalid zi file in rearguard format
  - Volgograd changes time zone from UTC+04 to UTC+03 on 2020-12-27.
  - Australia/Currie is identical to Australia/Hobart for all
    timestamps since 1970 and was therefore created by mistake,
    now moved to the "backward" file.RKaG2Patsy Griffin <patsy@redhat.com> - 2020d-2_"- Update release and rebuild.'Jao2Patsy Griffin <patsy@redhat.com> - 2020d-1_"- Rebase to tzdata-2020d
 - Palestine will end summer time on 2020-10-24 rather than the
   predicted 2020-10-31.
N@PNRRaG3Patsy Griffin <patsy@redhat.com> - 2020d-2_"- Update release and rebuild.'Qao3Patsy Griffin <patsy@redhat.com> - 2020d-1_"- Rebase to tzdata-2020d
 - Palestine will end summer time on 2020-10-24 rather than the
   predicted 2020-10-31.kPaw3Patsy Griffin <patsy@redhat.com> - 2020c-1_- Rebase to tzdata-2020c
  - Fiji starts DST later than usual, on 2020-12-20.
  - Rearguard now provides an empty file pacificnew to support
    downstream software that expects it.;Oa3Patsy Griffin <patsy@redhat.com> - 2020b-3_- Include the upstream patch to support pacificnew for java tzupdater.
- Set POSIXRULES macro to continue installing posixrules file.
=	Ta33Patsy Griffin <patsy@redhat.com> - 2021a-1`
a@- Rebase to tzdata-2021a
  - South Sudan will change from +03 to +02 on 2021-02-01.>Sa3Patsy Griffin <patsy@redhat.com> - 2020f-1_@- Rebase to tzdata-2020f including changes for tzdata-2020e
  - tzdata-2020f fixes a bug in tzdata-2020e that caused an
    invalid zi file in rearguard format
  - Volgograd changes time zone from UTC+04 to UTC+03 on 2020-12-27.
  - Australia/Currie is identical to Australia/Hobart for all
    timestamps since 1970 and was therefore created by mistake,
    now moved to the "backward" file.
QQTVaK3Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.RUaE3Patsy Griffin <patsy@redhat.com> - 2021b-1aO@- Rebase to tzdata-2021b
  - Innclude patch for Mayen
  - Jordan now starts DST on February's last Thursday.
  - Samoa no longer observes DST.
  - Merge more location-based Zones whose timestamps agree since 1970.
  - Move some backward-compatibility links to 'backward'.
  - Rename Pacific/Enderbury to Pacific/Kanton.
  - Correct many pre-1993 transitions in Malawi, Portugal, etc.
  - zic now creates each output file or link atomically.
  - zic -L no longer omits the POSIX TZ string in its output.
  - zic fixes for truncation and leap second table expiration.
  - zic now follows POSIX for TZ strings using all-year DST.
  - Fix some localtime crashes and bugs in obscure cases.
  - zdump -v now outputs more-useful boundary cases.
  - tzfile.5 better matches a draft successor to RFC 8536.
 tRZaG4Patsy Griffin <patsy@redhat.com> - 2020d-2_"- Update release and rebuild.'Yao4Patsy Griffin <patsy@redhat.com> - 2020d-1_"- Rebase to tzdata-2020d
 - Palestine will end summer time on 2020-10-24 rather than the
   predicted 2020-10-31.kXaw4Patsy Griffin <patsy@redhat.com> - 2020c-1_- Rebase to tzdata-2020c
  - Fiji starts DST later than usual, on 2020-12-20.
  - Rearguard now provides an empty file pacificnew to support
    downstream software that expects it.kWaw3Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.
=	\a34Patsy Griffin <patsy@redhat.com> - 2021a-1`
a@- Rebase to tzdata-2021a
  - South Sudan will change from +03 to +02 on 2021-02-01.>[a4Patsy Griffin <patsy@redhat.com> - 2020f-1_@- Rebase to tzdata-2020f including changes for tzdata-2020e
  - tzdata-2020f fixes a bug in tzdata-2020e that caused an
    invalid zi file in rearguard format
  - Volgograd changes time zone from UTC+04 to UTC+03 on 2020-12-27.
  - Australia/Currie is identical to Australia/Hobart for all
    timestamps since 1970 and was therefore created by mistake,
    now moved to the "backward" file.
QQT^aK4Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.R]aE4Patsy Griffin <patsy@redhat.com> - 2021b-1aO@- Rebase to tzdata-2021b
  - Innclude patch for Mayen
  - Jordan now starts DST on February's last Thursday.
  - Samoa no longer observes DST.
  - Merge more location-based Zones whose timestamps agree since 1970.
  - Move some backward-compatibility links to 'backward'.
  - Rename Pacific/Enderbury to Pacific/Kanton.
  - Correct many pre-1993 transitions in Malawi, Portugal, etc.
  - zic now creates each output file or link atomically.
  - zic -L no longer omits the POSIX TZ string in its output.
  - zic fixes for truncation and leap second table expiration.
  - zic now follows POSIX for TZ strings using all-year DST.
  - Fix some localtime crashes and bugs in obscure cases.
  - zdump -v now outputs more-useful boundary cases.
  - tzfile.5 better matches a draft successor to RFC 8536.
bJb'bao5Patsy Griffin <patsy@redhat.com> - 2020d-1_"- Rebase to tzdata-2020d
 - Palestine will end summer time on 2020-10-24 rather than the
   predicted 2020-10-31.7aa4Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.A`a#4Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".k_aw4Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.
YY	ea35Patsy Griffin <patsy@redhat.com> - 2021a-1`
a@- Rebase to tzdata-2021a
  - South Sudan will change from +03 to +02 on 2021-02-01.>da5Patsy Griffin <patsy@redhat.com> - 2020f-1_@- Rebase to tzdata-2020f including changes for tzdata-2020e
  - tzdata-2020f fixes a bug in tzdata-2020e that caused an
    invalid zi file in rearguard format
  - Volgograd changes time zone from UTC+04 to UTC+03 on 2020-12-27.
  - Australia/Currie is identical to Australia/Hobart for all
    timestamps since 1970 and was therefore created by mistake,
    now moved to the "backward" file.RcaG5Patsy Griffin <patsy@redhat.com> - 2020d-2_"- Update release and rebuild.
QQTgaK5Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.RfaE5Patsy Griffin <patsy@redhat.com> - 2021b-1aO@- Rebase to tzdata-2021b
  - Innclude patch for Mayen
  - Jordan now starts DST on February's last Thursday.
  - Samoa no longer observes DST.
  - Merge more location-based Zones whose timestamps agree since 1970.
  - Move some backward-compatibility links to 'backward'.
  - Rename Pacific/Enderbury to Pacific/Kanton.
  - Correct many pre-1993 transitions in Malawi, Portugal, etc.
  - zic now creates each output file or link atomically.
  - zic -L no longer omits the POSIX TZ string in its output.
  - zic fixes for truncation and leap second table expiration.
  - zic now follows POSIX for TZ strings using all-year DST.
  - Fix some localtime crashes and bugs in obscure cases.
  - zdump -v now outputs more-useful boundary cases.
  - tzfile.5 better matches a draft successor to RFC 8536.
Jmka{5Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data7ja5Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.Aia#5Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".khaw5Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.
=	ma36Patsy Griffin <patsy@redhat.com> - 2021a-1`
a@- Rebase to tzdata-2021a
  - South Sudan will change from +03 to +02 on 2021-02-01.>la6Patsy Griffin <patsy@redhat.com> - 2020f-1_@- Rebase to tzdata-2020f including changes for tzdata-2020e
  - tzdata-2020f fixes a bug in tzdata-2020e that caused an
    invalid zi file in rearguard format
  - Volgograd changes time zone from UTC+04 to UTC+03 on 2020-12-27.
  - Australia/Currie is identical to Australia/Hobart for all
    timestamps since 1970 and was therefore created by mistake,
    now moved to the "backward" file.
QQToaK6Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.RnaE6Patsy Griffin <patsy@redhat.com> - 2021b-1aO@- Rebase to tzdata-2021b
  - Innclude patch for Mayen
  - Jordan now starts DST on February's last Thursday.
  - Samoa no longer observes DST.
  - Merge more location-based Zones whose timestamps agree since 1970.
  - Move some backward-compatibility links to 'backward'.
  - Rename Pacific/Enderbury to Pacific/Kanton.
  - Correct many pre-1993 transitions in Malawi, Portugal, etc.
  - zic now creates each output file or link atomically.
  - zic -L no longer omits the POSIX TZ string in its output.
  - zic fixes for truncation and leap second table expiration.
  - zic now follows POSIX for TZ strings using all-year DST.
  - Fix some localtime crashes and bugs in obscure cases.
  - zdump -v now outputs more-useful boundary cases.
  - tzfile.5 better matches a draft successor to RFC 8536.
Jmsa{6Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data7ra6Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.Aqa#6Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".kpaw6Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.
II	va37Patsy Griffin <patsy@redhat.com> - 2021a-1`
a@- Rebase to tzdata-2021a
  - South Sudan will change from +03 to +02 on 2021-02-01.buae6Patsy Griffin <patsy@redhat.com> - 2022c-1b- Rebase to tzdata-2022c - supersedes tzdata-2022b
  - Add a work-around for an awk bug in FreeBSD, macOS, etc.
  - Improve tzselect with respect to intercontinental Zones.=ta6Patsy Griffin <patsy@redhat.com> - 2022b-1b- Rebase to tzdata-2022b
  - Chile transitions to DST on 2022-09-11, not 2022-09-04
  - 'make install' now defaults LOCALTIME to Factory rather than GMT
  - More zones that are the same since 1970 have been moved to backzone.
  - Include patch for awk workaround.
QQTxaK7Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.RwaE7Patsy Griffin <patsy@redhat.com> - 2021b-1aO@- Rebase to tzdata-2021b
  - Innclude patch for Mayen
  - Jordan now starts DST on February's last Thursday.
  - Samoa no longer observes DST.
  - Merge more location-based Zones whose timestamps agree since 1970.
  - Move some backward-compatibility links to 'backward'.
  - Rename Pacific/Enderbury to Pacific/Kanton.
  - Correct many pre-1993 transitions in Malawi, Portugal, etc.
  - zic now creates each output file or link atomically.
  - zic -L no longer omits the POSIX TZ string in its output.
  - zic fixes for truncation and leap second table expiration.
  - zic now follows POSIX for TZ strings using all-year DST.
  - Fix some localtime crashes and bugs in obscure cases.
  - zdump -v now outputs more-useful boundary cases.
  - tzfile.5 better matches a draft successor to RFC 8536.
Jm|a{7Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data7{a7Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.Aza#7Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".kyaw7Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.
gao7Patsy Griffin <patsy@redhat.com> - 2022d-1c1@- Rebase to tzdata-2022d
  - Palestine's DST transition will be on October 29, 2022,
    not October 28, 2022.
  - Europe/Uzhgorod and Europe/Zaporozhye are moved to 'backzone'.b~ae7Patsy Griffin <patsy@redhat.com> - 2022c-1b- Rebase to tzdata-2022c - supersedes tzdata-2022b
  - Add a work-around for an awk bug in FreeBSD, macOS, etc.
  - Improve tzselect with respect to intercontinental Zones.=}a7Patsy Griffin <patsy@redhat.com> - 2022b-1b- Rebase to tzdata-2022b
  - Chile transitions to DST on 2022-09-11, not 2022-09-04
  - 'make install' now defaults LOCALTIME to Factory rather than GMT
  - More zones that are the same since 1970 have been moved to backzone.
  - Include patch for awk workaround.
QQTaK8Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.RaE8Patsy Griffin <patsy@redhat.com> - 2021b-1aO@- Rebase to tzdata-2021b
  - Innclude patch for Mayen
  - Jordan now starts DST on February's last Thursday.
  - Samoa no longer observes DST.
  - Merge more location-based Zones whose timestamps agree since 1970.
  - Move some backward-compatibility links to 'backward'.
  - Rename Pacific/Enderbury to Pacific/Kanton.
  - Correct many pre-1993 transitions in Malawi, Portugal, etc.
  - zic now creates each output file or link atomically.
  - zic -L no longer omits the POSIX TZ string in its output.
  - zic fixes for truncation and leap second table expiration.
  - zic now follows POSIX for TZ strings using all-year DST.
  - Fix some localtime crashes and bugs in obscure cases.
  - zdump -v now outputs more-useful boundary cases.
  - tzfile.5 better matches a draft successor to RFC 8536.
Jma{8Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data7a8Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.Aa#8Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".kaw8Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.
,,:	a8Patsy Griffin <patsy@redhat.com> - 2022e-1cF@- Rebase to tzdata-2022e
  - Jordan and Syria cancelled the DST transition planned
    for 2022-10-28, remaining at +03 permanently.gao8Patsy Griffin <patsy@redhat.com> - 2022d-1c1@- Rebase to tzdata-2022d
  - Palestine's DST transition will be on October 29, 2022,
    not October 28, 2022.
  - Europe/Uzhgorod and Europe/Zaporozhye are moved to 'backzone'.bae8Patsy Griffin <patsy@redhat.com> - 2022c-1b- Rebase to tzdata-2022c - supersedes tzdata-2022b
  - Add a work-around for an awk bug in FreeBSD, macOS, etc.
  - Improve tzselect with respect to intercontinental Zones.=a8Patsy Griffin <patsy@redhat.com> - 2022b-1b- Rebase to tzdata-2022b
  - Chile transitions to DST on 2022-09-11, not 2022-09-04
  - 'make install' now defaults LOCALTIME to Factory rather than GMT
  - More zones that are the same since 1970 have been moved to backzone.
  - Include patch for awk workaround.
7
a9Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.Aa#9Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".kaw9Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.T
aK9Patsy Griffin <patsy@redhat.com> - 2021b-2aTU@- Bump the release and rebuild.
bae9Patsy Griffin <patsy@redhat.com> - 2022c-1b- Rebase to tzdata-2022c - supersedes tzdata-2022b
  - Add a work-around for an awk bug in FreeBSD, macOS, etc.
  - Improve tzselect with respect to intercontinental Zones.=a9Patsy Griffin <patsy@redhat.com> - 2022b-1b- Rebase to tzdata-2022b
  - Chile transitions to DST on 2022-09-11, not 2022-09-04
  - 'make install' now defaults LOCALTIME to Factory rather than GMT
  - More zones that are the same since 1970 have been moved to backzone.
  - Include patch for awk workaround.ma{9Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data
uUeukaw:Patsy Griffin <patsy@redhat.com> - 2021c-1aZ- Rebase to tzdata-2021c
  - Revert most of 2021b changes to 'backward'.
  - Fix 'zic -b fat' bug in pre-1970 32-bit data.
  - Fix two Link line typos.
  - Distribute SECURITY file.kaw9Patsy Griffin <patsy@redhat.com> - 2022f-1c_- Rebase to tzdata-2022f
  - Mexico will stop observing DST except near the US border.
  - Chihuahua moved to -06 year round starting on 2022-10-30.
  - Fiji no longer observes DST.:a9Patsy Griffin <patsy@redhat.com> - 2022e-1cF@- Rebase to tzdata-2022e
  - Jordan and Syria cancelled the DST transition planned
    for 2022-10-28, remaining at +03 permanently.gao9Patsy Griffin <patsy@redhat.com> - 2022d-1c1@- Rebase to tzdata-2022d
  - Palestine's DST transition will be on October 29, 2022,
    not October 28, 2022.
  - Europe/Uzhgorod and Europe/Zaporozhye are moved to 'backzone'.
:ma{:Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data7a:Patsy Griffin <patsy@redhat.com> - 2021e-1ar- Rebase to tzdata-2021e - supersedes tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
  - Palestine will fall back 2021-10-29 at 01:00, rather
    than the predicted 2021-10-30.Aa#:Patsy Griffin <patsy@redhat.com> - 2021d-1ama- Rebase to tzdata-2021d
  - Pacific/Fiji suspended DST for the 2021/2022 season.
  - 'zic -r' now marks unspecified timestamps with "-00".
,,:a:Patsy Griffin <patsy@redhat.com> - 2022e-1cF@- Rebase to tzdata-2022e
  - Jordan and Syria cancelled the DST transition planned
    for 2022-10-28, remaining at +03 permanently.gao:Patsy Griffin <patsy@redhat.com> - 2022d-1c1@- Rebase to tzdata-2022d
  - Palestine's DST transition will be on October 29, 2022,
    not October 28, 2022.
  - Europe/Uzhgorod and Europe/Zaporozhye are moved to 'backzone'.bae:Patsy Griffin <patsy@redhat.com> - 2022c-1b- Rebase to tzdata-2022c - supersedes tzdata-2022b
  - Add a work-around for an awk bug in FreeBSD, macOS, etc.
  - Improve tzselect with respect to intercontinental Zones.=a:Patsy Griffin <patsy@redhat.com> - 2022b-1b- Rebase to tzdata-2022b
  - Chile transitions to DST on 2022-09-11, not 2022-09-04
  - 'make install' now defaults LOCALTIME to Factory rather than GMT
  - More zones that are the same since 1970 have been moved to backzone.
  - Include patch for awk workaround.
ma{;Patsy Griffin <patsy@redhat.com> - 2022a-1b1@- Rebase to tzdata-2022a
  - Palestine springs forward on 2022-03-27, not -03-26.
  - zdump -v now outputs better failure information
  - fixes for code that reads corrupted TZif data&am:Patsy Griffin <patsy@redhat.com> - 2022g-1c@- Rebase to tzdata-2022g
  - The northern edge of the Mexican state of Chihuahua will
    change time zone to agree with nearby US locations on
    2022-11-30.
  - Added a new Zone America/Ciudad_Juarez that splits from
    America/Ojinaga.kaw:Patsy Griffin <patsy@redhat.com> - 2022f-1c_- Rebase to tzdata-2022f
  - Mexico will stop observing DST except near the US border.
  - Chihuahua moved to -06 year round starting on 2022-10-30.
  - Fiji no longer observes DST.
,,:"a;Patsy Griffin <patsy@redhat.com> - 2022e-1cF@- Rebase to tzdata-2022e
  - Jordan and Syria cancelled the DST transition planned
    for 2022-10-28, remaining at +03 permanently.g!ao;Patsy Griffin <patsy@redhat.com> - 2022d-1c1@- Rebase to tzdata-2022d
  - Palestine's DST transition will be on October 29, 2022,
    not October 28, 2022.
  - Europe/Uzhgorod and Europe/Zaporozhye are moved to 'backzone'.b ae;Patsy Griffin <patsy@redhat.com> - 2022c-1b- Rebase to tzdata-2022c - supersedes tzdata-2022b
  - Add a work-around for an awk bug in FreeBSD, macOS, etc.
  - Improve tzselect with respect to intercontinental Zones.=a;Patsy Griffin <patsy@redhat.com> - 2022b-1b- Rebase to tzdata-2022b
  - Chile transitions to DST on 2022-09-11, not 2022-09-04
  - 'make install' now defaults LOCALTIME to Factory rather than GMT
  - More zones that are the same since 1970 have been moved to backzone.
  - Include patch for awk workaround.
]]&aE;Patsy Griffin <patsy@redhat.com> - 2023b-1d- Rebase to tzdata-2023b
  - Lebanon will transition to DST on April 20/21, not March 25/26.l%ay;Patsy Griffin <patsy@redhat.com> - 2023a-1d- Rebase to tzdata-2023a
  - Egypt reintroduced DST, from April through October.
  - Morocco springs forward April 23, not April 30.
  - Palestine delayed the start of DST this year.&$am;Patsy Griffin <patsy@redhat.com> - 2022g-1c@- Rebase to tzdata-2022g
  - The northern edge of the Mexican state of Chihuahua will
    change time zone to agree with nearby US locations on
    2022-11-30.
  - Added a new Zone America/Ciudad_Juarez that splits from
    America/Ojinaga.k#aw;Patsy Griffin <patsy@redhat.com> - 2022f-1c_- Rebase to tzdata-2022f
  - Mexico will stop observing DST except near the US border.
  - Chihuahua moved to -06 year round starting on 2022-10-30.
  - Fiji no longer observes DST.
vk*aw<Patsy Griffin <patsy@redhat.com> - 2022f-1c_- Rebase to tzdata-2022f
  - Mexico will stop observing DST except near the US border.
  - Chihuahua moved to -06 year round starting on 2022-10-30.
  - Fiji no longer observes DST.:)a<Patsy Griffin <patsy@redhat.com> - 2022e-1cF@- Rebase to tzdata-2022e
  - Jordan and Syria cancelled the DST transition planned
    for 2022-10-28, remaining at +03 permanently.g(ao<Patsy Griffin <patsy@redhat.com> - 2022d-1c1@- Rebase to tzdata-2022d
  - Palestine's DST transition will be on October 29, 2022,
    not October 28, 2022.
  - Europe/Uzhgorod and Europe/Zaporozhye are moved to 'backzone'.'a+;Patsy Griffin <patsy@redhat.com> - 2023c-1d"- Rebase to tzdata-2023c
  - Lebanon reversed the change added in tzdata-2023b.
OMOp/a<Patsy Griffin <patsy@redhat.com> - 2023c-2d@- Bump release to test recent process changes. (RHEL-1328).a+<Patsy Griffin <patsy@redhat.com> - 2023c-1d"- Rebase to tzdata-2023c
  - Lebanon reversed the change added in tzdata-2023b.-aE<Patsy Griffin <patsy@redhat.com> - 2023b-1d- Rebase to tzdata-2023b
  - Lebanon will transition to DST on April 20/21, not March 25/26.l,ay<Patsy Griffin <patsy@redhat.com> - 2023a-1d- Rebase to tzdata-2023a
  - Egypt reintroduced DST, from April through October.
  - Morocco springs forward April 23, not April 30.
  - Palestine delayed the start of DST this year.&+am<Patsy Griffin <patsy@redhat.com> - 2022g-1c@- Rebase to tzdata-2022g
  - The northern edge of the Mexican state of Chihuahua will
    change time zone to agree with nearby US locations on
    2022-11-30.
  - Added a new Zone America/Ciudad_Juarez that splits from
    America/Ojinaga.

U%4eg=Petr Stodulka <pstodulk@redhat.com> - 6.0-15T@- Fix CVE-2014-9636 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141
  Resolves: #1196134 #1196122 #1196126 #1196130e3ei=Petr Stodulka <pstodulk@redhat.com> - 6.0-14SR@- Fix caseinsensitive bug
  Resolves: #1104018K2[?=Daniel Mach <dmach@redhat.com> - 6.0-13RU- Mass rebuild 2014-01-24^1a]<Patsy Griffin <patsy@redhat.com> - 2024a-1e- Rebase to tzdata-2024a
  - Kazakhstan will transition from UTC+6 to UTC+5 on 2024-03-01.
  - Palestine will spring forward a week later than previously
    predicted.0a7<Patsy Griffin <patsy@redhat.com> - 2023d-1e@- Rebase to tzdata-2023d
  - Include time zone changes for Ittoqqortoormiit, Greenland
    and Vostok, Antarctica.
  - Update the expiration date for the leap-seconds.list file.
    No new leap seconds were added.
9:9g9gk=Jakub Martisko <jamartis@redhat.com> - 6.0-20\s- Fix CVE-2018-18384
  Resolves: CVE-2018-18384q8g}=Jakub Martisko <jamartis@redhat.com> - 6.0-19ZT- rename patch unzip-6.0-nostrip.patch to unzip-6.0-configure.patch
- make linking flags configurable from the specc file
- set linking flags to use relro hardening
  Related: #15311167gQ=Jakub Martisko <jamartis@redhat.com> - 6.0-18ZT- Add -DNOLCHMOD build option, since lchmod is not availabel on Linux
  Anyway
  Related: #1531116	6g-=Jakub Martisko <jamartis@redhat.com> - 6.0-17ZN@- Fix error with wrong CRC checks by adding -DNOMEMCPY flag
  Resolves: #152563635e=Petr Stodulka <pstodulk@redhat.com> - 6.0-16VU- Added patch for build option "-Werror=format-security"
- Added support of non-unicode non-latin charset
- Fix print of non-ascii filenames
- Fix troubles with symlinks for archives with many files
  Resolves: rhbz#1276746, rhbz#1286165, rhbz#1276744
l4	>g->Jakub Martisko <jamartis@redhat.com> - 6.0-17ZN@- Fix error with wrong CRC checks by adding -DNOMEMCPY flag
  Resolves: #15256363=e>Petr Stodulka <pstodulk@redhat.com> - 6.0-16VU- Added patch for build option "-Werror=format-security"
- Added support of non-unicode non-latin charset
- Fix print of non-ascii filenames
- Fix troubles with symlinks for archives with many files
  Resolves: rhbz#1276746, rhbz#1286165, rhbz#1276744%<eg>Petr Stodulka <pstodulk@redhat.com> - 6.0-15T@- Fix CVE-2014-9636 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141
  Resolves: #1196134 #1196122 #1196126 #1196130{;g=Jakub Martisko <jamartis@redhat.com> - 6.0-22`\{@- Fix a false positive in a zip bomb detection
- Resolves: 1920632g:gk=Jakub Martisko <jamartis@redhat.com> - 6.0-21]- Fix CVE-2019-13232
- Resolves: CVE-2019-13232
5`j5[DgQ>Jakub Martisko <jamartis@redhat.com> - 6.0-23a- Disable the zipbomb detection patches
- There were too many false positives for now, will reenable this later with an option to opt-out
- Resolves: rhbz#2020318{Cg>Jakub Martisko <jamartis@redhat.com> - 6.0-22`\{@- Fix a false positive in a zip bomb detection
- Resolves: 1920632gBgk>Jakub Martisko <jamartis@redhat.com> - 6.0-21]- Fix CVE-2019-13232
- Resolves: CVE-2019-13232gAgk>Jakub Martisko <jamartis@redhat.com> - 6.0-20\s- Fix CVE-2018-18384
  Resolves: CVE-2018-18384q@g}>Jakub Martisko <jamartis@redhat.com> - 6.0-19ZT- rename patch unzip-6.0-nostrip.patch to unzip-6.0-configure.patch
- make linking flags configurable from the specc file
- set linking flags to use relro hardening
  Related: #1531116?gQ>Jakub Martisko <jamartis@redhat.com> - 6.0-18ZT- Add -DNOLCHMOD build option, since lchmod is not availabel on Linux
  Anyway
  Related: #1531116
Bp(IW{?Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=HW%?Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedkGW?Karel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_FWk?Karel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)9Eg
>Jakub Martisko <jamartis@redhat.com> - 6.0-24aL- Reenable the zipbomb detection patches
- Add environment variable that disables the zipbomb detection
- Resolves: rhbz#2020318

er+V:eDK
31f5687f8cf2efb346cfb7c6db63dd20099ae55c53df37eace7337114a7ab96bDJ
05362c7e6d4437e600de7d1470e9fe6c2f6f27c1292646ff6a86a8a72ae75c9fDI
6992344b5a8b6f8518b34b8b6f7488ab9d8930c89df8401bbe760046a494d720DH
4bcba3242efbe299d1cca855971a52ac841ce3d6656543283cb9ff8dfd08b70dDG
f6645c7cbc24d07e153f2c8892cf815d6c7edf416985b8afe81d4a7af9562adcDF
0fa907c7a6165ea080e9b32810b7f06b8576ef3ab9fe6df734c98ca91fd4ff1cDE
e79f036d785295613332bcd3cf90576996a5ccf4caf4279ccd2519d51ec04845DD
b629a630cf9bcbefa47414156640cb216d8f887d9dae33819d9e0461c4c0119eDC
1900e396d24a404c2bdc5dd7198c7a0a6a08171c7ea6e2c4eff77792f3f335edDB
706b5941777a2e74d84643c364c9bf33de8003c8ccbac339a0fdb62fbcc0e38dDA
3619f7bf9f3566d19d7252cebb96f571e998412d785249dc7108dc067b00c751D@
ba087a07d4834f084f6c1c67dd0871b4faec0852cdda6a66f64c6203f78ef56cD?
f00c1a71ef838f6972f7559129c30772cf908879baef300c1d4d8fe9b449c0a9
EELWI?Karel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.AKW-?Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\JWc?Karel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;aNWm?Karel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZMW_?Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
vT#v(SW{@Karel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=RW%@Karel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedkQW@Karel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_PWk@Karel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)DOg#?Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
EEVWI@Karel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.AUW-@Karel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\TWc@Karel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;aXWm@Karel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZWW_@Karel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
vT#v(]W{AKarel Zak <kzak@redhat.com> 2.23.2-60\R@- fix #1664752 - Bull (Atos) server lands up in invalid stty settings on the serial console after boot preventing login=\W%AKarel Zak <kzak@redhat.com> 2.23.2-59[z@- fix #1618711 - exec option in mount unable to override the implicit noexec in user option
- fix #1616264 - Login to emergency shell failedk[WAKarel Zak <kzak@redhat.com> 2.23.2-58[<- fix #1594681 - [RHEL7.2] blkid does not output swap area_ZWkAKarel Zak <kzak@redhat.com> 2.23.2-57["X- add another ppc aliases to setarch (#1562125)DYg#@Karel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
EE`WIAKarel Zak <kzak@redhat.com> 2.23.2-63]]2@- fix #1740572 - libmount ignores empty domain field due to which plain domain option is sent.A_W-AKarel Zak <kzak@redhat.com> 2.23.2-62]Ik- fix #1734545 - blkid_get_dev() leak file descriptor to underlying block device
- fix #1712768 - lsmem segfaults on ppc64 wih -o
- fix #1690102 - setarch(8) does not check error return values properly.
- fix #1734261 - lscpu not showing Physical socket, chips information\^WcAKarel Zak <kzak@redhat.com> 2.23.2-61\@- #1203378 - Cannot use swapon with fallocated XFS swapfile
- #1632944 - blkid/lsblk does not recognize exfat filesystem without a label
- #1633657 - mount -a always tries to mount CIFS share subdir despite being already mounted
- #1639465 - Bad formatting in agetty.8 man page
- #1667942 - libsmartcols: scols_print_table_to_string() doesn't work
- #1678451 - Unable to mount to a directory that matches a dm device under /dev
;!;abWmAKarel Zak <kzak@redhat.com> 2.23.2-65^@- fix #1826719 - mount -a tries to mount already mounted cifs shares when we cannot query up to root dir
- fix #1745657 - mismatch between spec file and uuidd runtime directoryZaW_AKarel Zak <kzak@redhat.com> 2.23.2-64^k@- fix #1788896 - Internal testsuite: libmount tests failed
- fix #1802240 - systemd-udev segmentation fault in crc32() at lib/crc32.c (libblkid)
- fix #1816183 - "mount -a" should ignore already mounted bind mounts.
- fix #1747710 - please backport the "uid=forget" and "gid=forget" UDF mount options to libmount
- fix #1784579 - RHEL-7: col struct char_str c_column field should be of unsigned type and/or larger than 16 bit
M.MigmiBZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-5['- 1490927 - vim dumps core when system rebootspfmwBZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-4Y- fixed upstream tests, which failed after last build^emQBZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-3Yn@- 1267826 - Include c++11 syntax highlighting in vim
- 1319760 - [RFE] Vim should support blowfish2, plus ensure that RHEL6 encrypted files can be opened in RHEL7!dmWBZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-2X- 1383902 - CPU spikes to 100% and timeouts observed in strace when opening yaml extensions using vimDcg#AKarel Zak <kzak@redhat.com> 2.23.2-65.el7_9.1_м@- fix #1905956 - RHEL-7: chrt regression: unwanted 'nice' value reset on sched_setattr() [rhel-7.9.z]
- fix #1905954 - RHEL-7: chrt regression: unexpected default scheduler [rhel-7.9.z]
- fix #1883013 - RHEL-7: chrt command does not support the -R option [rhel-7.9.z]
,tmmBZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-8_ts@- 1833186 - gvim consums 100% cpu under certain conditionslm}BZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-7^&- 1743070 - manpage of vim is garbled in Japanese locale
km/BZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-6]A- increment release enough to get CVE fix 1719964 for clients migrated from RHEL6
jm)BZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-3]@- 1719964 - CVE-2019-12735 arbitrary command execution in getchar.c [rhel-7.7]zim	BZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-2\E@- adding several additional changes for #1377316 from upstreamOhm3BZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-1\?- 1563419 - Vim in RHEL 7 is older than VIM in RHEL 6 (Rebase)
- 1377316 - [RFE] make _remote_ vim doing the right decisions about 'set background'
DZwDzsm	CZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-2\E@- adding several additional changes for #1377316 from upstreamOrm3CZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-1\?- 1563419 - Vim in RHEL 7 is older than VIM in RHEL 6 (Rebase)
- 1377316 - [RFE] make _remote_ vim doing the right decisions about 'set background'iqmiCZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-5['- 1490927 - vim dumps core when system rebootsppmwCZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-4Y- fixed upstream tests, which failed after last build^omQCZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-3Yn@- 1267826 - Include c++11 syntax highlighting in vim
- 1319760 - [RFE] Vim should support blowfish2, plus ensure that RHEL6 encrypted files can be opened in RHEL7!nmWCZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-2X- 1383902 - CPU spikes to 100% and timeouts observed in strace when opening yaml extensions using vim
gqhJg^ymQDZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-3Yn@- 1267826 - Include c++11 syntax highlighting in vim
- 1319760 - [RFE] Vim should support blowfish2, plus ensure that RHEL6 encrypted files can be opened in RHEL7!xmWDZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-2X- 1383902 - CPU spikes to 100% and timeouts observed in strace when opening yaml extensions using vimtwmCZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-8_ts@- 1833186 - gvim consums 100% cpu under certain conditionsvm}CZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-7^&- 1743070 - manpage of vim is garbled in Japanese locale
um/CZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-6]A- increment release enough to get CVE fix 1719964 for clients migrated from RHEL6
tm)CZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-3]@- 1719964 - CVE-2019-12735 arbitrary command execution in getchar.c [rhel-7.7]
5K>5sm}DZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-7^&- 1743070 - manpage of vim is garbled in Japanese locale
m/DZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-6]A- increment release enough to get CVE fix 1719964 for clients migrated from RHEL6
~m)DZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-3]@- 1719964 - CVE-2019-12735 arbitrary command execution in getchar.c [rhel-7.7]z}m	DZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-2\E@- adding several additional changes for #1377316 from upstreamO|m3DZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-1\?- 1563419 - Vim in RHEL 7 is older than VIM in RHEL 6 (Rebase)
- 1377316 - [RFE] make _remote_ vim doing the right decisions about 'set background'i{miDZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-5['- 1490927 - vim dumps core when system rebootspzmwDZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-4Y- fixed upstream tests, which failed after last build
JJOm3EZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-1\?- 1563419 - Vim in RHEL 7 is older than VIM in RHEL 6 (Rebase)
- 1377316 - [RFE] make _remote_ vim doing the right decisions about 'set background'imiEZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-5['- 1490927 - vim dumps core when system rebootspmwEZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-4Y- fixed upstream tests, which failed after last build^mQEZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-3Yn@- 1267826 - Include c++11 syntax highlighting in vim
- 1319760 - [RFE] Vim should support blowfish2, plus ensure that RHEL6 encrypted files can be opened in RHEL7!mWEZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-2X- 1383902 - CPU spikes to 100% and timeouts observed in strace when opening yaml extensions using vimtmDZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-8_ts@- 1833186 - gvim consums 100% cpu under certain condition
ar!mWFZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-2X- 1383902 - CPU spikes to 100% and timeouts observed in strace when opening yaml extensions using vimtmEZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-8_ts@- 1833186 - gvim consums 100% cpu under certain conditions
m}EZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-7^&- 1743070 - manpage of vim is garbled in Japanese locale
	m/EZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-6]A- increment release enough to get CVE fix 1719964 for clients migrated from RHEL6
m)EZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-3]@- 1719964 - CVE-2019-12735 arbitrary command execution in getchar.c [rhel-7.7]zm	EZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-2\E@- adding several additional changes for #1377316 from upstream
[<h[
m)FZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-3]@- 1719964 - CVE-2019-12735 arbitrary command execution in getchar.c [rhel-7.7]zm	FZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-2\E@- adding several additional changes for #1377316 from upstreamOm3FZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-1\?- 1563419 - Vim in RHEL 7 is older than VIM in RHEL 6 (Rebase)
- 1377316 - [RFE] make _remote_ vim doing the right decisions about 'set background'imiFZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-5['- 1490927 - vim dumps core when system rebootspmwFZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-4Y- fixed upstream tests, which failed after last build^
mQFZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.160-3Yn@- 1267826 - Include c++11 syntax highlighting in vim
- 1319760 - [RFE] Vim should support blowfish2, plus ensure that RHEL6 encrypted files can be opened in RHEL7
*n0K*kOGRichard W.M. Jones <rjones@redhat.com> - 1.13-7Wg- Add support for detecting POWER KVM and LPAR
  resolves: rhbz#1147876
- Detect RHEV/oVirt
  resolves: rhbz#1249438
- Detect ACPI boot aarch64 guest
  resolves: rhbz#1275349
- Fix typo in manual page
  resolves: rhbz#1099289k9GRichard W.M. Jones <rjones@redhat.com> - 1.13-6U6;- Fix detection of aarch64
  resolves: rhbz#1201845
  Add all commits to version 1.15.K[?GDaniel Mach <dmach@redhat.com> - 1.13-5RU- Mass rebuild 2014-01-24K[?GDaniel Mach <dmach@redhat.com> - 1.13-4Rk- Mass rebuild 2013-12-27tmFZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-8_ts@- 1833186 - gvim consums 100% cpu under certain conditionsm}FZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-7^&- 1743070 - manpage of vim is garbled in Japanese locale
m/FZdenek Dohnal <zdohnal@redhat.com> - 2:7.4.629-6]A- increment release enough to get CVE fix 1719964 for clients migrated from RHEL6
]joiGRichard W.M. Jones <rjones@redhat.com> - 1.18-4.1`- Add Nutanix AHV support
  resolves: rhbz#xxxkGRichard W.M. Jones <rjones@redhat.com> - 1.18-4Y- Add patch to recognize ppc64le virtualization.
  resolves: rhbz#11478766kGRichard W.M. Jones <rjones@redhat.com> - 1.18-2Y- Rebase to Fedora Rawhide / upstream version.
- Include upstream patches since 1.18 was released.
  resolves: rhbz#1476878mmqGRichard W.M. Jones <rjones@redhat.com> - 1.13-10XP@- Require 'which' program
  resolves: rhbz#1433005skGRichard W.M. Jones <rjones@redhat.com> - 1.13-9X@- Detect RHEV/oVirt (second fix)
  resolves: rhbz#1249438skGRichard W.M. Jones <rjones@redhat.com> - 1.13-8W@- Depend on dmidecode on aarch64
  resolves: rhbz#1360699
tOto$e}HWilliam Poteat <wpoteat@redhat.com> 0.28.5-1^@- 1748677: Improved timeout for esx (wpoteat@redhat.com)!#e_HWilliam Poteat <wpoteat@redhat.com> 0.28.4-1^@- 1806572: virt-who using V3 APIs for communication with RHEVM which is
  deprecated (wpoteat@redhat.com)="eHWilliam Poteat <wpoteat@redhat.com> 0.28.3-1^s^- 1775535: config option to override api version (piotr.kliczewski@gmail.com)
- Update releasers for new version (wpoteat@redhat.com)!e'HWilliam Poteat <wpoteat@redhat.com> 0.28.2-1^U@- 1760161: Command line arguments need to be in man page (wpoteat@redhat.com)" eaHWilliam Poteat <wpoteat@redhat.com> 0.28.1-1^E:@- 1780467: Validate rhevm password when unicode is not allowed
  (wpoteat@redhat.com)
- 1751441: Add command line path parameter (piotr.kliczewski@gmail.com)
- 1762780: fix bug, when reporter_id is empty; ENT-1706 (jhnidek@redhat.com)
`4C`7*oIMartin Sehnoutka <msehnout@redhat.com> - 3.0.2-20WK- Resolves: #1147551 - Missing isolate_* options, incorrect default values of
  max_clients, max_per_ip in man vsftpd.conf)g)HWilliam Poteat <wpoteat@redhat.com> 0.28.10-1_/@- 1872477: virt-who fails to parse output from hypervisor (wpoteat@redhat.com)(eIHWilliam Poteat <wpoteat@redhat.com> 0.28.9-1^- 1809098: Convert UUID to big-endian for certain esx hardware versions
  (wpoteat@redhat.com)z'eHWilliam Poteat <wpoteat@redhat.com> 0.28.8-1^- 1844364: better behavior of --config option (jhnidek@redhat.com)o&e}HWilliam Poteat <wpoteat@redhat.com> 0.28.7-1^V@- 1835132: support milicpus (piotr.kliczewski@gmail.com)G%e+HWilliam Poteat <wpoteat@redhat.com> 0.28.6-1^m@- 1806572: RHEVM should only use version 4 (wpoteat@redhat.com)
- Update to tests to match changes in Subscription Manager (jhnidek@redhat.com)
y}.o
IOndřej Lysoněk <olysonek@redhat.com> - 3.0.2-24Z@- Fix reverse hostname lookup with IPv6
- Resolves: rhbz#15767057-oIOndřej Lysoněk <olysonek@redhat.com> - 3.0.2-23Z- Redefine VSFTP_COMMAND_FD to 1
- Resolves: rhbz#1443055
- Document the relationship of text_userdb_names and chroot_local_user
- Resolves: rhbz#1508021
- Document allow_writeable_chroot in the man page
- Resolves: rhbz#1508022
- Improve documentation of ascii_* options
- Resolves: rhbz#1517227
- Add new filename generation algorithm for STOU command
- Resolves: rhbz#1479237,gWIZdenek Dohnal <zdohnal@redhat.com> - 3.0.2-22XӸ- Resolves: #1432054 - secure ftp stopped working with default TLS settings in the new vsftpd package+oIMartin Sehnoutka <msehnout@redhat.com> - 3.0.2-21WP- Resolves: #1318947 vsftpd should permit specified TLS versions only
uT;uA3mIArtem Egorenkov <aegorenk@redhat.com> - 3.0.2-29`n@- Enable support for wide-character strings in logs
- Replace unprintables with HEX code, not question marks
- Resolves: rhbz#1922809u2oIOndřej Lysoněk <olysonek@redhat.com> - 3.0.2-28^`- Fix timestamp handling in MDTM
- Resolves: rhbz#15832471oIIOndřej Lysoněk <olysonek@redhat.com> - 3.0.2-27]HA- Partially fix problem with bad utmp entries when pututxline() fails
- Resolves: rhbz#16888480oIOndřej Lysoněk <olysonek@redhat.com> - 3.0.2-26]H@- Fix segfault when listen() returns an error
- Resolves: rhbz#1666380/oQIOndřej Lysoněk <olysonek@redhat.com> - 3.0.2-25[+@- Add config option log_die allowing to pass error messages to syslog
- Add config option bind_retries allowing to change the max number
- of attempts to find a listening port for the PASV/EPSV command
- Resolves: rhbz#1318198
^D^77oJOndřej Lysoněk <olysonek@redhat.com> - 3.0.2-23Z- Redefine VSFTP_COMMAND_FD to 1
- Resolves: rhbz#1443055
- Document the relationship of text_userdb_names and chroot_local_user
- Resolves: rhbz#1508021
- Document allow_writeable_chroot in the man page
- Resolves: rhbz#1508022
- Improve documentation of ascii_* options
- Resolves: rhbz#1517227
- Add new filename generation algorithm for STOU command
- Resolves: rhbz#14792376gWJZdenek Dohnal <zdohnal@redhat.com> - 3.0.2-22XӸ- Resolves: #1432054 - secure ftp stopped working with default TLS settings in the new vsftpd package5oJMartin Sehnoutka <msehnout@redhat.com> - 3.0.2-21WP- Resolves: #1318947 vsftpd should permit specified TLS versions only74oJMartin Sehnoutka <msehnout@redhat.com> - 3.0.2-20WK- Resolves: #1147551 - Missing isolate_* options, incorrect default values of
  max_clients, max_per_ip in man vsftpd.confbRIRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{I(|I)I*I+I,	I-
I.I/I0I1I2I3"I4&I5*I6/I74I89I9>I:DI;II=LI>NI?SI@VIAXIB]IC`IDbIEgIFmIGsIHyIIIJIKILIMINIO$IP*IQ.IR3IS7IU<IV@IWGIYLIZSI[YI\^I]eI^jI_qI`wIa|IbIcIdIeIfIg!Ih)Ii1Ij:IkBIlIInPIoXIp^IqfIrmIstIt|IuIvIwIxIy"Iz)I{0I|8I}@I~GINIVI^IeIlItI|II
III!I)I2I8
[3u<oJOndřej Lysoněk <olysonek@redhat.com> - 3.0.2-28^`- Fix timestamp handling in MDTM
- Resolves: rhbz#1583247;oIJOndřej Lysoněk <olysonek@redhat.com> - 3.0.2-27]HA- Partially fix problem with bad utmp entries when pututxline() fails
- Resolves: rhbz#1688848:oJOndřej Lysoněk <olysonek@redhat.com> - 3.0.2-26]H@- Fix segfault when listen() returns an error
- Resolves: rhbz#16663809oQJOndřej Lysoněk <olysonek@redhat.com> - 3.0.2-25[+@- Add config option log_die allowing to pass error messages to syslog
- Add config option bind_retries allowing to change the max number
- of attempts to find a listening port for the PASV/EPSV command
- Resolves: rhbz#1318198}8o
JOndřej Lysoněk <olysonek@redhat.com> - 3.0.2-24Z@- Fix reverse hostname lookup with IPv6
- Resolves: rhbz#1576705
\:\7@eKTomas Popela <tpopela@redhat.com> - 2.20.4-2[l,- webkitgtk4: Crash on Google login page when a11y is active
- Resolves: rhbz#1503624
- Revert patch causing rendering glitches+?esKTomas Popela <tpopela@redhat.com> - 2.20.4-1[h8@- Update to 2.20.4
- Resolves: rhbz#1576544
- WebKitWebProcess crashes when a11y is active
- Resolves: rhbz#1591638n>e{KTomas Popela <tpopela@redhat.com> - 2.20.3-5[3|@- Add GStreamer coverity fixes
- Resolves: rhbz#1576544A=mJArtem Egorenkov <aegorenk@redhat.com> - 3.0.2-29`n@- Enable support for wide-character strings in logs
- Replace unprintables with HEX code, not question marks
- Resolves: rhbz#1922809
)lhGu_KMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-3aS- Fix CVE-2021-30858
- Resolves: #2006421wFu}KMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-2^@- Resolves: rhbz#1817144 Rebuild to support ppc and s390hEu_KMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-1^m@- Resolves: rhbz#1817144 Rebase to 2.28.2YD_WKEike Rathke <erack@redhat.com> - 2.22.7-2\- Related: rhbz#1669482 covscan fixes\C_]KEike Rathke <erack@redhat.com> - 2.22.7-1\- Related: rhbz#1669482 Update to 2.22.7]B__KEike Rathke <erack@redhat.com> - 2.22.6-1\b@- Resolves: rhbz#1669482 Rebase to 2.22.6qAeKTomas Popela <tpopela@redhat.com> - 2.20.5-1[r@- Update to 2.20.5 - technically it was not necessary as the only difference
  between 2.20.4 and .5 was the revert of one change, that we already reverted
  while building 2.20.4. But it's better to stay with upstream.
- Update the labels patch with the version that was pushed upstream.
- Resolves: rhbz#1576544

er+V:eDX
cb8ae6ec45ef9ce08ede28575bc163dd1337f4776778e13ebf08457f0470623bDW
3bea27ba9e28b7b2fc421da397e966e4cec0ae9373ddb86b7cee9186fcc5ec16DV
cef919b47e2ac46501512262000f8aa6f2804d306139f51f0a7eb8a4f8443bdaDU
01359f42e5c172df7cebf52260aa08b51811b3cc29728a03a93dc546ffcfd21eDT
274694000767f81dd075fa9b55a09e5e143824fe75c13fb69a510889a95f7f25DS
4fbc6610c68813e5bd6ae12f052f547dce477ce710dcf0757d49212f8415fe33DR
d06eef6e09b25151ae88be0acd91ea6c0eebd9c3a619ef2de948701f44307288DQ
d8e9e473880f01fe4af7cbd16870f030f0c4d3b35cd00bcd3813a8c472c2eea3DP
ec1f41bbc53f78290aa486eef749003264f457b41442f93d5ea5e629c64bbe1fDO
3daba1d2ee59a3abcf9723759cf79cb532243682a4ffdbfc3dd7f5b29a3c046cDN
ea320050b773b3095645df0c61516e8030958f578d9daf62822c281104949a7cDM
fc8c80035602313a7b83027140e8b3e5895c85d6fbce04b2d73a53976a616e73DL
ca3865c7f4066896a26c6e00f973c8f6edbfb58dee7538f4795b8c102ec8dbf1
K"K]L__LEike Rathke <erack@redhat.com> - 2.22.6-1\b@- Resolves: rhbz#1669482 Rebase to 2.22.6qKeLTomas Popela <tpopela@redhat.com> - 2.20.5-1[r@- Update to 2.20.5 - technically it was not necessary as the only difference
  between 2.20.4 and .5 was the revert of one change, that we already reverted
  while building 2.20.4. But it's better to stay with upstream.
- Update the labels patch with the version that was pushed upstream.
- Resolves: rhbz#15765447JeLTomas Popela <tpopela@redhat.com> - 2.20.4-2[l,- webkitgtk4: Crash on Google login page when a11y is active
- Resolves: rhbz#1503624
- Revert patch causing rendering glitches+IesLTomas Popela <tpopela@redhat.com> - 2.20.4-1[h8@- Update to 2.20.4
- Resolves: rhbz#1576544
- WebKitWebProcess crashes when a11y is active
- Resolves: rhbz#1591638nHe{LTomas Popela <tpopela@redhat.com> - 2.20.3-5[3|@- Add GStreamer coverity fixes
- Resolves: rhbz#1576544
C\~+SesMTomas Popela <tpopela@redhat.com> - 2.20.4-1[h8@- Update to 2.20.4
- Resolves: rhbz#1576544
- WebKitWebProcess crashes when a11y is active
- Resolves: rhbz#1591638nRe{MTomas Popela <tpopela@redhat.com> - 2.20.3-5[3|@- Add GStreamer coverity fixes
- Resolves: rhbz#1576544hQu_LMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-3aS- Fix CVE-2021-30858
- Resolves: #2006421wPu}LMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-2^@- Resolves: rhbz#1817144 Rebuild to support ppc and s390hOu_LMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-1^m@- Resolves: rhbz#1817144 Rebase to 2.28.2YN_WLEike Rathke <erack@redhat.com> - 2.22.7-2\- Related: rhbz#1669482 covscan fixes\M_]LEike Rathke <erack@redhat.com> - 2.22.7-1\- Related: rhbz#1669482 Update to 2.22.7
DDm
DhYu_MMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-1^m@- Resolves: rhbz#1817144 Rebase to 2.28.2YX_WMEike Rathke <erack@redhat.com> - 2.22.7-2\- Related: rhbz#1669482 covscan fixes\W_]MEike Rathke <erack@redhat.com> - 2.22.7-1\- Related: rhbz#1669482 Update to 2.22.7]V__MEike Rathke <erack@redhat.com> - 2.22.6-1\b@- Resolves: rhbz#1669482 Rebase to 2.22.6qUeMTomas Popela <tpopela@redhat.com> - 2.20.5-1[r@- Update to 2.20.5 - technically it was not necessary as the only difference
  between 2.20.4 and .5 was the revert of one change, that we already reverted
  while building 2.20.4. But it's better to stay with upstream.
- Update the labels patch with the version that was pushed upstream.
- Resolves: rhbz#15765447TeMTomas Popela <tpopela@redhat.com> - 2.20.4-2[l,- webkitgtk4: Crash on Google login page when a11y is active
- Resolves: rhbz#1503624
- Revert patch causing rendering glitches
;;7^eNTomas Popela <tpopela@redhat.com> - 2.20.4-2[l,- webkitgtk4: Crash on Google login page when a11y is active
- Resolves: rhbz#1503624
- Revert patch causing rendering glitches+]esNTomas Popela <tpopela@redhat.com> - 2.20.4-1[h8@- Update to 2.20.4
- Resolves: rhbz#1576544
- WebKitWebProcess crashes when a11y is active
- Resolves: rhbz#1591638n\e{NTomas Popela <tpopela@redhat.com> - 2.20.3-5[3|@- Add GStreamer coverity fixes
- Resolves: rhbz#1576544h[u_MMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-3aS- Fix CVE-2021-30858
- Resolves: #2006421wZu}MMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-2^@- Resolves: rhbz#1817144 Rebuild to support ppc and s390
)lheu_NMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-3aS- Fix CVE-2021-30858
- Resolves: #2006421wdu}NMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-2^@- Resolves: rhbz#1817144 Rebuild to support ppc and s390hcu_NMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-1^m@- Resolves: rhbz#1817144 Rebase to 2.28.2Yb_WNEike Rathke <erack@redhat.com> - 2.22.7-2\- Related: rhbz#1669482 covscan fixes\a_]NEike Rathke <erack@redhat.com> - 2.22.7-1\- Related: rhbz#1669482 Update to 2.22.7]`__NEike Rathke <erack@redhat.com> - 2.22.6-1\b@- Resolves: rhbz#1669482 Rebase to 2.22.6q_eNTomas Popela <tpopela@redhat.com> - 2.20.5-1[r@- Update to 2.20.5 - technically it was not necessary as the only difference
  between 2.20.4 and .5 was the revert of one change, that we already reverted
  while building 2.20.4. But it's better to stay with upstream.
- Update the labels patch with the version that was pushed upstream.
- Resolves: rhbz#1576544
K"K]j__OEike Rathke <erack@redhat.com> - 2.22.6-1\b@- Resolves: rhbz#1669482 Rebase to 2.22.6qieOTomas Popela <tpopela@redhat.com> - 2.20.5-1[r@- Update to 2.20.5 - technically it was not necessary as the only difference
  between 2.20.4 and .5 was the revert of one change, that we already reverted
  while building 2.20.4. But it's better to stay with upstream.
- Update the labels patch with the version that was pushed upstream.
- Resolves: rhbz#15765447heOTomas Popela <tpopela@redhat.com> - 2.20.4-2[l,- webkitgtk4: Crash on Google login page when a11y is active
- Resolves: rhbz#1503624
- Revert patch causing rendering glitches+gesOTomas Popela <tpopela@redhat.com> - 2.20.4-1[h8@- Update to 2.20.4
- Resolves: rhbz#1576544
- WebKitWebProcess crashes when a11y is active
- Resolves: rhbz#1591638nfe{OTomas Popela <tpopela@redhat.com> - 2.20.3-5[3|@- Add GStreamer coverity fixes
- Resolves: rhbz#1576544
C\~+qesPTomas Popela <tpopela@redhat.com> - 2.20.4-1[h8@- Update to 2.20.4
- Resolves: rhbz#1576544
- WebKitWebProcess crashes when a11y is active
- Resolves: rhbz#1591638npe{PTomas Popela <tpopela@redhat.com> - 2.20.3-5[3|@- Add GStreamer coverity fixes
- Resolves: rhbz#1576544hou_OMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-3aS- Fix CVE-2021-30858
- Resolves: #2006421wnu}OMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-2^@- Resolves: rhbz#1817144 Rebuild to support ppc and s390hmu_OMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-1^m@- Resolves: rhbz#1817144 Rebase to 2.28.2Yl_WOEike Rathke <erack@redhat.com> - 2.22.7-2\- Related: rhbz#1669482 covscan fixes\k_]OEike Rathke <erack@redhat.com> - 2.22.7-1\- Related: rhbz#1669482 Update to 2.22.7
DDm
Dhwu_PMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-1^m@- Resolves: rhbz#1817144 Rebase to 2.28.2Yv_WPEike Rathke <erack@redhat.com> - 2.22.7-2\- Related: rhbz#1669482 covscan fixes\u_]PEike Rathke <erack@redhat.com> - 2.22.7-1\- Related: rhbz#1669482 Update to 2.22.7]t__PEike Rathke <erack@redhat.com> - 2.22.6-1\b@- Resolves: rhbz#1669482 Rebase to 2.22.6qsePTomas Popela <tpopela@redhat.com> - 2.20.5-1[r@- Update to 2.20.5 - technically it was not necessary as the only difference
  between 2.20.4 and .5 was the revert of one change, that we already reverted
  while building 2.20.4. But it's better to stay with upstream.
- Update the labels patch with the version that was pushed upstream.
- Resolves: rhbz#15765447rePTomas Popela <tpopela@redhat.com> - 2.20.4-2[l,- webkitgtk4: Crash on Google login page when a11y is active
- Resolves: rhbz#1503624
- Revert patch causing rendering glitches
;;7|eQTomas Popela <tpopela@redhat.com> - 2.20.4-2[l,- webkitgtk4: Crash on Google login page when a11y is active
- Resolves: rhbz#1503624
- Revert patch causing rendering glitches+{esQTomas Popela <tpopela@redhat.com> - 2.20.4-1[h8@- Update to 2.20.4
- Resolves: rhbz#1576544
- WebKitWebProcess crashes when a11y is active
- Resolves: rhbz#1591638nze{QTomas Popela <tpopela@redhat.com> - 2.20.3-5[3|@- Add GStreamer coverity fixes
- Resolves: rhbz#1576544hyu_PMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-3aS- Fix CVE-2021-30858
- Resolves: #2006421wxu}PMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-2^@- Resolves: rhbz#1817144 Rebuild to support ppc and s390
)lhu_QMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-3aS- Fix CVE-2021-30858
- Resolves: #2006421wu}QMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-2^@- Resolves: rhbz#1817144 Rebuild to support ppc and s390hu_QMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-1^m@- Resolves: rhbz#1817144 Rebase to 2.28.2Y_WQEike Rathke <erack@redhat.com> - 2.22.7-2\- Related: rhbz#1669482 covscan fixes\_]QEike Rathke <erack@redhat.com> - 2.22.7-1\- Related: rhbz#1669482 Update to 2.22.7]~__QEike Rathke <erack@redhat.com> - 2.22.6-1\b@- Resolves: rhbz#1669482 Rebase to 2.22.6q}eQTomas Popela <tpopela@redhat.com> - 2.20.5-1[r@- Update to 2.20.5 - technically it was not necessary as the only difference
  between 2.20.4 and .5 was the revert of one change, that we already reverted
  while building 2.20.4. But it's better to stay with upstream.
- Update the labels patch with the version that was pushed upstream.
- Resolves: rhbz#1576544
K"K]__REike Rathke <erack@redhat.com> - 2.22.6-1\b@- Resolves: rhbz#1669482 Rebase to 2.22.6qeRTomas Popela <tpopela@redhat.com> - 2.20.5-1[r@- Update to 2.20.5 - technically it was not necessary as the only difference
  between 2.20.4 and .5 was the revert of one change, that we already reverted
  while building 2.20.4. But it's better to stay with upstream.
- Update the labels patch with the version that was pushed upstream.
- Resolves: rhbz#15765447eRTomas Popela <tpopela@redhat.com> - 2.20.4-2[l,- webkitgtk4: Crash on Google login page when a11y is active
- Resolves: rhbz#1503624
- Revert patch causing rendering glitches+esRTomas Popela <tpopela@redhat.com> - 2.20.4-1[h8@- Update to 2.20.4
- Resolves: rhbz#1576544
- WebKitWebProcess crashes when a11y is active
- Resolves: rhbz#1591638ne{RTomas Popela <tpopela@redhat.com> - 2.20.3-5[3|@- Add GStreamer coverity fixes
- Resolves: rhbz#1576544
C\~+esSTomas Popela <tpopela@redhat.com> - 2.20.4-1[h8@- Update to 2.20.4
- Resolves: rhbz#1576544
- WebKitWebProcess crashes when a11y is active
- Resolves: rhbz#1591638ne{STomas Popela <tpopela@redhat.com> - 2.20.3-5[3|@- Add GStreamer coverity fixes
- Resolves: rhbz#1576544h
u_RMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-3aS- Fix CVE-2021-30858
- Resolves: #2006421wu}RMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-2^@- Resolves: rhbz#1817144 Rebuild to support ppc and s390hu_RMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-1^m@- Resolves: rhbz#1817144 Rebase to 2.28.2Y
_WREike Rathke <erack@redhat.com> - 2.22.7-2\- Related: rhbz#1669482 covscan fixes\	_]REike Rathke <erack@redhat.com> - 2.22.7-1\- Related: rhbz#1669482 Update to 2.22.7
DDm
Dhu_SMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-1^m@- Resolves: rhbz#1817144 Rebase to 2.28.2Y_WSEike Rathke <erack@redhat.com> - 2.22.7-2\- Related: rhbz#1669482 covscan fixes\_]SEike Rathke <erack@redhat.com> - 2.22.7-1\- Related: rhbz#1669482 Update to 2.22.7]__SEike Rathke <erack@redhat.com> - 2.22.6-1\b@- Resolves: rhbz#1669482 Rebase to 2.22.6qeSTomas Popela <tpopela@redhat.com> - 2.20.5-1[r@- Update to 2.20.5 - technically it was not necessary as the only difference
  between 2.20.4 and .5 was the revert of one change, that we already reverted
  while building 2.20.4. But it's better to stay with upstream.
- Update the labels patch with the version that was pushed upstream.
- Resolves: rhbz#15765447eSTomas Popela <tpopela@redhat.com> - 2.20.4-2[l,- webkitgtk4: Crash on Google login page when a11y is active
- Resolves: rhbz#1503624
- Revert patch causing rendering glitches
lZliikTDavide Caratti <dcaratti@redhat.com> - 1:2.6-7YB@- avoid key reinstallation (CVE-2017-13077, CVE-2017-13078, CVE-2017-13079,
  CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2017-13086,
  CVE-2017-13087, CVE-2017-13088)i'TDavide Caratti <dcaratti@redhat.com> - 1:2.6-6Y- Fix segmentation fault on EAPOL RX if macsec.ko is not loaded (rh #1489919)Li1TDavide Caratti <dcaratti@redhat.com> - 1:2.6-5Y;@- macsec: Fix segmentation fault in case macsec.ko is not loaded (rh #1440646)
- nl80211: Fix race condition in detecting MAC change (rh #1447073)^gYTLubomir Rintel <lrintel@redhat.com> - 1:2.6-4X9@- Include MACsec headers (rh #1438007)hu_SMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-3aS- Fix CVE-2021-30858
- Resolves: #2006421wu}SMichael Catanzaro <mcatanzaro@redhat.com> - 2.28.2-2^@- Resolves: rhbz#1817144 Rebuild to support ppc and s390
.*!o)TDavide Caratti <dcaratti@redhat.com> - 1:2.6-12.1`F- P2P: Fix a corner case in peer addition based on PD Request (CVE-2021-27803)} kTDavide Caratti <dcaratti@redhat.com> - 1:2.6-12[9@- Ignore unauthenticated encrypted EAPOL-Key data (CVE-2018-14526)pkyTDavide Caratti <dcaratti@redhat.com> - 1:2.6-11[5@- Better handling of /run/wpa_supplicant (rh #1507919)k-TDavide Caratti <dcaratti@redhat.com> - 1:2.6-10Z@- Fix memory leak when macsec MKA/PSK is used (rh #1500442)
- Fix authentication failure when the MAC is updated externally (rh #1490885)
- Let the kernel discard EAPOL if packet type is PACKET_OTHERHOST (rh #1434434)
- Don't restart wpa_supplicant.service on package upgrade (rh #1505404)
- Don't own a directory in /run/ (rh #1507919)dicTDavide Caratti <dcaratti@redhat.com> - 1:2.6-9ZS]@- Fix RPMDiff failures on ppc (rh #1532320)figTDavide Caratti <dcaratti@redhat.com> - 1:2.6-8ZOh- Fix build issue on kernel-alt (rh #1531254)
BOBQ)g?UDaniel Mach <dmach@redhat.com> - 3.3.12ga12-3Rk- Mass rebuild 2013-12-27f({UUSamantha N. Bueno <sbueno[at]redhat.com> - 3.3.12ga12-2QP<A- Rebuilt to include fix for #9267377'{uUSamantha N. Bueno <sbueno[at]redhat.com> - 3.3.12ga12-1QP<@- updated to 3.3.12ga12
- fixes CVE-2012-5662 (#889373, #924228)
- add support for aarch64 to build system (#926737)]&3UParag Nemade <paragn AT fedoraproject DOT org> - 3.3.12ga11-5Q- Remove vendor tag from desktop file as per https://fedorahosted.org/fesco/ticket/1077
- Cleanup spec as per recently changed packaging guidelinesX%cQUDan Horák <dan[at]danny.cz> - 3.3.12ga11-4P- fix license (BSD instead of MIT)P$cAUDan Horák <dan[at]danny.cz> - 3.3.12ga11-3Pd?- cleanup of BuildRequires\#cYUDan Horák <dan[at]danny.cz> - 3.3.12ga11-2P\V- enable DBCS character sets (#801139)M"c;UDan Horák <dan[at]danny.cz> - 3.3.12ga11-1PI- updated to 3.3.12ga11
BA<B71{uVSamantha N. Bueno <sbueno[at]redhat.com> - 3.3.12ga12-1QP<@- updated to 3.3.12ga12
- fixes CVE-2012-5662 (#889373, #924228)
- add support for aarch64 to build system (#926737)]03VParag Nemade <paragn AT fedoraproject DOT org> - 3.3.12ga11-5Q- Remove vendor tag from desktop file as per https://fedorahosted.org/fesco/ticket/1077
- Cleanup spec as per recently changed packaging guidelinesX/cQVDan Horák <dan[at]danny.cz> - 3.3.12ga11-4P- fix license (BSD instead of MIT)P.cAVDan Horák <dan[at]danny.cz> - 3.3.12ga11-3Pd?- cleanup of BuildRequires\-cYVDan Horák <dan[at]danny.cz> - 3.3.12ga11-2P\V- enable DBCS character sets (#801139)M,c;VDan Horák <dan[at]danny.cz> - 3.3.12ga11-1PI- updated to 3.3.12ga11f+keUJakub Čajka <jcajka@redhat.com> - 3.3.12ga12-5a(@- Fix sigill in c3270
- Resolves: BZ#2012913Q*g?UDaniel Mach <dmach@redhat.com> - 3.3.12ga12-4RU- Mass rebuild 2014-01-24
	?A1}!?]:3WParag Nemade <paragn AT fedoraproject DOT org> - 3.3.12ga11-5Q- Remove vendor tag from desktop file as per https://fedorahosted.org/fesco/ticket/1077
- Cleanup spec as per recently changed packaging guidelinesX9cQWDan Horák <dan[at]danny.cz> - 3.3.12ga11-4P- fix license (BSD instead of MIT)P8cAWDan Horák <dan[at]danny.cz> - 3.3.12ga11-3Pd?- cleanup of BuildRequires\7cYWDan Horák <dan[at]danny.cz> - 3.3.12ga11-2P\V- enable DBCS character sets (#801139)M6c;WDan Horák <dan[at]danny.cz> - 3.3.12ga11-1PI- updated to 3.3.12ga11f5keVJakub Čajka <jcajka@redhat.com> - 3.3.12ga12-5a(@- Fix sigill in c3270
- Resolves: BZ#2012913Q4g?VDaniel Mach <dmach@redhat.com> - 3.3.12ga12-4RU- Mass rebuild 2014-01-24Q3g?VDaniel Mach <dmach@redhat.com> - 3.3.12ga12-3Rk- Mass rebuild 2013-12-27f2{UVSamantha N. Bueno <sbueno[at]redhat.com> - 3.3.12ga12-2QP<A- Rebuilt to include fix for #926737
hD0_hXB_UXEric Sandeen <sandeen@redhat.com> 3.1.3-1RR@- Update to version 3.1.3 (#1016306)AXFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.1.2-2Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuildc@_kXEric Sandeen <sandeen@redhat.com> 3.1.2-1P@- New upstream release, with non-broken tarballf?keWJakub Čajka <jcajka@redhat.com> - 3.3.12ga12-5a(@- Fix sigill in c3270
- Resolves: BZ#2012913Q>g?WDaniel Mach <dmach@redhat.com> - 3.3.12ga12-4RU- Mass rebuild 2014-01-24Q=g?WDaniel Mach <dmach@redhat.com> - 3.3.12ga12-3Rk- Mass rebuild 2013-12-27f<{UWSamantha N. Bueno <sbueno[at]redhat.com> - 3.3.12ga12-2QP<A- Rebuilt to include fix for #9267377;{uWSamantha N. Bueno <sbueno[at]redhat.com> - 3.3.12ga12-1QP<@- updated to 3.3.12ga12
- fixes CVE-2012-5662 (#889373, #924228)
- add support for aarch64 to build system (#926737)
P?fI_qXEric Sandeen <sandeen@redhat.com> 3.1.7-2YZA- Fix bind mount vs root inode problems (#1698057)0H_XEric Sandeen <sandeen@redhat.com> 3.1.7-1YZ@- Rebase to build against current RHEL7 xfsprogs headers
- Fix race condition between lseek() and read()/write() (#1086532)	G_5XEric Sandeen <sandeen@redhat.com> 3.1.4-1S- Fix aarch64 build (#1028131)
- Rebase to 3.1.4 to roll up prior individual patchesmF_XEric Sandeen <sandeen@redhat.com> 3.1.3-5S- Preserve file capabilities during xfsrestore (#1013345)LE]?XDaniel Mach <dmach@redhat.com> - 3.1.3-4RU- Mass rebuild 2014-01-24LD]?XDaniel Mach <dmach@redhat.com> - 3.1.3-3Rk- Mass rebuild 2013-12-27+C_yXEric Sandeen <sandeen@redhat.com> 3.1.3-2R;- Preserve xattrs on multi-part stream restores (#1034014)
- Prevent segfault on multi-part stream restores (#1034015)

er+V:eDe
7f007138d6b8afc352f1f7423577591e6c1dddd316b6bad15657662274470ad8Dd
cc9a0f5a5c96b17d6168b3f922ccac3f1d0d73520ab3386c2b40ca2263835c11Dc
5d32bb64c9e38540fbd1eacb34c8a893d190ec02b8c21d9b8c07c84d9afbeea0Db
fc779dd3d8c318abfbcddbc7accbbfc6b6690b7989ac005f12a76ade071b6d13Da
2ee3a5da16c04faa9c4d68e73e214570e6b2a709f6222ff6e93b468a2b79f084D`
4df06b794b26d27579781dfbefc5c00b87d84844c334da58b364f3484b878593D_
421f399d269c4af9f6ea67eef863e122a920ba76ba5b890c4591f7adc604c2bcD^
c225d678d3f32eba7cf04174d8cf0eeb9ab41ca91d2b6ab7e323881eb77970d1D]
f175256e0db000797ef4332af954004e00e6e2e00f33db843eee3edb4eddc61eD\
e6771230fa6e197c3187538f6fa13d73b7350fb996824194127c1ad59a8fee30D[
8baa36fb50bc4850b5ac66dac93cb27812550ac6f755518bb37973c3a49e25e0DZ
ac76b51bd9f736a23ca9ba8c09321e9756cbe003031b58be353bdf21e4cc8f62DY
b87014ec721416e0cf97d51775ad4670f9e657f37f27c2287900efbdf9361423
e	Y	H	P_5YEric Sandeen <sandeen@redhat.com> 3.1.4-1S- Fix aarch64 build (#1028131)
- Rebase to 3.1.4 to roll up prior individual patchesmO_YEric Sandeen <sandeen@redhat.com> 3.1.3-5S- Preserve file capabilities during xfsrestore (#1013345)LN]?YDaniel Mach <dmach@redhat.com> - 3.1.3-4RU- Mass rebuild 2014-01-24LM]?YDaniel Mach <dmach@redhat.com> - 3.1.3-3Rk- Mass rebuild 2013-12-27+L_yYEric Sandeen <sandeen@redhat.com> 3.1.3-2R;- Preserve xattrs on multi-part stream restores (#1034014)
- Prevent segfault on multi-part stream restores (#1034015)XK_UYEric Sandeen <sandeen@redhat.com> 3.1.3-1RR@- Update to version 3.1.3 (#1016306)JYFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.1.2-2Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
[Kxl[mX_ZEric Sandeen <sandeen@redhat.com> 3.1.3-5S- Preserve file capabilities during xfsrestore (#1013345)LW]?ZDaniel Mach <dmach@redhat.com> - 3.1.3-4RU- Mass rebuild 2014-01-24LV]?ZDaniel Mach <dmach@redhat.com> - 3.1.3-3Rk- Mass rebuild 2013-12-27+U_yZEric Sandeen <sandeen@redhat.com> 3.1.3-2R;- Preserve xattrs on multi-part stream restores (#1034014)
- Prevent segfault on multi-part stream restores (#1034015)XT_UZEric Sandeen <sandeen@redhat.com> 3.1.3-1RR@- Update to version 3.1.3 (#1016306)eSeiYDonald Douwsma <ddouwsma@redhat.com> 3.1.7-3c- Fix restoring inventory from tape (#2054511)fR_qYEric Sandeen <sandeen@redhat.com> 3.1.7-2b@- Fix bind mount vs root inode problems (#1698057)0Q_YEric Sandeen <sandeen@redhat.com> 3.1.7-1YZ@- Rebase to build against current RHEL7 xfsprogs headers
- Fix race condition between lseek() and read()/write() (#1086532)
?rS?u^[[Simo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6-]cyZPavel Reichl <preichl@redhat.com> - 3.1.7-4e6`@- Batch fixing several issues
- xfsrestore: Files from the backup go to orphanage dir because of xfsdump
-      issue, Related: RHEL-10529
- xfsdump/xfsrestore: suggest recovery for false roots may be possible using -x,
-      Related: RHEL-14912e\eiZDonald Douwsma <ddouwsma@redhat.com> 3.1.7-3c- Fix restoring inventory from tape (#2054511)f[_qZEric Sandeen <sandeen@redhat.com> 3.1.7-2b@- Fix bind mount vs root inode problems (#1698057)0Z_ZEric Sandeen <sandeen@redhat.com> 3.1.7-1YZ@- Rebase to build against current RHEL7 xfsprogs headers
- Fix race condition between lseek() and read()/write() (#1086532)	Y_5ZEric Sandeen <sandeen@redhat.com> 3.1.4-1S- Fix aarch64 build (#1028131)
- Rebase to 3.1.4 to roll up prior individual patches
22f[=[Simo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkYe[[[Simo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091]d[c[Simo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038	c[9[Simo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorspb[[Simo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackageaa[k[Simo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzH`[7[Simo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamH_[9[Simo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patch
b[db	m[9\Simo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorspl[\Simo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackageak[k\Simo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzHj[7\Simo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamHi[9\Simo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patchuh[\Simo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 ge][Tomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337
{B
H{Ht[7]Simo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamHs[9]Simo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patchur[]Simo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 qe]\Tomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337p[=\Simo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkYo[[\Simo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091]n[c\Simo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038
-'8K-u|[^Simo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 {e]]Tomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337z[=]Simo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkYy[[]Simo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091]x[c]Simo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038	w[9]Simo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorspv[]Simo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackageau[k]Simo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzz
22[=^Simo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkY[[^Simo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091][c^Simo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038	[9^Simo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorsp[^Simo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackagea[k^Simo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzH~[7^Simo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamH}[9^Simo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patch
b[db	[9_Simo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorsp
[_Simo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackagea	[k_Simo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzH[7_Simo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamH[9_Simo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patchu[_Simo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 e]^Tomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337
{B
H{H[7`Simo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamH[9`Simo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patchu[`Simo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 e]_Tomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337[=_Simo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkY
[[_Simo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091][c_Simo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038
-'8K-u[aSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 e]`Tomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337[=`Simo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkY[[`Simo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091][c`Simo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038	[9`Simo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorsp[`Simo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackagea[k`Simo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzz
22"[=aSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkY![[aSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091] [caSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038	[9aSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorsp[aSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackagea[kaSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzH[7aSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamH[9aSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patch
b[db	)[9bSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorsp([bSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackagea'[kbSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzH&[7bSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamH%[9bSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patchu$[bSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 #e]aTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337
{B
H{H0[7cSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamH/[9cSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patchu.[cSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 -e]bTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337,[=bSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkY+[[bSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091]*[cbSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038
-'8K-u8[dSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 7e]cTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-33376[=cSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkY5[[cSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091]4[ccSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038	3[9cSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorsp2[cSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackagea1[kcSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzz
22@[=dSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkY?[[dSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091]>[cdSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038	=[9dSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorsp<[dSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackagea;[kdSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzH:[7dSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamH9[9dSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patch
b[db	G[9eSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorspF[eSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackageaE[keSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzHD[7eSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamHC[9eSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patchuB[eSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 Ae]dTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337
{B
H{HN[7fSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamHM[9fSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patchuL[fSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 Ke]eTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337J[=eSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkYI[[eSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091]H[ceSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038

er+V:eDr
375dc1e4e253dad77a1c726888c330f2d32bfac978fb2501318c810a4fb93843Dq
ce5ed6d89d8f493b333f990a74873904d861f5b520c9b0a8be3c6e2b614068f7Dp
0435f345b2b188c76dbb4a538bf0f878834a41e723491df1926231020fd88efdDo
d761e44c332a8ff96d411a4c5c1f89e8dd4f879fdc8fcc876f24cd2683aea6aeDn
152e52a9fea9de88492276d62ad1f3197d8720d0caf399f23d096b827375a6b5Dm
16e7fce47c141a06695e847b179e86c984a88ba42655eaa04388c7494d0b92fcDl
8ed81fb816e95c0feb27e37fdf7922b9999dfc31e8e871d968bf849bd8858bc9Dk
009f5f995347d3b6f6491ec4dd82192efd57cf782be7741597e2a9259a1b4a3cDj
6dd07a33a81efe8c3709098885698f104928c810cdaa6390f1c3327bd53dfd94Di
92338eb8dc8e5df6c7042a8d6f53cefa02c604ac421e41331a9b6a496e4b7dd6Dh
f3a22e24901cdfdb4cde6e3e1d5b92db9632edc9ae10810d0634340ae334a5fdDg
85452769364c8efbb31876c1f6d55993159c1055188c65ea7c17556d78ea87adDf
4920894974a22381aabd54732be72cc0879f5ab5e7584a6e9ea403da66101b5c
-'8K-uV[gSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 Ue]fTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337T[=fSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkYS[[fSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091]R[cfSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038	Q[9fSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorspP[fSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackageaO[kfSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzz
22^[=gSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkY][[gSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091]\[cgSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038	[[9gSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorspZ[gSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackageaY[kgSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzHX[7gSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamHW[9gSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patch
b[db	e[9hSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorspd[hSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackageac[khSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzHb[7hSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamHa[9hSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patchu`[hSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 _e]gTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337
{B
H{Hl[7iSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamHk[9iSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patchuj[iSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 ie]hTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337h[=hSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkYg[[hSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091]f[chSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038
-'8K-ut[jSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 se]iTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337r[=iSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkYq[[iSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091]p[ciSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038	o[9iSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorspn[iSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackageam[kiSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzz
22|[=jSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkY{[[jSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091]z[cjSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038	y[9jSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorspx[jSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackageaw[kjSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzHv[7jSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamHu[9jSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patch
b[db	[9kSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorsp[kSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackagea[kkSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzH[7kSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamH[9kSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patchu~[kSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 }e]jTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337
{B
H{H
[7lSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamH	[9lSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patchu[lSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 e]kTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337[=kSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkY[[kSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091][ckSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038
-'8K-u[mSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 e]lTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337[=lSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkY[[lSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091][clSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038	
[9lSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorsp[lSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackagea[klSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzz
22[=mSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkY[[mSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091][cmSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038	[9mSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorsp[mSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackagea[kmSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzH[7mSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamH[9mSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patch
b[db	![9nSimo Sorce <simo@redhat.com> - 1.2.20-4S[- Add fixes from upstream
- These were sent by us after covscan checks revelead errorsp [nSimo Sorce <simo@redhat.com> - 1.2.20-3S- Make RPMDiff happy by adding a strict require on subpackagea[knSimo Sorce <simo@redhat.com> - 1.2.20-2S- Update pkg-config fix patch to apply w/o fuzzH[7nSimo Sorce <simo@redhat.com> - 1.2.20-1S- New upstrema version with memleaks, crl checks and other fixes
- enable make check during build
- drop ecdsa patch as it has been included upstreamH[9nSimo Sorce <simo@redhat.com> - 1.2.19-6S8A- Fix incomplete patchu[nSimo Sorce <simo@redhat.com> - 1.2.19-5S8@- Add patch to deal with different behavior of pkg-config in RHEL6 e]mTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337
MB
HM@)_%oAdam Jackson <ajax@redhat.com> - 7.10.0-1Yd- ati 7.10.0Y(]YoAdam Jackson <ajax@redhat.com> - 7.7.1-3YG- Validate RANDR output property atomsV'WYoLyude Paul <lyude@redhat.com> 7.7.1-2X@- Fix more breakage from removing DRI1@&coHans de Goede <hdegoede@redhat.com> 7.7.1-1W- Update to latest git, this is the equivalent of 7.7.1 + fixes for use
  with xserver-1.19 (rhbz#1325613)
- Rebuild against xserver-1.19 %e]nTomas Halman <thalman@redhat.com> - 1.2.20-8e&@- xmlsec1 fails to validate XML signatures made using ECDSA algorithm in FIPS mode
- Resolves: RHEL-3337$[=nSimo Sorce <simo@redhat.com> - 1.2.20-7Y@- CVE-2017-1000061
- Related: #1472092
- Resolves: #1472091
- Fix mis-applied patch hunkY#[[nSimo Sorce <simo@redhat.com> - 1.2.20-6Ym@- CVE-2017-1000061
- Resolves: #1472091]"[cnSimo Sorce <simo@redhat.com> - 1.2.20-5T	- Add package to RHEL7
- Resolves: #1118038
	h@Pb2_ipAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreenc1cgpDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors}0s	pPeter Hutterer <peter.hutterer@redhat.com> 1.20.4-2\N- Don't reset last.valuators on slave device switch (#1640207)k/kooMichel Dänzer <mdaenzer@redhat.com> - 19.0.1-3^!- Fix a regression with user-switching (#1789741)g.meoOlivier Fourdan <ofourdan@redhat.com> - 19.0.1-2\@- Avoid breakage on Xserver reset (#1674474)@-_%oAdam Jackson <ajax@redhat.com> - 19.0.1-1\|- ati 19.0.1u,c	oDave Airlie <airlied@redhat.com> - 18.1.0-1[@- ati 18.1.0 fix some regressions with new X server (#1648116)@+_%oAdam Jackson <ajax@redhat.com> - 18.0.1-1[A- ati 18.0.1P*cAoAdam Jackson <ajax@redhat.com> - 7.10.0-1.1[@- Rebuild for xserver 1.20
98apAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg7aqpAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy6_pAdam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet5_pAdam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu4_
pAdam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)x3apRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120
A+6Ay?_qAdam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet>_qAdam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu=_
qAdam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)x<aqRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120b;_iqAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreenc:cgqDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors9mpMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
|q|uE_
rAdam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xDarRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120ZCmKqMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11BmqMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9AaqAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg@aqqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD
||ZKmKrMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11JmrMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9IarAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegHaqrAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyG_rAdam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetF_rAdam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies
|":|9RasAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegQaqsAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyP_sAdam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetO_sAdam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesuN_
sAdam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)MorOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dLo]rOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)

er+V:eD
ee2c790a3cd22b1261a5cde580d44da4c93c567104a3688cf2369009abb5d332D~
2d21d53b305e30b058ca88d8778bda67000a5d52ab320f04b35e63f6a78f2163D}
8e736c3e7e6197e2f51879707a4e058e188e3e707c7a986b9cfb7846c920b11bD|
730e3f511d99634857cb8c6d1d6a2bb0aeab30962a144cde1567228df8e3ff7cD{
58f7cbee25a91080d46dc3966e5de2b34323527c46cc8b78385b95e36bfd5b1fDz
ad104810553a3472aab26eafb9b0384c21ec463559eb1a5c594cbbac5aa5cbc5Dy
5bd8a5d4bcf1a29dfa914ba710c6486f4e0c90ef8486e5e85044a7488b9ec75eDx
1e079edd2e893af3264ce1312a543eb600f7324169393765ef4fad6463caad42Dw
7244017a6987e7001fb62931332183a4f84646b24773d5ba2acf5c799d15b1faDv
e2e263c938ce2c5090d810688c04ec6cd001741c076f39d1466a32d13305f123Du
ef867ce0d361ef3e0350fa0128a70e322998b6b6c0ed8efaf0a06ff011e132c8Dt
2bfd2b5c14b17c0e7510240064a110b33c36b377955ad7f1245005118f4dc0aaDs
cf170bfe59fb4723dcf9f79d8e4e924c16926a7fa50ee45988c38123421bfff3
X2MXyY_tAdam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetX_tAdam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies\Wa[sAdam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)VosOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dUo]sOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZTmKsMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11SmsMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
$q	$\`a[tAdam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)_otOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d^o]tOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z]mKtMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11\mtMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9[atAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegZaqtAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD
;G_;ZfmKuMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11emuMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9dauAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegcaquAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyb_uAdam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing store4ao{tOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
!J!9mavAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableglaqvAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD+koiuOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334jo{uOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\ia[uAdam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)houOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dgo]uOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)
2M4so{vOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\ra[vAdam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)qovOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dpo]vOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZomKvMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11nmvMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
iPViyowOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dxo]wOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZwmKwMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11vmwMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixesuo1vOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+toivOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
878nygwPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t~yqwPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)}o1wOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+|oiwOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334{o{wOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\za[wAdam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)
X:UXo1xOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oixOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{xOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[xAdam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oxOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]xOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKxMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11
#)<#4
o{yOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[yAdam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oyOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d
o]yOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)h	y[xPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nygxPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tyqxPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
~PQ~co[yOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hy[yPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nygyPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tyqyPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)o1yOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oiyOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
%{b%tyqzPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)o1zOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oizOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{zOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[zAdam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)ozOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)
\"%\+ oi{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[{Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)o5zJosé Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424co[zOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hy[zPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nygzPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)
ls.&o5{José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424c%o[{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h$y[{Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n#yg{Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t"yq{Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)!o1{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770
t#stn+yg|Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t*yq|Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797))o1|Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+(oi|Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033X'oC{José Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428
-X/oC|José Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428.o5|José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424c-o[|Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h,y[|Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)
''n3yg}Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t2yq}Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)j1oi|José Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{0o	|José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201
-X7oC}José Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-184286o5}José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424c5o[}Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h4y[}Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)
j9oi}José Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{8o	}José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201
<{<x?a~Ray Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120b>_i~Adam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreenc=cg~Dave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors}<s	~Peter Hutterer <peter.hutterer@redhat.com> 1.20.4-2\N- Don't reset last.valuators on slave device switch (#1640207)q;ow}José Expósito <jexposit@redhat.com> - 1.20.4-29f@- Fix regression caused by the fix for CVE-2024-31083:o}José Expósito <jexposit@redhat.com> - 1.20.4-28f@- CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and
  CVE-2024-31083
  Resolves: https://issues.redhat.com/browse/RHEL-31003
  Resolves: https://issues.redhat.com/browse/RHEL-30989
  Resolves: https://issues.redhat.com/browse/RHEL-30973
- Add util-linux as a dependency of Xvfb
- Fix compilation error on i686
a'iaEm~Michel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9Da~Adam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegCaq~Adam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyB_~Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetA_~Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu@_
~Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)
 3>I 9MaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegLaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyK_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetJ_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesuI_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xHaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120bG_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreencFcgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors
E-EgTaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyS_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetR_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesuQ_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xPaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120ZOmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11NmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes

er+V:eD
51fbacc2e26050a7772549f1fe16c46bd8063ea187825ad89b237c34fa9b4250D
b7a51c89deecc8235479935646047575b00838c8e74a15aa90fd3f04dbf38d1fD

e4982c6de18a9fd5a9baa26a2ae8d32a5e2474516998095e06a900fc16cecb18D	
5e8f26bf2d3c10f7ca2d8567b9777801f602ea250b6d32ea056853058490c39cD
cf60217ce1218a1776d98ef45492d93967a6f10369810ef6bb833bbbc8bcb9a0D
eade03c2757a3c0b0151aabbf535e1647f2a3c18eae55a5a975327c4c8027a4cD
aafce5e4b381bbdcd56ca810cabc34fd9ffb40b7f49bd9cec0edce43d0f8596aD
0607eb87b1e4a72aa8d10708247befdd19963e0ca5b2fe44d7d76eda6a408652D
4ba6b6ddecf71dc7d8295a3fb4185fa2934f07e58716d8466b73a50137c58a53D
db91ac87e5096fe4cf5cd292f4692633d26bdafb9ceefc8288141677f62626caD
5ef15604ff8baa8611a443eb38e948c0561633200d60d93d6ec70aafe375876eD
a83c7d173d50416c52930bc2a1c8a136889066cddd068990b84f0ed6f341dfacD
fc23786485123d8fc0e167c65ecee809b1c1047c61cea465e243cf4b64b2a78e
vB:tvuZ_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)YoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dXo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZWmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11VmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9UaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disable
||Z`mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11_mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9^aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg]aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy\_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet[_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies
;S9gaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegfaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDye_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetd_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies\ca[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)boOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dao]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)
2Myn_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing store4mo{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\la[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)koOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)djo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZimKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11hmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
$q	$\ua[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)toOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dso]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZrmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11qmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9paAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegoaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD
fG,nfzmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9yaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegxaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD+woiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334vo{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
X:UXo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\~a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)}oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d|o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z{mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11
2M4o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
PQd
o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11nygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t
yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)	o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
%{b%tyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)
l"5l+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)hy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)
Ils.I\!a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956) oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)co[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770
,G
,h'y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n&ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t%yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)$o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+#oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334"o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
:-o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+,oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334+o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\*a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956))o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424c(o[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)
O),OX3oCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-184282o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424c1o[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h0y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n/ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t.yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
~PQ~c9o[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h8y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n7ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t6yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)5o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+4oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
jj=oiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{<o	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201X;oCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428:o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424
O),OXCoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428Bo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cAo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h@y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n?ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t>yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)bRIRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{IEIKIRIYI`IfImIsIyIII
III I&I+I/I3I7I9I?IEIMITIZI`IgInIuIzIII
III!I'I-I3I9I=ICIEIKIQIƒYIÃ`IăfIŃlIƃsIǃzIȃIɃIʃ
I˃ĨI̓I΃&Iσ-IЃ3Iу9I҃?IӃEIԃIIՃOIփQI׃WIك]IڃeIۃlI܃rI݃xIރI߃I
IIII%I+I2I9I?IEIKIQIUI[I]IcIiIqIxI~III
jEoiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{Do	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201
<{<xKaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120bJ_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreencIcgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors}Hs	Peter Hutterer <peter.hutterer@redhat.com> 1.20.4-2\N- Don't reset last.valuators on slave device switch (#1640207)qGowJosé Expósito <jexposit@redhat.com> - 1.20.4-29f@- Fix regression caused by the fix for CVE-2024-31083FoJosé Expósito <jexposit@redhat.com> - 1.20.4-28f@- CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and
  CVE-2024-31083
  Resolves: https://issues.redhat.com/browse/RHEL-31003
  Resolves: https://issues.redhat.com/browse/RHEL-30989
  Resolves: https://issues.redhat.com/browse/RHEL-30973
- Add util-linux as a dependency of Xvfb
- Fix compilation error on i686
a'iaQmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9PaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegOaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyN_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetM_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesuL_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)

er+V:eD
f80cd4881b32dd129ece7202403ba656b6cabbaebccce97cfcacaf448e2d221fD
c7b6417b605af3adcca501eb73c1898aa00b4691197c4567e74e721dcb034436D
51531084503ccca2963d7cdc52e607efbbce02b1e36cb9bf5e983279ba6341b1D
c93c7d0870295039879e0541eba827c632e03b42a8662810fca06462a79987f1D
33aa4a6c127c0c756e8327baf78c7d6040d9adc0e92dd42d324a4b1625c99bb6D
56ca48ac0b31c1895271b0c78a7c6fd5045f217634b908660f5d61925af71252D
f31fd03961b259ff05fa33eb46e64b8dfb29cd1193b459d1721e424ea9616d10D
27db2217dfdcab84a095b8363c3aaf36fd751a336577cc3de811d0a747c37febD
98dba21e88ff7d380ddbbdde2d2aa47ccf7bc6da63c4ae460dab25788449a87eD
822adbeedf758cb1febec29ff177d207923b6e3c24749077ca4f3a684d593d1cD
a2f9c00b20dcf7207991f467a8714eb3d7273d424ee4dd045d1a5232da5cd797D
a79594486e59ec5b826e79499c455a6d627baff4bdc3f3df763e5018309b5f9cD

4fd4ad7ed695ea67c7d6d97ea6cc730d12e1d50fb6da365945d0f6255af4bd45
 3>I 9YaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegXaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyW_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetV_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesuU_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xTaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120bS_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreencRcgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors
E-Eg`aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy__Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet^_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu]_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)x\aRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120Z[mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11ZmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
vB:tvuf_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)eoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)ddo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZcmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11bmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disable
||ZlmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11kmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9jaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegiaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyh_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetg_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies
;S9saAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegraqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyq_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetp_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies\oa[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)noOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dmo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)
2Myz_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing store4yo{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\xa[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)woOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dvo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZumKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11tmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
$q	$\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z~mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11}mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9|aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg{aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD
fG,nfmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
X:UX
o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\
a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)	oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11
2M4o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
PQdo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11nygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
%{b%tyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)
l"5l+&oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334%o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\$a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)#oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d"o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)h!y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)
Ils.I\-a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956),oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)c+o[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h*y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n)ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t(yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)'o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770
,G
,h3y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n2ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t1yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)0o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+/oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334.o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
:9o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+8oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#210903347o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\6a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)5o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424c4o[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)
O),OX?oCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428>o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424c=o[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h<y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n;ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t:yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
~PQ~cEo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hDy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nCygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tByqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)Ao1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+@oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
jjIoiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{Ho	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201XGoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428Fo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424
O),OXOoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428No5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cMo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hLy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nKygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tJyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
jQoiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{Po	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201
<{<xWaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120bV_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreencUcgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors}Ts	Peter Hutterer <peter.hutterer@redhat.com> 1.20.4-2\N- Don't reset last.valuators on slave device switch (#1640207)qSowJosé Expósito <jexposit@redhat.com> - 1.20.4-29f@- Fix regression caused by the fix for CVE-2024-31083RoJosé Expósito <jexposit@redhat.com> - 1.20.4-28f@- CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and
  CVE-2024-31083
  Resolves: https://issues.redhat.com/browse/RHEL-31003
  Resolves: https://issues.redhat.com/browse/RHEL-30989
  Resolves: https://issues.redhat.com/browse/RHEL-30973
- Add util-linux as a dependency of Xvfb
- Fix compilation error on i686

er+V:eD&
dfe2f972771603f046f22e69e38741bf6dc94baeaec867665169bb3e9b9b8eacD%
43424b0d689ecfd0d4282dd45e7088dafcdd16f51f968cf76021b08f5a1060e0D$
85cd5123793aa450727948cc2dc0222838b43e3ba8e5301199710b0f897a9f21D#
65cf532a0d956c5b90633a7b13857b7e3092f374d67c465f3126a5fef5cf70aeD"
79e43cf434b3dee8dae9d367becc2c0025c3514b0684d27a2cfe6fbf9557c019D!
1a57399b3dc42160f3044e768ceb0aa76dee84a8c852b6e9c99ec3568e52eeddD 
7961a17846adb9bd4b8dc39c94b3cbe82106b9f14b61013a3b4896b7335f2e1eD
a88474ca9c7184610d2381b4f56de6ecd823c02da9266a63a5ba57230c0ae64dD
d222b43a6c9a83d63e9c529e8e528b248aa0f77b4b23e5e7256d32c1a64bee44D
cf01690bbc873920b5a486d4d4e6b92160ae532f81d1ce1045c632c8c0c68aaeD
38116fc986dbde5d1071bccc99bf83579d9cf9cfe210af409971b02a8225df2eD
6043225f18090a8529ea90341ff21d58fd2e2a85ee1c31af68145a7c070803c4D
eb89964d5fd40ec94ee8db97a5a14cc8dd6329b83d82ab29ee1a595653ce5223
a'ia]mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9\aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg[aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyZ_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetY_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesuX_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)
 3>I 9eaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegdaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyc_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetb_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesua_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)x`aRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120b__iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreenc^cgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors
E-EglaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyk_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetj_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesui_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xhaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120ZgmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11fmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
vB:tvur_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)qoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dpo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZomKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11nmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9maAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disable
||ZxmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11wmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9vaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableguaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyt_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storets_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies
;S9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg~aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy}_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet|_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies\{a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)zoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dyo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)
2My_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing store4o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
$q	$\
a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z
mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11	mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD
fG,nfmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
X:UXo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11
2M4o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
PQd%o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z$mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11n#ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t"yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)!o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+ oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
%{b%t+yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)*o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+)oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334(o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\'a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)&oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)
l"5l+2oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#210903341o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\0a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)/oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d.o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)h-y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n,ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)
Ils.I\9a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)8oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)c7o[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h6y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n5ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t4yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)3o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770
,G
,h?y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n>ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t=yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)<o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+;oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334:o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
:Eo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+DoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334Co{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\Ba[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)Ao5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424c@o[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)
O),OXKoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428Jo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cIo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hHy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nGygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tFyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
~PQ~cQo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hPy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nOygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tNyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)Mo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+LoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
jjUoiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{To	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201XSoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428Ro5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424

er+V:eD3
f5c53c037a56c4f01f26c5e6d1a0011da7c9f759cf87074bf864708e6ce19828D2
7361f0c9de0e2a09eb70e5f1b83d027a808b06433ca9e73208b44184ea5cb1a8D1
91edff8a7e3788908e55759660855db2ac6a6ef999858dac7faafbcc6b62cb99D0
cf6e5c1bef9ab5c56100beb91545140ecb2ffc878294ed3cb87ee4d53c82f799D/
43a65f36dfe6af5466184f30652144e3c9c8793fa34ed3f819d2d654e01edac9D.
c2cdc7a6e9930a49880578ed60314a159c97e36dd96908f892d53e315b1c0895D-
bbe6a456297232dde9056eadfd3e0082764eea1606419c384a0779b6951f9ae7D,
de6d7edb575cf2c912b54349020bb0c64b19b18869c865f5da30ef088e3cad85D+
ae1aa9868c275415bf9db1de0d9e270cf72ea7011a3c350bcb6efc29acb3b953D*
27534a1920262b79fa35a9509e192cd19a2916bb7b11d0db13f71ae7cff375a9D)
e826d4748706ca4acec7f8adad39873fcd390f7a0086ace767fbf32cfc28d3b0D(
ea32b047fba7fd327bf943da2a18413a1ed3e245cc1b077f34d1c8f6048d9813D'
a513143acbf28366be9f3830ac06cb3468fbca694206826e572edafd38461ed0
O),OX[oCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428Zo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cYo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hXy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nWygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tVyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
j]oiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{\o	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201
<{<xcaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120bb_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreencacgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors}`s	Peter Hutterer <peter.hutterer@redhat.com> 1.20.4-2\N- Don't reset last.valuators on slave device switch (#1640207)q_owJosé Expósito <jexposit@redhat.com> - 1.20.4-29f@- Fix regression caused by the fix for CVE-2024-31083^oJosé Expósito <jexposit@redhat.com> - 1.20.4-28f@- CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and
  CVE-2024-31083
  Resolves: https://issues.redhat.com/browse/RHEL-31003
  Resolves: https://issues.redhat.com/browse/RHEL-30989
  Resolves: https://issues.redhat.com/browse/RHEL-30973
- Add util-linux as a dependency of Xvfb
- Fix compilation error on i686
a'iaimMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9haAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableggaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyf_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storete_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesud_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)
 3>I 9qaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegpaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyo_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetn_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesum_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xlaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120bk_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreencjcgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors
E-EgxaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyw_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetv_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesuu_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xtaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120ZsmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11rmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
vB:tvu~_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)}oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d|o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z{mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11zmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9yaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disable
||ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies
;S9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg
aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy	_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)
2My_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing store4o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z
mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
$q	$\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD
fG,nfmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
X:UX%o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+$oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334#o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\"a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)!oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11
2M4+o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\*a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956))oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d(o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z'mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11&mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
PQd1o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z0mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11n/ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t.yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)-o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+,oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
%{b%t7yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)6o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+5oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#210903344o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\3a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)2oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)
l"5l+>oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334=o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\<a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956);oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d:o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)h9y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n8ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)
Ils.I\Ea[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)DoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)cCo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hBy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nAygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t@yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)?o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770
,G
,hKy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nJygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tIyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)Ho1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+GoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334Fo{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
:Qo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+PoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334Oo{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\Na[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)Mo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cLo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)
O),OXWoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428Vo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cUo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hTy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nSygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tRyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)

er+V:eD@
f83ec3658d72831d5deeee66d0ec75ae458c847847184396c345cb664bbe8d43D?
c24a69689734522bcd79de71a9857bfd1e1606898cc42344ee7b089da3406af0D>
f85fb2606d67d58d19d4784aa765bd6d383b85945372625ef606ddc20559702dD=
9bfa69b7940e4e41942fffc935239c974893faa573fe45c923cc53905317aad3D<
0579155d9d1a4a339ec6d119e12c2ecc135abd36aef7ba674704d62d18e6e6ccD;
ead119fe47b9382012e61124387aa69dfe644f344ccdfad3b91a64e1ab35f467D:
0e2842a9ef72de0a39b188244266ec36bb5efee89dbbb26d2d9b8832fdb44b78D9
ec5ec6e21071682dfbc3c256617c810c886af178cfc7f21a96104cf10ee6cb25D8
b0d7b591888b6fd49b457c15fa981112edaa1d269c881960174a8676102cad81D7
bee904f26bd404d9a8fbf3d71746543eca0b7761bcb562e0158d4282ef1ab8d4D6
4a6ffb39008edd469d4365bb3bf858f5f5f466129eb9e330d978b28866906891D5
dd05b77f960a6b0aed0f034b93449043a31100aec1f59ed4819b5d1ad663b83dD4
303a240bc1792e6c5e9c0d96992a7156a5d867e461081ec7d99fc535e81cb3a2
~PQ~c]o[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h\y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n[ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tZyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)Yo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+XoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
jjaoiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{`o	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201X_oCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428^o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424
O),OXgoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428fo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424ceo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hdy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)ncygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tbyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
jioiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{ho	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201
<{<xoaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120bn_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreencmcgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors}ls	Peter Hutterer <peter.hutterer@redhat.com> 1.20.4-2\N- Don't reset last.valuators on slave device switch (#1640207)qkowJosé Expósito <jexposit@redhat.com> - 1.20.4-29f@- Fix regression caused by the fix for CVE-2024-31083joJosé Expósito <jexposit@redhat.com> - 1.20.4-28f@- CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and
  CVE-2024-31083
  Resolves: https://issues.redhat.com/browse/RHEL-31003
  Resolves: https://issues.redhat.com/browse/RHEL-30989
  Resolves: https://issues.redhat.com/browse/RHEL-30973
- Add util-linux as a dependency of Xvfb
- Fix compilation error on i686
a'iaumMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9taAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegsaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyr_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetq_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesup_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)
 3>I 9}aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg|aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy{_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetz_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesuy_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xxaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120bw_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreencvcgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors
E-EgaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11~mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
vB:tvu
_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)	oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disable
||ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg
aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies
;S9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)
2My_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing store4o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
$q	$\%a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)$oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d#o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z"mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11!mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9 aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD
fG,nf*mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9)aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg(aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD+'oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334&o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
X:UX1o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+0oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334/o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\.a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)-oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d,o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z+mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11
2M47o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\6a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)5oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d4o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z3mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-112mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
PQd=o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z<mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11n;ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t:yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)9o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+8oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
%{b%tCyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)Bo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+AoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334@o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\?a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)>oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)
l"5l+JoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334Io{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\Ha[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)GoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dFo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)hEy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nDygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)
Ils.I\Qa[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)PoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)cOo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hNy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nMygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tLyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)Ko1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770
,G
,hWy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nVygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tUyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)To1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+SoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334Ro{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
:]o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+\oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334[o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\Za[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)Yo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cXo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)

er+V:eDM
0f90f0d1b094fbfc4ba66750ee90dbf63d119647ec2239d5614a604299fe4555DL
079a8f1382b2cde5fc460d2bfb277e6586eeffb928b2d9ed2bb6258fdc6fc4edDK
50b46cc6de592b1b49fec6ba38878c1a368940c367309a46433e7015b68a5184DJ
d009248700d9e5dfb31d429a3fc4511bf6d988ab6276af506e8279a020138c9bDI
9d2caa5bdf17716a2d9e2503e5e5490dd97a317659eb35ed3ee294d10b9132beDH
99b661c96e07cf126304451e9aa41291a49a8f3fc0d29d14dabcfb939072586fDG
96e84480f4e5f3ed973231a88b1834dd30e01f9cb98655b8551b7d1f382b024fDF
5ba93bb7af0fa5612cec66a27e5736fb8c5460ccfc0e32ff2e9e8c97c2587a3fDE
bf404adf3b74fc2e12fa6437b1abaaa8f327ed847a1b30602af13942c9bb57d7DD
339bcf68cb37a454eddff7218aff4153a36bafc0d36e2b5b6bde8311c6f3eed8DC
cf83179c708ff22b53ddfb306e537749dfa4ac8e8f7f820be6740d1988c8ffc8DB
701c51272a786e3642f50a00d1af86a89ff81297f2f58e485eecd9a7ff5bfe96DA
9771150045d3b5b33795e4accade6fa6112614b65b0ea938a0ee0cae6cc23ce9
O),OXcoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428bo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cao[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h`y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n_ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t^yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
~PQ~cio[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hhy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)ngygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tfyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)eo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+doiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
jjmoiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{lo	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201XkoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428jo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424
O),OXsoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428ro5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cqo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hpy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)noygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tnyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
juoiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{to	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201
<{<x{aRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120bz_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreencycgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors}xs	Peter Hutterer <peter.hutterer@redhat.com> 1.20.4-2\N- Don't reset last.valuators on slave device switch (#1640207)qwowJosé Expósito <jexposit@redhat.com> - 1.20.4-29f@- Fix regression caused by the fix for CVE-2024-31083voJosé Expósito <jexposit@redhat.com> - 1.20.4-28f@- CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and
  CVE-2024-31083
  Resolves: https://issues.redhat.com/browse/RHEL-31003
  Resolves: https://issues.redhat.com/browse/RHEL-30989
  Resolves: https://issues.redhat.com/browse/RHEL-30973
- Add util-linux as a dependency of Xvfb
- Fix compilation error on i686
a'iamMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy~_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet}_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu|_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)
 3>I 9	aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120b_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreenccgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors
E-EgaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu
_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11
mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
vB:tvu_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disable
||ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesTJR$+29@GNU\cjqx '.5<CJQX_fmt{II%I+I1I7I>IEJKJQJWJ]JaJgJiJoJ	uJ
}JJ
J
JJJ%J*J1J7J=JCJJJQJWJ]JcJiJmJsJuJ {J!J"	J#J$J%J'#J(*J)1J*6J+=J,CJ-IJ.OJ/VJ0]J2cJ3iJ4oJ5uJ6yJ7J8J9J:
J;J<J=!J>)J?0J@6JA<JBDJCKJDQJEWJF^JHdJIjJJpJKvJL}JMJN	JOJPJQ
;S9#aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg"aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy!_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet _Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)
2My*_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing store4)o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\(a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)'oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d&o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z%mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11$mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
$q	$\1a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)0oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d/o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z.mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11-mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9,aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg+aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD
fG,nf6mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes95aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg4aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD+3oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#210903342o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
X:UX=o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+<oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334;o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\:a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)9oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d8o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z7mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11
2M4Co{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\Ba[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)AoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d@o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z?mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11>mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
PQdIo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZHmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11nGygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tFyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)Eo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+DoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
%{b%tOyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)No1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+MoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334Lo{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\Ka[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)JoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)
l"5l+VoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334Uo{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\Ta[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)SoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dRo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)hQy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nPygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)
Ils.I\]a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)\oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)c[o[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hZy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nYygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tXyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)Wo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770

er+V:eDZ
c9dc78f6c0e94a26844ea7d1aa7fbde598ea704957ae7b657c4a63c822bd9f21DY
a2b140586a9cd6744d897271b92c1c28166d43a99eb058d831c0617399959558DX
d24805d0f00f2158a082be3fd450a90be7ca614871fb70850db6aa028a020d87DW
40a441051ed2bb80ba7bf16effb6ef562dc02cffbcb40be34952dcdc20a3b66cDV
8300c30550c66d4567d56de5063d79d5818aea066707cfcf6638dd2811bd74fcDU
5d1ce4fa6ac4356078869027bcaf729140f2ad908b655471ba65eb396ac94887DT
518a5be8d1eae8953da4a54a8b852ce6fdf3a22ed2fd22c5b4db85cd4174a5f5DS
e2dd0c67f3d88a9506f72fcc21ec0af786a377befabac8e1670d3e012d844b06DR
55e13fc8624f8a63b785b5194281c38a4670f03113b0ff2b8fc1df1ca473e1e8DQ
d048e9282e3eab42d5adfd632ef5cd029524100f32b305395da9da9a0371c460DP
878bd3f432c1a1de0ae5f44ae295f84e0ba2eb10d8864b4c35eb61a0a324b21eDO
c5b3418463d5359ed0d1cfb6d42a2b588d5ee49a2fcee4755d55489ae9e78860DN
8bdb42f75a635ac45d5c4a26f945cec79c82329639357232a0aad25797148f95
,G
,hcy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nbygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tayqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)`o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+_oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334^o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
:io1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+hoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334go{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\fa[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)eo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cdo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)
O),OXooCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428no5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cmo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hly[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nkygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tjyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
~PQ~cuo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hty[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nsygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tryqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)qo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+poiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
jjyoiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{xo	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201XwoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428vo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424
O),OXoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428~o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424c}o[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h|y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n{ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tzyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
joiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{o	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201
<{<xaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120b_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreenccgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors}s	Peter Hutterer <peter.hutterer@redhat.com> 1.20.4-2\N- Don't reset last.valuators on slave device switch (#1640207)qowJosé Expósito <jexposit@redhat.com> - 1.20.4-29f@- Fix regression caused by the fix for CVE-2024-31083oJosé Expósito <jexposit@redhat.com> - 1.20.4-28f@- CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and
  CVE-2024-31083
  Resolves: https://issues.redhat.com/browse/RHEL-31003
  Resolves: https://issues.redhat.com/browse/RHEL-30989
  Resolves: https://issues.redhat.com/browse/RHEL-30973
- Add util-linux as a dependency of Xvfb
- Fix compilation error on i686
a'ia
mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy
_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet	_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)
]6E]gaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120b_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreenccgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors}s	Peter Hutterer <peter.hutterer@redhat.com> 1.20.4-2\N- Don't reset last.valuators on slave device switch (#1640207)
xB:mxu_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120b_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreenccgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitorsmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disable
||Z!mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11 mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies
 3>I 9)aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg(aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy'_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet&_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu%_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)x$aRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120b#_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreenc"cgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors
E-Eg0aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy/_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet._Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu-_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)x,aRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120Z+mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11*mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
sB:tsx6aRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #16801205oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d4o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z3mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-112mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes91aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disable
a'ia<mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9;aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg:aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy9_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet8_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu7_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)
:<G9DaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegCaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyB_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetA_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu@_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)?oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d>o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z=mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11
\2M\tK_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesuJ_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)\Ia[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)HoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dGo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZFmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11EmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
ZRdQo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZPmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11OmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9NaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegMaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyL_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing store
{&9WaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegVaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyU_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetT_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies\Sa[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)RoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)
2Mt^_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies4]o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)[oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dZo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZYmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11XmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes

er+V:eDg
5463798db8055d74e5cb4403c06751d747572157fa2188e01c3f8cb37e714148Df
da0ee7d0ba196b9b234e978896c8b7430980fc8e6df7cab9fabd870d89ab5bf0De
202bf466967d3f4ab327e8e2dbe21c4696c4bcd058996baa9a4cc4a00c10dd03Dd
61f9f61c18480f59ddd7ef3382cbad48896469ac9da6dcfe2e3ddd8195e737d0Dc
c34ab6928f9fde2419804036a6bf4221cb2f3487c33bd131afad5e5573f289feDb
4c7d848c14e00ec553e54a225e05056fee56b5df54a71ffe45ce122d6b74625bDa
26770336a22190354f2629a10f4c6c2d42e78462a5b8b78e24159743658c844bD`
e23ad6387e0d97dd5a8214f1c20a8112b68c12124bedabc0dd60ef5e8397681aD_
5264ebb9f634f3266ba74ef377d0db45c52877826efb225687b1430a60c824fbD^
1deb2c2c595359a6d9ce1c3cbf28785cb264b03e34a46f8a05bb2c2922937dc0D]
1224b4daf58dc2c0d85e8536fe7e439c784d857c15e654ad9c5600780755947eD\
4ce199f03c4016f4eb22b3d9b8711e1cb1d9864540849b2a5a1c4df4ee5552ebD[
e58d4578833550c574d220588395dd2ff7fdabaa1bd5e48a04c31911a6caca8a
ZRddo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZcmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11bmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg`aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy__Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing store
{bz9jaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegiaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyh_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing store4go{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\fa[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)eoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)
2M4po{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\oa[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)noOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dmo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZlmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11kmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
DPhDZvmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11umMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9taAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegsaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyr_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing store+qoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
!J!9}aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg|aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD+{oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334zo{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\ya[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)xoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dwo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)
2M4o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11~mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
-PQ-Z	mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
Jo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334
o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d
o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)
2M4o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
IPQImMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixesnygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
X:UX!o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+ oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)do]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11
17J14(o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\'a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)&oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d%o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z$mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11n#ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t"yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
PQd/o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z.mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11h-y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n,ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t+yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)*o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+)oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
%{b%t5yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)4o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+3oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#210903342o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\1a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)0oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)
l"5l+<oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334;o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\:a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)9oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d8o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)h7y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n6ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)
Als.ACoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dBo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)cAo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h@y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n?ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t>yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)=o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770
878nIygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tHyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)Go1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+FoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334Eo{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\Da[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)
K-HKPo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+OoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334No{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\Ma[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)LoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)cKo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hJy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)
G),G\Wa[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)VoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)Uo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cTo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hSy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nRygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tQyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
,G
,h]y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n\ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t[yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)Zo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+YoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334Xo{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
:co1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+boiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334ao{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\`a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)_o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424c^o[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)

er+V:eDt
1e92ab11dbfdb95e9151c5fc2f4ef713c7bea0d91690886bf35bb75cd70c9870Ds
84f175bef4d2561cae46398abd9317955cdbe6a2c0352227323da35cedc29948Dr
1c3887c7641e7d177a4556fa5d66b74cca92bdb865265509120154804c5ddeabDq
d893452495f6ed739d82236d307ce20f1ee7fb06ea522109fca58008ef041452Dp
bb3864015d5c6e8d0e5f6d4ad1683af99c0b275dcf2efcaee1e4aebf6d78082dDo
c962e5dd6d3414983350e5da2de55b057477d165e891c9d963cb8eb49a7c6330Dn
1baa9cb2d4f8d4300ac333fbc7bc130dce9145c67aea3bd6efa4a0354fc92b6dDm
cfb8fb181e4fcc069e88e40ad4838b6d53339b522603c2c188f4b7719a7547d1Dl
b0a8eeea28a48870600033e3ed255b73b22ef84935f83e1d18f3bf72359b66d3Dk
8ace9615be81aa1aef785201bea8d1d530ab9d51947834eb409d60ec032e56d0Dj
df2ac268f02376356b5c4723b8c369c8593c63db05b25c52b9d0d0cfa7b0299bDi
ac303bf67828310850f24db08c7e288f5b122268f84782ca9efef694febcd6e3Dh
ca0dc93240a019ed96e9975ce1f61dee6b3765eb9bc098678f11bc9e92d8f8bc
O),OXioCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428ho5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cgo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hfy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)neygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tdyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
878noygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tnyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)mo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+loiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334ko{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\ja[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)
v-
vuo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+toiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033XsoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428ro5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cqo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hpy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)
O),OX{oCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428zo5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424cyo[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hxy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nwygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tvyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
NNo1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+~oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033j}oiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{|o	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201
O),OXoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424co[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
''n	ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)joiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{o	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201
-X
oCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424co[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h
y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)
joiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{o	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201
/{
/hy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)qowJosé Expósito <jexposit@redhat.com> - 1.20.4-29f@- Fix regression caused by the fix for CVE-2024-31083oJosé Expósito <jexposit@redhat.com> - 1.20.4-28f@- CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and
  CVE-2024-31083
  Resolves: https://issues.redhat.com/browse/RHEL-31003
  Resolves: https://issues.redhat.com/browse/RHEL-30989
  Resolves: https://issues.redhat.com/browse/RHEL-30973
- Add util-linux as a dependency of Xvfb
- Fix compilation error on i686
&&&{o	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201XoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424co[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)
J
Jb_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreenccgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors}s	Peter Hutterer <peter.hutterer@redhat.com> 1.20.4-2\N- Don't reset last.valuators on slave device switch (#1640207)qowJosé Expósito <jexposit@redhat.com> - 1.20.4-29f@- Fix regression caused by the fix for CVE-2024-31083oJosé Expósito <jexposit@redhat.com> - 1.20.4-28f@- CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and
  CVE-2024-31083
  Resolves: https://issues.redhat.com/browse/RHEL-31003
  Resolves: https://issues.redhat.com/browse/RHEL-30989
  Resolves: https://issues.redhat.com/browse/RHEL-30973
- Add util-linux as a dependency of Xvfb
- Fix compilation error on i686joiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886
9$aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg#aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy"_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet!_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu _
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)xaRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120
A+6Ay+_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet*_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu)_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)x(aRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120b'_iAdam Jackson <ajax@redhat.com> - 1.20.4-5\@- Fix a crash in RRProviderAutoConfigGpuScreenc&cgDave Airlie <airlied@redhat.com> - 1.20.4-3\@- Backport fix for 1612924 - enabled monitors%mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
|q|u1_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)x0aRay Strode <rstrode@redhat.com> - 1.20.4-6\!- Stop VT switching when inactive server dies
  Resolves: #1680120Z/mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11.mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9-aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg,aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD
||Z7mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-116mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes95aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg4aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy3_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet2_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies
|":|9>aAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disableg=aqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDy<_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storet;_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologiesu:_
Adam Jackson <ajax@redhat.com> - 1.20.4-7\"- Fix a segfault with non-PCI platform devices (and other cases)9oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d8o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)
X2MXyE_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing storetD_Adam Jackson <ajax@redhat.com> - 1.20.4-8]
#- Fix platform device PCI detection with complex bus topologies\Ca[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)BoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dAo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z@mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11?mMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
$q	$\La[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)KoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dJo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZImKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11HmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9GaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegFaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD
;G_;ZRmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11QmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes9PaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegOaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMDyN_Adam Jackson <ajax@redhat.com> - 1.20.4-9]R@- Fix a crash when destroying a redirected window with backing store4Mo{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)
!J!9YaAdam Jackson <ajax@redhat.com> - 1.20.4-11_- Fix a crash when moving an animated cursor between screens
- Be case-insentive when matching extension names to enable or disablegXaqAdam Jackson <ajax@redhat.com> - 1.20.4-10^@- Set fallback DRI2 driver names for Intel and AMD+WoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334Vo{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\Ua[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)ToOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dSo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)
2M4_o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\^a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)]oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)d\o]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)Z[mKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11ZmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixes
iPVieoOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)ddo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZcmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11bmMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-12_@- CVE fixes for: CVE-2020-14345 (#1872389), CVE-2020-14346 (#1872393),
  CVE-2020-14361 (#1872400), CVE-2020-14362 (#1872407)
- Temporarily revert fixes from 1.20.4-11 build for delivery of CVE fixesao1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+`oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033

er+V:eD
24dee6e8be939b14900bb668c0f5908df2590d8188545bd59c83122ddcd7a785D
0848e56ffcc658be84b8dc962cfae7e6e963b28421212d04c814be04b66154b4D
6abc3f24e051fa25828e517e1a6999a1a3612b5f97a13d8e99553cc31d24663dD~
0930a501a892602ab5d8c48730193fa5230e46803b8b20533482a6322014c898D}
2c1c518f7da653e7d7a53995c92f4baa7bf0f6fd4c51c0856182ee1c7e6d613cD|
f53aa25a58a78740dad5a5777ccec426834c3455b4a323c3cd264c877f39e567D{
a4e3cfe2ec39289ce4330038a8f3fa801449727c3b6173cf5ceabec99f36bf59Dz
145b9d5084c2fedb67f97a86a7a34cb159ed3eb46792eea9e063b1c632fde672Dy
77b4a6262e01a546f91e92c40dd8c101260465ac9a037ad0ea84bea77bf29201Dx
61d16044997c74e9f5ddf1cdc61b0e3f9e8d5e4575baf1378072e0338439530bDw
19b1bcc147b66f7afbe531c0ce8c1100de0382c508ad062a80e80ce061782f2aDv
4a8694a364e768699fa73bb47949f8b4f66c047ef8c5ddc23bde156d7e70f7d5Du
6f027d48513d5431e3da6ea4365a8f77b28f4a40c5d6c2552a5ab6817c5a1c2f
878nkygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tjyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)io1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+hoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334go{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\fa[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)
X:UXro1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+qoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334po{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\oa[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)noOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dmo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)ZlmKMichel Dänzer <mdaenzer@redhat.com> - 1.20.4-13_- Re-apply fixes from 1.20.4-11
#)<#4yo{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\xa[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)woOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)dvo]Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-14_
- CVE fix for: CVE-2020-14347 (#1862319)huy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)ntygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tsyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
~PQ~co[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h~y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)n}ygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)t|yqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797){o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+zoiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033
%{b%tyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)oOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-15_
- CVE fix for: CVE-2020-25712 (#1904937), CVE-2020-14360 (#1904934)
\"%\+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#21090334o{Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-17a- CVE fix for: CVE-2021-4008 (#2030161), CVE-2021-4009 (#2030171),
  CVE-2021-4010 (#2030176), CVE-2021-4011 (#2030180)\
a[Adam Jackson <ajax@redhat.com> - 1.20.4-16` @- CVE fix for: CVE-2021-3472 (#1944956)	o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424co[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)
ls.o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424co[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)nygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)
o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770
t#stnygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)o1Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-19ck@- CVE fix for: CVE-2022-3550, CVE-2022-3551
  Resolves: rhbz#2140765, rhbz#2140770+oiOlivier Fourdan <ofourdan@redhat.com> - 1.20.4-18bޅ- CVE fix for: CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070
  Resolves: rhbz#2109031, rhbz#2109033XoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428
-XoCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424co[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)hy[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)
''nygPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-21cR@- Follow-up fix for CVE-2022-46340 (#2151775)tyqPeter Hutterer <peter.hutterer@redhat.com> - 1.20.4-20c#@- CVE fix for: CVE-2022-4283 (#2151800), CVE-2022-46340 (#2151775),
  CVE-2022-46341 (#2151780), CVE-2022-46342 (#2151787),
  CVE-2022-46343 (#2151790), CVE-2022-46344 (#2151797)joiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{o	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201
-X#oCJosé Expósito <jexposit@redhat.com> - 1.20.4-25ez@- CVE fix for: CVE-2023-6377, CVE-2023-6478
  Resolves: https://issues.redhat.com/browse/RHEL-18416
  Resolves: https://issues.redhat.com/browse/RHEL-18428"o5José Expósito <jexposit@redhat.com> - 1.20.4-24e9@- CVE fix for: CVE-2023-5367
  Resolves: https://issues.redhat.com/browse/RHEL-13424c!o[Olivier Fourdan <ofourdan@redhat.com> - 1.20.4-23d$(@- CVE fix for: CVE-2023-1393 (#2180290)h y[Peter Hutterer <peter.hutterer@redhat.com> - 1.20.4-22c@- CVE fix for: CVE-2023-0494 (#2166513)
j%oiJosé Expósito <jexposit@redhat.com> - 1.20.4-27e- Fix use after free related to CVE-2024-21886{$o	José Expósito <jexposit@redhat.com> - 1.20.4-26eo- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886,
  CVE-2024-0408 and CVE-2024-0409
  Resolves: https://issues.redhat.com/browse/RHEL-21205
  Resolves: https://issues.redhat.com/browse/RHEL-20578
  Resolves: https://issues.redhat.com/browse/RHEL-20426
  Resolves: https://issues.redhat.com/browse/RHEL-20437
  Resolves: https://issues.redhat.com/browse/RHEL-21192
  Resolves: https://issues.redhat.com/browse/RHEL-21201
5{k5*Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.1-5Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild)Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.1-4P@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild(Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.1-3On@- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuildq'owJosé Expósito <jexposit@redhat.com> - 1.20.4-29f@- Fix regression caused by the fix for CVE-2024-31083&oJosé Expósito <jexposit@redhat.com> - 1.20.4-28f@- CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and
  CVE-2024-31083
  Resolves: https://issues.redhat.com/browse/RHEL-31003
  Resolves: https://issues.redhat.com/browse/RHEL-30989
  Resolves: https://issues.redhat.com/browse/RHEL-30973
- Add util-linux as a dependency of Xvfb
- Fix compilation error on i686
|}no|2Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.1-4P@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildT1o=Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-12_- Rebuild with OpenJDK 70oMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-11_S- Fix remote code execution vulnerability
- Resolves: CVE-2020-26217u/oMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-10R- Apply upstream security patch
- Resolves: CVE-2013-7285L.]?Daniel Mach <dmach@redhat.com> - 1.3.1-9Rk- Mass rebuild 2013-12-27T-m?Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-8RB@- Disable support for XOMc,m]Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-7Q- Update to current packaging guidelines+mMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-6Qz- Rebuild to regenerate API documentation
- Resolves: CVE-2013-1571
|e{#Z|T:o=Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-12_- Rebuild with OpenJDK 79oMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-11_S- Fix remote code execution vulnerability
- Resolves: CVE-2020-26217u8oMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-10R- Apply upstream security patch
- Resolves: CVE-2013-7285L7]?Daniel Mach <dmach@redhat.com> - 1.3.1-9Rk- Mass rebuild 2013-12-27T6m?Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-8RB@- Disable support for XOMc5m]Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-7Q- Update to current packaging guidelines4mMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-6Qz- Rebuild to regenerate API documentation
- Resolves: CVE-2013-15713Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.1-5Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
lw5luAoMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-10R- Apply upstream security patch
- Resolves: CVE-2013-7285L@]?Daniel Mach <dmach@redhat.com> - 1.3.1-9Rk- Mass rebuild 2013-12-27T?m?Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-8RB@- Disable support for XOMc>m]Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-7Q- Update to current packaging guidelines=mMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-6Qz- Rebuild to regenerate API documentation
- Resolves: CVE-2013-1571<Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.1-5Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuildi;gmMarian Koncek <mkoncek@redhat.com> - 1.3.1-13`u- Fix remote code execution vulnerability
- Resolves: CVE-2021-21344
- Resolves: CVE-2021-21345
- Resolves: CVE-2021-21346
- Resolves: CVE-2021-21347
- Resolves: CVE-2021-21350
}z"4}GFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.1-4P@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_RebuildFFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.1-3On@- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild}EgMarian Koncek <mkoncek@redhat.com> - 1.3.1-14`[- Fix remote code execution vulnerability
- Resolves: CVE-2021-29505iDgmMarian Koncek <mkoncek@redhat.com> - 1.3.1-13`u- Fix remote code execution vulnerability
- Resolves: CVE-2021-21344
- Resolves: CVE-2021-21345
- Resolves: CVE-2021-21346
- Resolves: CVE-2021-21347
- Resolves: CVE-2021-21350TCo=Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-12_- Rebuild with OpenJDK 7BoMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-11_S- Fix remote code execution vulnerability
- Resolves: CVE-2020-26217
|e{#Z|TOo=Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-12_- Rebuild with OpenJDK 7NoMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-11_S- Fix remote code execution vulnerability
- Resolves: CVE-2020-26217uMoMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-10R- Apply upstream security patch
- Resolves: CVE-2013-7285LL]?Daniel Mach <dmach@redhat.com> - 1.3.1-9Rk- Mass rebuild 2013-12-27TKm?Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-8RB@- Disable support for XOMcJm]Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-7Q- Update to current packaging guidelinesImMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-6Qz- Rebuild to regenerate API documentation
- Resolves: CVE-2013-1571HFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.1-5Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
9eG89WoMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-11_S- Fix remote code execution vulnerability
- Resolves: CVE-2020-26217uVoMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-10R- Apply upstream security patch
- Resolves: CVE-2013-7285LU]?Daniel Mach <dmach@redhat.com> - 1.3.1-9Rk- Mass rebuild 2013-12-27TTm?Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-8RB@- Disable support for XOMcSm]Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-7Q- Update to current packaging guidelinesRmMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-6Qz- Rebuild to regenerate API documentation
- Resolves: CVE-2013-1571QFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.1-5Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildPFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.1-4P@- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
5L^]?Daniel Mach <dmach@redhat.com> - 1.3.1-9Rk- Mass rebuild 2013-12-27T]m?Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-8RB@- Disable support for XOMc\m]Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-7Q- Update to current packaging guidelines[mMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-6Qz- Rebuild to regenerate API documentation
- Resolves: CVE-2013-1571ZFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.1-5Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildiYgmMarian Koncek <mkoncek@redhat.com> - 1.3.1-13`u- Fix remote code execution vulnerability
- Resolves: CVE-2021-21344
- Resolves: CVE-2021-21345
- Resolves: CVE-2021-21346
- Resolves: CVE-2021-21347
- Resolves: CVE-2021-21350TXo=Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-12_- Rebuild with OpenJDK 7
:Fee+Miroslav Lichvar <mlichvar@redhat.com> 289-1Q- update to 289Fde+Miroslav Lichvar <mlichvar@redhat.com> 288-1P@- update to 288}cgMarian Koncek <mkoncek@redhat.com> - 1.3.1-14`[- Fix remote code execution vulnerability
- Resolves: CVE-2021-29505ibgmMarian Koncek <mkoncek@redhat.com> - 1.3.1-13`u- Fix remote code execution vulnerability
- Resolves: CVE-2021-21344
- Resolves: CVE-2021-21345
- Resolves: CVE-2021-21346
- Resolves: CVE-2021-21347
- Resolves: CVE-2021-21350Tao=Mikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-12_- Rebuild with OpenJDK 7`oMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-11_S- Fix remote code execution vulnerability
- Resolves: CVE-2020-26217u_oMikolaj Izdebski <mizdebsk@redhat.com> - 1.3.1-10R- Apply upstream security patch
- Resolves: CVE-2013-7285

er+V:eD
79b31e2851cc21f81604266da5f6560bf26df1d0f6c6015f28b51d19463bbdb1D

d9429a549658c0c14acf519f07d00e2c522ae9defd82f2d4466baf627173297aD
d351a336b4df1a8014e1c30b9d39d008bb492694a7dd3a345cdad5b169a37692D
b5e1f251fa985a796daa60023e6589a2ba38ccb958e5fb09215538f676a01863D

c16b5a1bf49c89cb3789f39c8dd6db6309830df4d3274cfa0ea3d38e38f0ebb8D	
4b698de5fd7e0a64306106f3018e9d00dedc1f7a46d354339f012c97d004bd0cD
86b3087af0b5a421efcfc192824973fcedcaee28a0e78bdb52d9101ffee96ebcD
8c62263350421e7c3081b4a531f8e15ef5bfb5e410a34687ca4a799ff23362efD
4ddc7a2a317dc75228322785e2290c04acd3263ac771458097e5f402bb10508aD
2cb993f044a866a8d47b449c45f92f04540a139e5b827a0b845f6c9600d83af6D
aa0a9aa8e1958293d8bb429a513a459f4abafa838c9e217974640cfcd36c5e3aD
775f41c9398da339ae50faf7692eb4b9de783c58e046c6c24f659c666b25eb48D
1e384389a357083eef224ca9752df57e665959920ecfd6720d9f58d63924b0b8
	b: n#Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 5.1.2-3alphaQ#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildzmcTomas Korbar <tkorbar@redhat.com> - 295-3.1`*b@- Backport security fix for CVE-2021-27135
- Resolves: rhbz#1927564JlY?Daniel Mach <dmach@redhat.com> - 295-3RU- Mass rebuild 2014-01-24JkY?Daniel Mach <dmach@redhat.com> - 295-2Rk- Mass rebuild 2013-12-27Fje+Miroslav Lichvar <mlichvar@redhat.com> 295-1QL- update to 295Fie+Miroslav Lichvar <mlichvar@redhat.com> 293-1Q- update to 293Fhe+Miroslav Lichvar <mlichvar@redhat.com> 292-1Q~`- update to 292Fge+Miroslav Lichvar <mlichvar@redhat.com> 291-1Q/F- update to 291fy;Parag Nemade <paragn AT fedoraproject DOT org> - 289-2Q- Remove vendor tag from desktop file as per https://fedorahosted.org/fesco/ticket/1077
ZPZovg{Pavel Raiskup <praiskup@redhat.com> - 5.2.2-1Vx- rebase to stable release (rhbz#1190713, rhbz#1160193)us
Pavel Raiskup <praiskup@redhat.com> - 5.1.2-12alphaU- xzgrep: return 0 when at least one file matches (rhbz#1109123)qtquPavel Raiskup <praiskup@redhat.com> - 5.1.2-9alphaS-- better check the version of less binary (#1082639)Qsg?Daniel Mach <dmach@redhat.com> - 5.1.2-8alphaRU- Mass rebuild 2014-01-24irqePavel Raiskup <praiskup@redhat.com> - 5.1.2-7alphaR- build with -O3 on ppc64 (private #1051078)Qqg?Daniel Mach <dmach@redhat.com> - 5.1.2-6alphaRk- Mass rebuild 2013-12-271pqsPavel Raiskup <praiskup@redhat.com> - 5.1.2-5alphaQd- fix manual page inconsistencies with help output (private #948533)
- enable/fix the 'xzgrep -h' (private #850898)joioKarsten Hopp <karsten@redhat.com> 5.1.2-4alphaQ&@- add support for ppc64p7 arch (Power7 optimized)
HHq~quPavel Raiskup <praiskup@redhat.com> - 5.1.2-9alphaS-- better check the version of less binary (#1082639)Q}g?Daniel Mach <dmach@redhat.com> - 5.1.2-8alphaRU- Mass rebuild 2014-01-24i|qePavel Raiskup <praiskup@redhat.com> - 5.1.2-7alphaR- build with -O3 on ppc64 (private #1051078)Q{g?Daniel Mach <dmach@redhat.com> - 5.1.2-6alphaRk- Mass rebuild 2013-12-271zqsPavel Raiskup <praiskup@redhat.com> - 5.1.2-5alphaQd- fix manual page inconsistencies with help output (private #948533)
- enable/fix the 'xzgrep -h' (private #850898)jyioKarsten Hopp <karsten@redhat.com> 5.1.2-4alphaQ&@- add support for ppc64p7 arch (Power7 optimized)x#Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 5.1.2-3alphaQ#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuilddwegMatej Mužila <mmuzila@redhat.com> - 5.2.2-2b=- Fix CVE-2022-1271
  Resolves: CVE-2022-1271XJx '.5<CJQX_fmt{qjc\UNG@92+$JxJpJhJ`JWJOJGJ?J7J/J'JJJJJ~JvJnJfJ^JVJNJFJ<J4J,J%JJJ
JJ~JS(JT/JU5JV<JWCJXIJYPJZWJ[]J\cJ^iJ_oJ`uJa{JbJcJd	Je
JfJgJhJiJj$Jk+Jl1Jm7Jn>JoEJpLJqRJrYJs_JteJvkJwrJxyJyJzJ{J|J}J~JJ#J%J*J2J:JAJGJOJWJ^JeJnJv
}
iqePavel Raiskup <praiskup@redhat.com> - 5.1.2-7alphaR- build with -O3 on ppc64 (private #1051078)Qg?Daniel Mach <dmach@redhat.com> - 5.1.2-6alphaRk- Mass rebuild 2013-12-271qsPavel Raiskup <praiskup@redhat.com> - 5.1.2-5alphaQd- fix manual page inconsistencies with help output (private #948533)
- enable/fix the 'xzgrep -h' (private #850898)jioKarsten Hopp <karsten@redhat.com> 5.1.2-4alphaQ&@- add support for ppc64p7 arch (Power7 optimized)#Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 5.1.2-3alphaQ#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuilddegMatej Mužila <mmuzila@redhat.com> - 5.2.2-2b=- Fix CVE-2022-1271
  Resolves: CVE-2022-1271og{Pavel Raiskup <praiskup@redhat.com> - 5.2.2-1Vx- rebase to stable release (rhbz#1190713, rhbz#1160193)s
Pavel Raiskup <praiskup@redhat.com> - 5.1.2-12alphaU- xzgrep: return 0 when at least one file matches (rhbz#1109123)
6@8j
ioKarsten Hopp <karsten@redhat.com> 5.1.2-4alphaQ&@- add support for ppc64p7 arch (Power7 optimized)#Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 5.1.2-3alphaQ#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuilddegMatej Mužila <mmuzila@redhat.com> - 5.2.2-2b=- Fix CVE-2022-1271
  Resolves: CVE-2022-1271o
g{Pavel Raiskup <praiskup@redhat.com> - 5.2.2-1Vx- rebase to stable release (rhbz#1190713, rhbz#1160193)	s
Pavel Raiskup <praiskup@redhat.com> - 5.1.2-12alphaU- xzgrep: return 0 when at least one file matches (rhbz#1109123)qquPavel Raiskup <praiskup@redhat.com> - 5.1.2-9alphaS-- better check the version of less binary (#1082639)Qg?Daniel Mach <dmach@redhat.com> - 5.1.2-8alphaRU- Mass rebuild 2014-01-24
`J3;`degMatej Mužila <mmuzila@redhat.com> - 5.2.2-2b=- Fix CVE-2022-1271
  Resolves: CVE-2022-1271og{Pavel Raiskup <praiskup@redhat.com> - 5.2.2-1Vx- rebase to stable release (rhbz#1190713, rhbz#1160193)s
Pavel Raiskup <praiskup@redhat.com> - 5.1.2-12alphaU- xzgrep: return 0 when at least one file matches (rhbz#1109123)qquPavel Raiskup <praiskup@redhat.com> - 5.1.2-9alphaS-- better check the version of less binary (#1082639)Qg?Daniel Mach <dmach@redhat.com> - 5.1.2-8alphaRU- Mass rebuild 2014-01-24iqePavel Raiskup <praiskup@redhat.com> - 5.1.2-7alphaR- build with -O3 on ppc64 (private #1051078)Qg?Daniel Mach <dmach@redhat.com> - 5.1.2-6alphaRk- Mass rebuild 2013-12-271qsPavel Raiskup <praiskup@redhat.com> - 5.1.2-5alphaQd- fix manual page inconsistencies with help output (private #948533)
- enable/fix the 'xzgrep -h' (private #850898)
-`<z%-s
Pavel Raiskup <praiskup@redhat.com> - 5.1.2-12alphaU- xzgrep: return 0 when at least one file matches (rhbz#1109123)qquPavel Raiskup <praiskup@redhat.com> - 5.1.2-9alphaS-- better check the version of less binary (#1082639)Qg?Daniel Mach <dmach@redhat.com> - 5.1.2-8alphaRU- Mass rebuild 2014-01-24iqePavel Raiskup <praiskup@redhat.com> - 5.1.2-7alphaR- build with -O3 on ppc64 (private #1051078)Qg?Daniel Mach <dmach@redhat.com> - 5.1.2-6alphaRk- Mass rebuild 2013-12-271qsPavel Raiskup <praiskup@redhat.com> - 5.1.2-5alphaQd- fix manual page inconsistencies with help output (private #948533)
- enable/fix the 'xzgrep -h' (private #850898)jioKarsten Hopp <karsten@redhat.com> 5.1.2-4alphaQ&@- add support for ppc64p7 arch (Power7 optimized)#Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 5.1.2-3alphaQ#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
J%aJQ%g?Daniel Mach <dmach@redhat.com> - 5.1.2-8alphaRU- Mass rebuild 2014-01-24i$qePavel Raiskup <praiskup@redhat.com> - 5.1.2-7alphaR- build with -O3 on ppc64 (private #1051078)Q#g?Daniel Mach <dmach@redhat.com> - 5.1.2-6alphaRk- Mass rebuild 2013-12-271"qsPavel Raiskup <praiskup@redhat.com> - 5.1.2-5alphaQd- fix manual page inconsistencies with help output (private #948533)
- enable/fix the 'xzgrep -h' (private #850898)j!ioKarsten Hopp <karsten@redhat.com> 5.1.2-4alphaQ&@- add support for ppc64p7 arch (Power7 optimized) #Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 5.1.2-3alphaQ#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuilddegMatej Mužila <mmuzila@redhat.com> - 5.2.2-2b=- Fix CVE-2022-1271
  Resolves: CVE-2022-1271og{Pavel Raiskup <praiskup@redhat.com> - 5.2.2-1Vx- rebase to stable release (rhbz#1190713, rhbz#1160193)
i-i1,qs	Pavel Raiskup <praiskup@redhat.com> - 5.1.2-5alphaQd- fix manual page inconsistencies with help output (private #948533)
- enable/fix the 'xzgrep -h' (private #850898)j+io	Karsten Hopp <karsten@redhat.com> 5.1.2-4alphaQ&@- add support for ppc64p7 arch (Power7 optimized)*#	Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 5.1.2-3alphaQ#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuildd)egMatej Mužila <mmuzila@redhat.com> - 5.2.2-2b=- Fix CVE-2022-1271
  Resolves: CVE-2022-1271o(g{Pavel Raiskup <praiskup@redhat.com> - 5.2.2-1Vx- rebase to stable release (rhbz#1190713, rhbz#1160193)'s
Pavel Raiskup <praiskup@redhat.com> - 5.1.2-12alphaU- xzgrep: return 0 when at least one file matches (rhbz#1109123)q&quPavel Raiskup <praiskup@redhat.com> - 5.1.2-9alphaS-- better check the version of less binary (#1082639)
v>t~v4#
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 5.1.2-3alphaQ#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuildd3eg	Matej Mužila <mmuzila@redhat.com> - 5.2.2-2b=- Fix CVE-2022-1271
  Resolves: CVE-2022-1271o2g{	Pavel Raiskup <praiskup@redhat.com> - 5.2.2-1Vx- rebase to stable release (rhbz#1190713, rhbz#1160193)1s
	Pavel Raiskup <praiskup@redhat.com> - 5.1.2-12alphaU- xzgrep: return 0 when at least one file matches (rhbz#1109123)q0qu	Pavel Raiskup <praiskup@redhat.com> - 5.1.2-9alphaS-- better check the version of less binary (#1082639)Q/g?	Daniel Mach <dmach@redhat.com> - 5.1.2-8alphaRU- Mass rebuild 2014-01-24i.qe	Pavel Raiskup <praiskup@redhat.com> - 5.1.2-7alphaR- build with -O3 on ppc64 (private #1051078)Q-g?	Daniel Mach <dmach@redhat.com> - 5.1.2-6alphaRk- Mass rebuild 2013-12-27
ZPZo<g{
Pavel Raiskup <praiskup@redhat.com> - 5.2.2-1Vx- rebase to stable release (rhbz#1190713, rhbz#1160193);s

Pavel Raiskup <praiskup@redhat.com> - 5.1.2-12alphaU- xzgrep: return 0 when at least one file matches (rhbz#1109123)q:qu
Pavel Raiskup <praiskup@redhat.com> - 5.1.2-9alphaS-- better check the version of less binary (#1082639)Q9g?
Daniel Mach <dmach@redhat.com> - 5.1.2-8alphaRU- Mass rebuild 2014-01-24i8qe
Pavel Raiskup <praiskup@redhat.com> - 5.1.2-7alphaR- build with -O3 on ppc64 (private #1051078)Q7g?
Daniel Mach <dmach@redhat.com> - 5.1.2-6alphaRk- Mass rebuild 2013-12-2716qs
Pavel Raiskup <praiskup@redhat.com> - 5.1.2-5alphaQd- fix manual page inconsistencies with help output (private #948533)
- enable/fix the 'xzgrep -h' (private #850898)j5io
Karsten Hopp <karsten@redhat.com> 5.1.2-4alphaQ&@- add support for ppc64p7 arch (Power7 optimized)

3Jbd3`Fi[Richard Hughes <rhughes@redhat.com> - 3.28.1-1[)- Update to 3.28.1
- Resolves: #1569809^Ee[Kalev Lember <klember@redhat.com> - 3.22.0-1W- Update to 3.22.0
- Resolves: #1387068gDiiMatthias Clasen <mclasen@redhat.com> - 3.8.0-5Uo- Fix non-expanding lists
  Resolves: #1251137LC]?Daniel Mach <dmach@redhat.com> - 3.8.0-4RU- Mass rebuild 2014-01-24LB]?Daniel Mach <dmach@redhat.com> - 3.8.0-3Rk- Mass rebuild 2013-12-27ZAiOKalev Lember <kalevlember@gmail.com> - 3.8.0-2QQ- Minor spec file updates for 3.8I@g/Richard Hughes <rhughes@redhat.com> - 3.8.0-1QQ- Update to 3.8.0?Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.7.2-2Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildJ>i/Richard Hughes <hughsient@gmail.com> - 3.7.2-1P[- Update to 3.7.2d=eg
Matej Mužila <mmuzila@redhat.com> - 5.2.2-2b=- Fix CVE-2022-1271
  Resolves: CVE-2022-1271
u3iuN_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UMkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500uL_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archMK_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yJk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archMI_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27HFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.7-10Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild_G]eDavid King <dking@redhat.com> - 3.28.1-2b{@- Fix message dialog label layout (#2053529)
l%6luV_

jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archMU_?
Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yTk	
Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archMS_?
Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27R
Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.7-10Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildQcOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZPiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyO_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441
1[M^_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24y]k	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archM\_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27[c
Ondrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZZiO
Pavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyY_
jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441X_O
jchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UWkC
Peter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500
.3Mf_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27RegAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032dcOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZciOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyb_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441a_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330U`kCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u__
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le arch

er+V:eD
d7742b51255b8d94dbac98ddda85c44af8fd3e086a9e97e34eaa931c19309558D
b35155b1ceb01b0f1587514d282fbdc9fe8d837afdaf5f41c36043a5e5a43360D
1cd66f531b9b7e67edd8521e39973708061ed0dc06e81bb64cc48a56a3115cf5D
a3d1deaf9e376473910f9b57f2f2af63409cd1694461f15fa3888697f35dae99D
672e68e45c4b7fe8fc13c9120dc86f63a7501b0671c31efd1bc7fca754bcce6fD
b29312cc96f964f3acb2be38bc13b4893aeb1766954bbb95a9d214498a2e4b48D
052bc59d48a243df22b031df97865c1dc873c28379e0ef92b51f07311401764bD
0a22fdb0f60d3be3fd66877b980e41dfe9e76361231ab306f3eb3a98c2ef3139D
a9e9be6b6ce553ec52656aeeb84a56fd9cc324c060fd83aeddc2a4881bd164ecD
612794ffa4ef73358d2f49bc1d041762afc275c2285eaf7eaee6f5e3c360d415D
2bee86d12902723756eafa82ba6cc322136c4a67a78e0104ac988e14eb7fb5a1D
05ce97f826afdba77bdbabde3175ee402acbf40771f2af0a35ada58f14c7ecbcD
4286ac1c3d65716ecbf4c7210b1ecc94f1f602cc91db2bab294138fe254b2621
e2`HencOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZmiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyl_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441k_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UjkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500ui_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archMh_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24ygk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 arch
-c
oZviOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyu_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441t_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UskCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500ur_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archMq_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24ypk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archRogAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032
C{%~7C~_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330U}kCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u|_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archM{_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yzk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 arch"yk[Lukas Javorsky <ljavorsk@redhat.com> - 1.2.7-21cױ@- Fix heap-based buffer over-read or buffer overflow in inflate in inflate.c
- Resolves: CVE-2022-37434RxgAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032wcOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)
9%J9yk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archM_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.7-10Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild"k[Lukas Javorsky <ljavorsk@redhat.com> - 1.2.7-21cױ@- Fix heap-based buffer over-read or buffer overflow in inflate in inflate.c
- Resolves: CVE-2022-37434RgAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROy_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441
F6BgFFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.7-10Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROy_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441
_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330U	kCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archM_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24
2htZiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROy_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archM_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archM_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27
r{*\ry_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archM_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archM_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)
	;v/;'_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330U&kCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u%_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archM$_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24y#k	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archM"_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27R!gAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032 cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELRO
%J|U/kCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u._
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archM-_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24y,k	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archR+gAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032*cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)Z)iOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROy(_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441
:e:M7_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24y6k	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 arch"5k[Lukas Javorsky <ljavorsk@redhat.com> - 1.2.7-21cױ@- Fix heap-based buffer over-read or buffer overflow in inflate in inflate.c
- Resolves: CVE-2022-37434R4gAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-250323cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)Z2iOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROy1_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #13374410_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330
6.36"?k[Lukas Javorsky <ljavorsk@redhat.com> - 1.2.7-21cױ@- Fix heap-based buffer over-read or buffer overflow in inflate in inflate.c
- Resolves: CVE-2022-37434R>gAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032=cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)Z<iOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROy;_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441:_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330U9kCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500u8_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le arch
[dEs[yG_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441F_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UEkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500uD_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archMC_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yBk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archMA_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27@Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.7-10Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
0bUOkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500uN_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archMM_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yLk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archMK_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27JFedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.7-10Q#@- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_RebuildIcOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZHiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELRO
me7muW_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archMV_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yUk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archMT_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27ScOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZRiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyQ_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441P_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330
	71V7M`_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24y_k	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archM^_?Daniel Mach <dmach@redhat.com> - 1.2.7-11Rk- Mass rebuild 2013-12-27R]gAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032\cOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)Z[iOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyZ_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441Y_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UXkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500
`.3`yhk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 archRggAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032fcOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZeiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyd_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441c_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UbkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500ua_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le arch
rrD
7d3bfa9dc6bf0bfa9484b2f3613c4816e08534e247194ef466587ccf8938e69eD
f88c4bed9b2d9000b18a7505809eaf38777fe41fd6aeed9b928493c204e4783f
6BgRpgAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032ocOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)ZniOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROym_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441l_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UkkCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500uj_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archMi_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24
CYCZxiOPavel Raiskup <praiskup@redhat.com> - 1.2.7-18[CN@- Link with -z now for full RELROyw_jchaloup <jchaloup@redhat.com> - 1.2.7-17W=- Fix writing empty files on gzopen()/gzclose()
  resolves: #1337441v_Ojchaloup <jchaloup@redhat.com> - 1.2.7-16W - Fix serious but very rare decompression bug in inftrees.c (upstream patch)
  resolves: #1127330UukCPeter Robinson <pbrobinson@redhat.com> 1.2.7-15UQ@- Rebuild for rhbz #1123500ut_
jchaloup <jchaloup@redhat.com> - 1.2.7-14S/- resolves: #1123500
  recompiled with -O3 flag for ppc64le archMs_?Daniel Mach <dmach@redhat.com> - 1.2.7-13RU- Mass rebuild 2014-01-24yrk	Peter Schiffer <pschiffe@redhat.com> - 1.2.7-12R- resolves: #1051079
  recompiled with -O3 flag for ppc64 arch"qk[Lukas Javorsky <ljavorsk@redhat.com> - 1.2.7-21cױ@- Fix heap-based buffer over-read or buffer overflow in inflate in inflate.c
- Resolves: CVE-2022-37434
~{%~"{k[Lukas Javorsky <ljavorsk@redhat.com> - 1.2.7-21cױ@- Fix heap-based buffer over-read or buffer overflow in inflate in inflate.c
- Resolves: CVE-2022-37434RzgAMatej Mužila <mmuzila@redhat.com> - 1.2.7-20bUi- Resolves: CVE-2018-25032ycOndrej Dubaj <odubaj@redhat.com> - 1.2.7-19_X- fixed accessing password-protected .zip files via libminizip (#1875700)LLLiL$\KKuHKIX2J;J


"',16;AGMSY_ekqw}
%+17=CIOU[agmsy	!'-39?EKQW]ciou{												

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOP	Q	R	S	T	U	V	W	X	Y	Z
[
\
]
^
_
`
a
b
c
defghijklmnopqrstuvwx
y
z
{
|
}
~


p!(/6=DKRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{

p!(/6=DKRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{	

 !"#$%&'()*+,-./0123456 7 8 9 : ; < = > ? @!A!B!C!D!E!F!G!H!I!J"K"L"M"N"O"P"Q"R"S"T#U#V#W#X#Y#Z#[#\#]#^$_$`$a$b
p!(/6=DKRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{$d$e$f$g$h%i%j%k%l%m%n%o%p%q%r&s&t&u&v&w&x&y&z&{&|'}'~''''''''(((((((((())))))))))**********++++++++++,,,,,,,,,,----------..........///////
p!(/6=DKRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{//000000000011111111112222222222333333333344444444445	5
555
5555566666666667777 7!7"7#7$7%7&8'8(8)8*8+8,8-8.8/809192939495969798999::;:<:=:>:?:@:A:B:C:D
p!(/6=DKRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{;F;G;H;I;J;K;L;M;N<O<P<Q<R<S<T<U<V<W<X=Y=Z=[=\=]=^=_=`=a=b>c>d>e>f>g>h>i>j>k>l?m?n?o?p?q?r?s?t?u?v@w@x@y@z@{@|@}@~@@AAAAAAAAAABBBBBBBBBBCCCCCCCCCCDDDDDDDDDDEEEEEEEEEEFFF
p!(/6=DKRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{FFFFFFGGGGGGGGGGHHHHHHHHHHIIIIIIIIIIJJJJJJJJJJKKKKKKKKKKLLLLLLLLLLMMMMMMMMMMNNNNNNN	N
NNO
OOOOOOOOOPPPPPPPPPP Q!Q"Q#Q$Q%Q&
p!(/6=DKRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{Q(Q)Q*R+R,R-R.R/R0R1R2R3R4S5S6S7S8S9S:S;S<S=S>T?T@TATBTCTDTETFTGTHUIUJUKULUMUNUOUPUQURVSVTVUVVVWVXVYVZV[V\W]W^W_W`WaWbWcWdWeWfXgXhXiXjXkXlXmXnXoXpYqYrYsYtYuYvYwYxYyYzZ{Z|Z}Z~ZZZZZZ[[[[[[[[[[\\\\\\\\\
p!(/6=DKRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{]]]]]]]]]]^^^^^^^^^^__________``````````aaaaaaaaaabbbbbbbbbbccccccccccddddddddddeeeeeeeeeeffffffffffgggggggggghh
p!(/6=DKRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{h
hhh
hhhiiiiiiiiiijjjjjj j!j"j#j$k%k&k'k(k)k*k+k,k-k.l/l0l1l2l3l4l5l6l7l8m9m:m;m<m=m>m?m@mAmBnCnDnEnFnGnHnInJnKnLoMoNoOoPoQoRoSoToUoVpWpXpYpZp[p\p]p^p_p`qaqbqcqdqeqfqgqhqiqjrkrlrmrnrorprqrrrsrtsusvswsxsy
p!(/6=DKRY`gnu|$+29@GNU\cjqx '.5<CJQX_fmt{s{s|s}s~ttttttttttuuuuuuuuuuvvvvvvvvvvwwwwwwwwwwxxxxxxxxxxyyyyyyyyyyzzzzzzzzzz{{{{{{{{{{||||||||||}}}}}}}}}}~~~~~~~~
f!(08@HPX`hpx (08@HPX`hpx (08@HPX`hpx~	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQ
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	


e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNO
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	


e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx												
			
																			 	!	"	#	$	%	&	'	(	)	*	+	,	-	.	/	0	1	2	3	4	5	6	7	8	9	:	;	<	=	>	?	@	A	B	C	D	E	F	G	H	I	J	K	L	M
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	O	P	Q	R	S	T	U	V	W	X	Y	Z	[	\	]	^	_	`	a	b	c	d	e	f	g	h	i	j	k	l	m	n	o	p	q	r	s	t	u	v	w	x	y	z	{	|	}	~																																																					
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx																																																																											









	


















e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx





 
!
"
#
$
%
&
'
(
)
*
+
,
-
.
/
0
1
2
3
4
5
6
7
8
9
:
;
<
=
>
?
@
A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P	
Q	
R	
S	
T	
U	
V	
W	
X	
Y	
Z

[

\

]

^

_

`

a

b

c

d
e
f
g
h
i
j
k
l
m
n
o
p
q
r
s
t
u
v
w
x
y
z
{
|
}
~

e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx





































































































e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
























	

 !"#$%&'()*+,-./0123456 7 8 9 : ; < = > ? @!A!B!C!D!E!F!G!H!I!J"K
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx"M"N"O"P"Q"R"S"T#U#V#W#X#Y#Z#[#\#]#^$_$`$a$b$c$d$e$f$g$h%i%j%k%l%m%n%o%p%q%r&s&t&u&v&w&x&y&z&{&|'}'~''''''''(((((((((())))))))))**********++++++++++,,,
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx,,,,,,----------..........//////////000000000011111111112222222222333333333344444444445	5
555
5555566666
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx66667777 7!7"7#7$7%7&8'8(8)8*8+8,8-8.8/809192939495969798999::;:<:=:>:?:@:A:B:C:D;E;F;G;H;I;J;K;L;M;N<O<P<Q<R<S<T<U<V<W<X=Y=Z=[=\=]=^=_=`=a=b>c>d>e>f>g>h>i>j>k>l?m?n?o?p?q?r?s?t?u?v@w@x@y@z@{@|@}
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx@@AAAAAAAAAABBBBBBBBBBCCCCCCCCCCDDDDDDDDDDEEEEEEEEEEFFFFFFFFFFGGGGGGGGGGHHHHHHHHHHIIIIIIIIIIJJJJJJJJJ
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxKKKKKKKKKKLLLLLLLLLLMMMMMMMM
M
M
N
N
N
N
N
N
N
	N
N
N
O

O
O
O
O
O
O
O
O
O
P
P
P
P
P
P
P
P
P
P
 Q
!Q
"Q
#Q
$Q
%Q
&Q
'Q
(Q
)Q
*R
+R
,R
-R
.R
/R
0R
1R
2R
3R
4S
5S
6S
7S
8S
9S
:S
;S
<S
=S
>T
?T
@T
AT
BT
CT
DT
ET
FT
GT
HU
I
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxU
KU
LU
MU
NU
OU
PU
QU
RV
SV
TV
UV
VV
WV
XV
YV
ZV
[V
\W
]W
^W
_W
`W
aW
bW
cW
dW
eW
fX
gX
hX
iX
jX
kX
lX
mX
nX
oX
pY
qY
rY
sY
tY
uY
vY
wY
xY
yY
zZ
{Z
|Z
}Z
~Z
Z
Z
Z
Z
Z
[
[
[
[
[
[
[
[
[
[
\
\
\
\
\
\
\
\
\
\
]
]
]
]
]
]
]
]
]
]
^
^
^
^
^
^
^
^
^
^
_
_
_
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx_
_
_
_
_
_
`
`
`
`
`
`
`
`
`
`
a
a
a
a
a
a
a
a
a
a
b
b
b
b
b
b
b
b
b
b
c
c
c
c
c
c
c
c
c
c
d
d
d
d
d
d
d
d
d
d
e
e
e
e
e
e
e
e
e
e
f
f
f
f
f
f
f
f
f
f
g
g
g
ggggggghhh	h
hhh
hhhiiiii
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxiiiijjjjjj j!j"j#j$k%k&k'k(k)k*k+k,k-k.l/l0l1l2l3l4l5l6l7l8m9m:m;m<m=m>m?m@mAmBnCnDnEnFnGnHnInJnKnLoMoNoOoPoQoRoSoToUoVpWpXpYpZp[p\p]p^p_p`qaqbqcqdqeqfqgqhqiqjrkrlrmrnrorprqrrrsrtsusvswsxsyszs{
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxs}s~ttttttttttuuuuuuuuuuvvvvvvvvvvwwwwwwwwwwxxxxxxxxxxyyyyyyyyyyzzzzzzzzzz{{{{{{{{{{||||||||||}}}}}}}}}
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx~~~~~~~~~~	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFG
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	


e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxy
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDE
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	


e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvw
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxyz{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	

 !"#$%&'()*+,-./0123456789:;<=>?@ABC
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	


e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOP	Q	R	S	T	U	V	W	X	Y	Z
[
\
]
^
_
`
a
b
c
defghijklmnopqrstu
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxwx
y
z
{
|
}
~




e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	

 !"#$%&'()*+,-./0123456 7 8 9 : ; < = > ? @!A
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx!C!D!E!F!G!H!I!J"K"L"M"N"O"P"Q"R"S"T#U#V#W#X#Y#Z#[#\#]#^$_$`$a$b$c$d$e$f$g$h%i%j%k%l%m%n%o%p%q%r&s&t&u&v&w&x&y&z&{&|'}'~''''''''(((((((((())))))))))**********+++
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx++++++,,,,,,,,,,----------..........//////////000000000011111111112222222222333333333344444444445	5
555
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx555566666666667777 7!7"7#7$7%7&8'8(8)8*8+8,8-8.8/809192939495969798999::;:<:=:>:?:@:A:B:C:D;E;F;G;H;I;J;K;L;M;N<O<P<Q<R<S<T<U<V<W<X=Y=Z=[=\=]=^=_=`=a=b>c>d>e>f>g>h>i>j>k>l?m?n?o?p?q?r?s
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx?u?v@w@x@y@z@{@|@}@~@@AAAAAAAAAABBBBBBBBBBCCCCCCCCCCDDDDDDDDDDEEEEEEEEEEFFFFFFFFFFGGGGGGGGGGHHHHHHHHHHIIIIIIIII
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxJJJJJJJJJJKKKKKKKKKKLLLLLLLLLLMMMMMMMMMMNNNNNNN	N
NNO
OOOOOOOOOPPPPPPPPPP Q!Q"Q#Q$Q%Q&Q'Q(Q)Q*R+R,R-R.R/R0R1R2R3R4S5S6S7S8S9S:S;S<S=S>T?
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxTATBTCTDTETFTGTHUIUJUKULUMUNUOUPUQURVSVTVUVVVWVXVYVZV[V\W]W^W_W`WaWbWcWdWeWfXgXhXiXjXkXlXmXnXoXpYqYrYsYtYuYvYwYxYyYzZ{Z|Z}Z~ZZZZZZ[[[[[[[[[[\\\\\\\\\\]]]]]]]]]]^^^
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx^^^^^^__________``````````aaaaaaaaaabbbbbbbbbbccccccccccddddddddddeeeeeeeeeeffffffffffgggggggggghhh	h
h
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxh
hhhiiiiiiiiiijjjjjj j!j"j#j$k%k&k'k(k)k*k+k,k-k.l/l0l1l2l3l4l5l6l7l8m9m:m;m<m=m>m?m@mAmBnCnDnEnFnGnHnInJnKnLoMoNoOoPoQoRoSoToUoVpWpXpYpZp[p\p]p^p_p`qaqbqcqdqeqfqgqhqiqjrkrlrmrnrorprq
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxrsrtsusvswsxsyszs{s|s}s~ttttttttttuuuuuuuuuuvvvvvvvvvvwwwwwwwwwwxxxxxxxxxxyyyyyyyyyyzzzzzzzzzz{{{{{{{{{{|||||||||
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx}}}}}}}}}}~~~~~~~~~~	

 !"#$%&'()*+,-./0123456789:;<=
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmno
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxqrstuvwxyz{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	

 !"#$%&'()*+,-./0123456789:;
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklm
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxopqrstuvwxyz{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	

 !"#$%&'()*+,-./0123456789
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOP	Q	R	S	T	U	V	W	X	Y	Z
[
\
]
^
_
`
a
b
c
defghijkIJ
$0<HT`lx ,8DP\ht(4@LXdp|J
JJ$cJ/J;EJFJQ'J\Jh	JszJ~JRJJJJJPJJJJJ	NJ	J
J
J
J"LJ,J6J@~JJJU
JJ_
JiJs|J}JHJJJzJJFJJJxJJDJJJvJJ!BJ+J5J?tJIJT@J^JhJrrJ|J>JJ
JpJJ<JJJnJJ:JHKG$0<HT`lx ,8DP\ht(4@LXdp|JlKK 8K*K4 K> jKH KS!6K]!Kg"K	q"hK
{"K#4K#K
$K$fK$K%2K%K%K&dK&K'0K'K'K
(bK(K).K))K3)K=*`KG*KR+,K \+K!f+K"x,^K#,K$-*K%-K&-K'.\K(.K)/(K*/K+/K,0ZK-0K.1&K/
1K01K12XK2)2K333$K4=3K5G3K6R4VK7\4K8f5"K9p5K:z5K;6TK<6K=7 K>7K?7K@8RKA8KB9KC9KD9KE:PKF:
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxmnopqrstuvwx
y
z
{
|
}
~




e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	

 !"#$%&'()*+,-./0123456 7
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx 9 : ; < = > ? @!A!B!C!D!E!F!G!H!I!J"K"L"M"N"O"P"Q"R"S"T#U#V#W#X#Y#Z#[#\#]#^$_$`$a$b$c$d$e$f$g$h%i%j%k%l%m%n%o%p%q%r&s&t&u&v&w&x&y&z&{&|'}'~''''''''(((((((((())))))))))***
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx******++++++++++,,,,,,,,,,----------..........//////////000000000011111111112222222222333333333344 4 4 4 
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx4 4 4 4 5 	5 
5 5 5 
5 5 5 5 5 6 6 6 6 6 6 6 6 6 6 7 7 7 7  7 !7 "7 #7 $7 %7 &8 '8 (8 )8 *8 +8 ,8 -8 .8 /8 09 19 29 39 49 59 69 79 89 99 :: ;: <: =: >: ?: @: A: B: C: D; E; F; G; H; I; J; K; L; M; N< O< P< Q< R< S< T< U< V< W< X= Y= Z= [= \= ]= ^= _= `= a= b> c> d> e> f> g> h> i
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx> k> l? m? n? o? p? q? r? s? t? u? v@ w@ x@ y@ z@ {@ |@ }@ ~@ @ A A A A A A A A A A B B B B B B B B B B C C C C C C C C C C D D D D D D D D D D E E E E E E E E E E F F F F F F F F F F G G G G G G G G G G H H H H H H H H H 
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxI I I I I I I I I I J J J J J J J J J J K K K K K K K K K K L L L L L L L L L L M M M M M M M M!M!M!N!N!N!N!N!N!N!	N!
N!N!O!
O!O!O!O!O!O!O!O!O!P!P!P!P!P!P!P!P!P!P! Q!!Q!"Q!#Q!$Q!%Q!&Q!'Q!(Q!)Q!*R!+R!,R!-R!.R!/R!0R!1R!2R!3R!4S!5
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxS!7S!8S!9S!:S!;S!<S!=S!>T!?T!@T!AT!BT!CT!DT!ET!FT!GT!HU!IU!JU!KU!LU!MU!NU!OU!PU!QU!RV!SV!TV!UV!VV!WV!XV!YV!ZV![V!\W!]W!^W!_W!`W!aW!bW!cW!dW!eW!fX!gX!hX!iX!jX!kX!lX!mX!nX!oX!pY!qY!rY!sY!tY!uY!vY!wY!xY!yY!zZ!{Z!|Z!}Z!~Z!Z!Z!Z!Z!Z![![![![![![![![![![!\!\!\!\!\!\!\!\!\!\!]!]!]!
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx]!]!]!]!]!]!^!^!^!^!^!^!^!^!^!^!_!_!_!_!_!_!_!_!_!_!`!`!`!`!`!`!`!`!`!`!a!a!a!a!a!a!a!a!a!a!b!b!b!b!b!b!b!b!b!b!c!c!c!c!c!c!c!c!c!c!d!d!d!d!d!d!d!d!d!d!e!e!e!e!e!e!e!e!e!e!f!f!f!f!f!f!f!f!f!f!g!g!g!g"g"
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxg"g"g"g"h"h"h"	h"
h"h"h"
h"h"h"i"i"i"i"i"i"i"i"i"i"j"j"j"j"j"j" j"!j""j"#j"$k"%k"&k"'k"(k")k"*k"+k",k"-k".l"/l"0l"1l"2l"3l"4l"5l"6l"7l"8m"9m":m";m"<m"=m">m"?m"@m"Am"Bn"Cn"Dn"En"Fn"Gn"Hn"In"Jn"Kn"Lo"Mo"No"Oo"Po"Qo"Ro"So"To"Uo"Vp"Wp"Xp"Yp"Zp"[p"\p"]p"^p"_p"`q"aq"bq"cq"dq"eq"fq"g
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxq"iq"jr"kr"lr"mr"nr"or"pr"qr"rr"sr"ts"us"vs"ws"xs"ys"zs"{s"|s"}s"~t"t"t"t"t"t"t"t"t"t"u"u"u"u"u"u"u"u"u"u"v"v"v"v"v"v"v"v"v"v"w"w"w"w"w"w"w"w"w"w"x"x"x"x"x"x"x"x"x"x"y"y"y"y"y"y"y"y"y"y"z"z"z"z"z"z"z"z"z"z"{"{"{"{"{"{"{"{"{"
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx|"|"|"|"|"|"|"|"|"|"}"}"}"}"}"}"}"}"}"}"~"~"~"~"~"~"~"~"~"~""""""""""""""""""""##########	#
###
################### #!#"###$#%#&#'#(#)#*#+#,#-#.#/#0#1#2#3
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx#5#6#7#8#9#:#;#<#=#>#?#@#A#B#C#D#E#F#G#H#I#J#K#L#M#N#O#P#Q#R#S#T#U#V#W#X#Y#Z#[#\#]#^#_#`#a#b#c#d#e#f#g#h#i#j#k#l#m#n#o#p#q#r#s#t#u#v#w#x#y#z#{#|#}#~###########################
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx#####################################################################################################
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx$$$$$$$$$	$
$$$
$$$$$$$$$$$$$$$$$$$ $!$"$#$$$%$&$'$($)$*$+$,$-$.$/$0$1$2$3$4$5$6$7$8$9$:$;$<$=$>$?$@$A$B$C$D$E$F$G$H$I$J$K$L$M$N$O$P$Q$R$S$T$U$V$W$X$Y$Z$[$\$]$^$_$`$a$b$c$d$e
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx$g$h$i$j$k$l$m$n$o$p$q$r$s$t$u$v$w$x$y$z${$|$}$~$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$%%%%%%%%%%	%
%%%
%%%%%%%%%%%%%%%%%%% %!%"%#%$%%%&%'%(%)%*%+%,%-%.%/%0%1
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx%3%4%5%6%7%8%9%:%;%<%=%>%?%@%A%B%C%D%E%F%G%H%I%J%K%L%M%N%O%P%Q%R%S%T%U%V%W%X%Y%Z%[%\%]%^%_%`%a%b%c%d%e%f%g%h%i%j%k%l%m%n%o%p%q%r%s%t%u%v%w%x%y%z%{%|%}%~%%%%%%%%%%%%%%%%%%%%%%%%%
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx%&&&&&&&&&&	&
&&&
&&&&&&&&&&&&&&&&&&& &!&"&#&$&%&&&'&(&)&*&+&,&-&.&/&0&1&2&3&4&5&6&7&8&9&:&;&<&=&>&?&@&A&B&C&D&E&F&G&H&I&J&K&L&M&N&O&P&Q&R&S&T&U&V&W&X&Y&Z&[&\&]&^&_&`&a&b&c
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx&e&f&g&h&i&j&k&l&m&n&o&p&q&r&s&t&u&v&w&x&y&z&{&|&}&~&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&''''''''''	'
'''
''''''''''''''''''' '!'"'#'$'%'&'''(')'*'+','-'.'/
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx'1'2'3'4'5'6'7'8'9':';'<'='>'?'@'A'B'C'D'E'F'G'H'I'J'K'L'M'N'O'P'Q'R'S'T'U'V'W'X'Y'Z'['\']'^'_'`'a'b'c'd'e'f'g'h'i'j'k'l'm'n'o'p'q'r's't'u'v'w'x'y'z'{'|'}'~'''''''''''''''''''''''
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx'''((((((((((	(
(((
((((((((((((((((((( (!("(#($(%(&('((()(*(+(,(-(.(/(0(1(2(3(4(5(6(7(8(9(:(;(<(=(>(?(@(A(B(C(D(E(F(G(H(I(J(K(L(M(N(O(P	(Q	(R	(S	(T	(U	(V	(W	(X	(Y	(Z
([
(\
(]
(^
(_
(`
(a
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
(c
(d(e(f(g(h(i(j(k(l(m(n(o(p(q(r(s(t(u(v(w(x
(y
(z
({
(|
(}
(~
(
(
(
((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx((((((((((((((((((((((((((((((((((((((((((((((((((((((())))))))))	)
)))
))))))))))))))))))) )!)")#)$)%)&)')()))*)+),)-
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx)/)0)1)2)3)4)5)6 )7 )8 )9 ): ); )< )= )> )? )@!)A!)B!)C!)D!)E!)F!)G!)H!)I!)J")K")L")M")N")O")P")Q")R")S")T#)U#)V#)W#)X#)Y#)Z#)[#)\#)]#)^$)_$)`$)a$)b$)c$)d$)e$)f$)g$)h%)i%)j%)k%)l%)m%)n%)o%)p%)q%)r&)s&)t&)u&)v&)w&)x&)y&)z&){&)|')}')~')')')')')')')')()()()()()()()()()()))))))
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx))))))))))))*)*)*)*)*)*)*)*)*)*)+)+)+)+)+)+)+)+)+)+),),),),),),),),),),)-)-)-)-)-)-)-)-)-)-).).).).).).).).).).)/)/)/)/)/)/)/)/)/)/)0)0)0)0)0)0)0)0)0)0)1)1)1)1)1)1)1)1)1)1)2)2)2)2)2)2)2)2)2)2)3)3)3)3)3)
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx3)3)3)3)4)4*4*4*4*4*4*4*4*4*5*	5*
5*5*5*
5*5*5*5*5*6*6*6*6*6*6*6*6*6*6*7*7*7*7* 7*!7*"7*#7*$7*%7*&8*'8*(8*)8**8*+8*,8*-8*.8*/8*09*19*29*39*49*59*69*79*89*99*::*;:*<:*=:*>:*?:*@:*A:*B:*C:*D;*E;*F;*G;*H;*I;*J;*K;*L;*M;*N<*O<*P<*Q<*R<*S<*T<*U<*V<*W<*X=*Y=*Z=*[=*\=*]=*^=*_
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx=*a=*b>*c>*d>*e>*f>*g>*h>*i>*j>*k>*l?*m?*n?*o?*p?*q?*r?*s?*t?*u?*v@*w@*x@*y@*z@*{@*|@*}@*~@*@*A*A*A*A*A*A*A*A*A*A*B*B*B*B*B*B*B*B*B*B*C*C*C*C*C*C*C*C*C*C*D*D*D*D*D*D*D*D*D*D*E*E*E*E*E*E*E*E*E*E*F*F*F*F*F*F*F*F*F*F*G*G*G*G*G*G*G*G*G*
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxH*H*H*H*H*H*H*H*H*H*I*I*I*I*I*I*I*I*I*I*J*J*J*J*J*J*J*J*J*J*K*K*K*K*K*K*K*K*K*K*L*L*L*L*L*L*L*L*L*L*M*M*M*M*M*M*M*M+M+M+N+N+N+N+N+N+N+	N+
N+N+O+
O+O+O+O+O+O+O+O+O+P+P+P+P+P+P+P+P+P+P+ Q+!Q+"Q+#Q+$Q+%Q+&Q+'Q+(Q+)Q+*R++
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxR+-R+.R+/R+0R+1R+2R+3R+4S+5S+6S+7S+8S+9S+:S+;S+<S+=S+>T+?T+@T+AT+BT+CT+DT+ET+FT+GT+HU+IU+JU+KU+LU+MU+NU+OU+PU+QU+RV+SV+TV+UV+VV+WV+XV+YV+ZV+[V+\W+]W+^W+_W+`W+aW+bW+cW+dW+eW+fX+gX+hX+iX+jX+kX+lX+mX+nX+oX+pY+qY+rY+sY+tY+uY+vY+wY+xY+yY+zZ+{Z+|Z+}Z+~Z+Z+Z+Z+Z+Z+[+[+[+[+[+[+[+[+[+[+\+\+\+
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx\+\+\+\+\+\+]+]+]+]+]+]+]+]+]+]+^+^+^+^+^+^+^+^+^+^+_+_+_+_+_+_+_+_+_+_+`+`+`+`+`+`+`+`+`+`+a+a+a+a+a+a+a+a+a+a+b+b+b+b+b+b+b+b+b+b+c+c+c+c+c+c+c+c+c+c+d+d+d+d+d+d+d+d+d+d+e+e+e+e+e+e+e+e+e+e+f+f+f+f+f+
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxf+f+f+f+g+g+g+g,g,g,g,g,g,g,h,h,h,	h,
h,h,h,
h,h,h,i,i,i,i,i,i,i,i,i,i,j,j,j,k,k,k, l,!l,"l,#l,$m,%m,&m,'m,(n,)n,*n,+o,,o,-o,.p,/p,0p,1p,2q,3q,4q,5q,6r,7r,8r,9s,:s,;s,<t,=t,>t,?t,@u,Au,Bu,Cu,Dv,Ev,Fv,Gv,Hv,Iv,Jv,Kv,Lv,Mv,Nw,Ow,Pw,Qw,Rw,Sw,Tw,Uw,Vw,Ww,Xx,Yx,Zx,[x,\x,]
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxx,_x,`x,ax,by,cy,dy,ey,fy,gy,hy,iy,jy,ky,lz,mz,nz,oz,pz,qz,rz,sz,tz,uz,v{,w{,x{,y{,z{,{{,|{,}{,~{,{,|,|,|,|,|,|,|,|,|,|,},},},},},},},},},},~,~,~,~,~,~,~,~,~,~,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,----------	-
---
------------------- -!-"-#-$-%-&-'-(-)
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx-+-,---.-/-0-1-2-3-4-5-6-7-8-9-:-;-<-=->-?-@-A-B-C-D-E-F-G-H-I-J-K-L-M-N-O-P-Q-R-S-T-U-V-W-X-Y-Z-[-\-]-^-_-`-a-b-c-d-e-f-g-h-i-j-k-l-m-n-o-p-q-r-s-t-u-v-w-x-y-z-{-|-}-~-----------------
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx-----------------------------------------------------------------------------------------------------
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx---------..........	.
...
................... .!.".#.$.%.&.'.(.).*.+.,.-.../.0.1.2.3.4.5.6.7.8.9.:.;.<.=.>.?.@.A.B.C.D.E.F.G.H.I.J.K.L.M.N.O.P.Q.R.S.T.U.V.W.X.Y.Z.[
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx.].^._.`.a.b.c.d.e.f.g.h.i.j.k.l.m.n.o.p.q.r.s.t.u.v.w.x.y.z.{.|.}.~...................................................................
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx.............................................................//////////	/
///
/////////////////// /!/"/#/$/%/&/'
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx/)/*/+/,/-/.///0/1/2/3/4/5/6/7/8/9/:/;/</=/>/?/@/A/B/C/D/E/F/G/H/I/J/K/L/M/N/O/P/Q/R/S/T/U/V/W/X/Y/Z/[/\/]/^/_/`/a/b/c/d/e/f/g/h/i/j/k/l/m/n/o/p/q/r/s/t/u/v/w/x/y/z/{/|/}/~///////////////
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx/////////////////////////////////////////////////////////////////////////////////////////////////////
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx///////////0000000000	0
000
0000000000000000000 0!0"0#0$0%0&0'0(0)0*0+0,0-0.0/000102030405060708090:0;0<0=0>0?0@0A0B0C0D0E0F0G0H0I0J0K0L0M0N0O0P0Q0R0S0T0U0V0W0X0Y
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx0[0\0]0^0_0`0a0b0c0d0e0f0g0h0i0j0k0l0m0n0o0p0q0r0s0t0u0v0w0x0y0z0{0|0}0~00000000000000000000000000000000000000000000000000000000000000000
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx0000000000000000000000000000000000000000000000000000000000000001111111111	1
111
1111111111111111111 1!1"1#1$1%
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx1'1(1)1*1+1,1-1.1/101112131415161718191:1;1<1=1>1?1@1A1B1C1D1E1F1G1H1I1J1K1L1M1N1O1P1Q1R1S1T1U1V1W1X1Y1Z1[1\1]1^1_1`1a1b1c1d1e1f1g1h1i1j1k1l1m1n1o1p1q1r1s1t1u1v1w1x1y1z1{	1|	1}	1~	1	1	1	1	1	1	1
1
1
1
1
1
1
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
1
1
111111111111111111111
1
1
1
1
1
1
1
1
1
111111111111111111111111111111111111111111111111111111111111111111111
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx11111111111112222222222	2
222
2222222222222222222 2!2"2#2$2%2&2'2(2)2*2+2,2-2.2/202122232425262728292:2;2<2=2>2?2@2A2B2C2D2E2F2G2H2I2J2K2L2M2N2O2P2Q2R2S2T2U2V2W
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx2Y2Z2[2\2]2^2_2`2a 2b 2c 2d 2e 2f 2g 2h 2i 2j 2k!2l!2m!2n!2o!2p!2q!2r!2s!2t!2u"2v"2w"2x"2y"2z"2{"2|"2}"2~"2#2#2#2#2#2#2#2#2#2#2$2$2$2$2$2$2$2$2$2$2%2%2%2%2%2%2%2%2%2%2&2&2&2&2&2&2&2&2&2&2'2'2'2'2'2'2'2'2'2'2(2(2(2(2(2(2(2(2(2(2)2)2
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx)2)2)2)2)2)2)2*2*2*2*2*2*2*2*2*2*2+2+2+2+2+2+2+2+2+2+2,2,2,2,2,2,2,2,2,2,2-2-2-2-2-2-2-2-2-2-2.2.2.2.2.2.2.2.2.2.2/2/2/2/2/2/2/2/2/3/30303030303030303	03
031313
13131313131313132323232323232323232333 33!33"33#
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx33%33&33'33(33)43*43+43,43-43.43/43043143243353453553653753853953:53;53<53=63>63?63@63A63B63C63D63E63F63G73H73I73J73K73L73M73N73O73P73Q83R83S83T83U83V83W83X83Y83Z83[93\93]93^93_93`93a93b93c93d93e:3f:3g:3h:3i:3j:3k:3l:3m:3n:3o;3p;3q;3r;3s;3t;3u;3v;3w;3x;3y<3z<3{<3|<3}<3~<3<3<3<3<3=3=3=3=3=3=3
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx=3=3=3>3>3>3>3>3>3>3>3>3>3?3?3?3?3?3?3?3?3?3?3@3@3@3@3@3@3@3@3@3@3A3A3A3A3A3A3A3A3A3A3B3B3B3B3B3B3B3B3B3B3C3C3C3C3C3C3C3C3C3C3D3D3D3D3D3D3D3D3D3D3E3E3E3E3E3E3E3E3E3E3F3F3F3F3F3F3F3F3F3F3G3G3G3G3G3G3G3G3
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxG3H3H3H3H3H3H3H3H3H3H3I3I3I3I3I4I4I4I4I4I4J4J4J4J4	J4
J4J4J4
J4J4K4K4K4K4K4K4K4K4K4K4L4L4L4L4L4L4L4 L4!L4"L4#M4$M4%M4&M4'M4(M4)M4*M4+M4,M4-N4.N4/N40N41N42N43N44N45N46N47O48O49O4:O4;O4<O4=O4>O4?O4@O4AP4BP4CP4DP4EP4FP4GP4HP4IP4JP4KQ4LQ4MQ4NQ4OQ4PQ4QQ4RQ4SQ4TQ4U
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxR4WR4XR4YR4ZR4[R4\R4]R4^R4_S4`S4aS4bS4cS4dS4eS4fS4gS4hS4iT4jT4kT4lT4mT4nT4oT4pT4qT4rT4sU4tU4uU4vU4wU4xU4yU4zU4{U4|U4}V4~V4V4V4V4V4V4V4V4V4W4W4W4W4W4W4W4W4W4W4X4X4X4X4X4X4X4X4X4X4Y4Y4Y4Y4Y4Y4Y4Y4Y4Y4Z4Z4Z4Z4Z4Z4Z4Z4Z4Z4[4[4[4[4[4[4[4[4[4[4\4\4
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx\4\4\4\4\4\4\4]4]4]4]4]4]4]4]4]4]4^4^4^4^4^4^4^4^4^4^4_4_4_4_4_4_4_4_4_4_4`4`4`4`4`4`4`4`4`4`4a4a4a4a4a4a4a4a4a4a4b4b4b4b4b4b4b4b4b4b4c5c5c5c5c5c5c5c5c5c5	d5
d5d5d5
d5d5d5d5d5d5e5e5e5e5e5e5e5e5e5e5f5f5f5 f5!
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxf5#f5$f5%f5&f5'g5(g5)g5*g5+g5,g5-g5.g5/g50g51h52h53h54h55h56h57h58h59h5:h5;i5<i5=i5>i5?i5@i5Ai5Bi5Ci5Di5Ej5Fj5Gj5Hj5Ij5Jj5Kj5Lj5Mj5Nj5Ok5Pk5Qk5Rk5Sk5Tk5Uk5Vk5Wk5Xk5Yl5Zl5[l5\l5]l5^l5_l5`l5al5bl5cm5dm5em5fm5gm5hm5im5jm5km5lm5mn5nn5on5pn5qn5rn5sn5tn5un5vn5wo5xo5yo5zo5{o5|o5}o5~o5o5o5p5p5p5p5p5p5
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxp5p5p5q5q5q5q5q5q5q5q5q5q5r5r5r5r5r5r5r5r5r5r5s5s5s5s5s5s5s5s5s5s5t5t5t5t5t5t5t5t5t5t5u5u5u5u5u5u5u5u5u5u5v5v5v5v5v5v5v5v5v5v5w5w5w5w5w5w5w5w5w5w5x5x5x5x5x5x5x5x5x5x5y5y5y5y5y5y5y5y5y5y5z5z5z5z5z5z5z5z5
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxz5{5{5{5{5{5{5{5{5{5{5|5|5|5|5|5|5|6|6|6|6}6}6}6}6}6}6	}6
}6}6}6
~6~6~6~6~6~6~6~6~6~6666666666 6!6"6#6$6%6&6'6(6)6*6+6,6-6.6/606162636465666768696:6;6<6=6>6?6@6A6B6C6D6E6F6G6H6I6J6K6L6M6N6O6P6Q6R6S
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx6U6V6W6X6Y6Z6[6\6]6^6_6`6a6b6c6d6e6f6g6h6i6j6k6l6m6n6o6p6q6r6s6t6u6v6w6x6y6z6{6|6}6~66666666666666666666666666666666666666666666666666666666666
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx6666666666666666666666666666666666666666666666666666666666666666666667777777777	7
777
777777777777777777
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx7!7"7#7$7%7&7'7(7)7*7+7,7-7.7/707172737475767778797:7;7<7=7>7?7@7A7B7C7D7E7F7G7H7I7J7K7L7M7N7O7P7Q7R7S7T7U7V7W7X7Y7Z7[7\7]7^7_7`7a7b7c7d7e7f7g7h7i7j7k7l7m7n7o7p7q7r7s7t7u7v7w7x7y7z7{7|7}7~7777777
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx77777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx77777777777777777778888888888	8
888
8888888888888888888 8!8"8#8$8%8&8'8(8)8*8+8,8-8.8/808182838485868788898:8;8<8=8>8?8@8A8B8C8D8E8F8G8H8I8J8K8L8M8N8O8P8Q
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx8S8T8U8V8W8X8Y8Z8[8\8]8^8_8`8a8b8c8d8e8f8g8h8i8j8k8l8m8n8o8p8q8r8s8t8u8v8w8x8y8z8{8|8}8~888888888888888888888888888888888888888888888888888888888
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx888888888888888888888888888888888888888888888888888888888888888888888889999999999	9
999
9999999999999999
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx99 9!9"9#9$9%9&9'9(9)9*9+9,9-9.9/909192939495969798999:9;9<9=9>9?9@9A9B9C9D9E9F9G9H9I9J9K9L9M9N9O9P9Q9R9S9T9U9V9W9X9Y9Z9[9\9]9^9_9`9a9b9c9d9e9f9g9h9i9j9k9l9m9n9o9p9q9r9s9t9u9v9w9x9y9z9{9|9}9~99999
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx99999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx999999999999999999999::::::::::	:
:::
::::::::::::::::::: :!:":#:$:%:&:':(:):*:+:,:-:.:/:0:1:2:3:4:5:6:7:8:9:::;:<:=:>:?:@:A:B:C:D:E:F:G:H:I:J:K:L:M:N:O
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx:Q:R:S:T:U:V:W:X:Y:Z:[:\:]:^:_:`:a:b:c:d:e:f:g:h:i:j:k:l:m:n:o:p:q:r:s:t:u:v:w:x:y:z:{:|:}:~:::::::::::::::::::::::::::::::::::::::::::::::::::::::
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx::::::::::::::::::::::::::::::::::::::::::::	:	:	:	:	:	:	:	:	:	:
:
:
:
:
:
:
:
:
:
::::::::::;;;;;;;;;;	;

;
;
;

;
;
;
;
;
;
;;;;;;;;
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx;;;; ;!;";#;$;%;&;';(;);*;+;,;-;.;/;0;1;2;3;4;5;6;7;8;9;:;;;<;=;>;?;@;A;B;C;D;E;F;G;H;I;J;K;L;M;N;O;P;Q;R;S;T;U;V;W;X;Y;Z;[;\;];^;_;`;a;b;c;d;e;f;g;h;i;j;k;l;m;n;o;p;q;r;s;t;u;v;w;x;y;z;{;|;};~;;;HK$0<HT`lx ,8DP\ht(4@LXdp|KH;KJ#;KK-<NKL7<KMA=KNK=KOV=KP`>LKQj>KRt?KS~?~KT?KU@JKV@KWAKXA|KYAKZBHK[BK\CK]CzK^CK_DFK`DKaEKbExKc$EKd.FDKe8FKfCGKgMGvKhWGKiaHBKjkHKkvIKlItKmIKnJ@KoJKpKKqKrKrKKsL>KtLKuM
KvMpKwMKxN<KyNKzOK{OnK|#OK}-P:K~7PKBQKLQlKVQK`R8KjRKuSKSjKSKT6KTKUKUhKUKV4KVKWKWfKW
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; ; ; ; ; ; ; ; ; ; ;!;!;!;!;!;!;!;!;!;!;";";";";";";";";";";#;
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx#;#;#;#;#;#;#;#;$;$;$;$;$;$;$;$;$;$;%;%;%;%;%;%<%<%<%<%<&<&<&<&<&<	&<
&<&<&<
&<'<'<'<'<'<'<'<'<'<'<(<(<(<(<(<(<(<(< (<!(<")<#)<$)<%)<&)<')<()<))<*)<+)<,*<-*<.*</*<0*<1*<2*<3*<4*<5*<6+<7+<8+<9+<:+<;+<<+<=+<>+<?+<@,<A,<B,<C,<D,<E,<F,<G,<H,<I,<J-<K-<L-<M
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx-<O-<P-<Q-<R-<S-<T.<U.<V.<W.<X.<Y.<Z.<[.<\.<].<^/<_/<`/<a/<b/<c/<d/<e/<f/<g/<h0<i0<j0<k0<l0<m0<n0<o0<p0<q0<r1<s1<t1<u1<v1<w1<x1<y1<z1<{1<|2<}2<~2<2<2<2<2<2<2<2<3<3<3<3<3<3<3<3<3<3<4<4<4<4<4<4<4<4<4<4<5<5<5<5<5<5<5<5<5<5<6<6<6<6<6<6<6<6<6<6<7<7<7<7<7<
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx7<7<7<7<8<8<8<8<8<8<8<8<8<8<9<9<9<9<9<9<9<9<9<9<:<:<:<:<:<:<:<:<:<:<;<;<;<;<;<;<;<;<;<;<<<<<<<<<<<<<<<<<<<<<=<=<=<=<=<=<=<=<=<=<><><><><><><><><><><?<?=?=?=?=?=?=?=?=?=@=	@=
@=@=@=
@=@=@=@=@=A=A=A=A=A=A=A=
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxA=A=B=B=B=B= B=!B="B=#B=$B=%B=&C='C=(C=)C=*C=+C=,C=-C=.C=/C=0D=1D=2D=3D=4D=5D=6D=7D=8D=9D=:E=;E=<E==E=>E=?E=@E=AE=BE=CE=DF=EF=FF=GF=HF=IF=JF=KF=LF=MF=NG=OG=PG=QG=RG=SG=TG=UG=VG=WG=XH=YH=ZH=[H=\H=]H=^H=_H=`H=aH=bI=cI=dI=eI=fI=gI=hI=iI=jI=kI=lJ=mJ=nJ=oJ=pJ=qJ=rJ=sJ=tJ=uJ=vK=wK=xK=yK=zK={K=|K=}K=~K=
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxL=L=L=L=L=L=L=L=L=L=M=M=M=M=M=M=M=M=M=M=N=N=N=N=N=N=N=N=N=N=O=O=O=O=O=O=O=O=O=O=P=P=P=P=P=P=P=P=P=P=Q=Q=Q=Q=Q=Q=Q=Q=Q=Q=R=R=R=R=R=R=R=R=R=R=S=S=S=S=S=S=S=S=S=S=T=T=T=T=T=T=T=T=T=T=U=U=U=U=U=U=U=U=U=U=V=
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxV=V=V=V=V=V=V=V=W=W=W=W=W=W=W=W=W=W=X=X=X=X=X=X=X=X>X>X>Y>Y>Y>Y>Y>Y>Y>	Y>
Y>Y>Z>
Z>Z>Z>Z>Z>Z>Z>Z>Z>[>[>[>[>[>[>[>[>[>[> \>!\>"\>#\>$\>%\>&\>'\>(\>)\>*]>+]>,]>-]>.]>/]>0]>1]>2]>3]>4^>5^>6^>7^>8^>9^>:^>;^><^>=^>>_>?_>@_>A_>B_>C_>D_>E_>F_>G_>H`>I`>J`>K
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx`>M`>N`>O`>P`>Q`>Ra>Sa>Ta>Ua>Va>Wa>Xa>Ya>Za>[a>\b>]b>^b>_b>`b>ab>bb>cb>db>eb>fc>gc>hc>ic>jc>kc>lc>mc>nc>oc>pd>qd>rd>sd>td>ud>vd>wd>xd>yd>ze>{e>|e>}e>~e>e>e>e>e>e>f>f>f>f>f>f>f>f>f>f>g>g>g>g>g>g>g>g>g>g>h>h>h>h>h>h>h>h>h>h>i>i>i>i>i>i>i>i>i>i>j>j>j>j>j>
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxj>j>j>j>k>k>k>k>k>k>k>k>k>k>l>l>l>l>l>l>l>l>l>l>m>m>m>m>m>m>m>m>m>m>n>n>n>n>n>n>n>n>n>n>o>o>o>o>o>o>o>o>o>o>p>p>p>p>p>p>p>p>p>p>q>q>q>q>q>q>q>q>q>q>r>r>r>r?r?r?r?r?r?r?s?s?s?	s?
s?s?s?
s?s?s?t?t?t?t?t?t?t?
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxt?t?u?u?u?u?u?u? u?!u?"u?#u?$v?%v?&v?'v?(v?)v?*v?+v?,v?-v?.w?/w?0w?1w?2w?3w?4w?5w?6w?7w?8x?9x?:x?;x?<x?=x?>x??x?@x?Ax?By?Cy?Dy?Ey?Fy?Gy?Hy?Iy?Jy?Ky?Lz?Mz?Nz?Oz?Pz?Qz?Rz?Sz?Tz?Uz?V{?W{?X{?Y{?Z{?[{?\{?]{?^{?_{?`|?a|?b|?c|?d|?e|?f|?g|?h|?i|?j}?k}?l}?m}?n}?o}?p}?q}?r}?s}?t~?u~?v~?w~?x~?y~?z~?{~?|~?}
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx?????????????????????????????????????????????????????????????????????????????????????????????????????
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx???????????????????????????@@@@@@@@@@	@
@@@
@@@@@@@@@@@@@@@@@@@ @!@"@#@$@%@&@'@(@)@*@+@,@-@.@/@0@1@2@3@4@5@6@7@8@9@:@;@<@=@>@?@@@A@B@C@D@E@F@G@H@I
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx@K@L@M@N@O@P@Q@R@S@T@U@V@W@X@Y@Z@[@\@]@^@_@`@a@b@c@d@e@f@g@h@i@j@k@l@m@n@o@p@q@r@s@t@u@v@w@x@y@z@{@|@}@~@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@AAAAAAAAAA	A
AAA
AAAAAAAA
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxAAAAAAAAAA A!A"A#A$A%A&A'A(A)A*A+A,A-A.A/A0A1A2A3A4A5A6A7A8A9A:A;A<A=A>A?A@AAABACADAEAFAGAHAIAJAKALAMANAOAPAQARASATAUAVAWAXAYAZA[A\A]A^A_A`AaAbAcAdAeAfAgAhAiAjAkAlAmAnAoApAqArAsAtAuAvAwAxAyAzA{
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxA}A~AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxAAAAAAAAAAAAAAAAAAAAAAAAAAAAABBBBBBBBBB	B
BBB
BBBBBBBBBBBBBBBBBBB B!B"B#B$B%B&B'B(B)B*B+B,B-B.B/B0B1B2B3B4B5B6B7B8B9B:B;B<B=B>B?B@BABBBCBDBEBFBG
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxBIBJBKBLBMBNBOBPBQBRBSBTBUBVBWBXBYBZB[B\B]B^B_B`BaBbBcBdBeBfBgBhBiBjBkBlBmBnBoBpBqBrBsBtBuBvBwBxByBzB{B|B}B~BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBCCCCCCCCCC	C
CCC
CCCCCC
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxCCCCCCCCCCCC C!C"C#C$C%C&C'C(C)C*C+C,C-C.C/C0C1C2C3C4C5C6C7C8C9C:C;C<C=C>C?C@CACBCCCDCECFCGCHCICJCKCLCMCNCOCPCQCRCSCTCUCVCWCXCYCZC[C\C]C^C_C`CaCbCcCdCeCfCgChCiCjCkClCmCnCoCpCqCrCsCtCuCvCwCxCy
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxC{C|C}C~CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCDDDDDDDDDD	D
DDD
DDDDDDDDDDDDDDDDDDD D!D"D#D$D%D&D'D(D)D*D+D,D-D.D/D0D1D2D3D4D5D6D7D8D9D:D;D<D=D>D?D@DADBDCDDDE
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxDGDHDIDJDKDLDMDNDODPDQDRDSDTDUDVDWDXDYDZD[D\D]D^D_D`DaDbDcDdDeDfDgDhDiDjDkDlDmDnDoDpDqDrDsDtDuDvDwDxDyDzD{D|D}D~DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD	D	D	D	D	D	D	D	D	D	D
D
D
D
D
D
D
D
D
D
DDDDDDDDDDDDDDDDDDDDD
D
D
D
D
D
D
D
D
D
DDDDEEEEEEEEEE	E
EEE
EEEE
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxEEEEEEEEEEEEEE E!E"E#E$E%E&E'E(E)E*E+E,E-E.E/E0E1E2E3E4E5E6E7E8E9E:E;E<E=E>E?E@EAEBECEDEEEFEGEHEIEJEKELEMENEOEPEQERESETEUEVEWEXEYEZE[E\E]E^E_E`EaEbEcEdEeEfEgEhEiEjEkElEmEnEoEpEqErEsEtEuEvEw
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxEyEzE{E|E}E~EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE E E E E E E E E E E!E!E!E!E!E!E!E!E!E!E"E"E"E"E"E"E"E"E"E"E#E#E#E#E#E#E#E#E#E#E$E$E$E$E$E
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx$E$E$E$E%E%E%E%E%E%E%E%E%E%E&E&E&E&E&E&E&E&E&E&E'E'E'E'E'E'E'E'E'E'F(F(F(F(F(F(F(F(F(F	(F
)F)F)F
)F)F)F)F)F)F)F*F*F*F*F*F*F*F*F*F*F+F+F +F!+F"+F#+F$+F%+F&+F'+F(,F),F*,F+,F,,F-,F.,F/,F0,F1,F2-F3-F4-F5-F6-F7-F8-F9-F:-F;-F<.F=.F>.F?.F@.FA.FB.FC
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx.FE.FF/FG/FH/FI/FJ/FK/FL/FM/FN/FO/FP0FQ0FR0FS0FT0FU0FV0FW0FX0FY0FZ1F[1F\1F]1F^1F_1F`1Fa1Fb1Fc1Fd2Fe2Ff2Fg2Fh2Fi2Fj2Fk2Fl2Fm2Fn3Fo3Fp3Fq3Fr3Fs3Ft3Fu3Fv3Fw3Fx4Fy4Fz4F{4F|4F}4F~4F4F4F4F5F5F5F5F5F5F5F5F5F5F6F6F6F6F6F6F6F6F6F6F7F7F7F7F7F7F7F7F7F7F8F8F8F8F8F8F8F8F8F
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx9F9F9F9F9F9F9F9F9F9F:F:F:F:F:F:F:F:F:F:F;F;F;F;F;F;F;F;F;F;F<F<F<F<F<F<F<F<F<F<F=F=F=F=F=F=F=F=F=F=F>F>F>F>F>F>F>F>F>F>F?F?F?F?F?F?F?F?F?F?F@F@F@F@F@F@F@F@F@F@FAFAFAFAFAFAGAGAGAGAGBGBGBGBGBG	BG
BGBGBG
BGCG
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxCGCGCGCGCGCGCGCGDGDGDGDGDGDGDGDG DG!DG"EG#EG$EG%EG&EG'EG(EG)EG*EG+EG,FG-FG.FG/FG0FG1FG2FG3FG4FG5FG6GG7GG8GG9GG:GG;GG<GG=GG>GG?GG@HGAHGBHGCHGDHGEHGFHGGHGHHGIHGJIGKIGLIGMIGNIGOIGPIGQIGRIGSIGTJGUJGVJGWJGXJGYJGZJG[JG\JG]JG^KG_KG`KGaKGbKGcKGdKGeKGfKGgKGhLGiLGjLGkLGlLGmLGnLGoLGpLGqLGrMGsMGtMGu
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxMGwMGxMGyMGzMG{MG|NG}NG~NGNGNGNGNGNGNGNGOGOGOGOGOGOGOGOGOGOGPGPGPGPGPGPGPGPGPGPGQGQGQGQGQGQGQGQGQGQGRGRGRGRGRGRGRGRGRGRGSGSGSGSGSGSGSGSGSGSGTGTGTGTGTGTGTGTGTGTGUGUGUGUGUGUGUGUGUGUGVGVGVGVGVGVGVGVGVGVGWGWGWGWGWG
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxWGWGWGWGXGXGXGXGXGXGXGXGXGXGYGYGYGYGYGYGYGYGYGYGZGZGZGZGZGZGZGZGZGZG[G[H[H[H[H[H[H[H[H[H\H	\H
\H\H\H
\H\H\H\H\H]H]H]H]H]H]H]H]H]H]H^H^H^H^H ^H!^H"^H#^H$^H%^H&_H'_H(_H)_H*_H+_H,_H-_H._H/_H0`H1`H2`H3`H4`H5`H6`H7`H8`H9`H:aH;aH<aH=aH>aH?aH@aHA
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxaHCaHDbHEbHFbHGbHHbHIbHJbHKbHLbHMbHNcHOcHPcHQcHRcHScHTcHUcHVcHWcHXdHYdHZdH[dH\dH]dH^dH_dH`dHadHbeHceHdeHeeHfeHgeHheHieHjeHkeHlfHmfHnfHofHpfHqfHrfHsfHtfHufHvgHwgHxgHygHzgH{gH|gH}gH~gHgHhHhHhHhHhHhHhHhHhHhHiHiHiHiHiHiHiHiHiHiHjHjHjHjHjHjHjHjHjHjHkHkHkHkHkHkHkHkHkH
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxlHlHlHlHlHlHlHlHlHlHmHmHmHmHmHmHmHmHmHmHnHnHnHnHnHnHnHnHnHnHoHoHoHoHoHoHoHoHoHoHpHpHpHpHpHpHpHpHpHpHqHqHqHqHqHqHqHqHqHqHrHrHrHrHrHrHrHrHrHrHsHsHsHsHsHsHsHsHsHsHtHtHtHtHtHtHtHtItItIuIuIuIuIuIuIuI	uI
uIuIvI
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxvIvIvIvIvIvIvIvIwIwIwIwIwIwIwIwIwIwI xI!xI"xI#xI$xI%xI&xI'xI(xI)xI*yI+yI,yI-yI.yI/yI0yI1yI2yI3yI4zI5zI6zI7zI8zI9zI:zI;zI<zI=zI>{I?{I@{IA{IB{IC{ID{IE{IF{IG{IH|II|IJ|IK|IL|IM|IN|IO|IP|IQ|IR}IS}IT}IU}IV}IW}IX}IY}IZ}I[}I\~I]~I^~I_~I`~Ia~Ib~Ic~Id~Ie~IfIgIhIiIjIkIlImInIoIpIqIrIs
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxIuIvIwIxIyIzI{I|I}I~IIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIJJJJJJJJJJ	J
JJJ
JJJJJJJJJJJJJJJJJJJ J!J"J#J$J%J&J'J(J)J*J+J,J-J.J/J0J1J2J3J4J5J6J7J8J9J:J;J<J=J>J?
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxJAJBJCJDJEJFJGJHJIJJJKJLJMJNJOJPJQJRJSJTJUJVJWJXJYJZJ[J\J]J^J_J`JaJbJcJdJeJfJgJhJiJjJkJlJmJnJoJpJqJrJsJtJuJvJwJxJyJzJ{J|J}J~JJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJ
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJKKKKKKKKKK	K
K
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxK
KKKKKKKKKKKKKKKKKKK K!K"K#K$K%K&K'K(K)K*K+K,K-K.K/K0K1K2K3K4K5K6K7K8K9K:K;K<K=K>K?K@KAKBKCKDKEKFKGKHKIKJKKKLKMKNKOKPKQKRKSKTKUKVKWKXKYKZK[K\K]K^K_K`KaKbKcKdKeKfKgKhKiKjKkKlKmKnKoKpKq
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxKsKtKuKvKwKxKyKzK{K|K}K~KKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKK
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKLLLLLLLLLL	L
LLL
LLLLLLLLLLLLLLLLLLL L!L"L#L$L%L&L'L(L)L*L+L,L-L.L/L0L1L2L3L4L5L6L7L8L9L:L;L<L=
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxL?L@LALBLCLDLELFLGLHLILJLKLLLMLNLOLPLQLRLSLTLULVLWLXLYLZL[L\L]L^L_L`LaLbLcLdLeLfLgLhLiLjLkLlLmLnLoLpLqLrLsLtLuLvLwLxLyLzL{L|L}L~LLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLL
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLMMMMMMMMMM	
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxMMM
MMMMMMMMMMMMMMMMMMM M!M"M#M$M%M&M'M(M)M*M+M,M-M.M/M0M1M2M3M4M5M6M7M8M9M:M;M<M=M>M?M@MAMBMCMDMEMFMGMHMIMJMKMLMMMNMOMPMQMRMSMTMUMVMWMXMYMZM[M\M]M^M_M`MaMbMcMdMeMfMgMhMiMjMkMlMmMnMo
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxMqMrMsMtMuMvMwMxMyMzM{M|M}M~MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMNNNNNNNNNN	N
NNN
NNNNNNNNNNNNNNNNNNN N!N"N#N$N%N&N'N(N)N*N+N,N-N.N/N0N1N2N3N4N5N6N7N8N9N:N;
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxN=N>N?N@NANBNCNDNENFNGNHNINJNKNLNMNNNONPNQNRNSNTNUNVNWNXNYNZN[N\N]N^N_N`NaNbNcNdNeNfNgNhNiNjNkNlNmNnNoNpNqNrNsNtNuNvNwNxNyNzN{N|N}N~NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN	N	N	N	N	N	N	N	N	N	N
N
N
N
N
N
N
N
N
N
NNNNNNNNNNNNNNNNNNNNN
N
N
N
N
N
N
N
N
N
NNNNOOOOOOOO
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxO	O
OOO
OOOOOOOOOOOOOOOOOOO O!O"O#O$O%O&O'O(O)O*O+O,O-O.O/O0O1O2O3O4O5O6O7O8O9O:O;O<O=O>O?O@OAOBOCODOEOFOGOHOIOJOKOLOMONOOOPOQOROSOTOUOVOWOXOYOZO[O\O]O^O_O`OaObOcOdOeOfOgOhOiOjOkOlOm
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxOoOpOqOrOsOtOuOvOwOxOyOzO{O|O}O~OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO O O O O O O O O O O!O!O!O!O!O!O!O!O!O!O"O"O"O"O"O"O"O"O"O"O#O#O#O#O#O
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx#O#O#O#O$O$O$O$O$O$O$O$O$O$O%O%O%O%O%O%O%O%O%O%O&O&O&O&O&O&O&O&O&O&O'O'O'O'O'O'O'O'O'O'P(P(P(P(P(P(P(P(P(P	(P
)P)P)P
)P)P)P)P)P)P)P*P*P*P*P*P*P*P*P*P*P+P+P +P!+P"+P#+P$+P%+P&+P'+P(,P),P*,P+,P,,P-,P.,P/,P0,P1,P2-P3-P4-P5-P6-P7-P8-P9
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx-P;-P<.P=.P>.P?.P@.PA.PB.PC.PD.PE.PF/PG/PH/PI/PJ/PK/PL/PM/PN/PO/PP0PQ0PR0PS0PT0PU0PV0PW0PX0PY0PZ1P[1P\1P]1P^1P_1P`1Pa1Pb1Pc1Pd2Pe2Pf2Pg2Ph2Pi2Pj2Pk2Pl2Pm2Pn3Po3Pp3Pq3Pr3Ps3Pt3Pu3Pv3Pw3Px4Py4Pz4P{4P|4P}4P~4P4P4P4P5P5P5P5P5P5P5P5P5P5P6P6P6P6P6P6P6P6P6P6P7P7P7P7P7P7P7P7P7P
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx8P8P8P8P8P8P8P8P8P8P9P9P9P9P9P9P9P9P9P9P:P:P:P:P:P:P:P:P:P:P;P;P;P;P;P;P;P;P;P;P<P<P<P<P<P<P<P<P<P<P=P=P=P=P=P=P=P=P=P=P>P>P>P>P>P>P>P>P>P>P?P?P?P?P?P?P?P?P?P?P@P@P@P@P@P@P@P@P@P@PAPAPAPAPAPAQAQAQAQAQBQ
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxBQBQBQ	BQ
BQBQBQ
BQCQCQCQCQCQCQCQCQCQCQDQDQDQDQDQDQDQDQ DQ!DQ"EQ#EQ$EQ%EQ&EQ'EQ(EQ)EQ*EQ+EQ,FQ-FQ.FQ/FQ0FQ1FQ2FQ3FQ4FQ5FQ6GQ7GQ8GQ9GQ:GQ;GQ<GQ=GQ>GQ?GQ@HQAHQBHQCHQDHQEHQFHQGHQHHQIHQJIQKIQLIQMIQNIQOIQPIQQIQRIQSIQTJQUJQVJQWJQXJQYJQZJQ[JQ\JQ]JQ^KQ_KQ`KQaKQbKQcKQdKQeKQfKQgKQhLQiLQjLQk
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxLQmLQnLQoLQpLQqLQrMQsMQtMQuMQvMQwMQxMQyMQzMQ{MQ|NQ}NQ~NQNQNQNQNQNQNQNQOQOQOQOQOQOQOQOQOQOQPQPQPQPQPQPQPQPQPQPQQQQQQQQQQQQQQQQQQQQQRQRQRQRQRQRQRQRQRQRQSQSQSQSQSQSQSQSQSQSQTQTQTQTQTQTQTQTQTQTQUQUQUQUQUQUQUQUQUQUQVQVQVQVQVQ
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxVQVQVQVQWQWQWQWQWQWQWQWQWQWQXQXQXQXQXQXQXQXQXQXQYQYQYQYQYQYQYQYQYQYQZQZQZQZQZQZQZQZQZQZQ[Q[R[R[R[R[R[R[R[R[R\R	\R
\R\R\R
\R\R\R\R\R]R]R]R]R]R]R]R]R]R]R^R^R^R^R ^R!^R"^R#^R$^R%^R&_R'_R(_R)_R*_R+_R,_R-_R._R/_R0`R1`R2`R3`R4`R5`R6`R7
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx`R9`R:aR;aR<aR=aR>aR?aR@aRAaRBaRCaRDbREbRFbRGbRHbRIbRJbRKbRLbRMbRNcROcRPcRQcRRcRScRTcRUcRVcRWcRXdRYdRZdR[dR\dR]dR^dR_dR`dRadRbeRceRdeReeRfeRgeRheRieRjeRkeRlfRmfRnfRofRpfRqfRrfRsfRtfRufRvgRwgRxgRygRzgR{gR|gR}gR~gRgRhRhRhRhRhRhRhRhRhRhRiRiRiRiRiRiRiRiRiRiRjRjRjRjRjRjRjRjRjR
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxkRkRkRkRkRkRkRkRkRkRlRlRlRlRlRlRlRlRlRlRmRmRmRmRmRmRmRmRmRmRnRnRnRnRnRnRnRnRnRnRoRoRoRoRoRoRoRoRoRoRpRpRpRpRpRpRpRpRpRpRqRqRqRqRqRqRqRqRqRqRrRrRrRrRrRrRrRrRrRrRsRsRsRsRsRsRsRsRsRsRtRtRtRtRtRtRtRtStStSuS
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxuSuSuSuSuS	uS
uSuSvS
vSvSvSvSvSvSvSvSvSwSwSwSwSwSwSwSwSwSwS xS!xS"xS#xS$xS%xS&xS'xS(xS)xS*yS+yS,yS-yS.yS/yS0yS1yS2yS3yS4zS5zS6zS7zS8zS9zS:zS;zS<zS=zS>{S?{S@{SA{SB{SC{SD{SE{SF{SG{SH|SI|SJ|SK|SL|SM|SN|SO|SP|SQ|SR}SS}ST}SU}SV}SW}SX}SY}SZ}S[}S\~S]~S^~S_~S`~Sa~Sb~Sc~Sd~Se~SfSgShSi
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxSkSlSmSnSoSpSqSrSsStSuSvSwSxSySzS{S|S}S~SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSTTTTTTTTTT	T
TTT
TTTTTTTTTTTTTTTTTTT T!T"T#T$T%T&T'T(T)T*T+T,T-T.T/T0T1T2T3T4T5
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxT7T8T9T:T;T<T=T>T?T@TATBTCTDTETFTGTHTITJTKTLTMTNTOTPTQTRTSTTTUTVTWTXTYTZT[T\T]T^T_T`TaTbTcTdTeTfTgThTiTjTkTlTmTnToTpTqTrTsTtTuTvTwTxTyTzT{T|T}T~TTTTTTTTTTTTTTTTTTTTTTTTTTTTT
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTUU
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxUUUUUUU	U
UUU
UUUUUUUUUUUUUUUUUUU U!U"U#U$U%U&U'U(U)U*U+U,U-U.U/U0U1U2U3U4U5U6U7U8U9U:U;U<U=U>U?U@UAUBUCUDUEUFUGUHUIUJUKULUMUNUOUPUQURUSUTUUUVUWUXUYUZU[U\U]U^U_U`UaUbUcUdUeUfUg
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxUiUjUkUlUmUnUoUpUqUrUsUtUuUvUwUxUyUzU{U|U}U~UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUVVVVVVVVVV	V
VVV
VVVVVVVVVVVVVVVVVVV V!V"V#V$V%V&V'V(V)V*V+V,V-V.V/V0V1V2V3
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxV5V6V7V8V9V:V;V<V=V>V?V@VAVBVCVDVEVFVGVHVIVJVKVLVMVNVOVPVQVRVSVTVUVVVWVXVYVZV[V\V]V^V_V`VaVbVcVdVeVfVgVhViVjVkVlVmVnVoVpVqVrVsVtVuVvVwVxVyVzV{V|V}V~VVVVVVVVVVVVVVVVVVVVVVVVVVV
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxWWWWWWWWW	W
WWW
WWWWWWWWWWWWWWWWWWW W!W"W#W$W%W&W'W(W)W*W+W,W-W.W/W0W1W2W3W4W5W6W7W8W9W:W;W<W=W>W?W@WAWBWCWDWEWFWGWHWIWJWKWLWMWNWOWPWQWRWSWTWUWVWWWXWYWZW[W\W]W^W_W`WaWbWcWdWe
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxWgWhWiWjWkWlWmWnWoWpWqWrWsWtWuWvWwWxWyWzW{W|W}W~WWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWW
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWXXXXXXXXXX	X
XXX
XXXXXXXXXXXXXXXXXXX X!X"X#X$X%X&X'X(X)X*X+X,X-X.X/X0X1
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxX3X4X5X6X7X8X9X:X;X<X=X>X?X@XAXBXCXDXEXFXGXHXIXJXKXLXMXNXOXPXQXRXSXTXUXVXWXXXYXZX[X\X]X^X_X`XaXbXcXdXeXfXgXhXiXjXkXlXmXnXoXp	Xq	Xr	Xs	Xt	Xu	Xv	Xw	Xx	Xy	Xz	X{	X|	X}	X~	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	XHK$0<HT`lx ,8DP\ht(4@LXdp|K	XK	XK	YdK	"YK	,Z0K	6ZK	AZK	K[bK	U[K	_\.K	i\K	t\K	~]`K	]K	^,K	^K	^K	_^K	_K	`*K	`K	`K	a\K	aK	b(K
bK

bK
cZK
!cK
+d&K
5dK
@dK
JeXK
TeK
^f$K
hfK
sfK
}gVK
gK
h"K
hK
hK
iTK
iK
j K
jK
jK
kRK
kK
lKlKlKmPK mK*nK4nK?nKIoNKSoK]pKgpKrpK|qLKqKrKr~KrKsJKsKtKt|Kt
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X		X		X		X		X		X		X		X		X		X		X	
X	
X	
X	
X	
X	
X	
X	
X	
X	
X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	X	
X	
X	
X	
X	
X	
X	
X	
X	
X	
X	X
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	X	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y		Y
	Y	Y	Y
	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y 	Y!	Y"	Y#	Y$	Y%	Y&	Y'	Y(	Y)	Y*	Y+	Y,	Y-	Y.	Y/	Y0	Y1	Y2	Y3	Y4	Y5	Y6	Y7	Y8	Y9	Y:	Y;	Y<	Y=	Y>	Y?	Y@	YA	YB	YC	YD	YE	YF	YG	YH	YI	YJ	YK	YL	YM	YN	YO	YP	YQ	YR	YS	YT	YU	YV	YW	YX	YY	YZ	Y[	Y\	Y]	Y^	Y_	Y`	Ya	Yb	Yc
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	Ye	Yf	Yg	Yh	Yi	Yj	Yk	Yl	Ym	Yn	Yo	Yp	Yq	Yr	Ys	Yt	Yu	Yv	Yw	Yx	Yy	Yz	Y{	Y|	Y}	Y~	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	Y	 Y	 Y	 Y	 Y	 Y	 Y	 Y	 Y	 Y	 Y	!Y	!Y	!Y	!Y	!Y	!Y	!Y	!Y	!Y	!Y	"Y	"Y	"Y	"Y	"Y
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	"Y	"Y	"Y	"Y	#Y	#Y	#Y	#Y	#Y	#Y	#Y	#Y	#Y	#Y	$Y	$Y	$Y	$Y	$Y	$Y	$Y	$Y	$Y	$Y	%Y	%Y	%Y	%Y	%Y	%Y	%Y	%Y	%Y	%Y	&Y	&Y	&Y	&Y	&Y	&Y	&Y	&Y	&Y	&Y	'Y	'Y	'Y	'Y	'Y	'Y	'Y	'Y	'Y	'Z	(Z	(Z	(Z	(Z	(Z	(Z	(Z	(Z	(Z		(Z
	)Z	)Z	)Z
	)Z	)Z	)Z	)Z	)Z	)Z	)Z	*Z	*Z	*Z	*Z	*Z	*Z	*Z	*Z	*Z	*Z	+Z	+Z 	+Z!	+Z"	+Z#	+Z$	+Z%	+Z&	+Z'	+Z(	,Z)	,Z*	,Z+	,Z,	,Z-	,Z.	,Z/
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	,Z1	,Z2	-Z3	-Z4	-Z5	-Z6	-Z7	-Z8	-Z9	-Z:	-Z;	-Z<	.Z=	.Z>	.Z?	.Z@	.ZA	.ZB	.ZC	.ZD	.ZE	.ZF	/ZG	/ZH	/ZI	/ZJ	/ZK	/ZL	/ZM	/ZN	/ZO	/ZP	0ZQ	0ZR	0ZS	0ZT	0ZU	0ZV	0ZW	0ZX	0ZY	0ZZ	1Z[	1Z\	1Z]	1Z^	1Z_	1Z`	1Za	1Zb	1Zc	1Zd	2Ze	2Zf	2Zg	2Zh	2Zi	2Zj	2Zk	2Zl	2Zm	2Zn	3Zo	3Zp	3Zq	3Zr	3Zs	3Zt	3Zu	3Zv	3Zw	3Zx	4Zy	4Zz	4Z{	4Z|	4Z}	4Z~	4Z	4Z	4Z	4Z	5Z	5Z	5Z	5Z	5Z	5Z	5Z	5Z	5Z	5Z	6Z	6Z	6Z	6Z	6Z	6Z	6Z	6Z	6Z
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	7Z	7Z	7Z	7Z	7Z	7Z	7Z	7Z	7Z	7Z	8Z	8Z	8Z	8Z	8Z	8Z	8Z	8Z	8Z	8Z	9Z	9Z	9Z	9Z	9Z	9Z	9Z	9Z	9Z	9Z	:Z	:Z	:Z	:Z	:Z	:Z	:Z	:Z	:Z	:Z	;Z	;Z	;Z	;Z	;Z	;Z	;Z	;Z	;Z	;Z	<Z	<Z	<Z	<Z	<Z	<Z	<Z	<Z	<Z	<Z	=Z	=Z	=Z	=Z	=Z	=Z	=Z	=Z	=Z	=Z	>Z	>Z	>Z	>Z	>Z	>Z	>Z	>Z	>Z	>Z	?Z	?Z	?Z	?Z	?Z	?Z	?Z	?Z	?Z	?Z	@Z	@Z	@Z	@Z	@Z	@Z	@Z	@Z	@Z	@Z	AZ
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	AZ	AZ	AZ	A[	A[	A[	A[	A[	B[	B[	B[	B[	B[		B[
	B[	B[	B[
	B[	C[	C[	C[	C[	C[	C[	C[	C[	C[	C[	D[	D[	D[	D[	D[	D[	D[	D[ 	D[!	D["	E[#	E[$	E[%	E[&	E['	E[(	E[)	E[*	E[+	E[,	F[-	F[.	F[/	F[0	F[1	F[2	F[3	F[4	F[5	F[6	G[7	G[8	G[9	G[:	G[;	G[<	G[=	G[>	G[?	G[@	H[A	H[B	H[C	H[D	H[E	H[F	H[G	H[H	H[I	H[J	I[K	I[L	I[M	I[N	I[O	I[P	I[Q	I[R	I[S	I[T	J[U	J[V	J[W	J[X	J[Y	J[Z	J[[	J[\	J[]	J[^	K[_	K[`	K[a
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	K[c	K[d	K[e	K[f	K[g	K[h	L[i	L[j	L[k	L[l	L[m	L[n	L[o	L[p	L[q	L[r	M[s	M[t	M[u	M[v	M[w	M[x	M[y	M[z	M[{	M[|	N[}	N[~	N[	N[	N[	N[	N[	N[	N[	N[	O[	O[	O[	O[	O[	O[	O[	O[	O[	O[	P[	P[	P[	P[	P[	P[	P[	P[	P[	P[	Q[	Q[	Q[	Q[	Q[	Q[	Q[	Q[	Q[	Q[	R[	R[	R[	R[	R[	R[	R[	R[	R[	R[	S[	S[	S[	S[	S[	S[	S[	S[	S[	S[	T[	T[	T[	T[	T[	T[	T[	T[	T[	T[	U[	U[	U[	U[	U[
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	U[	U[	U[	U[	V[	V[	V[	V[	V[	V[	V[	V[	V[	V[	W[	W[	W[	W[	W[	W[	W[	W[	W[	W[	X[	X[	X[	X[	X[	X[	X[	X[	X[	X[	Y[	Y[	Y[	Y[	Y[	Y[	Y[	Y[	Y[	Y[	Z[	Z[	Z[	Z[	Z[	Z[	Z[	Z[	Z[	Z[	[[	[\	[\	[\	[\	[\	[\	[\	[\	[\	\\		\\
	\\	\\	\\
	\\	\\	\\	\\	\\	]\	]\	]\	]\	]\	]\	]\	]\	]\	]\	^\	^\	^\	^\ 	^\!	^\"	^\#	^\$	^\%	^\&	_\'	_\(	_\)	_\*	_\+	_\,	_\-
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	_\/	_\0	`\1	`\2	`\3	`\4	`\5	`\6	`\7	`\8	`\9	`\:	a\;	a\<	a\=	a\>	a\?	a\@	a\A	a\B	a\C	a\D	b\E	b\F	b\G	b\H	b\I	b\J	b\K	b\L	b\M	b\N	c\O	c\P	c\Q	c\R	c\S	c\T	c\U	c\V	c\W	c\X	d\Y	d\Z	d\[	d\\	d\]	d\^	d\_	d\`	d\a	d\b	e\c	e\d	e\e	e\f	e\g	e\h	e\i	e\j	e\k	e\l	f\m	f\n	f\o	f\p	f\q	f\r	f\s	f\t	f\u	f\v	g\w	g\x	g\y	g\z	g\{	g\|	g\}	g\~	g\	g\	h\	h\	h\	h\	h\	h\	h\	h\	h\	h\	i\	i\	i\	i\	i\	i\	i\	i\	i\
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	j\	j\	j\	j\	j\	j\	j\	j\	j\	j\	k\	k\	k\	k\	k\	k\	k\	k\	k\	k\	l\	l\	l\	l\	l\	l\	l\	l\	l\	l\	m\	m\	m\	m\	m\	m\	m\	m\	m\	m\	n\	n\	n\	n\	n\	n\	n\	n\	n\	n\	o\	o\	o\	o\	o\	o\	o\	o\	o\	o\	p\	p\	p\	p\	p\	p\	p\	p\	p\	p\	q\	q\	q\	q\	q\	q\	q\	q\	q\	q\	r\	r\	r\	r\	r\	r\	r\	r\	r\	r\	s\	s\	s\	s\	s\	s\	s\	s\	s\	s\	t\
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	t\	t\	t\	t\	t\	t]	t]	t]	u]	u]	u]	u]	u]	u]	u]		u]
	u]	u]	v]
	v]	v]	v]	v]	v]	v]	v]	v]	v]	w]	w]	w]	w]	w]	w]	w]	w]	w]	w] 	x]!	x]"	x]#	x]$	x]%	x]&	x]'	x](	x])	x]*	y]+	y],	y]-	y].	y]/	y]0	y]1	y]2	y]3	y]4	z]5	z]6	z]7	z]8	z]9	z]:	z];	z]<	z]=	z]>	{]?	{]@	{]A	{]B	{]C	{]D	{]E	{]F	{]G	{]H	|]I	|]J	|]K	|]L	|]M	|]N	|]O	|]P	|]Q	|]R	}]S	}]T	}]U	}]V	}]W	}]X	}]Y	}]Z	}][	}]\	~]]	~]^	~]_
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	~]a	~]b	~]c	~]d	~]e	~]f	]g	]h	]i	]j	]k	]l	]m	]n	]o	]p	]q	]r	]s	]t	]u	]v	]w	]x	]y	]z	]{	]|	]}	]~	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	]	^	^	^	^	^	^	^	^	^	^		^
	^	^	^
	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^ 	^!	^"	^#	^$	^%	^&	^'	^(	^)	^*	^+
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	^-	^.	^/	^0	^1	^2	^3	^4	^5	^6	^7	^8	^9	^:	^;	^<	^=	^>	^?	^@	^A	^B	^C	^D	^E	^F	^G	^H	^I	^J	^K	^L	^M	^N	^O	^P	^Q	^R	^S	^T	^U	^V	^W	^X	^Y	^Z	^[	^\	^]	^^	^_	^`	^a	^b	^c	^d	^e	^f	^g	^h	^i	^j	^k	^l	^m	^n	^o	^p	^q	^r	^s	^t	^u	^v	^w	^x	^y	^z	^{	^|	^}	^~	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^	^
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	^	^	^	^	^	^	^	_	_	_	_	_	_	_	_	_	_		_
	_	_	_
	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_ 	_!	_"	_#	_$	_%	_&	_'	_(	_)	_*	_+	_,	_-	_.	_/	_0	_1	_2	_3	_4	_5	_6	_7	_8	_9	_:	_;	_<	_=	_>	_?	_@	_A	_B	_C	_D	_E	_F	_G	_H	_I	_J	_K	_L	_M	_N	_O	_P	_Q	_R	_S	_T	_U	_V	_W	_X	_Y	_Z	_[	_\	_]
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	__	_`	_a	_b	_c	_d	_e	_f	_g	_h	_i	_j	_k	_l	_m	_n	_o	_p	_q	_r	_s	_t	_u	_v	_w	_x	_y	_z	_{	_|	_}	_~	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	_	`	`	`	`	`	`	`	`	`	`		`
	`	`	`
	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	` 	`!	`"	`#	`$	`%	`&	`'	`(	`)
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	`+	`,	`-	`.	`/	`0	`1	`2	`3	`4	`5	`6	`7	`8	`9	`:	`;	`<	`=	`>	`?	`@	`A	`B	`C	`D	`E	`F	`G	`H	`I	`J	`K	`L	`M	`N	`O	`P	`Q	`R	`S	`T	`U	`V	`W	`X	`Y	`Z	`[	`\	`]	`^	`_	``	`a	`b	`c	`d	`e	`f	`g	`h	`i	`j	`k	`l	`m	`n	`o	`p	`q	`r	`s	`t	`u	`v	`w	`x	`y	`z	`{	`|	`}	`~	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`	`
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	`	`	`	`	`	`	`	`	`	a	a	a	a	a	a	a	a	a	a		a
	a	a	a
	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a 	a!	a"	a#	a$	a%	a&	a'	a(	a)	a*	a+	a,	a-	a.	a/	a0	a1	a2	a3	a4	a5	a6	a7	a8	a9	a:	a;	a<	a=	a>	a?	a@	aA	aB	aC	aD	aE	aF	aG	aH	aI	aJ	aK	aL	aM	aN	aO	aP	aQ	aR	aS	aT	aU	aV	aW	aX	aY	aZ	a[
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	a]	a^	a_	a`	aa	ab	ac	ad	ae	af	ag	ah	ai	aj	ak	al	am	an	ao	ap	aq	ar	as	at	au	av	aw	ax	ay	az	a{	a|	a}	a~	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	a	b	b	b	b	b	b	b	b	b	b		b
	b	b	b
	b	b	b	b	b	b	b	b	b	b	b	b	b	b	b	b	b	b	b 	b!	b"	b#	b$	b%	b&	b'
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx	b)	b*	b+	b,	b-	b.	b/	b0	b1	b2	b3	b4	b5	b6	b7	b8	b9	b:	b;	b<	b=	b>	b?	b@	bA	bB	bC	bD	bE	bF	bG	bH	bI	bJ	bK	bL	bM	bN	bO	bP	bQ	bR	bS	bT	bU	bV	bW	bX	bY	bZ	b[	b\	b]	b^	b_	b`	ba	bb	bc	bd	be	bf	bg	bh	bi	bj	bk	bl	bm	bn	bo	bp
bq
br
bs
bt
bu
bv
bw
bx
by
bz
b{
b|
b}
b~
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
	b
	b
	b
	b
	b
	b
	b
	b
	b
	b

b

b

b

b

b

b

b

b

b

b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b
b

b
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx

b

b

b

b

b

b

b

b
b
b
b
c
c
c
c
c
c
c
c
c
c	
c

c
c
c

c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c 
c!
c"
c#
c$
c%
c&
c'
c(
c)
c*
c+
c,
c-
c.
c/
c0
c1
c2
c3
c4
c5
c6
c7
c8
c9
c:
c;
c<
c=
c>
c?
c@
cA
cB
cC
cD
cE
cF
cG
cH
cI
cJ
cK
cL
cM
cN
cO
cP
cQ
cR
cS
cT
cU
cV
cW
cX
cY
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
c[
c\
c]
c^
c_
c`
ca
cb
cc
cd
ce
cf
cg
ch
ci
cj
ck
cl
cm
cn
co
cp
cq
cr
cs
ct
cu
cv
cw
cx
cy
cz
c{
c|
c}
c~
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
c
 c
 c
 c
 c
 c
 c
 c
 c
 c
 c
!c
!c
!c
!c
!c
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
!c
!c
!c
!c
"c
"c
"c
"c
"c
"c
"c
"c
"c
"c
#c
#c
#c
#c
#c
#c
#c
#c
#c
#c
$c
$c
$c
$c
$c
$c
$c
$c
$c
$c
%c
%c
%c
%c
%c
%c
%c
%c
%c
%c
&c
&c
&c
&c
&c
&c
&c
&c
&c
&c
'c
'c
'c
'c
'c
'c
'c
'c
'c
'd
(d
(d
(d
(d
(d
(d
(d
(d
(d	
(d

)d
)d
)d

)d
)d
)d
)d
)d
)d
)d
*d
*d
*d
*d
*d
*d
*d
*d
*d
*d
+d
+d 
+d!
+d"
+d#
+d$
+d%
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
+d'
+d(
,d)
,d*
,d+
,d,
,d-
,d.
,d/
,d0
,d1
,d2
-d3
-d4
-d5
-d6
-d7
-d8
-d9
-d:
-d;
-d<
.d=
.d>
.d?
.d@
.dA
.dB
.dC
.dD
.dE
.dF
/dG
/dH
/dI
/dJ
/dK
/dL
/dM
/dN
/dO
/dP
0dQ
0dR
0dS
0dT
0dU
0dV
0dW
0dX
0dY
0dZ
1d[
1d\
1d]
1d^
1d_
1d`
1da
1db
1dc
1dd
2de
2df
2dg
2dh
2di
2dj
2dk
2dl
2dm
2dn
3do
3dp
3dq
3dr
3ds
3dt
3du
3dv
3dw
3dx
4dy
4dz
4d{
4d|
4d}
4d~
4d
4d
4d
4d
5d
5d
5d
5d
5d
5d
5d
5d
5d
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
6d
6d
6d
6d
6d
6d
6d
6d
6d
6d
7d
7d
7d
7d
7d
7d
7d
7d
7d
7d
8d
8d
8d
8d
8d
8d
8d
8d
8d
8d
9d
9d
9d
9d
9d
9d
9d
9d
9d
9d
:d
:d
:d
:d
:d
:d
:d
:d
:d
:d
;d
;d
;d
;d
;d
;d
;d
;d
;d
;d
<d
<d
<d
<d
<d
<d
<d
<d
<d
<d
=d
=d
=d
=d
=d
=d
=d
=d
=d
=d
>d
>d
>d
>d
>d
>d
>d
>d
>d
>d
?d
?d
?d
?d
?d
?d
?d
?d
?d
?d
@d
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
@d
@d
@d
@d
@d
@d
@d
@d
Ad
Ad
Ad
Ad
Ad
Ae
Ae
Ae
Ae
Ae
Be
Be
Be
Be
Be	
Be

Be
Be
Be

Be
Ce
Ce
Ce
Ce
Ce
Ce
Ce
Ce
Ce
Ce
De
De
De
De
De
De
De
De 
De!
De"
Ee#
Ee$
Ee%
Ee&
Ee'
Ee(
Ee)
Ee*
Ee+
Ee,
Fe-
Fe.
Fe/
Fe0
Fe1
Fe2
Fe3
Fe4
Fe5
Fe6
Ge7
Ge8
Ge9
Ge:
Ge;
Ge<
Ge=
Ge>
Ge?
Ge@
HeA
HeB
HeC
HeD
HeE
HeF
HeG
HeH
HeI
HeJ
IeK
IeL
IeM
IeN
IeO
IeP
IeQ
IeR
IeS
IeT
JeU
JeV
JeW
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
JeY
JeZ
Je[
Je\
Je]
Je^
Ke_
Ke`
Kea
Keb
Kec
Ked
Kee
Kef
Keg
Keh
Lei
Lej
Lek
Lel
Lem
Len
Leo
Lep
Leq
Ler
Mes
Met
Meu
Mev
Mew
Mex
Mey
Mez
Me{
Me|
Ne}
Ne~
Ne
Ne
Ne
Ne
Ne
Ne
Ne
Ne
Oe
Oe
Oe
Oe
Oe
Oe
Oe
Oe
Oe
Oe
Pe
Pe
Pe
Pe
Pe
Pe
Pe
Pe
Pe
Pe
Qe
Qe
Qe
Qe
Qe
Qe
Qe
Qe
Qe
Qe
Re
Re
Re
Re
Re
Re
Re
Re
Re
Re
Se
Se
Se
Se
Se
Se
Se
Se
Se
Se
Te
Te
Te
Te
Te
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
Te
Te
Te
Te
Ue
Ue
Ue
Ue
Ue
Ue
Ue
Ue
Ue
Ue
Ve
Ve
Ve
Ve
Ve
Ve
Ve
Ve
Ve
Ve
We
We
We
We
We
We
We
We
We
We
Xe
Xe
Xe
Xe
Xe
Xe
Xe
Xe
Xe
Xe
Ye
Ye
Ye
Ye
Ye
Ye
Ye
Ye
Ye
Ye
Ze
Ze
Ze
Ze
Ze
Ze
Ze
Ze
Ze
Ze
[e
[f
[f
[f
[f
[f
[f
[f
[f
[f
\f	
\f

\f
\f
\f

\f
\f
\f
\f
\f
]f
]f
]f
]f
]f
]f
]f
]f
]f
]f
^f
^f
^f
^f 
^f!
^f"
^f#
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
^f%
^f&
_f'
_f(
_f)
_f*
_f+
_f,
_f-
_f.
_f/
_f0
`f1
`f2
`f3
`f4
`f5
`f6
`f7
`f8
`f9
`f:
af;
af<
af=
af>
af?
af@
afA
afB
afC
afD
bfE
bfF
bfG
bfH
bfI
bfJ
bfK
bfL
bfM
bfN
cfO
cfP
cfQ
cfR
cfS
cfT
cfU
cfV
cfW
cfX
dfY
dfZ
df[
df\
df]
df^
df_
df`
dfa
dfb
efc
efd
efe
eff
efg
efh
efi
efj
efk
efl
ffm
ffn
ffo
ffp
ffq
ffr
ffs
fft
ffu
ffv
gfw
gfx
gfy
gfz
gf{
gf|
gf}
gf~
gf
gf
hf
hf
hf
hf
hf
hf
hf
hf
hf
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
if
if
if
if
if
if
if
if
if
if
jf
jf
jf
jf
jf
jf
jf
jf
jf
jf
kf
kf
kf
kf
kf
kf
kf
kf
kf
kf
lf
lf
lf
lf
lf
lf
lf
lf
lf
lf
mf
mf
mf
mf
mf
mf
mf
mf
mf
mf
nf
nf
nf
nf
nf
nf
nf
nf
nf
nf
of
of
of
of
of
of
of
of
of
of
pf
pf
pf
pf
pf
pf
pf
pf
pf
pf
qf
qf
qf
qf
qf
qf
qf
qf
qf
qf
rf
rf
rf
rf
rf
rf
rf
rf
rf
rf
sf
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
sf
sf
sf
sf
sf
sf
sf
sf
tf
tf
tf
tf
tf
tf
tf
tg
tg
tg
ug
ug
ug
ug
ug
ug
ug	
ug

ug
ug
vg

vg
vg
vg
vg
vg
vg
vg
vg
vg
wg
wg
wg
wg
wg
wg
wg
wg
wg
wg 
xg!
xg"
xg#
xg$
xg%
xg&
xg'
xg(
xg)
xg*
yg+
yg,
yg-
yg.
yg/
yg0
yg1
yg2
yg3
yg4
zg5
zg6
zg7
zg8
zg9
zg:
zg;
zg<
zg=
zg>
{g?
{g@
{gA
{gB
{gC
{gD
{gE
{gF
{gG
{gH
|gI
|gJ
|gK
|gL
|gM
|gN
|gO
|gP
|gQ
|gR
}gS
}gT
}gU
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
}gW
}gX
}gY
}gZ
}g[
}g\
~g]
~g^
~g_
~g`
~ga
~gb
~gc
~gd
~ge
~gf
gg
gh
gi
gj
gk
gl
gm
gn
go
gp
gq
gr
gs
gt
gu
gv
gw
gx
gy
gz
g{
g|
g}
g~
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
g
h
h
h
h
h
h
h
h
h
h	
h

h
h
h

h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h 
h!
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
h#
h$
h%
h&
h'
h(
h)
h*
h+
h,
h-
h.
h/
h0
h1
h2
h3
h4
h5
h6
h7
h8
h9
h:
h;
h<
h=
h>
h?
h@
hA
hB
hC
hD
hE
hF
hG
hH
hI
hJ
hK
hL
hM
hN
hO
hP
hQ
hR
hS
hT
hU
hV
hW
hX
hY
hZ
h[
h\
h]
h^
h_
h`
ha
hb
hc
hd
he
hf
hg
hh
hi
hj
hk
hl
hm
hn
ho
hp
hq
hr
hs
ht
hu
hv
hw
hx
hy
hz
h{
h|
h}
h~
h
h
h
h
h
h
h
h
h
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
h
i
i
i
i
i
i
i
i
i
i	
i

i
i
i

i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i 
i!
i"
i#
i$
i%
i&
i'
i(
i)
i*
i+
i,
i-
i.
i/
i0
i1
i2
i3
i4
i5
i6
i7
i8
i9
i:
i;
i<
i=
i>
i?
i@
iA
iB
iC
iD
iE
iF
iG
iH
iI
iJ
iK
iL
iM
iN
iO
iP
iQ
iR
iS
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
iU
iV
iW
iX
iY
iZ
i[
i\
i]
i^
i_
i`
ia
ib
ic
id
ie
if
ig
ih
ii
ij
ik
il
im
in
io
ip
iq
ir
is
it
iu
iv
iw
ix
iy
iz
i{
i|
i}
i~
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
i
j
j
j
j
j
j
j
j
j
j	
j

j
j
j

j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
j!
j"
j#
j$
j%
j&
j'
j(
j)
j*
j+
j,
j-
j.
j/
j0
j1
j2
j3
j4
j5
j6
j7
j8
j9
j:
j;
j<
j=
j>
j?
j@
jA
jB
jC
jD
jE
jF
jG
jH
jI
jJ
jK
jL
jM
jN
jO
jP
jQ
jR
jS
jT
jU
jV
jW
jX
jY
jZ
j[
j\
j]
j^
j_
j`
ja
jb
jc
jd
je
jf
jg
jh
ji
jj
jk
jl
jm
jn
jo
jp
jq
jr
js
jt
ju
jv
jw
jx
jy
jz
j{
j|
j}
j~
j
j
j
j
j
j
j
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
j
k
k
k
k
k
k
k
k
k
k	
k

k
k
k

k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k 
k!
k"
k#
k$
k%
k&
k'
k(
k)
k*
k+
k,
k-
k.
k/
k0
k1
k2
k3
k4
k5
k6
k7
k8
k9
k:
k;
k<
k=
k>
k?
k@
kA
kB
kC
kD
kE
kF
kG
kH
kI
kJ
kK
kL
kM
kN
kO
kP
kQ
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
kS
kT
kU
kV
kW
kX
kY
kZ
k[
k\
k]
k^
k_
k`
ka
kb
kc
kd
ke
kf
kg
kh
ki
kj
kk
kl
km
kn
ko
kp
kq
kr
ks
kt
ku
kv
kw
kx
ky
kz
k{
k|
k}
k~
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
k
l
l
l
l
l
l
l
l
l
l	
l

l
l
l

l
l
l
l
l
l
l
l
l
l
l
l
l
l
l
l
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx
l
l 
l!
l"
l#
l$
l%
l&
l'
l(
l)
l*
l+
l,
l-
l.
l/
l0
l1
l2
l3
l4
l5
l6
l7
l8
l9
l:
l;
l<
l=
l>
l?
l@
lA
lB
lC
lD
lE
lF
lG
lH
lI
lJ
lK
lL
lM
lN
lO
lP
lQ
lR
lS
lT
lU
lV
lW
lX
lY
lZ
l[
l\
l]
l^
l_
l`
la
lb
lc
ld
le
lf
lg
lh
li
lj
lk
ll
lm
ln
lo
lplqlrlsltlulvlwlxlylzl{l|l}l~lllll
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll	l	l	l	l	l	l	l	l	l	l
l
l
l
l
l
l
l
l
l
llllllllllll
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxllllllll
l
l
l
l
l
l
l
l
l
llllmmmmmmmmmm	m
mmm
mmmmmmmmmmmmmmmmmmm m!m"m#m$m%m&m'm(m)m*m+m,m-m.m/m0m1m2m3m4m5m6m7m8m9m:m;m<m=m>m?m@mAmBmCmDmEmFmGmHmImJmKmLmMmNmO
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxmQmRmSmTmUmVmWmXmYmZm[m\m]m^m_m`mambmcmdmemfmgmhmimjmkmlmmmnmompmqmrmsmtmumvmwmxmymzm{m|m}m~mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm m m m m m
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx m m m m!m!m!m!m!m!m!m!m!m!m"m"m"m"m"m"m"m"m"m"m#m#m#m#m#m#m#m#m#m#m$m$m$m$m$m$m$m$m$m$m%m%m%m%m%m%m%m%m%m%m&m&m&m&m&m&m&m&m&m&m'm'm'm'm'm'm'm'm'm'n(n(n(n(n(n(n(n(n(n	(n
)n)n)n
)n)n)n)n)n)n)n*n*n*n*n*n*n*n
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx*n*n+n+n +n!+n"+n#+n$+n%+n&+n'+n(,n),n*,n+,n,,n-,n.,n/,n0,n1,n2-n3-n4-n5-n6-n7-n8-n9-n:-n;-n<.n=.n>.n?.n@.nA.nB.nC.nD.nE.nF/nG/nH/nI/nJ/nK/nL/nM/nN/nO/nP0nQ0nR0nS0nT0nU0nV0nW0nX0nY0nZ1n[1n\1n]1n^1n_1n`1na1nb1nc1nd2ne2nf2ng2nh2ni2nj2nk2nl2nm2nn3no3np3nq3nr3ns3nt3nu3nv3nw3nx4ny4nz4n{4n|4n}4n~4n4n4n
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx5n5n5n5n5n5n5n5n5n5n6n6n6n6n6n6n6n6n6n6n7n7n7n7n7n7n7n7n7n7n8n8n8n8n8n8n8n8n8n8n9n9n9n9n9n9n9n9n9n9n:n:n:n:n:n:n:n:n:n:n;n;n;n;n;n;n;n;n;n;n<n<n<n<n<n<n<n<n<n<n=n=n=n=n=n=n=n=n=n=n>n>n>n>n>n>n>n>n>n>n?n
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx?n?n?n?n?n?n?n?n@n@n@n@n@n@n@n@n@n@nAnAnAnAnAnAoAoAoAoAoBoBoBoBoBo	Bo
BoBoBo
BoCoCoCoCoCoCoCoCoCoCoDoDoDoDoDoDoDoDo Do!Do"Eo#Eo$Eo%Eo&Eo'Eo(Eo)Eo*Eo+Eo,Fo-Fo.Fo/Fo0Fo1Fo2Fo3Fo4Fo5Fo6Go7Go8Go9Go:Go;Go<Go=Go>Go?Go@HoAHoBHoCHoDHoEHoFHoGHoHHoIHoJIoKIoLIoM
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxIoOIoPIoQIoRIoSIoTJoUJoVJoWJoXJoYJoZJo[Jo\Jo]Jo^Ko_Ko`KoaKobKocKodKoeKofKogKohLoiLojLokLolLomLonLooLopLoqLorMosMotMouMovMowMoxMoyMozMo{Mo|No}No~NoNoNoNoNoNoNoNoOoOoOoOoOoOoOoOoOoOoPoPoPoPoPoPoPoPoPoPoQoQoQoQoQoQoQoQoQoQoRoRoRoRoRoRoRoRoRoRoSoSoSoSoSo
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxSoSoSoSoToToToToToToToToToToUoUoUoUoUoUoUoUoUoUoVoVoVoVoVoVoVoVoVoVoWoWoWoWoWoWoWoWoWoWoXoXoXoXoXoXoXoXoXoXoYoYoYoYoYoYoYoYoYoYoZoZoZoZoZoZoZoZoZoZo[o[p[p[p[p[p[p[p[p[p\p	\p
\p\p\p
\p\p\p\p\p]p]p]p]p]p]p]p
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx]p]p^p^p^p^p ^p!^p"^p#^p$^p%^p&_p'_p(_p)_p*_p+_p,_p-_p._p/_p0`p1`p2`p3`p4`p5`p6`p7`p8`p9`p:ap;ap<ap=ap>ap?ap@apAapBapCapDbpEbpFbpGbpHbpIbpJbpKbpLbpMbpNcpOcpPcpQcpRcpScpTcpUcpVcpWcpXdpYdpZdp[dp\dp]dp^dp_dp`dpadpbepcepdepeepfepgephepiepjepkeplfpmfpnfpofppfpqfprfpsfptfpufpvgpwgpxgpygpzgp{gp|gp}gp~gp
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxhphphphphphphphphphpipipipipipipipipipipjpjpjpjpjpjpjpjpjpjpkpkpkpkpkpkpkpkpkpkplplplplplplplplplplpmpmpmpmpmpmpmpmpmpmpnpnpnpnpnpnpnpnpnpnpopopopopopopopopopopppppppppppppppppppppqpqpqpqpqpqpqpqpqpqprp
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxrprprprprprprprpspspspspspspspspspsptptptptptptptptqtqtquququququququq	uq
uquqvq
vqvqvqvqvqvqvqvqvqwqwqwqwqwqwqwqwqwqwq xq!xq"xq#xq$xq%xq&xq'xq(xq)xq*yq+yq,yq-yq.yq/yq0yq1yq2yq3yq4zq5zq6zq7zq8zq9zq:zq;zq<zq=zq>{q?{q@{qA{qB{qC{qD{qE{qF{qG{qH|qI|qJ|qK
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx|qM|qN|qO|qP|qQ|qR}qS}qT}qU}qV}qW}qX}qY}qZ}q[}q\~q]~q^~q_~q`~qa~qb~qc~qd~qe~qfqgqhqiqjqkqlqmqnqoqpqqqrqsqtquqvqwqxqyqzq{q|q}q~qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqrrrrrrrrrr	r
rrr
rrrrrrrrrr
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxrrrrrrrr r!r"r#r$r%r&r'r(r)r*r+r,r-r.r/r0r1r2r3r4r5r6r7r8r9r:r;r<r=r>r?r@rArBrCrDrErFrGrHrIrJrKrLrMrNrOrPrQrRrSrTrUrVrWrXrYrZr[r\r]r^r_r`rarbrcrdrerfrgrhrirjrkrlrmrnrorprqrrrsrtrurvrwrxryrzr{r|r}
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxrrrrrrrrrrrrrrrrrrrrrrrrrrrssssssssss	s
sss
sssssssssssssssssss s!s"s#s$s%s&s's(s)s*s+s,s-s.s/s0s1s2s3s4s5s6s7s8s9s:s;s<s=s>s?s@sAsBsCsDsEsFsGsHsI
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxsKsLsMsNsOsPsQsRsSsTsUsVsWsXsYsZs[s\s]s^s_s`sasbscsdsesfsgshsisjskslsmsnsospsqsrssstsusvswsxsyszs{s|s}s~sssssssssssssssssssssssssssssssssssssssssssssssss
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssstttttttttt	t
ttt
tttttttt
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxtttttttttt t!t"t#t$t%t&t't(t)t*t+t,t-t.t/t0t1t2t3t4t5t6t7t8t9t:t;t<t=t>t?t@tAtBtCtDtEtFtGtHtItJtKtLtMtNtOtPtQtRtStTtUtVtWtXtYtZt[t\t]t^t_t`tatbtctdtetftgthtitjtktltmtntotptqtrtstttutvtwtxtytzt{
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxt}t~ttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttt
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxtttttttttttttttttttttttttttttuuuuuuuuuu	u
uuu
uuuuuuuuuuuuuuuuuuu u!u"u#u$u%u&u'u(u)u*u+u,u-u.u/u0u1u2u3u4u5u6u7u8u9u:u;u<u=u>u?u@uAuBuCuDuEuFuG
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxuIuJuKuLuMuNuOuPuQuRuSuTuUuVuWuXuYuZu[u\u]u^u_u`uaubucudueufuguhuiujukulumunuoupuqurusutuuuvuwuxuyuzu{u|u}u~uuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuEL")5AMYeq},9FS`mz	#0=JWdq~KuKvKvzKvKwFKwK)xK3xxK>xKHyDKRyK\zKfzvKqzK{{BK{K|K|tK|K}@K}K~K~rK~K>KK	KfK
K
 K
}K
$K
-7K
6K
@L
INL
RL
[L
eeL
nL
wL
|L
L
6L	
L

L
ML
L

L
dL
L
L
{L
L
5LLLLLL(L1cL;LDLMzLWL`4LiL rL!|K
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuvvvvvvvvvv	v
vvv
vvvvvv
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxvvvvvvvvvvvv v!v"v#v$v%v&v'v(v)v*v+v,v-v.v/v0v1v2v3v4v5v6v7v8v9v:v;v<v=v>v?v@vAvBvCvDvEvFvGvHvIvJvKvLvMvNvOvPvQvRvSvTvUvVvWvXvYvZv[v\v]v^v_v`vavbvcvdvevfvgvhvivjvkvlvmvnvovpvqvrvsvtvuvvvwvxvy
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxv{v|v}v~vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv	v	v	v	v	v	v	v	v	v	v
v
v
v
v
v
v
v
v
v
vv
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxvvvvvvvvvvvvvvvvvv
v
v
v
v
v
v
v
v
v
vvvvwwwwwwwwww	w
www
wwwwwwwwwwwwwwwwwww w!w"w#w$w%w&w'w(w)w*w+w,w-w.w/w0w1w2w3w4w5w6w7w8w9w:w;w<w=w>w?w@wAwBwCwDwE
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxwGwHwIwJwKwLwMwNwOwPwQwRwSwTwUwVwWwXwYwZw[w\w]w^w_w`wawbwcwdwewfwgwhwiwjwkwlwmwnwowpwqwrwswtwuwvwwwxwywzw{w|w}w~wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxwwww w w w w w w w w w w!w!w!w!w!w!w!w!w!w!w"w"w"w"w"w"w"w"w"w"w#w#w#w#w#w#w#w#w#w#w$w$w$w$w$w$w$w$w$w$w%w%w%w%w%w%w%w%w%w%w&w&w&w&w&w&w&w&w&w&w'w'w'w'w'w'w'w'w'w'x(x(x(x(x(x(x(x(x(x	(x
)x)x)x
)x)x)x)x
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx)x)x*x*x*x*x*x*x*x*x*x*x+x+x +x!+x"+x#+x$+x%+x&+x'+x(,x),x*,x+,x,,x-,x.,x/,x0,x1,x2-x3-x4-x5-x6-x7-x8-x9-x:-x;-x<.x=.x>.x?.x@.xA.xB.xC.xD.xE.xF/xG/xH/xI/xJ/xK/xL/xM/xN/xO/xP0xQ0xR0xS0xT0xU0xV0xW0xX0xY0xZ1x[1x\1x]1x^1x_1x`1xa1xb1xc1xd2xe2xf2xg2xh2xi2xj2xk2xl2xm2xn3xo3xp3xq3xr3xs3xt3xu3xv3xw
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx4xy4xz4x{4x|4x}4x~4x4x4x4x5x5x5x5x5x5x5x5x5x5x6x6x6x6x6x6x6x6x6x6x7x7x7x7x7x7x7x7x7x7x8x8x8x8x8x8x8x8x8x8x9x9x9x9x9x9x9x9x9x9x:x:x:x:x:x:x:x:x:x:x;x;x;x;x;x;x;x;x;x;x<x<x<x<x<x<x<x<x<x<x=x=x=x=x=x=x=x=x=x=x>x
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx>x>x>x>x>x>x>x>x?x?x?x?x?x?x?x?x?x?x@x@x@x@x@x@x@x@x@x@xAxAxAxAxAxAyAyAyAyAyByByByByBy	By
ByByBy
ByCyCyCyCyCyCyCyCyCyCyDyDyDyDyDyDyDyDy Dy!Dy"Ey#Ey$Ey%Ey&Ey'Ey(Ey)Ey*Ey+Ey,Fy-Fy.Fy/Fy0Fy1Fy2Fy3Fy4Fy5Fy6Gy7Gy8Gy9Gy:Gy;Gy<Gy=Gy>Gy?Gy@HyAHyBHyC
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxHyEHyFHyGHyHHyIHyJIyKIyLIyMIyNIyOIyPIyQIyRIySIyTJyUJyVJyWJyXJyYJyZJy[Jy\Jy]Jy^Ky_Ky`KyaKybKycKydKyeKyfKygKyhLyiLyjLykLylLymLynLyoLypLyqLyrMysMytMyuMyvMywMyxMyyMyzMy{My|Ny}Ny~NyNyNyNyNyNyNyNyOyOyOyOyOyOyOyOyOyOyPyPyPyPyPyPyPyPyPyPyQyQyQyQyQyQyQyQyQyQyRyRyRyRyRy
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxRyRyRyRySySySySySySySySySySyTyTyTyTyTyTyTyTyTyTyUyUyUyUyUyUyUyUyUyUyVyVyVyVyVyVyVyVyVyVyWyWyWyWyWyWyWyWyWyWyXyXyXyXyXyXyXyXyXyXyYyYyYyYyYyYyYyYyYyYyZyZyZyZyZyZyZyZyZyZy[y[z[z[z[z[z[z[z[z[z\z	\z
\z\z\z
\z\z
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx\z\z]z]z]z]z]z]z]z]z]z]z^z^z^z^z ^z!^z"^z#^z$^z%^z&_z'_z(_z)_z*_z+_z,_z-_z._z/_z0`z1`z2`z3`z4`z5`z6`z7`z8`z9`z:az;az<az=az>az?az@azAazBazCazDbzEbzFbzGbzHbzIbzJbzKbzLbzMbzNczOczPczQczRczSczTczUczVczWczXdzYdzZdz[dz\dz]dz^dz_dz`dzadzbezcezdezeezfezgezheziezjezkezlfzmfznfzofzpfzqfzrfzsfztfzu
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxgzwgzxgzygzzgz{gz|gz}gz~gzgzhzhzhzhzhzhzhzhzhzhzizizizizizizizizizizjzjzjzjzjzjzjzjzjzjzkzkzkzkzkzkzkzkzkzkzlzlzlzlzlzlzlzlzlzlzmzmzmzmzmzmzmzmzmzmznznznznznznznznznznzozozozozozozozozozozpzpzpzpzpzpzpzpzpzpzqz
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpxqzqzqzqzqzqzqzqzrzrzrzrzrzrzrzrzrzrzszszszszszszszszszsztztztztztztztzt{t{t{u{u{u{u{u{u{u{	u{
u{u{v{
v{v{v{v{v{v{v{v{v{w{w{w{w{w{w{w{w{w{w{ x{!x{"x{#x{$x{%x{&x{'x{(x{)x{*y{+y{,y{-y{.y{/y{0y{1y{2y{3y{4z{5z{6z{7z{8z{9z{:z{;z{<z{=z{>{{?{{@{{A
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx{{C{{D{{E{{F{{G{{H|{I|{J|{K|{L|{M|{N|{O|{P|{Q|{R}{S}{T}{U}{V}{W}{X}{Y}{Z}{[}{\~{]~{^~{_~{`~{a~{b~{c~{d~{e~{f{g{h{i{j{k{l{m{n{o{p{q{r{s{t{u{v{w{x{y{z{{{|{}{~{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{||||||||||	|
|||
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx|||||||||||||||||| |!|"|#|$|%|&|'|(|)|*|+|,|-|.|/|0|1|2|3|4|5|6|7|8|9|:|;|<|=|>|?|@|A|B|C|D|E|F|G|H|I|J|K|L|M|N|O|P|Q|R|S|T|U|V|W|X|Y|Z|[|\|]|^|_|`|a|b|c|d|e|f|g|h|i|j|k|l|m|n|o|p|q|r|s
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx|u|v|w|x|y|z|{|||}|~|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx|||||||||||||||||||||||||||||||||||||}}}}}}}}}}	}
}}}
}}}}}}}}}}}}}}}}}}} }!}"}#}$}%}&}'}(})}*}+},}-}.}/}0}1}2}3}4}5}6}7}8}9}:};}<}=}>}?
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx}A}B}C}D}E}F}G}H}I}J}K}L}M}N}O}P}Q}R}S}T}U}V}W}X}Y}Z}[}\}]}^}_}`}a}b}c}d}e}f}g}h}i}j}k}l}m}n}o}p}q}r}s}t}u}v}w}x}y}z}{}|}}}~}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}~~~~~~~~~~	~
~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx~
~~~~~~~~~~~~~~~~~~~ ~!~"~#~$~%~&~'~(~)~*~+~,~-~.~/~0~1~2~3~4~5~6~7~8~9~:~;~<~=~>~?~@~A~B~C~D~E~F~G~H~I~J~K~L~M~N~O~P~Q~R~S~T~U~V~W~X~Y~Z~[~\~]~^~_~`~a~b~c~d~e~f~g~h~i~j~k~l~m~n~o~p~q
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx~s~t~u~v~w~x~y~z~{~|~}~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~	

 !"#$%&'()*+,-./0123456789:;<=
e (08@HPX`hpx (08@HPX`hpx (08@HPX`hpx?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
d'/7?GOW_gow'/7?GOW_gow'/7?GOW_gow
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcde
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyghijklmnop
q
r
s
t
u
v
w
x
y
z
{
|
}
~




































































\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy







	
	
	
	
	
	
	
	
	
	






























































	
























\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
!
"
#
$
%
&
'
(
)
*
+
,
-
.
/
0
1
2
3
4
5
6
7
8
9
:
;
<
=
>
?
@
A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
[
\
]
^
_
`
a
b
c
d
e
f
g
h
i
j
k
l
m
n
o
p
q
r
s
t
u
v
w
x
y
z
{
|
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
~


















































 
 
 
 
 
 
 
 
 
 
!
!
!
!
!
!
!
!
!
!
"
"
"
"
"
"
"
"
"
"
#
#
#
#
#
#
#
#
#
#
$
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
$
$
$
$
$
$
$
$
%
%
%
%
%
%
%
%
%
%
&
&
&
&
&
&
&
&
&
&
'
'
'
'
'
'
'
'
'
'
(
(
(
(
(
(
(
(
(	
(

)
)
)

)
)
)
)
)
)
)
*
*
*
*
*
*
*
*
*
*
+
+ 
+!
+"
+#
+$
+%
+&
+'
+(
,)
,*
,+
,,
,-
,.
,/
,0
,1
,2
-3
-4
-5
-6
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
-8
-9
-:
-;
-<
.=
.>
.?
.@
.A
.B
.C
.D
.E
.F
/G
/H
/I
/J
/K
/L
/M
/N
/O
/P
0Q
0R
0S
0T
0U
0V
0W
0X
0Y
0Z
1[
1\
1]
1^
1_
1`
1a
1b
1c
1d
2e
2f
2g
2h
2i
2j
2k
2l
2m
2n
3o
3p
3q
3r
3s
3t
3u
3v
3w
3x
4y
4z
4{
4|
4}
4~
4
4
4
4
5
5
5
5
5
5
5
5
5
5
6
6
6
6
6
6
6
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
6
6
7
7
7
7
7
7
7
7
7
7
8
8
8
8
8
8
8
8
8
8
9
9
9
9
9
9
9
9
9
9
:
:
:
:
:
:
:
:
:
:
;
;
;
;
;
;
;
;
;
;
<
<
<
<
<
<
<
<
<
<
=
=
=
=
=
=
=
=
=
=
>
>
>
>
>
>
>
>
>
>
?
?
?
?
?
?
?
?
?
?
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
@
@
@
@
@
@
@
@
@
A
A
A
A
A
A
A
A
A
A
B
B
B
B
B	
B

B
B
B

B
C
C
C
C
C
C
C
C
C
C
D
D
D
D
D
D
D
D 
D!
D"
E#
E$
E%
E&
E'
E(
E)
E*
E+
E,
F-
F.
F/
F0
F1
F2
F3
F4
F5
F6
G7
G8
G9
G:
G;
G<
G=
G>
G?
G@
HA
HB
HC
HD
HE
HF
HG
HH
HI
HJ
IK
IL
IM
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
IO
IP
IQ
IR
IS
IT
JU
JV
JW
JX
JY
JZ
J[
J\
J]
J^
K_
K`
Ka
Kb
Kc
Kd
Ke
Kf
Kg
Kh
Li
Lj
Lk
Ll
Lm
Ln
Lo
Lp
Lq
Lr
Ms
Mt
Mu
Mv
Mw
Mx
My
Mz
M{
M|
N}
N~
N
N
N
N
N
N
N
N
O
O
O
O
O
O
O
O
O
O
P
P
P
P
P
P
P
P
P
P
Q
Q
Q
Q
Q
Q
Q
Q
Q
Q
R
R
R
R
R
R
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
R
R
R
S
S
S
S
S
S
S
S
S
S
T
T
T
T
T
T
T
T
T
T
U
U
U
U
U
U
U
U
U
U
V
V
V
V
V
V
V
V
V
V
W
W
W
W
W
W
W
W
W
W
X
X
X
X
X
X
X
X
X
X
Y
Y
Y
Y
Y
Y
Y
Y
Y
Y
Z
Z
Z
Z
Z
Z
Z
Z
Z
Z
[
[
[
[
[
[
[
[
[
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\	
\

\
\
\

\
\
\
\
\
]
]
]
]
]
]
]
]
]
]
^
^
^
^ 
^!
^"
^#
^$
^%
^&
_'
_(
_)
_*
_+
_,
_-
_.
_/
_0
`1
`2
`3
`4
`5
`6
`7
`8
`9
`:
a;
a<
a=
a>
a?
a@
aA
aB
aC
aD
bE
bF
bG
bH
bI
bJ
bK
bL
bM
bN
cO
cP
cQ
cR
cS
cT
cU
cV
cW
cX
dY
dZ
d[
d\
d]
d^
d_
d`
da
db
ec
ed
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
ef
eg
eh
ei
ej
ek
el
fm
fn
fo
fp
fq
fr
fs
ft
fu
fv
gw
gx
gy
gz
g{
g|
g}
g~
g
g
h
h
h
h
h
h
h
h
h
h
i
i
i
i
i
i
i
i
i
i
j
j
j
j
j
j
j
j
j
j
k
k
k
k
k
k
k
k
k
k
l
l
l
l
l
l
l
l
l
l
m
m
m
m
m
m
m
m
m
m
n
n
n
n
n
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
n
n
n
n
o
o
o
o
o
o
o
o
o
o
p
p
p
p
p
p
p
p
p
p
q
q
q
q
q
q
q
q
q
q
r
r
r
r
r
r
r
r
r
r
s
s
s
s
s
s
s
s
s
s
t
t
t
t
t
t
t
t
t
t
u
u
u
u
u
u
u	
u

u
u
v

v
v
v
v
v
v
v
v
v
w
w
w
w
w
w
w
w
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
w 
x!
x"
x#
x$
x%
x&
x'
x(
x)
x*
y+
y,
y-
y.
y/
y0
y1
y2
y3
y4
z5
z6
z7
z8
z9
z:
z;
z<
z=
z>
{?
{@
{A
{B
{C
{D
{E
{F
{G
{H
|I
|J
|K
|L
|M
|N
|O
|P
|Q
|R
}S
}T
}U
}V
}W
}X
}Y
}Z
}[
}\
~]
~^
~_
~`
~a
~b
~c
~d
~e
~f
g
h
i
j
k
l
m
n
o
p
q
r
s
t
u
v
w
x
y
z
{
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
}
~


























































































\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy















































	
























 
!
"
#
$
%
&
'
(
)
*
+
,
-
.
/
0
1
2
3
4
5
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
7
8
9
:
;
<
=
>
?
@
A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
[
\
]
^
_
`
a
b
c
d
e
f
g
h
i
j
k
l
m
n
o
p
q
r
s
t
u
v
w
x
y
z
{
|
}
~




















\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy




























































































\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
























	
























 
!
"
#
$
%
&
'
(
)
*
+
,
-
.
/
0
1
2
3
4
5
6
7
8
9
:
;
<
=
>
?
@
A
B
C
D
E
F
G
H
I
J
K
L
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
[
\
]
^
_
`
a
b
c
d
e
f
g
h
i
j
k
l
m
n
o
p
q
r
s
t
u
v
w
x
y
z
{
|
}
~











































\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy




























































































\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy

	
























 
!
"
#
$
%
&
'
(
)
*
+
,
-
.
/
0
1
2
3
4
5
6
7
8
9
:
;
<
=
>
?
@
A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
[
\
]
^
_
`
a
b
c
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
e
f
g
h
i
j
k
l
m
n
o
p
q
r
s
t
u
v
w
x
y
z
{
|
}
~


































































\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy







































































	






















\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy

 
!
"
#
$
%
&
'
(
)
*
+
,
-
.
/
0
1
2
3
4
5
6
7
8
9
:
;
<
=
>
?
@
A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
[
\
]
^
_
`
a
b
c
d
e
f
g
h
i
j
k
l
m
n
o
p
q
r
s
t
u
v
w
x
y
z
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
|
}
~

























































































\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
















































	
























 
!
"
#
$
%
&
'
(
)
*
+
,
-
.
/
0
1
2
3
4
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
6
7
8
9
:
;
<
=
>
?
@
A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
[
\
]
^
_
`
a
b
c
d
e
f
g
h
i
j
k
l
m
n
o
pqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy										










\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy









	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJK
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy          !!!!!!!!!!""""""""""##########$$$$$$$$$$%%%%%%%%%%&&&&&&&&&&''''''''''(((((
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy(((	(
)))
)))))))**********++ +!+"+#+$+%+&+'+(,),*,+,,,-,.,/,0,1,2-3-4-5-6-7-8-9-:-;-<.=.>.?.@.A.B.C.D.E.F/G/H/I/J/K/L/M/N/O/P0Q0R0S0T0U0V0W0X0Y0Z1[1\1]1^1_1`1a1b
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy1d2e2f2g2h2i2j2k2l2m2n3o3p3q3r3s3t3u3v3w3x4y4z4{4|4}4~444455555555556666666666777777777788888888889999999999::::::::::;
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy;;;;;;;;<<<<<<<<<<==========>>>>>>>>>>??????????@@@@@@@@@@AAAAAAAAAABBBBB	B
BBB
BCCCCCCCCCCDDDD
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyDDD D!D"E#E$E%E&E'E(E)E*E+E,F-F.F/F0F1F2F3F4F5F6G7G8G9G:G;G<G=G>G?G@HAHBHCHDHEHFHGHHHIHJIKILIMINIOIPIQIRISITJUJVJWJXJYJZJ[J\J]J^K_K`KaKbKcKdKeKfKgKhLiLjLkLlLmLnLoLpLqLrMsMtMuMvMwMxMy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyM{M|N}N~NNNNNNNNOOOOOOOOOOPPPPPPPPPPQQQQQQQQQQRRRRRRRRRRSSSSSSSSSSTTTTTTTTTTUUUUUUUUUUVVVVVVVVVV
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyWWWWWWWWWXXXXXXXXXXYYYYYYYYYYZZZZZZZZZZ[[[[[[[[[[\	\
\\\
\\\\\]]]]]]]]]]^^^^ ^!^"^#^$^%^&_'_(_)_*_+_,_-_._/_0`1`2`3
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy`5`6`7`8`9`:a;a<a=a>a?a@aAaBaCaDbEbFbGbHbIbJbKbLbMbNcOcPcQcRcScTcUcVcWcXdYdZd[d\d]d^d_d`dadbecedeeefegeheiejekelfmfnfofpfqfrfsftfufvgwgxgygzg{g|g}g~gghhhhhhhhhhiiiiii
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyiiijjjjjjjjjjkkkkkkkkkkllllllllllmmmmmmmmmmnnnnnnnnnnooooooooooppppppppppqqqqqqqqqqrrrrrrrrr
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyssssssssssttttttttttuuuuuuu	u
uuv
vvvvvvvvvwwwwwwwwww x!x"x#x$x%x&x'x(x)x*y+y,y-y.y/y0y1y2y3y4z5z6z7z8z9z:z;z<z=z>{?{@{A{B{C{D{E{F{G{H|I|J
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy|L|M|N|O|P|Q|R}S}T}U}V}W}X}Y}Z}[}\~]~^~_~`~a~b~c~d~e~fghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyCLg(5BO\iv,9FS`mz	#0=JWdq~L#L%bL&L'L(yL)L*3L+L,L-JL.L/L0aL1L2L3xL4#L5-2L66L7?L8HIL9RL:[L;d`L<nL=wL>wL?L@1LALBLCHLDLELF_LGLHLIvLJLK0LLLMLNGLOLP(LQ1^LR:LSDLTMuLUVLV_/LWiLXrLY{FLZL[L\]L]L^L_tL`La.LbLcLdELeLf
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`a
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpycdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	


\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwx
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./012
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHI
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpybcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy										



















	


\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvw
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyyz{|}~          !!!!!!!!!!""""""""""#######
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy##$$$$$$$$$$%%%%%%%%%%&&&&&&&&&&''''''''''((((((((((	)
)))
))))))**********+++ +!+"+#+$+%+&+',(,),*,+,,,-,.,/,0,1
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy-3-4-5-6-7-8-9-:-;.<.=.>.?.@.A.B.C.D.E/F/G/H/I/J/K/L/M/N/O0P0Q0R0S0T0U0V0W0X0Y1Z1[1\1]1^1_1`1a1b1c2d2e2f2g2h2i2j2k2l2m3n3o3p3q3r3s3t3u3v3w4x4y4z4{4|4}4~4445555555555666
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy666666777777777788888888889999999999::::::::::;;;;;;;;;;<<<<<<<<<<==========>>>>>>>>>>??????
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy???@@@@@@@@@@AAAAAAAAAABBBBBB	B
BBB
CCCCCCCCCCDDDDDDDDD D!E"E#E$E%E&E'E(E)E*E+F,F-F.F/F0F1F2F3F4F5G6G7G8G9G:G;G<G=G>G?H@HAHBHCHDHEHFHGHH
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyIJIKILIMINIOIPIQIRISJTJUJVJWJXJYJZJ[J\J]K^K_K`KaKbKcKdKeKfKgLhLiLjLkLlLmLnLoLpLqMrMsMtMuMvMwMxMyMzM{N|N}N~NNNNNNNOOOOOOOOOOPPPPPPPPPPQQQQQQQQQQRR
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyRRRRRRRSSSSSSSSSSTTTTTTTTTTUUUUUUUUUUVVVVVVVVVVWWWWWWWWWWXXXXXXXXXXYYYYYYYYYYZZZZZZZZZZ[[[[[
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy[[[[\\	\
\\\
\\\\]]]]]]]]]]^^^^^ ^!^"^#^$^%_&_'_(_)_*_+_,_-_._/`0`1`2`3`4`5`6`7`8`9a:a;a<a=a>a?a@aAaBaCbDbEbFbGbHbIbJbKbLbMcNcOcPcQcRcScTcUcVcWdXdYdZd[d\d]d^d_
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpydaebecedeeefegeheiejekflfmfnfofpfqfrfsftfugvgwgxgygzg{g|g}g~ghhhhhhhhhhiiiiiiiiiijjjjjjjjjjkkkkkkkkkkllllllllllmmmmmmmmmmn
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpynnnnnnnnooooooooooppppppppppqqqqqqqqqqrrrrrrrrrrssssssssssttttttttttuuuuuuuu	u
uvv
vvvvvvvvwwww
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpywwwwwx x!x"x#x$x%x&x'x(x)y*y+y,y-y.y/y0y1y2y3z4z5z6z7z8z9z:z;z<z={>{?{@{A{B{C{D{E{F{G|H|I|J|K|L|M|N|O|P|Q}R}S}T}U}V}W}X}Y}Z}[~\~]~^~_~`~a~b~c~d~efghijklmnopqrstuv
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy23456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFG
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	


\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstu
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpywxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy										










\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy









	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEF
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy          !!!!!!!!!!""""""""""##########$$$$$$$$$$%%%%%%%%%%&&&&&&&&&&''''''''''(
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy((((((((	)
)))
))))))**********+++ +!+"+#+$+%+&+',(,),*,+,,,-,.,/,0,1-2-3-4-5-6-7-8-9-:-;.<.=.>.?.@.A.B.C.D.E/F/G/H/I/J/K/L/M/N/O0P0Q0R0S0T0U0V0W0X0Y1Z1[1\1]
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy1_1`1a1b1c2d2e2f2g2h2i2j2k2l2m3n3o3p3q3r3s3t3u3v3w4x4y4z4{4|4}4~44455555555556666666666777777777788888888889999999999:::::::
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy::;;;;;;;;;;<<<<<<<<<<==========>>>>>>>>>>??????????@@@@@@@@@@AAAAAAAAAABBBBBB	B
BBB
CCCCCCCCCC
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyDDDDDDDD D!E"E#E$E%E&E'E(E)E*E+F,F-F.F/F0F1F2F3F4F5G6G7G8G9G:G;G<G=G>G?H@HAHBHCHDHEHFHGHHHIIJIKILIMINIOIPIQIRISJTJUJVJWJXJYJZJ[J\J]K^K_K`KaKbKcKdKeKfKgLhLiLjLkLlLmLnLoLpLqMrMsMt
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyMvMwMxMyMzM{N|N}N~NNNNNNNOOOOOOOOOOPPPPPPPPPPQQQQQQQQQQRRRRRRRRRRSSSSSSSSSSTTTTTTTTTTUUUUUUUUUUVVVVVV
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyVVVWWWWWWWWWWXXXXXXXXXXYYYYYYYYYYZZZZZZZZZZ[[[[[[[[[[\\	\
\\\
\\\\]]]]]]]]]]^^^^^ ^!^"^#^$^%_&_'_(_)_*_+_,_-_.
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy`0`1`2`3`4`5`6`7`8`9a:a;a<a=a>a?a@aAaBaCbDbEbFbGbHbIbJbKbLbMcNcOcPcQcRcScTcUcVcWdXdYdZd[d\d]d^d_d`daebecedeeefegeheiejekflfmfnfofpfqfrfsftfugvgwgxgygzg{g|g}g~ghhhhhhhhhhii
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyiiiiiiijjjjjjjjjjkkkkkkkkkkllllllllllmmmmmmmmmmnnnnnnnnnnooooooooooppppppppppqqqqqqqqqqrrrrr
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyrrrrssssssssssttttttttttuuuuuuuu	u
uvv
vvvvvvvvwwwwwwwwwwx x!x"x#x$x%x&x'x(x)y*y+y,y-y.y/y0y1y2y3z4z5z6z7z8z9z:z;z<z={>{?{@{A{B{C{D{E
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy{G|H|I|J|K|L|M|N|O|P|Q}R}S}T}U}V}W}X}Y}Z}[~\~]~^~_~`~a~b~c~d~efghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	


\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrs
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy/0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCD
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy]^_`abcdefghijklmnopqrstuvwxyz{|}~CL(5BO\iv,9FS`mz	#0=JWdq~LhLjLksLl#Lm,-Ln5Lo?LpHDLqQLr[Lsd[LtmLuvLvrLwLx,LyLzL{CL|L}L~ZLLLqLL+LLLBLL'L0YL:LCLLpLVL_*LhLrL{ALLLXLLLoLL)LLL@LLLWLLL)nL2L<(LELNLW?LaLjLsVL}
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy										



















	


\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqr
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpytuvwxyz{|}~          !!!!!!!!!!""""""""""##
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy#######$$$$$$$$$$%%%%%%%%%%&&&&&&&&&&''''''''''((((((((((	)
)))
))))))**********+++ +!+"+#+$+%+&+',(,),*,+,,
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy,.,/,0,1-2-3-4-5-6-7-8-9-:-;.<.=.>.?.@.A.B.C.D.E/F/G/H/I/J/K/L/M/N/O0P0Q0R0S0T0U0V0W0X0Y1Z1[1\1]1^1_1`1a1b1c2d2e2f2g2h2i2j2k2l2m3n3o3p3q3r3s3t3u3v3w4x4y4z4{4|4}4~44455555555
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy56666666666777777777788888888889999999999::::::::::;;;;;;;;;;<<<<<<<<<<==========>>>>>>>>>>?
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy????????@@@@@@@@@@AAAAAAAAAABBBBBB	B
BBB
CCCCCCCCCCDDDDDDDDD D!E"E#E$E%E&E'E(E)E*E+F,F-F.F/F0F1F2F3F4F5G6G7G8G9G:G;G<G=G>G?H@HAHBHC
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyHEHFHGHHHIIJIKILIMINIOIPIQIRISJTJUJVJWJXJYJZJ[J\J]K^K_K`KaKbKcKdKeKfKgLhLiLjLkLlLmLnLoLpLqMrMsMtMuMvMwMxMyMzM{N|N}N~NNNNNNNOOOOOOOOOOPPPPPPPPPPQQQQQQQ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyQQRRRRRRRRRRSSSSSSSSSSTTTTTTTTTTUUUUUUUUUUVVVVVVVVVVWWWWWWWWWWXXXXXXXXXXYYYYYYYYYYZZZZZZZZZZ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy[[[[[[[[[\\	\
\\\
\\\\]]]]]]]]]]^^^^^ ^!^"^#^$^%_&_'_(_)_*_+_,_-_._/`0`1`2`3`4`5`6`7`8`9a:a;a<a=a>a?a@aAaBaCbDbEbFbGbHbIbJbKbLbMcNcOcPcQcRcScTcUcVcWdXdYdZ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyd\d]d^d_d`daebecedeeefegeheiejekflfmfnfofpfqfrfsftfugvgwgxgygzg{g|g}g~ghhhhhhhhhhiiiiiiiiiijjjjjjjjjjkkkkkkkkkkllllllllllmmmmmm
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpymmmnnnnnnnnnnooooooooooppppppppppqqqqqqqqqqrrrrrrrrrrssssssssssttttttttttuuuuuuuu	u
uvv
vvvvvvv
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpywwwwwwwwwwx x!x"x#x$x%x&x'x(x)y*y+y,y-y.y/y0y1y2y3z4z5z6z7z8z9z:z;z<z={>{?{@{A{B{C{D{E{F{G|H|I|J|K|L|M|N|O|P|Q}R}S}T}U}V}W}X}Y}Z}[~\~]~^~_~`~a~b~c~d~efghijklmnopq
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpystuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@AB
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXY
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	


\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnop
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy										










\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy









	

 !"#$%&'()*+,-./0123456789:;<=>?@A
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy          !!!!!!!!!!""""""""""##########$$$$$$$$$$%%%%%%%%%%&&&&&&&&&&''''''
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy'''((((((((((	)
)))
))))))**********+++ +!+"+#+$+%+&+',(,),*,+,,,-,.,/,0,1-2-3-4-5-6-7-8-9-:-;.<.=.>.?.@.A.B.C.D.E/F/G/H/I/J/K/L/M/N/O0P0Q0R0S0T0U0V0W0X
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy1Z1[1\1]1^1_1`1a1b1c2d2e2f2g2h2i2j2k2l2m3n3o3p3q3r3s3t3u3v3w4x4y4z4{4|4}4~44455555555556666666666777777777788888888889999999999::
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy:::::::;;;;;;;;;;<<<<<<<<<<==========>>>>>>>>>>??????????@@@@@@@@@@AAAAAAAAAABBBBBB	B
BBB
CCCCC
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyCCCCDDDDDDDDD D!E"E#E$E%E&E'E(E)E*E+F,F-F.F/F0F1F2F3F4F5G6G7G8G9G:G;G<G=G>G?H@HAHBHCHDHEHFHGHHHIIJIKILIMINIOIPIQIRISJTJUJVJWJXJYJZJ[J\J]K^K_K`KaKbKcKdKeKfKgLhLiLjLkLlLmLnLo
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyLqMrMsMtMuMvMwMxMyMzM{N|N}N~NNNNNNNOOOOOOOOOOPPPPPPPPPPQQQQQQQQQQRRRRRRRRRRSSSSSSSSSSTTTTTTTTTTUUUUUUUUUUV
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyVVVVVVVVWWWWWWWWWWXXXXXXXXXXYYYYYYYYYYZZZZZZZZZZ[[[[[[[[[[\\	\
\\\
\\\\]]]]]]]]]]^^^^^ ^!^"^#^$^%_&_'_(_)
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy_+_,_-_._/`0`1`2`3`4`5`6`7`8`9a:a;a<a=a>a?a@aAaBaCbDbEbFbGbHbIbJbKbLbMcNcOcPcQcRcScTcUcVcWdXdYdZd[d\d]d^d_d`daebecedeeefegeheiejekflfmfnfofpfqfrfsftfugvgwgxgygzg{g|g}g~ghhhhhhh
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyhhiiiiiiiiiijjjjjjjjjjkkkkkkkkkkllllllllllmmmmmmmmmmnnnnnnnnnnooooooooooppppppppppqqqqqqqqqq
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyrrrrrrrrrssssssssssttttttttttuuuuuuuu	u
uvv
vvvvvvvvwwwwwwwwwwx x!x"x#x$x%x&x'x(x)y*y+y,y-y.y/y0y1y2y3z4z5z6z7z8z9z:z;z<z={>{?{@
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy{B{C{D{E{F{G|H|I|J|K|L|M|N|O|P|Q}R}S}T}U}V}W}X}Y}Z}[~\~]~^~_~`~a~b~c~d~efghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVW
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	


\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmn
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpypqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'(
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUV
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy										



















	


\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()*+,-./ 0 1!2!3"4"5#6#7$8$9$:$;$<$=$>$?$@$A%B%C%D%E%F%G%H%I%J%K&L&M&N&O&P&Q&R&S&T&U'V'W'X'Y'Z'['\']'^'_(`(a(b(c(d(e(f(g(h(i)j)k)l)m
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy)o)p)q)r)s*t*u*v*w*x*y*z*{*|*}+~+++++++++,,,,,,,,,,----------..........//////////000000000011111111112222222
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy22333333333344444444445555555555666666666677777777778888888888	9
999
999999::::::::::;;; ;!;";#;$;%;&;'
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy<)<*<+<,<-<.</<0<1=2=3=4=5=6=7=8=9=:=;><>=>>>?>@>A>B>C>D>E?F?G?H?I?J?K?L?M?N?O@P@Q@R@S@T@U@V@W@X@YAZA[A\A]A^A_A`AaAbAcBdBeBfBgBhBiBjBkBlBmCnCoCpCqCrCsCtCuCvCwDxDyDzD{D|D}D~DDDEEE
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyEEEEEEFFFFFFFFFFGGGGGGGGGGHHHHHHHHHHIIIIIIIIIIJJJJJJJJJJKKKKKKKKKKLLLLLLLLLLMMMMMMMMMMNNNNNN
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyNNNOOOOOOOOOOPPPPPPPPPPQQQQQQQQQQRRRRRR	R
RRR
SSSSSSSSSSTTTTTTTTT T!U"U#U$U%U&U'U(U)U*U+V,V-V.V/V0V1V2V3V4V5W6W7W8W9W:W;W<W=W>
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyX@XAXBXCXDXEXFXGXHXIYJYKYLYMYNYOYPYQYRYSZTZUZVZWZXZYZZZ[Z\Z][^[_[`[a[b[c[d[e[f[g\h\i\j\k\l\m\n\o\p\q]r]s]t]u]v]w]x]y]z]{^|^}^~^^^^^^^__________``````````aa
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyaaaaaaabbbbbbbbbbccccccccccddddddddddeeeeeeeeeeffffffffffgggggggggghhhhhhhhhhiiiiiiiiiijjjjj
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyjjjjkkkkkkkkkkll	l
lll
llllmmmmmmmmmmnnnnn n!n"n#n$n%o&o'o(o)o*o+o,o-o.o/p0p1p2p3p4p5p6p7p8p9q:q;q<q=q>q?q@qAqBqCrDrErFrGrHrIrJrKrLrMsNsOsPsQsRsSsTsU
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpysWtXtYtZt[t\t]t^t_t`taubucudueufuguhuiujukvlvmvnvovpvqvrvsvtvuwvwwwxwywzw{w|w}w~wxxxxxxxxxxyyyyyyyyyyzzzzzzzzzz{{{{{{{{{{||||||||||}
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy}}}}}}}}~~~~~~~~~~	


\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklCL(5BO\iv,9FS`mz	#0=JWdq~LmLL'L„LL>LÛLLULIJLLlLL&LƃLL$=L-ǚL7L@TLIȱLSL\kLeLn%LxʂLL<L˙LLSL̰L
LjLL$L΁LL;LϘLL
RLЯLL(iL2L;#LDҀLNLW:L`ӗLjLsQL|ԮLLhLL"LLL9LזLLPLحL
Lg
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpynopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~€‚ƒ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy…†‡ˆ‰Š‹ŒŽ‘’“”•–—˜™š›œžŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖרÙÚ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRST
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~ĀāĂ㥹ĆćĈĉĊċČčĎďĐđĒēĔĕĖėĘęĚěĜĝĞğĠġĢģĤĥĦħĨĩĪīĬĭĮįİı
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyijĴĵĶķĸĹĺĻļĽľĿ	


\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijk
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpymnopqrstuvwxyz{|}~ŀŁłŃńŅņŇňʼnŊŋŌōŎŏŐőŒœŔŕŖŗŘřŚśŜŝŞşŠšŢţŤťŦŧŨũŪūŬŭŮůŰűŲųŴŵŶŷŸŹźŻżŽžſ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy'()	*	+	,	-	.	/	0	1	2	3
4
5
6
7
8
9
:
;
<
=>?@ABCDEFGHIJKLMNOPQ
R
S
T
U
V
W
X
Y
Z
[\]^_`abcdefghijklmnopqrstuvwxyz{|}~ƀƁƂ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyƄƅƆƇƈƉƊƋƌƍƎƏƐƑƒƓƔƕƖƗƘƙƚƛƜƝƞƟƠơƢƣƤƥƦƧƨƩƪƫƬƭƮƯưƱƲƳƴƵƶƷƸƹƺƻƼƽƾƿ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

          !!!!!!! !!!"!#"$"%"&"'"(")"*"+","-#.#/#0#1#2#3#4#5#6#7$8$9$:$;$<
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy$>$?$@$A%B%C%D%E%F%G%H%I%J%K&L&M&N&O&P&Q&R&S&T&U'V'W'X'Y'Z'['\']'^'_(`(a(b(c(d(e(f(g(h(i)j)k)l)m)n)o)p)q)r)s*t*u*v*w*x*y*z*{*|*}+~++ǀ+ǁ+ǂ+ǃ+DŽ+Dž+dž+LJ,Lj,lj,NJ,Nj,nj,Ǎ,ǎ,Ǐ,ǐ,Ǒ-ǒ-Ǔ-ǔ-Ǖ-ǖ-Ǘ-ǘ-Ǚ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy-Ǜ.ǜ.ǝ.Ǟ.ǟ.Ǡ.ǡ.Ǣ.ǣ.Ǥ.ǥ/Ǧ/ǧ/Ǩ/ǩ/Ǫ/ǫ/Ǭ/ǭ/Ǯ/ǯ0ǰ0DZ0Dz0dz0Ǵ0ǵ0Ƕ0Ƿ0Ǹ0ǹ1Ǻ1ǻ1Ǽ1ǽ1Ǿ1ǿ1111222222222233333333334444444444555555555566666666667
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy777777778888888888	9
999
999999::::::::::;;; ;!;";#;$;%;&;'<(<)<*<+<,<-<.</<0<1=2=3=4=5=6=7=8=9=:=;><>=>>>?>@>A>B>C>D>E?F?G?H?I?J?K?L?M?N?O@P@Q@R@S
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy@U@V@W@X@YAZA[A\A]A^A_A`AaAbAcBdBeBfBgBhBiBjBkBlBmCnCoCpCqCrCsCtCuCvCwDxDyDzD{D|D}D~DDȀDȁEȂEȃEȄEȅEȆEȇEȈEȉEȊEȋFȌFȍFȎFȏFȐFȑFȒFȓFȔFȕGȖGȗGȘGșGȚGțGȜGȝGȞGȟHȠHȡHȢHȣHȤHȥHȦHȧHȨHȩIȪIȫIȬIȭIȮIȯIȰ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyIȲIȳJȴJȵJȶJȷJȸJȹJȺJȻJȼJȽKȾKȿKKKKKKKKLLLLLLLLLLMMMMMMMMMMNNNNNNNNNNOOOOOOOOOOPPPPPPPPPPQQQQQQQQQQRRRRRR	R
RRR
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpySSSSSSSSSTTTTTTTTT T!U"U#U$U%U&U'U(U)U*U+V,V-V.V/V0V1V2V3V4V5W6W7W8W9W:W;W<W=W>W?X@XAXBXCXDXEXFXGXHXIYJYKYLYMYNYOYPYQYRYSZTZUZVZWZXZYZZZ[Z\Z][^[_[`[a[b[c[d[e[f[g\h\i\j
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy\l\m\n\o\p\q]r]s]t]u]v]w]x]y]z]{^|^}^~^^ɀ^Ɂ^ɂ^Ƀ^Ʉ^Ʌ_Ɇ_ɇ_Ɉ_ɉ_Ɋ_ɋ_Ɍ_ɍ_Ɏ_ɏ`ɐ`ɑ`ɒ`ɓ`ɔ`ɕ`ɖ`ɗ`ɘ`əaɚaɛaɜaɝaɞaɟaɠaɡaɢaɣbɤbɥbɦbɧbɨbɩbɪbɫbɬbɭcɮcɯcɰcɱcɲcɳcɴcɵcɶcɷdɸdɹdɺdɻdɼdɽdɾdɿddeeeeee
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyeeeffffffffffgggggggggghhhhhhhhhhiiiiiiiiiijjjjjjjjjjkkkkkkkkkkll	l
lll
llllmmmmmmmmmmnnnnn n!n"n#n$
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyo&o'o(o)o*o+o,o-o.o/p0p1p2p3p4p5p6p7p8p9q:q;q<q=q>q?q@qAqBqCrDrErFrGrHrIrJrKrLrMsNsOsPsQsRsSsTsUsVsWtXtYtZt[t\t]t^t_t`taubucudueufuguhuiujukvlvmvnvovpvqvrvsvtvuwvwwwxwywzw{w|w}w~wxʀxʁ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyxʃxʄxʅxʆxʇxʈxʉyʊyʋyʌyʍyʎyʏyʐyʑyʒyʓzʔzʕzʖzʗzʘzʙzʚzʛzʜzʝ{ʞ{ʟ{ʠ{ʡ{ʢ{ʣ{ʤ{ʥ{ʦ{ʧ|ʨ|ʩ|ʪ|ʫ|ʬ|ʭ|ʮ|ʯ|ʰ|ʱ}ʲ}ʳ}ʴ}ʵ}ʶ}ʷ}ʸ}ʹ}ʺ}ʻ~ʼ~ʽ~ʾ~ʿ~~~~~~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~ˀˁ˂˃˄˅ˆˇˈˉˊˋˌˍˎˏːˑ˒˓˔˕˖˗˘
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy˚˛˜˝˞˟ˠˡˢˣˤ˥˦˧˨˩˪˫ˬ˭ˮ˯˰˱˲˳˴˵˶˷˸˹˺˻˼˽˾˿
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQR
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~̡̢̧̨̛̖̗̘̙̜̝̞̟̠̣̤̥̦̩̪̫̬̭̮̯̀́̂̃̄̅̆̇̈̉̊̋̌̍̎̏̐̑̒̓̔̕̚
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy̴̵̶̷̸̱̲̳̹̺̻̼̽̾̿	

\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghi
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyklmnopqrstuvwxyz{|}~͇͈͉͍͎̀́͂̓̈́͆͊͋͌ͅ͏͓͔͕͖͙͚͐͑͒͗͛ͣͤͥͦͧͨͩͪͫͬͭͮͯ͘͜͟͢͝͞͠͡ͰͱͲͳʹ͵Ͷͷ͸͹ͺͻͼͽ;Ϳ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~΀
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy΂΃΄΅Ά·ΈΉΊ΋Ό΍ΎΏΐΑΒΓΔΕΖΗΘΙΚΛΜΝΞΟΠΡ΢ΣΤΥΦΧΨΩΪΫάέήίΰαβγδεζηθικλμνξο
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~πρςστυφχψωϊϋόύώϏϐϑϒϓϔϕϖϗ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyϙϚϛϜϝϞϟϠϡϢϣϤϥϦϧϨϩϪϫϬϭϮϯϰϱϲϳϴϵ϶ϷϸϹϺϻϼϽϾϿ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()	*	+	,	-	.	/	0	1	2	3
4
5
6
7
8
9
:
;
<
=>?@ABCDEFGHIJKLMNOPQ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
S
T
U
V
W
X
Y
Z
[\]^_`abcdefghijklmnopqrstuvwxyz{|}~ЀЁЂЃЄЅІЇЈЉЊЋЌЍЎЏАБВГДЕЖЗИЙКЛМНОПРСТУФХЦЧШЩЪЫЬЭЮ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyабвгдежзийклмноп	

\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
          !!!!!!! !!!"!#"$"%"&"'"(")"*"+","-#.#/#0#1#2#3#4#5#6#7$8$9$:$;$<$=$>$?$@$A%B%C%D%E%F%G%H%I%J%K&L&M&N&O&P&Q&R&S&T&U'V'W'X'Y'Z'['\']'^'_(`(a(b(c(d(e(f(g(h
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy)j)k)l)m)n)o)p)q)r)s*t*u*v*w*x*y*z*{*|*}+~++р+с+т+у+ф+х+ц+ч,ш,щ,ъ,ы,ь,э,ю,я,ѐ,ё-ђ-ѓ-є-ѕ-і-ї-ј-љ-њ-ћ.ќ.ѝ.ў.џ.Ѡ.ѡ.Ѣ.ѣ.Ѥ.ѥ/Ѧ/ѧ/Ѩ/ѩ/Ѫ/ѫ/Ѭ/ѭ/Ѯ/ѯ0Ѱ0ѱ0Ѳ0ѳ0Ѵ0ѵ0Ѷ0ѷ0Ѹ0ѹ1Ѻ1ѻ1Ѽ1ѽ1Ѿ1ѿ111122
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy2222222333333333344444444445555555555666666666677777777778888888888	9
999
999999::::::::::;;; ;!;"
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy;$;%;&;'<(<)<*<+<,<-<.</<0<1=2=3=4=5=6=7=8=9=:=;><>=>>>?>@>A>B>C>D>E?F?G?H?I?J?K?L?M?N?O@P@Q@R@S@T@U@V@W@X@YAZA[A\A]A^A_A`AaAbAcBdBeBfBgBhBiBjBkBlBmCnCoCpCqCrCsCtCuCvCwDxDyDzD{D|D}D~D
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyDҁE҂E҃E҄E҅E҆E҇E҈E҉EҊEҋFҌFҍFҎFҏFҐFґFҒFғFҔFҕGҖGҗGҘGҙGҚGқGҜGҝGҞGҟHҠHҡHҢHңHҤHҥHҦHҧHҨHҩIҪIҫIҬIҭIҮIүIҰIұIҲIҳJҴJҵJҶJҷJҸJҹJҺJһJҼJҽKҾKҿKKKKKKKKLLLLLLLLLLMMMMMMMMMMN
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyNNNNNNNNOOOOOOOOOOPPPPPPPPPPQQQQQQQQQQRRRRRR	R
RRR
SSSSSSSSSSTTTTTTTTT T!U"U#U$U%U&U'U(U)U*U+V,V-V.V/V0V1V2V3V4V5W6W7W8W9
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyW;W<W=W>W?X@XAXBXCXDXEXFXGXHXIYJYKYLYMYNYOYPYQYRYSZTZUZVZWZXZYZZZ[Z\Z][^[_[`[a[b[c[d[e[f[g\h\i\j\k\l\m\n\o\p\q]r]s]t]u]v]w]x]y]z]{^|^}^~^^Ӏ^Ӂ^ӂ^Ӄ^ӄ^Ӆ_ӆ_Ӈ_ӈ_Ӊ_ӊ_Ӌ_ӌ_Ӎ_ӎ_ӏ`Ӑ`ӑ`Ӓ`ӓ`Ӕ`ӕ`Ӗ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy`Ә`әaӚaӛaӜaӝaӞaӟaӠaӡaӢaӣbӤbӥbӦbӧbӨbөbӪbӫbӬbӭcӮcӯcӰcӱcӲcӳcӴcӵcӶcӷdӸdӹdӺdӻdӼdӽdӾdӿddeeeeeeeeeeffffffffffgggggggggghhhhhhhhhhiiiiiiiiii
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyjjjjjjjjjkkkkkkkkkkll	l
lll
llllmmmmmmmmmmnnnnn n!n"n#n$n%o&o'o(o)o*o+o,o-o.o/p0p1p2p3p4p5p6p7p8p9q:q;q<q=q>q?q@qAqBqCrDrErFrGrHrIrJrKrLrMsNsOsP
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpysRsSsTsUsVsWtXtYtZt[t\t]t^t_t`taubucudueufuguhuiujukvlvmvnvovpvqvrvsvtvuwvwwwxwywzw{w|w}w~wxԀxԁxԂxԃxԄxԅxԆxԇxԈxԉyԊyԋyԌyԍyԎyԏyԐyԑyԒyԓzԔzԕzԖzԗzԘzԙzԚzԛzԜzԝ{Ԟ{ԟ{Ԡ{ԡ{Ԣ{ԣ{Ԥ{ԥ{Ԧ{ԧ|Ԩ|ԩ|Ԫ|ԫ|Ԭ|ԭ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy|ԯ|԰|Ա}Բ}Գ}Դ}Ե}Զ}Է}Ը}Թ}Ժ}Ի~Լ~Խ~Ծ~Կ~~~~~~	

\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefg
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyijklmnopqrstuvwxyz{|}~ՀՁՂՃՄՅՆՇՈՉՊՋՌՍՎՏՐՑՒՓՔՕՖ՗՘ՙ՚՛՜՝՞՟ՠաբգդեզէըթժիլխծկհձղճմյնշոչպջռսվտ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyրցւփքօֆևֈ։֊֋֌֍֎֏֐ְֱֲֳִֵֶַָֹֺֻּֽ֑֖֛֢֣֤֥֦֧֪֚֭֮֒֓֔֕֗֘֙֜֝֞֟֠֡֨֩֫֬֯־ֿ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./012345678
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~׀ׁׂ׃ׅׄ׆ׇ׈׉׊׋׌׍׎׏אבגדהו
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyחטיךכלםמןנסעףפץצקרשת׫׬׭׮ׯװױײ׳״׵׶׷׸׹׺׻׼׽׾׿
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNO
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~؀؁؂؃؄؅؆؇؈؉؊؋،؍؎؏ؘؙؚؐؑؒؓؔؕؖؗ؛؜؝؞؟ؠءآأؤإئابةتثج
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyخدذرزسشصضطظعغػؼؽؾؿ	
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdef
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyhijklmnopqrstuvwxyz{|}~ـفقكلمنهوىيًٌٍَُِّْٕٖٜٟٓٔٗ٘ٙٚٛٝٞ٠١٢٣٤٥٦٧٨٩٪٫٬٭ٮٯٰٱٲٳٴٵٶٷٸٹٺٻټٽپٿ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 :M-	#0=JWdq~zm`SF9,vi\OB5(M,M+yM*M)M(bM'M&M%KM$M#M"4M!M zMMMcMM|MrLMiM`MV5MMMD{M;M1M(dMMMMMM
M6MM
|M	ML!L~LL$8L-ەL6L?OLIܬLR	L[fLeLn Lw}MM7MߔMMNMMMe
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy"#$%&'()	*	+	,	-	.	/	0	1	2	3
4
5
6
7
8
9
:
;
<
=>?@ABCDEFGHIJKLMNOPQ
R
S
T
U
V
W
X
Y
Z
[\]^_`abcdefghijklmnopqrstuvwxyz{|}
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyڀځڂڃڄڅچڇڈډڊڋڌڍڎڏڐڑڒړڔڕږڗژڙښڛڜڝڞڟڠڡڢڣڤڥڦڧڨکڪګڬڭڮگڰڱڲڳڴڵڶڷڸڹںڻڼڽھڿ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

          !!!!!!! !!!"!#"$"%"&"'"(")"*"+","-#.#/#0#1#2#3#4#5#6#7
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy$9$:$;$<$=$>$?$@$A%B%C%D%E%F%G%H%I%J%K&L&M&N&O&P&Q&R&S&T&U'V'W'X'Y'Z'['\']'^'_(`(a(b(c(d(e(f(g(h(i)j)k)l)m)n)o)p)q)r)s*t*u*v*w*x*y*z*{*|*}+~++ۀ+ہ+ۂ+ۃ+ۄ+ۅ+ۆ+ۇ,ۈ,ۉ,ۊ,ۋ,ی,ۍ,ێ,ۏ,ې,ۑ-ے-ۓ-۔
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy-ۖ-ۗ-ۘ-ۙ-ۚ-ۛ.ۜ.۝.۞.۟.۠.ۡ.ۢ.ۣ.ۤ.ۥ/ۦ/ۧ/ۨ/۩/۪/۫/۬/ۭ/ۮ/ۯ0۰0۱0۲0۳0۴0۵0۶0۷0۸0۹1ۺ1ۻ1ۼ1۽1۾1ۿ11112222222222333333333344444444445555555555666666
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy66677777777778888888888	9
999
999999::::::::::;;; ;!;";#;$;%;&;'<(<)<*<+<,<-<.</<0<1=2=3=4=5=6=7=8=9=:=;><>=>>>?>@>A>B>C>D>E?F?G?H?I?J?K?L?M?N
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy@P@Q@R@S@T@U@V@W@X@YAZA[A\A]A^A_A`AaAbAcBdBeBfBgBhBiBjBkBlBmCnCoCpCqCrCsCtCuCvCwDxDyDzD{D|D}D~DD܀D܁E܂E܃E܄E܅E܆E܇E܈E܉E܊E܋F܌F܍F܎F܏FܐFܑFܒFܓFܔFܕGܖGܗGܘGܙGܚGܛGܜGܝGܞGܟHܠHܡHܢHܣHܤHܥHܦHܧHܨHܩIܪIܫ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyIܭIܮIܯIܰIܱIܲIܳJܴJܵJܶJܷJܸJܹJܺJܻJܼJܽKܾKܿKKKKKKKKLLLLLLLLLLMMMMMMMMMMNNNNNNNNNNOOOOOOOOOOPPPPPPPPPPQQQQQQQQQQRRRRR
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyR
RRR
SSSSSSSSSSTTTTTTTTT T!U"U#U$U%U&U'U(U)U*U+V,V-V.V/V0V1V2V3V4V5W6W7W8W9W:W;W<W=W>W?X@XAXBXCXDXEXFXGXHXIYJYKYLYMYNYOYPYQYRYSZTZUZVZWZXZYZZZ[Z\Z][^[_[`[a[b[c[d[e
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy[g\h\i\j\k\l\m\n\o\p\q]r]s]t]u]v]w]x]y]z]{^|^}^~^^݀^݁^݂^݃^݄^݅_݆_݇_݈_݉_݊_݋_݌_ݍ_ݎ_ݏ`ݐ`ݑ`ݒ`ݓ`ݔ`ݕ`ݖ`ݗ`ݘ`ݙaݚaݛaݜaݝaݞaݟaݠaݡaݢaݣbݤbݥbݦbݧbݨbݩbݪbݫbݬbݭcݮcݯcݰcݱcݲcݳcݴcݵcݶcݷdݸdݹdݺdݻdݼdݽdݾdݿdde
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyeeeeeeeeffffffffffgggggggggghhhhhhhhhhiiiiiiiiiijjjjjjjjjjkkkkkkkkkkll	l
lll
llllmmmmmmmmmmnnnn
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyn!n"n#n$n%o&o'o(o)o*o+o,o-o.o/p0p1p2p3p4p5p6p7p8p9q:q;q<q=q>q?q@qAqBqCrDrErFrGrHrIrJrKrLrMsNsOsPsQsRsSsTsUsVsWtXtYtZt[t\t]t^t_t`taubucudueufuguhuiujukvlvmvnvovpvqvrvsvtvuwvwwwxwywzw{w|
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyw~wxހxށxނxރxބxޅxކxއxވxމyފyދyތyލyގyޏyސyޑyޒyޓzޔzޕzޖzޗzޘzޙzޚzޛzޜzޝ{ޞ{ޟ{ޠ{ޡ{ޢ{ޣ{ޤ{ޥ{ަ{ާ|ި|ީ|ު|ޫ|ެ|ޭ|ޮ|ޯ|ް|ޱ}޲}޳}޴}޵}޶}޷}޸}޹}޺}޻~޼~޽~޾~޿~~~~~~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy89:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~߀߁߂߃߄߅߆߇߈߉ߊߋߌߍߎߏߐߑߒߓ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyߕߖߗߘߙߚߛߜߝߞߟߠߡߢߣߤߥߦߧߨߩߪ߲߫߬߭߮߯߰߱߳ߴߵ߶߷߸߹ߺ߻߼߽߾߿
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLM
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcd
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyfghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	


\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./012345
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()	*	+	,	-	.	/	0	1	2	3
4
5
6
7
8
9
:
;
<
=>?@ABCDEFGHIJKL
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyNOPQ
R
S
T
U
V
W
X
Y
Z
[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

          !!!!!!! !!!"!#"$"%"&"'"(")"*"+","-#.#/#0#1#2#3#4#5#6#7$8$9$:$;$<$=$>$?$@$A%B%C%D%E%F%G%H%I%J%K&L&M&N&O&P&Q&R&S&T&U'V'W'X'Y'Z'['\']'^'_(`(a(b(c
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy(e(f(g(h(i)j)k)l)m)n)o)p)q)r)s*t*u*v*w*x*y*z*{*|*}+~+++++++++,,,,,,,,,,----------..........//////////00000000001111111
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy112222222222333333333344444444445555555555666666666677777777778888888888	9
999
999999::::::::::
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy;; ;!;";#;$;%;&;'<(<)<*<+<,<-<.</<0<1=2=3=4=5=6=7=8=9=:=;><>=>>>?>@>A>B>C>D>E?F?G?H?I?J?K?L?M?N?O@P@Q@R@S@T@U@V@W@X@YAZA[A\A]A^A_A`AaAbAcBdBeBfBgBhBiBjBkBlBmCnCoCpCqCrCsCtCuCvCwDxDyDz
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyD|D}D~DDDEEEEEEEEEEFFFFFFFFFFGGGGGGGGGGHHHHHHHHHHIIIIIIIIIIJJJJJJJJJJKKKKKKKKKKLLLLLLLLLLMMMMMM
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyMMMNNNNNNNNNNOOOOOOOOOOPPPPPPPPPPQQQQQQQQQQRRRRRR	R
RRR
SSSSSSSSSSTTTTTTTTT T!U"U#U$U%U&U'U(U)U*U+V,V-V.V/V0V1V2V3V4
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyW6W7W8W9W:W;W<W=W>W?X@XAXBXCXDXEXFXGXHXIYJYKYLYMYNYOYPYQYRYSZTZUZVZWZXZYZZZ[Z\Z][^[_[`[a[b[c[d[e[f[g\h\i\j\k\l\m\n\o\p\q]r]s]t]u]v]w]x]y]z]{^|^}^~^^^^^^^__________``
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy```````aaaaaaaaaabbbbbbbbbbccccccccccddddddddddeeeeeeeeeeffffffffffgggggggggghhhhhhhhhhiiiii
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyiiiijjjjjjjjjjkkkkkkkkkkll	l
lll
llllmmmmmmmmmmnnnnn n!n"n#n$n%o&o'o(o)o*o+o,o-o.o/p0p1p2p3p4p5p6p7p8p9q:q;q<q=q>q?q@qAqBqCrDrErFrGrHrIrJrK
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyrMsNsOsPsQsRsSsTsUsVsWtXtYtZt[t\t]t^t_t`taubucudueufuguhuiujukvlvmvnvovpvqvrvsvtvuwvwwwxwywzw{w|w}w~wxxxxxxxxxxyyyyyyyyyyzzzzzzzzzz{{{{{{{{{{|
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy||||||||}}}}}}}}}}~~~~~~~~~~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ab
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpydefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	


\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy56789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJ
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpyLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	

 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`a
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpycdefghijklmnopqrstuvwxyz{|}~
\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy	


\'09BKT]fox#,5>GPYbkt}
(1:CLU^gpy !"#$%&'()	*	+	,	-	.	/	0	1	2	3
4
5
6
7
8
9
:
;
<
=>?@ABCDEFGHIJKLMNOPQ
R
S
T
U
V
W
X
Y
Z
[\]^_`abcdefghijklmnopqrstuvwx
['09BKT]fox#,5>GPYbkt}
(1:CLU^gpyz{|}~
&ypg^ULC:1(
jNjNF
e47652fa5e7642d21ed5f8769fe5f4fa1d3e7f416afe2b8f600aaf2ad97b5e27NF
70b9436a659665181aa90524926ff7ebeebcbc15038624b5a49e0657dedfb584


ee:V+rF
00056c9175a4ec1b58cad0e3b3b16cbd29712335001c85d5f270931b04d4bb6aF
00063f470db329bdbf0defd2b9622d72db94830b9c0a108b7646f6acb3316563
F
000c783ad67a44fbc26df8ad81ecd49cdb80c72bac2e0468445fe1454d75a522F
0021c82540d24671074ea3ef5535b58a819c02dfddf7e05c15f9ae392ea8c199F
002d4f7023944abaa5047112477822bce1cf921f395bbc76065f1bc6ecfa3c22JF
003c7635f8d23b7b12ec78287877a43a4ae9429260d34c92695eafb0df5d061aF
003d6e4f36c75c96397d74a2057705deb39e076f3fc1a18799709b07c8140187LF
0050786ebb1c2b37bb1a4450e340b50786707ce8f2f8f01b356ea66cd305165b/F
00608301be4450298d9a4f75fc3a36ab657c6083731a7fe1510fb0044564bb52F
00685f713fa548fd7e60ef95a370789739c4ef8bf55c1102f6d251548a251ed2}F
006866668980a661dabcff054750dcfabee9be838cbdbe8f6554a12c8d2437e4F
008b4a8cee71d4770d3f1c7d68b7c37fc61c86104417e049e1fd9eca1270711bSF
0094b5e088ab7669b50681c5ee1c139c5ea4b295dff26681ef9aabc6f5a119db,

ee:V+rF
009f1e5fdfe0287c2d456390aacab52be52e77247292e285d5caa965c2330dabF
009f5f995347d3b6f6491ec4dd82192efd57cf782be7741597e2a9259a1b4a3ckF
00a2d48440baace65111ae56106256b8e047e95d4a9a467ebaed09dc73f03585F
00c48e4de2e435d25917e5b12f697e6b79435fb251862569482e3c31793da0f8'F
00d2bde49dfc19aa010c5926838900760b435bfe8f53e8d8ad0acefd762cafcfF
00dbfd02a12975ec58e646015d21c1697f304b58353b1372310d96c80b2903aeRF
00dfecc575f562ca6c58f3290ca7fda9b19bbacf629d7c687dc4242984f8bb37tF
00ee764e0982d01d4e6bb4be901fe9d45e00ba81aada6ca3196a2f4c6a633f63
F
00f44bddea556d6114fd545f221ce9393e2498132e40d8c7e1ba1b4015de0671:F
00f64801d8abc5d57fcf628994aeed0267baba42e5be15b3a5d445cd3a2f12260F
00f6b15c036cb61966264e2a9c7ef1815399b860c29455f9b7b85bd59958ee0b,F
0106c00d777327c471f8f9e676017d61dd0e5e5b4fe97750869b7857f0838ba2aF
012bfa8eacdc2cdef0742df38d48737a13ab8171afc5020ef127dc81084a68b5]

ee:V+rF
01359f42e5c172df7cebf52260aa08b51811b3cc29728a03a93dc546ffcfd21eUF
0136b7f5a2716c2969f4dc132e19b7819af04e2aa0c5ba9bd9774ccf09c14e9flF
014111c7993e5c5c0c955d00c5e230799fda34ca92a9b109dd0a572200c4dbedF
014d6cdbaef0539c9b70adc727d4252d7aa3200cd7ca7a1afabf2ed85ad8feefhF
014f5bd144904dc6d27a7fe4b1819401d5f70ea084c8f04cf734fc30dd3fcfacyF
0150773cdef45797820d481008b2e7297bc32060b190f3493a27354e52ffb8baEF
0159bd2e5e5911a949c27ecc4ee8003c3e2bdc4fe0074b1d0eb53e28360580faF
017388e17ae8a0342ff3283f483c0f92172ac1005e8e97a4c40390e55f78d063
F
017e2d09736a9888ed8e38dca3b1a005fcfebb65e0d3d31617fa9ba35f62526d.F
017eff95084da1072645aceed55c7d64fe45d437ca48fa5ec6446759047a4d0dlF
0184b3c53d99c0d7a743fc2eefaec2158d3ccddc254688d6b5fed77bcdaf78d0F
01a6f6a9a36d8203819ae336a672955e40e9b1c9cf387d5ccd0942ebea8c147aF
01af8dbfbd06ab846b1473d9c0c02a8f51af1a47c8d92957ff4e5508b3d647da

ee:V+rF
01b83fa31f2e2ed972aa491423479df2e3e026e54668e3933d3b8b1803fe208b	'F
01da9776dbd5c2c0b5ee6d9e9020302a9007e6bf195079f25e6cf699c93e1decF
01fb0c20e028f3f34cb3fc42c0360980946fc9b2e0f4b1cfcbe93c27779126063F
01fb3a26a807a59931faaaabe295041a8fa40561ac74f13c180818145c68eae4xF
0202fe311e75a00ac449bf922bf22eacbdfcbc62ea3fb9eca5285643347ec389F
020558539740256bcdb84e7c5606c92c374e8b5d5af9021d52cb794b0f6131e1F
02153be2996d05b396970b128ff1c8411eb8c6920328c7f2bb84271d28caeff7F
0216cb555eb5ac8bb5f746370557652aa2a2e0814f298bdf4fe756f0f1cebcacF
0226602f67b7037375bd2d1258c099113d59cdda599052241225ce267656959fF
0228887c20e6cb39e203d667f60bf1e06e9496f7302af59a477a3db454b70575F
0261a6827bcb70a4d4e0bbabff124f88c79ad1171f8d19e379a2e019e4867abf6F
026420613efcc87726ba91b165fc0b746ce24ff329555220967db5cc979a803a\F
0265dca6e210e12ede6c0a683df0e1068291dfc35f0589544af045bc6f7bc898

ee:V+rF
029155dd11073cb7e583700a754feaab925bd20b392240a64723cb67d3a4db5bF
029192b133954b86d152440adc98cc50c2ad3ded6b1f727f31615807b2d6ac98=F
029a613293d1ba49b765f0f2ec6fc0b71f6fd43fb1ceff50f43e05dc84f98d20F
02b9f36207f55eecbaed6219e76bf38881875be99f49e0eca71ec75e6d3a7aa3F
02bef4b4e654f8dd811b3eecdf5516bd91608806ac3f8f3f596117947edc6652F
02cad16355e1d26c8bd3d5c772f181d7659d048dff3d0ae06e95050139572debF
02cae02000e8b7bc7519aaeb70ed3f09854a6bd0cb622de6b22e75aa2c644230F
02cbd7332b3ce796fb31c211ff00e807700217dbe4cbf3860f61c4a3bb69beb8
F
02d776d9eabc5a1600b998782d8d36dfd9f654699fe0d5ed0fcea97a75b44ac1
?F
02d7a80b905c4425a04fb580f2e9cedea180c37a12f4aebcc804d768f6a12ffdF
02ddd2f4ddbeafacbe9cdecd7071ce4d21239067950fce14f915e65b88e056b0;F
02df0d560a1cd7208b8336532084570d73cca1c40562c74bcccd6e5aef84f343F
02e583fec180896fabf3422f69975545e3bd8d8460665b7044a186d0d5a4f817

ee:V+rF
02f39c31f6b85c556cb651767e2383c2bac89bab5627ec18df62fd758577a348
F
02f897ee795a6592d97ca15c780cbdd6ca2bc2a793d53ef279ad3f01f27d472cF
02f9db11a20bee6dfde81279441c6b86bc5047ad9fc1b6243b5b1ed6d3a1608aF
0304822e8138a928f86fc2b725ede94f0fe7ad348c85d005729fc71bac0ba3b2?F
030b52a92f3fd60b2df1b1fee6a964377bc4d80776dbdfcfae051132e0c3815cmF
030d403b90d83c7791ba3ea26cc659f709c596898fbfbd5d5f6e4b737a1293facF
031f000698ae93b4d5d19e31521dddc308fa90b6dfee2faed3b23620d47fd150IF
0321354f5886437064ddff4080e65e1ed1d6f5a4d8f78872893181b71f450938F
0328daa881db258b5d0dcafa3d0c1f8bb4e2dd5034a74b2938d69c73b0a7dcbdF
033cc5d8ff989f638033f0a6af82cb11c2d68d26fc602668a0a4c9673a09ef9c|F
034c9033d1e0262176555d3b7dc0f189885361d53ccb042ac04e98012e34b040F
035b347d3201307242fcde833202a8aa1505b93cbfed75f9f4aa400f16f19cefhF
03701d6e0d843fdfb34d5135af97796623145817df79fabb6a8fb6eed7cfb552z

ee:V+rF
0380151eff2395148f47a991620ec2bd74e74d330969f2c6d6c0a064a0278166F
03861872c0b045970aa5d709fc96b48dc78114b5fe454d59dff316eb4753ec08	F
03a8c1b34a6e0348a56c5f5c1e6d5f586c514da1b01b442feaf2c7dfec629173F
03c52d5fc8024d804e827e048d07e835a984ac5f5d9391614c51b0905c9772a0$F
03c6e9f83275661d1eb892af76411bc871b3f442dc65c95ad96dadbaffe84cf7	F
03cf1dde125c19d5d48038e69f3552a4973548aa09dc383debd850eec84fa1a4
F
03e1baf0c1c94f364478eb3cd7d75ad83408dfe993ea8a69481c7f963ebb1cc3
F
03e57a64f56503f6e79a1fc2c5923cb7b7c844a98479ed62503b92933057832dZF
03ea957f3e2be56bc876a29ef48424ad8cc38c240505a263f9907bb55882d20fF
04123c3387456fe96ccae3db4f1c8332ab30d6d0ddea9994b55a58e704a1d264F
041f5f1e8b93254eb47e8b18434325a8ecfea6152330918662e991c8b435cdfeF
04338d51e121bd3112024a6e032e9dc376c437e7d1914a17d85868c3c59e8f72F
04343e0c734f4810fb43a53773019eae05e21428fa5cf05b99db8582265dc3d9

ee:V+rF
0448f0190f604f767981ff4c96e3e9210bc3ec57cf905b9c65ce31bcbdb59db6F
0449fb732714886324a83ab5585589c4bff8fd81cfd32d8cc00260106295b33bF
044fa462d51c4d22a5eb8db06de4ed95a23b6e26336c54e16ea3417cd87a5981F
0460e382ab0b0ff062ef27fbd07fe4a599aeb4704c295ef0ba4f0c14632a257aF
0474de8faa6866555281a93c12b25c1f8e532892f9dec72d0ccbaedaa2257d75tF
0479d5709839258211df37f5f528182b35422b740c858e9fee588961f3067033F
047afe9b60a6d1228931b215d26c7cc7dc637d69a40463e0a25163cd20c53b43F
049526fdb7a05153ccc486726ea5c75e9cbf7eb168e6d4eb673555e2a2ed8967
MF
04a4cfccd1c263a0f3de420c2200f1e9d5485e3f5734a0c08f2c01c3be01b144$F
04aafce3a01a8ef79a286f4b1e46007f4ff2310784c8df59fa21c4b9ef862b84ZF
04b0f0e217513325d81caf263da9288d80eb720c931507ed120b0b99d52505adF
04b4fe240bbb7def555afa21959f623f37179a6993d0e6a57f592f05ab3f531bF
04b897ee5a470f0fb0ecc0e412cc6d3910847f21d8a28f788c5515366e2ac15b

ee:V+rF
04c9f6e177144af377d7c3b0185efb36ce85abfaba270ab01faefaf1cfa6837bF
04dce9028a87d078c3036031ae186db04fd35a585bd35d7aa2fcc7c8300830ed*F
04eb35414e82fe2433c837b70edc142805f7455f68f171ad1ea43e534a94de83F
04ec871279754a00e7006a2f023b95ed305dc36a9ff23d65ed20cbf987b07ffdF
04f581972286e776f852cf380fd0a4c05af1556c3d62f8ad579d87985ee0467ccF
0506a69ed5099abb05188f0ad253ebf7fb23f9516de5789b336622a000b67e9dF
051767c8b8b2c33280f93fb2f1f60e7d9bdd8f44678ca6c68f5e2e59986a7ef8#F
05190e91801f134ec5c33d7636671a93327e2f26dc018ed5ef24541b0c91c9fe6F
052bc59d48a243df22b031df97865c1dc873c28379e0ef92b51f07311401764bF
052c8eb21db8776433111192ff5a74c5160dfebb1bfcc701324165599256b321F
05362c7e6d4437e600de7d1470e9fe6c2f6f27c1292646ff6a86a8a72ae75c9fJF
053bab8c7482789ca2a4d26eacb17ea07e87c7b88691ebeea4df085b8ee8b0c4
F
0546c6b078f73199e92d47749bd83c92594960b191bb14c1adc5fd5996219b74

ee:V+rF
056e7fe3c5a00be53248709c74120df1d6c073ef1b7b7beba63ff41d48f35c173F
0575f05deb1df2512ee0e962ca3a090704d98dca573c138f4280f758c83cc88a
F
0579155d9d1a4a339ec6d119e12c2ecc135abd36aef7ba674704d62d18e6e6ccF
058ac0bdef709238810c53bb5fa0fcf0b4843e91d77920ccea506da4114aed3cSF
059cd706e5668cb53ab32ca18815011ad932d1853567a29b3c7b2afca689e637"F
05a0c90006b42933811046c1278ba1584b25ae8404694f0d692582422b132360F
05a1a1334799c302fd4621a4dab067e901b9fbea4d7d269ebc6e9bea8d855923F
05a1afac9166ad0a6bd4d12f5586743519b206e5f4bb4ce59ee057b9dff7d92f
F
05a40b72da0cf303bc79e3b58cda8c7f7edb3f19a201eca57225af9a1e012bebqF
05ab159708542ab7cbdc54eec74ffdbd8cb86dd12b6b0a5c10faff3414c5ddceSF
05b12f50d113b0a0d5208b907519a36a79df62b2d79ddbb1d4019332f3d7ff39$F
05b66ae9aef06d6c9d64f8dd5f1ffb50591c5686b5d538f6a698b5725f8a5b12F
05b86a6126cc85e6e214a09707b886a17df5b705f5cb7dab4c86228f6b2ad4d28

ee:V+rF
05ca51bffce88a4ceee7e70a17f2e81e550cbe1f0573836e157840cea3610e88F
05cd5d302b4787e4b7f4d091ae0e2cfc78a0ad48883502cb3bc7ec1cf2c8601a}F
05ce97f826afdba77bdbabde3175ee402acbf40771f2af0a35ada58f14c7ecbcF
05cf4fd79bba0f69976ed978e39e96312e5c1ed1fc98158138579aa9d2b1ac01
F
05e34813e9daef9255f5e02eb2c3753c5308d070ffe9608abf8367fedeff8e2d=F
05fbad1e72d3fc82cab1e83391bf6c22c224dd3554ceed92227b792e08bf75b4pF
05ff5981a0c8f962a35dd854d2cf3aabccd82881efc4d700b5add509d6f0f289F
06027d118bc6eda893d13e73a13e75851e1f01cc10ad76d87de54aa42810f00eF
0607eb87b1e4a72aa8d10708247befdd19963e0ca5b2fe44d7d76eda6a408652F
06218f80b35658bc0f58476f103dcd67638009385f21b603c1005339fbd5841eF
06444e0746003a76118ae6a9895e5592ab3c18c2bf85ab614b50a43dd56980b9JF
065be8dcad1accb013d907c343f946bf2aee0c7ebe74cc8d43c80d008e10fed5zF
065c61acd07e5d7bf4396d3bb011f0b6440c73eae51c4902ebc118cfce7b8fd4x

ee:V+rF
0688bc15522e5a3eee9f6ec2d771f77743a5979f6ac5afa0ec5059daa5926e35F
06925f8c06ddc4e973f5d0c4eb2ea60c2c099d9608f354cf74311a817b75e734%F
06a5cb180f3ca29cdae7dd9547b29c30079ef85e1809389608777308ad5e4c3aF
06bc77dd6c2f2125c8f8ccb6b4e685a71d97e6defb84eb1d696ee180ac974e06
F
06bec1b1e5fba64eb4e0e530da173b3bafb747f95f9629079d77f65567b15d42F
06c9237d3d292ac356ab89dc89e2e9d7f41d6b52eaa838d872573cdeac93d2e7F
06cf0f65aa64e614d4aa2f4b52af2b2c2e8e6420e1a748807f9d326ed353d4b6(F
06d6c8fc8acd6bccaac9dcec5bc4fadf0a2b38f66fac335962e0352a7d2bf9bfBF
06d86e24f67250850372882170efd7d12d041a90b28a72fb952a0f3d10141825F
06dc7124955549934298d13f36f05d5c055ad9f2dc7291af7ea111042dff38c03F
06de00e45a444bd8381c6526ee4a204b80511ebbca8c8b0b52bfd9d9bacec74cF
06e4169680e37d4d65bf7fd8382c034d2d0434ae20eadb40888e7ab261de6aa2F
06e5fb6ecf1b329364a643c5ede73c7f38229a9b7aee51b73806126d416f71e8

ee:V+rF
06f1bb2af6f2c2c3b74476a6919d97cc43a92d7d43132345b87af3a3a4aede4bF
07061aa8f12ae1f09d204f2dc47e1608d9dce33042da18739a076fb7fa37fc13F
0709174e0519ec2d79dc3e1545a937fdee842ce5f5048538521cbcf27426440dMF
0710224c0e98852a70afc4e528bd026d4d46bf8fa6d68af8b7944e41683ae5cf1F
0718ec7a648c76821e1117532667414db4883898fdd43d3e8a631827814422fa	F
0720c43c680146e7a676c6340d3f1529fb116ef0c12105b5b84f41a448512564F
072e6332387b7078fb53410078598cb6a9480bef04a1e72bcfd996503ff19d12F
073a61debf16645920e116641fcf09bdcef80147f54754057c18515f5ebe1f8cF
07502ee4563c4bdc09b8d0b67eba7577aae0d6c871501af53b038aad8812d391F
07505d8e7877d8a5114d6db605a9dc9c2132c0d32d978e2df599fa2e69887780	F
075385572952a26db77d6708c6b4866e1a5b4e1fcef8f0f9e2ff1918b13c4439F
075e649f6da15e063d52ce4d0d3ba406ef07fe22522b3b701f9577056c5cf18aF
0768c02eab146e2f88cb0c3f41aee2d4f7b14dbdde274b3955f2155eb21cf944

ee:V+rF
0781ec76d6ef76f218a16289f31a21e27af4064a2fa1f213a49828a67e50c669-F
078d626065367dc1b0c00d308d8b5d9d69fe369a31b59dbf38747ea1e98647df
F
078df219eb34b52cef5f93c17533da34f2eceaec30e85da8944716d38dfee1962F
079057e8ac08393331b2846ec1d9b56021f2e524cf0eb682c033f6348fcf31daF
0794a0f7d6a515b2cdfb8187e15d5605671a95d2ebabff7bdf87777d0c9530dcF
079a8f1382b2cde5fc460d2bfb277e6586eeffb928b2d9ed2bb6258fdc6fc4edF
07a39b4944cc8d1c6e61f1ad215c744f685fcf1cf0494ce979a7f28539da66d6F
07b1856027333bf98a662c1c5c7b92d2391deb1108f57f3ca5b27d6ee192f7a0jF
07b97f3f2c7b61f7d3f1361ef0cb40ea95320f3213ff8441345dd39ed092edffF
07bd35c3abbf6026fb0e99d204b230ccbed3b91ccbed6d0675f5dc885931ea62
F
07cfec6beda5578439d467fa4a51b7e846ea94e1eb455753928367e7fd96ac68F
07e3f6b9b256a115590234dc0183bcf39f3cd1e274bd4d7506c4ae4992f8adedCF
07ef29e54e22c90b43aa4eb7133046f805b01fd91030eafee283ca4db4b35173

ee:V+rF
0821b9fe0910e051ebf760e8df0198202117a973492dee2aca30504c0f8a5544.F
082abb4e91620918c0d5d1da8dfb191f950c793d112a4ac3ec4f2055ca594c68F
0834c02bc349eaabe64a4015d07ee7cbcf7776a68766e81cd93be0a58c7d5465F
08396cb866f024b0054c16918fe544406f737f7ddefcecbda04ad29ab9a27a15kF
0848e56ffcc658be84b8dc962cfae7e6e963b28421212d04c814be04b66154b4F
085f001bc61a93bf23c68f240bd7b5c24aa41e4a9b6c5539dfe676b451ec102a	F
085f2174502e709dad29fc828ef0fd2f5c027de6d68e07e337607b8c77e184cdF
086c33b98ecb7adbc59297b29fb3fc219e4beda421611ef17471f6cc8e0a9b6f8F
087a9eb6f7e5a03f17d35ced5aea62e436334f59bd027880ae3be3eb69257219F
088144b029dc1cc8f91996726bfc5e8a3ea03cb750f26a8038b554a33f1bc66dF
08824226d21e7afa5b192b8623609503e7928c2f070b02660b7372a5fd8999b0F
0884e384499ad64f6f25f663be6d416d9290f010f743e6eed115ceae93d81f8bF
08863f9fce74c908ee529b7d6877678e4993d6800fa0e1f5ee19afd4c79373a6
1M<1|]>jM/F
009c4fd4d1a151a215ef1a31eb4f5b076e16ad5bd1c6bed249571dfdde69a686oM0F
013236ef5fa8a51d31d6d13a69fb89b023f7bf87400cfbe7442751e25e4a0c0dM1F
01b2d6f4dd3c509eda7a3396036cc2ba36461c6d867b18c64e8358fba4982e34\M2F
027f9ce824c240ccb21c3c503958433eb772483c1fe803ce30f44f232c06eaf4
tM3F
02f065f8fc1a7dad64b3db9dce1c2acf7f0fdb727133ffef1c209fa011adbcd6=M4F
037e885e4b00fa8c73772c5a2e0f05aa735f04807e080c5819a8a15dade3d5dcM5F
0435f345b2b188c76dbb4a538bf0f878834a41e723491df1926231020fd88efdpM6F
04c1cb44a333186da972033dd6cf11d36780a1631c165568ae8099544c2c1543M7F
054e750bc6d0c6d60f45a6fb60b3bc08bf7902623d269b106db0969e6a028abb>M8F
05ba725d5c869c501d11a5e7d8127d0ad80d328b3e6147d560401baf1810497bM9F
067642d9046b8566ef1ed0cf884f58e8a6d4e400e732070462b2051471465a19M:F
06e8b2bd304cd09ba4be27cd71f6e46da23994939ba405275e37c1d39b91f75bM;F
076ae5a31f58ce2e33f04de674fed5086fd8f72a8e802528d833f3033c017469r
1ML1|]>jM=F
0894834781a35f76e011fd41d9cf3bae6d4a47dcb32589aea06d68f2b07ad20e-M@F
08fbafcced5e9e1b471e4e7dfdaf102a8d2a4b77e5322e88d818828f064c5242MAF
097675babe2d377b7544507d5d63c4df6766f7bfa3508a1288be59444b79ef19MBF
0a35810bd924f95ae2af1ba31051f64c8683e42b953329a6af07ea00495f96a2MCF
0b0f6b7bf49772aa7d4525fb75fddff1ff77a08c6c3cf4c990c7fcb0fd59a2b9UMDF
0b44e2a7472e36fcf462b7b85a5bbc147c95150b55e8d7e6dc3fe4977c7cdc76MEF
0c17cb1415294598f297a58396280f055f0f3258f080b1ab697bfe04bbe0008d2MFF
0cb96b04da1187dc59c06a37d73082671753740008c7d0f948693e3929f1b1a4MGF
0d2d3cbaee9c9fdd4bf0e41db231e656141f296acbbf0480fb738b9c04e78268QMHF
0da377da9a9dc6f3210ae58f9365d1e379b41bfbc986639c5cb7df02de772356EMIF
0e0057ab9e8cb8424689c8f6e05bb121fb1bd2f7a3e0fbec225b582428df0176*MJF
0eaade45e4faa7e8e8b18e0ab2d01b531ee0b40d37435cff287a385b544dea75MKF
0f0fa59eb6e08ac74519d59b709ce746a54f5ac7294b9ef563943eea5bdc327d

ee:V+rF
08949cdd78826f2931cedc5db7b5ecee0f22e07f614ab03c88690cc3ad353c4c,F
089b94f213c170e875e90bb476e333d4b7d2491e323f4692f8e1513f78b4203eF
08b1fcdb6cdc4ebc6e4b8009023baa7759c113cc1d67ef555df1cef33880d688>F
08b4dee7a9b26d0de63eb7b9be7383288a1d179be539eb61df3c1d005566ba5fF
08b94d6efe931c32344ea97bafacefaf26b7ab57c499ee718b7466ba31c943211F
08c0606b2ec5ba2bb66a3ee30f97a269ff8da7cdfc8a081d621411fc68286e09'F
08d1d1cc28a0a4caf172ffb26c59f35532cb13b37543dc1b44895666f5c4d486F
08d3a3571d95f12d505af7454de2dadabca497aa265dbce4ff86b0317462b5db
F
08d77e2a53f45806fd7b82661a7ef4d17bedadab7f9241768695eafd2d8f6cf0-F
08dfe3130e723092bcc8145c8b90e71cc35804a68abc5879143350368fece38bVF
08ec368681cd5235d44e7c13637d697d5bc44aaf5cfd9f49fc33531191a5717bF
08eccef6a2ce6a06f95c7ad30f3fdd7db91e89b3991bbe05cc786dee1ccc9074
PF
08f9a253bf2654c7f281ec675c59f7bd4bd0f06ed499e82831fcd79aef82e50b

ee:V+rF
08fdefbdb8f11e74afa450cfe88c2d98b1e9caee0e6a213c4b67db47d4ca1dc5[F
08fe4123c9f2d5699c800a7e884d1f8f6958f6ec8448ac152f214735fd9ba5f9fF
0913430ac82b85ff2505f1428fd1ee1c2cbdf9c4b58cc447ab469fccea954369'F
0918063cb9b48c317391f431d587661c39613d95bd83d01ca9029660d7a1dfd9F
092200d5b5dde09d6818651bad72eaf924bc014da7f290860fa9416ca5d80c29dF
0926abec8c375e818901656da36c33757d3a3e3bf4baf9195278ae3f048fd8e5F
09277f1295e2db1f4f90bd3fce359dd8150009233cbba997650480e544b67766F
092cc13ed7af9de7e0332c1da0285f190396f1b75256ecd162899d06cf9b0e1aF
0930a501a892602ab5d8c48730193fa5230e46803b8b20533482a6322014c898F
093f80fc5d8e0da79a3979e52dfdc01e24389db68934cf76c4a575367b63914cF
0952cfe96c702aedc34ce0dcba4f7bde61e7ef84de1ad0057e39e6750b2c0bda
F
096e36a0f28a54f5ad7c593b2efd58ee933bf7f9c314927179a6d0244e0a596aEF
097333804cdbb8a534dabe56aeb0d3b2dbc4a9c4796ca5102c74fa94f597ff42

ee:V+rF
0986dce8e3a59471cabc7ed457e23c3f0fdc81e3cbab4093eaa0426e2d5d26efF
09936061a18c7bf3b0903e9e1994dca141d245478064ada19312d0d78abe44aeF
09b0a412ef431cf5907e6d41f5bf960d051927c73b0a292dea9a52585f306e01F
09c09056918a1d0fcf94103b7cc7f9728ea6f763a2c2d3db5a1a470846afc777F
09c46bafc8f7871f9037631642128c520e108bc7b90ffdfffbd477c7ea27543e
F
09c89c08debacc489fe15a2e0025630de1bd775a0f8b0e4ef911abb61cc7f0d1F
09cd4a65244763f9c5d860969f9294414316cc0b7472539300921b5021a3a048bF
09d536dbeed2bb97193afabb9564cc6e6def3636f719ed0e3bbb8c0e575f7033F
09de0197c6db452f0fd3f28c21887416beca324b835bd991b0385a41cd819f52F
09f2614aeded0a8d1f7454f0270fe81a129ba048470ed9851001049d758c2a0fF
09f598da7d3fbe1d2b05e159dc8f3d04792678621bf6d1f87c0edb4896d550a3F
0a050612befea77a0541c8b1e8c5655262271ebc40a5897b3fcb7bc85c56fc53F
0a22fdb0f60d3be3fd66877b980e41dfe9e76361231ab306f3eb3a98c2ef3139

ee:V+rF
0a5287477758b2371bd5090dfacaf9dd93c3f1cc379245204f8a143593599b48?F
0a551f7e2a238413dc99c1846c2fa6ce5424327eb7cae6cffdcc8530fe613c92F
0a5a7250aabe9649c502bfc98a71ff102a3a30a37575ea8c1c0ae22c267a6640cF
0a621e3a587fb00080786a7b80616e9ce0fe3cfbf0131712ea44c6dee612c0a3F
0a712b8f1eda25e3f9a256fe884b8e622404b2f830abfa7cb7a720a164b44109F
0a755493662be885a9d421b00ff08001a5d61a085bb86846d60072222530e672	F
0a7bd3f0caab514c1555ed06bde5524b4655f5fdc8b646492ded15867ea9f447WF
0a804c07144041c1bb5d619535096838e17f54b6d6c4295d4b1551f45f7031bfF
0a8d2dafb528818f6b019015fbaf8cdd2fe3b6535d85da90f6a1db984b828e8eF
0a8fa0a8748dd4667a74653e840521e8d0602e1f9210bb2b27d75c59318081c0F
0adc9fe4603e83cc02d7181487b5982803e7d1ac319a09428f7f62c4b74d8d3dF
0af4fa113704a011a3594459a6619542c384a68bce85aa250f90448e347431feF
0af8a6a9e3b24968bed3be9b8de12ef658fbbfc2164edfd7186a7cced585e5ec

ee:V+rF
0b115d54c14e78f3f59d84b00407c9b0d58b5c274afa2b7f993667bb66f3f8e8IF
0b16a6ff0f8a8988e02b31ad560630c7d2fdc9e63b234cc9a39273f3fc61e146F
0b185730ee6a43395cfa0f8cd6a7a6749386e567da85ed56e884df2ca709923fF
0b1af8e104a87dcac9e19a39e5868fef98096447b8a8eafc1e3fe57711fabf57F
0b22b530fe470f3e466de0b4c9a662510b4feffc3540c2add9689e58fe543a56F
0b25bab3a8a0341d22387d3674f6676645e3d3d497d2de92de115a56fa012b1bjF
0b299d62c2e3249e8aa1132f170b5b2eb81a8441f5fcb1b29f9970da5b40d33dF
0b29c214b8a3ff37cfcb010079194019a3d4b2e97d32adcd0571daa7b2572234%F
0b31fcea001c43db8cd9d635933b11a63756f99e56b454bbfd3b201a1ec4a077
 F
0b321ea4f022bb7f3c34a1bd3f7d2b5cda3bc71f527d5d4e5af585464ef88de7F
0b33ebe4a47333d7d3cfb619025360776f080666c4ca5b9dd7a539591cc58c9aF
0b35b40bf56766439cd4f160aa0bb3028afd3654b4df1a07cbe49d5a0c3642fb
F
0b42148789300af59e74814b7d8cb50a3c1453dc197a498f2f37cdc75a6a97d7

ee:V+rF
0b48a1dc6bd965ac5f800c44cf498da51c5fd0ec07bf16a07911d66f89932c4b3F
0b514834510f57ab09a2051d0b0c2be8a61777452ad125d1b3e5e90abeb6fa22
F
0b666836eac572662e426b0b815d751ae62dd8422c5ab5c6d910f8bf94ad1141F
0ba33a407f36442d9f5f526712fe0c940b67897540b9e10a14271928cffed297<F
0bb28c9f68dfa70b3b78027fb8b42c4122bccb671f14d669ce89f85990ee5c7b
)F
0bbfce2dd7e12ca5610015aba9f167cbc4cc29d360a77f3801b7508618bb17fb
F
0bc17855cc6640920597c449da532b260707f9f0446c2d6c601ace461632007eTF
0bc7a3258a261dafb1804614ca3e65cc202ca5a9607554f6524da136cb7c7ee67F
0bec8227df4692ec640eaf96154a87faa5a1ab3d9c37856f4f8e0c0a98c88525F
0bfce88e921ad0a5fd946306ecf24c9d04e2662eaeaf728d05dbcdc32010c8eaF
0c048c74887e157b97b761a85580b46558525fc2a03b50627c102edbdffe5e76F
0c05547ab6db1a5fe777068a16ceaf758e35d33abedd3643f7dc8bee4b68af5f4F
0c0ba36a5e8704ab304024f5f4bc9616e4592da8ef6293f27ee584cd13805973U

ee:V+rF
0c3ad35e059126bc405bb6ab3f4ae6d37fcb202c2192112ede3ec719d4c45554F
0c50466e187899042f37e621ad418348afddcf8a0b1ef74a9c42573da5425ecaF
0c6ad74477b64388fb061cd59308e5053fb53c352648ac10728050169bb9ac48F
0c7bc243b0e57280cd7bdd324734b2af9b6ea05f5309af24c0897ceb134b9ffezF
0c844b3fd55943ad6df491c0f9396667119e7d8f737d079ca70e1e354c04d769^F
0c8cc9217954e5b7e4fba72b8cac347c473caf377f918d06fdc3c2bb7e672917	]F
0c8fa4695663226154eeb62875404c38ac8f61913460fe2e8036ae8e76cad75eF
0c8fb84a63da81ffc9727d465f04ac197820bce6473ad8ca5f2d241c6cdfb9a7`F
0c9251da98f68e439285f3e9fe1d2564f460335667000f17d613cca5310aa9549F
0c9cd97e333e5ea85907e92483ef91dbdb08349b7e29916dcf5c08061c74f8361F
0cad55db6dba2a060d78d5cd109fe110b948f6008192e29b843fe591ffec7fc2WF
0cb228d7dc8544ea720f5503724f929baf79d69d2a7d1eb9dd47cf361620788e	F
0cb275f3f74903e0b995fb60bd6d2d45b6d75c0f10a329bf957ff43cddf17096

ee:V+rF
0cc793e2d0f59813a9e09567f1c3af4510272946883ebb48cc9cce9189664c7eF
0cc9ba42a15c78ffcce2049a61fd84727a2586eca9d5215f1ca32e1a24b02bfeMF
0cd349e9faa4208c5a06dd623c32419cde907327603062ef0197ae238ecf9cb1F
0cd7aee9f2db00d6755f43fa30faafe7382aa8e438f5c11a40c90c0e5e8352d2F
0cdb951d2a540947e97b85a4754dcc8bbf1cb878e5dbd0f1bdad2a6a4626f694F
0cdf4d5f9455b9e3e0eeca97fcb7fa4f7b76899970af7d0fa1bdc2c1ade16fe2
1F
0ce460c4fec36484894f526d04090272961a86fa1cadfc07b79bf7eb7f0095f6XF
0cf6bb4e5beb49f3a45a5171babb25685cf72156e8666dc2a57f9fef6af67838F
0cfe90113fcfe21d6f21f6022481283b9b35ca916c02484fc39e89b88fcffa8aF
0cff7abce034e9ae5e89bd1f5c50241356dd38507e0c53e17d563453b7923822F
0d2891caee1b493f9b544af0495b535e91b27d243df3f653a39ffeafe3e16dbeIF
0d291da8585bc5dc3d72a81e494c64767eb04ba5a938f0847121edded2bcbdecaF
0d2b3fa57c857e63e2bc038eba8140a308abe22d4261989634084fe5e9eb73bd

ff;W+rF
0d30036d6a876fd21fc61439985a43f29d496b4089d41c5fa578c65ecde1d198F
0d33e36e3c9f478cdd404e7a15bdde7f8470d1267ae29e4c3127e06d2646a3b8F
0d39c362f6c9f3279419ed4315d754b3944058bc88a48263152b512ed67f0dda\F
0d3a93f5635729a3341a43ad550bf5e1a022c431b725a9126b80bbb5bce8cdc22F
0d3c2c589c5e9e3f8ffbf1a3ecab65c4237f0445ab4f8f1840daac3a9bde8e16F
0d57fe6a1b4c3013d7384f4d0457ff6aacdaf60ec4bcad0624f3d41fbaeb80c46F
0d768d1ea1cafc2aac35e0917a8c6e9184c802e60dc7add05251d7c940193f32
AF
0d7905c384f2eb08286c9eaf8161f50db1d1312363a1fe8b484962d4ed6e149b}F
0d795cbf22fec282f02654f7712344c97027974130c274b8e837bec939303861fE
0d7ee838bc95b1ca0f6653c7bb6bf7f82fd91bddf5008eb108ab46da2a4a15a4{F
0d7fa70d37741c62bde710cf842f10260cf261673a4a7408c061b0e28d2bc955CF
0d89f6cb70bf9117dfd174a86c11de319ac44c664effcaa3b959f00d436ae1a2F
0d953611a4ac63b86ca9bbf1ca0f35e9ef53094123f9e581e16919ed0393c690

ff;W,sF
0dac2946a3cac243477b0ac6573b491a15bcd751bbfaa32b92535f850f10cf3fF
0daf2f065c20c572dbd4c2cd864cef8c197f640a926ce017c7343205b4e5e77dF
0dafa08f6f467ecca9fd5fafad09fcd5cac9b1f2f050f88329a90f3434c52078F
0db1ad475d57dd2dcf3165a763d246f2f2b899c3bc4bad744291c568d041127cF
0dc167d2f05541662cc1bfe1773d78ea0566b4fae06130399f47b0f01f34e177[F
0dc9fbacba7b11cb8fe67dd7a2596d89132d937ce3099a1e872d630f5f68fafcF
0ddc672fbbf22b385a04e5922c34037d8950a75fb1cd0527f909bcc1783abb9fF
0de12d2701881f7f8bd093302babcb112ad65af4943bd2e0d2bcb2884f12012dhF
0de8a90ff171bad788a3e83dfb9e880aedf1440a7e0e201037073ea3c6af5cae5F
0de926f65070e07d518fd6dde604c0aa41ed7aedee86e9dbd0db39abed1534cbpF
0debd7af9974202b568d8b8c1c87e8d70139dd2dbc62ba9bf7a9e72fe64c3990oE
0df91ae3f7e140e17025cfcac0a1bbb8507f665cf4f2ae6e8e6951f0fbc667e5]F
0dfc6e8ea7cfb111b83da1e6ce7bfc3f5f3c353f61b25a21812ba01aed81cbed

ee:V+rF
0e0b806579667e86ea70685a838f8c23073e5084c9c3135588b05d5d395ec9d3F
0e0d9ae9f3664f3a8aa2a994019ef5a1293a67c401f5fde714661afc37cd8438F
0e15a4084dc2ccf63f0b0ad4073f81fdd2a5a9137184d9fd3f72e558dadcb56eF
0e2027754d28d80891f36030409114272ec237f698e5ff38e5ab7268da1dce52F
0e230546571aa26c06f1097967584ab4b9e777e7ca6c94d45f8706a36bdccc22BF
0e2842a9ef72de0a39b188244266ec36bb5efee89dbbb26d2d9b8832fdb44b78F
0e30ee127b67a51aaff1ffe3ae0cb616b808bc21850fe2f23be2b229a8bb8853UF
0e46815b96448a8115c16703aeaeadf07680cb2172f0028f3a8ab4b9d6e6897d
F
0e50e504282d4892f5bb05084db338d47c7312f569aaa3fcbb60451b38e17abdF
0e5624fbb0590aa72e8ae21556cd6ed2655b7a7955c181db303cdd39320028f1MF
0e63c2347e36ece8d4f15909b64a5a6c3b79f38a6e53f614e310fbfd86f26b06F
0e83fd6b33039ac7fda9317c440371d5e1d6e4173afb995bd498be0589efbf51F
0e9f601a50df8e60748b538e0a74fbb3fe326ce3a54a551b7a254c64afcf272f

ee:V+rF
0eb359490eab964f970cb8d6fd9987a38a3e3f9c585348941c53fb1b709c71f1F
0ebd7a7d93f6af20c4e8fff8d52032fda80556a14021adf330e1c9f9e8063482eF
0ebed7ba324c9dd19b4c287a0d21bb0ff3631197a4d341dfff3705451356c18eTF
0ec52bd7a95347c5c330df35b5067f28cdd262383f84e176598367ad11c98a27F
0ed0c68541bccf9732065a361a46692699a4a2ce01c4a502809c2c7c16a1d213
4F
0ed523747db652e84c5b5a87d2207d7410229587204a4fbc5f477091cf0e9706F
0eda90367bc11ce10165853be705e1303b3ac2a0f5072131cbd8b2ea6ed2d1eaF
0ee22c6eb0445485cec58e7d73154100a461cce8a0bf2a9e3b8350e6ad3d073e&F
0ee97394870cffe996ee7e4b916ac7fd3a1843f7b577ee2bf1a309f6b5e3e325F
0eec836c027a565c281645294b192571bfe852631d94438627371cba58c380de	F
0f0241e556ea298645602911fe3d8280bc945bfbbbdf05c822cbe1fd63f1641crF
0f031938a045f2ce246507b233ce7a53103a6051e0cda09aa7d2b4feab4e773bF
0f0f20e5079748f9103ff3e0068108043ec9079822de5e46263c2c1f09b6dc0d

ff;W,rF
0f15bf4e21cca58586fae47893052796624bb20d948f2087a88fa6589059216aF
0f2573a885d17c39d3733cec678c69833ac6d49b29e7e65f7783644066ec0b8d{F
0f278d26606d17a63d5e0da05a7bd5983a694993f71d76ab6409e00238f2d71bF
0f2b27230afc7e0f0e4681b53e974e613f93cdd1f542dd4b63a37b74db2caa55F
0f2b2ab9e05c1447b23d28c2912f8057c494168f4eed17e7d868e5970436722dF
0f4b94a13ab49a4fb2ac8ff3106cdaa6e83e43757720457189e685e7a55ed6d6eF
0f50b27c447626e536dd1b872545c9247a7634a66cb5763f417cbc9eea4790d8fF
0f5a8848daead9b08962772ffcfea5205ed58cc1314cf39de5639e4757359ea6cF
0f63545c1582739bc1542a1eaf0c5dce4c4ef0527df85045f95f6e3e58f7dc1a*F
0f67dd341c128a15768806e3944c813d90260a364561887b61378a18ff049547E
0f6b2d20fc79acfdc5f930788c81abbec7863d8a4d373229f80a9f4d126d1db8F
0f6bed5732bc76bfe3e0c85d59ade8d7716ebb9113974ea0d93511212d1907df-F
0f6e2c2f22024dd4f9db5cb729bdd2f2744882ba37e965a50b954f861c99243bv

ee:V+rF
0f725b790a384924e7b95b0b06d3009171c8060554b98e9cc285dabe9c324930`F
0f791fdbdca1788b246815a870b316c43b536133a58c0b7483e09cce243dbf52sF
0f79393bd746c2a784972b1db928fdca74d0c0324e00a1859ceede81d1af8b93IF
0f7c4de217d674dd4adcc5ec84c9df840a974061fb940697d0f1d2c3317bca7dF
0f8617080bdf5906164380f70a90898bdb69a7910d8fedcf476ef4c3300ccc36F
0f90f0d1b094fbfc4ba66750ee90dbf63d119647ec2239d5614a604299fe4555F
0f91ee82a0f353071438675ca34ab961c867b90d20e8e45c2472604fdc1165ectF
0f9586b6d0d300edc438c789f89bb5cc08cc5ad9ef33210f4da2aa9cb0977f06F
0f9b27fa945a2929eef54b26fe1fa8010d7cbd461cd3c645fb8cc62de85d5a8b`F
0fa3ba7dae428c14500eba9a62de5fd03fb07234b8db1fea572d45fa78f0e0d7F
0fa4711e307981d6c9174ab9d2a6a3091cae2a4a43da04ce41a45407c143d240}F
0fa907c7a6165ea080e9b32810b7f06b8576ef3ab9fe6df734c98ca91fd4ff1cFF
0fb81dae84cc52ddf4eb6a080d15e4a750ae48a9057d60e0322152493282eab8
2M[2}^>jMMF
0fbc642e2648e77838d136eb26008e221d165a8465fd50b51c8e7ef52d5c3376MOF
104ab2ef65171e91197d612304922a2a41a03bb8e9cbd65666f2899ffca2d489fMPF
10d9cd406a9424d6ffedd18a738deca45a4e4eb8b3d7040d57bae575915dce5e9MQF
11b4c218357ae653cc94b8f934d6cb161e9887b9f18ebd5184628d644e2ec02f
MRE
121ed67b550b9b757c921a1f6eba668e72a8d28d183054b14f8e1d37b81b602bqMSF
12a2e4e010484b9e7bd30fc89af801f0e1e212a2faaaa5017acde6e83cd52964MTF
1333d18f0d5f36acf0badba03a7250ddf92df7f789f4674ece2dfcfcd925f3b3MUF
13c6b2ac5e5019a9debc589efedb039c95513584922436476bdc65f0fa84b5e8
%MVF
147dc35e6fff3dff6a81de8b9ddae7411d557a2f80bb93a6b4040fde544b5c73VMWF
152dbbf3f7f9f134af6da2865820367d78a9a9699d7a81d9166fbe3415389719IMXF
15c7b778a896d0c127b0468d18a519b750dbd5a649ccba7fbb6b5b215b7243d6MYF
166d7341007094fcdf2e7262d74c699cb960d009945a221df4ba4a33d63ebc76MZF
16e7fce47c141a06695e847b179e86c984a88ba42655eaa04388c7494d0b92fcm

ee:V+rF
0fcf726d57a4432750417154846f7c22cecf1bd6d6e09cbccc91d48290d7d69f
mF
0fd4e46db83e6ecf64c063a8c953be3ba857eec99d069a0824fbc7cb3181c25fF
0ff1974a6100b7f2cbd7eed090daafd948fcf3710a299e3b612fb23e609059de
F
10051afb3f6d2fb5bf647ec9390076d0e4fdf72b804eaad8ed489a50c74d6237F
1006b3d0a088752eeb2598abc422708ea48c9813a37b05520a479db06e8b6d2cF
1006f493d08b88033474d82a195562d019c3fcf80328843dd0d8bb351e49ab25F
100f1234d4c5782b5913aa69ba66a3d90098ad06808fb39b4433d80beb94075dF
101d4c439d586a23bd095ccd9577412c6ab04356eb16a1563922718a2e88282f!F
101fd2608e35308dceb00d10e0a0521748cb0223084821b2a0bfdf550b1dbb11F
102055158159425115e1f789e5fc2320b09a7a6f4b5b764de3614f437bfa3e71F
102ed9eedebeacd4ea5f6fc19a2a0cffb500ccb7516b4f616a67ee86654acde1PF
1032b8922d675f553db7b6424ba04c52bf5594bf148d3c80cf447060379be540!F
1039cd93e11117af53816432e691fa32ce9f5c6aef8a37f44ed3c7b1291ba097

ee:V+rF
105a6b516b3b76e51de1f49c194fc9e35f3a871f57878abbb5b6a53bc54dbc8c
F
107322552a77011bd81b348ebfbb5f9181eec6a6de74a1a746e6bccf9773e1a6F
107479062ac7d45131a7f63b41712cb8d8bbc15a68e65ae36bc4612536690957;F
1098fb31b298327e754a43c15283034ffb6c1138ed0b9ba0e5547441891481dcF
109d66ff27fd10890453e0e8e39139cafcd73f6341aac559e6f00b019b08a12fF
10a06eabffcd2d73d1de3fa1821108cbfe10fb4977603c9f495854984a91542bF
10a162b74ab12cba105a1556951bb59dc3a6fe0ead031488abf12f3017324716JF
10b16b350ee16d3d6b97cb71b8b4c1f23359036277bb481e4ccc7cd698d26ed4F
10ba9a38035d22f8a1ee9eb610447ad60ca74948c3e82cb712eb09cf97eeecebF
10bf18711ec31e124e08d12cfe9942edc9e512ce03fb9b9ab9a4a20d6d665b83<F
10c0a3e8cca4f6a5ac8100afa56a4ced7e149d3968dfd722f8895b6144463313F
10c12fcdffb2b2b7e1abf077db33b288fdffac49a4e0acff89864f7742b7dd65PF
10d9b8b27ee08f5090cf1a5d694548af27d8f6cdc826e69807773aeb28c9bd11	s

ee:V+rF
10da91e17808a066fabc928e609db5fd20fe65299ed6b8fa0337fe213a70cb21SF
10f4d4344b761febc0bc92621104b56e8002faba2566c0f27a1152a2951005edF
1112275758e024da6aed300ab9d35464cd221ed62c67a573bd71242d60a699bfF
111c3beab8a3058046e42edddf8655dcd4e30d6e71bf5aa80d2a92dac1df6951F
112b6e97fc16e295181066cb46ff1a9262b26431c1ac47354e7d5d67d3fc1615(F
113bbd026677c12bbfb0f6803e303c762606f5f0c0dd003dac3e57e0a598d8c9`F
1140e209585f7f6f824c94f984cfe8ac43ee1498adcb74c031ce6e8e712d43b1F
11476c0df825b8cf64558132ab6c00817fd04a45533f011c2784f1a0df797631F
115dde7a103bd42e620ddd732d36ef609984603c7103f803f2d1d8bac1bef6c9F
1177f8d43f71a392da046005c8e1d337cda1f625f0dd12ae28400acc668f6b53F
117dfa1e07c65b202f4bbd0243e69bb5e24c7be31b9f971550d6ed083315bdc9F
11803c3ea95efe8e996c12cad83271ef43838dbf25dae72ab9afc3954d65639bmF
118a4f0750f04814284ed67586a40ab0b954a4f4ab7d694596131eb54460a3e2

ee:V+rF
11baa7d4bdd8079b0a48c38698900636641b8648bcc0beed5948a501e512c0a8bF
11babb3c74159846537e70da4fb01e148e8741a334bdc4689a5eb16b24a1a181F
11c4d1e2b30e04a86c011ebc0edda9c30a6b0f8a2a4c493606247511a8a39184F
11c70debdf0d39261740ffb0a5c8d3cfb7a03d7eb9be61a0ab8b83fec450f182HF
11d2a53897da8b2f56ff7a088f863588c6608a98701a107ae5cbb6d5b7b2e588F
11d3ad095a9838e98b8360b005aa07fa292cf9a71c4265bdf7c5adda14d463b3jF
11d3ec6a7cbf0f5ab4a611abed3a8e577bdb9e6c35243dff95e929892554069cF
11d891b8f8df76c76199d0d95bc23fe7ef53c80851883e2f7981576c44654966XF
11e7a9eb9ad854ce3901deb76ff9ab3e462f87d56766b9cda133c1fbcc89d812F
11eb54ccf2baedf7ad57449921954e6b13044b7677f41af6fba598987dda022fF
1204cfb28866866392e87bed4b27492fc16eb53791f205892fab3ad27a9bf935F
1211808e31a2f8b4a08003a44553ed8f98d1397772009e18d3edb51ea7c89fef4F
121ae3d3bc314678d6d4591403f12a7aac992b4097837f5c93e9dfa346814e6bL

ee:V+rF
1224b4daf58dc2c0d85e8536fe7e439c784d857c15e654ad9c5600780755947eF
12356c5566012c75f7cff8722dced224c1aa54d1c80a99482b0c3ec180432929F
1243b5c5c37f8cff61bef905abb14b3fec79b4baf0f8804006af238bbc09108fF
124996a9073a9ca8c3f0c37ffc32039a2cdb8a8eb5ae0de982fc65de11708c2c
F
124b95517eeee9deb9fa4cef2707b16c5530d6c6f263462b2c3deb2f8811b3d8PF
125ae22f4c9e8e637d89b849935d280420235c63f848bc2c66d739962c4cbf45vF
126385b940d5f6f201b6b30130139b0125b1d44dc7842c59cc7cbba5a9a4404d9F
126e1f4ba7b91116dc2de61216743f423ed250ef44140f20c97de01055c2374aF
1282baff4a36da2985cd30f9ea8f45ff5c8aa9ed747e858cf20363a7b30022abwF
12944ec5810169ac73652bcbd5cc441c1d5a084cd3877df22452e21f63a8b978
?F
1296d51c39d8f5be9667a1c80e53bc0edc3a1395b7d75cbce793d6ca7fc9648dF
129f6f9ff00bcf11fa14cab3ec12d80bf9b9612f1194adc7aaacead1b3e7b651QF
129ffba6bb846528ce31e13c3c411fca71678d07fa6e0e112e5862ec25ba2827

ff;W+rF
12a68692369968ab2848f9b52e492d4de687d092607a4bb029d6032c6b8512d8HF
12aa178b2c59b3f4c2d815f73b977ffeb7703da8b0da0e7a3a6f02c9aebee2a4F
12b6c2912b246899401394c661b0f6d550c810ec67c1a013c5686bebca186c0aGF
12c0315c9a306dde2cbcb74039dc11f2dfc2490f50ccf2ab16411ba4c3093b63F
12c5efd45c7ef298bfb73822c8f3f30c767fb03f40e504e94e3519f825ce6216fF
12eb69ce3ab02b67fd35247a607d73a70b5c657c3703598db21a9ebe26e45a42	F
12efe5e7e0fc2ad175b1c36f053e1a4532e1f85d27fe3489623cb945a5908677F
12fb546150a8175c1aa95419a75e512972cb4c6c8eea1ade84e3319b1cfadaeaF
13134e2ba51f0808b8c80f28f0f4a95f367f1ecef286a2a63576e93a76453a03E
1315433f5602796463c98742b5395f6bc95f0716a4d9322f2131b5bd23a0bcdcF
13154f5e2510e00d260ae211027b13f44ca11e49508ba2237ccccda2eea337b2F
1316ac625663f9009c64a89e399d60b4191a5bea7e69797e85132da3ccbcbc77F
132ce82de39a18ad1be89af9ce56bdf2cf2471eddae86a469dfbdaef42478652C

ee:V+rF
133710e665511ae5f9d0928eba116d6f2d1f06f71afbe0e7013e3d46a1238e21F
134406c95bb0e98bfe18a35cc06ff8a3deca7248e9196efcee6eb05a7a0dcd55F
134432ad69b8ff48c6929ed4f645153058d8cb0020dbb0be3eeb7ead882052b9F
134ebbe6274a1c839f7532e6c8c356f561d28c58fcde4685da109f394c8081acF
135902f9e5faac7a0682e6189f5cfddf652759007d300d8dd5ccb7d527fec1f4F
13620c99b0846a322488107d5cc07d2d64ddc79b24d8cd7eb307378a759389deF
136c98f13aca8088f8a6db32a4f1c09e88ab4e875a90611b2c854ca63a7db95aF
137fd6acb013717c21df14d056e3aec78767919094b31181c949789add37ed5chF
13955770f0ef1cb7ca5e13e21afb4cd0cce8b0b1d8181ffddb7f3fd4fad797e1F
13a2da96e0859c06d6b4b719445081c65053460547c38ccf8f0a2c1e06b039cbF
13c2180392f13ede0d3e45cf8895eb123d78ede2ff65fcaf4c05232a7cba595bF
13c3f114dacf10594cbfa9365b4107f3ea7e4dbc3dd4f7d0362049b983ea8f56F
13c47236e82fe68997766cf6d15ce0201350f4f534beee1f7e77dbee3e461cf0

ee:V+rF
13e6e0aca27ac928a13a8392353c51dcc310d1458f84cf2c8811620996c73fc2{F
13f0a70db8c30427ac5dcfc998ed9c2ea98da56b6c4439d62d54bc51fca0c198F
13fc5f5dbb279c4648c8bffcbb00b2e14727ae6ef9cbae25e6728251a8b2644eF
1409a93de8f33913e0adaf61bf58a25d2d2e6253e503e532e910519107835c33FF
141f11e739940e647d36915972ce6be77e89f7033f570f3ce6cad86a511b9f3f\F
1427f803b91f38e23ae66e6fb49eb6363167e457e76054fcb63fee011d6763b3
F
14290884418bd83ad4955aa6354b2113950b766239244a06bee2f2a364ba608f
F
1430b03046652a896ccac617100d4beab44c1c13c0d245b9bffbfe91817ea027
F
144001826455a5ca11b8e1701396ee66db5af5d0c7831453aba1309eb708a6c2F
145b9d5084c2fedb67f97a86a7a34cb159ed3eb46792eea9e063b1c632fde672F
146ca869c5ba405509685e617aa2689cda961f933ee72947d61013803f3d5fb8
F
147bc1295714b7317e539c11b0c800234b512dc4c8c7c1a62598b5f4204f4d68F
147c8de55409cc60a709e9f72364ee69759e7361564a732c0fd192e6fdd46d75

ee:V+rF
147f560470dacac3f89bc4c5cfaa3c9d32364fc302511f2bf1a13025a5875621?F
14915891af23de39be92b9e4e610d5fe1f11d691b6c0bd554ea4f71e130b80a8F
1497a77c838103e684f02aef90dea21228feaeec08fb162ab52cb8db75cd682fF
149c020747f7a669eb88245d5064fa806ac7462e9cdd3a6c05414ff08bdd43e7 F
14b4703549cb70dba8871814b76da451a63a067a0c48cbf78c90a94b528e8071F
14b5a03ea26d2ce50c3b85067c66d70c255d308324891750f4deb390e7a68518F
14c340f0dd683525dbfa9cc780253e123ac8b40391caeeaf7b12d5f35f96d7c0F
14ceaab30f17021789efedfc14f87608192f961f1318dd5bdb9c1278c54aad96*F
14d75975f6b77789e102a09b3e0c65a16a5cd38e795fdb34c4f40cf970a67b93F
14d9d53643fea7cc10917023b99621119465b51a9152b40c8803e3794b562f00{F
14eeefbe453cdf299889c12f5ada3a9024e4bfa0a7a528348d4799660822a0d7(F
150b5e83d6acc1e5a6e22bee18216d6c7e0c581dca489071a61aab70eb9b93fb
XF
151bddd3018c3cf341e45301fea7e855900839a749c197c0037edde602eaef35

ee:V+rF
152e52a9fea9de88492276d62ad1f3197d8720d0caf399f23d096b827375a6b5nF
1537999eab86e331b7616768bea67b873d68628c73c3287db0880ce0846cdbedF
155a01df2abb9e5b0463d2bbe0314d3147245d1540cc0e5026de16abc670d0e6lF
155f2a67548cb8ab54265b28dbf3f1e731e26cf182da45d98c95425930890046F
1562216c2581239f50ab2fbbcd1a38b49ace932313a42d97acd2fa2767606ffdF
1563224cd55060ababda0629baf763138a4b5c22b82b6494721b272e3e38a000RF
1563bc40289a666bdb5b6b948e788815b2b17e6ae8e32bd7645f8b2183f82d81F
158e955d20950ef61a38c645accc22bd6cf37c7f31e06cdd3313c2bc5b0d969fF
15929d57409b9d810314750e5974d9d4d764c8cb7d06c8a05aa72c3a1e815adeOF
1594da41bb4b69a611ac9e605dec625b69dd2f867a53943a544a8babfb76594cF
15a85325dd91b5d41165cb155f2faac7f1c67c75551d52a664027fc559a5c62cF
15a8be046768a2968cfabc11099c94d9e4758a47f1ad0a4684b5381191fef135F
15ba10efc121a3ed0a0eca1fa166dedb998e453bd44dfab80b4ea710432aa8c02

ee:V+rF
15d88fa90e0a746ab04810e8c5001282b587b8a21da83e08f7a05195f6fdd775TF
15dbef5a2991f085e58a23e6a7047ea54e528a6f93b07a28839c0b6e3ed48c5eVF
15eee91d297a4a3b7715b991e5411fa38326f5c44b7a58895868067a828537daoF
160346449f601718afb8de2d7f7e0aeb2ac8a5f4e2163d2f74d1b98233db4002F
1612a4f04271f95f905580cfc4cc94695b1a11ade17803d000750d518bc0e3acF
1617a73a615b21a99cc94d4baf19a16b3e787c5cae853c5b1ca7340d1dfe84c94F
1619875cba8598818f4bb31d4ba22a7d88804cab9b8ed1e66cb4cf18b1b446cbvF
161f535137bc7817d8e0950475afcc618e67819ad26590c829257f75ab51211c.F
1627c36660c246a28b1b4c12b7bb6265a2948ecc122efd459f7d3a78959935e7F
163de5925a8b793540385ac13a1624df2bd90f757dcf6374adaabf2b88c60647F
163f0d23cfe8fd01038ccb7746a4af46b5d8859204698181d3dcc73e81d8fb94!F
164f86624a46a2f71b3b2a951d0544b44be7971180929255dc526785acc3a143F
1661002b4d684efd2898ed72901055d3f780eab559156150f5421b5f448d823d

ee:V+rF
166e3f5af4c284b83976badb2166ef9cbf7ee9204cc585ab900bfe28006a7917F
168aca43a6275ed770802ded267285a01db77e46803e6ec90dad47985d8145eayF
168bff58938382034bb054ff55ce6aa5b0976326389d6260fbc85840fe154bd8
JF
168cb87176ec6a7a6805dcccc50c34a22945c1ebfd027164ff0028a1a140a637F
1699532891581ac8f26d0ec07605ccb1d294d5a52f3b72ac2d996d064199d55eF
16a78c16f102931cd4ab634fc4177b99535edda6436721529c1f30e8ec464b9amF
16a8541fcf4b2cd339c282e65bbae76ff488caf5eed0840a759841b6e56ff912F
16a9d3e7ce759abfcc7721bbe369b46acd4b3c511910e0ac4f61445d857f52d8
F
16c4eac47cfb42c7b2453290f21172024727ffd7444425d48a2170493b43db784F
16cbd958b4cd93617722d3eda68b3a078e46f235e47a40ceca9a90151e5ee683F
16cc8bcd9289899b14393eedecdb5d31b11e6a4d0c504f593037804de5878fce
F
16de628b418b1829da4235fe7e51f4fad2f0c73137e1c5cd7fe972ff2a960f53F
16e1a4a30424173e656cc48c68ae55bac63aeb586b1cd0e94eca634d8e1f153e

ff;W+rF
17166fc5096e5f62c88e7eff8f2e850bf452600e5d52eaf11a1dff4bc21c285fCF
1724001fdb91ff6c4e1fcf64bccf981017dfd7ab649f21c1333810e6cbd8e9c6F
17401dca64ff03c547fb51c7e83d60963cc03409dbba4804272853959d2b9a21	F
1768bd5acb4d22e917fb9f3d2c5b2d56b9563f0d453dc52f436e8ee1fe717ab6F
176be26252edd9349f87c81796fa0c0c19ed3e8dbd43a82b201b7ebab75624edF
176d124a27956ac315b44b6b42bb13fe2fa7702d805ae7b58731b8d634bc0a2eTF
1771d7f870046fcd2d0c96d054f425f3032a0f4271dfb54c5e5bb22cd2f87d11mE
177ecfa448785c1fa6fae690a5662325ebe3e141bf45117920f280b5a8880a0a^F
178ac00cbf99e924ca4b26e5bede47496404e34c1fe48906789d80dd955c9793F
179672f8c8746404f915bf9e8645d88839973a7f5e024e6b7c6a3e00ce2c6f98}F
179d2c236a9c0fd2a6c44145f3d47c793b7450b2e9967fb4caa8fb636c2090f7F
179d7e14905a53e3d09515993644464c53e8bf4c10bcd829502d153744fdf666	F
17a03afe739f681263e0d7a0e0adc83bc4c4a647094714cc9176e4e82ca51df0

gg<X,sF
17cb2cf3a7524082c239fd29082b6e294757fdb6175dc11ee0f7a52fb4e3fd76F
17ed16fa6fa0dce15c8b3485e9d01613b70ef05e54ce42b4ead591c57c7f47aaF
1802f181e6589961ea6d796ae4920da55d454d730791ccea8f2c37d1dc609c37F
180fe822e8d8229970daac8f8d746b4a0b83877121f93490003022ee941544c1
F
1824faf3f57ad70fa29640a76cd08c71a18f5f97c91c1117929ab588f9aa44dc
GF
18263e1b0a03802679269ba3b6efec82086ba491183c1ab84bd9de4e5a98c0712F
1838c4a50fba6cc7f01b473b8ebeaa6c7edb92cac0662a563b2b802ffa0fb3aaF
1849014c019076934853ec6d7ad795b91829e59d3946c36ff4c13951f53c6a67F
185387ed3f5744ba48ddfaf8a3d5ccc041f095dff1ea382c043dbe6835d3e739E
18552d6d05e89198db7ddef073bf9f88ff81556cc037c82a133b0eba4e12c71aF
186d5436f6365f279482c72b48d2038d776476514615d06d9fbbf8a163f36dfbE
187145d7bfd310c612f73b86a31e75562cbe69306dca7362841fcb038b52fa3bF
189ac4f6255d2b5abc0708dbb15227064a2197770e4044055b575c335118f124
1Mj1|]>jM\F
189cab5bc603286773946e73c42d38c539c7a0de2d36fdb6fa6aba0763c86a44M^F
18ff9230e89f660287403152d255b18ab93e778ca6eb16560d9f2a33b716775f
lM_F
199c200e85ae57dc217530a09f2172f136c763583a9869d518e3dd7c2a2f3c24M`F
1a5b2d18101ca9a398c7873900403ed4ffc7daf7fb801a9ce1649c3fafe185cfMaF
1aa7058dfddcf6000119e4d89f90da91d35b7562587f5a8c91a2db80781c6303sMbF
1b461b4e217ac5f51d8990aad583c7f189e73fd3220a54053124772b83c42ebaMcF
1bab4a2f960faa0a69de616785116c776e018a15bdc67d8f57416af2a12896db
-MdF
1c844415d79cf4e5509e9b7ea70274ecad4b7e52cd6d0810f0df2dda40106afcMeF
1cd93bcccbab328b508e869ff3ceeaa30e1ab5ac781b7a6c3b91207832226025	MfF
1dcdc8db1818ed7523d6f6801be8434b3245034ec83d045632e076c4f10742c0MgF
1e46d6b60429dbed54c038855d87f27518fd4c4f7f6e66a15ff60a3bda266f78MMhF
1eb686e8a290603d5223ec70ee6fb522d7289f9e573548836dfd8858a99a978bMiF
1f633f20c7b2aa6eafb4ac8894d9cd73727c40432189eee52f62aee11daf62e9J

ee:V+rF
18a12adf2bee6b8b9f5f9ed18be2ae1759d9d9d3aaeac59fd9a62973cfd8e759F
18a2c3ea2e2d5c5ae12660bf9eb03c2d3889e23de31d9b4ab4402b973dc2b813
F
18a944fd24888ada7034062b23c8096dad6ee599c3c1262ac434394919b64aeeF
18b2663b932253d1cd4199938857bde269a7f2c90665ff7782c334d88b68f7b7F
18b6542a7872436ef0c7efd318aadaca8d2c6de3a49d4cd5fd54986bf4b9109eF
18cd5d8d39b9aec1631228c86412a11eed902b967a26b6a64c816e4fcccaff89WF
18ced00cd6c1f923fc88ba96abb6a1ffa4ccb1baa01b41e22d2c729310d6def7#F
18d2703d9432cd3d8353acf0fb1f852fe4c15301b3d49fffac3f0194c6a4aaa0	F
18d655d9234417eb4a995a66801cb9c7ac35362aadaa734d8674f8e744986b8fF
18defd29c31366e3f3fc7602eed4307dcdd1028a8e25fd6823379fa2ef33eb6bF
18e4458c6be87d024a157c9233b2f318b21378e4939151e17d4d302d944b059bxF
18f14d208b245267c6cc29b0b7074e0e030ee89e895659c26047d4186135bd94F
18fbc0b4bb2aefb2e3524107d2daa21178d1d96eeb51a3421ac5e3aaae21aaa6;

ee:V+rF
1900d58b22825187824aca7c1c6d194d7a401d5fcf0c433dc2037ac97141b1fd&F
1900e396d24a404c2bdc5dd7198c7a0a6a08171c7ea6e2c4eff77792f3f335edCF
191e06199dad5d65a5b31df32a668436cf290b67dd7cdebea120791a8af5661aF
192e0475321fe56db4e9593f45ee8e350eefc332f30d7e62d1412741c38ef09bF
1930ee508064d9fc5b82d42aba3062a28da268f293b47a7af9f89dfc9ff3fd1fF
19575eb2feb5e29ed339c078e462e2a4ac7a44f0888328185fc248a30681b82e
F
195f9b3429ced50e475e3f14ae59ece2ac1f581466cf6713231c9da9927283e0F
196df95b9b19a08f79321b9b3709379e9fbdf71dd5cdc4d74bd313d84468f412
F
1979501bae62e6070c0c6037b5547a69c4342485df1f9dd821ad18a174b0bd48KF
197c0516912c709ff341d1764b675758fd47d18d35c0f69234271e78366dbad5 F
1988a7c1f3496679d0f5155d1ccdb326d4c38efbb8e673eb67c29ca61004a3da
F
199014d97d9be442d1dce91e30112d132e8c5ac82003d8631976c1607ad2e159F
19978c4af00a791c32ebd350c7567fcaa35f1777bf2095ed486565c265b574f7

ee:V+rF
19b1bcc147b66f7afbe531c0ce8c1100de0382c508ad062a80e80ce061782f2aF
19b2915a18191474719e65f30ae39ec3e32b24de808caf1144908d5905ec22dbF
19cc17be5a8b2b11edcbc35b6648252c7d5913d500ab82bda2d44c47f0d3f440kF
1a0a2c585f883eff1f329e4976169d243f39b899c3b430426cd6e1c996b89624F
1a13b258a98c48877d221312e7236468718d76e2db7278d2da0271a016036278F
1a19777f00999ca9d5a879d29fb67c078a61e7584353514d1ff9875c172b83beGF
1a1a8ca0b3ee1af1eea431740811a8a48d9564e81093de7dc250d46e47d3383fF
1a25dc8c20fd98c6b44d7a50ee5bbeab01a9250c1764965613176ca25661a781F
1a363c8575a8323b1e1cbafa08ba87655572c3b032a755bcf5cf957927fb9a70F
1a4b2811d9710ab0cbee6c14d0d65efdfcbc1fb050caa3686160958d16c06337F
1a506ab0d1bb5fe446384f454d2e3cccb4d626df0d87e0effd61680d6a9d026boF
1a53c3292a73f1254003ddafa161c57842ace3830adbe515eebac0b44ee7d99aF
1a57399b3dc42160f3044e768ceb0aa76dee84a8c852b6e9c99ec3568e52eedd

ee:V+rF
1a73f880c24703aeacd0795c62a4ddd8fe4db2ca199a961180176c9713e3fdf2gF
1a74fcb33103de74d5129a6eea3fe37137b7cbdc136b11a49f79822b8fbd6194	F
1a762e2d8882a0c051d0a322eb97ba3c2fbdb843e16699bb702cecd284f238faFF
1a7644fd57be2d7e96c28f3c6603e556bdb0d939164b61e085301064464d1aa7F
1a7fc39e7d481badbe2fe10dd40d290dcdefdeb4f572a8affee7880a751d5805F
1a8201b73f71ee44efe72426328fc48ad33413143a7f40a898fb7b926034487fF
1a86cce369d4fa519dc82e79409e0ff8f027575c7dd5f588f2c3ca8ed78e840bF
1a87cf953d16581b70a51f9c131f6f714e364e0a57dee8b2856b43aad7d89104F
1a8bb6d0d5d3a9bbd2452e189a4bddbc5fb7dd910ae645de886896daf57d324bF
1a901043d59b38297076c304b82d8cf36fa295747a7273a0009f8566a93e0988
F
1a91953e84dbe2c03ef4d9284debe9f3fd29f808a721e032346b19d8191151ccF
1aa4d5a6ea319219e3813cc9caf102cd6341fa2aebfa9e4b9096e4e1df7854d2F
1aa586cd752451a887e64054c0eda881403fbc6b7e9c6079ce1e356a839fd225<

ee:V+rF
1ab3f90a7eed6a0e8f44c9833e1def98bdbceb194f37062e21cfb6fb030563e2cF
1ac0a06d5f14e63729e4206d6934c71f032a9d594c6bbb5ecc1c0ceee1abc06d8F
1adcef07e0e83f4fc27809eacf51bdd1d75267095f0cf92832e1d636e04e477cF
1aed659e1e3bce0de9d3874074bcf4fc4df05a8018e054fdb5ac7209dd8ffad7	KF
1afd010d898c09610cd98864d1e601d56fbb031d59f51f0e0e1a08fc482b006f
F
1b0076a98d327d7bc0db69b985d05e02f9d0e927d5d7645ad2a14dba64ceaf52F
1b0d419b8d0ecbbebdaf88198d39462c8f0babefb9b711f46865cfaaf19e8ad2F
1b137d71d271e1a3ea8da17a90f65d981a49674c7781a7491eb07f02fd41cee6F
1b1b3c99c21402de3620ed1fecbd44518682eccd70866a5c3c361b33f649f188<F
1b20547bbbfca3c83fa9317da6351d845a3f6ee818efb377f5a74fe92ae5a2fdcF
1b2a2bdcb8f8539c6b2c875f6eb99acd1ce16f662f02b83d2dc3dd8e3408c5f6zF
1b30b4a38b3fef0e81dd1879d3e9b159f739eadedc3e869eb5947a4bd3b25968F
1b3f8f389416ac835d75a09fd6027e44daad1e8447c349cac349b674506ce80f

ee:V+rF
1b481cd6a6df8a141bc7064b72ffee022095969d0a25a8b9a57bfdc1ec3af7be	F
1b57cc987d64b98efbaa6f796a3df838d4f4cc4a2b892e4e19685ea37ea8188dF
1b5fd99f401b83a160bcf8506fd135056203e2df730c72f49440fe457a1ec20e[F
1b6f592d463f10e592cc2b035e409be816bd6dc189d7457574d5641fdcf767bc	CF
1b79cf7e51fdd270ad47abaf4877bf5ef54856e2842af27bf476d4129bf130cbF
1b7c83c31498a1d9eec34b76e89035fa039c4d34cdfb507851df956c9a5cb86b?F
1b815a5f718f4c8aa2b5ff3b119fa6fe64709eeed08150a007a61a3d9d4c50eeF
1b927fc58d94ad45dc78d0926b1fb83cae72958110a6ebfa24f75a5d5a9a4b4d%F
1b9318b477ed42cea383e924a42367b049b54e29451b58ab4f7761a1c26052d4
XF
1b94bec42529799dff727dd6082c4b038c96227041b81d95f21ee5457cb4c089F
1b9fbe198a3af7e79bb697022c8043d39441c77daf5446b0e0b8e7f5c18603c8OF
1ba4f8757a2691d9efa669857ab5fb078e658b82755130941f6240d178c6b8eeF
1baa9cb2d4f8d4300ac333fbc7bc130dce9145c67aea3bd6efa4a0354fc92b6d

ee:V+rF
1bb75937417ce4c985d73d9cf214bfece58dd2abdf6c21d4b1cb0108f070e2ff	@F
1bc4e395f855f18adf61d113affcda6539558d534fd9b3ed379bfa03301bb5ddKF
1bdade2f19c49a1f75262e570473159eba076e5147708897ef26211f4c3e6253F
1be054e17c50261a454bf852731c5ce00520ff292c6811df3d49ab473f540a41
F
1bf8bba46b2c5ea348a5a25ac9f2104263ce970c23bc3860e64178099e215f79
F
1c0761e63af4f982fec4bf5ddbda7da44c1f6472883839db48386eaaac902785F
1c18af2ea0813b4f11b632925aa26a45a80769bbc1970188c2088f2a572d15f2F
1c21a4bf7dd0a9330e1d0f9859575f2ab5436413cea65a4a73f0b1991f3dd1ceVF
1c34f59825eecb09675665b804b5fed5cfba3340912d9fd887d39770e7d0ae60F
1c3887c7641e7d177a4556fa5d66b74cca92bdb865265509120154804c5ddeabF
1c5b7d04128c901ef27ab4d83ef677d205b161991be8f9d8b1210a92bde8b3abF
1c7643a1efa2eb22c7167b8cee83405baa0f986f5f651d3226b0e0e5a443279dF
1c826c2145a30350f476ab5a9a6151bd349415c6cab19956813fffb3b864a331.

ee:V+rF
1c92e98be2e233ea55c194d01aa73ed4184d0ef0f92f289e7070396b6ea55cf5mF
1ca99a830f21e3f243a3f20099285c28e83738059736b8931da396f1b77e1b0a_F
1cb1df73a2743fe17a9ccf9a82ba1339ff309d7912d173c10e2a3e8ef400fcff@F
1cb47e9ddc0c4d017161325b321b5a50d4645ac07758b0d9cc09ce6180bce014XF
1cb65029ad75fd77a7975a1a11ecf00d33c40ae006a565c6b49188cb7f9eb6ccF
1cbb2208fd1a88235398a0429e2e4dfaef8c5ce0593aa8b550c370224ca23fe1F
1cbeca0135b7f2bc07c9bcd75fc0fe3f09797e00adfb9350ced9cd89eeb77a8eF
1cd00988d4a50430747550422159355a53806a543c45da98d1b08a6114cde7cd8F
1cd1ae8c0b9506f0a8066d9b0a935712889175386de9909062d20b0523e2876bF
1cd646bb6272d044e00b987d196c13c7541d1e953946dd96356956e301fda53f
F
1cd66f531b9b7e67edd8521e39973708061ed0dc06e81bb64cc48a56a3115cf5F
1cd733c69fed61cd28bbf528bf31510db3dbaaa4cbc45ab7ed8a654264b298aaF
1cd870f8b1c30e2f168c6960a8dde4ac59970a62aca538042b33d37a679f1a3b

ee:V+rF
1cdd1bc2cbd53aa25851e70a8024e7e85db9b9d0fcdfcc2df323c89e5944ec7aF
1cf3973fb3523d1d1a511479268703611131014d54aec79f628f19fb4b486117F
1d1a5f1c9af127056984dbd611ad930070668a97c33632c67e5261d7e1cb2491F
1d2c5ccf5a54793d996b971ad4448b1d95a72bf1270703b1cdd944b0b4a82932F
1d31499d687de8d016bd60a5b2fbacf8065dd426d5a48f4060f427cccd242680F
1d55e611e9d8085d8a329b27450b4fb96d5c488a59e0f8043df68d8765940b62F
1d64801f6bea041340ff67b2461569f13a202632b966b9ca8426a8027c14353bF
1d8a98543a1bf0ec8722595afa191584c9cba8432bcaa4234ae07105479c78c7F
1d90c0cbed34ba8bd0787832d1c7deb1024fe2c25a4f9accea2b95c7fa1c152aF
1d9aa0d9b3f62047faad0dd116b485d64442f569bc592a53a88f39ac5ba871c7F
1d9cb7ca8c804f9fa970b5e2df8cc163112c6d02f4769316009d22c080bddf91F
1db80fc0b7ec4ad66d1f7b86e831c3ed4d4386b1db1558cc7afcecf08ff5184eOF
1dcd5933cc511b7268b7c46d30ee331788e825ef5dc6aeefc373ae7708e575f7

ee:V+rF
1dcf380a319a132c90457bf82f10d67e9fb2f0795535e4a430c15eba981edeefnF
1de65c5f5091d176efefe324dee42e11290463e4e9d6a45c2bafe24ff7a3a8e7
F
1deb2c2c595359a6d9ce1c3cbf28785cb264b03e34a46f8a05bb2c2922937dc0F
1df29b4610f51702868338437a84151544ec5f149b1abd3299bec1abd9aebb57F
1e050a70197e546f07c1f78ed2e33fa01d93756947ab17d6c3343eaf08eb2702
F
1e079edd2e893af3264ce1312a543eb600f7324169393765ef4fad6463caad42xF
1e0e7cf67ede91280fd5a1d1a63490ea597c590a44d12ba3e9d2c08a05b703c1F
1e1c43fd5f02a819df67f4ea70bbc1d3725d96664de7ae2da966f9456b5ececfF
1e1f0a4ca49b831262ecfe3ac11e0eaf955da130a0d8c2a9887d17d6514fad7eF
1e2e0f37c2f3a9f903d1952f17782bcb4362107488cc541c0bb3de118635d8f4F
1e384389a357083eef224ca9752df57e665959920ecfd6720d9f58d63924b0b8F
1e40420731f3976bda8671ed42244cc12837a19a812572d663d3731cfde54fc3nF
1e46c617c397ebf4bddf22b24fc3c9121739db329c756295e2c7fac068c4aab1]

ff;W,sF
1e539eb940638371c11f0e077bf6396b4c0afe2d8a5e55e1a10d9e05b8865487F
1e67462d537e085a22099169bfc37a18a1e6f210a61839b9e0b229fcde3add6eF
1e71ddbce6e19382bbeabad1c266e4c7cb09e2a56d99175af4ac9ac047af3945
F
1e843fde687553231eecf687163be424f4d2df8b4398e28a34c6dff791e1b161WF
1e8d63f3eb80cd678a21631ab2ebcb9b62ce51bba0f293bfe51b327fad1145e2F
1e8f0a4b4a44bd6aebb338ec755620508f9ad59babc55b9832396a5439cbf5832F
1e8f86c76054032814d84435dbde30e74557bf6a1f7136131394674bde65ad63LF
1e92ab11dbfdb95e9151c5fc2f4ef713c7bea0d91690886bf35bb75cd70c9870F
1e9916f4ea1571cb999400331ff1a0186d71b4f21844b0f5ed33712e42b454deF
1e9ecb13d56ad5c7fa67acece7a0f89c452b11bad3fc66a7589eb57a67fdb766SF
1eac2001120394176840294e989343eb699519e8284843a3cdd14f5fb3f39a95E
1eae80c524fc2bc5a90ced35062890a40b5625b866e658c984d2c21a6b84fbda|F
1eb2e0f2ab532fc7491714b9d8dae34bf6977843c4b9649fe0509d2fc7dc3b59

ee:V+rF
1ec9ab3e99e2c5ab2c09573b75bace2a32b399ef7f96411b8be713b0793225de+F
1ed3b35b8ed762f11879c5cfa1d97f379a6268de2ed28fb8c9b9c0cfae430cc73F
1edd338d1d20b130c1a107ea59652842ef0a8167393745468301105b2a59ca6dF
1ede1f94ef149ac05c9b87696792135237e12c4f7eb09ed33fcb232bee567817	HF
1ee43730cfd6c1751ff45f321c91c0f0965e683e47cb52b91f87ac210ed93c1a7F
1ef57080cad8889aa2a957bb771d161af38b61bf4aec83a7fcd19e2dfe510079F
1efc77004111254487934c32f189a3b3fc8b1baf00a6e8350558183281f3855dF
1f08621d329170cddb192cd470d84cca45c4f102f80f2763f6ad12bcd7d94903F
1f0f6113c67eb17059e2588bc76ce4d1ce793113d638c89faf42684d92ac2c3e]F
1f2763028ec3d49595e594f3c26e4361b3462c3391db1c8dbebdb12aeb792896F
1f353580c9e10d38968fb29d6afe568ae1887002f902073726b229aacd22921aF
1f4f286b0441b2c508c416f72ee52c1b323a1ba12aae4579f986c007ecde653fF
1f62ae8c12fed4f7639f910b2b5ff758d169ec26fdf5536df0cfd5d6bee2d247

ff;W,sF
1f800a61ea4b98c012916d84ad280573560d18bf31af0e459b43494dbf907a0dF
1f886544574d6a8eab00de815966c7ca8a7292ab3a2ac66dcb19ce07dcdf04e0~F
1f9b0f9eecf8b7a6008d7136a85ba783f0bc60894d8d724b0adb44f56d167728F
1fa785144303de32e2279da8e40942e02967bad3724f4de700446c1ac09a1b64F
1fb9ef577f0e9e4a896981792189019932788dd1325084e83bf11f422ec11e55%F
1fcad50692febc35d99fcc084dee4f58b8bcb6471e12072b6ea2bcf2cfe49dfdF
1fe72164363f910c775d358dbfd20b12da516c49d28c4a4388ff663a5f4291dcKF
1ff119238acc93098135e4601d4178d8f681c72ad91be0993739d0774b0824fcF
1ffc8e6c986e1cc0d0bec287cc7ad4bbb77cd0ccc1bcb147a4d5be35dbe062eacF
2009ebe5d0c47032c5784190a92c5dfb2abdff45270eabce812d7641915b2fb6?F
20135be9052bd1b2d8da133fe7cc987b80d4dc2685146012968f6b8e78e0bfe9
F
201819cd83614093dbe14240fec542722aadee2886e13b2006ee8f6f0c063950E
2020ae44e6c85c50fdf7fbfec19d2bbaf6f8395f641b1b48c4743285b9fd8bdcr

gg;W,rF
2031956532e4c86af01a9e7885660b200d3432a40e8aa1938e571e99424f7b1d
&E
20385107dd6a4623cd7aaccc57b216a7fd04a22b8f56bf7e874d9fbe49095bf1gF
203db2e870a8753e2c1ba5897367c0822ee2a5c79b866fa6486effebd9f23b96F
203db3d0d6a1ba449e52187f6910583ce0b23cd0c8ee52676a996d6659236bd9@F
2041fb62286ddc1875cdc0396db816edd188bd1beeb362b3e99a3166a7bf8179
	F
20693e146f5e799d72526af73b57a86d3d7d316b6f7e0678460e69cc3c684e1eXF
2070f81e2419a997f63d16358fa5bce8d6ec0e00e5999fb5444e8c6f5fed72c7F
2077a5a2df3692687ac9b3f892005ec2eabe97368eec05197fbf1f961f013442F
2079fcbe2c07aa0485612a667be1c81504654629f2931e7110664db306550787F
207aade4092c5ae2176b6a08df041bef38194b9beb887c0eecd8a4934aecb6c7E
208142489b5b939b70a9d0d5242ac84ad700f6bc7f8549c1b26d447993c66b86IF
2085e16e3688337145397ad071965596e29a2b506f9ed495de26bab6e9ad7e4elF
20865c1814ad86f27c05f9c958a9ea1303c9b5b7762952f4c5f8da12d65f4cce
1My1|]>jMkF
20887cda88d458e236a1d13d68fb01b10056907594d573f0342d40b9bd677d37MmF
2111718d7572c52cddb1070151dd723808174e0f46528dd636ee9dd3afc41523	MnF
21af3e26269599f29ef700b687a3e84539aa03ffc025f0794649d54f0a041582
4MoF
225dcf54b58bc05175127f8b4645952fb99ba04b377f788b193dd25888a029ef
MpF
22eb2233053a534b388c3ed8e39dfa1b4901d5e8b1e278a8c843c301c9db2488MqF
237720a4e9199e2738ab3196d8e7c59b9fa4ba4d4dfc2395b09b8670e45f802cuMrF
2445bee7e1332244f8b40961bfe9f59880197fd2e4ea9800c0b288239d229acbMsF
24b248d1220fef75f61061cd2400aad329970e06b2f254507cdd35348d968aa0MtF
256f88bd5667a9d5534690123098dcb92c0e72a1a20c14cfc7fc6f93d1c33891
MuF
25fa10449317511df1bc80c25c0cc1e7bede87a02929b5c0676ce9957353a8d9MvF
2699d7c26ffc9f022f434f324f0530dfee3fbaba767104e9902922124ba69b63MwF
27200e5f598a44637d8820694fe7f924e715e6052b300a7ab49405cf2a482a7fMxF
27aff6d12be971449c18fbddaf62e746dbde00a72186da96eeb19d8af6a3783c=

gg<X-sF
208f92bb62fd7e69ec6decb3b63b18a2c7e51d8c1ea83099de63b56163c9d1d2F
2095e4e98eb5962eb97eb3c3165dd036bf0cc42fbb1cfd2c138811047868000f	F
209916882b3c80523545c0e55445deecfae6f7a37cc100b47fc3ef29971078e6F
20c77d771507c889e3dc80615a78f99df44de70df4d11450949897b0fb73e028F
20d48e214a59a2848b7152ea8c378eda0ab10d93902bef3627ec70603b8ad96fF
20de254161b05ef02d837d21731032c8f4207723f0eccf9665c6f04f2b1e2866DF
20df00700ce564462df55efddd738d3298f0144e75431e267025497928e55dd6F
20e9c59ba021cc9600dbade71b83e1e1b014eae44d6ba273d5fa6491d9508f08	F
20f4ac29a67806ff93314f45fbaeb1158df4cfcdc8bcedf26aa23f8d8449da24F
21074e40c8578a4e4a866f138184265b3827027519d1d1574e83df6ea2d30c71E
210a76b6e2c83684ac3c106fff35849b22269be89a5b895625ac4ca5bf489796%F
211028daa1af91e1fc841cb5b76e2f4edf63f510630571253c89635fccd41209	E
21113ab4dcd135895d98e51d9d540e8be477abdc44e185a460a9a835e382a7c1p

ee:V+rF
2117399e425ef95fb4a8b8d38c39a38d73b5e0ad8f8212f6e467901f5f05ca9cF
211c26bfbf530d58f28b3bff1ac40338e642a96b7252fd6857fcb26e533c5790F
21239c5b9999cc70790783421ae9dd4466f9017bc973479de248a20ed5447111F
2128f5867b50e91bf6e0f43a02f4d16b03085189d8040f386c115ab75f5a842b	4F
2130f82985059fdc1825e34c818c10ce54691d99d56fb5b663cd8452c750913eF
2141ba5b56fde898fffe70f5ebc0e8dd7ef3958b68e0cb81881c570fbfc2a0f2	>F
214fc2bc53e4979642949a2ce8ea6bd43bff20e98fa27016ae4ad1be3c189b60F
2152a348fc6d94205b82143e948cc225b5abf2e72debfedc99a192d0540f8dd9F
2163bd81f1d4891e8048088136ac2e2285db8db7bf8cfe2aeb16b8fe1d7f8085F
217a929503c5b9fc47654c4bd44a691380f40b921379b5acb0c12f913296b4ebKF
2185f211100a288fd632f43d7f2b186da452c6d0827eb87dea7ac3154a5e94f3F
218cc9a564ccf2b06cc13a609ffdc007f0f4e45e935a32631db3d78e1c63ccb6F
219e0773f6cf831ca0c2983c48e45797cf1ed6150a23e416cebe02b6c43d5d35

ee:V+rF
21b8e6781d07f056a511706388aa4397ee3bf2578eb1f6455af17956f29b8a3cF
21c9f734ac2660b9ca8602966521796728c6e3830a5aa75fda5d6c6674d2f5d3
LF
21cd1d5d48d73a90f3072f23c5e4e21283dbd047dba314b528013a884054068ePF
21e025565c6df51abd78e6c98b69d9f5be23937f57c5a64c76d807474bb9cb0bF
21ed5458a8abe02695e7c68bd4c068debb35056a454d12b095dcc9c2dd435449F
21f326e5f1282a6a5e71862e6a10e53257b80f7942532b86fc740c5060bd5d66F
21fa1a95375af231395873580adb9f748d65f91c14f7835244aed1cbf60db644F
22218edd785c94ee6fbbe5ded89195ece5e0450abc17b7afb225b4677b79f3f10F
222af4af29ee9e4dea368547514867dd1734fdc205d9dc9b484dd99e567f4d75F
222d1cb4f63704dc1cb456a7733ac13be509de7210e4f3ef68095502f871ad42`F
22368115a8dd7ef1ec13ecc12ebfa7ea254651f0f7e10223b188155bfd2552f9F
223ee648bd84e6a7bd0e7a0a189113bd1a3af31a18ecd5529530b10979cd3328xF
2244aba731b0cc66db6a9b851a8fa413e9243bdd8fded42aa81fcb9d5c9beabc5

ee:V+rF
226ad3151c609e6c6ae4f2fcadec7bd71f08fdb6c976380ebc8d8c0eac5afbfdF
2272979129fdda737c2763fb9bb135cf5763b18ba685523ac289d17b110c0dfa<F
22822221e0cec5832d579c490f43f73da5575489c0b0fe6c53f5d0ca3ffda90cF
228b8ee7bdee5b627106d8959417f2a8b8b2a44b8b631203b220ccb5bf160b83F
22a2f90a540cd9a8330a6a4c96da322865926757812e4c0fdfea538a351e6f5a
F
22ad74d75ec657ae1c2e0ef0ec2331caf9bbe77cd9d4af628f4350d8891164d0F
22b030d124eaf33b5a95d386b50c0b6eb1b02dfa96a1333d4af435fedbe097b4F
22b2f7582ba663c4bb9f008bce4f7a80e69654b30b05c0571864b3b8292f8ff5	BF
22bfec4ae12f95ec0baa30ad642504987294442f2a28150fd5c850b8aeb04373F
22c712c0742c37d17a067192cfa1bcc35a1d96fc1200fdddc0f752ba8df52d72rF
22d64046fb95580843be1a65bdeaa8f2a9beca7721f0af5f20f9263a59cc2977cF
22e3e72ea0793e34fa431ce4f6c77af3460b1cd5e67558a3b644f1e438900d99fF
22e7b5d6e46a23025f394d1dd9e25e4e5cfd1c5dbb00f74226f20929ee065bd9	

ff;V+rF
22f6e0dc0621a93077ed64c276366eb9c44393ec755722b64a175a9ef296b112wF
2308127baa502197469a17cef0a36622ccd5c528247af648e424284943e73572BF
230daa889ac4a0bede450aeb0258b6c9db6746486271506eb2037b877bbce588#F
2310b0e53fdf17749832f558cf06510e127435a1cce7658a84665de1bf9fa2e7WE
231493e830d00be6017e14f2838a22163835ecea8facf688b9769eed88f3c9b2
F
231c99ff7648c2fa512b52e36ee21cfb15033bb178cb5c38c37a3928feedec99oF
232113158f29ca0be28b87fea599e2ceb671ea597d510b952fa9490d78950783
F
232b24511b4ca567b436255eb6fe7f9fe68d66f2514a25334fc5cc4097d48238
0F
232dc47c310816030f4221dedbaacb35004dc24f0a8fd53b574e4aaf87fa67d7F
233182440f451ea41600279219e708b82494832752dd921ec2f2e4c0ab2a7353F
235100bdba26a1af51c7f66f533d9318837d01dafa0c5e822245c8e0e5469978F
235d7a11f2bec5ce59b3207ad420c1a0034747f77ac4902d343951c7bd4109d6F
236b16f4eff9a720f06ea780d58be74598f1326a04d143dea2ea6a3bf5dfb061

ee:V+rF
237858b698163e9a4615ec1ab98636d66cd7e26deb3512708bd88164019a1994qF
237bcee37560d0ebf83c164ac3467d48d1c0e37558d2608e16c324a417061e16F
23872416b1e3fe4aeba522975174df37b9536f0c3c2394d432e0af7788af80dfF
23886775cbbf0f0b980d7e700a1fa3cce9ae8149522a191554e770fe0acf1813bF
23bb9783bb909c0cddbbcaeb08d2ecd0d27ba3325b65571783ef5837be019a60F
23c887a392429ec463dea994475481a04b8745d5f29926c149d6f3f48c5ebde0F
23e60a3de6f5ccfa5704efa5c39a19b795f04e65312ef6af6e4264233e4fa953bF
24039275da54c6bead07277fc20529befb42b1c310557cb1598abc0ae73b37f4F
240ac23487f8ee37fa0e974ec81a99ac0f9ef344259c12e512cbca60992948bfF
240e9a52eaeceaf3760066a892aab0f7a74bac5492ba14ced65ddc253119eed6eF
242b3c3eb9d45d48b5e607845d5fbc380afca79449f49cf9cd801ea4a95ef419QF
24374c0fbadcce0d6917a2e88255f302cb3f4a155216a45c8492da80d78ae47aYF
2438f52168e5bd5317e5aae571902a59d445fde074f9fe592ad04c60e7fb4d82

ee:V+rF
245bfc9c157989c74777ef47e429b5b2823da6b25f940cc71fd0fae7aa230185#F
2468aa7b84cd02bdd3dadf04f5dd64bbffc5ae57ff7ef4a973bc74b29757bf6fF
24699358bf47868256f0864e15068069f9dc2d6b473bfc07b8c40d1a5f0bf3edF
24769d4968eb49e6106e6ccec86baf5eeb3e053dfd03158fb385fd0bfd8b3cd7F
247fc0e92238ee99057179d386718ac73601d9dcbbf86ef80e98ec27d4c7d86fF
248724675fc45561c18b6906dfbeacda8c1e9b4451c512be528649e3e34c63b9F
248b2b0bfb0de8b031b61088bfef62e0c0553e6fbfbf409774f977e6aa73b58e\F
248b6271c4100aa6ae97c9a74a7d3b0bf217ed7e074e51ff84d4eb50183ea9a5F
249e4941a5a5071a668ba290a7dc5e28013fd43206a9a9b2a2a236220aee04dd
F
249f14138ea4a9e978acfe243db005efa9310dc87776a7c89364e9d0332dc70b)F
24a29d91614a01ef8bac9bbf460d34163c334449765b6003400b4298035f4ac3F
24a92c5b29a507c8439dd16dba779ab76d6b93fb7f92021e42f3de1dcdde9308(F
24b0fb3cf77c1414e8d4be523ab73cb876049596622b95f63dc9c7aa989b80665

ee:V+rF
24c85de4433c7d3441a0b4765cbe8e897ea5e9178eca2d1f545940ae96e7f940sF
24d9b1ac9ee09da7c86076a3d26116d0eff8b39fbd7ce382098d1fb81ce2481b9F
24dee6e8be939b14900bb668c0f5908df2590d8188545bd59c83122ddcd7a785F
24f07a4fe7e067974796688aef2936d4d3134d870c6f53a7327a664da0d208933F
250a28dac3da0fc3f250e7d3e7690254c46a1dd5d2663f2573ba5efdae5e0909F
25140183ca7e3bbe7db7168653af8054b00324b50e2d6f28041960f5bf914598$F
251baa632d0d33e46681b76fba3f93cc9ea07b9084a6dbc7bb018c50a1abb9b1F
2520a8d9459f82ba9401fb0a86ddb5154277672b55919b252535b199ef9fc3d4F
252358bff773a45f41c33ac5e89717fa9768dccf112a04337a33f37cc5737ac4F
2524b4985525aeeba914c2536aa270d378e6159677fc4a6e6c2d0f5e10cf03b7F
25391ffb1394e063287420508e3e0ba93134a21e2a4cae273434eda6c0613fb1!F
2543d29db08633a435d64df84ea00c6bdfb481a55fd6621a7e31190ab94c1ddfTF
254d3dd41b5b9214e5ff2838cf5688082478f2a5e8e8a104082720ea06bb1921

ff;W+rF
2590f93594e0978b11599b182212244c231fcb0808dff97b691b518fbd531adaF
2596d8e58b7977e350ac45b39a8c22507bf5f23a48e5c5af3025b81016622b58F
259d7d947d78e3105849ae7a9929d030e772e103b7c652d987701a6a7d08f78d]F
25ac1048044afca67ce7c131d644b1fbf4661666b58a9bf482f289e5b1905c0fF
25afe9864fffab25d5ffab54abb193c47e76f577fe26ccdeeff50269d7b964ccF
25b247bcb5f601c204d1a8049befe95cc84a219558a504a5e7412cc129f8cceabF
25b4bbbd9ce981e8e49520f5c93c5c8ffc7b6d26b911440cb79a134719182d2cF
25c2ea7e33ae0636ef4ab7f805e637c22a39efff5c74c6192209cc229e03cc3fF
25c4de241ae499bb87004a0bd23c0264cf0e5ec7003c83fa57962fc6ca0fff80E
25d8cb3d83565ead22c4bfc3963acaa10f44a28286e88bfd60ce16ec510a113bF
25e553164777a8317ea8977d7a80cabc995d717d2c470f08b6c043bdce419cd6eF
25eda2d5ea8c705770886b5cf7cf2643b509f198fe1feae97607f96210343f0fF
25f4706211e06a217d7143f0aead6ea49f2a47344d314396d09e691a83a51848

ee:V+rF
26057397691d0e4487c2c746c43e15367dce434090f9495b535dab7657e51a9cF
2617375bbb0a52fe637164f0f40bbbc00ea29b150dd35ba0e0f79447454ad604
:F
26284ef9814e9eefa37f15d0dfb0ddab775cc08083594ba1bd43d0b652f61680F
262dbb7f2a09156ec1388f48b84cdfae97e0c8a8a47a0eabf39d4db7348d2f88
iF
263ab19ddbf99ff851e5ec348f81b1a2fd27b14a82e84c024b8df1092fff99a7;F
263b13ff1007ce0f1a2b919dcc679eaee72fb8105b37c94235f23c5f710eb42d
CF
2660a3b1922f5ae40d7ad5ae794ca536eef7602567dd9c6fdb63dc9e6eba432fF
2663e6a78d254c25af0632b96caa6ae85c1a93cf308dc522b9e8bfaa334d9f2eZF
266ee44dc28b8838740a524e7e79e747a4f52b1e9c6c56a1fbda8f8ac816cf0cF
2670e3582d71b9a17efc9c2892e66a3c54a3160c71fdf742693ca914289185fc F
2676b39f946e027f903e8815ed686e37a2b8101f353ca2063367ccce93da761bF
26770336a22190354f2629a10f4c6c2d42e78462a5b8b78e24159743658c844bF
268b5774f4a3a55f845738bad78c64c2e69fcd2089e893ce164ec299ecf563ca

ff;W+rF
26a68d26adb827543aeaad6e4d3d44e9427ff343621f03ac95b3ee77567a2791F
26b65e8ddb2e0f1b106113ae92e86c40572c636fadb1825dfa21ea13c21ecc4cF
26c0bf18af70ee3cb9525c40bdea17bad250aa0b3b0200dd8132b995dc4081a9LF
26d3fc7fdf6a25b2590dc3f7c8cdb80f22bcb6b5d68c1dad9f14e3337c0ff45bF
26dd5513dd4b2211aa6f24f32382b86bafd5ff88c0d642448cc8725093a58146F
26e0a18b1adcde25239343e4537dc1023fada0ed64e1d72e8b7a98ac795d90deF
26e499c5c940c85a9dc99a8198b266b67825eeb218071c6b6d0848d7e3ba9b92
fF
26f837f65c41f6f8f28c88fd6f276825f409b924d8a0007694a7b9c158cc8d83E
26f9837529ec8886d1314252f193f695e2df988f21ba6cbdef62da935e15848fF
27091e98db08364ca7ce67c92ed7fea1f2ef9a1b64dd06f659d6bb1cf563d729F
2716e4ffcbb6db566a73fd0c27d1df83f2082b07e88c85e2e3382e086a9d8294F
27194ef3e88b3dacc48cebc87ff15160878a2198d33fb8689040549b6083a26c|F
2719ebeaea38face0d4ce2a92221526737bef4b1a797d1c4a93a640ef5251600


ee:V+rF
27258fffe6d62545a0a0c40b4e07b0f92e1a3b79588415f8f1242624918720bc
F
2729d48cb21bb132a7a1c8ea58f36f1994b4d757d2752e75e27d2266774a0de00F
2735ed4ad4e07e41a6e6b59da981af90e90b0bb1e85343189ce011e147af53cc
F
27381d0aaac8bd4271fb0d07366118b74445a7c2e330a29bed462dcbe88fad16F
274694000767f81dd075fa9b55a09e5e143824fe75c13fb69a510889a95f7f25TF
27534a1920262b79fa35a9509e192cd19a2916bb7b11d0db13f71ae7cff375a9F
27554b9b56bcf99ec38c5aac4a10faefaeb0b46d53264ec179036107f7c5461fF
275d7c54ef8b97dfca3a0aeae434bcf2bc9cc690357c78c2944a06043dd90fbeF
2762293f4b83a93a76a349d261bacbdf67469071936e8daeaa3979de38b05145 F
27630533e7ce471a5218ba93882e15e857abb3262a57b550aa04a27de283e57a8F
276df6b2e20398eb1acd7d2327f480491884ec450b49410d4cad1f010cba2e36F
278b669b053892a784bbbac57d1b11be6496d6c624a0350a7d5628bcc2cba7a9F
2790ee1f2222b6bacc39245756529d819aa586d22b8f921a30392fabf1e845cc4

ff;W+rF
27b3a6d5e1c664607297b18087e7b61c8f79281dcd08b501d6a4a98d0f06ccc1F
27bc90124c2fa6f18a9edb3748c392b723f315a736b6b34038195625871ecf2b:F
27bf800e475fe735de26f8983bba34eab9261ed1b48593690d77e5bc7d0acde1F
27c88f137de5866849397dd80af6fd026191916624a901d7d157db89d720351b'F
27d1ba676d3d4007102e714f71f0f4e97d46890c6eed54e5f10720ff65e7cea8qF
27d4858f1741f00448f919a33388f3a4ce77d65c758523ac1aaa6845fcf67c97F
27db2217dfdcab84a095b8363c3aaf36fd751a336577cc3de811d0a747c37febE
27db2cd3bba9e5240c46f94fcd95f8d419bad9f865a7b32e02a98759ed918be2F
27e369dd165f3e4ff6b99227422febe5eb07cd10c6962ce831eade5566e16b91F
27e3e327ceafc04ea5e9faed37c22dbb650fa79b11eebea73713df7e611dfcb8%F
27f2bd3c549d96fc721458ba0085c54f33b57ffc368dc6a0cb33627d326ab37b-F
27fa8705d3dff1a9ead8a72326edbe7713a85aef397c766654dc88099acc1354F
27fd50136804eda5f0c7bfe32a61dcd680349725916fcebde89f0c8a2e549767H

ee:V+rF
280bc79dccb9b2223e4216b8dc257b35f8686cebd950a724747d1722af5d8582F
2825f16fd21e4445da86539295790890cabf52e583783c3a52aaa3c565dc6ecbF
2833f7d8c4764e2c4c247d5f95bf07698e64f2a6dc53aba92fe3fa1f92affe42F
283e32e5ae51636ccebdf22a1c2c394d89be5d20c981cb3d22cd9353e90c3fbaRF
2841663b99276082da78eea8a950fce8e865e7bca51a7bb46703fc30d76d9768AF
2847971791401757255fc2092497c37efa1f8f7440c3ce7fc60b243b497e8094F
284a8c6f38b53f8ec780e1374c2a59b687177b7be9e40b2a673f14675843b17bF
284e903527e4376ba342697bff7afdcf76804823b3344908e0ad3589efb08d0eF
285022f2d97dce4f3ed1d27af515d776f7bf7d3331bcfaee0f0945955f738288HF
2872eebb01865b8ead0f4f8bb9b8cda849c0b3a564ce459640c72efad9cb6f83F
289a95c54f089f8ce63931c0b1b113b2e0f6b74f859eb3900ce19534baafd6d4

F
28a4508ffc1c1668b23b1b346fa1d8f6999482b63898c282fcc25247623bd55e
F
28a4c9399dcb130222cfa30fabd302b361ec8967c075e982a44603e492358e57
2M2}]>jMzF
28a98571198ec6a28a437669678c624aad4fa1d5a6a2dd1bfb4884dddc584a5cM|E
2952ebf67510a8da5c648a66cb72fb82d02a871b1b805e3fa5d9a1ab8d1377d2
M}F
2a085ac87e43c3c43e031cb33170bfabf4fbeea917c6492d513aab56393104b5
M~F
2aba6dcda4b716437cd39f662b144aa8fe26ea6f15b54f36ae5c7340a33c8b36MF
2b66b267a753255256f090bf87977338168b89d26c4ffd982c87cd2f91b93577
MF
2c1c518f7da653e7d7a53995c92f4baa7bf0f6fd4c51c0856182ee1c7e6d613cMF
2cb819274f11f736ace2eed931cc816e6c1833a96ebefa661cf5f185432be991MF
2d58b75f307b928bfae35e0818fe5449c542ed611f46c2ba4663d50f304c0295MF
2e548be4d940969b8feee6cc4ffb8dde5ac295e684713eba0f96b20f287e7b40pMF
2ebe4dd6652fe19a01c6576bd236175a5952205b51f6f3c76a25a539af114ca1EMF
2f160bf3a57455fd82821ea858e6ab2789596f1ae502a2b3968383670f17296fMF
2fe8803bf3b71fc183107689fe53ca7b40a655e57b4fc6531786f97143f55b5fMF
30c32ac3292a24f2136302bf5bf2d8ebf572bc2b8c57b4cb3c50ffeb223e144e

ee:V+rF
28c2a5051272af63a8edc3a8a14de5ce766ac890e9ece13f89e53bf7481f9f51)F
28d32718cac59baf9c4162573d291af2345e664d16de912661fa18de7157ca63F
28d98e71d3a3f5bef8abd07f0acc8353279545bf2aee26db49d58baded52104eF
28f3f06dbb75d2a2fd58b0494a47a36def1dde4acad9dde4faf9ec2d6f7c9321)F
28f3ff68224de0783083894b44eefc57e4833a53461ce91f1f4656bbc1b0eb9fF
28f85ca5b6e7c2b1e3ab7c4b31675583e8a72c18188f86f288a9a9bc046a202c
F
290f6f5895e4d30a12a9560261497d6ad631dbba6dd34aa352f5df74c5b51a5fF
29124a79cce7024da4f024131a66f80d78a70d73c5fafe6456617633e5b83560F
2924951f311fafa5d17831ab4e1bd85bee2bd6d9ed591445149b5fd70152d077F
293f6c4af159003426f1ce9255f1bc981d24fe6d1e848489c5b960eb8d9b7e85&F
2945d0d59bd61b57919da46f45e6437971f4b5d914e30049df9465e3f9159275
jF
2949f6a1f906f0892e15a8ee8c20f69ae5d4957c01b49b14336b97a39682d8d2F
295238e79bcc60f7da37eb6e533e39f157bbafa94bbd0724124a24661cfe67f7

ff;W,sF
2953e2a9ba9042a9c5ebb93523d595d91f7367d8b83dc5b40a473e85572478b2F
295c3de68a936013058598624efdd7c0f37f4f950b68746738fee46aab824fcfF
295e1258aea3781299e6710ef8708bef6a5dd8bc6617af2cf2e7e205f45081b0F
29653969b83d43fd83befb74a89b5811c1b7b3d613637aa64efa39a1d4b2e76a	F
2974a1f35f8a1dbd3f46361c76fee7876402f098199e8208407a59471c892340`F
298d464e537220ee820bd7139581301c828d6e60d9deb0f490ea21510f3a7884F
298ea0c2efac5573e322e25503e2c30d52bb589fa8ef1cc0df2ba4f2bbbfd3c3EF
29938eb53cc7e9d2d0198a3a51f899d7a6d63659353fc78aac0dd24310a2cd39F
29afed10faa9e050e9b84ade3202f51f3836b8d12289ddbf91099a716ea0838cF
29bd25debd6689e7eb9f2261280bdb1b0233f6d1bf8099f49d31d530c4432eb0F
29cf78c6548f65bd34d75b05924b962409425d231430172907211eab40e38cceE
29d3baca7632def182f6a6250f76f26476b491b66dfe819eb6d94008003dfc3d)F
29feb5e5f9922979d66fabe2aac8bd7fdd18f1915777acf5b360bb7e5cdb0109


ee:V+rF
2a26d447506a770f081b5fb28e25fb0f7666bbfffc7c5f065c200fda418823eaF
2a27d4cd848272f9c9e4251b28efc591660799054bcd62d321892c0a8a608f9d
F
2a3e32785639d588761d6bf2e56e7121d3b1a72e11b62d59b95a594bbfe19836F
2a53fc6879935314c27af738cec3350d3ceb42d0ac3d7163f52ab94febb50dea	qF
2a69b561a8c58b7ed126929ce0f305827b54da8604e8f662568fc8ec96090f26
5F
2a6f1dc296b8103e565b9c2b18d2f04ed098a133f239f299f974b5430b5cda97/F
2a85a789f09834655fede0beff4a30eea8c21356b1669e49795509c63d513254%F
2a94cd35eaf2c096188c8f30e38bb1ae656122294b6b2f692f185e9533bf7f02F
2a98b158e15d67666730cc76ed42eba2c909cbdb8c3d93ede1374768389a48b3sF
2aa040acfde2b250770d5a5742e1a2a67ac343654200b1286fcf39302661446cF
2aa53317687b50178bded94e1bdf4d35e70e1210e700ac30dff774aab3e3736bSF
2aabb9b7280de41a29a8a6d2e099490ab2248876bb0e907b1ac88eee12a34093F
2ab47339de73a640409073095dc5c6953e2918938b772d47f1402c12c8954584
~

ee:V+rF
2ac60b8088805d258f480005417e5958a86da93d764c9825c111401402c2b72d	F
2acff987d578fb2dc7aa7309391c70d97bcea8f1a44ee74b888c44fae20627773F
2ad5877d7f45633aac8fe2c12d2a6f3490fa224374fff1161e930b4f55896467F
2ad84664179e15d935155fba6042722c65d3395b14c39b9f1b0c8766d4fb802bF
2ae808b4a690aa7b3a3a08ea73c102fff26dca7c8554dd72bc2269c985154726F
2aebe9981726c0cb957fba5fd53f20dc834ae5db5bffd674f3e8dfd37e300569F
2b0dc7f8c8bffbe06bd0124f1cbc07bb9eda4e34b45db595e6101d68eee5ebedF
2b1a27963b4d2d2d4589a7d96e361c8f4359cb51ad10f5e108215c381d491ba3eF
2b1dab8460db8d4ed73a10ff93169013dc92d4a6925455ed9bafce32fb719ae7
F
2b4e66ff61ba4a7722ed44b9ca9487b146ddcbe7bc27c08a8b07be8049b546e70F
2b5152401ce98d5b3a93e430dbe5819aed3a19a15ef5104214f16d8171c990fe/F
2b55d4f35dce819b798ee136c0dfb0c453985cfd824a8e839552fa2112ae4123	F
2b65890542b472692e7023dc8a29b0b0fb54c80adcb4705c53d520b6c66c1c4b

ee:V+rF
2b6dd64d39816de5f6fd5330c2e6b95ae66fa3c853d61272092b0a027fbd1da3IF
2b98912d64d86fdfe8af76dc95ea23e41332536c8e0ef98223e9a33f2d227f22F
2ba1457373a2cd07d465b437c0f82ad35d9f1c92a7e5ea5465b0e3d4ea9a3c0dF
2ba740802cbbc7ff23957b8b2a38c06b773a113b40708d05815b6081f7eecb19
QF
2ba8ed563d8e7d31e393c915f3705b7c8c4c991ca337616916c90e4a14049411;F
2bb0b6d6fcc0774c8edfa188a222399464a6b216f7edf3776d72aba9dd432b37F
2be7029195f42dbcdd8ba97e167624b401660f10618f61457b3a4c7a18a0add5@F
2bee86d12902723756eafa82ba6cc322136c4a67a78e0104ac988e14eb7fb5a1F
2bf6c6071be41d65c91d31c9399563bd6d9298e9a9911c2cfff1bae35d4209feFF
2bf9825999c7f3930c1032ad0b77786e49c18ee2996e142adc2d28d3b61709ed,F
2bfd2b5c14b17c0e7510240064a110b33c36b377955ad7f1245005118f4dc0aatF
2c05f80ee0d06dcbfa8d83439b41cacb2acbe096d4994aed2e9a4b88d43c309cF
2c11742cf173f5b0b9c866fa8aad7037f8fdb604c6cbbc7c9e373118871941df

ee:V+rF
2c301bfa4814d7a20e642e7fec605dacbeef49885fa13f382cd7c85e03e827dfKF
2c6107fda911499372be453221b095232c40415491b307e4b96667feea7e85d8F
2c612e423c3e3ace2108965f2996ecb1002eee8415cdce8e05c58aafa5f37306	F
2c64dd985521f02ada8ac0415b1d852ab79d87ebdf2950e421d8258a4d86d153	F
2c656f5e90d00ae998a2b2a6a9d7caaa9328030aefb87a1ce161d941af33182eF
2c6bfa0e8aa6838cc1b81537932ca579cbd93cc93d440a8a7c84b5342ca0a123F
2c6eb5afea1c0a0fa2d5103b42a1dfd64c5d9d81d7974ab2bf5adbf20f29033aF
2c72fd0a8014e13440ebde0c0ae037cea29cc8aa567b3723619486dc2040f9e5KF
2c799ceaa86c1f7b721be3e99bb1bb146d316ec6fb045e1a75d03e2bd335a85e_F
2c8b6a3c06bbaf16efe5dda84ccb23687cd29b2f04bf1f640024f805be0dc23bF
2c9324974a8a0cabc911ea21fe71581d404b5d397c0c010f06880df10520bbf3F
2c9b86ff8b1784c1b3fe907125539409c664ed05d051c38e8a810200fe93b330UF
2c9e65472d82364af217344ab0110865c917422d27b922d937affb01473027fb

ff;V+rF
2cb993f044a866a8d47b449c45f92f04540a139e5b827a0b845f6c9600d83af6F
2cc2e0d90af5e45dd0446328fe940a605fcb5aeaa3c115959be8469b6f134c83F
2ccb9266c84a96525ac6a03cd1a8a0e14b45062bede6bb3bfe7c4e72a5b63280UF
2cece1860f84d0ba0608689920352f54328bbb5bd72c2369c2023db772c8d3b5F
2ced5602fa70385602b80de9a0a4dd9347186ade416907e8bb7fd066af18f6e3uF
2cee495ddd05e0808ca1e516d0b1ad02fcdf3e46ede1dadb81a285b96ab3648c	%E
2cfc157959dd7203260a2f727d8590878e5ebaf061e1f17210e36684e46916d4F
2d1f2caacc8bdd289ec4d9a21bbe90c08d63cc088bec34c32f2acb2df58d2761F
2d21d53b305e30b058ca88d8778bda67000a5d52ab320f04b35e63f6a78f2163~F
2d2d708e0066e80880184f19ceae8aceb4c6fdafaa3674831f96b0d35d4f1fd9}F
2d39e047ddef688bbc3b526d384126a7602bf927866cbbd6d9306cf24221253d.F
2d55f68e1a5fb1da8eb138aca00951f0f028a8f3db6a4427488b57f1c043891eF
2d56375cfa3857fe31113c74ef70da90917d1f03086e295520df01f2c0424fcb

ee:V+rF
2d5e71a837c196e47d9d4ea6dfd48be8ec78faaf662f54465992a8340399b0ccF
2d79f11c74a72adcef4f3407e674947b25332958c8d3722a976ffc2d712fb812~F
2d829e46da9b44d01cec2e07cdfb10a09d198cb3c3c5b5bb26d4f5db8f2a7853
1F
2d969a1909d01ab5b4127c7c6dd5f7523026eadbe9500b658c5c3749db47612dF
2da57e3f11f7feb8e50c18578d16794bb2a9a020b5c7c2a5ed12d4c49a0e597d
F
2db01b2d2f442ec2b3ab438e94ca56bfd13bc67b07ac74f28b1b9d2435418aa5F
2df02b3bb45254d1541c757afacad26d93c7abaeb07503b155a89e9094ee1e18F
2df5c1c5020f78e8c1d592e7c531833f864133f64fb76513eda7fa4b1d3f8a79YF
2e128ce7e0b40d016f4c989a929934ab7599ef1aeb57ed1bb868a609e4680dc3
F
2e1ba328190cee6e94f98145224aec06902152d1cc3188f06c1ac84dc0887d0bNF
2e4e3b337d65ebe2475a8b0c521957f5a723460fab8ee95aace9f4b6433d25c1
F
2e4ef0b59e648eed97f857dbb868a2e14afec888dc7074820f587738e8085781F
2e4f169246c2ce1c02926c3021b68913f273ab5b7474087d761d93b81e98eedb
6

ee:V+rF
2e5a211202f039bf2713d7e2e1bc0fe2c8e9ca6d3e7ad3b3283b64df474b99e1F
2e5c474731992282d7faabe7c8d55f7253fbce05507a987f3bd332681c4e839cF
2e6658df1cad274f8acd004adf1a98e57338b7aeae5ac65e2c25e78bfe0d2f99
;F
2e69eeedc5aed03c46ec6f8fd3d7d75c65c5f88aef5cacb89a4b23aa19c92d1dF
2e997f7e17c861373d0fa5737eaf371bb9187d5db73e8c89cb03ef342029cfaa	F
2ea0d8ddefec1030824b74aedac593962bb24222add6f70b3b00533ed8993995
F
2ea9b64c6b87755ded68455e09101ffd22979b77f06e55588e58f91c9a0155d1F
2eaa174ec4232e07070ccd4b7aee3cc74f51b5f55922176ea0fe278584f8dfde
F
2eb32fa5c1642715eed3bff00d204b72790f716770349e1a3307229ec9f1a88aAF
2eb468f0d5d765cc3f6897270a1abde77e76fa366c6ca1473a03ee15bc47748d:F
2eb85e9cbd29bebc8ce3cd107af06c6ae0f59fcc9a1056aa9226b8201c309a26F
2ebad179e5985efceb7d0129bf95c5bdb47be73f2fad61d7da432bf901ce14farF
2ebb08ac7cb76c373713ca2bd23cc2232982bc402088afaa3c55fff250bb8869	3

ee:V+rF
2ecaf9207562dd4f4767c7e478f1e8c603b1b90864ef3d2b0d210d4f60a1d9ed
F
2ed0b9cb14b8c09ea2a369592a8ae716f4f5a0d7a288dbb4a4fa9e6089e40760F
2ed2fcd8e79d8a62a374c054083792b657cb4d4668e39188deeb1ad3d72c948fF
2ee3a5da16c04faa9c4d68e73e214570e6b2a709f6222ff6e93b468a2b79f084aF
2eeaafbd3cb22d15a16eddd840a62f042636325ea6009b82fbb72f520fc834b2
F
2eebe28ab1f164eeb8573869c86de47b750d8a043f1b3897566fe0753003f2a4F
2ef14c819a2c602bcce68d1f84b1e8143bb560f7737ba254e3b07d9c4302af67F
2efed6a1834b9396c783a23359a0750766c22f944cdc5953485f45050af967fe(F
2f00c2ff15b5c113c361dc4ad8be22ff7ec2bde7c1098b7abe496171dc1d7b49F
2f075ce3d7df67323ba3022b428490fb252d7a5759a81d0f53e6570ba24dd777yF
2f096012ac594da690f66f1e3c46720188e409c2af7f791c49395822c50dfb6c&F
2f0b2cb6eb70e8325b1e26082c9f953fa3bbe383a04e9bad22161bf475931cd5
F
2f0d2a97bc011f105608fc115346133185d5789361484a950ec00bcc5e36bc70

ee:V+rF
2f18acc2929e31dcc316b54ca1bb28829287b1d12176f94d365d38d1a1ef23c9F
2f2f67956f80076c79a81d009a5aee971589176deeda7985a84ca07ae0164a5a`F
2f2fef32bd829834efcff997a91ea78ebad9913aec9b94421efa69579be8f39cF
2f35a9c1bf11fa8350dfd2b02c990903292933bde6dd81da9a05921d0265d756	F
2f36d8b2e3ff73bf61ed280b55eab167ae99178b23f186fbf6d4721158eb5a5a
FF
2f3a77bd6bf53c49e09304c30a934f3f38f8f85bb51455216f94ab7eeb5a0502F
2f3ecc42146a179224d79240ca93c8847a1d18a128540feb63355af3b7ac4a671F
2f40644349b7b023a5ac1b6045dc14e19a4d5af38ffd90e8907d4b98929b12b2F
2f6df5451338232fc54158e957a6c5e4c1ed718d22490cc1d0031abf1ddb128e
F
2f740a705cf289cc730913827ebc04cd2b4e26e229696914ddce3e48bfee0552	F
2f7c6c553d364083a3603f33a066c8031c3bc2f1e9c8bb2d64b355daf9a42c2bF
2f972c76855cb2639dc2a960dd3b2ab524ab364a74e37c8962ab8772b4e8115dF
2fda5e0025c27a97a92116265279bc7592a072372d95f68ec7c2e289e884155b

ff;V+rF
2ff70d59a80bb5a8d198a023ddeeddd3d158a43054e77660764247997d9d5529F
2ff94d80fcae8e5f2ae6416eb0e955f4149e7639722b5426b2b8f12150cc14bbrF
30090b57be5124d284a1340b0f43017ad484be4f476f8f4103506d8736eef996F
301d479dffc9084746269cad6d9be379a3c01fafa139c9203aa5c98ca7e9d79eE
30212ff031337cd6d1555e594dd9bb0d28c9a5c7c25257cfe0770146ed77d1870F
3034b99da622294d9d3140fc599314e5bd6267cc30dcbb8d88f15027d96d7fe0zF
3038e1befe3903f7b2bfb4fb5ed1ee07a0ba36db33ae2aae4ba05e4040d2b65fwF
3039329a21200cbbf7463db4cd240372bb1bbd52f6a2f4db0f5c59e224b39a1eF
303a240bc1792e6c5e9c0d96992a7156a5d867e461081ec7d99fc535e81cb3a2F
3054ca1c0cc8eef5f08ce1d3be56c7a39e97d92361e8bd265bea14d06f590219F
3059b560a681189650e415ad7288004812bfd2e3c70a86249b7a9650f86f646eF
307213631a2c91a2525aabaa4c385612cf940c0756076d44a20f99ccf48fb1e3F
30b844415ba647e65a9810574f3ded5e1fc1edd02e28f73cc44ee2c35e97baea

ee:V+rF
30c56f4f794204c049aed74f749c3b0b0739f232b66c48497f125252af988405F
30d47ccf8c6af77d81b8e9bb9bbeb51114e301cd9a47a8f37a3077a6b1bb08a8LF
30d6b8cd40a40000166c63a1a2cf163a33883ee83f065a500e90f56de33f8e1aF
30da7f395230fa024303c27e46e2a5133d77edaece70586694945a12275a23f2
F
30eb275b4ea0c87a84abafbe22dd3006c16cac9a0fa0c57de243a23c72d28adfF
30f252a9be101e11f5009f24025e69ac8850c0e429134629fceda20f9508a261F
30f27f7cbabd3d9bee929e1fa43a3ac2a916c5a427598ee5e816dd100518994dF
30f3aba3a19b56a1f1c066cc1e427359fec9c66a1a27eac68b33d9e207a2c25bBF
30f73d4f8a1abd8421100fbb68de1f107a838a542bb020b5e22316b330a1560c;F
30fb1512e1cb3b565ab1bc735499011c641766b730df4ce0ba6baf035db92c70F
31030f948b4de98b9532d047d42d0551f372894911f715fa36be3ad12c33673bF
3103d16f84c636f0c9414dff8107cf8586ae75fbcb90a3f62b7eee6412a9b821
HF
3119a1efea41b19b200e56173924d777ef2edb1f4cb0722d9c9d99b5001de9b2


ee:V+rF
3120b8ac49c833eac5d65d84950dd53543736014e6974e6d7d1939f63c988544:F
313127128dfeab1a78ae930c9890aa99789694b8356bad44d6b56c72932a543cF
3135fb73649247a469c3691a2239b2a4121aa0631f04e3bbb0f5c25bac9f93c7F
313a86e45fc4b42084c618c11f233c1ab6950f5af7ce19f962ea3fd1020736ebqF
314863a27a19049fe9480f37f1d931ad115a3966777cfe9685ce45f0eaf763a2F
314a81ff92e3f3500ef8c7b95dd418bbf2ed11ea8d65031d6e8de42e8e43ab73F
31535d62fcdd33c68d7c941c0b2b9e56b4f4749c5c04518d19b67a70214a8012F
315bb4f6a8cd60a7becf60b599198a41a19465d28cc706d98dfa3b927f357dad	F
31678e32384951f2d0803f480a17916c8967a20bfa4c0a7b627436b112c717fdF
3171334483be56275cf95caaad81576b0625965bf82c2a8cb91be41784e991d1F
317a76559462ea9c4e676627bc07ad51cdeabb16ed71de9e1006e9136d921666>F
319595ccfe3f0ebb45ebf6df0161096bcff75941edf191e4b985817405996515F
3198edac074ce72829e22b3fc0c16b2361413759b0418cd6443a6a5394eaf84a
b
1M1|]>jMF
31a00a78690dbd25c399c0d6dc257233ed9c90313969f69bafac3ab599e0a3f5MF
324eaa8a27d384658ffb3045f886fe533acdd20ff60a9dad14007b9f07a43205MF
32f2360a1cd39e18ee281e0776cfb076b98630d9d2f537026ade2e9f9781d773MF
337b3b492087333d675bf644cd7cab27fad998fd2eb5f3f1064b766e5fbf85c1MF
33da9fcfa473611ac5db46a1be964f5a878cd46aa94bc51035801bdb2ee4b266MF
3442dd9e3cb39ce1bccd183f239742f4ae9a9499d4772d140b7b2a2c451d5507}MF
3525be93a809d42aa8d6b8563d5762f4fd6f25a1b228b65589656a65c2bbba4aMF
36100cd15f92cdafbc93a99d22267147437baa08033156354f656dfc64b59e9eNMF
36700e5bb7c0b78ab0e613260beefe4a8ca7dcad56b18461ccd56a4d671e6938BMF
36ff4ef5c9d824aa0dc623200d80aad9bf2bc1f5d992c7cfd42bd6eb14264c63MF
375ebea7e1dcf98b38f838956b03b236dd23db4b665522d9268223ed9b4e8d3ddMF
381a42f9ec21ac9b849c1cdd79e2900f003e44319a05a25427dce938f720c548MF
3917b6cb3159c03532be12c75002a6b66aa15b5a026b3d9613b39cd118b668c1

ee:V+rF
31a17cc7c43aa0aefd3039a43028118f0ea8b11195c232e1310e14547c07b77dF
31cb8b4500b30fc437c8e439643e9d1afd49b8c687a8be5c9b39c44c31f51d44F
31dbae1dc23e561a169170b6a4e76e5abb65227590e305195a2a4c4709cc4a0dcF
31deb0ef8475cdf1766d7273df81d1e80842c260ddc7eac34364361b4b00b974LF
31e074062d36f692f0ee2ec64a68e0193b540bf85cc09b3fd7a6f3384ab55806MF
31e1c574e3fa3fef3b015e2b2e1d685b860a8b96e7151d331b9ef708986965c3F
31f1aea6422bc6b0072f7c26fc3200a90ac929108eee513f7452415171c8a9bdF
31f3f35c713ad4fecb47ca4bfcba6b22a99a0311e91687edac989c0a717ba2ecF
31f46b22cd82ef4ccbb472cae30cc13508b35a42fe8d5807a5d9fc45b18a830awF
31f5687f8cf2efb346cfb7c6db63dd20099ae55c53df37eace7337114a7ab96bKF
32249537b076dbba37c943b1b65d1fff2e87bb54365e3b33c003135dd728a178F
322851c3e3042c4bb07d4bb68b94af8a35852bcac51ee3546cab4f53bc08392bF
324c9d5ad49eb48866d128a022079508c40c45aa4d4176abc382f606369448d0

ee:V+rF
3252927809ad349b76f38136eaa163f3abd94c46df6a5933f90e8bb2f0d633e3TF
3268859dec4857e91df2b98be2c4c1039a81c1208032d1627ffafee642953fc2xF
3268b7dcf19f5e3720d65d039632fa15991336537a37e486e37ed194609102b2(F
3278f8dbfd0afa8e751afeffde943cb66ed2c2a57495f39ce66a95c3bf852ede+F
327a16cb84103e242030ecfe69ccf4a3d6b745ebcaa6a416efaf9fd6b57dbb18F
328461666a24e217d010ef9c4a1fa1802b6a66e769d41f06e0f36ef5390ce3b5F
328f46b687b75e421aa0632db00bd3a424a9bb575aee94e2ddd24cd9fa19ab14KF
32a6e9291813e4daadd971db10a8925ff8233160eb5a5a4fb45d5590f18f2893LF
32af5400af5619a7e1f0c43f574170ae98cfd7cdc7e831f572b8d05530bd8913F
32c5eb73c64b93d71f0a965e4b0d4b50cc2363ac261d96c97b1440fb668e3e0fF
32da1842a79bb4ed02be3e6979ea97d79701733a3dadad668bf35bf4bc617e34F
32e1c67e1aff171de13642d103f733792e12a4c17c9ee64aa931d2315b08e1ecF
32f0185e8d6a9ab586922827519f1f38fb921fcaff260385904d3e61dd029d44

ee:V+rF
32f371a2fb734b59d724e7f158a6b7786a4e7608c6e9200aacc4b1624c2d55fe
F
32fdc77032a9de115471b54289fc5f0fd4e2fe3f428c90a14db22d18d246a781F
330b8ae0aa3720eeebeb9d9321a83a407e356101f5d7cb524b333e0a138ceb96F
33233f04e60e9c664a7bf40da5737db125bcf521206e43d06261d80d1b4babe37F
33293b1fe8b0638219c4a88ea8d7217eb55c5b4e227d7945c14a9121db97e4d1F
332d0c5fbd59617b2854c4ef7acc7a7862676bdf591666e519d3b09c2f3435e8F
3336d0c5df4e7d13b0a72ba226318a764a5ec8aa70ecdccfb63e3e01fe7dbf426F
3345891d8547aab466be25914ccc742f1c11210c09ab84648527d4d266971c3c"F
334b38af49e56e5f0435be05785e022ac744d9fb66965fc0b8baeec1fbc47653F
334cdf2e5acff8ba4421fc51d46210b1cc6cca7070a3a55c0b71135ea842a3c7F
33522ef6344e2c23c9585439f96860fbac64c8059e3fafe85e39f00d654826bevF
3358f19c8ca9746105376676f9d44c518ec567358ba86b5a92b874dbdb9c8a448F
33747e3cee335e0df270058b70d2ce33f91cadb372c26e1a24641083294b45b2

ee:V+rF
3391ca1aa9dc6a5e4ed248a618ad059946ec5c65625f2566cbe9773d60646f54F
3398d3a8a0f8d7273ef408e2922e3b985aab4a0398a30203ce247637331432d5	F
339bcf68cb37a454eddff7218aff4153a36bafc0d36e2b5b6bde8311c6f3eed8F
339e96b8a52bc311433f3ed0ce535dd62f4808232fb75bf0eaf2b4f0cd82f726%F
339f233813e1f39b24e1e909a69e3050071f267633c137494ad16972ff55f201ZF
33aa4a6c127c0c756e8327baf78c7d6040d9adc0e92dd42d324a4b1625c99bb6F
33aa69d7f9394b9a6d1d03cca5e79975ae42fc6d8a6d1794ebe7bfcf8d3bf01aF
33aea343791620e71f600e75789b92a84ee5b9007aaa3aa71b3cea849c8c069e+F
33b524d6eec3fc82a17df2220b596193025c1faf20c5939c4271809681f95803	F
33beb19a202929092a6e1605a3f6115c5442714589a627267a8ba12528865a7eF
33cb91f162bf1272cbef0f8ac3f812a3af2b586d5be6e77a0a773db69590044b
F
33d81cf734e717eea6795c7c41a630b5e0eecbab4514f5859db6609e50ef0447	2F
33d941826eff0dae2edb97052b2bc115956b725729096f5428d558679c2c50b1

ff;W+rF
33dd225ef7b01c077e7d0977782fa69f3d8fd4cea6363f4cde213cc37694b3a2F
33ead8c29c4da7be1c35398bea14adbd1069eb04196df8a75ddffab71562e778iF
33f79495a144745f0bf779634202c2e16ec9ce1d545d08ada1d51ff124397d755F
33f93263c696ee536e808126745c9fa540fc61ef70ce1cffc4848d598c98eae1	^F
33fa2846ccf25385f17ff97c1999aeae26f83868dcd26164e5524c4255cb1ce1F
34157ccac81b1fd2400592605aa6918ce36609a1d9a3b2cf1b602234d548488dF
34171e7570b3702011ad6135ba344acf87732fde15fa9714876fa317e1cfd747mF
341b7f6c5352eee2a98665ce78feaf6c4a52626e0322ce9b65c82f9e08190f7eE
342100bd7ce3ca8e951285697781ddb9192c0a02dd56cad55d48bdf20a74bec2LF
34210a0ec25b1987cb28b7719bb7ab7d7eff1adb56711dc0f4835ba89256cc82SF
34255ef50bd9c16239a9a579c23a1bc1f046428a2aecf0fb06e04340b46af985
zF
34269e92e56a1ed2e47570b48ed01530719dca4cb561baa301db389d679afdb1zF
3430976f8acda648d8659eecbc9ab33a1dcb14139a6206b64b25c7a1129d685e#

ee:V+rF
349059abdcb4206de241619b0a997e70897934335a8863a2070dccf45c49f019
F
3494247306924b94b55f3da45af759539e2b9710c85996ca25ee2b838ccaf8d9
F
34a08308f948f94b0ad18d9d233e22453d984465c89a58935ec1185d071e7f4dF
34a441b65b1e00f9aabba569dcd45ab40478d9681269cef9566513b8b0754934F
34ce748bf1845ac8f646607f3776e2995f16c3c1b8ed68775327e24981f1c217pF
34d206ee003d27edc3b435c9aecc9569a8efa0cebca782b60e595b2c78f06326
F
34e3369ca1560dc34b862cce4a9fb6a7939494ce15ee0f68fb76edaf5fb3ee53F
34f10adeaa6be7f713c3b688736291759f254661968bf607fab161503364705f6F
34ff7de8a4ca78de046e416a969184543fb961e44c8500ad933f5d0d9d71bdb4F
350bcc459207279a04b2e6c772304349c7c5d63b58f4b52efe0c5856681203c4
F
3518ffcaeb18d70ca1e7a98dfb39cdb789944a2791b29a154aa0a970188b0b33F
351bd76d723a1fb9939e1e952f343ba53068b239d463ccd75fc7b724ffd4735b<F
35254d0cedc9b7756462a8c23a1b9bbf476fefd2ec13b879640bcc09a53504b6	

ee:V+rF
353fc523cad5efc4cbbcfc1283eb522f0f97dcaeacf8fed02b5b71b895fe4f26rF
354a7f6dc710763963d56fba904430a98f75f770240185bd954597c4338b1d0e!F
3579555a0a1408bf0ffc0c41aa84d2045a42a0fc9536c5b03f837ea3080086a2FF
358ebccf9931f8222e5503aa6255be88b2b6862a1cff9b34c0622117c0fcfc97F
3594f2b7367495aba0e2ad40d7aeabb3ec7bcd176bfa09127a9021573f936f66
F
359852ce38e0555b23e78c945070ef67c0599138eac0c52de77a819e8fdebce9F
3598b7d61bba2f202c95efea45958f70f97c86c499e19042f49589dccbf233ce
nF
3598bf42bdc531b55ad9bbe89ca716bd42b7f2e4ff19fa4082235369c9a263031F
35add167f7cb884e0fa8709237307f4caa3297832e3165d1530bcf474ed45e74"F
35b3f04497e7cd33947d10c42841c8a302879e0665aff842a760e318a83d90aaF
35f5c229e131ffb525fc38628dbe4dc399fd7f6077f047e169dc8e5ddcce20e8F
35fc790f76f1d12e738a6b5cd1438085704844f9c267638a15f9cc080376b10dF
3603a5475d52875262a18bc253888633c218b9df5c6fbdfad0972c07da32b981_

gg<X,sF
36101de00585de431de07579343b064018d049adcaa3bb90ae0c55e997d8e1a8-F
361435b0149d64bce7ddd96522893346319af483ba71ff2f7d32c353614b224f
F
3619f7bf9f3566d19d7252cebb96f571e998412d785249dc7108dc067b00c751AF
36259b436231dc4bfc0fb0c9db4b4bcb6693260e26b5c858fed3e11c71a5be0aF
36410412b59ca22b5708b34c6f8dafdb38024efff345c20c4dc28c75a7eb8a0aF
3645870dc323bf6f63b5757d520178a52a8a714d71e280c47014f095f2c2fe69F
3650ca3ecdb13198b3e14e49b52b7dd911c3839ba77826f5b2dbd315026cc82fjF
36577f1cf5cefd40798e73d112856b462b3290fa90abd70553c107f45542a070sE
365ab6c383dd555fe42283836abe7f7014bf20c41b0828d72f1c13ab138cc1d1GF
365bf20a36b4781a7a21bb79b446907366fe135f7e5616c550b20d174cc96d1dF
36621778bbfe07d63cf5e8b83b198171e5f1bcc467910e9ea517faecfc1e27faF
3668549b1c43bc2b0dd420108f4ebcc8bff57ef08d4b839f3f8e6f9c4691f314	E
366db37e736f288688e2f7de25a2589d720f57d0ee9d9147989b609d9dfea648v

ff:V+rF
3687a70548cbd4d02fcf7f26b82c06330dc5e341e67504643b30e20c257b33a3E
3694e0f350aab4369f5eda09dba8aaf0c4d0128990509c2eab7a69e8a99c5400JF
369ac51f105f8b0b9fb343deb57c8ed97f3e08bbb535d683866ddfd47b058675F
36aad460808510bfa2e38f113711d7d1b1ec88d77ddb1badbedd8829e5c8dd02F
36ad5a43df60889dd9c1134cb0e042317befa64f7293f44bc91271fddbbfc7e6F
36ae65670b57a81f320f0e21426f30d359715f401c51ab27568393a36e6d75aa$F
36cbb6317ac31a74661962dff6944ef7630e01a16c0c3426f1e58b4a6dbd259eF
36de51c65d7a208f69d6a68ad07d468a5ba7dc6b245097eac3e9db107d5d6ef4F
36e226643adb16e51005fd729514451221b0570727d946df70bc555084b1ab43F
36e338a02697b1f86cb751a4d30e96bbb9a01a424dfe6f050474e28f832d3b2d?F
36f13b26a3b985a2d5e41a86724a23f3387adf18ce34902378ed32345f865d1a
F
36fd57be259185c71e4768b2cd69c293e89e53afca9359f3a04c397ebb715d25F
36fed680eaa8454cb71901db4b5393c54c16fdfc72c0901bc461231559e164ef

gg<W+rF
37036b6e228127d501401f8546d504c70f6e51fcc1271a33342effbc6d6a62cdF
3704909dce1c80a6e3fa47ea59c51797dbe73c34511a242cf1e0756e078fba23F
37146ed7255163cbdf3bb94a0f5e8ea9cb46eeddd0d269546fb213017f212548F
372372d382848eb9ecb5e551dd606aa646c12d3683f43b876ed5191e7a529c3eE
37244afa6bebe0e93a5dcd0ef3ea1ac9a76f734e116ce8c087a5f791ad1136d3/F
37356ac1734506c064e4fdf1e87d69a442a12767a7e98626e8c9c571fb460198F
37388f00a7d1fc6d93e26f1ef6a2ace5b99ec8b0ff895e5d156253d00fa59db3iE
373ae4c777d075890ed70569cf89dd0563fc99e76ace4281502f4aed12d4dcf61F
374186860ba10d433ef1b2fc521d6b97c48570d7340740cbe2e83f73df0b05e4	FF
374238fd13c46caa7cbfc40bb0504875bf89695119fdc6cdbf33ab47bd195079F
374f721b5f41a11a081cd23537162130ab654a02ece3e8c55f3840ecd8f839a0F
375c6aec9492dfeb3bf49e8ed7cde201a8d10e0a725c713f6131c221f187519acF
375dc1e4e253dad77a1c726888c330f2d32bfac978fb2501318c810a4fb93843r

ee:V+rF
376c090acbd7598c0ec397a027eaa7db2374a09ecf6b7d78663cb04b5f928d57F
376c21e2589fa7b033d3dbd7673defdb1d5e23c6ad32b112bddd31ae3915a582	F
37726d4a426ccbdf697e55aa4f02f394d32283a3df6de51d99714a596409ae64F
377ad2aef6a59ddb2c292a6fac9feb315ee0b1fa109bd47f5aca3c6b7710e3b8F
3791b9ec0f2a83fb568d433ee44df76fab4784e85ba1e6da6172d66b8161511e
F
37ac533da616e343432c0f1378f9e585ef3a6d8ad632bf56c45e59e7cbb1076aF
37c1fc32da75405bdcca093c9fce198c021c7868450f7b272aed38def708857d$F
37dc67f68342f587481c58ec0ac8c6ada7eb0f9e8b5e356c1864db3cec910332F
37e88e4bf1d956c4200c41a6b0592a43ed17ce9e8ba6f60c8856ef69516f2d52QF
380017b2933fbc2a789cf7c1b00bb0fa298bf6b9cb61d88aaf52bd314eaa1efc	F
3805c7e453631cda2c446cb60a6ea941975f89b2d544824c96b37f874f6e5bacF
38116fc986dbde5d1071bccc99bf83579d9cf9cfe210af409971b02a8225df2eF
38165265e6956a27cc026b542a5b84342b4e8d479263713e10c9a0b0871d9705


ee:V+rF
3820c04e5244db590096c735cfebaf9c275d7ef5d644f71712940bd565f671e7F
3831827b92fb33007bdf9bb579f1947d04221cf988fdfd40615012e00b9500a3:F
38375293dabf1abf54765991dcbdc6f2a1cd8c3ebe3d7fabc2405e566a16c5f0F
385d88da6f3dbafec168b9405c82b40252b4f9d9df0ef1b7328108f1b7de4898
F
386bf9ac5cf0faeb2ff2784055e2032e081a36e7187d99c1111cf03fac18d874F
386d6eeb6ec186c7d3ac868781a062f7659e7f29629bf7919767ced443ced16e(F
388aba1b0bdea4684f1db472cbd84cc4331e3d51543a84e076c8c8209113539e[F
388ece9ac8d1f44fa207868af7af9df39a1479ce72301c159bfb9ed3f436fd61F
38926b3705d3995333fb2ea6d22cd0d4590578927040ef0006aa35db2898e209"F
38d054f054325006f87cc688b0f258c342122a6a0a76a8efb07f3c1ff8cd20dc	F
38e563cf1d4db62856dbadb61d0f77927c69dd05e4c6cc79a131fa4eb2081514F
38f6f38400a02dfd304ef361c147ae8587357a50cec7a0113047ebd33cf7c5e3F
390e0d90e7a686457526470783a48fb4b4555c09798e0576afd065c0488356b9M

ee:V+rF
393806557640081ee6c9dd7dc6ee00e307d9ae676a1a267d20fb4793dda538d7	$F
393b6f38ca21b31f198eb40d2fbdecb79a43ca0306ac436c4ebcc4fc8a15043aF
394db1fa5c7f0d2612ba1c758328abe415aa0a5677f936aeeb8f95543e5c4110
aF
395a33a57a17338d844c031715190aa5f9cfe26cbff564eca64617c5328e167fF
39769e7385d3d8eb28ca268acbedfd9c29363613ab7fa8b641d5ad4a91230f51)F
39839baa55b7d0e9b82004503792fd5f8c0608ae6d937d375d2febb11a92f830F
3989ac4ab63df7b51e1ce010e2b0d2368a33f915f06ae6b659dd6861d3dc3721F
3990236c7fd1972169692ed6297dee2d25331fe73bf38ac66bd45bb990ed139a
KF
3997f8bf7bec69e2b9fc0ff0a33790347a77cd30140b40f7b9a36ae91591d36eF
39a345eb07bae6f35b9362289fb910cb39998826047249bc3991a0ab55547bceF
39ac208f2aaeedee724d09ffc9d779294a7721cd83807bbda081d0114bd94acdF
39ac6caf2f744acfdea88f8f05d08f1cc0f3ead1b5cc458a36db4d7d5553972f*F
39b2ee3cdead3a8fa94b2f7fb082014e56dc28992ac2740a46795004ac7dd6c0	

ee:V+rF
39b51aaf98eda72373e0ad8ad89a206476833813b0262e2e149bab9f2fa4e4b2F
39bc056b01daeb577a1d13e5d56959179803eea2c53c39eeff982663bc189df1F
39c2715a2db8a65b7a5d313ddb5b14fd5c9c71fa1a03989786099e82c0e41522F
39c70285432c56fe5dd79f0d155069d48956d10fcdcac838a4590c4a44b0b521F
39ce1d8d6ffa3efde898b475b2be150a92edca9d2aadf7ed8d5d69e6865175f9	F
39d478d2186cad86df1a7e0bcfb9ec33d5205653c9b51f111a67f541511da671	F
39e6418349394ca9bdce4ea754f217c46186d4d7ac6e256c57becbcf78cb2932
F
39eda1390e30c1d89d4a235798a2680748e9b2b95ad2b6a7c76d547977b8afa3F
3a16156819b55d3d9e234fe19ee8f016b2394f4d77627ba4be2bfe06f19a148f;F
3a214c9b7993ff445157cc339c9a34103eea57c31ad42b15dba0db83b51bcda9)F
3a2ad8e88cf0956c1a2c89acc48514e79526a2cfa14023dee71a714c83ea1779F
3a576a2d4c9d495a81817e62770bc36d792d089f36be65e81f5449f4f304415eJF
3a7a5d5027216e07b3eae0f5b2cf013760700d03cca8961ca4395cd637ac3c5e
3M3~_?jMF
3a846ba46e8a41f29b08fc2e10e3f6ea6459d1d57fbe6c19523bf1269d7754ff
MF
3af5287deb01c0880a6d6916b3fc0ecdfaf93e576369b1b9cfdcc1613bc22a7dMF
3b822a517d29541cd78da3a94ca8b9ce8095283d799bf7d7ebe96461744ae90dMF
3bf5af40702f37c01b474763465e7acba66d1f9cca53e59538aa92a72f018a35MF
3cc12df2dbbe22e4c3186fdf10fdc4f4f176bdac5296996b92aafd1019a8fab1ME
3d1f2217dd6b5ed505a6858933c562175be86840b5c6c7328291ec8c31333a56HMF
3da02ed3dc4e5e3639e3507426c68050a9d7e1896480c46dd9016e2bfde917a8MF
3e729bea301dda80bd7dad924182af1a8859d3473da42b7cb9ed78adebef8963PMF
3f5e731ad10b48db0b27227b5dc172665bd2f7df987c4805e234a12851c320fa
ME
3fb72ac0367e9afd39874f48b9a0b356b9cbb0b86d41265538358ef72583d32dPMF
401c21fed02d492f7c9f4ef47e8a82e8a7bfeb0a3e08789c00a7220db5e1fbd8JMF
40ceb41cf108321fdafc40bff1168cbc4f3e85a9ec271d6b55e946ed83697fb7MF
412317b2522f388f60a8b9846d99020fa2c884e8557b0552ad09b4218e97803d

ee:V+rF
3a891b3b430fed933fb5c51f4dabf4aad4986782e238208490c03139368c40d4F
3a8eb48fa6a00af9e9dcaea80df8b2f0afdff3c5e06bdb7f02f38db59317e110F
3a9368e803399e85ff27406fbdc5d6ffad6e000d636a8540ac83b236273b5d2a_F
3a95d1dbf8e717a5e29b32daea78a11867867d80343e09ffc29f6c9dedd70720)F
3a9691f067f58e1bce93011bcff272d08b255c1d950fccd1a5aa734d7f8b7050F
3a9e272508ed53c6c3ca36cc4d1c537b9a6096425aa6339399939cfb7a44d1c2F
3aa4e1ccd9fd1a78767f931c25659037fc4cc3726f2bf2f979ed6ea52afe1815?F
3aa88d01f6198efa435e94380ac7bb30d03f89a522b7860137a566276cea51c98F
3ab460e6bd274b4d17b8de62c56e1c66dc26fda6159f4e9f57be04e8bb94bc1a
F
3ab4d0b3d34008809f0d657e9f4732dbc33963cf480b77f6b3afa455be2b0eb3OF
3aca72fcb712db6bcacfb3033aa1cee51230819ab53e90a5d44e468d36de4777F
3ad9c854816cd51073279e25d66deb06e14c0f98f40cc6d468a2d1aee2d2c284
F
3ae0d9e3b7846210244c8d17e6fbf04621eea150bfe308a6b23c21561cc38acd

ee:V+rF
3aff8eeef1e22685460bc0aabe262f29bc20ce164b68243c87e313c98c1e32e9F
3b04769f0fca70f22717ac8026b0938bb9fbc4229eece6d24f30b72db5e9276dBF
3b2af1cbe29d541a936e2a76af8f1cc07780ea069f8cc04404f4b2f85184abfc{F
3b2f3d7b1d885c5edc646e442aa9d94f1445bf4eedc14e0b85c4b0d8f69524a8F
3b37792998533e55b2ebe20d10052f6104ae209a5db1a84826bfde614e6d7c44
F
3b52c38e47ee82671fa761bae2755fd870054dc377cb23f09b0dda2a5da96a65F
3b5672f51204c1617610ae8cd9b6f52811ce9c9fa0d5d33100995554e954e356
DF
3b5a17995e4660d4c305944c4a13cd1bd8bdda18b9d69d13031b2b1044e1cd77bF
3b66f1712118ad0d41f8596409e86a1e86066cef3804f7bdd83ef8c519cbc003F
3b6744ba25565e7f93733bc406e01364aff0968d6eb153c58e942635400ed11c{F
3b6d9c55ef22a3afc1250d7b0a6f4d5e8599880d7982a85aafde17fdd2e4ebeeF
3b6da3b418fa4789feaf744245bf1f8d61ffecf40017e594ba7ddac0372332c0F
3b72db221eb1db189edcf9c97b83663b0494d24fa1fe73c09e6916b1baaec8e6t

ee:V+rF
3b84e45c8f431e6aced2faecb97912cb424f0373293013c739154621f571ced8F
3ba1c872bc9e60330b7b4b28cf7a36bdd1618d3c55d034ccc2f1b537590a34b8F
3ba273d4314760eb122b0661daa6126b87cb2ccfa2ee5813199419415261ca9foF
3baf28c0979d5f90558e58f7499f8c92082cc8e9b4e8e68acfa4d95a6a902be4F
3bb061745bcab5ccdf7cac588403affcb1f45108fd78412872bc78b646404b98HF
3bb0da4f1c883b5aaa0ad687bcc2022ba9573d912ff906b6657bc7e96676c5d9-F
3bba9df9a126294f1b6d125afef0399b652648e92446de453d3f9aa966726dc7
F
3bbbdec13d548901746ce3f8e2bf282000598614b5b70523edb80f329ec935e0JF
3bbea9323c322a5179cd1dc270e81ca0b7012086d4d12c606d5f71993e272e7eF
3bc9984dc4e0e90245e74d760cf04b6707669b3289dc3e70c040cdfde4d44319pF
3bd639121f6b04020233f7f81a713e0fdde89de7bd7b34c14ad4c211ad5b1560F
3be8775407bc08f4fe54e5628c556d5472f9d4ef0d5b89d29c9c9b634121cb07YF
3bea27ba9e28b7b2fc421da397e966e4cec0ae9373ddb86b7cee9186fcc5ec16W

ff;W,sF
3c12cdb5717ff04a0dcf949d40ddef5d878342fe63c8cf26ece6f2f0f56c9075F
3c1b09a234b987d0d6b7eeda50bfd65fdd56ba1cd18a3d7bfaf6c502e6a18295
F
3c1d7d5a10b6bbb96820657c57af7a774ba60dd1acb011d623b218102b3251f3
9F
3c2c5a9be0e4c30b02e5553db78d0a3f434bf544273422faeab125baf392165e
6F
3c4ec0f5afdd9b9d8e623857335cfd73d8e86540fe7c74886a0fc678fbf926acF
3c68468d65b23e5a50cce88db5e3d11674fb488c8e0bf375200f6f529c438a203F
3c79cb3de74e545373941c507295276cafff95e505438c0bb771fd73deb0cf11F
3c7a4b80b2ddae9fd2eea4d9ca2f112f0086b0f0366fe20bd37a1f21328467c9F
3c80748d03286542b429491e9861564380252fcbcd1d92283ddfa799fb2dc3f5WF
3c93170cfdb435ab3bb64346b420376ebaa38ff8f2252277971e3b6117422fe5F
3c96054de3771395180ce2ef6da4dfcd565ee2d14573da0adad58ff76b63d77aMF
3cacb30cdf9cf8886bd3adabfb82541a6334ec3b33f75528e73c4d209bb76917E
3cbf76c62b3dabd78db73ad0e95a34d50022e61f36e7a967aabcc7f9c3f4c6ccs

ee:V+rF
3cc29a69aafb39574532fe2809182aad0e720f88cccd15dc57272ac96c7b2417F
3cd32436440b9a64a4f9971f907fba98209aeed82000b3d7441689e93ed58cb6F
3ce3178d47c0937ca4073ad24a4d21e17880a93c83bed7d7cdde515bda87c789
\F
3cf6225627d15b57e6db240be4821a47a55d2bf482e4fe8f1928862282e7998eF
3cf860317663bddc14b4af70586d0e219e8532bba47638fb4b72460e2bac69b3F
3cfc9f52a00f0406e2e427948342a30ca2cd4762712b56ebee9d8bf24018e163cF
3cfeeda763854fb5e06228183bd5e587f1bed1e4d625590a6b4ac06187c951b4F
3d08be30af99cb4e2248e149d75d36071c2dfd0806f511abe5c972b4051fe7d7	F
3d0d4dbcbdb1f804aa9e133124ebb735a5037654221d45f8e93d4e81c3cc2f75ZF
3d1213d433cc4f76de4bc1d38f0920c5716b596dcc3ced3dfff4e9e143ba5b59
F
3d130588e8e704895aa41cc1d3a57139effbcdabe57ea04b561e8d3b1d252e41F
3d16cbc8797f49fcd4f8fd66dcd9abf0441a825f9ad6028f0548e6003c0e23661F
3d1a72d4d1f896acb82915d2121ccc8032a2e15e43ba9390abbf0c6e1ddfdb81

ee:V+rF
3d240ca1688d3b6d6b6371756d97a6aeb744a9a8557a0e554507ed284c013250F
3d3fa496232fa0f5bb5b56927dea03ee514808271edae94b35d550e3dbe54772ZF
3d48adfd65237fbd521c95fe26d5d4f17e03f7af968c2b5cd036e099d635d188=F
3d4ce04e90a019a713860f38b262e7e948563f62770c6d7fa6bafd59e0ad0580F
3d4d0d965fc073d950dd63507c1b1287648ef59c103d02cf09891c04bd99e930F
3d75be4567f3055d6aa45834620c4fdab40240d0eac958aa3b5401832cf284bbOF
3d77cb8ffdf08db08553aa94df7707d9a0b2fdd0e4b233f18189356e16f26f6dF
3d78c1d5498c9bcf2b022b55d7e3cace4f911eb0bf74758e0eaf4a756e5f831bvF
3d8ff28a1b05b9697b82489f71fd9ccdb0c088f4ca37c35263925511db5f5c7b/F
3d901cc9a4697e9c08105de93d1a190650a8439e1dabe11a97d17c67cd1d951cF
3d9697b9d1df6afe1e6f7753c817927e77aab45d8ae4e6b00aab690614c170a3F
3d985b2d2ec13d506f3e32f82236c706a953bf9178605bd7e9c559e99fe33c06F
3d9a71ffb2359ea5a0dc6d4ed6231ba9e22038c3542aa2e129564b7029b25277

ee:V+rF
3da43cb47b5ad18f1ce3f3b8c4d77981a8aeebe7eeafb778c043bdf4d7883d0eoF
3daac146d8edbefdb34bcb729d74336de8f1afbaee929dc55464706da7615618F
3daba1d2ee59a3abcf9723759cf79cb532243682a4ffdbfc3dd7f5b29a3c046cOF
3db35ae4792e6efe04cf89e50aeb71e9794589152c92cc1de54f2c92dc956b40	eF
3db947e6e862b89a0ca5b23880b8c910b68d3c16831d17f914d62706e4e337db
F
3dc3c0c7d9f3c7865360c72790fdc0bb19b96e9e07fe98300e5e7443b0c5eec8F
3deb7d3a6136871ad159d05ae95e27d8d744b7e3ed0cdee2668d0f7c847daaa5kF
3e01c37b17dac632211d855274ca843a3926cde218387315d5124f7b90008656iF
3e0a8c76f0c416e9b2f67cade48b3e2606a3fc3b47348110c033aa2cc1835a00F
3e22c1e91e6c946f60aaa437911042d67c7e9de92d77cf458a51d5660658186cF
3e3655960230e1c13e294b6c96c6ba573e155deb76a3ee8c62d3d2ff7b5bbc06F
3e3ebfa1eb1b1cf926276a074c1b8bf839ea1353d1334f5304dbd50d4721979fF
3e669a493af1a126cce0a77eecae0864765c9b701b5640962ecfa5a8ec1afc30

ee:V+rF
3ea9a16edeb166326b2db578b5d4fbc8f9700179808b798dd4c33c6f0d273beaF
3ec6e9340959cede8f65ef85eb65d48800aad8e51db71b9f3bd47bed04cd9c3aF
3ed462219356a67f4b4e61ac7fe20b5177652f7b0016197ed02c546f91020c7f^F
3ed9d0bcbc1cf0d2a450b8b6e598051e1c685e052cdab05aeab562c3fbd1094fF
3edc5c8d5cf1dd51b987f3178aa2e996847bacf9b48d9d5f96f0831a21c48b97F
3ef3e8c076f637b1c91f85480d4df87d7fe63a0aee8b42f8fc774dd84b683aa2SF
3f11637118683c18d64ab08e86467d90916b689368a1c29e9b095c9b7c8e2633F
3f1d1aaf2ad1912b72db538da9e7a824ec1beb3f7eceb8da6ab8b296c810b913F
3f3a9c60625ad194ae3406fcef007e24a583db933f244ad66404e2ce22e8628bF
3f3deff3566c606e953d135ea14e38e49de5f579a679c901193204c07cb123f1F
3f51b4953396f40f83ef6281561e6aa2bd69daf5e98921e1562160c40eb64061hF
3f5208ad5e6d40b1cdbd818874e03c204f1a94371bda2f9525511fe0a0803522@F
3f56b1a9c01d9d56c7c61e5e85f89f379f66270b55c609f84ba58194ac11e489k

ff;W,sF
3f67c1b26c1f278f9f7675269681e617b83498e50e541a04d9a936a563d20506wF
3f73609586cbfb03e673487d50c8317cc03657e173b51bd38b9491c79062a838F
3f77e8c91079e010fb161e28eaf613452e1c25d2d67b0367cb344f3141bf3cb9	F
3f7b46638efdb99c13fe45aa513af69cad728c4ffca568196d21fed273ba7f970F
3f7e486965cffc49635b45bdebd92b770f1cf0549894d2014fa5b8ac030c214cF
3f7f1d7529325771aca130abb3ada20b55752fb8168b35e388cf43ccaba01f5a
F
3f87a8a259dcf40c961dfad59240eff08fc35580ae718952a8849e7b5926cfb4F
3f8e4829e35974784aa21e86171e8782ae787788130e87d8098084937f4a1a3bF
3f9569f5e76f2c85ea0b8843abaa2fe4d295bef235b8e3c6c65588c40bfbaad2F
3f9a0f21e2acc0ae5b83814ce830b1a500157b9c6b68efd957007ce368622288	F
3f9b0f657dd2581e1dd7b33d31ff3179c309539c7fadc4275ca679411bbd4f7d^E
3fa609f1cadb881d127a3eed1c7b8f2fa2ba4efc32cb2e34e025b3d4215af9d1[F
3fb0b77a99715fb931ff65f91089240046d339752c82495a1069470792e26818

ff;W+rF
3fc86cf389acff5dfff9dfd65e25b9d96d358214bd2bd236061ed31d647ad9bbF
3fc9b311cc6984896d03711ca684b967577d4370b4c5b037efe81245cfc9a5f2OF
3fd5a3ec93bfb1ba9a34a9f68433573b2a39224e618b9e9c02aed4cb89de5c48F
3fd85597715ed99be96dcdbcfa10bedfcca32a7ad600f9ebf609b83a2c6d481a	F
3fe92e24b021f0064189e1c7e735a79fffdf4d33994fb8e504bcdbbd19dacb339F
3fe9c9d1c5627efcbd130b935885968a811be55b5028953a858e8517243e5d5agF
3feced91f7391352cfca0debae0c2aa43febbeee7d24929c75cd8d1d5a6b782eF
4002815b3af5011f39413ce958784b1f26655ab8f66ee5e65f83422aa955b381,F
400558346b5b54b33a80390a5849a1a330722cdff9436c07acf3e168b477330evE
40080eb44ef8aa6b4771bc9e085e56264b9e562822c2bbfbd713b6887b64b41f:F
40085a6aba324cf85849d9d215ea0210e30299d2952b61e18b07e9bbd0256068	6F
4011ecba5e1b135d1f741f84948ead212a82a060f0cf75bab01b2a37fdd319c0F
4016c342a85401eac37beabfbb025c514e077802555e329f3f4a77d1a835864f,

ee:V+rF
402c8ad0ef6726c780c90655a28c409b5f0ea3b0d5b2e1562caeb06dd9062e22`F
404156845f116a61c9627f44cc1b924461c60e723c92dd3a152f2840e6e9003a	F
40519a4b9f7188d9987ae8efcdcd2a6c382d6311c8aafae7cf914313e1d5eef3F
4054f1d88ab29666683f77b8b9040e7fe11145c8e91bccaa37e202661206d524F
405c83aec688febd1c01afeb7dcce3417c406be86016fef5342ad46668393522
F
406370b48821a02c6cd77913d2bbfb9b1c8a38d584ee789492dbdbda1796c482F
40778cececacdc153601f3e0bdde3c295376d9e7a17eef328a28fd1f1d7e2f2eF
4085f09e7be4410758ded16aeb5fca59795cf4c2ad37a1afa78cddf45bef6806F
40a0c734dea8e1bcdc12a1fa49951322a06ea7216cf06631e2528d597a596fd7!F
40a441051ed2bb80ba7bf16effb6ef562dc02cffbcb40be34952dcdc20a3b66cF
40a9bbf97909feac9fdb52ebe77bd0ec92e96ff00529d4803ce6c56086f78337F
40afa7c237d384eb15a196fb651eecd913e28b743ba7734e05849c45323ff597"F
40b62a1609bf1e6b7221ee088dfbf97f47ad76f2533474c46260a24ca3439cdf
e

ee:V+rF
40d5b25bdbe536d2fd38b5b64869d82f574e42b8d756e38bc4d749bdf8f6ffe6XF
40e08209c8de5003d4423a0ad7ed9c6b0f8180f4ac00c11d42d96a7a5069ebdbF
40e235c4553d138143d79a740ff6929dacaa7d0bb99c84caf67b643e58c12a99F
40e97878099ade8002e5833f16600e777791b1a319a702abc746d9b4194aa4daF
40ebdc19d1f43fa0892059019bcdba4bd97351c6d146ef74e530e00dc4732c4cF
40f292198cfd1d640409908c391eac750a799c0007158bd95505cc00794862e8$F
40f5419ef2f5f5628caafd1966853e3ed258c5f6cb1984c8471c853323bd793bcF
40fbdb5955ea06836fc5cd49841d43c8ca177c4a345a3731b7fdcb0e482fcde0
xF
40ff738de8c90ab572f7f1b75bd512df524c5b0251c9fbf54e4d81783f7d5a34F
410ce04c09d80f22a31d904271e83d196121736299e85e3eed33da09b5e99399F
4110581b81ae9c5b81888451ef2d92b364bd02c2919a96ed2f541d4b690b1932
|F
4112f1f23e8f476ae869ef1e7ba7b1dcd072616c0fcd173ce6f6a784d7d9f05f%F
411d4dcdad36f25940ac90a44c595935da1b410049409e9047bf8e5a0d896d00

ee:V+rF
412cf05f06bbad13dcf4147fd9d0fe36f85f1ac4e736a1e70cceb3317d6375edF
413133e05ac7cf1be0030800e9f11f9f92b4cfd832e8cd453bf6a9b75994fe86F
41389a794b7cc04dd2e3fd21ff891d278296ee4aefdfda8491c6075a8b52e2d7
F
4159fb078456195a5426e0c1b4c344097b8cea15b93d89a5b0edec624c3dfaba	RF
4168f549a1eed91719335c29e0efff79a7747ffbbdf777b56e435e5123a039a7aF
416d63eed80ece67c95210f8579b267e2d49d197964c16f46abc57e43e2e7cb4F
416e2bda192d4d2ef653af8a613b3317548b4dffe2455e834970d920976316a3F
417df6c01f4373a219da10ea1df04e2565b5b27e4710818aa6718065c174f25fqF
41923a544cdeeda959457ff656dfdd7e871d90f2d4f234055c2bb0f1f3996609F
419a628252f2a83438fabbadf25cbc862ef23160a9a3d32fa110f61a1f1f3930F
41d3b70e19103a25ac6a0a877859dcc9105adf2602d4dea078e3220d5fdcb007F
41f4c18963dcef2f45ef879ee1b029b4d4e655031847de4f3052176ca15d7892
F
4206286662c3bca7d5dec45b6571835c5c580374921fcc382635bbf1caddac77h

ee:V+rF
421c0198c864523a8a97b579662dd5f24971d1c8a60d7b2146b913582652afa9KF
421f399d269c4af9f6ea67eef863e122a920ba76ba5b890c4591f7adc604c2bc_F
423fbdf1d86a2b10618e98f380c62c9e34640a2c7aae29c80960b34008181a8aF
425b1c0988b4a82a7edad5a994ae16e7775d36d9efe1e2cfab48f0893276a38c5F
4261abb467f2744c5f43003c5dff6813e00cd4a52c72325f233dddfa3008e983(F
4266dcf7867c8c57f9684916eb7d5867aba2298775bf2e55af86bb7d8b4ef39cF
4276584eb593d2fb304ab50518d7e2c4f955abe8fc5b3d1b9f0dd053d363f298F
42867004de7a228cf85955e79762cca11cfedcace4742b7caa46109e8131839aF
4286ac1c3d65716ecbf4c7210b1ecc94f1f602cc91db2bab294138fe254b2621F
42a032cda37e42e63ccb183ecdaa7710140521828aa8549a8f19dd0bc7fbea36F
42ab3de394252ea2575955dde550d26c4c2d82245f48145c1880b3eee1f049e5eF
42b68ad1d87236d5de03de1b7d591b6a993c1067b4bb54558ceaa48a68fff9e1F
42bbeefe5d2da9855ecb5e645b7be4aacf43260cc22bd95b02da32fc849a989d
1M1|]>jMF
42bea60ba5a685f45ed8675f855c453f0cc42f054af12af28b5201bf1a660ffcGMF
4331d246086138c76b626867bfe7e22ada968505bcd02d526951cb2236da0d31MF
43a65f36dfe6af5466184f30652144e3c9c8793fa34ed3f819d2d654e01edac9MF
44366b0b7affba7de64323741418475b4e65ac775871a7709bdc2230e592c5af]MF
449fcca21f14ce7eafdbe53266ec3665872f2ce58cd9fd10b5ebe923ec7e12a2MF
4535717be95f1dcc2921d19bb37276451f877f99558ee69df6a67597d545a010MF
45af49fe978be47c6b7dc1d84f54b54ddf45d39e67431887ec68d47802feb0cc)MF
461a3ca0afeaa8e8ae87e2d1547a6874187f8e530bf5dbfc39b6c0c22d899d43MF
46b7ac1c6e8834a1d46051b922ee8bd78569b89c91a40bac7b9886b7f75ed974MF
472b850598b3b222ab19456cea632da56a9a1a5433cbd99f43868e6e98595701MF
47b2d4db641e0cb05ac7567ff73f91567cff400dec134469086e86b41ebe1072MF
4857df90d4f9aa3520255aef6c5bdbe887f7cdaae0d006c15b15db7c418b372f"MF
48f161dd4b8ad99c1d1c53c15b3b1e64dea4116e9347fd9464c14ac1742ff5cd[

ee:V+rF
42bfea454da2eacfb32d84a41908a2e6d89c8e46d04ea6a5ccefa5e251b3f3f9(F
42cd49e0abb9c9f367848467f27274693443d3037a447b74cde10b94706c4a80F
42cf93b353c32a2f1ee4496369b7f3181e00c033475ee1a6ada5dd1706c96a78F
42d201c11113e97e1033dde57dbe80c43d0b96fe2894ca9d7448018fc605c871F
42e22ddc4f5145c86fda06a008ba1415e8c40c3caa32ca21f81ce460fa3e2bf5/F
42e5dee7b0556011cb8bdc92961b584ecf210268b03c4e68df01ba36dc1f30e1F
42e853b9aba262824af1f06fbf3521c29f339081059d0bab496fb26bc0f3ab17F
42ea2b85b1cebb4239ade45fc36a1b309a29b95be50d26bf314165428aeb66acjF
42f1179fa155a1a3b4448c2b7429ab632d2e5b7216612cb0f5458e96d9c9e738F
42f4a67a0204be33ee75b48a1f31717570a6e3cf9551930351d405cd614f5ecbF
42ff9328e94163ac1555369afb66d510954eee171420041d8a4d8bcf504fe3f8F
4317de17f229764365281623322d3bfc068eeae3772e61937438e1e190c1251e.F
431b22149fa33a26bb336eee9700dbf64d3ec3c03e9604c4203a06a8e35aab3c

ee:V+rF
43424b0d689ecfd0d4282dd45e7088dafcdd16f51f968cf76021b08f5a1060e0F
434aa31c1e300108134248129540211cac97b9c972fee7b8a5c1247a8c318c2fDF
43561875a5de2607f06bea160d4eb38c49eb95d2de1193d32c75d69bbef928deF
43570d8e293bd93001cb8c4cac3e4b2045b3024b7f3e08f4449735bfb9d206c6GF
435acde66414134bd505e6658dda39972f87e643ec0169c1f4c59a938280fa39`F
435f966aab54d076f8753e805379be8aab3e4bb69459fff3ce7c63cef6a043c8F
4370607a6da65b16c10efee16a7e7dc47d3ca219e5adbb651ea25e3150d278f4F
4371a5846dcf1faffbb4329cff76c64cdf7cf7f9103bbdde6357e230e6f9ba83QF
4378731794448fc800d324e71a41beeae2b174ba078b23eb78ccff27fd8d5764F
43797987bd1c6a7789711b4d44fcbdd981073b3086621718cadbafddd9a64625F
438402ee92c25f036bd2deaa1cdeb1a00f4983754853d65bac78fd9adc101eabF
438a67adb5128df187df7f5745a6afe2d244d1571ecaf4159b03356b32a60436tF
43931a5196450e67afee8e240f59257098e4480d715afddd7ca69d04c9af6240*

ee:V+rF
43a8791d748c2ca3cb5e8c1b6682319313b8373bb0e84e9e545ba09dc9e093bb^F
43ae4b92ba776ff7c0a7d9e6c5837380d87b103b8cafa435c922bb2e68bce68fF
43b09300e3cae57123f6afdd23ac7e88411c687be6f131ff215ea718f5933e1c{F
43b68e9aee5969d0a7628cb49b8b9e8a4b328432cd2bbf3a542567a7d9be9cc8F
43b8b70412f6c494314d9177182cfca0820391aec220e38ecf47b9fb9d4acd86
+F
43ba47c5fe93e659e2128f88d812fbff89a0212d3f97b085a69f6ec65e2a1b2aF
43d76c869fe744e94bf344aa66f638f4afcac144a43ed4d8336d4147ae3bb81eF
43e5f421e8e3c2fe23f7a93bd002c12ec11faf3194b342d07ee3a9f9fb37a875F
43e8db14504b7b1b92c33224717880dd9e4ea6101787efd5f0da89bc9bf2d7a0F
43e92b9290406137c9b3c56768f3269a089b338a410de4e2879c249fd794ac2bF
43f50cb7c44309253c847a258d592992e250678cda19887c482849bd67b447e3F
4402a7fcf865ee506196d91c722ec2875470f134b63f3912ac69561ba10e5113F
4435a2d66b8a1b83a30085a0be118a8b93bf7989d924736ce0ab0c1085446d8b

ee:V+rF
443c9cfc06a5f4f00f7780823a1f4d236782b838c05109edde4737cba50357cbF
4459ade066985609ab1ac51574d24bb466645a717a2ff3a30e417a8b91609a87F
445c2d91fe49788941d409448267b19e014c9f6354238fdee408aa1d585cfd01
=F
445eab0d09b92ba9a49ba8c3bfd3c3eee915acfbb0d71c89b249baf899d7fcb2EF
44600066daf3f3b57b9e269737e0b0dfcd410f3a524fbbd74aec3162d6f84f7cF
446b4bb7e11daeccdf09a55cd6a749365497b1d1ce2addc86246a46f9de47af4F
447681bd8d74b001a4a5461694a948bba8dce453c2c054b8fb5d38408b7888a3F
447af92c743509fb44207fbeccdb5f8b9f35865517ad94009935976e7e5339edF
447bf3552c5156b143306396c3569328e80baec97cb1a11315280cd2f3b38e0eF
4483963c33f057bfcd4b6120dbcefdc634413263eea9af2c988563522cfa5127mF
44904175313b13552ac962d42d456dc5d52bface994ef485f56c33f7f6971440
F
4499296b0da4f8a6353fc0b32880c2dd463d4a440d98446b29fd4d12a5a2ed28F
449b85f4d50008df3b5663b39feaa09ec5df8f99f0a2327e0e8e846345963022F

ee:V+rF
44ab9339bd5d854867709f046ee7265cdf470dcab6e44935238e9d85f50a3ffbZF
44b24b7b0c7aa6f549efcc0d2d645424850f626003bf441a5cd992eaf86c7fd3F
44c119ffc1f4001f24a6905dc7a8b1db1b192babbc6e3390b81e54adfb63b7b8
F
44c332e4f12eed26da249463f404e2a9b0a26965d3864059eabafa8b359ad304F
44d06a1ca389cc452e21dee550e31d9247c635c403355f8fa7df144b76f7ee8e*F
44df7609ed5e477add5d58e49530bb036fc2ff1d94098c85b2111eeb85a31168F
44e365718f57aa02dbc0e6c0f884b3e6dd15e03acd28ab5154d917184b1d05cerF
44eb1405754fcd4ae144cb5025d91b3ac8759293ff1a0f187ca3a1e153137223F
44f231fe5f62541a6b45943aaab6e3541465a25fd0a14bd3c846d9df73cdcd9bCF
44fdf0fd6b2ea0867e2530297d92b753e9b67534567ffa09595ff50bc74c9886F
4501c2327452af05f97c309a9269b764df7c26f9118e1c6cc2594f1660aefb89rF
45190bf945897c615199c3c6632ae316c3c9299a53118705ae10de934f61741fF
4521dde116f75afbb70beca46c5f369e56507e92501cb8051a6caf5aebe62def

ee:V+rF
454bbafafa2ed6a940377a73f755cc70525a8547533b1c20ff588842216101d0
3F
4552c0e9031fc5f990a165feb17e2cd243461f760cb80e75769c837d1052f193F
4555608cef90da4d409d7d09f1176fc6cc4348f516c64411e318379a54137083F
45631c9c56e97ad1c34577b8df4c774f108693f67b52f45cfe6915a3e3f40208F
45664af56e8ecd30d4df0d0ca03b53d10f0840e2da053735655a3283b7b1fb6dF
456aa067cc96e03aaa605e52a86cc973f7a8dab09337cce112097a4608dd143aF
4579c7a7925097881dd33b28c72cce227a024a5f071fa4cd0c5bb09cd76d8ec0F
457da3dc935ceedbf369f8d8283038086c61d7ec599b6b13c34f1a9eb692decd"F
458a2e4662739309c98eb0b79c83a8348f583ceb85c8d0889d5b32448cdf18bfF
458d8d0ed05bdaad8b13b09c5d860beda84b34bf0ab4c5673194584865a68103F
4598455c105686eb7e3fd9bbe5dd3d1c3e012036441206b4a4b2c4cf8b7323026F
4598ab08f211c59a2ee7f9d85a2e2c7a4f7b8845e0d7ac7dbfbb570230111cf0dF
45aa06d1829f4839d099598b630eabc9be0756f534ae4a81d0d6b7ab5922bc09

ee:V+rF
45d71f9f39e70560b9d5baa82caf326bdbcb0b135c3f872940bebef466ce91c6DF
45e140c5fc3aa4f6210be1b434e86df569f40a99aa8d64401a5ee00649f3b677=F
45e4431fa6444a15d0292df48fe285761bee76d70d5eda0b7e810f4052b8ed92F
45e9a1e7f70a5fd4ccd35c605d9412dad9cba3c4602e350da0bd341a6d217b42|F
45ea6e4e3244ee8c391939ed27d9667af07cbcf7e683b8241c444b5dc4340f93
F
45f0406fbbb55abe1511ceade8ca9fb297ae44cce197166c9a3f70561dbffc30F
45fefc5e38fdda8877b262c158dcf1558ddd8b48fca3c2cd58b21d90e637096fF
46014250185344e990623d8284713f5bcea7006c7779fc959f7da3d39032c89bF
4602b5323f417a87240cc0e7d73bd59b5353a8e84649b1ddda629f812a651716F
46064f76c45b401ff1197bbdcd32585b704afcef86d2dad3fb76250749b3ef7dF
4612dc1b815321d8acda2baafa9107d32d2e88453f1c98a341c59936db87f826F
4613273bfc2c11c9816fb2825af9aeec01ebd5785d69700793afafb364fdfa5bwF
46160c3e8468e10ca76482b787522ad64e1f769900fb6947b4bc6690893303cb


ee:V+rF
461bf2c4280e37fa28f8577583cf56315e10dc6a8898497da766b5dffbdb1a56F
4631ab28c6b9c4fb1461b0f98b9c1de4c06d08fc1e07b0e42d44f966c8d31507F
463481903ff9ac36f08f2d63e5bce0da7c84afc7274e5f35ea4d39f73cc6873eF
4634b74cfe7dbc9b83774cbbc50314221241227045a9199072df357ddda72bf3F
46604e7e63c82851d300be853fd43bec9f863d6c14a9a404185a9c0fe6b88932F
4660a5a7faa79cea2990c384533fca3da9b3ac6afdf6f55b36b2cad51352c3e0*F
46649389b1065af3dd7807f1fef23cb1e6f50351ea151d97424e8b8a75c616f3zF
467ea07622b7bd1dc0694405f23e3047a904f677d60e58b4778fc8e889c2d224F
4684e767f94d3dbc6eaccc3037287d441ff4f9d0bda6586211a7181edd68f6a8
F
469ca6e8993db68735d7333e493a80dd4dde10f37d4c15b290e072922a543da8F
46a04b65f068cbfdca98fdfb989911df818cda7f362078f3f1fdede4d819cc71F
46a11b35c33059224764ebf871842b0fb284b2783875ccd819e16761e47dc4cbF
46ac94286722fc2f6f68ec4c0e70152b3d1ff6fac6001d2155f8228d91126574

ff;W,sF
46bb7deb87e89f41a59af551779c4df4a4f0afad8e7966438568b1534c02fc3bF
46bca967117d9441489461b3e6c17e9d3e387f3c3bfba523e30b819bb00825ef:F
46c46ba8573d8f101c53fe10179a66e853ec151d66f5dfb686fb60c5e75aa610	F
46cf410604f7938205308a15957f49b1342c994799e461a129e01bd216d7a933'F
46de5f99129eb78da5ff4975f706a21b2b68e99ac0a5aba0c19ea1b67daa44c9;F
46f713cd31041330e2739c5a644e4f598536096f3e39d6c667a6d044eaa87893F
46f776adf7f88106a8e818889463dd616d261bb3462ec68346857a126aee742egF
46fcca6c6687e1d7465d0f99ea219de21f84bde74cc822721a5e55a13bf97a0cF
47005db64df1a2026edd49418e5714bd0cc4b55a22af61ad08162f38d849be23		F
4705cdec550031f6ee8f3f2c0c78c72c88ec88a70a3c20ebb27eea168bfdd9af
F
4706b7d5da4cf50b5e9a1e2b512bf1746aac5d7ff7525f047e6a79a392d7f548AF
4709ece2740b527335e0d4d46746a1f8ddcdfbb92aef8389bef8e6944d560ee5E
47174964aa424317b7623852dab6eb134838bc81b1ecc6687a16e8461523c3c8

ee:V+rF
472c45bad9fc5ff6c17193d9dfb942a7291f6edc650f2c9c6c14dbd3dbd515b0F
472dfbe984defab2da4d391865a8dad49409470d075bba14d4c3b8ed3ece9e0dF
4735272f88bc3a162accf0ab7bae821772bb319cd6b136ca5791eb1cef2eb048F
474549f2d0c95b83d89f1d651d078459863a9e1f202ab7c4c64e77e2735fab8aF
47479ca82c3c2c2c7d65a383dba4f54f39f315bfe0571d1d9129c0d4101abdd8F
4752988d38c83850c74c74ec19ca5b7e1c79f8817544be00ab3fbc407c01355a}F
476abb9c019d06d8fbb8b7d20433405022b208c2c777b1de0c036fff3108fc7e@F
478b6dae53400cf32a4edf127885888456e0d40687b130621abfb48015757969F
47969fe770db3c0a761b6cada255644049a5915767baa562e1ad4010e338fa35F
479b38bee7280885a7df789a1472c2d43e1a0103f8607f0e6d3fb26c2ae13423	F
47a1d5d0a1ad064ec478ea6d44b259972b9111eefcf4ada7bbacbbe6aaf5a0be
KF
47a66548a049d52ad8e7adcde0de98e6768596cb771d5b8ee590193dda421dd4	F
47b080e5a77e0a4e64120cb62ee1a56fde234cd979ec9e29cfa1488c409e4a88

ee:V+rF
47ba59d4b1cb5b673b1229b14f41032935be9d093380d4ebda5b7a3a020d1829pF
47decaf77cfab5ae9ac6ca376aea7b186c9ab835d41abe31c6bcd91c3dee313f`F
47f19899e75c7c9a5b74f30643d69d0ccff2cf5451546d7ad1a727bccaaf0ea4sF
47f52ae65081a918aa822fb28261dafe5b707b012d7f07714f3beff7a4d49f45F
4800c473b78c5271f956b53fa3f8a3f696c8b2709fa3afd5457178a5946300ebF
48050d32a9ddb2c79d03c638c04cd306724f7ac310231a77812108d47d170a94
F
4808002a70058c1d3b9c495b731f8403aaf27010bc15e1e5a808639ca82489a6qF
48122d3d4653fe0fc63133e91c130b529db55e9ff1940bca669fbe8d0e04f223tF
48329854b7d3d8bc442c5246bb0589aaffd665388bbecfc7c00032cfffabb222F
483c0e526fee490fe5e387d8f466ba9336f13e99e38a22801656db9f0ef6fdbfF
4846ff9c3501bdbb24a3b5c855a6e385c608a7387446302cb070e7c305b0a087

F
484cb9d2c6a1b098378ddaf70bdb38133dc17da620e66106b68fe5d774de37f0F
4851da54ebe84600b0c7af372a59c38094992018f2ffe45bec040b2dd5d380bd

ee:V+rF
48733bcb59a63cace889d40e1387badbc9621da7fad0ddcd0d198e83f214e41f3F
4874985f1d75f7c43dceb6929982f36fc7a9566042a70c22a42bc6e3e6a65b58F
488103f93db3517ddb11caa529814abccd07f454858bec9681eec8375c544207QF
488bba15bc1daaf393fe105bb25934f4e99b57cd9d0774beeb3fb7bcd72df936F
48a43cbf24e5cc56899ebdd66e5c0f3d2fe213629ce3c7debc96435077102d8dF
48b1742bdd262f815457ccce6a8412a9c65dc9affb811fc52a31da14b7fe7f4eF
48b28be8658e81953a40daf5ae041fd07fe585facbf0a5c985d98cee88b3f0aaF
48c1cdad82823961370ac3c16ed4a93a8b8b46bde9034024316e1a72af9522d4F
48c7292215b233ddce0ec673e57163a6f867a0e6557f4d3d0ae79f6155792fd3F
48c754619fa5b6636c02b2b5d79f0529027a96e638760d84ff74df57ece87bd25F
48d7e4811a291ee31fea33ff56b5e11082ae3d2a0bee442c7ee6b29212f72b3e#F
48db0a9dafc6ecf4c0b955075d04ff198a44fa5b1bdea37a0f03af3d9d75e1a6F
48de10d35c7c78cda02151a71c35178d70d58dce2c1dc876ddabcacf02451fd3	9

ee:V+rF
49113267f534c7bd5e707eaf237fd29c16d11aae9ee70d8a16d8dd33edb75084F
491db6a3e909d355ebf2f70d1e83753a0ca5ce5a0a294d1a7903cb2e82a228c8F
4920894974a22381aabd54732be72cc0879f5ab5e7584a6e9ea403da66101b5cfF
49275f52aa1c71edc688e6802a1f2c8b136594807077f4aa90e4e2686edd8ddbF
492eb3d51d30fb1af43e49282e578161b5b19cce5b45e3fad31bb1affd621cffF
4933dfa26c52c90e550bd7f8821e6e879a155babc9e60eba5472271aa463f60dF
4935d172a32f8bef9fd07236702a965e4d14a6e86b534e6c52fbe4aad6047e03PF
493b003d3ae9b9c7add7127460997cc5a69ceef2b8884c9efa668bd7c7cda3a8F
496ca22ef6b436dbee6813613f31f2ebe1718fbe7c53d90796a6f3f18ee0a331F
496cf5c5ca7cdfa69a957f1fd58b42a7ca210246b35627830c2607273e22b7c0F
496ee19b0bed3aa542d3fe7473b517f0eca004f3306333e343b200c30cdad5c7
<F
497230bf98b04ad42a5e86190210020c9d693a673e748256dfdae01fda278f6bF
497675cb6d7517ba23fea71659d07fd3761c557cdf9fd151aa544223dbc11237

gg<W+rF
4979bbf79b86bc451b21e72cc74db0991153920063a30b01bef2f9334eed1607F
4985ef8243b405acb259897280bebdf83951ffe71af3db3fcf8140797602544bF
498b3c4385806f5535a6ebd9a444db2e30938bba2f9b1f553b35189edc73b0e43E
49941263a7a0309c58b3d3e00ab81c56b1ee1a70b49b873188cc23686f5d3d9b@F
499aafdde42137b651f07de95acdb9b2b0426c0923756ba0bb98c74731260debF
49a6803a256d5206d45f93d9583e7333cd4961a731881b7a82c761bb7ea7c9abF
49a7e87cdd6368571e9c30b74a1800f53df55d4cd91fc41ab8073e666edbda38wF
49a94cfaa934548d43b739e469156d5cbf8467609c08c9d7583ecd18912a49b7"F
49aab94d53d2b184f6a56304123436d4e5036e2f12df6e2e89bef3f8e09e48c5
E
49ac1322f5ed8d216331f29c35eab930dc5be738f27bf00fca63036fbce5de80\F
49bbdc6d250ec47750ab688a1618baefc947110bdd51d0ede255d5b1610a74fd?F
49c502046e8fd1833a810286c8db37a87f18dc47667827f45a56267aefdac60fF
49c62aad693f852c4a093519a3b829f4e69ae106375d2be0eae07159b97d4d48(
2M2}^>jMF
49c9854872e8bc5ea2a45b52e2667a2d8a44dc7c1e42f73a3ed483d4ed29ddac$MF
4a53adae3dd3a8d933f2ec113b7303ce7d9c782edd612d17b8d3badf4c04167eMF
4aea4b143d8173155f3ca2e53011c25de372518c46da064056b3507555cdc03a8MF
4b35cc37198ac1275db864e9be35ef4048337b891115e699165a85a519fdd7a2MF
4be78491df030e9fec9f5e5789c29611f39d783a9bf1e70cab686d996dc7f9eeuME
4c39fd8baa3677dd6ae1debc1bc8f2bcb012f024717dc7b97179d39ba6e3853f_MF
4ce199f03c4016f4eb22b3d9b8711e1cb1d9864540849b2a5a1c4df4ee5552ebMF
4d3ff47c13cc9874693a7b3fa026f1ab176d6a2d2b0a14b6d2ce80773ed3fae9MF
4dc25e03c0a0a30babb3b4e2d1e9e2f11733686d656dc393fa7d1a62fc9f6fc3>MF
4e92d3195efccd7f140506a0902f4b658d5fed14a465e7c9aa46b8ecca2996acMF
4f181bcb90816497b5e18006556c8e9c5e26bb5a1da4f5be2acce0472c81866dMF
4fbc6610c68813e5bd6ae12f052f547dce477ce710dcf0757d49212f8415fe33SMF
505e596b1b77d05f545fd3684fbdd8591bf9ca308db67ff0a6b36dd0a1341c17

ee:V+rF
49d7fd7bc99dd196b6ad0b23effba028c00ec83384e764f0625ec4d1a888a932F
49e01e923bc5d1026751341c9a01ab8ef4d50d8b17e94f179de33afcbfb0b234F
49e9c90df2985998052c0402a2bc848b5090e19a31cd9259e1fd77529e6a3505zF
49f444eb43979988b55286bf011d39ef639f814d68348b633249b8d4d229e0f3F
49fd4de23b8c381fa2c7fade2fcd21a022bd86e95b20a8657eacf9b0f27664d1F
49fee1d14c58251ceaf27e463d004b657ab809c483a44ab5c2bc0bf22a098086F
4a0c264159f020e612793ba279b544a49c67ce5644e4673d6a1b7e01986d8c98F
4a1eda7aca52060e944393a7b40798a1e90bbd8b4ffcf3bdfe5779ccbe2acc43F
4a1f2f949b103bdfe54eebc6b4963f047de93b1a0cc47cfa795070d2edcf457dF
4a27bc911920120ba55850208fce562c36cd54a517a88cc8a4b4adde165bdbc5F
4a28543a74238167f9429cc3669d937bcf9dd1f1fbbac1543897abe810b13539F
4a2de0d15d4fadd42283d48bfb0d4abea9092c5e82e168374e117d6b6d7b27d4=F
4a40dbfa3e0e5c2e7457bda18c82a1c0d3f49f91b8d548c568fea520908bec6b

ee:V+rF
4a6ffb39008edd469d4365bb3bf858f5f5f466129eb9e330d978b28866906891F
4a74ed8e2ec25ff2f90a460ace450f1f5f9d8ec2388840ac54190eadc8a43575	zF
4a764611d924b3be2baab6d6ffd5fc562fe6a7c2c08cede4d58bb7259f7a0f35F
4a8694a364e768699fa73bb47949f8b4f66c047ef8c5ddc23bde156d7e70f7d5F
4a8faacf86955f2abf551cdb070907bfb67ba8d81e0df1c694adb79e873aa809F
4aab05abd1b63222c6aa994c3754ec20a9d3258f4769449d5e105f718ba5f442dF
4abd16c4ab5141d33e867b7f35275398808b6ec6c8b49a01a8fe2836089ca1ed_F
4abf0ebc2127e7a5b5dfb595fa447cb44f339ff023ce88bb0a97992bba4cd3a9	F
4ac5393de035d7805106e39277a7b7b6ab0713a00553bee6342fb42b71e80ac3F
4aca2e6c6e4faa4ced065ea161be76f436ab64e5f16cd84c5a0378ab451f1d80
oF
4ad0b71e3a6468fba1b43ab82fad024415b5296c7b77d1348fb9afa3f828f98eF
4ad165c06922e2252a43f8ea8424a0e1ad01faa0b3cc0656d5e88a5bb3bc053fF
4ad790401b462e49852b64d52ac831ef97ef989b5b507c46e6711cbffdc8e689

ee:V+rF
4aeb221b696dbe4b67c7b108b689cf26df6c7baa673fd4a529bd4df444eaf4fc
.F
4aeb4ec586ae68b258e3a26e5bf455914a1bef9bf96ce52ea53b74decb9d1176xF
4af524ef4c3174e29991b9c0e236ba3d89b8d2c935d9359910aca965ba5001ca-F
4afd47d6a1f2abe50950226f0ebe58f8973c16a4aa727eadd72419fda729468fF
4b031b0a3b505796cae1f7221a96821c6c953c4e2f94f8869bfc2a6139af8b2aTF
4b0430168f86ed2d3205e156f91cb895de8e9f80a08f08355aaaed21286d7be5%F
4b10b467e7f7d3c03d65a1978142de23e7d3b60c9c6729496eac6cd915d2e83cF
4b14173ba0287bf249a3f49d9d5968a1bb673fe58f4a0ee8e066a9aa389741bd2F
4b1e28830cdeb09548b5fed9c3021450437dcf28952e709628dd86397bf78af4
F
4b1fd0ab7ed6265d09954241b71684d0db26d624318d6cbb227909a3ca804bfcvF
4b2789795e0561f07932d99dc35a224a5cb2e2fb4ffc4d3c3b1fb1c9256f2f25F
4b286d1b4cb3c5b51e8b4cc94f6e08beb1728d48f042e99fb51808ba50156970F
4b31ab8ebd6b1481a2299adfff2b7d616abc0233760f8745ec256b96b86d0077

ee:V+rF
4b38bac5d80fcc0063946dca9ca07cf5eb6d0ed1e82eaa7df1715a790288016eF
4b4af671ab41596e55314e4e7f8cb70452287460fc44b844405f9035b7823f84
F
4b5b55c14d140a53eea4285b441202dc50e0ea78ec297bd568befaf65e5582faF
4b6626a337fe2141755d1e57f9afb5d1914f4b0d752fac9cb28cea90640d95d3	F
4b698de5fd7e0a64306106f3018e9d00dedc1f7a46d354339f012c97d004bd0c	F
4b8be9f1166188e6844902fa02e3822fd56edbfd5e5043d22efd3d39bd199f57F
4ba6b6ddecf71dc7d8295a3fb4185fa2934f07e58716d8466b73a50137c58a53F
4badd67c65c46b09cdfb999c67dcf07efbec0e2b1b5ee21318fb415d90aff27e@F
4bb74807b09db308a56c244e21970f4698de871955175c9b552234229de92f91F
4bc4f9b1528598d166b590b62bdc782e328cf226edcc858a3d5a60dfc73ace54F
4bcba3242efbe299d1cca855971a52ac841ce3d6656543283cb9ff8dfd08b70dHF
4bd28dce0b162f8a2da3d74b80a28f0bed475feb3b13bc07076dbd9447d2deaaWF
4bdf983ae009a8ef897188d860d0535c00a5071923c33261e644570fa2d5cb9d8

ee:V+rF
4bec36ddbf5963ce6aa8fffba7900ae727da0978060620165937170bee608f51-F
4bf12266defcaeaaa70a5bbe431d815b7c435f5f95d2be12d8be7de214533e53F
4bfbeb71cf3639c4f6067ddf6c491f06976bc93d091646bb825481dd641a719fF
4c0432991858f896026445ef401636f12a857102f3329b8a5d034aa2e99e2bd4#F
4c04f9c0edd59e74074f9a36500741821e912b6a5865fae5f59b76252ebba71f1F
4c0b51e89a2551de7942fb433c79d0f9aa1a872daee24a3859ba5e6e51888012`F
4c0ef9ca78331cc0b0d030d525a258c4b4b7b48e388c2a3e3c8cf104d2f410efF
4c0f98326dda59f363bb5eed1feaf1425f58894bb5fc4394be480c3fd35ff517F
4c0fe67802024d085939269a1da54ef7d9c6feea27bc2b6b94c3c64d18835d38QF
4c1acd8485fdfe86cd47962474dfcb9f59d713caf6da198b738ec4fa3dd0c38bF
4c33dc16f8bf9f19d59d71c209205c27c9923c2016d5ca5f3409885c95bd8be4F
4c3662507f01c062009127bb3ab45ab19236e6dcc70fe08ca363713b45cf9229XF
4c39d29f58affbbc0dca6ea29bd2dd9b75658d24d46f216c7de17b46f021b13ex

ff;W,sF
4c4e8afba69331a45497c224ebaa7b237c5e25c3fa2dba00bb45fa49fc41aed8F
4c5528d38245aa14b33d05948eb02c322e95528485c9970733d2e5a577774d6dF
4c591b2e577a321d2a3be5e390eecceec9fe2e18c4d4f269ef41f4ecb0ef6c0cF
4c61a98e630cf29009706ab099ff7870c3593c7eb39e9d0edb5e059359012e52F
4c7a4b1402ce62b471994dd364f3e883167ad5ba8ebba01d67f8ceee2f63d6a5F
4c7d848c14e00ec553e54a225e05056fee56b5df54a71ffe45ce122d6b74625bF
4c86c1c3d77ede8a23e4eef1b4c3e4de9e50b799ed8dc0e6a6091ff032631cf6F
4c8d4ec39fdb607061601e0e4b1e5230323ad72c01643e17ec55ef571d886e49F
4c928cbb9b34a074f2c249f56cfc152f8e285cd974e184b9f5ee05214cbecd42F
4c96449444e550b77b9d63a86b708d50e9b146f62a64f89fbfce2abfa49c871f=F
4cab2e9389c0bda9927bc8ffb3f5843f6888147fd2ee09109c97a50a8e313dfaE
4cae2658d6c984132e253fc1cb8af035251a3acc79acc7957fc3c92111b0f643<F
4cd8e9cddd54af538fc6e1a395c1cb5338b2616fac4687ec3606a53441b3b88d 

ee:V+rF
4cf62f2fe312ff9b70310eeb760aecc8141285cba4ffec167b47f1cd26cb8fecF
4cf77513a445cacd9183e8004a68488a4038ea670b7d8afe41da213c440c508a|F
4cfa5141393a1004bc9d7885fee9a606293ee21216066238700f933afd5e4598oF
4d0e360eff9294623b345353bcf2cb4623c50a3e2bf31ace6ba05141150d85fdF
4d12827b417a44adfb6029689a3750767d051d27bb01400addcf87233d9c73aaF
4d1bd70c6b0a083aa5199e8688e2f1a51866cd56dfb5c1d7604347e2bce43b18F
4d236aaf4435c04e7eca7641052df2e7fe956b46c24fdf530db5d3367025b1f4
2F
4d2980f737ca5c15f4f33e1a43a82d6b00ca06a5c6d284643ea2f0b2e7928f76F
4d2dbd65fa67b8c23648a188f830340cc1da72b5dbc71795229022de0ff9720dF
4d30dcad5eaa26754ca93719c17a0897f17b0ffe1c050c78afd90769cefa027dF
4d32b8be0b3416b8c7b225709e77847f3eb420ac65b6a5a1c9c5f7bf13033407F
4d332cc4ff11d1dc4a0a7e039eb49da22510476539025c6d32b9a5a212c7cfc5
*F
4d378775c38c6fc1f731d1861a287e0d217101b8afe07f3c8b0d015fc2a45e89

ff;W,sF
4d459fe6f652254e5a835c98f2be03ec668f7667a2f0789647fd5a2e1ec01e0dF
4d49a5d533e4c753cbeaf06a490dca1f72f5462a8fa7f3c634484c68241ddc7cqF
4d57a9eb757639f05691dc0a674b6cde76770c459608cab6a9a6bc054d091f7fF
4d58a246d4453df6a19b52d675c58ebe8d648d62ede5f2fc0cbcb709d686a098F
4d66ddd3b79ce560d9eab146d518f751de7e9ef4d667fa701a868a978f1342cb	F
4d7007f3cf68064e511dec0623843f0d41c7dee3f69d1b581ca0a6e9069cf098
F
4d706aab7c08c3071b31ae66919573e924ce2400aa7bf07fb5eeea3a69a8bb73F
4d766c79e706152df781ac169a04106c6cc571faea5ad9beef0fcae6481c3a5cgF
4d77c6049313415fe1c4aab3e4ee43727167a46b87e28723f6c79f4bffef36071F
4d7880fbe60e6c8b83c4e01347b5e9ad274f8eee38feee4a3d7c3f8410c561aeQF
4da4812c211785ed6403e9aa77dbffbe1dd3d4a923d331a118e097ee72e34831F
4daf83f9424e98f68f851994a49d811bd5721394db482d92ed7f2062337bafd9E
4dc1a1327e468460b517ab53ed5f213f2ea0b15a999fc2c3f80d7d5b477118cdc

ee:V+rF
4ddc7a2a317dc75228322785e2290c04acd3263ac771458097e5f402bb10508aF
4de0f5c0f1ddd055c4b4b2635e35081b0a75f314bbe5cb8978790bfc21cebbc8
F
4df06b794b26d27579781dfbefc5c00b87d84844c334da58b364f3484b878593`F
4e09aa7b08c80287291584ba0426ddf0d69699ff7e4f0bc6cc8e1a788e10bc57F
4e0fff288896ea81f4c997cb6ce0c357c6515c6987555c53ddbd8c800177f083NF
4e2af30c8cdafabdbbd71cf0b42194118f3297380446e1e39471402c1358b840F
4e2fdfb11cf1f7b0f724741e7730e02c2e6ab6bc2b306bf41ace3283e2b8739bF
4e67706fef5e2721101385bb71163dd6a70a46cdc7b46ca2c10b2007847ad2f0F
4e697ffc60fca75a99deb8089617f94c12550b52fd5e8a07ec885967667c7541F
4e6c5997489d089dba27aefe96602ec7208298c2e48067c3ef634fd5a6da5f0dF
4e82685863559181e2fb19cd0ab050ce5c0cc72aee0aa23484c3c8bd3233a2aeF
4e89a2934346fd031ae25135a0e99fcabcba01ba6e6d9efece1eaa54d9929e59F
4e8a4eb320294b8d3f17b50efaf7163b718c714032a6266f8778c53722127d3c

ee:V+rF
4ea1017b5a921ab782e09ead7f9368a70cc11716ebe116ff1cbc4c7bc8cddf99F
4eb117f25866c9e447c845336fe608b5c30ec80262a6ffb3dfb33756f0001e62F
4eb469f0ca30f89921cee1b76ff6dd7b1c0025256c9be1d13e2d2c4dfbb1b927
:F
4eb98f8f58cf6cec17799f6df6cd52b55de57ac3aef90f330df1e07c1f8f3702
F
4ebc55a9954ac2afcab8fb9d5afd7de1ac28a66e18e635767c73d22ff0bb53eagF
4ec201776d93e717d898e90c7576b88da99dbbcc0c2c4e7a0088d155ac4678dbF
4ed29d175fb03385533dbaacc9824611743ebcc84d3ce5fa6f376a5568058d49F
4ee55b429ec95f43a7388f2b424b8db5a2a637fb009b640ffe07fc328900315eF
4efa7633b62075aef43851141d38c2ac3929b35c36aac708e648998975d72298F
4effc7564fc196a4c6411751bedca4e9e01367a459bcaff78bc6849dc7cf71f5
>F
4f005504d21283f588231c70d4fdfecc7393a4b60fa72b1498f6aba2985e1d0b<F
4f125e807f2d9654af85653665201a2fb6833421172f030513ae09616ba3f069
wF
4f162133b3536d798fabbd26d093d1126b87e049d6687beb758da8930753e4f8]

ee:V+rF
4f26a49ed12aa41e17cd5c146486cc8db5796101704d7b492066007312935250
F
4f2b4a6fe32be5906b5f4c7f75b71adcae776bcea3e6698d3694791b316cf542@F
4f2b6dd685c3fa625585b5fe41f9b3277cb8925b675a3b8add0c89efb81b9de9F
4f2f74c8de47efbfeea14ccb4e01899a829a67121a6963532b82205d11eaea8bF
4f37e8e35d62af3023fa7e8393ded5ec181f09c19bbdf8f8210919d800c883acF
4f3a3cf03d964bc88b6358c7506edcacfae9e90eca37a578abe76cb85f497a8eF
4f490fc935e1622edd8f29833cff99546eda921facd62b71d30c95acefada869F
4f58b903b21acdc1828cdfde9dd84d381db27ebca47cc84a8a8225dd657221ebnF
4f723648476309de9070d25c30df94bf8d0ec5cc665cf947714768e3903e6677
F
4f80068ba1aae1df0b1a343be00c4f8225667afd61a123bede56704529ab3f6c
'F
4fa63e9cbed9669fb646f612b5c9371ba7bd3f11e6ce5059f28af1cdc7da0780bF
4fb46ce209b71d1437ce790ff6339784632c86ff1c34dc42c88780ecc894575dF
4fb95ce0e3bb960c9c63b40c2398ead5b921b09764ee630c5e15c83ef4569e24

ee:V+rF
4fc0e17577976ecf2487198134b9f2656bdc36caf8e27c75efb6aff14204088eF
4fd4ad7ed695ea67c7d6d97ea6cc730d12e1d50fb6da365945d0f6255af4bd45F
4fdc56dc0f2c90e2f3e04a9191f8f4da825b37f6ac25fe246820e255ce02e8a1
=F
4ff26a4c002984d75b6bf2b0150de3b528864e2ce86be2ab94743d10ddef1544
F
4ff754e3b0277c5062fbf7116cde18b1ff4c39ef530dd4fecc189d221739fe28vF
5001584535af6ba52a00d1913b2b5f60df1239116a2cbcff84db48a9359bd3a3SF
5005ebdd55f4e6e5ffc6888045041951f173c1227a635bb776b918e888efdfba
F
5013f655f5321c66d30f6ab553d640e8a1df541105200e36eeae415ca903a7acVF
5016630a65d39bcfb9fe686d8dda94e2b896afc8b8c41f7c29a6bc5d3305884e
yF
502759520df3c6fcc6838d5f2158c4dab3f4aada9ff9455473132a5be1808ca0F
503b6775fa6993e20617e140090892909b171ba5cb9cf102f14e12e8e3722fbfF
504528b2f64bf9e246a93ff851b9fbf624d77355d1d57587ae1acaa4522c8fcbF
5056d3b14c1c47acae89cc110be58d13ce5c372f2467505049cf09faeef3f7b3A

ee:V+rF
50637eb878b9d983dd9ef2ddcf46fd38bb751310409cbed318028c6ff3c514daF
506818895cd30b93e3417b8379f3afc7f80a2a69c7739886bc58648f153fb9e6	F
508911ce79f98f5eed94b7cbd546f0c6e54fe284ef02edf721f6bdeea590659c
EF
50933b6c70f520be21299ca43c2f9714dd3359dc1c4ac8f96290b572eea4c093F
50988ba783fc21f380b1867ef9c2f3753fc650d74ce1e24f4f3f94a5284b4dbfnF
509cf9ac14798ddb50f8710817ee91492ef1e1b1a27d3921e30b5434858dc294ZF
50a577d62eed91a0ed5c686f85830b3c9252dff331c94841f673d8f19924250d	&F
50b41570ec21f348d3c7adf1b62909fcf0674e4f13126166d7667664345d4f42F
50b46cc6de592b1b49fec6ba38878c1a368940c367309a46433e7015b68a5184F
50c11af52b9c7aba5a74a2beb07e802550af036c3a37feb00b9bfca7b241ffa1AF
50d0381894cd1165df39084b17a13d53f360ad62fcfdcffb2c1b16a1684643acF
50da2508f98f265f7ea4063d0f2a29fa9248b1aab9b37f54f9278b1addfc22be#F
50dd826f883ca6e83a5520159702919e8640813f0006c32d9ce6531b4f92818b

ee:V+rF
511a7fcece3cd644106c80e487095e7d8ab9fa20dc09168c489f175eb63f9636F
511bc16b7002a23d4c2365e7a369074e23ce6ac569f14b967ca4c8b20d29400a1F
51252d279ae23e76f0eab56a60f8b34948a2cb91859a5ebcb4dd70f5b140ade0F
514e7d973b405b3d0028fc7df9e3b46ac3dbc49e864417967dad13ed6c1a344dF
51531084503ccca2963d7cdc52e607efbbce02b1e36cb9bf5e983279ba6341b1F
516201be4c2a553028eb1f983417912a1b05f800b8989fcd30a55f89623a57b6F
5171be56dca06ca1e7da429b0b918c643f00522f432cfaa4d67aeea0ee796306F
517ba6cf72ceb45dad798a989a8d5555073598c3fdb08328ca70ce3270d794ecF
518082fd34ea1c14e44917a04af17aa6e3307369f369dbe369f0fdf4e5b8e1eaWF
518634909b8077578379878100a6cc50c82ef6ffa0726ef538f628609f07e436eF
518a5be8d1eae8953da4a54a8b852ce6fdf3a22ed2fd22c5b4db85cd4174a5f5F
518ebaac264e510836e723892b0b9982787bf6b242d9843e5ab09ecc5c9f642a#F
51a15a1f28637adcdf2f0d13e8d6a81017809612ab5a6a46dda8025be6f4aeec
1M1|]>jMF
51a53d551be2e1872620790737f76e64debc40419b8fd39d769e922deee5e6cf.MF
5259da8d02da50b7fa77e6a85337bd5b220b5a2f13fdffdf6bf2245e630017c8RMF
533e33c4dc57038b0d5c6ee8639e010a745908371d1295b11c0afcfbabbf8231MF
53cf10100297e3ee9624975cc473fc78d64bd6ad2a0106e1e5fd695e76c2ce9cMF
545b84aca9e92f936ab9998e50b8f869519ed25a9b0ab3b228ca86046f34160eMF
54b72bac2daf97a8d1ba79e4288be55712b5b35027f2df547f3e0af93bd9b6a5MF
555f9e2c01c86b0dd1946344981074918e29ef0848b6ac14772ed9fef57c2115MF
55ad97e23070c92807ae6019da970533404496ea9c55b2581bb34f2be3b54cd0MF
564ac561fd3290312c3e833edb5ea883a24d202539893cdb0482247a743750b5MF
56ca48ac0b31c1895271b0c78a7c6fd5045f217634b908660f5d61925af71252MF
573a2c4f5486b06a893fb7f1e7a97a45c7fe7c28b4314f367ca8116a785809babMF
5800fe1251af68096a15f87c737c6bb60eea189076391a14cee6c95f32fdb304ZMF
58bf74631393f9fcc43410a3e2bed3cad154da2aa6ea87017696651917d10727B

ee:V+rF
51af7b29f1554b6ee4cfc1be4f18e91dcb17d8795d87ad960cb26d3fe381cc64F
51baa210ba3ca7c7a874db3fb24682d5b524662f17895952c53f472c0c1d4c45CF
51bd5d48aea076879005b6bb6ecd6f14aa7212f61f98a0ad49b0b9379badb17a+F
51c06da7ce2ef116cd43474b64056e939ccb0ae0e6198dd907ee842fdc5005b9GF
51c0c235f8ee720c1949dd34f66d66bf7f5b50fe1c37d366fe724ce644b3bee5F
51eac9ff71e53c4175eb210efa8bffca4476cc9cd86104293d1ca7f714062a4eF
51f9017134f88118879ffbdb248450e3b3d9099bcd70dd6c20b9044df41ebaad
#F
51fbacc2e26050a7772549f1fe16c46bd8063ea187825ad89b237c34fa9b4250F
51fbcbb6ee3318561a41b9335488c8645ebf76f62edb08fa951189b31ce14afdF
523d10d80eca952ef1884acfb524e844fed7f5ba15040c03fb8bfd7e54beaed3
F
524031feb4b382103cd67a6e7a15219524577b7af9ecf3f8b7e5ca443bb043aa)F
52427e37a69f9019c71338e82cb47b4093f49f6cbe7aaf6c7472b6ece216b3bd	OF
524cdd869b6f342223fb2289ff3e3ebaa8408bf57bbd257d0349efe0946b9dbd

ff;V+rF
5264ebb9f634f3266ba74ef377d0db45c52877826efb225687b1430a60c824fbF
5268af6fbc32bf7411d9d0df3379c86428de9b0d25cbcbd8a6f1703caac79829~F
5272882f683e83a910d603b0d6b4d2bb3031f9b793b125f6df3208740a29d2adRF
5272f52e8e18d2702e48f4c1ff860fc6d052acf1543d9556f54efa55bbe31535F
527d093e43a30a0f0ec3101a8926eeba2b14e4496c495e70a1d5a3ceca45adbdF
528d0642b5b6549b3084ad519bbeef6aa4048aa69d52903acce6a22132ac9303	E
528e29a03538329527c3f4082c917cb49d0bf14f6f4b401f793a6ea83f3413952F
529b379f29069f8d8015829e0ce51b950cdfd5764b3d2de634462f2f45957b29F
52d1677bb4b0b6cf9d2e5dcd4c9cb2e58dee114d048654302dd20d27a8d31eceF
52e08c5707423c423c562574e04e5f1da46c6b67f3ef38f30e4725f991a49a12F
52f37df997426edd5eb1185b3069bb6f0cbf59be802e98607beb40e5a32434f3F
52fc84afa30b500c79c2116a67a199c3eba6bbed1b7b171fc4fec483dc2c9f4c	F
530c5e0227cf705a60da80a809db414020ef88b26923ed6828fe285d4f1b5e18b

gg<X,rF
5343570a081f4c1fbce42a13f928cc48ab03be8c1c68a418094e37927e1b78d5VF
53452ad31f9655e8f71a0b4c49b118b9337855433c50f25a9f5a75b92ebb8a8a	kF
534afd073131ca7dea6b8cf23565728f280489bcc5783d53e1fc4f3e92bef942F
53566f9e1bd64ce95963cf88dab607767e896835057ff6634b9a8518b3310365F
53777bef4b884ec988d12664f72eaadc76fa2b24890080c6649e74f9c9769d94F
53785b577694f90da1cd6542ee6cd7b90b33ac6f11db3ae5b38c3a417ea82085F
537d165748ea34474b3c9f20b83e298df8f9c60a97f43737c751dec828963330NF
537f6ca06c1c64b8b443ddea71e5ed3c2e491cdc767579a7e3a42473aced25b0F
5380ad090ba99c100379b2fc1cf54a62f85cdfe390b04b6e5e0fe4c213aa4661_E
53bef7d8f496ce93d095af2f28cf9ea690f7d61117266073c87080d1457a56e3E
53cb4b1814b006d5822769285fafe984c2312ad59f2a1efd65a648bf4d1f6df1fF
53cc61153b028eb77eee99eb4b318593a92007ff036a6f6a823411e1ac986690
$F
53ce8c9651b597aaf7b719c2d54b58fe264c394bd216587abb5e3c9981502c35

ee:V+rF
53d8438b425a4358f4349cb5b43de3ceb51d10df527995c1c37a7d1598e8e8eeF
53dc295cff436bce362e2f1ff515b0cf2e97a55b54554ce10fcc04a18e480028F
53dc9de016bb6fc2c1a005c20044580f8d5de2f99f77df7527b054e08cb02e1e>F
53dcd4410dcf2e10fbcb28e2ca530d42ca4402dc531e3e719f798111531560f9LF
53ebea1b387c7333eb49334b5bf8e867d5307742f502d7d40091abe8eb42387b
[F
53f19e6a64582f844301bdf853863da54891f234bc44dc77426164612697903dF
53f42f617e8184218d75676860dfcd10bd810905d61d6d241b88ff372c208b42F
540ad2675ab792c4e347811b9c59c9dfa46be5932ed582b6b0748c7a27660973
{F
54284e0ce96588259af1165cabdb431f59b260e11eaa00817d54fe6be8d00a8chF
542aab85e68ca0ec1ae3084cd0af6195d78adc16d93c4be11b237a264eedb1bcLF
542eec90efcf10ac7a2c505eed834595826e5ac255df60ccfed65594368d644c*F
5435c138b53b3d77c61b682fd1142b6ebad9946a7aafbb1f722f6f9a4896a265}F
544b35d1b0c600d66cc166c5f116fe849ac376a65105997c84d89296afb22861

ff;V+rF
5463798db8055d74e5cb4403c06751d747572157fa2188e01c3f8cb37e714148F
5471f87193fdfe4646e6c6f388c9c498da8ede8ccdcade0353ee7503e8299e9c\F
5473bf46793bafa1cf84c7ae24ecb341d287d12494cbea04a1fd46c81fd5c2c8^F
5475ede3cff8776a20cbf47c4b3c85074267733ee7b25756385442d60aa680c8
E
54773bd4792a30ed2a90d50d65778c4d34f672bedec6da03981162ca13109417KF
547b0510681fd163f611bd36836750eb87f43894c5f7c7b2578765bbcce090bd0F
547e7d5fe595fcb6ed9634585475a0cdf56327add42e4ccd74358d8c4a27b140KF
548503fcc3f2803339a5af3de411713359e79ca6ca3db7aa4c0e221102c86c86F
54904b5dad92e58cb221e767835398cc72621bab301b2d3964a854595d9e6d60F
5490d928d2dc55d285caa5eaf9606be884605bf43d81604819679bc307219d29lF
5496c1582c68c5314603d320dbb44e5435532564f1a4c6068e8040f2767a1797]F
549ed9d000ddff74758b2c4266ac73c915179f78808cb685c1812d5cbe4d3c36F
54ab243faa67657b5614c4deb2cdc3ed777723a654a2faa316fcbea81f89ea3a

ee:V+rF
54bf6ecd682245bc83076c67fa21c5c7db62c883a50972dc40dbfeda8a121125F
54c6e6aa53fe175c25dc35fe3f6476d9b195d85a4fc5e64d5625d1731cc5b1ceF
54ccdc7cf35a5a397da2776db1e3698403ddd8b7aaa89e9bd1156f4f0b376933
qF
54d67315041544440edcdc1a784b786f749cce152edd23d3ed953826b64a5b3bLF
551d2065c265d1e53d4bec46b49874d3aff2ccc0e5b50f98b64fb49c31c77700MF
552aefa94572e48c27a350e1ef2936db101b0d78eba2ef8d8369a651e1bbd1dfF
552d8f1a349abd352ed882be0cfbe9423589f98f6621627e58afa84d6c83599dF
5530c892f1f2952996a03043005582fd05142b2402c3d3ba2d871149e6f6b902F
553cb086c6ccc5df943b00d1342272a201f6f00d3833176eb02708135da3101e;F
5544075a70cc259a73eb5555c11efef72bbad8385da2d376a511efce351ff5df
]F
55556c4993ccacf2204ccfa733c8e105f1bc1cd4accc50b36960aa8c6a339aea
uF
555b9b32b3933d547da1546861b8ba783cebcece9d878cb604bcea85de993e1eF
555f6ee454fa312fb09d6fafbe3c2aa2f876b4599c73856eff9aa4d9f1b2f06cb

ee:V+rF
5562431c48cab67aa1da614c3d19c3f6becfbc386d29c7133f40bcd4ec21c3dcF
556772de85dcdb8d7bf429e3cca280e03ffdcdd1ee99bff14fef8b64b6c102a5IF
5573691deaca712e1478b3d889fe322be138680d8955a04b75e3a0066e099ca2
F
5578da34b6bdd59f584a7e2baf29876c99b00d2684ede1967f37ca2d95b787a3;F
557caeee2f6ed8008504fde4f489a621524ac25488986c4d163e7ea8b153e0c3F
557d4fb63564285a746012864ee4fa67be9d0f1756df5771b7f9380de46393c5vF
558dc0f83e3862c9b965afa5b391a230262f95f6a63563d97c9110ca4deccd16`F
55921bf220651db8e53c670393336486760efc2eb102ac7de7bc83f6731698f6F
5597c86554e7f88c701acbd24766aa87c93c449673c10e38cbd74b8bbf5e84faF
559d3f3c580f94eb5e25df5db277b1e4076d0d1911bd304941680178b21d9e5fF
55a15d25343aa48f6f67cbbb7365207f4430960b97fe22eea6521df9ef5f6e1eF
55a90d093b44adee52d01531fa0e512335d53d71c5d5b988d4bc903982900cd6F
55a9b8612201e7db7b7823d8075e79401bb12973850ce1975a877189671c59f7i

ee:V+rF
55b8fbe53a3211935d82bafb555f9585fbe02d4aad743ea7bfe9b68c31fff322F
55baaa197af05067cb206423655392e7b0a52e3ee9144a1fde30de40eb599d5a1F
55be553fdb6b711c94e1f41369abf744fab2d8d3938dc7af09ee75d2249c22d5F
55c1b8836656a45aac1437e8175add10dff725b5c7b26b850730b4562282349cF
55db8fa1e758d5038aa9f74ed8982f1b73505b989a9643ef81f8b704f975fb8cBF
55e13fc8624f8a63b785b5194281c38a4670f03113b0ff2b8fc1df1ca473e1e8F
55e1830d8be44d9b010552a3d903913d14a27e26eafcd4cfb45fd3106ce59c32F
55f08ad739819e709de85f5c4527291e0f16eaae36d650b0616bbe2b34dda6cdzF
562577dc40b07d4f6bfc5f0a837b2a0772968b369b1e30f1b6c11338772ecc1aF
562d2ea97d59915b01db3a45495b50c8986b34604a13ff652057a9548b0b8c30F
56345477656cfcf05709f7ed9a7e36814bd7eda39a49f2d5fc436d774aef8e06hF
563fbcd370477439a58af9940298f2c82a2b3a37e487abffaa7f2cc6dc359b31	F
5640bc5d7f5bdc1cba31958835239b6e304ee9faabd531c630f74e9e6867e32b'

ee:V+rF
564e997b9c790bd2ccb1bc895a8ace373c5af426e771063ebc24eb3ac892b979aF
564f2d36422f90238f6c163afa40b0bd03b7f8ed4505e447cc0161f41b6507d5	F
565a99b9e94164785e21e6c316bc072e35df5c03df3267601461e2b96157b0f9IF
566646f7e600ab8480640215904fa6db201c8d068ab3d6f8b7e348bf1ad1fd34F
56771785cffde9bcf2a1b33447024e6a12a3805c64a69be7e940a45fda1e2824F
56773da33ba948469db1f7ab9d9bc267d2e29b3458b2d1376573c09525ad4581
F
569c3afb20ee7aa02a316df5870c65b53bb314376059e9e761ab3e81622b3891$F
569c75b83fb8869babbff7da458924e4ef2a3cceabd9c1e5b1274d1d95ca521cF
56a814e3eeaf048c77ba188904c435aeaea3d62cc3a5cb3e815e9921e1d60166F
56b0e8da36b334813521cd572d937eb75a589047d4c9a956b630d239792bf4e6F
56b6f928a45667b9da2599adf7728717580afc5e3ce24bbe5dfa41d4e9881447F
56bf7e797eed9d37f2dce5d87422a5e569612928a7a5e9eebbca059550ad9245F
56c9932aa2318a64e391b3f64c794e77737aeacd923b2b7d8e02b450cd58abd2
|

ff;W+rF
56cdf3051f5fd87ff809ab1843192abe235c6093bc0a83213f73bb7ebe2a0f2aF
56e522d6f6a849ac7522778022a72719f7d1b252990db7cf3bed6b06f753b096=F
56ec7e50303f9b981bec76c83f17fd6d6eaafaf4b44ba798d7dd4592b9c6663dF
56f07c39bdea546bc3f3eb930711eb7562fbf0cd8fbcbd9f5e3f7fae8dbf2013F
56f09419cecb436d408500ec34950196ee1969ca1d67a1140bc4453bdc7db16dF
56f9a2f564549616cc842c446f06bff9820333e8cf00b5f21132bfd6597f6be2EF
56fdfe56e71473fc17bdd4e12e6ff4713e56fd02c7595517593f0cabc98308f9F
57060ad1d840d5c5b714fe83a3d14486758cf9d186bea54eeb40b00a53427f02
F
570aef75009a72d1f785eeeb0cf1e9b1c5113c73c46a3a7c2eebe0f87a44655btE
572d9ccefce27e99905ba8c221c2216b7ba572949a397e457aeaf3e65ce8b4e4RF
572ff1fa3f621ad26e4183404533f0d373eee24c0a12955ab2ab39ca102d691e	F
5732a4798be4c87badb456e95d85a69fdcc47d79f536cdf10bf8bfe8ac5353ab3F
5734c3f66c0d576c4dd6f560daf55c682f147e046ce312efb7cf7c0428164ede

ee:V+rF
573cc1166190452dbe3b43b1be7bef29a1ffa0ed9f8dbfd29b063674c60834d3F
57519dda2c881614316fc810027c0c66b31bab6e5e16dcd0d91cf84b6d63fc3a
fF
575a71de43d9ee448ec1678d6e6396b7c3cc5de05454e3681e5a3f900c5dc4bc#F
575e728d855d72fba88b860be7518db2c8fa0dc1add9046074dd5d320e1156bbF
576b6cc00210001f9cced4b7f0a9cce611a7ec4e4294bb24f514f685685d994d
F
577c5f15aa7fe917fc8073ef1e9b96c46ff667b05714023b580aa56ba79395cbF
577ce44c27214c84f76d58a38be32a4a5f165af65c0e77afa334270e98b8008dF
5784610bb7a7b03cfd4ed995bd2f9d4785cdbc6dd40713274e6f1ae158558f20F
5789e9eefcb8257802229f6c4a0c33ffeebca3524e72f87f7094d6126e171b3fF
57975bf3b85630da395b3a5f46aa15caed57803b4508f1391c84aeb4ba95541a9F
579a8660d11a9685cd885b48ee54281757a07a1f578e4d25da3e9a0fe38a378dF
57cd2f70db38f1fa93cd1038f8b78c691635c9ffc591f01d4c77aef6482048e5F
57e3a74cb68c72426ee6a022b286950bbc4ac0c0a450be5d5e07d0a0ac91fcc0

ee:V+rF
580edd83e305e9b58fb0cceca959a21a8c59ccd3bc075f075211019108f73863F
580eedc42430dabee13298aaafa5f6d0828a7c8ee03e48cc34e248044b273c98F
5830fa7abe16fd9ef562c14318f17462eb9ebe4e2473b4b94827dab6efc8cb5b6F
5858767f54c2120e5d407542c3960c0bcdbe0ac20b7db144d540566f95fa03eeF
586962e501bdd67c2893b8019c9cdcd07d6767b123c3fe8e93e64e94439c832bF
587553122ef589c1cf5063202b40fd092f24f3f9b50a3d38f3deb36d00ed7d2c|F
58790e773666a310f1c4417f46de1fb127437bce225ed0d9cbf6b4a08054ae98F
587d17ef9061cf41b72bf1d3a0c8b1ef5bd5fd3f8fcb45fcc0b4af9023587f45mF
589706b3e3179980b4ac5c2328bf6ff3d88a995174ce4fa64d0ad480965e67c2rF
589b285340071ac5a04d6fc61453fbc9ef5c7d6c4d24c934c944d51787ae5966"F
58a27b52c09a126948ce6287661318459d3416d0cd51071d3b438cd6b8b6f5easF
58a5f6025a63f07b9dc9793ec13c58029a3502315d1bb29d4c7015091c9e8dbeF
58b23e3f8226650315902eba6ab9e2d2a81f816aa85d12cebf74af56a8504c16

ee:V+rF
58d55e76b88d088f5d397d7b1d908c6ffc3f06ec1ee82d97c1383fb167104aabF
58d8a7b6d0fdb9777df76fd29a92c1c249ab8fe602e217d454e4b89dd8a82452'F
58dcbc8296bbbf5a241618ee45e73e4be9870a429bfea9339cb245b68523f7abF
58dd6ecca9f9c38c402d46c56efacaf2a8739de21c64f22dfb3f9887f2de6c94F
58e972759347ee479f41461c94e8a34221731d3f5e4a517f3472362a853548e8F
58f0137ac65f40eaa3ff281ba91bb68d78f71041a8ab7a9d08578d3ba06cc792?F
58f7cbee25a91080d46dc3966e5de2b34323527c46cc8b78385b95e36bfd5b1f{F
58f957357894f41ea8dce27b4768e570d26ebe184ba29202236806ebd3286af2F
58fb7f4dacffd07cdbe657ec86f4af0d40760828a968dd894a92ea0fc7028255F
591c8ad60cbb62f0c95441ec820072142ae5392cedd248fc81f71eb1d8a699fbF
59270b3d96c02888cb8fd34bca5e596de497c24051804658439170f2d9e36fdawF
592f30134c5a086d2102c5e64047ef6d7c337e0cc5d5350cc6f763992cdde4a1
F
59316b28cf9e6cac60f1962177c09c08777c01cdecf6df02042c2f6d1ec3b15e

ee:V+rF
593add2cc79905baeb70c882cdcad64327b85acb067b1c40ed26d9b81428f98fF
593df90370183706f3bc69451b1aa4c6cd88b0a4d1d3964bc1b8e621b3d67d97|F
5941cfa3708aa1d7eae457e8f0abc55a55d5a84eadb56473770f0a82215aa495F
594bfd4b3bb5ccb47a34df5c0220769ae40a50c53152652adbcf1803d747d0f3F
594dfccfe823bf2e7b0b092a49e9599e40606708a101de2e67c467258d6fd21eF
59502bb5d4a7b0894afa700c66752b3529c815f645f28c3b1c2b321d7ddd2629
F
5950600c8fad63a2225e6de0a7ee94e2ae7e8d5131aa6b799923c80580f5f7d5YF
596130fb4480b497134f1ceee905500a7718c15559963c2786a784a511011077TF
596e62671849cfd110b4ac4c57b171fec5bb07301be496f20b9b86d591947ebeF
597a98034f38019a6ec047dd5674188fbb428a55fadfca294b210b303125fa02>F
5989f8701c6fe912d154675a3f7ad276f5dccc5afc8ccce28405408ee673c16clF
598f5c1de287046f5cbd57cfaf3cc1d9daa8acbbcfe94363eda1070339b435a8F
598ff4789a5b089a81ead99e67555f293c41e08b2771cb5d1eb4868f669d0894
1M1|]>jMF
59a052cd2596a592fc02e8e794d976aa238ae34da00d247445d0f51bb9e87bccMF
5a42bda7621305ca3bcd588a0c84aac743aba372ea8ee558945564b62173e3f3MF
5acff1ca859e33437e5bba88b3f8e1335360828b81bf51c413327aa84347242d
MF
5b93e870e57b80682109021a45ee40d59a50ca460b054a2fdff648fe118c7ec0DMF
5c04fbcd46e3e025d84e9e8ddf45f002a83926d8117b74d5e0012aa43c934978MF
5c6e935d06978bc962ba371367424881edecc7735e2833f96a64554589179077:MF
5ce2a0af968d496cf93f82d5106b30e2f55b8df48349636d27dfb49c14f8905b:MF
5d59acc61e4c24682f9a5b9b41b1c5f8974de87c4a1fb4e029e9131a51888c38
MF
5df62ba637b7f77964da2d97a25f63cdec28f90a8dfa76b05a4080f7aa03b3a2MF
5ea1964ea7cdad4c1675afa57a96c5cca4a574eb022294b1d38ddcc08e6c6b3dMF
5f4ca284587783143968fcdf3917477a4d6a68b7e9106aa1c96b92591e63a261)MF
5fe799d217f2dcf27b8e40b81b8417542ff242f26f79a7436f2f1834b7ed2461MF
6085603dfc592d80718a8fb07a369da5c47fe019535a490c02e8e0eeac89b9c2

ee:V+rF
59b2eac344b965618bc03745e27bb5c92278b9fa7c3a6327c3f89fdda6289a54F
59c284ae5662792cf83c5c6b3c1f1a903d45dae94e28667259f016a7aec17a9fF
59c66abe57e107fb07bfa33cca0326a2a7dfae6183e42d0d806de55598f76776LF
59f3e6ecf2f05648af5bd7cf1479e1cb010929f1310143f5e007725c4773c36cF
5a07757ffcab76dc74eef1e1537c4ea823f723bae2c05ab1dd29679d95478db1}F
5a07e58d6cda56dbd47d3a94fc14aba56df74cd39ba554ead4b6dee97ef05e5bF
5a103d4f3b121195638cf61cb91fbc034b9c2a6deee845296612dfb590ef0859	F
5a11f15beb55665259230a77f5624af4b896062e2a61b610d31d355500431f88F
5a169173d476ff530595d0ae6b03d7f7fba5bf999d95a008a477896efb71218d4F
5a1a14cf6500d688cfc898ef4ad3cdca51ca829da10e098f412a9a7c63ce86a6F
5a34d2e48c7b78b23d4ae6c9697fa3094d3e9bc3dfdb7d09f1670206a32b7e46F
5a4016edab2fb96b11729042f640f939d31bdd1eea435240f269d9ece5ab72d1F
5a404e4d0261a2aa45188a169969665640124c8587bfaff7eaa4706a5f16727d

ee:V+rF
5a559d47a300848514e0aa63937e0ec7ba4d9c80c12f1947a494d7511dac89dcF
5a64f67b760664231aa056ce36899a472656f882e163cec3ee2c913fe4b34140NF
5a66d5d5dc478ed425ac3150ca54707625780a2e26284391fb1ebfb7924f88e9F
5a74a6ec4e7d6d8944913ada4270edb09c6f3b75a0b4caba77d076c07bc64964FF
5a75bd391a4b8675246d8051d4d1a0e28e7ba932456d922c9e6dfe78320bf4ddF
5a78d8d35284262a7fc70c262cad28716a7f9f4557e122fef43cf18904efeec0F
5a7cdc99b9d090c26ee5c769f9c02bcc2598cf3c5ebb4b9e0d041e33a5f8334ciF
5a7f183ea8444e1f7ef2ca3b7c8339565f6b19fb23f0968b9b3171b2d50a64ddF
5a97b7da594519145c772a191ec16781f3e65f7befa1cb1697ae9bae09c6be3eF
5aa6c18760291c5e22fa5fd2f7960f92c9547071b62e9766ae30bbe111f5e714.F
5ab1da2e283d1df09cccde7a8681441b9f5b20a027b34d367ff19dda331235d5.F
5ab6cab7d848d0f73216a7e9da6f5e67da62be1a0f2777afc4314eabbcd350fdF
5acc0609a41df6553c86c09d5b59189c6442930ac603ef8674a29954ae4a3fd3

ee:V+rF
5af10f82c939cf1b8c13d3064e3ddfe2de4add71af9db95263ae64050efcaef3F
5af6b82a47585513d5a6a8ccc974d524ebc2a67fba642652aa75b566045b004c3F
5b0b31c3c4aa723f9a677d0ccaea58da6ec37710d6177cb930b490c716240bf8F
5b152b26c3cb00751f5faf6a0e5bf8cffab7cb953c9a7a44d5c064beadb2c64b	F
5b19e42e03ab5ffdc24e71ec6c71dd0d4c8a557e482b142cb58bd7eaf529174aF
5b2d852e11af1f062bd27d2ec053f7544ae75e75c9c69a0eba94e287ef60f044F
5b66719aa307b84457c7ac3edc58f4b71cc65248e0ef006e5fee0c3e52896b5fF
5b68af3481bd9ec99e96979c742095c04ad5a420aca88d0278499ae1949f56d7F
5b750b8f5db8f4ebe68335063aeb85fc0c687063ea49ab0c7ba1275baf6245c9
F
5b75d2143ffe291c5183924ee30ab08ceb34c6da47f540b55f39025c5123e419	F
5b81f0de16b9e09141c5ea31f902a18f54277c2e168b86007146e71b8f29b163%F
5b8e30bc61877d67eb0781546eda037e3125af2d61226ff947eae46d951dea87F
5b90034629bafae7fc40e3688bcd096834f9ce5de48a7f47ccb507c4f1c06c93t

ee:V+rF
5b9aa9d2efdec945a27722458f45fc65a0105bf5378594552fe8bc991a4e86e1
F
5b9c35a49f05bdae1d6d9ae13688adb2f1aa9eed15604ea80e3126af3ad89c77GF
5ba93bb7af0fa5612cec66a27e5736fb8c5460ccfc0e32ff2e9e8c97c2587a3fF
5bae0cc126abb5ec4f6861872ef8dca8ae25c3d7c3bc9d186d3450e8e5f8cb469F
5bba5c2f7eb1e8689b410449cc9ad15917af4897477ab8f44972e6e8c0298324
5F
5bc7e489f2286aea26973b124918a70b6f8f29e9936508ee68e5fa89b453002bF
5bc9838767e0c9e764e7008304015cb982d5e4e37860284948034ef17d6c3b41lF
5bd8a5d4bcf1a29dfa914ba710c6486f4e0c90ef8486e5e85044a7488b9ec75eyF
5bea05b28dab5f6e5c851855e06049b7d5dcb569c591a728efd7ea42b4a9ac8e	F
5bee4fc25b489a427e91f9972dc2c6116c2159fb420fda53da7e793376b51ff1F
5bf6acef9988011be2fdcbfe74a0c08dafb93852b5728854c765bf5d29f344b1xF
5bf6f0344add69eb5397aa58808fbb3f7473db3d8ebc8a33268d40b93fcfe0cc
F
5bf7fa347b641deaa5b1dd5752635a5a43ee644e71cca2e924839f74490cf862

ee:V+rF
5c0a4fb7b658b9dca77b858ff98bd534bbc056c94aa438b11b253b1da80720a4F
5c0bed31f5ed7d1cccaeb6276746900d9f0fe837b806759153ea696c3b33b423,F
5c171ad6a96c5f3feec12d0ec56fecf45cb0e8859deeb78966c227cc21a25217F
5c264476a12da876822ba10518576ea9ba06566847192d58c4642df8ad70f0deF
5c3a51f2cd800bc1eb63007add93f02cb14e4acbe93b537fa3fb5d1a05f91ceaF
5c3bcfc599ddd884790cbf5e2d8043339f4cd5b91ad9595afa0db6b779424c22
pF
5c3e30fe5f331dff8d929397fe55cd6da4c97325fd1c26f6c51b2567a15414e5JF
5c3f57ee8f26430a0967dbc9fb3d9d5fc2c5dd13b98177359cedcda6874b3799.F
5c42cdde11e5b38683d6da4d90fd10c1431b5c27c563bd4b7bdcf251800b7272WF
5c481b40303686e7be3e1c4fb48c29d0e1c8d41c8eec46b55771c7970af95954>F
5c48f63f55884ffae342bab8da56b7300ef3a1c678ca2fd3ed60b450b739c9d0xF
5c57f76aba32a986317ac294945a789bd49f7cd09491d4a66c8c259b336a13dbF
5c5cbbb79d474d8a08d41a7a9eab16454a6204f748c42ff97d2ca8776ea1fbc8	!

ee:V+rF
5c75d507373106773899d8f085ed0c9921518de33190dfac20ba2aa951e5b2c2
&F
5c8c85c382c8ac22f1c5330ee708bcb6604c6ac08bd86bb0cecc265c1123d786
iF
5ca0ccb7e4af7c807c1f99c10409892524195addd4cfc1d830e5cc351643409fF
5ca34c751582faa8c936ab6598cc2492a6b1853a7b3f019060e590b86e7b9ee3F
5ca5234e59243cc5ced75e11bc9ad434a82d86c5fa5eab71a130bd3c3ae49334F
5ca852164720791fe6e270a360e14b479b57e0fa1f71c93c1e582a9179353c61$F
5cadd6d1e44a896802e1df30ac84a484345f572bfaaa938544b43458dc6d80bdF
5cbb74a2688de09192fd42f0956329cbe2c77efa2ec5ed4d5dd90ffcdd07f898F
5cbbd37d7f37600583b60a26e2cd6b0287db9cbef15816447152aa601ab00a32F
5cc00750206f4e78afabfb9b056e174bae1ac30245373825f150d87b55a7c6ab%F
5cd33852a9e9061d05228552a9fa6fe6b3b0667fc738828b9df7e633dbe46bd5RF
5cdd011988bd5f786fd69bb2f85ee35ad72937f71784e3c1b95f7eaad14b4e71
F
5cdfe7f1d4c546122d7808d352018750bdf5bdc270398c9f41c3414349e3f861

gg<W,sF
5ceaceb75d9c3e12ea45d4a97b594b8085dcedb0037193817a44a30fe9ff98ad?F
5ced3b05c339804924a538a2b874f1a95cbe14eb2973fd4bdd808a14f095fb07F
5cf5d9d1af4c78ca14d14daa45c998d5f75484a3ab878d4a4e8caae845ff0c1dNF
5cf93be19fa91922ddc7ba9806b15e6fe9b422f89ed4b63465373a0a29b17e95
F
5d10762096ebcbd7efdc8eecb2d15ca2b35d49c6fbf417a3f85b555ac622eafcJE
5d1951ec0080791e7902a50f19ea2eab2f07b5ce3efea78f024eb1a197abfb77F
5d1ce4fa6ac4356078869027bcaf729140f2ad908b655471ba65eb396ac94887F
5d2375f20cc25e073efba76f4aeff505ebc4d30019f64ff6c16696cf30c075d2F
5d260748ee7254fcf65c3e3312e541e2f9883d21279926f45ee85ad44eb5b4e7aF
5d32bb64c9e38540fbd1eacb34c8a893d190ec02b8c21d9b8c07c84d9afbeea0cF
5d35f8e8e692daf8ad4f89ccba227841148704f4f1a52d100f8d5555f6e2c562F
5d4abbc89df8da961aa64935f5a986b89626f1f1e99a8728467557a6b761decfE
5d56166abb7686fc795b62a2d6600a144699caccdbc3ea53b082d1535c2834b0

ee:V+rF
5d5db220e9130b6d2c5d13730c7f90b5554b0201e7fbeb60cfed67b092ebed44F
5d5eaf30c36d5edff16d10d59883fcd24b4d915f4f6a332fd0a4498d47a9abe2F
5d6009ff10b81ed847436f4edd71eb726209b7ed8b9c98078577cd9ace844de0WF
5d6548300fb6f193fc969c4a7b833ac0ebc9a04231decb2ff8f853bf5fe358e0F
5d7e06887d90404f63aebfadc1d4b6b84280cfe7082d40d0288f3d973a586453F
5d92d36050c5d7174cd65358882ce23f7eab51af6a02070c42917f77f9dcb3feF
5dbc6a254bc8c77e947deecbb35eecf6dd6724e8271f52c60fabb83775d0653cF
5dc4485c972bd78d1637297056bbcc819f90e800c1681f449d5ab226d2b8772bLF
5dd078d9c34f67aacb48cc5f22103833d14b4bfa4bc86f6a4d5ba09de9cdbdcbF
5dd24758d5e830a0fbbb424ad112abfec1537db1194a06f3d33d97dbc8be9831F
5dd9606b0cc78d1b1b9d016a6fa1467882e158f9ff00e4781a33715ab0889212F
5df1a4e83ab5135939c23e1037e6d05b3b83a60b3b4a06fb6e85e91959657cbdpF
5df1c4a4149790ce8d3fed738d0a047014ad764f90ad0dcf2d4fb022afde1ac4

ee:V+rF
5dfc9505dc8c10ee2fa6b344d1a86a8ea57d43b15353225888d1f9888a840220dF
5dfcf8baeded2f96a2597b878a1006d7eb03d4d61927a000e1528dd9008b0671[F
5e128b028063e43ec93a59c4107b46344a43bc260f99578b7c4a2b788885cc7e7F
5e130e7019c26fc26493cc8b1c227f57d4451afda99fda03e0dac4bd46628980F
5e35c68daaac093d3beb1bdd57551b4b11d68962192494ead3ec78504bd924e9F
5e632ae289a07749557d914455977eb18c0451d2f3b06c6f4482d91ce046ec68F
5e65bcb053440eb744a0b29be0f36cc5c82a7fab303e26ad6ee2a714bfd4651cF
5e7c13e7ca9ceba3ee4769206f16397f62fe367684d347573b551f0ff2c8fd6d
F
5e7f113d0a50e93468c406b83d0079441feedc8fdc94a3867761526c5cf7b4adF
5e7fbcbc653f613c746c3e1bb2b62d8fcc19ac0cf1d92487882d5541de4284c0F
5e8f26bf2d3c10f7ca2d8567b9777801f602ea250b6d32ea056853058490c39cF
5e9fa6a9c3dc6c925f58ce3d112f48e8d7a89835f56c85fdfa648a880246ebccF
5ea154c824570a42b00ec0dd66ecba1eb3ba53a7d8875b374a32bfc093aea76f

ee:V+rF
5ea661034ba07766b55a6d64aeefb1af0d3e0e6608e4f50fca341a03abf1f701
F
5eaba3f50062813592c389ebb343e248af7f03caee550d7cab3599bd3e6847d4
F
5ec01f00815a52d61439e813a4a0958fc52c9c59500edb2e2fabac3c7fe068c8F
5ec120d1c66453ab1a85e5107b0b4457686f595cf2e8dfc5ca04adcec4f0ade0	F
5ec49c65245b5b4768c2ac475d313f22f92daa8114cbfc555c7189d5844f7b24nF
5ecc9b46e51b23acaedd89900ee220b11e9dfca92b98fe38fe0234b8ff1221424F
5ee8683f8c93ce6cd407d16531478f99660fed0dd9f582ce317a1aeb518e6484
F
5eee4ed6f4cdcbe1b9de452b76bc924f965eab492a06b0b7f5bb0bbb156d824fbF
5ef15604ff8baa8611a443eb38e948c0561633200d60d93d6ec70aafe375876eF
5ef7809b46025089f784a5c5eef97c5cb1c0ae4576bd7a05f04c657f2231d054F
5effb3b9f9c3b2e58564ce52ef1e7d855cc8030a6d8903d0d257eb9a2f166a73"F
5f044c5e59d547e3073ad6d5da425845c091f6e24a072716c7f61b3ecc5688b6F
5f3727aea86f6f83c8535492e9334015510770ed19b3f3a98ab88000dfa6b9e6

ff;W+rF
5f5b887dfc9f6ab8986542411f965a160cefec2bd50e34635046cb950eb7d93dF
5f5c399567e8888b62c997c08412e019f0c5ddf8dd28c78cfa0128928dcd853e)F
5f692d98607238270b572db3bdedd64d8b9eb468b0cc08cead1d6b23aae63718SF
5f7b92aac28013990bf6ff5dfda904b49259d332381f6fd3a71b635df396f7e1-F
5f7f4b24a0e71345d5407d27b3ec2dba93f549f3873d99c73c1a6b6d5527120bCF
5f884150b5350047089be49bfa331fcf0d8fbd783b21c01062b4f7a03626feca0F
5f9ffa10d0718dbd468c695dee255d77d9ba1a9b0d1b7e44a156806dcdca67a1
yE
5fa6b764fa4d36de1e4b14029d52584b86f65e0020290798aecbd853fb5b4ab5OF
5fb4e74677604f4bdb11376b47ccc1642147df00b0cd8d54f349ffc0749a8bf7rF
5fb69356881606ecd95f99c9d00d35c86e20c4e0489e6983a59445f286cf8d70eF
5fbc333de175a0adcac5bba533d0d772ecd8d8c92ec3a872c294bc9c25c7dae2CF
5fbeceddf0bf8f98be4ae1abfe85a15497949baa0f03eb2097d8bd245122c6ca5F
5fe18b0b420aaf810ed5edcf1e1fd4fa93b6639632315bdd9348ecd11d6dac60

ee:V+rF
5ff60c9fc8d59e0004f0a615c0b3b023014fe0ba062442fdf0449dd359e754b9
_F
600d4f94f14cc026544d704f5a8190f1e11d4020dcff350bfca31fef4c037731ZF
601f376aa7ef59f60e13ba11f0a9a7286b883a945173b5b829fe2e939b6b3d1e+F
602cbf2e2644ca8e5ce215838f087adf2ca12992b3040f73b33fa5d3c4c91610F
6032cf77d642b54e8e24ecb96c2f6ffad12f9b165c3bfdeefdcdb469f79f5f25F
6043225f18090a8529ea90341ff21d58fd2e2a85ee1c31af68145a7c070803c4F
604d0dced14a23f9e7eefa1abb0d32242d50b5ad9b6bc699114284e55ffc288fF
6055927e846079a3ce12f1dd26324dd574b3c9ee5586ac850d83353548a1f68cnF
60601627ced255e03b49d78f605f8c7726747b2eb27ab5531b5296d0afd1b2cezF
60639db656637bac71a8495c83b9cc351c89b200e836ed3343dfa6bca29e3956F
60647855ba6fb280673a3654ce82ab9610ce8bcdca3ea825ad3ea4023b200fdcAF
606cd78f5ca90a81ab3e934fbd5a9355ef4e5232694e0583575fe2c6144e00daF
607a56f5829235f4d97bd2c9135a74f23a25422c6eb8e64ad1a207404f8ce181

ee:V+rF
60b33a8a989840613908660e2204def7a4fe9b0d9cbcdf16e46b65bfc1c9bb2c#F
60c42c4261b381295acac9b8bad53e4d11b07aa44a6886d268acdf68415fb2e3$F
60e80bc431d4065eaaeb5d133dd160c01f64d7e9543d7cbfdc49c8799a6b079faF
60e92e4b5eccd578699334e15aeedbd39648619e8c4fcfdafec19e48fe080697F
60f10f4641f2dac4d689ad5b1ee25cc224768eadce58b7f0d64c3eecf32b94ffF
60f47d3d5a4d59ab230916a44b7ecff881116a21de176de5276bd96e52ac5c3eF
610253d61d946788184230adb18227e8e92b245a2c2244a5d929b1b096fe7faa	F
61151006ef84f2d4d9a7972cde6323a16d6ef02ce23105493ff8386ffb7d7708F
611d2e194ff61bd1597a7136c77b1cf881bf1473268ee08ccf54184adcc4da79F
6123edb3ca2fb4af89e0aafdcc06a518dc2adf261f69c5208d7e0dcf72996887
'F
612794ffa4ef73358d2f49bc1d041762afc275c2285eaf7eaee6f5e3c360d415F
61357d6eb9ca6e939f89412cfa01e3e26beeb6e28a3f90998db4cd5808430a6dF
614205bf0041e0a5d32d64bd0743218a5ed52c6dcd8e5880076d87abff2016b2

ee:V+rF
6151436b0cdfffbc9de946bc989ec92ce8de7794357a065c433e0c8dfd3e7fdbjF
6164453fc73f06d895ca8df581d46682883daa8322bdf6c511c25bd367caea15[F
6167999a4aa9b0b7fd775e20f7868e663374c2934e84072c1c95adbb617120f3
F
61679ab7934366aedce5be340b71089ee0a1460bac5c95cb884fc6059f1bb7a1<F
61772a9e48d677eb7feb9225da4fdbfa417f99764a26adf0ba4e311baad2696cF
617e115047b71db008189f9a914bce3674313e8fcd3e3ce40564fe69f65c44e1F
617fff79ce97ec5ee66c7f45cec546ea2429f9ce776263cf40a0b246665913e1
F
618179611cd44ba685db172d3afd1dc0248e66533a35b8e46cdf118d812340d30F
6182e47b9746410469ab21c90f69c924a80ceff0a394abd6a25a441e8d6cc49eF
618bc94e003b50654a567449109303c221bd56c7f188de529a8d1ab1d8e20fd8	F
61925baba4d4105a8e0a3e4da4f567f21fe8f341492cc4f0d809f774ead1a48bF
619978f4cd3319fc56335a010d227ac9446de3fe27758ad4f22319183b1a35bb	F
61a1892c950bfc4a208064a4e1d8a4d65876ca4891cc730ee2b045f0f37f7794
2M2}^?jMF
61a258f5eb7c2c013c4eeb36791fdc7dc8b813c04b4ae5b0d1a31faa435a58acMF
61ec12fb0832b09ad331cdf362aebd011e7d319697b112abc7430ee0ffc4bcdbMF
626a2e289d1c398ebfec878eca2a5a697890c2e6865f803db0f2579642b2b421MF
63037d9ff075fdac3127a74533eb74eaba6a3dd7a6b714768f44507fd8962d88;MF
63a16686d243cda459362fe273e2bf3e64a84899038415039c265f34388b8257MF
645b31999a5a9633d017660dd3029d098a23145a02bcc776967acb3d0414464c=MF
64beb126b2ee27d945966c6e8ed0eb93929053bfca0af0c12db4ed0a2219389cMF
6574b4b68f18c25488f8d81b6428bc0c2d58438c98a5e53c49f813717763e9ecmME
66236b68ae255104741eb03ff98c372f45d1070837fd9f390037488468b9dd1dMF
66c291b64d8ff006ef287fd920978e0b901b0947dfa61d8ee3b0f3f76f242480MF
67464059f8d9ef6bdaaabcff4bd255af5760b16b8ca9af7c4e194e78ab73d9e9eMF
6813b3fd706e79a0721cb26c926c2fdd57aaf1300c3f48cd8573cbf02eb06168MF
6862243c7d4e91bdc68839fc5b50b2fe2d9be11cdc30df983b8506abd9bd00ab

ee:V+rF
61a3387e568e2d46dba9932a1b959d8cdcdc17e7ba5ba6162d1085700bca40bfF
61a8eaa6a0f98be8585a74fd7663aa37fdb6f542080f0ee3e6b96844e82564a5AF
61afac8f37a4ea3ff4615ff2c44e669f884f9d092a45699fc0fd2dcac09465d8uF
61b97c3a1622caf467be58d602a85f34f16db6320e94c9d471b9ef874ce61982F
61c74a7c104da9dbf65e04e0cc9a97adda225fc72f10000914e503e0bae407abVF
61c886355da15df816e8e94fb32990af3d0e4c89549b100c128c54b438924eb7OF
61ce4b03660d33874c07cc8931ddbfe63af33129c020331fef0850ec847167e3F
61cfa80ff521cdee2ca184780c2e8e55454cba77894c18944b233eb145b6c262	F
61d16044997c74e9f5ddf1cdc61b0e3f9e8d5e4575baf1378072e0338439530bF
61d2fe31693bd543dd103cf15e107e060b04ebfad13d914865e704aef9a7bfbcF
61dc6bb4a8a0afa5abfca5dbd6cc89799609dd46cb583de0e51dde496c7b2a305F
61e6d58d8d1b2b2be1f5bb1731c99cf450b81b29303d4f3e1c8772d9b04d2bbdF
61eb1f5291daee31b9568e4897e13e2fa0260d850c62490f336ee5f55b31703b1

ee:V+rF
61ec99762a4cb0f13335876298ef0c38a6f690949282991213f5505233899d63AF
61f2ce61f188dc44b4bac40752a37aceb51e5ab3ad31e9832585553728f1153a
F
61f3ebaaeea6b7aa7f2cb2e4e49d7030e15a0242954617931c4ca2d74e49c807
F
61f9945c76bfd6399739a4cfc42c3e9b350ca70cec8aab0875d6618d3f45ceceF
61f9f61c18480f59ddd7ef3382cbad48896469ac9da6dcfe2e3ddd8195e737d0F
620e6945f7639eacc1508005775c37d66e64ae3f5ec915e87d132a17a45d3999F
621d13e7c135311f66ed8669c828821fa8da5c7b602afb4066d01bcdddf43bc3F
622141e5636c218b10a59ecdbd66106cdad2a25b673f891edc0d4b61ac7965f8F
623f1a82453fc1bd44617826a88974cd43fbbb30a2d72e47bd706b0deb895254CF
6251257e2c5253fdfcba671ae6cb37b06e73d7cd02051442ae5fe2d66a63df83JF
62597c6811ab1a4372c93868c223a056ac2947a911f6b318ab3df4ead1b06de3_F
625bcfa68a8612af0baa8859f0b08904bf96f2b85129d8b178500dc33ae0d9b1F
6263d570ddf0f6cf0247a3e7266a7aa7caae795462727dbb4d747261bc4aa1be

ff;W,rF
62730a490f70fb743015316019c09c1992ef54947750f054eaaf08ff9a387163BF
6277ccdddce2fa5ee1ecc12615c107ef3a280e1716b89c5bb60d515fecf84416|F
627873cfe317368f11a034089c743611ad85c7f5985f6c68ca714c1b0329eec3F
6288171549b2c71602c97035ef0f1d087455361c00d42948b460d82d0c0c4387F
62bf471ba14072212be41f68548e536d8a022b8fffa4c7fdf94b4dc26c4d7d3aF
62ccf282c2df0d4b0fb164fedda7d42b0e9be1966f8da03fdcebfb08cf4e5456F
62db43a91b2c1f3cd0407729f5c13f51ea098fea0aa9b90e2444d92166d1817d	F
62dcb9c05fcad8a7e7f0588dcf5a7500f9fb5e4b2cf0250f64430bd3a95b42f8F
62e79c444efc16b710b9f1e149bb3fee5abb2dea036b57e363ce6cc8d48b4c6dF
62ee7eed9057a933f386601510a2ee1dbe6cee295c00a4e75c1d5ca32a0e17cdE
62f87a828471cada41da0e65515893c663ffb4843c97b49a68ce916292d1f8b2dF
62f9c2b74b51bf8854ad9eb25a2929d8ce7ccc484972923e91b52d1a2e026a77F
62fb9bed135072100886d8af661320bffe7159a6a42c55a6edc43a35171437d3'

ee:V+rF
6323899c2cf49904753b9b4050225498b3bce1cc5ae2893977e1201c90220e64
F
6334cfed646e36032d28600310824098963bf8c4a3d59a3dffaafae4184e1d56F
6335456bae4a6531a1e5a588c09b5fa47d70ef61f6374951aca147a452b4eb029F
6337008a1e944b28b17317dcde8003b1ccb848dc5a09a17a27903c4e32e60846+F
6341f007df657335759aa49bd308613667e9481106e29eff6fe1a74abfc9200aF
63558d42575ae3f93c0f05594402264ff08a7344fbea29b0340f75e051de0cf2F
637c8c01ec07ac21fcb709f52f870af6526eaa83bd2915683f8a6f983072e500F
637d3a56cc4d58c44384c03a0e5fd138ce60d2aafd7d584dd7f66e53cbeb3049qF
6384423635a67bb9f927be241ed3f67b1e101743ff36d4f239fdca3de98d1474F
6388020c7ae6967173c10e44d5542309498d0c339891675e68467cdd71ec93bfnF
6389f5f5c812cb020dd4bcf4dc948be8137ffef92ecbea10a81268530ca43c7bF
639a97b21ae7b51141fd76f2777d2f3ea1bd758549e53130764657fafe2daf7aZF
639be57d983a29004b74a7f3b753de3e62c2aca8e576d15d3d5b4ca2b847507a

ee:V+rF
63a41ccee737a4e9e6d6fb1b86ec39bafd39ebc8819e7fc387fbba943d9840f4F
63b1ab146204798dae708a4ea6d4d6f395bf1e1c9926c9fa14e4498aa40b071dF
63b78d16ff05658c1581a33fcbba6aef6d587165c3310243fa9aef6ae820ac57F
63bb7c514d317f810847e161cd7afb196f824e9b410a73c8e0ce05df376c310akF
63c3055a3e9d4079dcbfedfed3e049509ed10bdc0f3de7959902ff8cfcec5e9frF
63c82c1e8917281adf931c995b90cce5c368fb95285f2659b691785c1fdd6a86
F
63c934de1e5c85819654daeea796881641d8431d74c21df7d4cc109514cacb35F
63e5114d5fdf7fa2162781d184e8588d2af92fd268bf72cf0824edd0ad85d504F
64083e41574124b62214c724c95ecf69227a63f84cb8ea3c1b91c9e46909d214}F
641422dc7cee4f12cf22bee612253cc8d91ac4de59d08779329152d5b123cecfF
643e8a5dafaf596ced8be2e0be3e3edb692c0c81871c46db2a2541ee4de4aca2<F
64577751243751eedbe850fc528ea04d250e8a953a86f23a1a44bf84dfdd8e77wF
6457ba14ffee5554b41e56b32c8a9f8c2873e5ebe04d17cbb12e0e3e6edd3933

ff;V+rF
645ff71bbd0c6801049154ee1c5338517839d23b8146501039a0a919dd696e33	jF
6461bbe99176941777ad3a8221e32a189aa802b7e481a45accd4ea4f5b8b1377F
64701408bd6314de93c364f1b1a6d1f58f607d97f62aed713456040f9a7d6a21E
6471268f8ca47b59f93b0c5a8b8bbf5e9a7d6cfb337f2a89a19b76d82ac5bde2+F
647a613d1c2a1a76e224f9b2858aada971c346c973f46566c503a58ea2958063eF
648278bb5ec15af8835f0ac633c1ae82e1135e7a6bdc7ff8c3723b9319b41e7dWF
648913500d3bbad2fc637cb3b8d8bfeafa3a89bbf0fb33504657bab719b25763F
6489c51c51e8202231b1a3e24f6328463bbd952da0cbdede7cfd828112422e18;F
649668855741b2c9edbad09dfdf69374c2011e1b429ea28cf0f6c96a62a14f57F
649c2ee77e6ebe7b0ada06b4afab6acc21bb572fecb9b419d681640d40847bf0	F
64a40a4e60c03c1f3ad8929d3659cd713e7b869eb726d9f8cabf080ed73dfa6bF
64a62730fee8363341816507f9171c57a6c6433b7c7418501dbfc6686c446190NF
64a964dbf122edcb897186c8824b60976d45bd7ddce017d938404771e1396a1e

ee:V+rF
64c5a32d35ccc6312c43d89cfee42872bacebecc43ec10e09f90916daedb80daSF
64c82c743b0aa34d2ad89724607562e8cf196bdaec58dcfd940a8f728ce9c7541F
64d308b2273fa36c403e5a4ed7c61854903e74760d31d9b214f1bf89fe0393e6#F
64d39cb55589918f3c7cc7eebfd7ff6020fe1f126e87eb124bd3399e6a321938mF
64eaa7b016a8e2dfc63c23045a2a81e467d7e0553af8d19b447d9f84265a2b26F
64ec5a21e706505bd67ed2ff5da8b90fcfb71ea07550d90a777323f49c8ee5d9F
64f15baadb874e4dcc756fc50e0f361c704a78fb0c5c3e1dee25e51bd7bc0347
F
650dc5eb73a88b8297704da202b361a3a2367643c25269a9d667ea5803dbc397F
650ecdc0d3c0f2d221347461dc47da74b9aeb8041326a30662c310db8452c289fF
65199e9ea2e12be16d067a95704c987d84ddb573ef4d2dca215c5cd3a28b3b2cF
65584369e0052524a4788078e14f671f1ab55c3f0e2f3ea69702c77b5242d309~F
656525e1205096365c3f08ea7899826e736d536330910a13a0d12adff683e362F
656975f5968fdbaba0a643e24529b3b0762ebabec0f92509a22f96017cfcb03e+

ff;W,rF
6576a71997c6b88e455bd9405164a03375ea03ef6dfbfc8c070d29e8de1f5324F
658486f1d946fc518624c59a2badf6990f524bb7d5d660d1e34420cc78dcfe62xF
658e256dc2a855fce160722fd0be5cc972233fe8bec6cca01cba74d0e6277a43F
6597772d1fa9bdcbb982220b4e56bd13fb3a65b1ccdee0a911f8e5af3f58d188YF
6598e08634815038cb179701fefe7d97564cc4df49d4858c66ac323e5c9c5628F
659d1840568aaaa0890a8531c9387ac75d19acdb5849da0093220059585ae3c2F
65a42ec733799dc8d274d0582c47380210b9ba82d7d6c4e9bb2f2cc9e93e54aeF
65b46c58329dcd3a310fbfb4c8b9371639bb59c96629f150e82a7820305f44fbF
65cf532a0d956c5b90633a7b13857b7e3092f374d67c465f3126a5fef5cf70aeF
65d95beebc4fa859daf899819187c19f9a0f248d4f60b30fed6a324c4ffda665E
65debf30e942beaf68eeeebb661030f709a1c53b1981536c005e8dddf29b7da6.F
6602351182c085c415d4c05b7e325611057898b48cdc1249a54c5106cd0735fdF
660894a2c18d390472d0f133b53c845c1ecffde9327004870721603cd1f91b48O

ee:V+rF
6629074551d9fb3315ab487254009bfbf5ff68dc9d1c73b4aa5c866e5448129ceF
662a9d17ec8e137ca36a020dc0efbe8ae088dfd2e1dab2436cf4496bf31f3c75(F
662cd360391f504282c0f422539c52fe0554845bd065148bec2cc7ca32f09fceF
664e7cfa4c02ab9121f80adbb03b0b47bb258e1ff0c45161da3208d48bf6750aF
664ee953022453c5e78fe8b0d4d06dc2c1ec406c0d52a232f631aca0f1032abcF
664f64a4a6b87e761d7b0bc0efba577178e77a23ec390ffb222b9caee6c3206awF
6652fd59e1328ff5e8f2141d6e091685a4e2cb80366a0f729537fb40a17779b8F
666bdeb5237f9bac4020a4b5da35bdc2b27ec3fe6d28b4e3823d1ad165c013b5xF
667a197939b4f8fb8e33219958fabfaa7eccce599d0e0a365514b76cb20d2a60F
668aa02abd3ff0859bc87b987a759a3a31fbe34f12aac062a8c53a042ea273c7F
66a4fd1fe3f059fdf718b2b6cfe2780550bd2ecc35fc7e05bfc971d08dda1d24F
66aed3864f29912482e74e2a3bb2ea45d7402aa197018dc629d10fcebcd960abF
66af09f68408482637e668b90619392a27fa21b7d4ed06f3c3cbc60d87ce1d78	

ee:V+rF
66c5f4e48d6872789f81a04ef48fceb67a1705aadd369b0ccff804cb0eefeda9jF
66c9841543e52d2762a3f03b0bf340fa1bcf22e9038a8ad6659900270e97843aF
66cc35a05dd83f4129f6b3bb4f774d59fc607704c381b660b909ab3e3776ab96F
66d5ac31048d37a6a1e65da7b344292d028e8fbb82d4b9d710ab79080280254c!F
66fb08b8f23996f9e3c5ff82303886294a5596df60377f29eaf713d40038fe52F
66fc4721d3b2689eac33494f18ab2cf85d9ee8d1dd8532c964f11eeff008e9f1IF
66ff6d3d39c89b89cff9ea3640241dc426267d705caad62f73e5fb5ec36489da F
670e8233e94a81c11ff801e9565903257b0694462a07b7f8724d3008d060ad94F
6725bd1e0d020512b60182f153b95d2f6eebfc10cd5929625a7498254bd56f56F
67269c66b7c5a0c291c9f49a9ab7b1185370d1686cb0538cf41f90cbc4853472F
672e68e45c4b7fe8fc13c9120dc86f63a7501b0671c31efd1bc7fca754bcce6fF
672ffef35a04fe32b016bba89b95e6120a868c7d27c5054cb5fed31aca0fca0aF
67364ca692de365478eee5a94879717c1fae2b7a4ba46d128ec04f0477c8c2b5


ff;V+rF
676257fa89a2415e1fed624878b0d5c3f3c334c139f75c44938d08415b9e8b3fuF
6764ea39a74b1ccba4e77eeb2236358817368cb8f0b3064e3a6fda6da289f363F
6765ca1b27d1b3812e3c6442a00515395c3887ebcddeefb849912f45c005c54eE
6777f22d398c85f89da0f1efaa40c7fb3d16e1d72eeb8ae99d1e2dc818769d0dF
677cbb3bd9f4a461b86460be4a5a9ef23ab126d06907725c3ffe789009559936F
679e963c7906dde82f6ac27f545036d5c38c79be36b3c643018742f7c21953c3F
67a0b1ce4f650123760a584297eade73a87e8a5cd69ee80b0de1e46c6734c7e0F
67c66396a0ecb57afd6c3a2f070e239f41c72943e3c3994c64e68c02a4cc1829F
67cc5f25f8e6a42f9536eb9dbe7e22e3fab22c55d87d37db23cb90136913067eF
67ce50ba914619acce9365d0d7d6b3868526ac655a064b3e74819bd54992e79eF
67dc839e667e3f5b861596b011039393d6a243f7dfb880c5c787ed72ab1e601fF
67dceb0f183dc4e838b1ec1b27236a59cfa08a537707ff6eda2a10c5c9601421	F
6800883f09c022594a86d5e180d107e71cc758c3f5f307af8b151a36b1f98818D

ff;W,sF
6814c1585ec14edaecfb3a1c411a60fa17aa216d2f668964f68de8ee908ba367F
6815b9d123a4214f4d4bf68b7d0d6c2ea059a5ed94bf0abe1b157d1e14de7f6cF
68163138ff814f89bcf82178fed4293a777a5b62ff3a006bf4f80cc95692ff51F
6817bc65309730ab6a1f49ab977c2ea11a9cb5a2f623376008276eeda89f41da	F
681f16ea3fafb50e4f8583381026ef08759cc8c327b923cb4b822515b1d02144
ZF
681f9ded8847701dec6bf5ba7ebdeed4dc1b38b39177a2f1e148695f5ee1b1aaF
682b34f9ba65eb2126b3140d6fe7319d11e990cef5a3d74f66b79f00719e6adaF
6838d1704d6089791d6b3d53de842f0901465128bc97227e71cbfb2073418234F
684af720a124815101b07a8a52109e6312fa2da52e6a2f276a425b50b688b7a4RF
684dee15b7f2949d1127299fe87e939137acab9c8ab3a3b6ad0e0604573ea8a2
F
6856b6c454d9ab38557feb769e9f6ad01dab3cef1e61417d841eb5c243932401E
6858631f1ec62fd357122548e9196427a27ee3daeb8bc9decbb2919eedf39730;F
6858b0825e7c10d48e4a834df4baf94b38ae7f99b036340669e3abf74bdfc689
g

ee:V+rF
68765f29d06d31652e80d398846d899e7437a836c1fffeb61248afa76e51b90fF
687ed68537f2f9b2bc7c1f4aa45d061f8e36a38d93c1b7144cf2b6e35157001esF
6889ca4b0900ba23876bca7cf204adce1bfd41a09d82a67b81254773908cb5d0KF
68ad96ff2728b35a2bfef5e46685a550d379ee6937f9081450a2c2f4c5e5c68cF
68b19039b1e53465dc3f08f0e56e24f7e1672b449a51dd05f8ae10ff49416b66F
68b647f3d90f5828c04a513b4561ba0866363b42452fbf73668418e2faa06983F
68c5c1e442cb8c8c7a3e075f4f200477ce6b2f53023da840209a0d79dbb16cacF
68c911318f2dcbe594b8475d8adb5d700b385aded343fa7870ca41d70e302681F
68cfd2b5e2aa6b9bad7a4040def6ccec2aa6ca31c6acf4758e98b507e8efc105
8F
68dca12ceecda33b2f945d88f466ab32954ff89b462395ef6346d95a47ea375exF
68e1429d8531b268902804fdf15f6eb8ffcadc2d36315c6090a3edb14eb2ab13F
68ee3d48388315e955a81bc549710f8201b486ea8413b2e63a516ea8d40e5534NF
68fdae357028fe930922530fba8f0491b1f04b11e6ce8cc9f6c7b362bfe37101

ee:V+rF
69372e8180b47681712e917eeaf3777bfa1ae27641645b1797b5e61104693c4eiF
693e3ce2908adefcc2bc524795b6cde949103c699866ca985fd42a827214dd0e5F
6940a7ecc43ade6a78b801d66f177ded5fb4e3631de7f454dfee50cfca1694c4&F
694a1661be3ee29b44619821670f2826998a9100cefc0efc36d04db24b211e47F
694e41c94c00e68912502d5f6c5bfde8a366987f5381e5d31b889a6b3928fdf0F
6964dd0077dc7a05fc63ad2b2e02aecba267ac20fdf80589b768e01146960b74	`F
69714123fc4f27b58c1e15a2bdfef799961c0c2c3f1398116a458d05cf87f618F
697fc862a611518e9a75fc2d3bd296143b53d97834fbcd415d05c6cf3c77c118F
6982c05564f03f4db81df93b42eeb29b22e1c82675c42eaf1077f90bf1847c7aLF
6992344b5a8b6f8518b34b8b6f7488ab9d8930c89df8401bbe760046a494d720IF
6999892560bc188d71af958078c8b9560ffeb626747978ac0a90a392c446598fgF
69a52650aaaa5549296f7aed59178ab2f5ca948416e7e89b182107dc728f0387AF
69aa633d0d57b2f5e92a58731547bb1ae2b44fa1f61b2a529c041ce27a603f2d4
1N1|]>jMF
69ae41a6c3ac23339ec68078341f79bf409340725c4349483ba59ace78f79028MF
6a2860de3c6856a89ddef7db26248c1132d0358c047f0d29f64cddea617e46a6MF
6abc3f24e051fa25828e517e1a6999a1a3612b5f97a13d8e99553cc31d24663dMF
6b5e660e5d0921510f1a69a4692a914101958749fe11fe52afc2dfb4f09213c4MF
6c1525a5d4f0e9045c028f3d1abe0c4e7e9aa2e3216a1472b79d3f60b02d135dMF
6cbada440eaf05d5c86416fab118a0ab641f93992a6a4070b19938894fcb8bbbMF
6d01edd55d9f52f8ba1366e53274676bc33d48854b4465e49a15f474ddd0672fMF
6d7bcceec43abb616cbffadcf76d1c208a4f658a0625d17e0b0315b3e5a4c252&MF
6e01c854832108abd04704caf65fe4bafc23e70ae26e9cf272872718eee16d87CMF
6ec6b4d2ab3c7cf65dceaadd6a13d91e6ca7e48b3d6bf5712f0c0bf3639015b0
]MF
6f484446414072c482a1b896884d3548ebc69e39b5a32f1817778985ebfe7054MF
6fa281a1277a0474df3c2033953900cb085700242c41a44cda525992e8b7c5c6HMF
7040c353b5fb82abf2f6a8f2ca1f7dc6752192e19210070275d4676cc61318b3

gg;W,sF
69af040152db8a48f4976d9b63fb954fae461308585661d36105e126da985f47E
69b46c2053c4fbaa163f2390003a89acba1e45f20c75c06337f18474970f4943F
69b52b527f2581aac941a0d4fa71d1bce28da1b79f2f313b12818e1090892dfbF
69bfe28a120aa3364ed2beefdae50126ff4e6b20ea1caf0f10549049646767245F
69c2b3156d7f7348e92c9b6d94a15da2b8f77e0597041944eb9741c941e07001
F
69c508f0e20fb539180c31753dac2b1ea06cc63302811dd4f870628b72cc3f78F
69c9b42984d2a52a135360b34ce4482f7f1f7c83bcdc685dbc6cc7db28136840F
69d4fb9319ca5a9e4cae9e47996216cc1f227003389290e9e68c05911af73d15BF
69e3af51dee6dd3aca7ef07201a7beeaa6d764016a11afffdabce904928aee48OF
6a0c97cc57949a9e0b7e374e73c9631bdb4a96d91de5560c68e054144df60d8aSF
6a1b6459f1f724a4030deb520745ead7657fcaae71a35ba2905022d5da341997E
6a1e8e996df86eab01a9069d9b5a346d8a727e6c633a9f89b1adef59b208e01dyF
6a232fa9ad8c17cfa5cf5fefe213336bbd9160948ed66031dfd0a65edc56190a

ee:V+rF
6a2fc5bcfdf2c8ed011976da11bfa2c4e64084e1f45d265f784bcd58fbece989
F
6a3415f454a536cd4bddf7dbc03ff8c17e3484e1d6e9df356fd2660f6f7a96b3F
6a35640d03a1109ec551440c9e15e05aac57712c85cd6644b826678181e23b5dF
6a423d2e3e4b4b0cd81b2df3ad65109a6c7e435cf5f4d7b65f79f895ac7dd281F
6a47e214a36fc58ad9b00ab50073240c79076c8bd04a01dd01029f8ca43122bd
F
6a54b11f2a8b565659f8bbc6b4fdd6ea12732e30070c5a27c01336f48847fffc\F
6a5560cf575ee9bfa9cac85044e94e3bce3ea85e26431c99e41877289cf82b64NF
6a5c15723351049958d68d7476e529ec68de1d64478a1e66f36bbf5a50e2f0d9SF
6a5cc17610dacd423285c7b8f0036b7cdcfbc9fb0e513eca14b1d7d5ea047f7f
F
6a6db0a030199ad5a8e0edde0f8458ca5391f94ac4ccd7a93c3c186326026cc3F
6a71d3f89673ae6444441f6f1e25eb47a4347ba95f13345e2fcfcdfda313670b=F
6a841f73df251cdd51f2173820d7aefd9cdad93e87f34531d4856379e80aebfc
F
6ab73b9be208b744fbb10e2b4b62ee6782dd5717e49b00d2c93994bf8c59e499_

ff;V+rF
6ac785b4fd5c3fbb3f1b4107b21e46b2cbdc7e63216e249d74bdbc43d05c70c5F
6ad05aacb55ec137da2b221c99a490660a5f37778642d8b590d33d5fbb093262
BF
6aef55f22ccae6cb279470d28bd97b90a8ac51e8d3c01f08c9363be80465a5ed
E
6af757b1f83a00f0551ab69c27a637b1a7fcd95125d64c9146be9158ec4964c4	F
6afa61594c5b06f1ffc4710ba8533b869a889dfbfe0172d8e3cf6ea56d8269dfF
6afa89d1f93f0c18b712d80864bb7c05453680e7c2ef4267277d1a05fc5f3ed5'F
6b024502ff2b69fb4876076ce49575439e5b94cae11c486cd7c59b464106d8256F
6b0e694fe0bd25769497d03ebe96ad15e93d707736bcee6eb8e89bae4d0f77c1	1F
6b0ef069c7763a3ba0b61d3804a6919fa06467de6088cbbcda7c568dfc3309b0CF
6b1f4e0b7d2eac0f0c87900cfe0b6ceee898b0e7fff0ea37a318fb2be0b794aeF
6b2d3f3ea7403045cab9e0c8644c832cd7c229b54f24e41a1e5e35eebd699e08nF
6b416b00b5ef6cb53e5629184ff45e772a8c2a837a9e0bb69dc38ebdd07ec7f2GF
6b59b214e1d648dd6450ccf97a6e02143f15dcb331b6d520b32e3390c35df31eZ

ee:V+rF
6b85f79e92ef0c82246378fae50f149f91d8ee31ac8f97a53f0333aef59c5632F
6b870279912b279a310ff11d1024fd1270f6693d8f6ed22ad211f11ac56455c6sF
6b8e84e40f76c1ccc98e60f6fc669dc338d056f42c48ba13b6a52100a4f94564F
6b93ef98f6a4d5466b5be6c353e9339237a7ee06b8879ce1e25290af5e63339c	wF
6b9b9395896aada874edc170d344039f28e922ef896e327a1058aac608e3bf713F
6ba3e0dd497e559f7b44eabac8136c12499febdb7526dbf3ba89a7b3627aed84	F
6bba16931590ee051b717e6cc7eaf6319e483746bab088b484dada27e5f230d5+F
6bc5d11d6925535123b8762c2ad80e64d81a9fc384b6def702e2585966637c24+F
6bca052cf755c10a9a15dd05c1eba4a527bd36e88354bfc05d9a678661d7d827.F
6bcf5f3e89c2755d81da6331cde8d0f4c05fcdc2ce0250804be9609d9e125125F
6bd554a06d2cacb7334035a74ef3a0a10379a000a628cc964aba4a5a4c8d82e8
F
6c06e0b4e7b36d4a64097557ada558aaa42f90b60af6f66d06329756c6ea57c9F
6c0b00e1f00b1bfb079fb63ec314dec78319b2c8c2820688cfdc033017e0dc14

ff;W+rF
6c21b000ed4eaee655f575de1d380dded8d228f9631df396279ba89debbe6faeF
6c2a1f394c23865716bd975554c638950ef8bb2b3efd23074290f41ebd724f20F
6c3c6e8e517dcf759d5a75600d88260d972e071d18adcef801da195de54076b60F
6c557f44383a709d2f0b400c2b77b432a965e5b7d4507ed1ecaf15fd92b55760F
6c6c39f0c94adba5ee8c50460abf33d8b6c2d1741b4e3882ed1436af7ced0d88
wF
6c72e414ed7ca2608725b7230e3820171e7ceca0b47d1c5a4623b22e410f9c5eF
6c7c9ba4877418093e491bb7d8133af21eb702e5e6c5220866cf64e6755dadb3E
6c8904697fe6c2ee66e07070d91ead8cd93c7f2b07461f411e7fbb303c278589F
6c8d7f6e3e1e16170883c18ddcbe50ef6eb86c9a8222fb7fe4f75b91670adc57GF
6c91bb92ae5a0ac8598c4281307b9ca0d51ba4690e5f6927ebd9bc857c360de6#F
6ca8c118a949900b7ee2de435dfa29344feecf178d19d4852cfd3f958da2ac14F
6cac781f27cb3127831f0723bbd81603bf1aa948ef07042576138eded250dafa>F
6cb04e523ff2e6b8d60ef0c4e8df263d8d56af10fd076b4510daa749d0d1b65d*

ee:V+rF
6cc655263da0213df7eb5a2c6c63b5825361f55336855a67a7b33881d10ca955F
6cc9689dc7dfe51e1de149a22559946854b93c2f46f3d9f68ea4bc070cc665aeF
6ccf9907f4606b6cd68c6c6cb2c66c9cdf87b17f1ef8f2839dbf76b985bdf369F
6cd18c7d7a47f7f1e42e63865172f463162be9c7697c5e7b1953c41099a4d25d	F
6cd37a431fbb8cf1ad0ee95e2fbef2ca533dd95e28fed9e9845a74acd29cccbe
F
6cd845a6c8f106877b1240c8be24cc3b931a354a08536833f36917d64f2c3a8aF
6cdebf9c4780af0f03b80b00c611402cb25855be68d159669e31cebcae14e948
FF
6ce4b480a292b7fa51c31777377a1711c2537597c5cf02d8aa14b345321b67bf	F
6ce9a07c50256531ba281b344b048ba26881b6d3612f2c4ee5f35d0801d8be57F
6ceb416b5532f415886858adab254c77f6774ca35e5bf9bb0d73e58fa794a0ffF
6cf85cafbf0ed8b58696a680262f819d5ebbe64f5d4ce8010a037a47a9f1ae9f	F
6cfb6bf58c05c3d5623f5406c5e146a76aced8a97fef4153ef7d295cc5776298	F
6d003f6bec920c3f0353f927a0e4ce5191ad4e906e1f42da6845c022fe42c6c5

ff;W+rF
6d0aee209b29a68899270b50fbdb5657444b46017f3f4b39ff4652e77f30292cRF
6d1470830d621e224bc916d1ef07109d5e9c254b87795bc6bce9f712f138681eF
6d1695ee0cacafe8f21952e32e2db02bc6e264eadd5e68c3e8db3612519ab13aIF
6d16c50325196936545ac4cbb31f743a7fdab2589124f05cedf47845149e1035F
6d1d56332454173cddc2595690e7c56c35decdfd2263853829c0fd32e430c247F
6d23e0e03a7a536fe3cae17f34dc45960c361e2ee84b11158681f3db86dbb0b3\F
6d31c249f4ea5cbb99f5d7d01050aeaa157ab3eb14d78071165578cf70934576F
6d3e0ab4e00db4dbaa9adaaeda6959ba06c02854163d2f14ce6376153c971409
E
6d4f5821c8a6634679262138e6c634828699fef39bbd22f409c545e572e816bcSF
6d5044b286e25a56e8f05f0e476289cd678bdace8a5cdf6c00b7b99df760dd47F
6d5b1649b1e98557b5173af9108f9a86fc71dcf1bec82baed2b16dc82c6491d4+F
6d6d3ccc17a9eee0b41995b6db620df39e9070da91831a1ee3a9c9f9bf6eb135F
6d7a031416a306298ea9aa3f89fda52e0ed56ff1a48e7c9aa6e2d05c299a912b

ee:V+rF
6d8bf16512d109e75893de1fd5c3fff8aa8557a12556eccd6e6c8fbfd7f184adF
6da0086ed5fcfe18e8f92777f56bc0561f7b8a591eb03c6f38ba815464fbbdd1F
6dafcb9ecc7ca14a4ae5417e71c1fee10a7213e0ebf3d3750cbd23a8cacf5eef/F
6db6194f7a398d0d7abc7755a2f9fc2b6887cd20921eaa12f12ae087c8d48816@F
6dce221414fb5a6fc2d69f0e321ab26390708d0c5ae297b2b4a9886bc5ba834c3F
6dce766bf15259d4d1a7aba1acd135a56d9bb61b6d653cef2da6590e890d9fd9F
6dcf38b2dd21eea79940f1fdaf48332d6c3ecaa1fd0add17464537dd24fef021F
6dd07a33a81efe8c3709098885698f104928c810cdaa6390f1c3327bd53dfd94jF
6ddc2c9687b0552d18c038d01ec287088d430f5ce898b65fb0fe065c00b8ef8fF
6ddc8fea6aac5d2cf395f1d06506d529fc6fde104aa7ced09ed3d16f8996db76BF
6de2aaa52ef36e3802e22e8f09a0ff085d85520f42e12fcdb9a095686b4d365cF
6de667e5382d2e35f18b69390c3e03a9e718d8bc403a5db6c6f6072e6bf683c2F
6df17149302a2cb98a128880ea6df6fe1092d0cd169dda5bd470cf1dc5c73494/

ee:V+rF
6e083d21d81ff7ba6c8b92912ea5657be3fb00255a52e7d3ad7fbf5f49b55960F
6e1413f213a7c818dc679fc121435a30906e97b4db03211f3cd23acf9e35b88bF
6e22c4b0aee7e9979b7f739d1db74f8609f8f27a72d28c139c4b20648516c712dF
6e241bf0dc50bd058f110b48194543b466e895d9ce51ae777aa7f7d34f994e08
F
6e3bb564a139de89aa75082746181d125ed4c599326591693741010469bbd88eFF
6e3ec45785f4e53b2ba5cb144820351bce901ac38bbe5bfece3b71293c84197a]F
6e70e53e5187df893930a8cf3cec44c126d94196925b1a43fa27f481acdeb5bbF
6e73c8cf692c96778253ff1dcfb1fa2fbff0c5bd4b3bb64b10dd7cc1b5edc4ac
F
6e90444675848a4c5c3119f364cbb66d41bf048c40ae4f2af79225fe2278dcb4mF
6e91279c2c56161f7ffdfd5a8f8f361d282238b249859e57ac7e8d4b04a799e7	F
6ead86e81280d56c02e90e7af54080a1b332b55814bf405227418471a84c582d]F
6eb48672224acb21d0dbc83835af74ba98ee85d8e9d3991623af2bc0d57d6761F
6eb6b0f0d64dd44ca445beb920426e0a8262e18d4611f37af0bcf266a49e7ba1

ee:V+rF
6ee3e1f10e89d75ee121580fdd4238d1a9c783a16450d6b30b08f4dae782c4b6F
6f027d48513d5431e3da6ea4365a8f77b28f4a40c5d6c2552a5ab6817c5a1c2fF
6f13f12c50ed9a62d92967f246f2c8b9f5260a7546412f06126b024aedc1789fF
6f164909e08bae70614e499ae419c8240f745a3e5a7212281901e38d69a975d4	pF
6f168ecee0a2bbae92e0564565c3d22e1bae72f64557c32569a7bffd94b76ca4F
6f1a8e6e9202d70c194d4aaed3c034d719a85eb53ac63f8c6235756a9646a2faF
6f1bbacef1dc67ded3f5dae9926f3a9422cbb14531e25cbb1668f8ac69d00b8d
F
6f203af825d8187dfb775adef80a3622f5216a88db513e0ed31eafc3db4c7f54F
6f2e6d0fece31e7231bbaae7370f0f0edc484ea6e4bb69ce105819e1f85a83e5F
6f2f5c5aaa6b9cf8f21471e48aa6a2516a79b06217aba938f508f1ec9e32759dF
6f4280fe77b168975f638489aefbd874e08a1bcc00b9b43792472c51d7f9fb1cF
6f44954e7559753b1cb37504f1b6070062ebd03b2055d1a1becc6179569b8472xF
6f455484f1eb5f3b6fb66db239a002b80058c5b1b96396b1f9845be413af51df


ee:V+rF
6f4992979d6450182615d2419ce9c9ce044361871407e1a88a1c9911fe497221gF
6f4bf52463b1c528e35abf3e53489d86f0214da06151240744c0ab18b50ab903	;F
6f4c1e2f1a4962df4b746e55c425cf5ae75b8d5b8768adede04c96f2e00ddffeF
6f515d110cfd49f16feb45eb873662abd7d90f7d6a9521856506cb39bc3ec4341F
6f58c9c348a9dafbd677a7e56cd3f98765ae140f59756077d92d757199b1200aF
6f603069d8c52e3cf80cd2299fead7f8539598c42a9cd85ae42363724530da93F
6f66883f6d03f79791c375ff0cdc81d646922c4276e97e30803dff62b55b566dTF
6f6a33848cbd89fc9434117312104d1e8bcbc065f6821b6b24ebf04def7bf36dF
6f7cd47756fa8dfb7b6cb88b9a65c779de1981cf1b2707b6326ba27ddea5138dF
6f853b40dd81bacb35a8698a21c1a1d6663fa911cc8c99485387e4e10aa1cec17F
6f89875815ef474fc2dd49d33fb56f30d070a424491a2ab970b04c4b3a36133eF
6f9c2eab5630c71a827f71ce416ea6cd0c6b2aba734a2d023f35f7af3d415da4
"F
6f9f0808ad0d78d8f4557bb41258ee0a449509e5f0cd09b1ef99660661d29109

ee:V+rF
6fa692d6d3de0571869dd57603761a3835f55a4a06091767d81757431cfffe68kF
6fb636bf5fc99a0e0e7c9660b447ddb3de9d1e93eab0350986882884d02c9a69F
6fbcfd20152fd53029a53f360639d892f5a3daa9485dc2be94c27eed6cf2df64KF
6fc0812fc250d841a58cd125c88d60ba6c53d4c751c3c985ba925f28e597e5adtF
6fc93f49bcfb356742bd0f053b32fc44739f52e356d8575874ed5e03d9fd09babF
6ff94086763de7dbc7a08197fae9ec80ef7dbba995606dc86e245517b4635a11F
7003e053072c0715532264432024d1fce948f74d5ed2f2cef63aee418dfd47a5
^F
7007758347481b5bd5b486012d4105aaa620968a412da55bf70e5eb5ee4ea52f
F
7013395de5d70b992ff1cb20c5fcc916c7f545ed46a9021f6f2105e575039bfcF
70147742c172a9a706e38cf38eb04c08145498f9822bed40df6a19a4dd171abfF
701c51272a786e3642f50a00d1af86a89ff81297f2f58e485eecd9a7ff5bfe96F
70215dcd3ae55ef64ecc4091cf3625d634872ef001749ced33e1b98ccf7a9b10{F
7029af1412cd34983bc590c58b75f33a9bcb75cb2a5bdf5e6514f8ac4b8089e6

ff;W,rF
7046aa1eabc63c20c57732ab2750fd10c21bc29fbb4198fbd9497b0323bb525dF
704e68779e898e44b1324e899262e104a830680049fc89a0fc633372c94879d0F
706b5941777a2e74d84643c364c9bf33de8003c8ccbac339a0fdb62fbcc0e38dBF
707c34f7fa9d4787f56722da43ebdb1458d9855c217691d5688c6bde0306a2b7F
7086a3c094b4e91c8ec76f30de930c4f4c0d0eb7f9617e94c419d74aabb4f793F
708ae9f5c9f58b7f03e17c41afccd5768e49cb8d182d52db3c83077d9a7294c8F
708afa796fdb709f3e98d685f94be58af8cefd4ff05ab6d0a215d63d47cff237F
708df0316ccfbaa7713f5cc4d0174450936ff711924ac55e5527b630498ef3d4kF
708f19a2413ea0ae0ab9a7619a05c06675c69004d477b56b71ac6ec988ee1cc4!F
709d5075348bcccbd422a85b699ee6d907bff4255b77146b10e04b6ed5924e09.E
709e283813b0f0f0fdef0e1af87059ea4abce1a31640b490109436fad941d2dbF
70ab660529559dbc0857824877d03fb7953ba5e86fde837ba44bd5f6d5ee3adfF
70b5a86232c1ba2b2535285ea1e7951e1c2ce4779402d9ef8b14a9e2574922c4)

ee:V+rF
70bbd71ba6462d9f6702322739a79ddf57ab8a23f41a3ae1e2c47feacb60d0d1F
70d313100de0a9a28bad9868e3267b01f56634e7b633d7519f3153020d8c77b7}F
70d4d64cd1a4bf0b8b9ccc8e2cb0e8bc239ffd0632a796d2c869f55b6626defeF
70e1c9c7b7313acc1ccb883850558645a0cb1025e1b3d02d84b62ac7a8bef574F
70e9899b03ea3d4adef955f81b9ef893b9391bf9f209434d85b8d5254d3b97e0F
70fef3e281063a882efee9c52f35d342cd008f1417571c2af4e4f52c5a4439acF
712ab01fa46be5aaee9891582b7f8a686291b410d047f9e6094789f904b00faaF
714b86985ff8c757c1d759dc240539eb7226c4445ee4b6ed010da90d5449c6a6$F
7174a32cc247b70e650aa36730fa976b5d7e498a9fc59fde5c06de3be20d8da3F
7179cfedeaf917db1ff4e9e2c9261746c977c39ff98d06e7bed342cca2633c45F
717c6856842ddb6b4eca2817cbb3adfce002d371a61b322c8c74761e57ae5bcfF
717d93d915b4145b601363d9eea5ba57a7d532d16a4390f52cb99c069c612c19&F
71ab07234942e8c84134be2b225f1e3f417e7974f4dcf6a080e9820b68b1b81c
1N1|]>jNF
71b7e0dd87fd725a96f1b8e998c7b16f7c063cf2f5888312df9191de086378b7NF
72415fc89f5dcb558370bd92e670638fc9add9ad19ba4ee77ef546520c9a9e39NF
72a96620c19fb6a9a585ba00fc0f399375dda07b85a42c151bddb6c1323b81c9!NF
7359842aed62ed18b7e387856697f0a6cf8b16b27c7c68064ba6567b32c76b6b
NF
73ae0d5fb6285b4b0077f98e47a68f4b9fece79c2d81f4ee0718940d27177616
}N	F
740cebdde7c6823d4f1beee23080215f1f12ef9577011c88461d3bf597d1931a	/N
F
74b69c0cad0206438485f298e20a6d074c6e227e6785bba46afaca709e38ef8bQNF
7541eb5333c72fe17aa8e0d7dc2f7f91d8769a57129608043af2b098b5741661	
NF
75d06c1bd614e9afb5bb7ee3df0687c26dd805b2c3b4430087f9db6565d30371N
F
765577455a2956ce537d4c4d5768286fbead171668c41853b5d6f0989dd4013cNF
76f4f248ab4aaef273c6428865ba506ee4dcc78c5a1d7c81a8d95a729a9ac4a0NF
779491f4aff62cb66747a794b7b823e9645eed730e157ff87a8425bfd96871c9[NF
789245b54d2cc37181b3209ca55431722601a4544e987a98c0953c1b64660406

1M1|]>jM>F
081e9334981d1b4b5c7b0096cade8b94d105829885494e80e9e2ca16d37b30a4M?F
0f703e8cc67838485cc773d2d5fbbc55f6844c4144d32644f69e6d0005d860f6MNF
17bb69c6badb60ea50ca06dd905f5cf912769e8d8394ed0f28e46698ce95540eM]F
202bf466967d3f4ab327e8e2dbe21c4696c4bcd058996baa9a4cc4a00c10dd03MlF
28000a91ccbcd79237e5ddae52f2c4002be7344262fc0e43ce86378d90823bd7M{F
311a90d5eda02bf4ce86639848bc226ee6a17f1a66b1f15375a48b77a3d6b9acbMF
39b34f1245a4dd4e09703d7a8fa93bb27414f909eb7514764f934e9248878ee3cMF
4214383e3e5d362039f4752421a5c4dd66c7a5aad772859a41684a0b984c5373MF
49776569805f34f9417a664fb394e7bff8444fee386100309ce6306cba1c8b1a.MF
5105577688287233ec925ee639d92524c00f6f7490e2c5501c49eeb0f07cd511fMF
59322a58bf2949a46807f44a970d90fdb94b2e15f2de040025b4cb5e17568171 MF
614857c396c65004fd986e7b0b3b669ea5f8880fc93c655a69ea8ff5177d58fbMF
6907d4d091a1107f3bf16ccdbf5e24663641bba18bd965f06812680002457959

1N1|]>jNF
7954c520b09dc7bfb10b62124f03b0340cfc571dc7d61d91873543f3a413149bNF
81842832fb5e2ebf0b8c4d8f9d6e5fce417deee396059e72dd09a8180b6c94af5N"F
8819df992dd160364ba0aee29998326c7fce6c403594c9abe3dc7e8c293bea83N1F
913377ddeda7e9a87688016fb775cfe7ac678ed7b17cab277996497a766e6c67N@F
99f0c52a65a75ef09c13260211d703963aba5c4870dc9b32bbda82b9a3a9fe18NOF
a2b140586a9cd6744d897271b92c1c28166d43a99eb058d831c0617399959558N^F
ab5ba7db71da82b8f11f7725428c46b6cf857fa74755c8a4626182781ec2a388NmF
b38f765f577317761aaaf492c0a93c317974aef18e4e53fea2895acb530ec50e
cN|F
bc29e9309d0d6c8bcbf454c1d73fd5eda133e3cd0a96c01283bd3c2830a03310NF
c472916040722df81c63f7a4b84001545fcde6fe7ff88a7d90493dac79e09626(NF
cc9a0f5a5c96b17d6168b3f922ccac3f1d0d73520ab3386c2b40ca2263835c11dNF
d4e1ed8394af297a574fede15b7e0b3dcc28d263998175257f45e728f22fca91	[NF
dc7ff660e8cb322dcf0a071b2f556dfa57cc7a3c0a543524ae2c9b6a807d8262

ee:V+rF
71d5237e53d98bad084c2240820cd15af03b5f087119d5b59e92f1a002d4386cpF
71e8109b89c2bfa0c40687b649c02bd70e7702214ec1fb76fe606db76ace6affF
71f02e63578770de15752f8dd63988ac82d645cc84914639679034beaf9f41361F
71f20a3e8a0bfe010564d4b6ff77d4b2647ba8383e62e64a557c131359fff8898F
71f4e4bdc94d32ca413c40fe3666b5b8b0a092fc42d58ea96801a440297da553F
7200ad28455e7f8044a9521a187ff712e7d782e9a38db84d1c18e9b54e7a9a28F
7202bdb3eb9b58bc979d8ec45159b6e39ea0ff80df19efb9cc6274a852beee11
F
720ce08cb7d09fef55e566296d6985f0a465fbdb1a66bfda747f53f178f67f3abF
7213d0af79ee2d01cc5036dbcf46247c7d1adf8bfe1cf77ec8fb28e3b0dcc05cF
7213e6e2bfdc556860c8f1e0dbd57dcd1201fe9556912fc6ed9c972b00af8306AF
722785536ad769e0f2077e33c2c6aa02937baf01e2357433b6873c7a444503daF
722b0dc706f7600d25c378ec61ab127376170d2f1df9446acfb02d438beb9e18{F
724104b78d65c37a7c944beaca3bddc2e94e0e2766838104816b951ec6b107c5

ee:V+rF
7244017a6987e7001fb62931332183a4f84646b24773d5ba2acf5c799d15b1fawF
724795eec6065da1df593d22a6a359fc5b241aec5a3916cbec646ff78f2196baFF
724f57980c52e692722c8586a68fbb7ecfc81812bf1d923a920abbdb04014943	7F
72598a2a7205cad8abd1c6adb36033bebbb72e0537e83288ff0a562511b5e061F
725f41aabdbe0d99f4ff043c8413b75aec1da746d9c27e7540b090a7120002f3F
7266766000b531cf157295f474f17dcfde3f6c02dca1c64d75e027774c33560fuF
72669bb54a42016961de3ef8bfcc2ec60aef58f9897e239a330679bdcf828e86F
72811299e34ce97ab4abb454b8e728ca0bcc192a314cab3cc6799df21cc7b92bF
7284d6fec357299a1772944305ca58f5d48637a3031733bcdd30849ec50f7a98F
72866ddd3fc9bb8286ebd7b4f6c5d977fc3e7925268a253cfefe4511c6e90150^F
72872ee299214c68c0fb449a111ab5178f764ab24db86850448332c6b4fb7cfc&F
728ac150acc4c81d235b89af0449b11ae268d8c5ea5df6ca8b54c4f90b3deb7cF
729bff77f6c7fc23bab8a062cad450e4fec1ed72327936a033ec519b4a1f1a5dM

ee:V+rF
72ab9b204a4a984bb758843741ab139089f24553cac0336f08a7b1d1029030aeUF
72b814596920effa935ebdde082d64181b5aa2f44485a058f2535c54828f931eQF
72c749a3e397bf18c32e697dd5d3adea234b8aa2a9755e5fd2cd34140f3988eeF
72dc266e5da09e38d19f4c3904bdb983146af68adbe466120ff8bfecdb4567bf	F
72e40ba785c31c8259b00c65df653253a9d5ea138de40dbb02d655d32830c0c4F
72e5967a31cc0ef1edc116fd15578c5e906edd2f9c5485a13dfaf37b191efb7cF
72fedcf3bf921b3e8efb6e27a94cc4edfe624334e5b7a143442d707cfb625b06F
730a731598f675b1827b85e2f2a963fb1c75d82ea0eb61e2b544a1c868517c7aF
730e3f511d99634857cb8c6d1d6a2bb0aeab30962a144cde1567228df8e3ff7c|F
7315923a129e703d18cf9c04318c3fce2223c31b6b9d9f8742322e1c2bfd100dF
7336707319b5f28ace3e7bf0ea8751a0ba448a98bfa2b4875c2d08c7207b3bc08F
733a34dc60cdc0d449bbed26105adcf2ede2d935f0d054e31690592628f2fd4dF
733cd7b64f33a955dabc853a4b1cd0c8c37bf1e8e726fc0bacb1d1ce4472cea3n

ee:V+rF
735a91bac6263309ccf5145f1e264cf16d27bec4da5fc2e9ab42e3b055fc46c5F
7361f0c9de0e2a09eb70e5f1b83d027a808b06433ca9e73208b44184ea5cb1a8F
7362e3afa20e7270f6bd0843928dbc50fc58aee6b6187699194d02979a9c9b4bF
7380c6641a8e803a62e76e8af53969ed47f13f90aded491ee5e72f1947b0995bKF
7383213f19577210f9167fcd27957f9bd4763d172ec1509e90329b4f69c04a81F
73839ad166f5daa6f4e5a2a9b08686fda05962283302afa1963df3b66c4b53e0F
738674ab7d423fde7ddc0d251b0d8c8447088a4f7f39ef36b39ba26c41f4a83e4F
738ba060f72edaaec140a48f940f7fdf573a9f888afd244b937e86cefba2f1ca
F
73952b31447b02abc10d1c2efafb6def58e9237532ddef9eb3a691baaa88a495F
7397d7ada85a990118fbb29a019e0229dcc123eb73b3d901e8a68ca2b7f2da53F
73a833b69925445587e5e902cf5b0432e6cdf5d8c184064ea6f735ed11d28452F
73a913f2c7fb75a15cc3b74e08df90f3afc8fe8e36e918044a3fb407b7cf85e4F
73aa4d41c028013891614d9b96e424d2511ce51af87ead1125bd84075eba4b04

ee:V+rF
73b613dd48f531b02ef3e8b042c6bb5fa7f517faeedbd0883ebda2f46aca3135
F
73be1cce35dd9bd5fb59093ba5faf459b1f723fec8ccad9d13b18e6e1b249b10F
73c486ff61695559ce4daae66d613f19b44873db66b308ac0f3d693c35e6bc5cF
73cda0f598ca90fe3470940ed62663a7a5a1091731757b8e057fc929d3c1a209F
73d0fdb5a95bdec295481af2bf2057fc8d78d8110d2f95f3bb7c85577a034eb7F
73e2cf9bb12255322e5252ec0b918e3e62d5c6df5b610dd7d2ecf351b34f1365wF
73e6c1345f450c5929eb00e5f4f97abca74086756ad6e3bd8c36e85d989c8283F
73e7e5f1dff51614ddae5538cafc528cb724c6dcfb3a9b9459be4d82230e5160F
73ea554de089905aab93ded3a974f753899d2b8f0f3f3044d9f41d44a86324db,F
73ef9f5aba212c3f0d0e055cd597dbddc8d7752ec301de688be47c0a416b5a6dF
73fc0c87cb3098d277406335ceeb029508b87e5d4f5c7d1cc89eeffaf0bc4009pF
74038c223561306541466c5407569dcc8055567f3cc9a56e7ec106015d2df942F
740cba8784afe4330523ae1c3ed41bce93c5537dad8f467cf1fdc17ea21f53e1

ee:V+rF
7423f22c87721f8d9e25856620d67f6482cedf0716640fcf8f7e8f609797cb2e'F
743d9e213a14ae1fa06bcef18a210a44805cb5da5b65c0f584ac8098ed4b81e6dF
743f6a2f0afed6f677ea24028a9be02fb82801ed898d3523695bc6b923a302d3FF
74484befc2ade710df325b9af62b87ffaef3b2b13a00935396297467ec8e98a8F
744a4dba649fc88cac73b711d32a121916093d5d15e77ef286faaedeb4a661675F
7454f4ffa83154415c00c37d9cb1e5e253feeb7dd34081b445318d2340ae4e42F
74668b90f41c424000d241ad2f9a624d6386a447a8d58add20fd173375e09b32?F
746af4568fbd4f2bb6981f2e903fd2f1917f331b5c6fc90f7504882525070fa4RF
7474f32c17d8003c3366608f1620d6945efdcff859c4f6900ae7da9ce3f9585bwF
747801d0d750e872620c71b8849522e592cbf713a0e5acaafe2579d358550d242F
7479424a5b57460d14eb031904fe5f6c5eacebff7fa6b708fb1b98b33a6b3900F
74820898155583309223b3ef4e3d5a41b76e9d492696051d4ec79f981d16febbF
74b63c28e824b50dfd7c42b254636029cedf22dfe885fc3017c73533680e434e

ee:V+rF
74ba5dbc31e8d072aad83ccc34e693990c0625ce81a367690bc1cc6bbdbdc121F
74be24de7bd01781535f8ae78fba77bf331f0afd97e69de054496dfa406689b1dF
74c5d742dbaa75738c5c52f77416c65b88472bdd5eafe0c39fe63d1816522476F
74cf9b03dd4c4fd8b948481f59523011514a6b13612c953041fe8c112c7aa0d9vF
74d5c2dc05acd6045abc44a395a51bc278efcd90d8b9949118c7b18193eccde5qF
74dfc146e5e4ab219dba838033e3a2a983e2ad796cee5a175fda1b6c17653193	F
74e98e4966e80435f954bb2859be485730a97c3e547acc848d76d50f49af0329F
74f4bb31b79790aa5a646612520c06cdd181b6e3e39b90a65dfc2634c1821260F
74f6bb5bbf891159807474196fe08baee6d2ef51b9508b2bcec100949f6a756bF
74fb87c43d42d2e134909edffc5d2d759fa9ac176e342697b6d590d62ca8a11fXF
7506ca728020b82295ffed2418c27fbcdc236ff1ef18d4ad5b231beae0f3defe F
751fbd8677147721988c4cec90747030a077b3dd3211d87dabcce6357d612e7a)F
753153d2c6886bf4e0fd54f9652da1247fec1c0ab4d58a1aeb4bec8ebba28d9e	

ee:V+rF
754f6af1bc5302dd16280e706cba386ac96e7198be4530e907559fe08ab098e3F
75518cc294a25dd2bf8e7d7c0883cc13f46fbe3694ee431b5e7ac646eae722b4F
757772969a2b13e5983aef925c31b673696df5c322b359714f2a89267929bf4eF
757cbedb5a1d0d38a9479759f8661ec2fc0853efaf4ef184a79a5f96ef5b7a8e1F
757db012689225d59ae444ae9fe49b96ad20d6b478e9a2858bc9c4a3c2ce5b7cUF
758b00bfddac1117f7a640983316c5c512053334e60eb19cc2b8b9bd616cc3411F
758b5cae55b3ac82f5e0a21bdf123b49f2e3ddee46a47f58c99a1c2e02d78f546F
758d2c3a908dc2f48b1ab2c25ec323231a54e2b646281ebbd88192b61617775eXF
758f0b0b263f27bf6a17362a156e2d236f0210bb8fd11a69dbd5e2d9ca1be328F
75989f565f1e52c44012dd4948e788f9b6b90cf9a5a649233e43f199a47b4e44%F
75b8e9f03001f9908924df507ac906625eedad84d4f379872e8537a185488c11F
75cdb68690a46ab40f6949579f2ea4df2f3e811398a7dcefb77813e87272e899_F
75ce644c70ec9964e32bce8017125212233496a086225b0503cf1810e717e333\

ee:V+rF
75e71ed053fe00917b68d0c20c63e517d0ac97df8a4844808522ccadcc94f568F
75f984b4cdee8c054416401d8e1a4f00cb8d0fa104e54d12456f8884c58d7db5F
760d5445bc23c3428607195fc5e872474f29cb02a1ec8cc53a0bc41b6771e204F
7614360f2f41c4a9acb375c65afe79453a28906b14eb8088a9a89a96d3374218"F
7621e69d1f6a5287ec45f7ae6e9410b61ce65c095de32ed792b022a4520de7d1F
7631dec5bfc4f885319322ddf28a8c174bd735138c0021a996ea89b80e010ec4F
763431d569a4717a132d38c72d98eb0656623f04155dc15baf5f8face7a581aaF
76398082a1500552d12445932d6e5689e02b1ebdced0a38e4003a7fa56871ce1F
764049c60a710f88bfffed5ba17cd51ea7bb2822f89390f24d0db26a94bb9220lF
76499affa56e11ce8cb0b60296dc990f3d6d2f235f5edeb8261ed147ff7a3323F
764b6da4f9a89bd034bdb5f3c7e3d13f7fcd081d64b01ef179ecd51b31ec0e20F
764b877678619df456d5a383316616afaadcb63072ba391f1e306803942b51c7F
764c4140bd73b1c0bdc434edd88f8c15595f4b1c04c426277e3e1b098ebe7d16~

ee:V+rF
76640b341c1b50d068385f178412bff6541f41c567500e0f8e16463cdeb30c40F
766b6de38798e8e6035b4c0b18df36607cccc2e988be356ea2d9eb9c21de9b6cF
767a5d433dc92613d0cab0185b37f0fa6590e1823a9bc7f2ece1abc592069bd5wF
76813e1abc18c641eb46092531885c18b9c6ddd5e9dc4e228b79d8c1701b18aaF
7690f944ed218f74b3624308e1a4d4ddbbef310d2d09257774fdfdadf5cd3916CF
769518511a9626c3f684d9b19a35320e0bf5eaad8dc6377c966be0005c590641NF
769a4e98dcdf66de7159dd3adbff251c61fcb448ebdacbcc474122895e9cf709vF
76b71b906c9f1af8e7860bcf78af0d724ef72c918767fb655b3ac9f2e0e6530b	F
76b9c89c43e25719214415b156394b6c8108b41639e8116895753032c1480241F
76bc9b2f317ca1734d3d4a20a64af355a4fdf864a86b43797f7bf7ef506f5b34%F
76c5012bb1a4018438b2d42ef73cd3f71d74224ce2b5eaba5a63f6a8e7daa068F
76cfa65febb7025f91800c11072204ec3748d9a68501cdf0cfde5a6c5404f0e4CF
76ef31892a454a03675c6f23a831bedd4e585942eccd9b529c271b8ad2e600db

ee:V+rF
76f7044e7f7cf0b257e3f983a0bb8457ed7e60c7c386096fd844e8a43f3614acF
76facf50f1b80b009a8db32a440b75f305a0ebb492bfd12472396c89645ad637
lF
7702850f4e2e80c04e6c3466c990e0b651afe9da7ec148a25504e6539b25fcfa
F
7709c0d2acd7ad42cb32f7de9cac262193958bda0a1f863ea37484f52147282a`F
7712f39d03fe27ce44ff48e5aea72a3011bc46509644b864641c2f3fd7d54e158F
7724d8a7b5c53b6b19107130e41d127672ad5e6814dd6d9cdf6130a27f22354bF
77269448e020f6a70c9a9ee15224c6dffd91e47f8c5a0c05dc8281dec47ff3f1F
772df4394d584927dcf77fefe3909f14263b4a632dfec53f011d34b412b30d8cZF
7733397737d974f9005123481470b631bef4144d428a07acd29c461f8073d83eF
7742bb9e3b59162a644886a0fa900fa88dfa7012386ae583ac5a8bd6c5ac79f4
F
7744a295fd69e27c223298b284d7c8853f441d6b08e8333049ec0bbc9e32287c
GF
775f41c9398da339ae50faf7692eb4b9de783c58e046c6c24f659c666b25eb48F
776a13c05abec92b93e26a3e73b33106410100566b5e395d5a22469f660365ab

ee:V+rF
779af39181edc4bdb4e091b266ec46176447a4ccc0941c928f999ed3fa780cacfF
77a2ace1d206cdce59078a04e1d50602e60fa9783490a87d7d894bfb57c1904cF
77b4a6262e01a546f91e92c40dd8c101260465ac9a037ad0ea84bea77bf29201F
77c36db32c50f15916ca53f42fba6ef0360314d11a2d6e929276d3f8890dcf99PF
77eccc75e9f9bd1beac93212452f411060218b9f17289e0f6bd3b293aaeaf916
(F
77f8b56d670e17fdf230395120c7cac1c190ab7df682f7afe91f4299ef0e0357+F
7804215d9e8fd6eaae4ae7d7fb360dd0ec85e87ed93ec488ef3d1cb1285ff33e	~F
7813e68c7a683514d7f3a5da05d9e10253ff77a5a4efb99321ccd3176db9dd97
F
783b344765a19ddce5583dff7a5df7639ac3de2a002a21d71a0528d6aaae8258SF
786d9abb0444f4e1a0a27702f0bb4b6278bcf8c30e15093e909b111eae35842cF
78721775026f8ae9ad659054bb6aa8c453a791cc260f66e1ea959649a8f8d922VF
7878e948667fc382edca199743ec7e4e3bd9f82c2a0b2e50af7f93121264ee6eF
78923c044dee6993ff55684229e266296bd04b772f4c47761a0e197bf8ddada6

ee:V+rF
78a505e2bcfc16a350b57ebc21548ec930762a04126892a45b3a16320eab40bfF
78bf4a4e4e5885b5d88e541e46d3237eddae49bc51b74c8c40c52741b0ce4534gF
78c54e3e24da878a2395d1db2fe940598eade355a2ed7955fe408e1151a3bdebF
78d3877b596cc832e4549e218cae35c884640fcb1d8e5764ee09a774a110fb45F
78d39bca758e7f5e4b5122c075cbb2a2c1d8ab9c258b4f91f4744f9ff29a5e8dKF
78d5b1f2129f41fe187e0ac04949364deea63d749d50862bb7767f1e00444a71F
78de7ead3aa002c4e670d2a6bb86af61059a4efe2b86257958242df65bc50d42F
78f9c4332b1d2f19135c616b66d43dfc85165cfc47974524516f8cfde4bb96657F
790b5c852e13d4b60fb3844c4e81a28b8500aad7ad521d07ead00631d519881fF
792164299f57de7fad013d1cbb4d0847d3228f6a89e6ed330af88b4f95b4e458F
793ed94885ccb91d3de9ac0ee3c6ae228181f6d4d90d6c2ba44aeecea596a647/F
794055514a0043fb0a97d85b7e623b6862a4861b6e488835385596d392b4f24eF
794a3fb2e476acfb436f4d7da625bc3f96841861ad270f795c67ff6046875f47

ee:V+rF
79588570ccbd1df263463cf10a5d97ef323266e2abedfeb2fefafd34609a08dfF
7961a17846adb9bd4b8dc39c94b3cbe82106b9f14b61013a3b4896b7335f2e1eF
796aeedf2cba1ce6592411175e3cf65482a97625d933bb4da8a28f0d16cf34f04F
797abce4232e5ed3353b7d0733cce5d5aea1134edf9acaa37b6028ef6bcfbc3dF
79973cc33f53bcaa66861b86f5ca88df66744a2b5a58c2f2f7f0dc2e37c67a36~F
7999b3417dab3aca80a1f8a57c6a7b9f98efab7f9c530e0131e8ee2cbd026459kF
79ac9fe0cf39a64255d82fbb10c0d150d68cd88753359d4d13150cbb094c9674F
79b1198c3958d0c5aaf003eb2c5f482ad658aac62e3b7fe05127e6498153d891fF
79b31e2851cc21f81604266da5f6560bf26df1d0f6c6015f28b51d19463bbdb1F
79d0f0c2a70577d228a2c71fdc289b4a2944b4681bf3f5d79f9b04862f3af683F
79d78fa443907f0ca28a70215cf61c47f965c37ef5ad56c02db408bdd9e238c2
IF
79d7dc58c2f988ca4128c170279bb74b7e02f4d11996be672cb921db54e36161jF
79da3fae5743d2c375b344832b875293be6e093e0f5535dbfd33978c82e7d095
2N 2}^?jNF
79de22a187c8d6582548815722742e3d7cc19659ecf90597109866199ec5deeeHNF
7a5f1f1bd0da49fe22b1022a7bf998826161eacca343e82125f1b036b9cdbdacMNF
7ac006a9950b2c1cc710083732c5cc4a33e7c20c3699c50ad6f24318b5986edbNF
7b7ec44f73e60f1826d6c1d04e2dd0dcdf55c7db06718558d74313208c397656NF
7c0a15ef78a1950328029433601564ae9606ccc8e17e7470a5e84088ce0cd908NF
7cc876a75a07e0764ab0c3b780afa6d07f9464d369cde9a0a7fa0d5514a397e9NF
7d5c7ed2663b8b4d93ccdce3e87fa7b84c42697397d9594170591871b706c60dNF
7e50ed884e06e8b99632be1537d095f84b2961978088e061936f9dc699a523b1vNF
7eee4abf22678a8043377d3ff29621b20a1dbe6da04bb0918068ef07eacf23e7	NE
7f6f935600e1b0c0b16538a2e5c86c076209ebb973e4d33e6f98c66d85973c9e9NF
7ffe1e93feefa9f0a3fb660a77c95541359f3947d165e16a808a69bd327b5ca9VNF
80846d26d36affb3de74ab705faf20f1ccf2d552bf0f63a19314ff38efed5522NF
80f55b0df82d9eb00f5b602013b5219abee2198b4d76be5dbf7622302dc2c749F

ee:V+rF
79e43cf434b3dee8dae9d367becc2c0025c3514b0684d27a2cfe6fbf9557c019F
79eacef92a2947aefaab902e53fada60dc27d9c173b1e175f1ce4db04d6c653eF
79effda42d229dffeed9ec2dc1067ea15c3d1895c9bdfe9d24064abaa134d7a7
F
79f1fedc8c8be3af6f1d989940ed7d956d779d3f488f821b4f08032ed83b1f3b
F
79f38750b9d405228c1da2c38370aaa60d7421ed5671c4a1dbd4e0c5308606b7F
7a01c8e4b4c1eaaf03f29bc31b1fe91b81c17591f2d6a358c7e57ae3b8103eb6	-F
7a0d7cf0562ad8c11ff90029a2c2cd9fd83de148afbd1a8db3fb79e0d11ffbfaF
7a120b5dad1d3423bed8b8972e2921ed34ecc22037b1ceae0e2a44fd7079bfe1\F
7a1256ee4fd271d588649f70d8aa4492d3967b0afd9d82a145275924442baae0uF
7a15e89049ae929f16d7970980522d53b696c61a5d5ce15d47c614ac40e4e05cF
7a192ba7047354c7646edd4e2c5e44dc140a332186434319479f733ea0d3a469F
7a53443e34cc7fe98a4371e9025389c86bc36e38ca424a98b85b4224bbcac1c8F
7a5d98b836fb6cbb743996d5dd4c13cd9fe0b108498811fbc5ccf1dafa7797efP

ee:V+rF
7a692eca430d652a3cc0c216034cbd84562dbf07b12cc646e4c6e4d5ab7c2fe7F
7a77df777aa49e715d99b786d4ec6329b8453f637359c0c17c35c656462e7f18F
7a7b265708dca056a11cfae6ae29db41405f54311ecc3a62636751d2e8044546F
7a8603cbba23f0fcd47e61e17dd4bc37f62141da71555814f5e89555fe2eb8f3F
7a8a2950c90f28d4e41ed775b9ba97a61e78927e387a936edd2bb1ccadd3bdc7F
7a94ec0c411357ec66396223ab1a2614a6df7dcab88aacd0aeabf389ad0335404F
7a957336373214b86e031556081bbbfea7f560af4a8ad2dbd60475b20bc824d2F
7a967bdf7823255236452e9a45977d7f6c253c9f3c88f18a80ae1ceb606319fdF
7a99b195e228185309513ea38f47665d85c3f48be1efc08b2131eebb4af1771cAF
7aa980726f441dcbdcee2948aec3a75da1f5fef953faeb2e9aa52c3d5818a4e8F
7ab133f1d96805c9be74317d0b4bcea3e9eababb5fcc413f08dbe0176819a8c7F
7ab4f1b0aa285d3773fdbd8bfc529969ca101a627d3ea88bea1f99a42093e132F
7abbb0853851a20592aac6a51b52bbe28466f3f0ee1d83a240a39b4e4f336537a

ee:V+rF
7ac7d7acc2695d1247889b192c63a490c516efb9b8c1309543008402c549f1ebqF
7ae117b77c126ac691263ef8d207cc3c2dd9ed5f34f138e411d09ae4a6122407F
7ae732734ae47230b9ee78bd90d72d963f85df5663e2f2ce2377f9f040e2ced7KF
7af082c81c1d06e353c77f01f35f6d3cd695a765a542d309f406079af5f14000F
7af718b81b8f45b39e82ed35fcd1065c8dd2f178f9310777598dc5f3544dd695-F
7afb4c27414189dd2a2cc1df1ce6c80ad77c0eb59aca381a22a3f4033f950c67F
7b0c0a663c4992773363ce6c177e9d75ad05e8f8ee19c76a4d1f71fdd6a97da07F
7b1c52bbe226abacf3c7479ca52c3d631af47e215754ccfb2ad53c6226e13392F
7b215997f9c81095863133061f447c80e870ef64f74f3d78e13b7f9cbe749027jF
7b3d8994d78928ac66011137e013e2d788ecc7712d592ce7c08306cfd1728489DF
7b45707f7663e49ac7b9284020212ac82fa961b018eae09ce504f69ced527ca1*F
7b4f34148e411ba03bffe54c35102df45b1e78e1ed461d8ba62a118f517e96d9\F
7b73f05a3cad8a9e27146ed66584c90db157d3c8dd9073156714b06d53ae16b4%

ee:V+rF
7b812c97766f36c2e477c31f7c5cfaabf34e7bfaf746d34a7f6971d6abc3e95cF
7b8ac8b33b435a9814ec099de17eab143568599d591c4426da4cffcce26808a6F
7b90cb8bc8d2c7faf537d5ae45a0a5a1723647451341f52d133cd54aed8e427c	_F
7b92de985a23ef4b67bd11135a92917ca99025920b1e4db59517205a2278c3f1F
7b99cae552eb8e3aa9044c06a0c67601794c80300cf140324bc228da9d9f0c30F
7bb7db4c0e3b5dbb711a2589b4e752e8fe25c9b73185eaa3eecc00450d613c21PF
7bbf77456d5e310210c4bd541fee70097c26568f34f44184c878e5874e2b57f1F
7bc141e86767fb1aded5e84e27ba2b03fae8eba8456610294def618a96028c69;F
7bc6360b4ac0650d8d43651e36f72b8c9c1a393ee315d2c1ee3d3e997ec61b5eF
7bddd4fb53bfa9c6ecfb51584e6173525154d1432fdd23c18162b8a5428fd9c2
F
7bfce38ec77185d1696e388cecf4163509c7884933ded369897a1fcf77610b49~F
7bfed40726a8044b0f0685487bd9f5131499f3c91242720ec1c55565601abd18F
7c03b652e1b0cb7c5ebe1d7b4c4e230bff7b2cc8cb68a40c51541d017458d4ac

ee:V+rF
7c1cc6ce8c70a7a3b07d877d8ba90c49382b8945d6695e986df3f69e3b59cc32F
7c35e147b314a2db86256a9a76e58c2eb54bc2c62f2acdbcc0dafe986f0caff8F
7c3a5727b1fac7e2de0318d8d80ec9c79f8d4817cde856564f2029e02691769f'F
7c45ba29959e72ceece7bd3f48bcc0ce0a86ebce4677a50e9d95a46e172b5d3b
F
7c4bcb2fae18cd595ec3e02100dba37726442206905efcc349d085f60cef45e3F
7c5dcd2035ff3f4503debbaeecc9659798c5a4cc8626f9cb089451584f53fefc
F
7c67eafa7cee5c39a41ff1aeb7d5cd4d764c1967ad0cc0795ad34e1d63727f0e(F
7c6aa8cfb40e021ce2fd6990bdd23916f3ceda1eb1455e49f09d1d0fb41d0f7aF
7c74b103220013bb9c00f724937c12e143a5ce16e2b00ff71a37c5201ed308e03F
7c759545a38cb6f7d1990533a397e63777b0f5056c0fdbb807b6d6972e8512adF
7c7eaf7933e4baf3cf7625220da22e524fe3ed89a2e6b6796e753638c6af6de59F
7c83aac8738db8a2cfb8c54ae4ea010d008959520d9078ac174ef677f712c83d
TF
7cc5e8e7cd7fd7b33ddc2f01d6d1866e7073a0a2e8ec65d4a8b21009e3f67777

ee:V+rF
7cca95dd2bd890021e0f9bf2eaab7788beef2dbb9ef929b7da82f9d98d4b10feF
7cf7e3e4798fd8a46b48e37fc7adc314491a938ee17b815dd3f5c0887cfb2f42F
7cf9167bef9413a9b392bca9faff3196f5c05d3ec73a6d3e2429936ca11db4a3F
7d006c10e1e850ab6583783df33de8d968fa27fd47068c159bb2bac55c7eeecaaF
7d0c45c842a51eb4e14eecce16a8da906ea6668258c6fe279d9649645d4bd422F
7d33a7b50c3e3166f40ccd88712ae894914a62c9c8468f2b8145876e20f92bf9F
7d3b3df85df3f1d47ab959aa42eea6f3302b166b9e37ef92779c1c8acedfd671F
7d3bfa9dc6bf0bfa9484b2f3613c4816e08534e247194ef466587ccf8938e69eF
7d44f440dcfa707ff7ed627fb7b3fb3254742dcf60373b386105ea09f4e14293
F
7d49e6164c17d7539dfdc7b2354026cb06b6ee0a32b0c9218ac3d8960f348534dF
7d4cedf119f33ca8dc827b0f6f2be910119d492bf48ad4b4fd46ee45c6094800	|F
7d51d69ba5aa33fd5b306518dd99095ba3f2ff1d6747f56936b992042029875aF
7d581bf8155fdcfdd7570ca3bd524e4ab64b42a8bcbfe776cc2d97ca9fd25264

ee:V+rF
7d5e6120ec65accb2c5c369568085687a5c6a5b1b8a72db4eab223aeff60b971F
7d80d5c3223ee7166a1d09374bac557258cbea615497efbd575aaf673d58b321F
7d9adf9e27536faf7c726121ff0e58d8a0d0c473168713c55c95d74da74c2ebfF
7d9fd10906d65ff1e5f7dc8aed453f9fa04ddb34ca3a6622b45b15bbf2b7dc66	F
7dae50109a258ad6094999bad1cf8de9bc680b967fcb221cf9e38f896f8cbf93F
7db76247917b09c13f39c3f19f3ecbd478e5c46584b6d8ff68a51268b0251871
F
7dc75ff8c8c8c6b5a6b9fc8c0b75b9ddaaaff8045fabbd17663a334c27c8b9cb F
7de0016fd49560394d1c4f5584dd396e5b41989957702068ef31979934c299dd_F
7dfa4db17abc05d6bf097a9695e02d8f0889d219fe48c90d147cef40ee6a34e0]F
7e0b3e536d03b5890007813734653bd6fbc40e2af79d298e9448d84e81ea4734	F
7e0f590ddcedeebdbcdd4b72907bb5cb9affb7ffdc5d55c89e57dfc3eae94eb32F
7e3441543e04cea1f513eee2573e964910463f84549bdf1a6c50721b6528186aF
7e3d2b8310ef0375992c9db512db676147c1e9c655d571aff4a18539c7617b44#

ee:V+rF
7e5b27fb6123ab5f0cdd5f923b6c4f144c4cff9c981c132969b3026427a32a17-F
7e64442436c5c1978be36615d69bc4f59a79cef4c9a5819e922bc16f290cdc13F
7e6cf4cf5a25112c185e8d9c2750ce650787af37ded646d8d3923984a1868673F
7e7bc2ad7bb400736ea42cfba2ef80b5d0a56bc7d73625f692b8597a92251297LF
7e8e536933fb7b0d5a5fc7670bcd56337af338f221f564415328864f937088ad
F
7ea4c424cb331a1de27539fd790be4a991e6525f0d33035d854f2e66e0c2e274F
7ea68138245e021dc4dbaf9e1b990e5250e1b72ebca41352896a1b5dbceda2fbUF
7eafe5ff654144eafe243a63bd26f5f8be857f9a6db277149949bba5f768b643
PF
7ec2f032f1c9b576b66559472dbe5f59eff0b891da2e1c9a1794711b872c6cdbfF
7ec31554c4d3119952f3384c6c4e611722a6b4069ee4f6de885660f933e49194F
7ed2c97dedcd344ca3d389d366a728d3d18c9b22b1f567b0d03394574fd4ba2cF
7ed3fc20ba01570a826ffa2af023ade0d8581765238cc534b73fe6e9508c4bebF
7eebede496a10ef7610a306704e8b7a5ad7104bef3763ae5d089c514d1656a99

gg<V+rF
7efe56d9bcad9ff6dc145a50baf931d2125888da4d984a84fd14a509862f3751F
7f007138d6b8afc352f1f7423577591e6c1dddd316b6bad15657662274470ad8eF
7f18b428cb0449058380cba27d10eac85a6389b6c3393ef6454032f2dda04023DF
7f1d9434068b1dab6eb2d4673f1f11fee7c197500b464616bdb606f4cb097f8eWF
7f22cccc77b46b6d72fc3cd7f68664be248f5c21b739751c0122fc78466873069E
7f2bca34d66595ea71392f8a9fe4f631679313d883bbc5d48d3d49e1ceb88d8bE
7f3bdd324d9659e15f12b5165027a55a0cea71990ff77d978912c84bebe836338F
7f4ef7b8732bcac3d9fd39fa13b53c8401e618cc64cf7e86b46a6a0bf9f5ae93F
7f527d338cce3e1cb86323b7257ae02c7e130d6c37bc6ff07f75a20ad82a2e25
F
7f5933636add693e7d9a57c9d29615c25c2163009b4d680b43a93c0f252fc3c4RF
7f67e4364ed1e323c02f8bdeafb086bb8d6633c2da0a3139a1a54be82a87bdecF
7f699df3b1a5a03f46da8dc559615cdabf4c01094c12f89d7bbbbb93f3744af6F
7f6c1ee79dd230a85336204331bee68c57e6de3879ff35719632a2132c9d3c75N

ee:V+rF
7f71841bd15ea189a3946e054f1c018051ce33de76170da0fa7a4ec172429517F
7f851a8769285e3f9758a4eaf850aac198635f11095424df455837066af7c141iF
7f8cb3fbedf15a4146ccc43a641071e7f99fbde04c72526476d5cd90545e4644F
7f98ddb94869395b5d09e7f387eb87ae1829dcd23a0e383391bf1b8f7b2a9dfbF
7fa5ad9d67b6a38b005e9e2a1e8217c78399fa4a6135965a3d32ed6d2ab0889cxF
7fad090d109f3a2e81094996192b76c6a9c2f3dc5bdf9730d806f26705d9ec47F
7fceeee6972a71bd87c407e8be73b29da2cb7fdd6f2197b3e49fe3be552b0f0dF
7fd90181b9a3e062d087509d186c4ef8394aec39ce24e0670b0a4c7b21d8c381F
7fdb130eab949bc403e1c3601e83e6c3cbc7954955279ba1bea21124e1e5de38
F
7fde0881297ab193f65e33fd5c8b564df7735f25fdee512b44a93fc5919686e3F
7fe1420aaf46d2b3e38efd53645a2803c75ef85aa2e51400cf062745f1a1e9ca9F
7feb97ca5ba81f62121c4d6fe734440acedc56ff87444880b72d989261a4148eF
7ffb232f1c8d11186c79f3208453ffcfe309aa5cb3a09181ea598fc82f582228$

ee:V+rF
80196e9f5cfeb1b79fee9a0c7fdadd992ab7aa207db374333f67dbda5f2fd14e	aF
801be54b282724d9d09516d698bc641c19471a40f11821cbf51804f40228e59a^F
801c2058a333ace01ba2317b6297c530b615d43b97c7c076ab0842fec5a12dfbF
801e9bca39684a29a84c368956ed668beef392b230692274c32ffbc1cb714b73F
802a7e88deb752607d0e6f0f44f099a1dfee4747bd86101389d25eccf2a9ebe8eF
802ef81827f925a8e48e7eac8b4f0c0e44a7873cc15a96c696316840d6541191F
80390bf3a08ba0f650c404d34722110ba6e30e0aa373d82bb1bc2d8d2d7d31bapF
8043266fac97f3c92dfeaa8fad590469ad37ab990d86e9ece87829bdd9e0c8aeF
80476ff98812cbbcef61bbadab92341dfb34cec67d6654aa104495f4469a5e98F
804cbacad84b958748331da1bcd0479ae493f31fb8564a84104a6573e7aa7c81	F
8050b0ef335b05d786d15521243cec669562d6625e4d80db07c84aec1e66d0a3tF
805b144f9365a51694ca9ecf28482dd714b37f78fa08e3a4a7a5aa22da4216de F
808073e5962f5fd81e0f89ce66bccad77dea549a509cf522580257f973f2dbe4Z

gg;W+rF
8087b4408319998ae1d6b166c84ecab64a54cea6ca23c0fa10d0108446ac99c1nF
8089409b82d6904e6a2853e0d520b54e8935468e99ddd4cec8394dcee0e731d7fE
808bc13d124b864d8dd90f80437bc5d919d6dcdca1ebbd9efcd56e575fbfb500'F
8090afe9c1843d71bfe8d10d6b4076aea3559e86d8fa4c232dee54817c5b76fblF
809f841a5c44ddbe609d0827d1562e3515efe0f58ca9a5b5495789e578e2f7cfF
80ae1fdd564cfbaee7f977fca0a23cb7bb35f9a6955a26b716894f379759d7d0UF
80b0aaff62516f728ee4d1972185e7b7b5f5d15ea67da82dd19429fac70a5b23-F
80b89881a4e050f35e7e02a7da9f7eeb5a152b057a835557cd8472b6f91d182aF
80b9e73c5db5a194278ac3415303dcf5c49c780dae020e15b55a65a9e02f2a56BE
80bdac5815e2cb87ffd8f9a1347f373f9a9ced0b8d2fe36ed814bd54f4ef39fawF
80bfd0e65eafbe59f9079ccbd7a8c303269a333e10aaddfce933c3cc81907c66aF
80ce6a4a15f013d38eba7effe54a0be427263f17ea3cccd5f299625962e17ef3F
80e8a702983be224224c674404dfed4b8a89aa2c699a0bb3c32dc8c20f0219c9+

ee:V+rF
80f69ad6b79f4c708720c43f742e85b81d91b383f247fed78bd4d579dc9c3358F
80f7c4d43325e0eaf5c03d461abdecaa270e288f97e98c48b11ef953ac3c2ad7F
80fba5d63f2251d74b40f2d94f3fa1ea15c4abee2772339081238b1d17a44eb3F
811548ea9fa1b1fd4ba32a27977ce75a08bd90e1f90d50bbdfaabe36480c3f46lF
8126411e939ed28c342373246930b21454d5af2651f4d36c56e7d17b279978ffF
8127547ec74cf787276b994c2f00085304d697481622d6712560f5c1fde57dd1F
8129ad43222a6a88ffa26b7ed5f36d10b1edede7d67aa145c0880eb6d3058828F
8134bb4793d96d74f2db411ef17a6b86bcdf3847073ba2f4a8d8e89bc0d849c6_F
815665d02d2dd24faf81af70e9152d3a62a47d616ae070372b69b3ce7b0c1e95F
81673643543357b7e306b0565d82bcd642537fefb2eb0244c2dc8b1dbe481c2bF
816c816facf8421458376b99f244ef91c147063ed4f4955fd0e8dae62eccaeb8F
816ca6511f010052482e88ab2a3bafd3be37b7f6544e98aa51c2e521eea8ab265F
8180d23815951b3c5be397846577728116502dad35bbc2dd67b7c4188244e465~

gg;W,sE
8185f310e186803f0af31262808f321254090fced72ee96c77a5b4ecea2ab08cF
81962e4767ff3bdd232b266847805d5a9914ba7ee1f405ee6212d3e9a2ea45d09F
81a303d0e2c1f786e5921377bd64c30c8d1daa75fda45c1e17c45ef28b02c568F
81b2e85bd83c8dc868290121adb4b8821c2da304dd04a69ec5ea65031c46d351

F
81b4e4f401d2402736ceba4627eaafd5b615c2cc45aa4d4f941ea79562045139
LF
81b502f5e282e58db43c00894f89f50523953165c64a408ef983aa2829145c7aF
81bcb4324bc25258c6e46c0bdc146842422c22344fda2af0164660b98db7c0dc
F
81c248f72126ea7b1e33a7f47a8133ab505675f4db87438422eb0a47bb6f2bf0F
81c536f389863d868ed8bc21eae1b2225ce8631429c5df133d0e769c3f340f77F
81ccbdfa61dd66d66bcfc3a8b2aa34c860aeeca888655db0c4a47cfc4855210cF
81d6abea697da32a4834b6bbe7be764845468cc2ee8e089861fd0eb80c2466c6F
81df5804e78ba7e49ce4ceb11f4b7c514d4f06d0ad146b950993c6cb77e58dfaE
81e77a0ae807ac0a5e4579c4ac44dde54b30b6b5c6ab31d335b8c1bd1836ecb27
1N/1|]>jN!F
81ec5721e33cf86aa5a19edb4af8269a95b79b41d2afc6f593319894b7fd8cf4N#F
823e82a094d45f0cabd438920e6e33584712ea5e4c9e767ad9d3d1a34b4ee0e2
ON$F
82a28484b658942b7c372b985b9758e0960b5693341a8ede58595d4285be2863N%F
82f169e42c36e9579026a6d56d46f2cbe59221a611192fe96b613ff527e57a1c
N&F
836c3fcced9a9357e2eead69c55ef322cb19c6fed119b1eae1877c6b2bd51169?N'F
83d237d121542e1a8974ca5404efc06ebabca5aa5ab1f7f036ed16f3396c2445N(F
843def5f9cabf23dde3a6c7cc1d52f68406f3af88c42d2d84dfe7a35cca79197
CN)F
84b71cd28250d68d8dd0c9a9da4983782f0ef2c5888c5734b7d12841ff61313bN*F
851583dc78e98a516586667fe472405624392dbb850b366aac5e87fde83e922eN+F
85cd5123793aa450727948cc2dc0222838b43e3ba8e5301199710b0f897a9f21N,F
86754c49d208af8b291d53143af752244a68d88e0b4ccbd4efb6811386339d4caN-F
8739cf31df198902b5c4e96ff918fdcbce1f988373e266baf0f5836a83776919N.F
8799ebab64d83170ce71b98732944e96f18743f83950b9452d4ca10c21d7455a

ee:V+rF
81f4f035197f26565bfc9caddcd8374921d1e73e9c89c65d4769e9daf437a158F
81fe53c540c2219cdfff5019d61db2306219389015797fa7f76cb1b9d772482a	QF
820151304111db2bd87d6e5ae6446b11a958a081a44feb85b88cf0ec6c550aed
HF
820567529a85b68ae8094f0be50f5116b0622ed1c526afa0e239f84b9bcb0860pF
820ba4ad8ead8e86f08c52f1683fb89e78daca198b5a3d010ccbda6eeb6afeed
#F
821164fdb3e807716631102ab1778e4736d70fc13bfc34bebdebe03bcfc8510f@F
82146c665ec6adb6b5a44f5163ac78834431f9d37ddbeee4cc990634d979481b
F
821ad7280fd9322e235862f73d1cb6c433fe48e14911cbc39141b2df2732bc01F
821d095b31cdbab402488cd14bacefa75cb451e7fbd956f61a6bc92a68d59f68F
821df7321c6fd01dc77f9435ba556d7b08cfdfdb262113c4223883e34adeedf3F
82269d23d95a9f1e1e213464701f07feb1fb5233bc66364a7b39d1a25b4a7a72
F
822adbeedf758cb1febec29ff177d207923b6e3c24749077ca4f3a684d593d1cF
82386943e7fd9af89f6c5d8dcb1845c1484cf6a8e11a055c062e3c11deb5110c#

ff;V+rF
824340802392135f9a064de630acd55a619c7b8240b3aa7ae13f664637c0f023-F
8244566af4a36c890bd6abe69ab5f9fd27a7847a32c6063c2ec5fb6de40b84feF
8246ba658ab0a84cdf2b467c142701ec560b9ced3db90dfd04a7275cb2636566F
8251d9d6d6785ae0ed2231e5acd6b3d6b86a215d008b16ed8f78ea929cfc9c4d
JF
82615b5f75a4fb89fd8a9662bc57f478e82e61656145912b4cf6dc7349a9b42d
F
826c87462956fa022a02326f271d542600fd73a7be32feb4eb7108cbc8b45eee{E
82770f241e9bdc035784ea9189503fbe592d5c29147b6f0860949963afbefbe1hF
82822855575f68931a78cb69d0b2b66a872fb63e31213c05cb77147946c29c41F
828e5f8c216c003561b21fac3ee1c2a2c2d556fe14b7f7eb5cecff383dcdcdde
F
828fe4eb26915648840d50ea3daa571c3735822ed66eced81dd20b12dff3e10e$F
829050a62694fea5287076cdabeec66b15fe994809fcdd5931ebb992d47fecd4F
82932d0635147c1a6bbad3358a167d3e6f1a59a1ee3cce64d41ef8729a3f2993tF
82943aa98d57823fabd6521b0364b533551b4f5b299febc13bc41d5342b5583c/

ee:V+rF
82a64c4e305a429be421cace128685a29a5971da0cb54ac1d883f150b1f92460F
82af7be38d0c8eb49df265c4c0138bdc35cb7ac26a1b6e3a4d0f0a47d293dc93
F
82b1d1dfa51bb5a8958691fdfa3bcacef757cb4afe47f1a082dab853cf9650d3uF
82b2eaccefb7228d0de8dd9a88417b5a3b5cd4911bacf3931b092c0c35f16e7a|F
82bf486bffe227eaa4681fdcf6cb4c2225d25b5dbdad8b4009f3da4a506834efF
82c766a327f786b1d8e1cf34a5ed50e63b48ed813b1e42b1cdf8bdbe7d349866$F
82cc32e8088438f5d4fc7f78b91aff778d193cc5d296a1afeec04f69ee1134a3F
82d5ee0b6f067209f21584e5acc7fc2bea3ab64f1d41f52bbe4bddc612f4670dF
82d73a39a7efd415652fcfc12d6bf4b9c9213db0f32c9c81ec5b93e7020c715fF
82d9617a439490782837e05a5e05310b0748f064a0556d264fbc615afd85671bF
82e182e512caa6c722313fe432c89e81a61b1c021c5fa0e223a163e77c95ce6e	mF
82e901dcdc6ecc6088013e726925ea0a208b449014b09f844465ad5d7b305805F
82eb45d206c4798cbb97d743814081a5b2e5621151b5d0be9cb94ebcdb32447a,

ee:V+rF
82f985084dd4473e97f352c4919005eac36a824d8c9490c80095912a2f94e3c5
F
82fcde3856cc70e10a4bd10d93452cca394045a7afa452b0880881752f2c6b56F
8300c30550c66d4567d56de5063d79d5818aea066707cfcf6638dd2811bd74fcF
830680293bf892ad9b57630cd1fd50d4415343677c361c32b8b849c399daeb14
F
830b3c9f628ae0632f8a286c53dd687d6d9700525aa381704ed8d5f152ff43d5F
8317594c4733bc6fd9c13e0001d962d14e7bffb83ed66e6337f6b8a490067ea9F
8319e904c4b86f6892579492778456a31dcdbb29d4f7b62060dba26486be2a85	+F
832470ee4b64e39723111ada3304a733f57c404fb89c7383123a52f33bbde6d6F
83282159f5c6971ea89b738532ec3620b616c1b9d90ff2a62527714e210cad05	F
833dc73a5ec23e1c5d73db93091846da2a990c4c750e903a4a09f3a61282dab0\F
8359e9ef711ab7df3dd2ff2d776303381cb9569b28010fc635d1dc38c63d0a3c
F
835e86766eabc1d9ae0e8b151d9721a415b5dfdc6b9dc31497b790dc7f51e60dF
836ae43529ca6681c98238726bad12871f01ac8436aa3e19605c87ec7aded177

ff:V+rF
836e44d1bc907b9e41d6d905730da4fdf18d002f62676006795789a1aaa6084cE
8376cfa512fe6b2ff76656a962eb9991e84736e4a697d521ce94ef01b76d8224~F
83798801595394e9798351e90ce24993027044de3f66b95c7da60059c1e8b1e1F
838de1ef14179e1a8bb9c6a1bab3b688e72d7571e8442fa520294f469817484ekF
838f9c1a4495b9f9bd85ed4019e8c2dc8ac645f72e221541ed03338c1cea45bdF
839520c8f5c973a577f0bb417d4afcf5cee1ae5ae2f72e64134b38bae1468c0cF
8398bd6b079096f5128dc71162f6fb902418319a1f157c08cd55e55ea7b42815
F
839aadc2fbe0a7a4b708e39eb1e3e9359bbbad64641fd674e425f561de5d004aF
83b0eba9581758f02b5754034154c3a6a53b89674d90775b537b093b6d1abebf'F
83b3cec745768f57ddcdabe20c4c848fee7126552012cc9fa7a1be366825f4ad{F
83b8bc9adb407e5d032b0b7036ab81ae352bb583870b195e840ac2f094c2cde6`F
83c007c9ec430e38dbcdce8b868daa1718da2090b7ef60980dfaeff2c633aa2fF
83c818ad04bf6b2bffa2f694713b5cf4daf9cb03a8d10c5c5bf31c984bf9fd5b

ee:V+rF
83d5e8fcf034f22af47eccbbd1c693274a94cfc7afdec007e5cebcb5d3ed2a73F
83d61057ed2eda189f751ce319a8369da48465187416f37a4dbc5db0b9df35a8]F
83da2d9387fb7b54637b838d32f6027693e46e5eaa5f85a337fda688683830f5F
83e709af69a954f17415b836c06c639e57234896cfbc5a9d849530590fd960efF
83e71037aa03cb56d8e5d9d0d2f0e410673cb723d0cf4f81dff15ea65830fd59F
83e83351bd9f8e17bb928673f2236a6035cf3a335789585a60a5d5068c2c8b23F
8408d0aca2bfcaaac96c7f2344996a46fdebe107dd0cb02f4af7dbdca094e232F
840f1eeb8f5f65eb3e144edba32348ee678812d22065a6e75c237879369172b36F
841781e279649ca9fced8e74583d9a30e6d5e96023b689f339cd0c6814f8a746<F
841d060e918275386a6f0807073b7dfbf1d8b8ef4e46c4ac35317a6f61457d8e
pF
842133034fea3edd8842d20f2ab2a87bc76f467525d1a38c9db15fab32ad4a5aF
84217b8ac653dfecde5e7761d967ffab45d9ea928e22a4a2cd5a502719a1a0b2F
84338ef31ca6974b5061ab6de6f266737dfa9cd9bfd5636c91498adb8d422130o

ee:V+rF
843fb795c9bf323f16859c41219123409abcc114812537da012befe15091fbc3F
84429c34c87f336378bdb26019944d56abac80c14e6c4ee130584e9a6b1042d3F
844cd40a498923147207285c6be1f1005d82c0c81ce3d61538110f24c99a8732F
84515e054cf47fee3e466382e25e19eb92f6f9947741105ea5f6071f7fe18185F
84534b4e8a9f57e1d6cedeafa786721a479e210dc0b2bc07dd005e62c961e69e$F
8453856c66fc79e7ec946e471ab4cddd8112886e40b99a72093c616592b2258fF
8468dd2d01e7228ce1d031241b5387d85911912180e2b91324d509c7631724aeF
8477e56cf835d806a8f5345ebff218dfbceb351c7bca81b9aa806a2fa8930f02	F
847a5e41805b10521ebc6aff29431992c0a22a8d17c634a1e13970158fa1af9cF
8480c9c162030638d7e1aeafac122629e6446c5a5c93910cdd0ea2bdc51c5597F
849380b5dd59adac484f86c0be1242d6fe1a44e5e1ad0f83c18bf6a82a4f531fF
84a70ceb4fc3a611fb4f2317063db48a3627bf5b481b3c89956e1f1e9fa9f5fc
F
84b67246d4b4d43e8127de0275d0f6e2904295a58a879e7d64b8a9d7890561e9/

ee:V+rF
84b8b611d8300bcaa1b8a5f55f2a12f6469df74e32e649b9b505e76925339810
F
84e0987f67e674a41976b9cd147cec00e6c57db8a4feeb9b141b7fb607b890efF
84ea46ab16a2d8ddddcb890ba2ccf11b3c873260b9756f1ed64d7aa1a779ac5eF
84eacac2027d38ab8ac05edb1c4325c192f14bb386175f2256239f2d4d9d32b8F
84eb961185970d439cbddea77f57986510cc0e948d47a65f64173b75fa19949bF
84ee79c0b96353a8ac5b4d46b6624e17ed80e67fe48583aac6c73b9b4deea759=F
84f175bef4d2561cae46398abd9317955cdbe6a2c0352227323da35cedc29948F
84fb40705d6f0704a0543373e2e266ea3565b3125d70e1cf4d3a2ef8497670a0DF
84ff86ac505c0857bbf75916d7ef4b6be65454e5dd5ec6ed67ec662a819c10e0
aF
850766245b53884b841d001909aa89898b167cf79a244d26c44c42dd775019c3;F
8509c76026145b29ba6f1b8ae37a82d1ed82aae0b7d56716d065d753c42837f3
F
8509fe4641cb16b24f3aced3e8cb56ef28648055b03221b4d4cb4017259e1995F
850be6d438290af4b3c31805a40c2f8a88e4e751bafa1bb02b6b884736f80ef2

ee:V+rF
8519d3cb6d82e68f50832778a44e1f676b5fbb85f891a07751e7f2c0767112bcF
8528777e2d5d089f809fd37c5c722627e07d23a1c4a116c83e8ff648c57058b9F
852bab23cc3bdff5b4cdf1f101f36a4d1fd4e8d3e570d399b4ef0b06e0e29536F
85419f90d3d3f07662a30384cc8ac45f87402b540d725dd0f8c9705d2c814733
F
85452769364c8efbb31876c1f6d55993159c1055188c65ea7c17556d78ea87adgF
8547960e747f135c2514a024771cf2225c649ca891512c2dd1069a06138796a8F
854eda8da3ba3e3e7ccc94e40250bb1351aa11df12f57ddce1e307ae0bf448e9PF
8552fe474d6c38b9a301d6273b81897005c2a518b97ad149df81dca168a8bdc6F
85883036219c6afb70af3efeedd40855b4513b05e5a5134abc56c4b95841a125
hF
858c36d8de6e26caf93ad7dc07224b2b333fcf1617a211b7303e44cdd15a6f3dF
85ac0468355fd6847c79849e947fd3b5d88f606ad3aa6fd06cb4aca3fe3c9fc8JF
85b37a5fd5787e7ba6d0b814f2b7c0de2df1e314d12a9e9ec3fd2cd80e7dbf28>F
85c0d75554f340d99942609a8488c0ad5b2e4ddc0e40c1192056ab8ab8395492

ff;V+rF
85d24ca3ceecf07ce09d89a8ea7abcb5f605c7de3bd556f87b0654c517fd5759F
85de1b747c97e7d16a742f3f0789c4d8761e3b44c28ff437bc8b47499a9132adF
86101a94927cf01319d801575aa4ea26e63efa577a5431856e0329f06a994596F
86216059235592e65e7652d91f110d715907836ae9f6759187c8cf877a851e69F
862a87260cad27824364c01e25cd821b1fc2a084f3522fee0b5654d684839796F
8634b9087fce679a0f75d56b47ee7f5bab818bafc65af5c3bbf22d74b7807c3c;E
8638584ccb7fcde8b4799f13f6a58ef2c129baba95c41aeb504453c5262416a1F
8649585113a6705fe59be338b82b0ec406c0c3351b940dbebdffabd40fbc2eb5]F
864bee28e84214e17a2569dc4782fe389e64424fc470fc80157b86f2bdf0df03FF
865bb89dcd4d8816e485ab34a083b55c7d4056ac265766974695a87da62d8aeeF
86614c497d063d072a270460ce1367ee6647bfa57eb10ec1f02b27e267bfff67F
8667cee91ed1aa014f71555f076cfab5dd62a042d3dc7ea1d86ef30655b038ddF
8670eed5135654aa066965442ce0915cbf933f4742d0a6dab8b6dfc7ecc2f773;

ee:V+rF
8682aa231a96b16cfd29d6bcb965dc552b13f5ce5e91dc71b4cb0725eb72bf7bF
868a84b5cfeae8a5e75edd91fc853a5ed3490b4de3805f6ff0020f5483875122|F
86993bde440204eca01ab08264c50ea2e67b216b8b0460a9abd7ed1e48864926F
86b3087af0b5a421efcfc192824973fcedcaee28a0e78bdb52d9101ffee96ebcF
86b8329276455f1ab7137f0bfbed2c18288a75bb75932393695583ae82613063
F
86b9d3e949b76b70e8c793f03ef07004f125e978056735b094814e3c282208a6F
86cef284a27c740098bf41032dcb527c08c5847589bc56cd6dda05d37f714bdcF
86d0b148abfa317696a046ac187cb479b242ea3f9ec769e6891130395ea172a9F
86d37b5ad18b07654ecb4a92153db1f1929859e2e00c1a74b0455e6a33a22949F
86f47f4e0ba937bd5cc3e11936092ae2624f85a10417a53a3620844161158224F
8717e76e453ff6da56721f14fb3f66a602f200c27eb0d7730ad11ad9f0e696c4
F
8724fc26052010a537fbffaecee3413ede14b44646e26a456c4c8695f5f259c0F
8737c27147724574d3a8eca1a97c42dbd392c654e638efa67e05c34316dbefa8h

ee:V+rF
87421442fb8dc3f0b7025e35dcc33c47b33e35e6cff668106fc871a7fdc443b7F
8747532845b7b53c68c46cbd4ae380333a36f007a086d57f8e04ec356181bc5d
F
874d8d26f7b80bc0f9296f56fd0bce77ced84db38f8562499930d8c065c0c040F
8764032443efee4dc7bfb0ee1a11749205880cd86b230ad538346b697120c5e7	F
87690efabf1c1904d1640276e18c4a1568f33f6688bfde4c8352defdd62b25d4F
87818b04247bfad1a3a5ad6b7d4ba90f571e7df0d267da4a66fd5e1e17409c65UF
87841863f56822350511aa76203106e84213cbf0f0d73dbadb356aac7fe91054F
878572277531168e4e6b34f6078224450001b713981b2781b0ccb572c1db7c3aF
878bd3f432c1a1de0ae5f44ae295f84e0ba2eb10d8864b4c35eb61a0a324b21eF
878c505e878a659e3fe83b051ba1014e223ab1130afed6d39765703c451945b3
F
878d2dbcd884adb9e2de690242d04710df89bee67b51aa86e9468e01de78341bF
878e4a65ea92ff450fd8d2bd226c5bc9e55bcd148895af1d80aec4ad27528da7F
879103353158ba94017ff99828895da2eeec60fae6276746aa90627aa3867891

ee:V+rF
87aee3a9528b247730a778c50eab6e97da58d331049a063fa5f651d993db29d5
F
87b4bf85d74acb5f568e2cb39c5b3f1c972eba5db5f0219021c385fcf2d297327F
87b930e9a82a5887d60c5bf35a95284a59744832eca1423a916a46ac5dc807a3F
87bd7b630c33f8be6348fd87af02cdb167d891fac4dc956b41cfd5911def169aF
87c1a04fd7037d13c6be98a8a975ef7a41eec66aa9031b781b61eabe9107ce9bF
87c30f42a079f461de618eaafd1eeb3225bf684cb0b4fe11da401f0550be3c80F
87d2bce399fdc13d6471dbc90583d7e69c82b39679f9b844bea1a2f3051c3d10F
87d3a6a27aa6179e43d778cec0765e166b68510a391d6eea5236b2e70d6d746bF
87db2fe7caa5472a08068b5229089b79f46799961c76df49341071e86736a23eF
87e7e547e429b8f05895e13d2852cf0bb18f91a4aba2a1bddc445c950284fc3aF
87fc214b49a5aba9c5d113e739d9654287b4a0272123ff8eead1a12b7c845ec3OF
87fe3fb7cde1d8eee7a0811446e9f57ce979666bc9e6e29ac3cc9efc60d86d02
F
880ff35253177a36cd35ad8763cde4cb91281f1e945561e8856f21de6d706dbb

ee:V+rF
88400b854d053822b230b8e0402132b7559ddccd811a7abcedeb1406f7bd8cbdlF
88425ec1660289732da5de1bf61433d763b6a1dd261bd1f618a21bbad1e482ebF
8862347f9d7582ff00f24363fe2ec9973c30d8b3a4bb2acbaffe35de8e6b6dc0`F
8862c2d66552b96db725de231e282bb308785e3aceaa1a3373dd4a21a3279f14F
8864cd46b197d894c0037ac70b483f8091d39212b9cf6ace09e8c117d76a1c12F
88829e504b63e6f7b3b0f74d257ab87d6d2ac4c04e4220a90e33576fdc11d02f>F
888ebbd06b84707dedf11dfd38f8932aad6140dc08932e3e14ac9591d14843c5F
889cf274fa9d2dc353f72daefeafeef0bab8bbc22a11e69f5009602f524dfc5f_F
88ab2f3a84ae0b670762548a3b07213bc1a96a8249ebb3ac49b9d659b4187823F
88ac00911754d4623eae65cfa475ed5082d7d2b0f2ed678b1b27991079abf58c
3F
88ac66f78b2cf64dc6ea2d02f58193bd752cb598be4fa33a9328f2bf4d42de00F
88bc32f0b32b7bb8891d9dd012f0481bd2103ca60cadb3ebc387b8645c331524F
88cbca784ae7af25ab7e769129e7fd6d1e91281dc714e9bc35a46dfde2da5624V
1N>1|]>jN0F
88d0132317540d77db005b570d44a340644516f643914b0a811161f3f3f83a7fcN2F
895038cbd6764ef3eb9ee3cd61f7aeb95255a9dab0f3a8da8ecf81d235a2abc1N3F
89fe97926c4d82b3dbe9d1b08249e01972849f4771aa0ffff539f310b5c68178N4F
8aac2519f49dcdc64ce5554ba02dde6b31912d07ee75f879d789a0439eeb22ecN5F
8b7baa93242958102343838092c3c8f2c9699b186e25f62b224a2810946a81d4jN6F
8be164f0d67b7adb4850c664fc43b933559317a3a400aea58cb4c0f28d317ff3N7F
8c51f1c38ad47d554e10f738e37c0bf122f76f4859f755e0449895448111fdfb	N8F
8d0c9dc0f9481cf8541a333911be9aaa997c3a44c8cccd0692a6c28d7a5cc0afN9F
8dbad9b74358ef443eacae1628f33b8cf52128bfd4a1e2ad38ef0ec9549a22c4PN:F
8e736c3e7e6197e2f51879707a4e058e188e3e707c7a986b9cfb7846c920b11b}N;F
8f33285bb25298291523ef6f04cb95fa5815d34f7b05d4efa5f5308614c6a8dbN<F
8ffaad6b295a49f6f99b79f05ff9da300f9ed61b1611dbc6384efd5e0d7384d0JN=F
9094f634e973446d22eec7485aece9a4f3294db660812abe442e6d174a51ee34T

ee:V+rF
88e20a1e34cd524371d77d54b3e1c9679b5fc0a76238556241eba29703e64e10&F
88e796afa3934d3cefb09a6a575714bdc8aede8ee6a3c6b7be0bb59a130d5efdF
88e98b9e84008f81960ec7ef7833a591eded866cb407e6fef47c13d1ecb21d53{F
88ebbac297f77c53cd09a2f137fda3254023224d3da2a351b153770a4ada109f~F
88ec95b43c8491db9c18162f1e7fba8a23bdd4c936af58ebbc5e3ca5294bfb53
jF
88ee54419e99f4dacae891d93199c6fed6512d9a534c7d923a9477877d953d6aF
8901005d391fcf6247d95caeaae9763898d0d5a0e8da308e73380bbdefdbbb1c>F
8908f58fb71fd39056da9b792dd69e358735856d43352a085ffea8b4b8f2039eF
891dab92096ecafec7121bace38c5d802443f838cef21422beb6a451c0e0892dYF
89218a788c99c93aaa563b09b3f7b71ed061025bda32116e0f5ad78d034e5d949F
892bbb9cf85d74f25b2bd5cf3702f0da63f86e4093b201704e571b7d86a65f14JF
892fa4df2150169a5c8680af75e4e63f2ffbf5ca0f9dafb19d1928769a5769b9F
894926755bf0b5caaf2195043acd56dcc5dc992c1c51411a5e923a6e2e1d55cb?

ee:V+rF
89508e57764f6439d8043a9ae25c798163d3dc7e1ea5019bab2063d6eaafb9c3
dF
89663c4870645c61c09aa110191348cb2ce24502cea8c4fffd24cf917b5e31b9F
89818b9dde137228b185c849e8eec7f90bed6867be5b294a8b8121f52776af6agF
898a07f35eaa8781f7f96ee6666297c5864472115945d11efcee3bfabc801e33KF
898a882b2bfc15fc532825fa940804005432ab222c1efaacec472c1c18aa8c66iF
898e4f478919925f999cecc6d8765d5ca6196494ad8200b1c02607de58303982F
89988277f04bdfb0831030270ba38286c5de52d83e5c015250fa99a89d9f5a47F
89a42b57b8107e340a51b81c28d25743fa831b6a86f64bbbe3b811eba4226e53F
89b015eb0d04659b187b7cae8d68fd38cdfd6ebc31ef6a4cc9432e777fe5c452F
89ba59bcc18f02cf622a16a2b4485ddbebf2c0e577d2b9cc5b891f7f18b2b729yF
89bf5b84dc71e5ad5f0d9d9867283539d89d67b1aa0c88f54a59c8766c3d2351F
89c58d30f7f1b409bf2172a4eb140ffdd938bbe72118610420ec4abc9c64eff6F
89fc26f9b9704d242bcd1974e846283609f11bf4dc47d614efae548b2b836ec9	

ee:V+rF
8a0bacc73339833881bc5ae7fa62eafa7a9c0011b40065f3a69fb02d298f29d6F
8a1a847b55b0f0c7eb4ee01caaddbacba34459dac20fbc69bf3e33941d234f40	F
8a3167ab075b7b5fb344b2c1a8b338bb5fe197f76d476082cb8f2c3ab6e464d3F
8a45d170c2b696356237faac6e20f84a8fe83b9b0d0990de4c51df8c043ae548F
8a462bdff8ebc77ce5f8cf6eb1d98625e34218cd0b64485d9b9e6e7837d422f7F
8a5fd0b970dc3eb282790ae8ea380ab02a73599a63846085865e041e8624d19bF
8a6c2691d1645347df9eff452b78fb18042623b1204c96aafae8161528c51327
F
8a6cef14e08d6e8b37d66e40c1ac1a7bedf36720f015c5cf16ef968d5bd61eb9F
8a6f4b746d5edf5cd1a9c83d8f03ddbe3050f70230be328aa88328d12100ea4bF
8a7f53c7e5c8a77fc603887cb200d840cb724658ff8f2439c41293131f94be82F
8a874d1a0c3f0dce30ef48f0095dafcb59e864b2b89528a61ee1b1d0a5dcfb7fOF
8a8a993d640a917f86f781a7b6f422fb2bc8f0cdeafa9a8b16d5205c76f2a164F
8aa95e78921113508fef7b52fbf20b5c2731cc1b9798d653a482bf00087462c1

ff:V+rF
8ab724702b39a664d2114819b5f3c29149c945a1f5443d7e7e4672d694b15c90F
8ace9615be81aa1aef785201bea8d1d530ab9d51947834eb409d60ec032e56d0E
8ad876dd83b3d0a6435b5decb5ebce5c58c33e7d6fe1fd43a96a9f7e6afcb5625F
8ada58179dcbbef50383829ff646e8482d88b3597602d1e89527ff2801adc78bEF
8afb8e27332a8489152d37ca03c25098d73ea51e0982b87f6a7bb7d35104b927F
8b0d31d3b3732537ed9539107e868dbb4725488aa14e7a5070bee4b31e133318F
8b27ff2d6ae464c9929368b71564984ac614007abaed4abfb490c301cdd341deF
8b2f892532b5441db04bb9a1d3ad5ae901202de8ca4725355c38b6ac842c3f60F
8b331529abc56930e532f91b8634eaa719301817f62a7a7fbbc720594baf85da	F
8b49fbdabac5e8dd32d8de8826af7fee4b0eeab0828f5ad71004efba08ce1b40YF
8b57170fd0541d89c862ecea52f823ede947a5b16983a9646cf0c6e4970996b4JF
8b60c6a9194e57ad101ad2a28015f644b915aa5c958a5f8b0e68def14394fa13
F
8b700371dc8370c8630ae79ceb9e1fea3cdcdc691595db63eb30d8a874968077

ff:V+rE
8b82511897f48ce484e303fe650c32ea1191e71ee0cbd9aff580743fa4f9067cAF
8b93611a7e50ab8b817c59d6ef504cf63f14b1ba210b4da69add3f3176898478{F
8b9983515bad07afac7d8a923e4244430a10f0e33fb043f5940c02b4b63188b7F
8ba208735c422fc7201d30c4eee2567d7d1db7cfe28590c93e563015db58818bF
8ba45a2931417326f5988ff2fa9db54c083bfab2f5fe260ea31072a26b0d9adbF
8baa36fb50bc4850b5ac66dac93cb27812550ac6f755518bb37973c3a49e25e0[F
8bad0cae9095a9462eee405070201f5aa90c8754e0b955a3e7e3599af9f81ffbF
8bad4d40202c32d3b92c589f87621067f44ac2cd0793dc3c8ca85d82dc069603NF
8bb27e3133d87750b1501993b54e0bc9006242f30c7f46e98b7e0bc0a450cf2fF
8bb3427e24cc96d1a03b8501420a96372b0121baf87a18de170d70b0423f324eF
8bc7d7a6d1b39eee668c11eb933d1cb38ebd708d11b2c0b2b1a7891e74af0cfbF
8bcc89f7bef113e056e226e9e5c3e3be2396e0d1fa312a4a061ee85ad8c52a3aAF
8bdb42f75a635ac45d5c4a26f945cec79c82329639357232a0aad25797148f95

ee:V+rF
8bebe621091a0ae4cea699aab647472b02128fdedc6cd35f7a87166bd62ed233yF
8beccf052a2dbefb6d4d3598f864bc4c75f6f3a8b74ae1959275af52a7a8f4c0,F
8bf0a6fa452bb777d2800beaf0ba2e84f3dd1b17964e1b1bb26b099bcd5ba413F
8c0250c573335738373e9064ccc227bb57bf3a3ce5d859aa2fe9f129bbc28592hF
8c0e209a9b3e465d9d43e1e9e5585d8222d61a73748d1a2e8ce486e8b2b25715XF
8c0eff6015d46baf10cb337069eb8d7100741d665dddd559e9e053509293cad7,F
8c178f2dd6153d2d3dcfef1a3398ac4285de7accb9561c9a03366def1b7c2aa3
F
8c1a2436bb9993077d1787d888e9de96eb7d1ce37e361e8ed8f64c131ab0b58e0F
8c1afba082bedaba9392d11b613759a65431711c73e71af2ca4c1d2710b71ac5
F
8c2a340bb8e3487639e7851ddf9b80b263ca137dee7948eceddfd372f4b80882F
8c2b3aa763d6d464e67be783b62d083cadc0aa9caf7fd24997ebcb514c44a4b2	=F
8c2f38d98708ff0e8889fa8f45f759f08f4ec491e20d77dfbd8b7ad4a6bc79b2FF
8c4048ad0a30efd78b835e73ee590a52730bf658e4ee011dd963e908a4dbad81<

ee:V+rF
8c61ae91b0b15370cc12465214b2a97e5f414aec4feb6af550ac11024416aaa4F
8c62263350421e7c3081b4a531f8e15ef5bfb5e410a34687ca4a799ff23362efF
8c78bd9be20532927c0a937e33b0befaa0f49afcab1f09654f5004054cf179b0F
8c834bac2f30be752f112c1cc6098fa621dd2400df835b51ee13e22bd5c05807>F
8c8b857999a32f70ec103af37b684d4c2eb482a3f8d75f62cec86acb6c10e940cF
8c8d68b411cf4b1553f6d61ec9e5e792aab640f1b6ce5645df2f4da01896ad23F
8c9ca7fef03b651b6cf4439fc8f4e9406e901baac07b1d86a9d94eedeb2b84cc<F
8cab4a117a1efc20543417ed7f4d69f0626329800f58029dc586d0a2bdadea33F
8ccfeff30f33569622e94d656bd899c28dec3d943fe48b0140ff2230c98cf112F
8cd2d58f528256baddd73bebea799773f83bd54624d090696d0c2ca0cac8656d	F
8cddf6415beefe785c3a074c6907be271292411506ead04f691c5b753a40fb9c*F
8cdf3d0ccf31842dffcd39b5f3b05819fc442a375c03a3212e7b51db17f53e29	}F
8ce3c00b5ddec20bc2e8b9298da33c7143687fe46bc2765f98f31a35a820ac4d

ee:V+rF
8d2234f4b3652ffa6caf553d843f040d43d53c10ec6156b8de9fbd3efb4aef2c
F
8d3bcb06b72e062aa3717dc899aa7260d669eb53ff0fc27e1090f66617498a96F
8d43d74f369183dc4073b21eb34b054828ea394433bb870f7b75b636e1135b24uF
8d5c171c9ce6a333fe8241291edf73b4b6bbed0df2258efac8cfac13210aba97F
8d6cfc5c9cef32a028f7938e7be7de7b81bde37d434b23891fb9c2f0583c18dfF
8d73e99ddd2060604e1a2bddc4b10b1b92cf6f81b0d2a05a103cebd6d052a316
F
8d7b3ce7f953eba64eb5ea6f0a0fd7b8a9e05c1d43bd8fa681d19fe3a735e568F
8d89498cb8dcf0209edf2265d251f9c645f540e964d455d6554b04f5f5f6edd8F
8d8b3cb385da57417205c3d9356d8976758920c3bc55610e49f55d64121a248eF
8d8f18480a50ae9e2993b7bee4e3a0d583f2b6288ec60e32b2b42a5b4256456aF
8d95806a7fbf5e875e27f1dac6cd557d87cc508a301218b36c67eb9012718b1aF
8d96cac84dd7d2d8bf80953662039db4ad42350b6281599a0f5b97a679b9c4b2F
8db5b248a66cb5ad1ed9c3264fe68eb2d2de4e9b3a5c7cc07f61bde703d26938	\

ee:V+rF
8dbf315b824ef3ed709ed82b3c42515cc6137b6f4eaf95ccff91f5d362b86985hF
8dc48d5e4e60131ad36fe3003497d6d355365e66c85a79b791c2245839838f72F
8dce1ab16065eccc2ffb9c5d0e51f15c77fa6e7e03bae26aa3ebbd9092a330a2F
8dd767740e6b6382366fcbecc18ee6a8aa1e5cd856ce2b54b3611960dc3c297e~F
8debaae538b7c7704b4ad782c4f0a725f3c0977f97d9cde4eb6a1546e54f02e7
F
8dedf2da6f27ca502253716ed29c2de2e1c11c34463b46e12d9e88053e48796cF
8df89d78d785928efa5b8d059e96ce33ffe0c9356663c9acb50ce3ec8c660d92F
8e01728503e8663cde52ff2eb87bcbcd9a04b60fa17e1729dc2658f1cce309dcF
8e0d749ba5b5f6a9925903f7cb854321aba39a3bc393c295fbbff22c33feb07cF
8e35267d29e2ee8a7d9678927b89dd4a07137e32a7f920844428b1f94aaf2c97F
8e6103f5bc92eabbe008d9d10cd7ea86a1fd82eed882657037c36f9c0dd9ef59%F
8e64b7d56dda27658b854cd7ae4711c43c6b16b97ee01075b4c86e7bea44f202F
8e6626556734c046cef5124024bb71c2d64d98b0563d3b93b4769c8f47380342

ee:V+rF
8e85466eac6dba299f3f8211333d50827e103a67a8296884c3d1d1a87ce8a828HF
8e8d757181381eff83e8b40078f2dd69e053551b72a94cd397d0ddcad18a61ee
2F
8e8d874e43fcfca807986a24918c2f7b0c82f04d8a0ca32bc0d9523000380ae8F
8eb970d9067e83d78cc7fabc26ab7bd356ac7bdd924f37cc65f1880942065026F
8ece8095faf9fc05572d63b861d8bc795ed3d56a7c3235a44d3ee07d1403cde5F
8ed81fb816e95c0feb27e37fdf7922b9999dfc31e8e871d968bf849bd8858bc9lF
8edd67ec853916a9acaf2fddad8db6c86590d7e4c9f7039a7a22270cf6eba4a4F
8ee9327d2fb76742bd611491c6f916eebd397da0976737f7b48eec36a25080b9zF
8ef9940c8eab06db4d162a8e62feb96b91bf5674ca74e3d18247cbacdb1fedd1F
8f01b6b2a6ce4e4129d3b25510ee332c113e0f671df54f56ad2dff8e711a11b8HF
8f060c38fbe87356d18b29d60da5dae1ab1bb783fbe9d75c1738ca0ab27b8ec6F
8f21403b3615c8a3c67833bcb49d11b4c3b80d768a6bdba42abe5d2b299d9cb3	*F
8f22a24548ec519571fd7dcc4779339bb29955be70e289533d286d4069cdfe23

ee:V+rF
8f47718dafddfb7d6dc1a738692f3af308d282de65b923b319975a317ee602d3F
8f4946bea37ca0505511d6afe2aeaedbca2a9b61c752de65d10866dcea00fad4F
8f4f01e9c17c3579c8a8e8757582b5911c301c9f5219d0fa56b868db7964640f,F
8f596e23215f48c31a9bb115c327431b21431ac93d7279b39dc998ca0bdfc6b8F
8f63c53cfad328c376db111c9f46d7f6c7de014b98eb16dd9bbcf62583303adbF
8f6430d25a368ef161d771713f41a8108fe1562d0f2f53e1a94254edcc76e656F
8f8cfe9eb61a9f25ca7e0e1a0141cb8189a5465ea0cb8dd6c524a2ef72866ea8F
8f9c62b62ee309f73ecbf3c62a51cb3d3b553a7505e51047083926355d41e0cdjF
8faaf8f128a420775ca80ce1a715e9558ae61ebfead1106052e080d3192d7162
,F
8fab540ec8ac058e28cb3e62a08c210f00ce22695ad5a2b0412d48e0f77c285asF
8fbe338dd8adc0ef568214985a4b86d964a490b7b5eb963f88ed406169b64c43F
8fefb0595d7ec2b0969e86042785c698809542ecd2b793434519146c6285a65e*F
8ff288d2044bc096fa50399fcc642f5cb7c09ba23f131fb8b2386f6228076ff1

ee:V+rF
9006cdd20e1088f1fdd49320df4c8447cf22d2feb90151205e9288920768b599<F
9006d58c6ebd992f1413230a4531d1584921f01326a875a717363abde71d6b03F
902507007b4e5ee04bd47f98345b605b7cce177b0569460eb0efb299a91918e5]F
90290c5f2092315060a14a82b7d692c91c1f7a1b307ffd574420dbe3936b6177CF
9030c370aec5edcb0723952a2989c5012de7aea238458f7f55ec1a6b9a24962anF
903dd1548295c69291a624080d2c82e710a22a8ff376f018d6fd3a0f4d907c85F
903e1d0ede27725fa4cc5c201b48de10f5cbd5f90594a9cb1c3a7e06037b2fe0-F
904bf015b9ebdad14b887224bff8f4c245ea3f185ebc64c0a9446b250f5ddcd2F
905b3f686bda411e8b1469cccabec8ed3ae99a60153880597dd656cabc81a501
F
905c6cb39018d44fe1113513cbf517b142fbc537206ae23c0ce00c299f5e39a4EF
906005c50af3c97fba3c5a02b14b7ce32f662a5eafb00675e8750675b8323966F
90862c0f721b1d5b253c6c69c26a15f9b8e4f492615fda39d9aa26a36263853dF
908fa60367f005eeb06ef2422874df47c562ea782942062b68547373fdaa4040

ee:V+rF
9096f48c5db56f9f48a681b03c82afe3ed04a3f10af7b37ad132a68062fdc34bF
90add33a3f4cc834b9be91c4ccc12114abeee16aab262829030db0c9ce27fafe	F
90b4df9d1f42ba4c9d6ed5a171805bd3aa1ab73ca030c78d62b088ffd716ff81=F
90b70e89b675963abcce8494de690686f885b273dc190de89560db7345231837	F
90d24b11f08fa24d41c2102a917044b252760ee28a2d70c68a1ff4f9043c7464UF
90ee404ae7f217e125818a3a078d8727a3d722574a1fe488df803a8e74e702b8F
90f1c235b87123f7d8a5ed0f7a6b6a246999326ece8c0c87c4412e41a67e4990F
90f9bcfc03ace81b54541dfb0892bbacaabcc873c597d5c78bd3e56e91a2cd80F
911c67bf8be2e9d6a8d64cffde6ace72707962e5ee3df52066dc91049cea2aa1AF
9124221e268619f8424d72980a7b256e0e00ba0639fcf0be1387712d145c7416F
91265a7a7ea601e581e1e9d0927369baa2509184619fcbfe483ba909db979caa&F
912bd6993c1df63e3c9381201d80fe8178c75ff27aeb3b45999e28983222ff86F
912ce11b5c1438a25af1e1961d891e6421717a57685de5add6d528d3ff3bdf42

ee:V+rF
91353b8f07e3454295bdcd3066dd865de2413f8c9940caa28844124b3ccc2e2cF
9160f97ee226a06b3da3e93f37a538bc89b639fbbfac6c152018d42532d6799bF
917535cc1bccdcfa4383143cc52d13f8fd161a5ec8f1037f606123737f818acfF
917745f55091ed42757a3d445e0f98ebd8e84ff75ab716acbdd8f6e1c584a8fdOF
9183798963f96d58d5fcaf70beb6047196f8bc9b1b7767de2b59e133fe27c94bLF
9194142e9ca71c44cbdedac14b2fbe14b54b0a0893096cf32b9783f204b7da87F
919e733f2ea0f03322ddd4ac6824dcb44dd6d5fcaabb66ccb9afee48b8b78718F
91b3059cb08a4f72259c6d15febbed4bf315c966b9b48ef63e56b900babbfcbcF
91c532ed3ffc0c3a3ff8c2e0c2f2eea28b1497fd586422e4640ae48504011029?F
91c597c3c15155bea7576d423bb897ce5644669e24f2b918fb694fe845700c49*F
91d045022efb0cd2e147b359f329cbd083f5efa2e778b5a35adf22874dba15e2HF
91d2cf4d7a40fe66ba14583d4d5f045850fefc8b26b7e0adc2634f5ec9f9a775	fF
91de6d1a2c900bf6a030d637e635ba8bed416176970159ef63c61ba70f93a275
1NM1|]>jN?F
91e11d6d33aef2e3286d36cad20e968159d1995461d24cfd238bc15aa535639cNAF
92cbd8f4ae37e782c4571e81f3d13e76955fa6b037771d881242a1ec17cc5490UNBF
932effd782396fd543e9119dfb730e5009b85100c4e34c453d8c4079975172a7
8NCF
938bb9ba7be38a8654b48fbbb34f5d8a3a6db6e2453cbe54b8b837c099acb52cNDF
94003135dce2fc46854f2202251cb46b096bbabd25f6b98e55704280bf4d77d8NEF
94aaf8d6f0db1300c892d45a1a8334173bca651326cfadf717623f714460fe61NFF
956c25bea6f5a263d7233838769732e4650583ff222b531bdab7067f4a6a0b6fNGF
9653063ff86adaa3cf63420a5d68c5ebb55e16a3bbe27a79314e37a1bf604fdfNHF
96e8afde7554bf087d7015345cb62d8833fcecf0f4165e71ec3a77681591973dDNIF
97708bdbb05e028158319a2bcc0079feb219bc2cbe8d1b3c5b3861d43afd818f	NJF
980d1c1b856c308eb7fb1dc1f32d4d5d9828a5ac152037e4fcb99050874e9506UNKF
98cb7a80b5609722e12d6cd1a4562d0177f0672359013887fde3560ec9647c8fNLF
995ede74f9ad67d498e9de6c2936cb1589f9d0f6316193c57d226d30e41b59ea

ee:V+rF
91edff8a7e3788908e55759660855db2ac6a6ef999858dac7faafbcc6b62cb99F
91fc50b78a1f5d50c4f2a592996c690be37c4d7e9724a2dbd625eba57e9d607bF
920dd1baf1fd31b9436ff47d0be39b0142c33dfb36ef0255aaf0e2c529756a9bqF
922e0899bd8cf38bf10d752a0549435a450f968969520194880a2484c23f16dfF
92338eb8dc8e5df6c7042a8d6f53cefa02c604ac421e41331a9b6a496e4b7dd6iF
925078e3fe326e7212b074bf495287d0fafc0395d9657b439a01b27d1539037eF
9253408f51b5e89b9beb8bfd7b35383d55a86420ea8834e2d54d161be9d81233F
9277a339164ce4554d7e44a5274d72e8acdef0f65c7e2f5ae1558953312edbfcvF
928ac4b150a768535d5d82dad1f8f4549ff8ef568798b62c65debe00f659767dbF
92a1308d201f7d1061b56b28ce70c44b58e1f876568a1cd1ce0d04d71b4e616fF
92aef4b8e3ee011c2535abd3662b5231c16dfc9b45c3e7649a1a6b3355518f1bF
92b1ec3eeccc76ef95cbdf3336b545c2ded469e9d6ebaa81b98312b0ef0cc80aF
92b645cab65928cc0f32fe9883d7068564a4040ac0faf35c3ee1790142b461a1"

ee:V+rF
92d0aa22a8ae445d70ea7fb4531c9e4056b5c852123fd61e665f8a3007539408/F
92d0bc0edf07e6a5b24d5dcbe83924f7438ff5eaa170034fbde75f52fbbde969F
92d5b94aea2121671cd099763736607349b3607d2d2e2e681811cd2f4c86ba88KF
92d8d566c14d02ab87f59d48e5f011678c4d1ad1effce954445cfff6e2186ac9F
92dc223c986a6952b0510b50be70d54b8def042975f883b9a1ecb8d0f62a138bF
92e24421bd43dc1bc206b56f3d63452a3bffc509e64e9b541086b542c48c40deF
92f5cebdb6aa43fe3966ec42e66aa71cfa74ff2c65896eb315d447b773ceeffaF
92fe5e925dcbbf773a6a9a67725a97c2ee05ba99988b7c569d34ea5485b8e2caF
9308a731a1aba4b9209f5cc4ee3e7f8bd57be5fa213ed219fd59941fb9b092cbAF
9311ccab42970f1272cfc018419932b0fb8fe37ba50649863fba7a09fcb64c4b"F
9313b35402e85897b582429f4df8f344b42d30cec4731079c2c5f5a680fcc839F
931e68ffcae787d5ccc19e02105ea41bb97387921e3e0e7bfa8402118570759dF
932e0ad4e24e0525ba464544c1e8e10938e5fe172b6f926e51a12e6e2874b3ed

ee:V+rF
933451069f9fdd66cf5110ba003ce53bcfcee82260f53a69105373c07f77d5f0
NF
9337c05672cf9bfec36d4f07ea3e1ff83103684578d98cb0b7c93d90c03620dc?F
9339296f633515808554bf8032f56569d2f34d4c9a34b1d71f968cd560dfc9e2nF
9339fa8d6974fa8dfc8e28dbe75760c7c49d355183c0f71b2e5d7d7ea2db67dcTF
9349658aa8b7d4b836a718f62cdaf519b05370897881d1661e16c4ca039a4fcfhF
93506197bcd7012844761bc83df82a2fa27d417449b0cc8377a4f2fa84277d60F
935642d829064a30780cd84c8e1ca654486d06cc675f9a06e246d6b366d333c5F
9359973256508b24175ed9887851616fac8f922f2e55231ced8c44ff757ef828pF
935c4a6b750a10f3954948c3fdc3d3d3fc914b613533a75f0b3f087222591c52F
93736c157e6c574d78df16b0ccdcb3d5d5bc0856fb66a7d43da85bfe6d0149a69F
938086442b2d90233bb54c18a12a65965685e408b96dafa4e36c18a4179676dfF
9384178dce07e0ac299086cce68e4bb80df8f3f7a7fbb3157138f9c5959fefa1DF
9384630d77721b9cf0583684ad152790662a117c211334438628621a8b12dec7C

ee:V+rF
938bca67aabbf5f68ed289ef571582f9e1c3c144f27c0cc38dc3b60c03bb184e
F
938d5007ce1dff2b3235913a2a5efe8141b51ff690ea6d5b59b6289df55ab4f8F
93a29cb8a20d95092bbb437ad52a8901fb2b1e4d84591469dd4975622609cbeeF
93a4cbbbc8b5c4b31b05ac687761f0f8f9699c2b5691192ad0f370b70ad1a30fmF
93a54cb9f013c14a0d42bbb9abed4ec7186612d1288e74148ff8fa20ccc973a6F
93b059a3da417ccc61646327c6d1ed94b3a83a59eea67aeb8419f44ebb5522d3F
93ba9f06a5d98fa7404897fad897da748076dbca3329d102d3792d9b20bf8c4dF
93d3b99f0fd9bf0940325c81b2d8cadba8f402c03b3b36117a666eb53a39d4aeF
93d59adb2af4416388006f622bdf8c0f758944b16c04ac683b05b66a90cd48c7F
93e5893e2543f24cc6076a35548745fc96be00bd8f9960f8645d41100dcf0c3aVF
93e83a7482939b72a1377200f3ba36de2f5a593ed72db969095bca9b712022f4
F
93f5058bbfe57b3134debfc599214a91d401380ef38ec57336a0d995704d9c26	hF
93ffdd88323d633406fd4f495ae9b81a2e9022740ce9b398b77bb2fad9f8c6eeu

ee:V+rF
9408ed4cf3bb74bfe932474193ada99007d34cf9c767bbc2acddae99d4db12fe/F
940d3c647a6731e9ac3db41e0ac29dd98c5646b2f3d6559663e1ef5e309d5a77>F
9440248086b43cdef2b59af7d4689cf4358b9549a0e882439813dcc84f72e359F
9454700c32cd463eb0cc88eb843acc8c9da791accd71ed786c92357f2403b784
F
94640be31162fbff22a0573cb0d7212f9516ed92f67a3553e720fa125d332b1f
F
946b8442c4a0e72fe683a8d2c6b3ab7143aa27670b547b3ff7849aa236ae494b4F
946bfad55d48fe614e3519a074265c4e7c6b21d160e933e697f3ed783a7214c0F
946e0d4202b53b3b065d23a43e6a5a0a32f61836c1b7305ec2a65d63b2fa48d0xF
94700baa2330493c2173bb7d59f922ff0cf174e02a7abbada312d73458b2870f
F
948dadcdb6a107784d457eb7291106200038a0a93fe476580a9a43cd45652b477F
948dd58b9aa2d3fe20747516b2640cf6b85bdabed1557859baee0cec0fa8a25cF
94956f35cf998fadb6818b03bda0abd42d6bb6eaef56f6c880f239607a6b876a
VF
94a821399c6834a9613024e8e79095fed47945651c6f3043fb698f645b47ea98


ee:V+rF
94b92924f85680ecbc45ab163f775966e4511c2f9885c4c80f5e90d414a6b7edF
94cc4c729c9fc12e3385fb74c8004acc5ebf27eed73cae3facf775403d14109ejF
94d47b782d9d01f589874cfe848688d584d291d216cca5e37b467e4d747dd75eF
94d6c80d9b08af719fa8a5e007bf753a3f13406d99bcd8411d914c6115c3b571F
94e1c0f560a6748a67411c8d4a86f1e3f8f7528cf1614061076e85844e120007
>F
94f2a00b93b3f897df457012da67dd3358c6c280b2c7b40b81b965f4420ce5b1.F
9512843f182c5c1950953d11669afc9c97394a90e3b4ebda1834fab7b5a97d88TF
951d300e30de3f44fa83fea5bff378fb53589245060530b325e00fa9f6c7f5d3|F
952a5dbe4255ec430a5d16b0eaadd30ef55d670c83a068d7b76ddc39ab2fd146F
95328dc6ff974a63f71a020d2f75e367ec10635e3db3ece1c6894c07d22f40cd
F
9550ba6de8671ca79fa26dead08e944ef94706fde1c73e99c2c59e595b752061BF
95534a4322ef4fc7dfa9b623b1de5cd5d0d72c43f81f18b07d085100fc928858F
955704fe8de0bbcec645e44f2b204e4b12ce8b7bd2c8bfaba5e8968ee76f0568

ee:V+rF
95793f42b845d0ea4f32a235ac9b117b776a44e3f656a26633a3012f93a31bfe|F
958d635feece68e98a7942fb734aa2b1c79c887db56e57df5884c0a90afa291fF
9592f2b746e7ef4c2e4fd13ac3fad913504fb720911df981e24b63bf2011a6e6	(F
95abbd8b6931c04aa8fdca6df2600bc37b23414c8395a75a4ef0a54d57357161	F
95c0d1a3ba0c09becb41fdca9e7a82ee4f169e2c6bd810f7883f9414d007e4c3
F
95ca57f8286ce2eaacee848405bb95f1e3ae571def5526f34c8d1abdb873b30cF
95cd2150c007f035eadda039e10d251a6fba3aab09685ce25fd54a2cf296e7b5F
95d76c0c65f9a62fc846a490f4d2b19a993d7bfe3b29c8f5435e619d31f10fe5F
95e6995373810d5b756222856d1b5d2f7d82bcb15022cc12282cbc282404516fF
960bfdc3d9c1208a97afc3a7f003cb7b1890daa08e77d317bc572d4b563e272eF
961c48cd798bb2acb18bcb4bd7ebd24f8752f021a87363745131dc5e83535165	F
9640c5a912cb29c8938076ba00b4a29313f55ccd7e684dbbc133c330b71ec3aaF
964701bf20ea9285610ce775b493e6d79bf2f27999d29ccbdc6ac91eb4261ce9_

gg;W,sF
966ec9754e2cc3fe39729998dcef6f877a9061b02c36cada54ff696eb4dd98c6E
96954d570d0d25ab837bbc471057f6a90d46ffff9195b1391abb3cbc708c7684NF
969eab9ba9b8ec436addf7c0e053780ff8e9fcafc51ae2195eee7d809f21dc64`F
96abc02747879aa68bd335dadad5f1e2d5ea64c519db929820194757e80af933F
96abdf65e00da59857928e4d3001835a9e548fe6b84ef391015153d2fcd5ca97
F
96ad2d995fd1cb55307d12d5cba4b02f11fe423d353b3a4e1479ccc4a628163d=F
96b2891b2db1ae3878909b85454b12d4f3bf98634a199e8944cd81886d37e424fF
96c48318b9e9154def4e98ffc6c16ef9c9663b6dd5fd0a35de6a541ab73ea684F
96d0ea79b3da11f9b3d85598dae3187e501c54728cd8509492569f9dc2c1670fZF
96d4abfe67bd7a9d955276cf0a4e0987e05c018e86c09903e0f0417e753e77acoF
96d562d6852e65228f853d36aee7193ca56da0031cf09991e2d16e15f55f69ffE
96e5936275322903cfbb6baf53a0c7b17d256a8f32f01311f863e027c6f7d955}F
96e84480f4e5f3ed973231a88b1834dd30e01f9cb98655b8551b7d1f382b024f

ee:V+rF
96f852d003908ae51e7c33a2d18e329760dd559b5ca3c8a594e3d2a5ebf41ce5F
96fa85d78505fae4e97f91bb1f42605707a0acaa501c968c075924348581046fLF
97077fe95c5fd7927b97fea9e945e2065d9ef3dd5ca4eb757666fdc5b42ad749F
970a62a2a5e145cc2c8fa7e55e770b427abb4943c6d8e85bb81c928a192bb407dF
970bcc7ec1c59c73d7a05a3364494e66e1a3bc0882edd7eb63d85aebcd8c059f
F
9711433d3deaee69fd66f5b86d352d4250222cc0624b6a64b1cab5215d69348b(F
973367a3a9c98b25bdcff626cce24fd23fe78725e3f446889ec5a9091fc9c005F
973cf0ccc163c9374db09502b1e69f3323abc0960eca2ad66bfae874ac23d131F
9744361dc7129978289b5a40fcacd9f52369b57774ec2256bc3c078d4d6e8f03F
97484ec3860cbfbbd5c2af0639469ee8d66a3f43238adbf11b9b14a0c86c978aF
9750748b6d2332b552e8a31ec27de32bd9783d10d32bb22d09b4a112c4f25e2c F
975ab2772de42fecf4ee5854a33ecf17992227d28f7a91eec834e9caac12e7fe[F
976cd3979b04d952ae4511353b7a157eff7733234abb279a441ad447656af9fe

ee:V+rF
9771150045d3b5b33795e4accade6fa6112614b65b0ea938a0ee0cae6cc23ce9F
977e49aa36e447c99e215e9eeb2628e0e19cafb64eca4dbe1affffcfe2ad2c6fF
979c4dddfa5465daad9544c21ea318624da5d9cd9873a573d52cbdeaaa74d14dF
97afe94345fd3c005c2618f3f48fcbae76e8b91619f9bfe40ec51d70d2b90c75'F
97b7678d75ee215e9c9c2485e486af9ec549e3cc4a432b3c7070cd8b737ab439F
97b86b131c407c89d83051cf1a4f98e0807a3198b30346ee90104748242d3bc2
YF
97ca74d50cef86200eaedf11cbb46855b4d2c943de9de770a9b024fbbf90ce3d
F
97cdaffa439041e92b0a8642fd10637591e412ee471c5dd1572dd88e2d6decc7F
97de078974c76f22114377981f82fac9312b4ce5e781ef81172b4cf2d22a8cf2?F
97de1dacbcdab0e2e4fb05e8ddc0616aa314dfa320e4635133391b3491d7cc95F
97eec08dd36b082c41af38fa508339931bbf380795208dfcf82213afc0e5486dF
97f2d1ab20836c94cc0c8fb0f450e8d93261f964058478270e2b309a246e35c0CF
97f2f474f7e410b8f477b1e905b6207ab4497c4def5fa6005eca7739687d0fca

ee:V+rF
981af71f35ff127f9a818e70105e8d4597de1eae244d22caa97ea246a29deee1F
9827101cf4d8dcc1d15f1fb432105b7bb92fc32f4674ff6e1b053110b96810c5F
982b829b97c5eb8400e883ee7e5cd1199ec463fe88265cc6be5560667a3366eeHF
9840fc5d69627a908ae29e24dc640f83ad9be6b88a9779079293c46cd56d1fa55F
9848ba3b7d2dcbf53d06c6dcd18ead76a0a0048e2222d60c5027b037fdd628a5"F
985cd3c30e1357c60af6a5b4425c5d16eca3e6970da5871aca65ecca4c468cd1hF
9869383533db8674f9c9ae37eddb0b159acdfe01aa0d5ad7dfc0fbd06b550883~F
9880e1f05df5dfa26e6a6348cf66b755758a4196fc03d93df208e7b2351e07d9F
98887262492c65c2f5769777ce9b0419c04f0f6dbf264e6ea58451ec3eb69bd67F
9888e1c7e5a6ba68fcb281294fab022f976b2e122801da77461f2029f281517bF
98918dc25b41bec2b5ac51e8782f6207f2389722d5bceec6f30c41eaeb02e336;F
989f890ca6fa4ad9fb01ed7adf6b4b450bbb4b99745d1462d7fbb610298b96bbF
98c4c14b7a0910ce624cb7b36dfb871441e4dc7f083e2dc7b39b52dfce97238f

ff;W,sF
98d431e1523dbb3f7b2df74717a2e41dc1d70f15e80c7fdb07bb88cc13a58c4dF
98dba21e88ff7d380ddbbdde2d2aa47ccf7bc6da63c4ae460dab25788449a87eF
98f19e1b800783ce86112ad1cabb55fccc84a4979bb77d07ffceab8d38da6f2a F
98f3b8342ce89b923c57a4b705d3efa4f050f19a729aee47d0a57f765db515e0`F
98f975d1354a7cc4711afccd61e1974d67622fdcd82305c34e00b404ab02ea8aF
98fa7e7c32572003a415282278a680123f7896108aa35e2ddad608cf9a8bf1b6F
98fb1fad0191aec5d51055b0a98b319339dfdb3295a687465da5a1122d7998b7F
990637f443055506d031e7c48d1973aa08e372a46ffffec43207a9c00ff8e8c4F
9937fd1ce7c6e05f160cf8f1d278aaa79cfe89f767f8122c9d3a05bf197f736f?F
993ebb29f0261ce55c92629ffd652f5fd4b867dbb41765fad94a00716ec5e8b1F
9952c1ad9640539f832b2907ecca1438442f4d21c5b1159a6b061b54d0245407[E
99549f1842c7801ff61d826ce12f1351ce7f60f836b2dcf51fb46da34c4b3d1e,F
995c318e872c57fa7ce17355320c34d3fdd0774343e691cc23d9e9215ad53931

ee:V+rF
995f1138e1de2ec2b063d80c34f72c7c9580839633287baad40f5b5b23f9e258
F
996c2919ed070ff29e27f8c9e3ec7f7ce69e1eea9e9da6d559423f84983ba41cF
996ee55268c9971d07d38c3217e0fb813a202d1b838963b6db16217069d193db	cF
996fe95f2ff819a29dac70f925ca8ea28c9dd6245d7ec72ffd1ea497c1ac2225
F
997876dc6dace25c6299e9ca1dc76b8112d4862b054ac67c11bcfa1e81c637efF
9980a8413abfc3a1135efb5094b967176ab339e1f12d5eca6b6bab8d981b0391!F
99812ac04e29b031870c5675a4888ceb7ec75a205bace3fe8e9339e91f0e8109IF
9984ba09f2a5bb2165cfe6589c4861a4ae3214b1932e9978e0648e075937b182F
9988a58fd1793b7bc5fef2c748a853a2c83650e825e9d524d12cccb139f1068cF
998aeda730e4ca3c63ce73e2345ed6e97ec1682e90df490b0e96faff1ebf4665F
99b661c96e07cf126304451e9aa41291a49a8f3fc0d29d14dabcfb939072586fF
99b96b570fc91fa44db61365343ee81cb62330dcb8c0e0c74bc140c218e7c02aF
99d7ab7cf207e1519d1bc9faa0e9cce19f934bf8db21f3946902e8b76737c8a7

ee:V+rF
99f7afea90a0a26964c80545f90fd551c442f1fdcb3ccdd6be042506650e78d5F
99fafc8a49fe4f04b587c0c5dfb8876f9377969f4f143426ab749dc0f84a48a8F
99fbbb592c991c048c088d31d6dc60cef74de08cfb469bfc81e440dd3938c4d4:F
9a14b340b2f3db002dcaa100cc68ebbcef4cd379500165da1b2fe3276e963ea6F
9a1fd5f559898dbaf4d03b56d97b096c2b79fc34289877bfec44204cca9aa895
F
9a2538ebee1a09c61de1b04f3ce4e0727b75e499fc1cbe6df0a72d5507871c0eF
9a48d9a5c8ba240b00760f5cdc0080f6ea8fb38b0f044469b34b8ced3f0be6e9F
9a5aad884099ccb669c4d020f69ddfec584bec4cb676f93818cd67346ee348d0F
9a5fa14360c626a157114ece6ad7b3186a9d13ffe35b54f68fab1678618a929d'F
9a5fecf7eddf64da702208bc6b583307af8b3e3c8f80f0306e8eb58001ba5cdawF
9a646552f12a087de4493fe8a4dfec0a5fb87521f568758c6136443c9644c22fgF
9a67185543ce85b81ea0ba5ae659db50e1022125ba9f4e1bebe34933d399141bF
9a702b71630a1f6857d6968df97b744cb45fd56fec8f16edbef0148661381390

1N\1|]>jNNF
9a717dd3b5eb02f5b812a44d5dde08db1964e2500b23bb7518df5c5083372f36NPF
9b205c9658e9caf5ecd6d928179b7e7b36aa629b18e33540805f21a0d0b9f939uNQF
9bc8c09cfaaabcb254797b1579fccbbf5a7ac3febd8172c07ad6764c33c3270eNRF
9c739eecd603856d78884d350c8dd6ede946fc361bbe142177f439da852cc952NSF
9d052bd282880b22a3fdd0e733ea2b915e29942748f9ccc7ea825a12f74d2f1bgNTF
9d9440a2b4ed4979c7741c8ff246d32dd982cf24ff59fb679bee4516ab71f0d1yNUF
9e499430d2fb2c6cb68c3ee8c7e80022d612bdba43e98c21c6cead204a19aee1NVF
9f2c5064a36e0190d1fb7f175cee62952c7e32951856a1ec5c9a427f2148aac2NWF
9fc8f4ae81c019b16a882823948eff561fe0f6ad38be509f514a5c287a60d121NXF
a01c3e5e0175a052f36e32e6cf907b5d7095df8c8df47790e64f8dd8c741aff0NYF
a0ea2fe57948c676dcf2c0fbdebfa53f6faf41c7af4de552c31411ddf372859dNZF
a1a79207d7fe88ceb95e5e7c1c63bd1c59cb5a98169680429a87fdd1ee285abaN[F
a2218b6da0ff7fbf1477f94aececde3dbb0c8dae25eaea7857803f8041d6f171

ee:V+rF
9a755fccab500090f9f294ce722c9245f42f0f67ffbc27667a08f8c94f0e706bF
9a83d7998a3864c74ef1b2bf4f61a19da0f4c226c45f7a70d50c9c0f75da1207F
9a8b2db0e1457c3d413a7d5db0d2a07fe70d2fe34918a818a9527c1bd851cf8eF
9a93379d2c2af5db3ccd19b3b12e93f6dee917f2156fc18048525a7a90b313caF
9a949108d90656bc8587b16aed99265931bfd33e4912eebc815b4acd99d709f0F
9a97f6e2d20a2e98ad20844706c47bf2fc689c6975c67067aa46d4ab03c1e47aqF
9aaf0e40133fe06566b60b7c5045d71204f986d2fb7aef8c6375d03c80b89120F
9acf4764f875271e9b8edf93cb0f5241361a82fe81d1381df235edd88ffa4981F
9b01dd0b8e02a853dbc19ea531e09d6c0d39b454023c90e0b36c94a8d8fdd356F
9b034f31b9d2ed3c7e58e6a93b911b9f49b07b0808de96a2e2e691263e14e0fa>F
9b04004d36145ad375dfe9de28a7d55007514df412aad6adb55517e39c5d5a94F
9b0f357ea1eeba57c0d266260414871735cb04729cc62e43ab7bc3503538cb95F
9b1fd6f75c44990182608f11437d29610a09c14eef6cd15e358d8dc204c067a6Q

ff;W+rF
9b3822948ac2fa18132b7f9d9a7d2a194615f396f5dc14dd0ecaa0ee2975470e	F
9b43305f54731049c328c1576f320912a045534f33373113f5ec315e63e8f094F
9b49885bec503dbc2bbb82461da78b854568129c5ea70410fc3d5ba68dd1e97dF
9b4b4560b2485d70634ad393bde40d05f38c2ecce03135964bdc3876bf556570kF
9b60f16bb0b8c4049fe3746ef82af738dea6d843c9a10278ae65a56e0f643543F
9b6758993720f8e305448717bc270151ffeedba84a7961f0c5e110065eb6f188F
9b69e41e187f8c3cd3d73d8a8b89d8ee3e0237dbf11ca2481d2bb26444e5ed32E
9b6de03afb9e2ed1eb1fe326e14a90ed08a67cee15e148db6d1d484cd4022e4cuF
9b7811c33c17c0451385a23f2766da783639500821e5bdd7fbea74b07f73a5f0F
9b8eaf39c60cfcb55b3c1b2bca5d0dd535225e1dcedf7eeb80d3c1241b9c0478F
9ba71fe357dd09d1913b30b0bd83507588d8cb06eda6f2c15326f3f1384c6180F
9bb37ac3924384d007bdead158f96496ee81fe8eefecab3416f0f81800604648F
9bbb081fdd6485184aa28dae8f3c1946680fdf0f31efe538dc75912939ac72ef

ee:V+rF
9bf2751a28e0695d59bf5c8e1ac8a371b4f65b45751daac5745c15803ecb05e8jF
9bfa69b7940e4e41942fffc935239c974893faa573fe45c923cc53905317aad3F
9bfce694395b42428b130fade4131953efe8248a166cb9df74a2681d8de08ecb
F
9c006d26a3fc490337a403596c661c5f56ddf827bc6cbd0f2da8d9f0c325eeb9F
9c0edeaeecaf19ea413db53d573ef306f6f69adbc4a87d9e0c522e0a6385b8d6
AF
9c1793d4db51f7f371d7e73208f169004d3aba5ed38b51d28f55cdcc8cb7f3c0
F
9c231e9b4e39bea78503148cf3642323271b9fdc99cef9271273ef16cfa78ef9F
9c36a1622791ce03d6ac94ea9fa499f523998938199fdd4b31677374da4a1118F
9c3d41d6041f9bdd8e0938ed6e0638aa29653f13b1631dd40dfbcc0dce9adc28]F
9c54883a611d1da210a5b0909cd7fd415b6c99473614fab81bae9df9cf8c6be2F
9c6296e27d68895aa9814be130a3a7bb16cd8fa2ec14d63699d1a6a1223dc662F
9c633fbd6673e42c90f906b0939d7603ab4b721859bff248db9a4cc0489b32a6F
9c713d3f8c2da0e96f093a322cd54bca18ff323dd824b4a6cfa730232160f754

ee:V+rF
9c7aa04ec57ce07caa9cac6c9e1c323ac60dccf00396891f117caa96863e4bc8F
9c8552ce4b79fef3a8e7b55a85b91bd83e2f2765635056bc7064ab7d071c6e1a	F
9c872d363d18d15dca6ce6002298b5b4812a2ca3a8743939cc98972ed12f7051F
9c883d2d32a12c3f672b6e40119adf476d62ae4bacb40ce0a88634b864d19701F
9c90fdb57f5b173c0200715d87a85083b5f8dd268a7aef1df7baddcd4f7ba0adF
9c9453260d66b8957dc7fb411913d40ce90346035eda2b58c2f9c759b2125cf7tF
9cbc0d51860b18d2d4dad73f8fcd78a82a9751a94316cae1b852109e078f1b33F
9cbd6eff83677c01360b1fef5a8c341cd87c5de0ad0732e7ac0d66ae86c24ef7F
9cd2077252d68212f08dd81f3353a8d296b4983fd631071221ad12978b80e2d3^F
9cda3404dd4c70ddebe5fc092534a2952e3c6f66ae3e9452bbdfded07730a7e5F
9cdcbe724241177f459023cb17fbe80d807010b1ab85f44514ed06b6a1a0abc3<F
9ce18db0c7edcdf3961e7086a8438b700e7bb5f91d89a4bca5049729c6b02228F
9cfc662e7205b955336839340e91d244d4c1151e65f24d263b83a7284397aadc8

ee:V+rF
9d07ac1bce7ef2c7b3f3df53bb8c04ddc9c17ab0cc6bc18d729ee1c7f97f800aF
9d2caa5bdf17716a2d9e2503e5e5490dd97a317659eb35ed3ee294d10b9132beF
9d34ca3784c0b623e48bc95dca03187a3404a69dd41baa19138db561f25be0f9F
9d5c67e50f13bee074d4860c206d81b8461ec0b7593a7cf3b207abe9f1e6f815
F
9d64772c1a50450f231fb3e75179eecc94b9aa1ff2a18fe00a4322da5b873623QF
9d6605784a491b25286fafef98f82226f7634b2197c483f0273690b3701d2853F
9d699056a31b7a651cd7680f41d92d78ae727215dd9dce336447373fd00a7bc6`F
9d6c8bed9c4d8626f8fd6586301ec93617410de9408cd2b65fef37c2cea142c9F
9d6dba1f2b69d9a60186e25386f8b45c69cd3fc28e58774151905a0edfac5a82F
9d8090a78aa40baa54d3800a01ae8e374a61c7be5587eb90bc2cf279a1c29e2e
F
9d883529a429fd5676d5deb1bcbc66ddd6a9aebebfe215ea0436c33ff0387b2f8F
9d8f6d50998e1ddcbcad83e5a929b89aebdccffb0d09afca0a5d451591034494BF
9d8f852847d542b8ca3a8f7afddddd363dfd43bfa65cfbf6dfc8aa04498417da

ee:V+rF
9db782d6307662cc280b48dbb9d5908c853c6f93c0175937ebbebb1942d0dbf1"F
9db93e031838e2ddbd104024296a70bd847b8e704bfa2e92f767297158bf6b6cF
9dc6103c894580255acdaca6f10c631843d1f93573f2546118ae35826f597314	5F
9ddb3989f547bec0175c3f866ce77a6ac4742203e5567fcd03af76e451568f49eF
9deefb8ac4e6a1d43c4894b9e5daf58d70b43a9f12952164dc89a1d15e5a400cF
9df3dd0592a54ada722f373efb2ba882dada990b05e08814608a1d5fb236de64\F
9e0249e756fa1e3dfb334a1acf42d322e19676dcef92227940e29b52a2972853F
9e05956f580c985a939dbd279aa13ca665ba62cb3985fe2751b38a299b82115dF
9e0df1a28efc20a09397d8fda7acd78003130bd6e24eaa47905a3a1c11b8fd1bF
9e2c495e6129261f090cea872f60243d9dc4dde47a1a16137f85ddc7bebce41bF
9e34155e9955877814c45bc4c249bf6c38112821f536ccc4baefe4ed42298b48
F
9e3c7f90c42ce49e7b713d239d0814692a9206c40398c880f541a2a12d8aa210	xF
9e472e05a5fca129f0efc2c81b7fc14f5daa96935b5c693cead447474422f17f

ff;V+rF
9e5cbf00ba9abdeb4b79e3b7688f06eb0cba3600861f6ba1b8e7589195f4cefeF
9e5e0690a1ca23a083173192c311f06da00d80fa4bc1fb9971a527571077eb0c5F
9e6c9b4224affd5105ee5ffe4355eb2e09681fde2148ce946769e1c4583a360bF
9e77aa7192e0e6ca06b1a23c5e174410e0034b59dedc6cc1edf7458486f920edF
9e8882a42b481017ad43c670ac8c75a3a878d804f43f7716f685798813397a3f[F
9e951fe6f09cc5cf1402211e1232a2a92d029d66404daf66003bfc285052a41dE
9e9a8ce7cbf019108675746a5f67d8ff853fb0b97c72cbd0f4d38b6dad0c96b7$F
9ea26fb857c06b7e275a794a125b7880359b3911861019696cd35074ee1063d3F
9eb8a6c91f46c6b191c972052582bf84913f5b8b77d733b9a22599022ce86a8bF
9ebd06e0dbe03a1b81d2bb45598fa8b2a8423c754eb01c2dc19009b37889af7dhF
9ec3b65cf753a77c4da092b4e68ecba78c87b41489cc86c51a071e27221c1008YF
9ed16457c6de56bbd64bcca2285bd78861c098822395446cc3a1c693ffb69c77F
9f0008a88260081411e863e41debfe8067b201353ea3a2182eb3f16e4267d6e5

ee:V+rF
9f3c7997d99823801fcaa63e46125569a1f11fcfe6050871f1260ac19a424cabF
9f4028fe73544b73e189e0028f1dae14bb0a141130988e21021ac4cef2074065tF
9f4044376829fa18da40d132a93644d44691a5cb6c1af69c266fa8e7c7187cdd@F
9f51218b8454129029c134ac7b8c3cfdae6f1bd1938cb010314534defd013717F
9f57641987fd36be4cd3915ab21939f74a4d1c79b1812b0469560179b445fb74RF
9f70940adeedfa2ad404110adcb36a268faa97569dc2fc32c100eab4368a9c54F
9f794072765d2423d8dc156f9a676c6e2b29c90d2a6f4e58cb579073b02c4017	dF
9f7d0b1438c902e19bff1151a338f2bc62e101701aa2cc4c684d09ef8a941fe7F
9f8abcf48b89d3171a189ec5449a97b802ba649f300ad32218c8310d9ae89caa<F
9f8bb077bbb9a1599bd7dfb6b7973517ca6a23674134edc3822c31d459a0fcf0
F
9fabfd6e48f2b62acf53b7c1041c0ca9cb1dc4ad4136784de7d73bae29b118c0!F
9fbd7c60ba0ef653dfcf59169cc19e74805f8e102bab5c4d038d343782872528F
9fc87325642e8e0a01c8a46507e124f43ad0d86942ddd1f2e5d1722588e7359c

ee:V+rF
9fd356bb83a32c07e83db458f3325d6bb9b9d294bf167987ff425f01ceec9bb3F
9fd5c36a0b8c70c04630c8224b3fcace1a47b80691c908ee62b4bcabac65bf5f,F
9fd94d3abf2eb974789a7462096058ddb3171ea77c08cd56496f956960a28322$F
9fe30f8f94bda5cdd5390de29d8a6c4c8f6dbbb9aeec90fb2dbf9da761d3e515wF
9fe65bb70a192bc16ad246fb03daefa211650e429f9834845e0a048fb42253d3F
9fe7f82ad271dad01797d8671e72b30eaa56799b8b56946e3a6091de48af5ea7SF
9fe95cd53733c5ac4fb1ee1e907acf53ce9a1661cc2b2e83a473ca67ae9bfc46F
9ff1593a282c3d42607507ffbc763ae17f3ae2a5896b8152f03b1dd8d3bebe51F
9ff292253bb056d6533811af24502ff8e6b9f03d370e153698aff7cc1cb568b6F
9ffa36744512a13fc23ae4541bafd054b58dfcecb57c59e6cbe9575f74e20809F
9fff25a7253ba8afcc5b3c163312a1f8eb3150a5d840c690f898fdad96a16863F
a005198937d77a556b2d5c86b03b36028c5cdf485f869c8f661e5bdaeca48381F
a019256591b9ba5eafbd13f6202b604bb7a7441347110ad87f864f0f8d374298

ee:V+rF
a01dae3f1eb932f0bc862e5f5466508b803a3d1c7bbc6b989e42cef1534de0e3RF
a03be94a199377cb1c5614368a415c0540f04e2d6bc74e7bfbe1a1dd0c525128^F
a051479c689a04906459e0f87104834ea707b2ffeb1317695704b03edb4c8b2b	F
a056997b96782b4b457a7404dada83836f46133ac10579459e04c22a64697b3f:F
a06df499751c88597c0ff2c9e3571f888ef5f4c900179b21dd22799ec89b624a
7F
a0725d3676ffa6a24b4686e544f68d9c21b869c274d28cebfafb3c70638c371elF
a0771a63bfd2ad4fc5390775761741924acb2e2a6d6fea5e21306d97e0c181904F
a07b8c2dfe81595e9e9b35a3f4a4c913496728d0ab4422f3a5e00e2c9d5174ad/F
a09b59d166ae4f96e35aa50238b29f47cbf2e30ed154a83dd200b7627918a160F
a09beb8f5ef98b4539f6e145b9e6318297e4159b1e5234b77768dd9c5b344039F
a0b60429c7fcd5fba41b9a28504facb63c1539487333911e73e7e2b166b38981F
a0b6efe5d9993351a08c5873bc1be89455d96a5535d9bf69e24384ab21850577F
a0c3a8dbbc209a90df3f8f2185925585b61c9809b9f26c087201f7c8d64a1f05

ee:V+rF
a100ffb8d2d8478959b6d515f8a57612af98cd23cd3f340be8fdc45b223ebd2bF
a1015ebe13614d40e027fbd95e9c012b121af65537d9fa42d84ae37bd4b3f77aF
a1186ec734eb9834a2715c84b38c55a5efc049d49063deb03d006c6cbc9dd48cF
a11deef2840f7fe80ce1b946609ec3aa04069da0557383edb2dd88107312e356F
a11e1ecb8f7034384a2138c08abe5aa5f4f9996c624112e951eb5a42353bc197	F
a12a8a2185579f6577042b3b9876e89a3c3c99ff67c168c0388c79d64d4d9854F
a133fe2fda391e345abde6444e57c6fbfb5ebcfe7720bc5b1ae1c3313bd38aed
WF
a14db656a37e716de6fd51d331dc591f90b663382f88a483d40e8c847e506676	F
a15acb72ee6adfbf7ace3b47300fda1914cad9d22e255326e32d3a93ce032670	F
a18aeb73905ede9c9bd2f5ab9736372813b7662678482ea5ad4990ce21b77ae9iF
a18e979a837324a9730fc3e5b08e4f228f22d46c20c0a6445f7147444b8449c3F
a191bcc40fb33d21a6109e116756d8999e60adb5535583f65d05f51ff3047463F
a1970a5fc923219ddca4fa8d05e7f29ee858edf46448313a44734fb4d4c4149dg

ff:V+rE
a1ac854d8e90e02d163b93f8f41c02c3b799b35db98f425c835e937468ad058bVF
a1b2bb66bfc18162bd1422b81f7e29c65df69760c35e15b769b04c93743d3fd9
rF
a1b74be1d5a4cc7822e76a9f4d891bbacc535194cb8b1f766c6b04f42b2e443aQF
a1c2e9d4603673b1df8482afca3dab078eea9124690469ef6dee7f9d4e663b29F
a1c734e7a148f0540c34ece6fc172664f88cf275abd4199a642731dc9f9bf5abtF
a1ca7e4977e1aa55e582537db75040c395105cb35ed1d15da80d8a11e4a3f662	PF
a1d7425caccc9a966670aae472b941355eabfd2f097cd2e1f237f22cfe4a17abYF
a1e667c441a340c5ac1f0544c4a3d934fde4bf968688af42f5d33e773f092b5bF
a1ec1d1affcf4fc30a5337ef7012e0b57d8288af74888ea3b40f8aa781fff212F
a20718245cbc3ce096de1da99acc9aadce7082881bcdc0b1576352b2959e8db8F
a219a29b75fdb33749412440d21f8b1ff92ad6616637e7e8cb818daf66fabe36F
a219dbccfdca9ac57c9b9064dffadc0044870709a425252ba874f86cfa15084c	F
a22140d2598b1d94d1cef9f4d960ba6d9726634bd9bec4682f6338583e5bedbeG

ee:V+rF
a2241dadf6e520288ff5e0285cd20102eb24c34f0045337577928089b0ff4d79EF
a2341873756b6756d7b18967c3dd2b6ce12fff550f0837ea9361171291c42397	F
a23725495610dce574aa0dd65ab70ebc49af45d253cb2c031fcb4f8050ef9174BF
a24b7bc1700c9020bc5e2e066c84007538c58004033ee208ec22a6eaec755711F
a25ea7a2e7fdf9c96aa665fd1d337fa501a8be996a208eede238af6018d94012F
a271a288a9e5d486a7d0633c7bc2cacdc437a5653257949d7aea3b6090eebd74
F
a2747777a7c3d1ef8019b71132c4a6eb6e5a8363b7b085140da95747f86c10af
F
a2766b83b6a876469856708425fef7119bad6779d4b9ed448fcb9ea454b97420vF
a27a74e92715fbe40b9a7d67bedad0e62952307a43ea09eecd25aa1667294bd5F
a288bfc4e0cabe06d845847deb1b0bbdf10a01f9707476ebbf61f3bc2e99e2a0F
a28c0efdadc06bf5a7278211745c542df980210b991db1532357b48d09b0e233
;F
a29e2e0a13cced40434f89b37fa93d3caf9d4d7726df5a200015fd9c03f045f6F
a2a0890a1bee535a6e50b46532778911b437fe971d72e228048964d8dd0f7550	

ee:V+rF
a2b22dc88f61d0fa6de4fcb62e090f383e630fc264c56ad005c9c508b1c0fcb2=F
a2cead9a7e5666819ec51f9e5c76ccde1eaf396651494f7020eb59615a2f9a17F
a2e16e3449f1d216456cce32c996514ef5ca92cbe8e4e01823b44edb2054748f
F
a2e3eec180d90a42cea830a8b5f0fa6890394a9b51d4349667c8010da5d2d418F
a2e99881f1afb105ba6355f4eef86e839d3ccf60d9543490c748c71e96cb2256F
a2f2af622884bf98fdf41e5b0a6ddb5e6e8b63443f213bbaecd8e9e08096de98jF
a2f70fbdd27181bcd656bbd6bb28222e80496a2d4cef2918f74b66e887b0ad68F
a2f8ab9e5767d2ec29dc6571b88d28e1d256bd0aaf2b7a447de4187709d699fa[F
a2f9c00b20dcf7207991f467a8714eb3d7273d424ee4dd045d1a5232da5cd797F
a2fb51336df10bfeae88e811816e04967399b366dd70cde5a7202cbabb4d0a7fF
a300fb68037da47d07903271c1b04a1bf9b9ce2da5c1a0e56fcede7f6614fa62QF
a33439122e1d6221585c619440d965d09ad0e9e2269f086ead9ef7cf4b84aaaaF
a33d9ecd05eaa2248f7384075877e78357534a302081fc03a9b5f0dcc71df48fC
3Nk3~_@ kN]F
a3461547f0108720d6413695a5d1110d735d6a9359910eca40e788f625bab184N_F
a3f82abae1cfa7453d9b8553062e87caf6acf5fab2d57ec6ba1cd09335b548f8N`F
a48861f8b0007e766c5886a948e293f97eb2f45c90d1afc5373722cf5a163b72XNaF
a4f562d2bfa43893cbae16d48549de733cb308300b8e00392e586a0a8337ba28
kNbF
a56dd9d75f85b76dd72f232aef6262710e4f66d7291c55f0e3467fa4c70855eeNcF
a663038e5d2fe0f26775744ace593a48c274a77a69c51d4592701ea604272ae1	NdF
a6fbfa63c8d1fd4dd8cfecfeb29858434215394a4e58af6c4ba12e2f82e2a61d*NeE
a7b0d2e78f9226d952fd5d798225620b853fb2b0edd6abeda0fcca3095856f7aENfF
a88474ca9c7184610d2381b4f56de6ecd823c02da9266a63a5ba57230c0ae64dNgF
a93a8dc3ff39c6f387f6ec4a439ce6ac3e94c0162375d5397c5b1d880d365031NhF
a9a7c7111b8132043c9c9351bdd7bf34051ae1eb9ab0c90e8e7582ca543c49d6
^NiE
aa0fe451ab8753df55722f121169c9aca26ca19a8b763c4d7f831af3bf826a26NjF
aaa6f5e10bb4f066d056589fbd2c2409c9e33e21cf5e6a20cf1c81c4de17ff57

ff;V+rF
a35e2c0d9f1e86c4ba70006c038141ae46bea796e4e9375fff2d525742bf85d76F
a374981fe49487005f6b444803f5ee027e4f454271acd10934c5612a37320bf3F
a384513b0be353541f3730615409df1cd228cf1a4fef5a3c14bd1bfca576d8f93F
a38a894774d443bd314d09acaa9ee6056116e25f757c9e76290fe30450b9ca95F
a39b37b22a67c2fed32b45b2c75ceda293b7a59938dfb6d991ff59b639ae2aeaE
a3a98ff12318616c1641d6e0d2dadf6e2f268b6bbc34e65924fe720f0ed2b498oF
a3a9ea28c98e59589049fb7889c20c37771b190b44b92388c4e2aa7aafcb1a2e	XF
a3ad033749fd54a7fd723f8b31abd4dea531eae66ff59e0f48a1e7412fd09051dF
a3cd127f94e232f4ccaddd486ee240986e25b65c51ab664b49ec511d5310482cF
a3d1deaf9e376473910f9b57f2f2af63409cd1694461f15fa3888697f35dae99F
a3db401db86968bf26b166686f43ca87a750990d0b9e46fad7c8f63e89052035F
a3ef423198831cced03969fcb478cb2a5ee78ec107a8600aa98854d428fa7a96
vF
a3ef6e35d2238c250f6554c30556a80122488a92f64edf3c23c04158556120ec

ee:V+rF
a40300c549d06a08cce3881d68a82db4bbd0d600667f58fd2017f98bd033fa4e9F
a40e6f107134f5d7997968a9ddc2ce1e7beb8cec4d869d04add1181bbf1653fd	F
a4124d55ffe94d6e2682cb82eb1191d84b8b271f2950a8cbf86be4ade606a768F
a41884a9bea64c478434afa440f59ad7fb2b3251861261bfa51c4a6142be01f3!F
a42f0d2d5c250a9f3a20b0d1766de040990c5ff04917d87601eb5ecaca50cc8b!F
a43b680de14ef93acee1419d61cdc454bcfc9439bdacd573060f26937b5e2164F
a44afb9ad79ce59c97899e5be3660c4d4dbd20f0aa44417e9f820995db76c42b
F
a44f98ca0940978bcb90de24620d95a537a8c46a0e15d0c211db20d0afe091313F
a450c1170181a3ff18ece403ab9cd454a3f2fbe440d5f9b595bd3f0de9b1dd08mF
a4645f394179a96fed5377b5fe20f2357bcc3d4c57000c4f11b2bd1c6d05a2e7F
a46868c4f685242ca769589626c8729cd89edd8240128f8b329e42dbf0398598)F
a48132ab5f5f42b2a741922bb5933c0f84e9994688313798505382288ac76453F
a488570f9d11e747c97f57e3754398d4b317a95c8b12a89765afa51f7a8d5b3c

ff:V+rF
a4aa01b378a3f60ccb4500c7b55fd5e37fde220dcb3863302b729de23aefcf5aF
a4b2a180e6418f7810ccfa0cbf722ce37a6133dc60adeb0ef64356a61444a32b+E
a4b372b0da7c95c62540dcfd5049d2b4cd05abf59cb373d2a9a94bcdce3472c3F
a4b82389944cd83f755da0bd6b1b81d987f9dc5f28ee78bd23bde637a51321e2	EF
a4c7433fc835c54d8bf366a26b4dc41534ab33b1bd9437ea1ba37c1150958611jF
a4d1e02c406da42d667a511a3172beae376e11ced63bb428e16894a66b9145927F
a4d493ddbcf031863d7df693b8bc739563ff7942f02210a63070f6e5f86aa7fc5F
a4dd90b3a38f048451db9452be71e7a4b4d0cfa945c1fb18335881ddf88355f3F
a4e1b36b41fc592139af224d55fdf5ffecd2f6b528dd8ae73388911df76a9f026F
a4e3cfe2ec39289ce4330038a8f3fa801449727c3b6173cf5ceabec99f36bf59F
a4e5c86a1cca9f1fc22a2b9ee7b057a8c3cf9a4e26ee74373e8878ad6288731alF
a4ed3b8d30ed584009accf96a7436d098f14e555ae10c804f398816146a347e6TF
a4f2dc5f488dc7bd53211931528d9c122391fbf1997e99e33a04a33c38c67995[

ee:V+rF
a4f8b4717015fbf8177d95a8a84a98b233c1bb9171ffa261d3b9bfff69345e5dF
a513143acbf28366be9f3830ac06cb3468fbca694206826e572edafd38461ed0F
a5200800917686a6972452c153a94ec608f7f8111e13fd0ed1403eed10246930F
a529f2b782f1a8ac2c40f6c193c7b680debbe16131700642d20f5c3c7792165fiF
a52b0985bc9791dee53f7a73f22051cc229824892249b53b748eaad81619a0bf#F
a52c89128003d6c528346ece42b32f7126708399f05995deaa7aa1e7035625a9F
a52fbf59e2e7f8b7b912ee6fd5be7c84450b3ab1d4cb68690cfc3f306086b817F
a5344af6f4e55dc3241835e173e61da3faccff81e74b16a504ca025d311661990F
a547520b96904888041cdae1529c93057c845c1215a8ac1a453c516eae9263a6F
a551edad1e9e549e9010c83ff60ebed361a870676f10b405c22b4a301de84699F
a5589b3ed616bfece0771799ef3774cb33d200e987dba38dc365b6df40958657F
a55f9423be083a88cde58065e6db2d37a2914f6a3c47d1e7691f1727476f4183F
a56bfb4be6763b8f94a45cd667d3d9e26cc48d8d10f46fa025a15f345484167b

ee:V+rF
a58a0b8408d78f804c67f0633541c402b9020555a4986e3fde782bf8544f5f06!F
a58d0d4575abce242db65f08764359915f175bed5665391d68c8b0848ca043e5F
a5909e444b1d27c443afbbb9a2c128c3ee271e86aed9bea120cceb657e7bc326F
a59b71df5f20f5b5cbdbc96ff9c1388cc6a2ae20c74c5c924f364b4150653748
F
a5a85314f27feb920e411ab6a9683cb3e8fd4b1ecc404906653cd728abed4bcbF
a5af318efcf06316076e95b5e88893eb108d829611813c7fc493ba3ebc5a1e32F
a5d07ef113639a1ab8da7c6d2429a8232e1a1dd44504eef67d44e146ca863729F
a5dc184a11c5ee57f55ab4b8abbcf391aa3b6bac3960c6f35615716c35d18da3F
a5f13a41cc54cc7e9bcaf76ee19fec24dd4c8b4f637c43a411f8fe4af310a88cnF
a5f9b329bc1130ffe9bf6f2ced3317e2ad895c4559a82bdf804c8b85e4765b28	F
a6114fbcf7f5bf08c4c84d6d0e2551e1175af5cd5b08fe5fa1557b575e292d02
F
a6119606e76fc09a37585914c2063026064b1b979d9cffcf71712c2218b4c3c2F
a64d622fd50cce3d3743013a5534e4fed4985139f60314ee23246e08601835cf

gg<X+rF
a6776dea18957f42231f6c504897a29ef208e3c2b1f0ae2ca2b12d5f93fec583UF
a679dce4cdf9324f44ec3dde672fc1978611c584f08c5d478d5091c78cbd8d27F
a6859e4664d6b26565182fc6c6f79171ac40e3aabb90299e00efc46e4acf5bc3F
a68751d71e847954a2206eba95e8947850efa80cb938416951ff10e842a23580
UF
a687b481be7d8b127fe830b2c0840854683d1ac18a2c1799d5caac56e8891e8fF
a687f0ccd9e74160f22533e305c5bb77d33023ba63729183e338ad27461a5494F
a68ecf7a99623031de79e1da0b60b7029a5516edf54ccc1462cf363187b5fb3aqD
	a6a35e6ed55e101d96fd0ed48dd8267a7e8e10917230172a9de28a796d39490eF
a6aac81cd2d6ebe99abec53cff2653ecf43ba9a2c3087ea8406123927419b978F
a6bfb1c5831155f91a3bad78a1830d94fefc2a73404bac0d0cd1818419a2bd97F
a6c934448f1ad13c105abb9c4606317935bd853ff0ba1a80735013b194ee0643F
a6d9b567ef1b06e195132a506e27e02e6e7b6768d0d22c13cd692ffbbc8acec3|F
a6fb96a295e675646b15c339c7b3d6070fefdec2a9d1b67402bcee35dc06bd72	i

ff;W+rF
a6fc6ceec2ef96703e31fadfc56988518eb77de39ff4fd2e69fa98b88e033dd7F
a7053f493f8ef154d0522e27764a50fa296c0f260992b84a51066efb0c8e8138F
a706d40bf0fcf24324c24d5742ca54450b84792752d49ed7af95192bcd3e4527F
a714e0889c00122a44ccbbd66032e67123e1f75d8cdad594e32de4c09400de94F
a71605698db58a372ff02ab6d78041cca4507c94f4bdc16507ec30994e53892fWF
a72dca1881f486beecebc91ccadda2fe934171b30a0aa1ecdeed9af74f7778d9F
a7333d8c99f660e6187ca76984c04c77a50d5b4767823ec52cc7f53fbdeb43bcRF
a7388c34d0bff23da18ea8026b4ad61a7789dc2606148be90e9c8b6440e41fbdE
a746522986b0afca052c56bfe30e019392742f4feb4722768d2eb43b4babeac8F
a746cbe3d7985ed9de3d8ea2565a0ba9d0e55c9e16d298d608b40797a31b231bF
a76f48da787342ed53a149870e65a5c17f6c5a2025f715b076686311a0255c64F
a79594486e59ec5b826e79499c455a6d627baff4bdc3f3df763e5018309b5f9cF
a7a8c48658f7054decf6176a5bd02e2d560ad065376f79744ce3f8843e7b5f6f

ee:V+rF
a7bda59425c5271981f20e38206eeec1c614dac49d55e56b9e6f1d73803d442aF
a7cb9faf1648281d26c03a5952b9c015a6e302f5018328fa99f1cd9aafbf89c4F
a7f79e36bdad845ee95ab0dcf81c2ac21d35da133b48c0cb448fbd6f1f3a5ceajF
a7f93d258bd14e3d81be8c58b2998d78081d84b5f8f763c1bff64b3571ca321eF
a7fd672c3ffb0bf842870e9f89f527fa381c0095f942e64501bc861b9e8f3d67F
a8011f7c5d7ee7b597856c9c2ae5e2c6fc7ae896c60e16be78780dc6f09a5babF
a80e94c28a71146376496e2e9902a431fca968386feb3bcfc1a8b876f55f48ce
F
a83374c57cbdfe6fe09065ecf3df2781d4ed835b1b41143f2b4e74dde0e6a8cdF
a83c7d173d50416c52930bc2a1c8a136889066cddd068990b84f0ed6f341dfacF
a83eb350bcaf8f5bf58970e8c94bdcbdd5f690dc3d7e90d21bf5532d9a597c62qF
a8405254acf23fb0843ab4e7c57f3684eb7ec1a6feb932b5dd00185927c7d7adF
a8415679884139db5b73792b19bc658a4e15f201e4f2b05c40f0e3f88e5e9a96{F
a85e9e7ec0cfd813ac23ae166540cb1ddbf0a4789afa4784dbb9d8f3c07ce5fe

ee:V+rF
a890176b2aa7995cdcca42b0e17be87bb8aae92260d663aa371f764d1a042638F
a8910c1e5eb6bae266e091a6d736d6d9cf6ee0d2019caf753c767a0798425bb4NF
a895efeb08422b537678146fb9329ca6a9b3238f9291a15d091a5a70273cfab3	F
a8bf325bc65d56d5cd74d8b007f3b2f09f0d1f6deccd0c0d0f56f515423fe6eb)F
a8c33d4ab95933b150aa784ba9bae1d03d59e6633afd229fc51bafff1df0e892MF
a8c5b5cdea96dc06b0e2bfe64814361d7099d10d8c06277305f17129b0304233F
a8d4bf67c5aec05b8881b57f4ec80fbc832c77a1fabb65bb68b376c269b759d3F
a8d6b71da3251c0921f8f1c9a527fe6468bab3f326f472567681e24f3f9bbd61>F
a8df8c8e4de2b928926717150e1d011ee1c85226c1099e9ddabfe5b08e2d0d4eF
a8f1e3373e10bfb45af34690456fb06dbf9cf8022362cfda341212c6841271dbF
a8f566d686a31517c6e1f0981aa8a7650ec4c8d5cea01c3500ae51e847966eeekF
a90d954e0c0bebfc47ee93b810520648c177574c86546b7215d65bbd566e1850F
a919c9e3a766f98e15edfc8dde8b699f46753980aaf8f4b46d2831fcc01cf9b7

ee:V+rF
a93df30801aba8cea190c36d5bfa44f375fde46284080e1a7e93e5873bc75bb9F
a941b5ad075b2f47806bea28420794a24bc7fb5373b6712a5d0b500ee6118759F
a9491aa4d8fe481a24a189a9849cfe530d5eaeb3550b1364284bf6b8b7a5a76bF
a94b2b0e58abe148cf3859a7fc971e0d1a559ce796f9f47b7450164810d65dc5F
a94dd20cc4d6f36d4c0e6369c1184936c60dfd226e51525275cc137526e1f229zF
a95af012a17347465a1f54e59f082ac490eff08433bede126e69f5fccf682f37ZF
a95d1f4bc03b57d5bf45411152deb77c11b8f7e7eea468e1ac9786e41c70b339
F
a962654ff0fe134fdd88392c47a711e94bc84e08e27d0a7cb7d28e9150d2999aF
a963852de3c08dce84508ca7b9b33ea8adeca40e1239dde2ce1a103e2fe560c2F
a9775c264bc9077729880ff223db6978a0ee4aae22b8fbdf9d5c6d935f6518a3aF
a979b1653b72f0551faf8fa54eed42be4d51511d962ed09d02ece63f2402d5f7|F
a979c38358d8c02e4590026e728a88db7c7b8f5f4eb9e080f77812bbe26a018b8F
a99bb11d5187d473fbf1ceddf45f95459a860863d190605924743cdb4f34261b)

ee:V+rF
a9a856900d5a29d9cf94b7fdac8c07e41ad87194e1b959095cdaa6019f30d4c6xF
a9b3782c3c170d426ed6352d73a207121cb78d86ee04aff09e0065659d0cddb7F
a9b4ea25e0a41a0300195b07a478887cdc00b3c879db84a0cf5c31832d626194	F
a9b560ad84f4c4da2302f2f1c1581df4d699c0e0f9cf0754e125b2bab6ea4795F
a9ba907298e679306020035cb1d25f9afc4e33153f8395fbcfb0ce1578791a93F
a9bf1a1e052ad0142193049e1f988dbdbc601a8d37337ee06021e30f7eee7bafF
a9cc4d39a2d6ad848428798509620c583ee6ec0da4ca03fdc079133cea857364aF
a9cdf7b1790648907c553d9bd3ea79400a2884d68c1cb870f1c3d0c0ef2af44dF
a9d0459586a325bd96baabc21fddbd37a71d0834a5f892c8ae85e543558e77f3F
a9e9be6b6ce553ec52656aeeb84a56fd9cc324c060fd83aeddc2a4881bd164ecF
a9f17b1fddb696d9e462b1c59846a76dfba2d99b26bfd9a07e461bcae6c41834F
a9fe909da2403e47e2010f35a9f2d61ffe1808b042a987b503c7c7c86a4ca895F
aa0a9aa8e1958293d8bb429a513a459f4abafa838c9e217974640cfcd36c5e3a

ee:V+rF
aa2c7472ee44f9db48646789dbda352a7399c0d9f9e2644db03345bfbf705395	F
aa2d737429489d52bcd0751bd1e48ba6c8f71eb071120236b9ab47a5ae3b3ebdhF
aa3730bd40f0c5b60ded75b15d9a0b7f845a26219a0a739f877d6d2ac7161c6faF
aa3af962872bcc364488d71c63463081dff2f68de76fd90b78d2d47d65c9f42aF
aa3dd48f76695ea199491a446126a20084e82d91243a36c7d1bc1bb4c386dde8F
aa4d5c25ee0ab0c6200041d7babcc2186123b17af2126662b27bed0013787faalF
aa50cc92809002bfd1b3255057b176376353bd9a36274c4d200209a0ec0861d3.F
aa52ec63113bfbe6468d7f69cefadbc170784e01175f841608614bc4443b6eb9F
aa74fc65a3e070d797d17ec1a51bec20f0c5a1f1ff74f20bd9459369a3b805683F
aa775be36b0d57745dd1f04714358ec65cc663466eb081aaac7ad87e1fa83ddbAF
aa8159ebe427848a84e44ec1263eb6e8467bd09994185803163c9501ede167adF
aa8fbebb1b09f5d4b003e51cc7e4003474c19e82d8bc3d986af0b378eb4ee9b5sF
aaa642c4d8ab309bd427dfe250bcf2154390e1fe39eeec98c816058e6da39c2f

ee:V+rF
aab72ef4b89bc4481b87f7aaf225cbdefb62073dddddc7fc7c2b94ab11a0a936F
aae99874c09826e7ffdc47307dc7fa4aa1ef9302e99a8432186772a7619d629dF
aafce5e4b381bbdcd56ca810cabc34fd9ffb40b7f49bd9cec0edce43d0f8596aF
ab078229f1b5a4b3faba2b28785c5ddc0ff1118b1a2b3480dd2d824f7201a9ce	DF
ab0dfa386979e8d8bdf410b61199e02f3996a0cafa084450435d18e99a7d33d2TF
ab13aa04aeb348258901773260b01891907dc2f1c189f183f4e44235a851f3af+F
ab17047e6cd355e0a693ee5bd8cca6e51616257233f9e4991c609933559e5831
F
ab2758dd1426e326fee61bd2598d1e3e1099478f8620ffce7bed64945dec78b0F
ab2e63b3fe04a633b718c47d41143f7ffa9fb32076d41cfdb01feaef74cd6158*F
ab37b1d65a0c8a304dddc11c7c15156bfbf447331a7afdff3f2f1c4a7632a7ffF
ab37db3638f3d63077ca3270c6b587f0147ede183844f7fd95cc12babea8f8a8F
ab57b19bedc00d6be037859d8d8126fff6c0f4421a2b085376f188106987b7e2)F
ab57e2a2afb31039c65c93e0ca3680f1377080ea7d39ce5ba84007dbe8770b6f

ee:V+rF
ab64f5672ee9bcce92e16118c4c13b43b53597bb1ec2a50445c04cb3b9eeef74F
ab74d7b998e9fec54c2357c857d922e433b311d8164291884b6b827aa2d9a8efF
ab886e520cf674bfa8b5efe8355f7150140a6f67d313e60090bd36049cdc6983F
ab9a79dcba43eba518e5c0bd8261fae155c1951f0d9f9de1194a57e26a1c43f4F
ab9cdb97c8451a96a6548a863ba8dbcf60034e7bf1ea6853b42a0451863a5ffdF
aba0487fc98846f969d23ad65f98b2fddc20c5a9ecbd166216fb523452d2cb47F
aba75d84977de2cd5e9da00e763912c5e72ba28b55b17e081014e97ca13ce809F
abb495131866830ec1e5474b69876de363e44c471e7221b10ce992f1f526f9669F
abb8fad659ee9b374da07546268016023d98393401191ae5ac9ac40748aad0edF
abf2f157e578b874738281a5fe3e278b9d6fe5f4a908e78a8a0786e24009222dF
ac054a6cb21fb80c8fa5d92b7cfe026640f5eb200f4e353fa4faf2ec2c2a0cf9sF
ac082581e82346ea696427fe38a4a1ad08c1a2f428d21c026da32d80aa0c4cfegF
ac1a64b7b78526de7991cf4af7c5df8f1b799a4c43b62277a17f7e6b5a8bb4e4
1Nz1|]>jNlF
ac303bf67828310850f24db08c7e288f5b122268f84782ca9efef694febcd6e3NnF
acbb0c34227bd9c7bba35cfa08b4942dd141ee4ccadd128d8acedaef5e31522cNoF
ad525efce24792177db9c59af54a5822206dc0ec6f5b18770062ca07e51ac4caNpF
ae536957e133aeb89aaad21eb5caebf2070b33547c21e967a1d51cc8ab213be4
NqF
aee634ff6dd524953bce90ba54a52b06711539a2df4b6da94cd10b418b71b0adHNrF
af747123a2f728bd5d30f3f31cf5d5124a9fa4ba4105764cf89594dde7453727NsF
aff30e07efab7028b05be02c4bbb2921b2c5a2e7a4db5788137073e27ba4e2a7
NtF
b06da13bab5aee0690c6d98073ecafe702d73f53e8e1b9421e90fe7928ba1d17`NuF
b0ddff8c5c64edbfff1b2f8f18cc330688586e6a01207ad39c6c30bbeffe82fbNvF
b16634b5890da4c94a654fa49d88e872174872df18ecfff9c897a547f2828abcNwF
b1ef52251919f4f18e97753ef2b6c690ce946d73749b031333749d21518f5096NxF
b29312cc96f964f3acb2be38bc13b4893aeb1766954bbb95a9d214498a2e4b48NyF
b31b9cf432a59766c6b5f9c8b9dfb6791a76a37c136babc439b16abef4d2ae11
W

ee:V+rF
ac3b19c2af6397ecfc8da1ca8a214b082e2537deb956d6f9ef387d52189be60aF
ac419246df9921713ed1c65bf7621fa6b5266999545f33a73aab328bcd38d3f0F
ac4c10593aace7feb58b42351306016a0668d518b590587b3be6a1fabb94aabf	LF
ac4c7414d6a7541a5319e863c261155019d2a35737e18e635bc5522b6971141aF
ac4d6d11bf69e5b905738e3547274f544c6780aad810056708d4cdb6ef2f2842F
ac61f136dfa8ec37083c4218f10c4b90438fde96c223895a6e3d08660c0652f3F
ac621916b414525cdb8e9a02b622a0b85c0f539979311abe60541cc0da534032CF
ac76b51bd9f736a23ca9ba8c09321e9756cbe003031b58be353bdf21e4cc8f62ZF
ac7d75cd25f6bfa86cdc28cc1059d66db9ae1f53bd0df0d2e026116587b508b0F
ac89e7436d5ce48c8bfe654ce6d2c7aa605cdb568aaad5d7088f3e36ffc915e9F
aca23e962d5b30b4147e2f0e756d929facad88ca94e488463a87261a6a8c0302DF
aca852521c8ca141634a0215e5e3383f36ca6fe54031a695fd5bae627b1891ecF
acb345f09856db7783a06a30026e252117dbee4274e86ea5b3c2959410f22b01X

ee:V+rF
acd182fdbf43efaafafe21332a32ca669b688ad9760f5af2cbe33be296901606F
ace18d3c4c3acb71a8d4c5a6930f0ae58e655462938d91d3ef45aef7694df479F
ace47954cb2fb4fba9ee4f0144a123a7fcd2343db0c8f16037bd3439f3b38736
NF
acedb410f50fe7ddd7938fec4bc88806e9f316f2c58569efa76c504f5ef11916iF
acf66eaf4814c700b8d03668188f2b09be1df06f54e8dfc7159e8377313b08d1F
ad0cdb4681378d6768d0ba8ff62f05cf6459eb32070c81c7d3eec65c844a8fa5F
ad104810553a3472aab26eafb9b0384c21ec463559eb1a5c594cbbac5aa5cbc5zF
ad182b2b1a28f50e4030294d1ad1de624300da1440a08ecc9180070cc3c2b076!F
ad1b306ed16dae044e07261f88e7b3e1846b160926009eba1eb3b872ad1d6443{F
ad1b644027e6c6f011f3ffcc714aa27825b548561a43f88debe325f3ed0dee5eF
ad24252031ea8c0e12e7acf23ebf80586b5162f12ce5e4eac8273966928e89d0F
ad3ed272a76cefffd6cfcbe64c326b1286965a0a1950072cb4a2337f839ca989rF
ad45990c26c50265b45cd64260502befba1696f09e6e431e28ae011baab8f4ab

ee:V+rF
ad66c6e64486ef32978fa8bc2e30651674507fed936596d70705e9e334965f98	F
ad6e6798e24fe8a37ac1aed9a3116bcf96b19cb797d6e59a4cbc7979cc334522iF
ad7bce9b915192b7b549afd2ed6063d2ada93cb004d25d42dc82dd3313d82a37	F
addcd00db9e64f493d8286287e758d561f51abb09ce1ba2dd73f4b708c60e866F
adf023be78972d5813085a5facdbea98c19687e2f35459fa6060b6c2fded31a9HF
adf17c4b2070f73fe44e9fc11648947e83c86d37a4e3532c9d77d3d8e9ae50e5	F
adf453caa95445c3a99ca102ec42c7d67b44d897aee8925bb4a1da3f07940c49F
ae1aa9868c275415bf9db1de0d9e270cf72ea7011a3c350bcb6efc29acb3b953F
ae2e332cb8ed86d6de74c580f47de47f6f0d33330807f898fad3b7a0b8ffa440F
ae30c015a383c2eb423b88776090420304ae65174ef0ecf4eb34bd608148c79cgF
ae3c48f21e37c807df89c63a1fa1216f44279908239b46e4dc5f7fc63160d0dd'F
ae43349e074e7aa2c0178a464cfe5b1989f31fa0e61c787de99ec01e156ca556F
ae4a37c25fe4cd0a6a91a2140530796b4b2c6059cf099f2bd2f65504b92e3742

ee:V+rF
ae5b869408794a434481ba8d5927690a56b9e2045b44efc1cca5b637285e435cF
ae5e89ffdb193ba77fff5f91338b3087497c816b899809d1d303e53d659e4ea3uF
ae6ecf30bc0a1b8e2c0c2d8702e3eaf7db4864987e02a301446311ff1594d050F
ae71e0763354a3a81b14cb8bd4de22629e35e59b0045199ad6958323fac31e30F
ae7235d8eadd22bf19fca7e2a758e17a26c6d01caf6e81861e6bf603fe82cb51
%F
ae74b02c469234e1874d6852f03edc12b68b262ee96a49590345a04f69d92c18 F
ae963ab8fb2fa512c2b276337b4855a49a8b73abd938e0edfcda3ef8eea4db57,F
aead54e95d1462dda834e3f40fcfcf9312670076f263f156c631a937038d3b00F
aeadded2fd899332eca7c3d0d69c10f06ba09b988bbb0be751dfc6ea05b1a753GF
aeb54137355c495d8cbda465df5347f7e0075a2330f89bc679ccd9d8f8d5b4f6F
aebed6c3e895ca3c142741fbc5d368ca8af370a2dcefaff98e3d2e596055f29eF
aed30d0de3bf0d71c9c9be43e3e4b5e8d6832a7e755e8cfd843a6bd7f735d310	F
aedb64f36af805dd8fb683d049561dd019fa2ef5e48b7562c0f91dbdb1fb951e*

gg;W+rF
aee92b7dc0fa366fb7dc58ba38778eaa69c633a74ec730c35144be5c00ad5baeF
aef77f3e427a8c93fb45d754ebe7752c844902b2b146a2e674ead9a54c577645.E
af07229f94ef571d7d7fa63fd7b1e5c4feaf193b6302b4faf6e64302611433ceeF
af1a3c42b3b93fdac07667c059dd206acf1333b397990288ff235aa9fb0d2febF
af2767aa1b7983e412e5c57ff7c018c32283c328f7c297d91fde01ea5fc02e62F
af27db711b76e9af2239a13ace9776ebce5fd5642631930f1b9ad66c9bc391f0F
af4714a643e3d4a5fe7d6877aeec7cfc2047da0866e0c7feb3defa34e1c54b14	F
af4cb1545cd730fee8de02f39c8201ee8909319eb1b8d4e09b97227b67b961b8
@E
af4f36c81584781e9a0b5038c6d887f8d9a95020701f12f3688519038ca47c156F
af56985c8953b2fc45d7974249df068c6d8d965f223db2279293d3ff072df271F
af59395f80e4a8af28d6c6ccafe41de973b85b01eae99f978460cfe0198a5ee6F
af5e8ccb9d54f4f9b71774537a4c1e69aad8ae1b83815d24f5930bb72e20d0f8F
af6f8cc2f0f6c25b367a6731610bc84784ff7ff2b8355c606556d449c930b965

ee:V+rF
af7e93ece536de48118743c25ba2dc36958cb213c049a71bf622da7992e28132@F
af89fab6b1b6beba4655dab160a80e43f00d9a3eb59e3da5678d9caf8ca4b865F
af95b47579ae105bbe84721bd483e536b8a004d3301c4efd6dc43296bb5dc441F
af95baddeac54f485e8299cc7cd2301b5e659e0a3c22ea98291b012c8a427d49#F
af9cf3acff909c4085ae929a3f5506bf2bed9dda37507802c11ad79e8d903390
DF
afa6cc1c77134d47d632ccdb524207f5d3993077790a943141d1dbd8cf0b211c
SF
afad00b6a6e0787361c27df8bba184168f6a8317833bb2188bd1f6c3ec7c9997F
afb7e36e5aaec8646bbdfa039bbfe6972eb157211104d1286ea36f29c07af0fb]F
afbb3b090c43e945d72c42562f98eaacc46b54087a8745127ab819b83c16c1d4F
afbd81a2f863df61c3490f215bc72bad2c81fb0e7772ce5f4bc736703c22f6ddF
afc40dc3937d9d41e9145c8c39744dfafffd80bb988b7e391d6d9deddaa9e317JF
afda0e4a1bc46470df4a4993f659a23e39c688752ccd5958b18e448a2d51f8d1F
afe9a7933f4656cf6daa79231cf44e96244592acfd586b9fbefcbbd00dbfa129F

ee:V+rF
b0179562abc1ff5d40c03661749ce4f7f4c7d58c428cecfc4a3711bfa98e6ec6F
b021fb63d01712466969d8b248713efeb2085fedebff3f3d2e0f0500cd70ea471F
b0239f1e155c51adc55198eac03bc51b27badae7390b0220ca96829e87c6c759F
b023cc7bb4beba93c1fa4b4ea3d00f85891637ae3f1692b51863007e799f93e4^F
b03ee55965cce1d19f8f7a5b24672dccf097948e9345a8b8a66584397af9732eF
b045612fcdf478362a31afe42cbcbfa3696fd627cd7125c30615831a7f9c7831
F
b050823fb61726e8976cc72b306b33896e52a61ba34741aaaacac29f20a9d428zF
b0526855331c1bb15a63cd3241270a0c0330c224d607dfbf6bc5f4b2bc92a167F
b0579fbf5f02ea45b706f77b73c1a248973966d8d1c97d2b3a5b63af1076dc30F
b05ac36a6c2c5fb2a3b34dee8aff347281f1ee28b49846b4add728a5cd69f06aF
b05cbfb8155501322d2372a41219a106a3f361ad36d86f1e9fcf2f235dd2e63cF
b063de6c9fdc361af76d98bb3d3b31fd5ee05e120f1dc64f9ddfe77217c012c6F
b067b77274a7e008ceafa9fe949f6649af4f291e1fe843cc01d5255b977ff6be

ff;V+rF
b06ece51d62eb4905a59da18d4a041ada4dc1d9541693245f60fa02f0ec302deF
b08b52ab528346df18af0d47ce99984bb2bd02ac6801bb580534ff9d3274a0abF
b08dd14ff4c9cde964c7eb832ae4496d321debc822b86b970f8051ca8589c6b3E
b095f7fcbb5d718e30c01471ddebc9eca7b0315ab21ba2c286f3e4c44b8bf2b1YF
b09cfd3f84ca7ac6c285e49ce46e9ee51537af067b1965560dd41d5f82f50deeFF
b09f1f08469f4eb7a40b74f2e3cd25fa408b93d9213c6bdbc7ef21b1ee1ac8a9F
b0a39d51fd2f8d6d5a8f011e24a249847065815606a7f38e2041f4b496cc0190mF
b0a46bb86e33be0981c1f64d814536e0aa1b9fde2bf106fea068c4252e33e8a7DF
b0a8eeea28a48870600033e3ed255b73b22ef84935f83e1d18f3bf72359b66d3F
b0d0a9428e29aa54f6cf8736a355da73553cc5c4e20f0795d6faf0e6cab0ce49pF
b0d102765a6254ba3124a2f0696551cdf5095c030aa9fcee435cd4fa3f06d423:F
b0d2ba1dfd6121490fde31684dfddf6d147c4889a36ef69028e8d42e1f5d7ee5F
b0d7b591888b6fd49b457c15fa981112edaa1d269c881960174a8676102cad81

ff;W,sF
b0e87fb6b83f2d417585b8e9d2ba138a98dc6fcb1f21ac5485ddcdd9076cc90bF
b0f845b17a6abdd7948335a2e03ef8bdbbf9e61bc00af3b2e543ed8708781374F
b0fbae2e0eb181380b19d158478bf7d42c9f4424384f6f24d8b1d95b7a9954b9F
b10e3c319490493ec81ce895694bf20ebddb48ec604b6a5d8d41cae60cbe4adaF
b1195f160b7732b069a76d55a22f0c4f5d8a7a92506dd8ec030b713507963ae7F
b11d559c42557a76fa28ec310e056c9da6ea2279ff9e9d2550f053c95a60eb4cF
b126c7678a3e74f9a0dca6136f61a6fdd9471991c6ce22a72c08d8a8aa86f2e1F
b128da11799b79cddf1ef0419560127564929391ef662226704b79b39ab3bb98	VF
b1355c30321cdcfe6f3fc6298e8e7995196ed2edc8127aa23cee6fb0def56d65MF
b135e72f01c1154da5b9255ee65113d9a344cc450c24d8b9e7174a0b731939ebF
b1471a49f356e514174b94e92dfc8993323e25a2de938cda266f9cd7d5850665
F
b153786a744ee0f5ed2df73a98fd3332ceb25e5bd7615afa48574656dfca002fE
b15c5bd5d17c47937d82efe2f0ce115cd380671ef484581d4184399c840e2c35F

ee:V+rF
b16a84b46233f40caa0d30fca524f23408cdf7301cecddbe17cc7b23be9336c9
!F
b1723c845eb0bd0f6313d26f5ab756da789229567920d005fec0525735b110a0NF
b181a29e8b480e5cdb16c69bd46f0085d124c0cf817f9faa339ebe447295beab
(F
b18eeaf97c8e575f6c91cac0852221503010783f1b05f5c71ba0566e0569c473
F
b18f3f7901340c38120aa1a6fa30010d2c8689dacd4c2609ff225ceed2672899F
b1985dc9a05a3ffe2eac12dd0ba63fc7285e6ca29af03c0351ff2b6bcbd39822	F
b1a437d314e4c8a0e5d1e099a8fdbcdb1ff51d9795ce9c175c3bce0b7e4ca564nF
b1b4503ca199a88ac8a81a7fa75f6487ef746fd58e4bf8d079e879b4ad3596cb-F
b1b8c61d7f414e0bff5b987279a268865b3400e4618cc614c0e2852dd52aef50F
b1c8c2c11e1df4cb77d96713a2285d4a6059f60b0d4baf4e2122da1910d62f6f}F
b1e13bff131933637fb9b843f0d5f4c6cb81232f5b53ac058376a71010948f6bF
b1e27eaa8378961d1d5aa1cfe6e8b864169425ac61e6881ca154a93ccff6d67aF
b1e85cc0f0d7b4783c129d2855d494d189e1974a9dfc0cafeac3f27cae0d79de
_

ee:V+rF
b1efb67b99edebdc9042e5a1fc8376aaaf9c18620d6efda4ea95ea1b1ebc91c5F
b1f22640d57b95b5f307687ba9cae4a938f5332030e06b6e6ade62170f059a4f?F
b1fa6d1fdf39dbf8d3397fcaa156e0402d827e1c451d262b62c3899c837fc47aF
b1fa72dca82442418098746eaa9881ac7e92678c41e6786a458c28d77235fd5eF
b1fc5ae8c9c372eb9d1971e1612aa3947e2c1b7fb9700813c9c66f35908dd4b3F
b2017332dfd84aebbbfe8b857c333da3eb192f27956aa48ab410bc0ea011ca72F
b20d6f1e46d161202c4ae45ba1ae9ed58e953a1d4ecbee1eb0acaf15da85fa78F
b218ab101b70c9d78787a08804e407030dfd24d15979db45116e871686e88c92F
b22820dc39c9c681f704d5e7b608b6d1aecc2fb1a4181df605e69e8a30e70237F
b22aa8999bea98b78e5fb8b2195a94bb82daa9f6c9469ec768b019d741e439db	)F
b233baa0fb9d61676aea025d1f7b834810ad66467adee309673c302ed29261eeF
b23b467a1a7c8028c65449557a6f6a8354bf652726aadf062e125ab59dd4db0fF
b278fb80905868e72a398c821811d157b927969735ff0b93fcd631121d772538

ee:V+rF
b29691f0851773e177dbf1022fdd7407ebdb0329a1fb62e66ecd797a49de36de
"F
b2a7339af908b8ee4bf1f85d0d58404c6e69e1311f16a5ce08f7c4e01629bac6XF
b2ab719c45f136d393fa35fa34b5f7ce41406fba2c86e188fc3d3823aabe7688F
b2b420ac2c03b3a2e4cadd073857498446180ec51a863fe30335c9da3a963fdeF
b2b7af7c6537a7e10965b0b999532c5684afc0b6d255efc2b50da0c38e3f168aF
b2c1cdb60ecdd165581074138534e1d9c89d29286cfae22235a53418e6994f26dF
b2e43341cc469f66b5495139b62a419c0c671b19535efcdc79df055cc43686e5F
b2ef8a6d19b994c6cead1e1510c4b2f0abe8b34327fe6fbc1e106f3549ef5de9F
b2fbef479f23da380eafd4aa77e97d08cb7415937a751ac477c8dd39371379baF
b3004d122d0a738cbff817b9531b9787dcd2e46f3ed06c59e99fd50749720806rF
b301b3885fb4d5b57bd90b729ff75d74dc31e2f35a8ae3b5efa64901202f1497F
b30805264689335b37e185dca416f299366d9a6516f7c7a10cbafad4f800f432F
b31602d66dc65e0bd7a5dac4f9770030528982795cfb1eb49b0cc1eea4786f27	

ee:V+rF
b31cc50cbf74e369bada216975078737e5f701111fb2ea5d0c97c5979d5c4db4MF
b3204ebd71ad924147ec931e26a4e2b1126596abc3c240218c3fa6304427d2898F
b322d84f1b35af3ca899bf943ee67782b8ae449a4769e0b3d0b7f455085b669c	<F
b32b8584f13412301461463bde85e0fdc2dde858c115cd5ff1e7c299096a8d77
kF
b3306affa940e0e2ab3cd9caec8dda837e626fe8043ec669f8465d62b7b08ed5zF
b3350c79767fa9a0a0ac49e9e26cb2d6f221c594bddb72ca5a870a8d7661e0f1F
b346f29da69c21241a449decf0f47b1117502c6f136b70a23a24f1438e919766F
b35155b1ceb01b0f1587514d282fbdc9fe8d837afdaf5f41c36043a5e5a43360F
b351574a459bf47d5aed5e921e49e33fc565cab9b3d72ce5cd6fefba1b6f83c9F
b3523f6bd479abca1bc4c70f870af2423e9747ad2cb185692334588138742f50pF
b3587c7ba2e0d12bead8a84ad8d8aad31b6a2da64b0de946850e55afd3787193
ZF
b3629bade8ef787d20012f38cc73971fd4d755469722b2aa65b093f247fe10ccdF
b38d022364150a6b271f7303931e221b21fa89648ecf7b19689e3aff7f73b9dbZ

ee:V+rF
b390b91a21665b3ff2a03ee9f7c6bdb30c06442a9b46e609048d87d28973909d4F
b39d7efe820971e3e85469fa528f6b8608b9fc3e46fd50fbfb19bf2bd8ca1a0b8F
b3bdc6e767be75bd2d9600181faa4ca87a0e88beb73a43bfc5fc4a5c8956a80f7F
b3c269833837e02c07b59ed5f8a0595794f5ae6d92b3d90ba420bd82eed56ffcoF
b3c76329ae932f3e67af5a1fe06c2e761c855d1039dd424d7c441f8c548f297e2F
b3cd6ec6014704060af86c8caa9a9ecbd7c3c5c0ca064b886bda0a31117ad014
F
b3cdcec7059a05b036622e2b2326259602d28b19672e0fe8766f1b0c59537bc9
F
b3dbb953a4dc9b8b5ee95024d51d922488db5a0f0ec2ece9bf47d8d5cbbf24faF
b3dcd6321521c266fd3fc743152c2fb5145426a5861f180609a075c9b1356d64F
b3e23051f12c034b848268c08321e17a519c484640546a3ae90e7f99b36e7174F
b3e690b11cafa64b176ad1733771549c822362e0515190949a20dd95d397be58
F
b3e7d51cd260028cee1b21b2d94a9e4694745e0e673f10a05aebb54a5a4928abF
b3eb25f000c6f150675f527c9303e23ee9dffdf1666a7746fa5d502bb01276e5
1N1|]>jN{F
b3ef87449f22bbc11d2c424b6a59ffecab688a083fb9da993f6d7f4994ad29f6N}F
b4a0638e6c66b83b32396e053b68f71ce9f9c0846f117e75c3223af733c923b9N~F
b54db851c807040a3e77a35898fb88a95a15258a38f47ec41a9657101b87a477NF
b5a460913216927a863650ccef6d332b05a92836c9647e73a369720e9156fe84
NF
b6d30937baeaab87a757d348cb7d1c880d0d7835e383cdd00aa3006f7b1a6cecVNF
b7958e30f90b1219e2202114385b2a92aa2271e3064f4b5e46ba9f99c2beeef9NF
b86b07e982db65a9de92fc9c7aa93f0d88b01391a29985f36ccf1ef735a3d904NF
b8df7b9911c734e2423d1ebb0116de9bc8b43bfbad024df88e3441f422aa93ff
NF
b96b6f75231c9bd50c073462605d9aa5494f79623d07db42df2d505c858be737
NF
b9d806c4557aff349da1d626e32967c4202becbc72147a2c93ba8a440c08995c!NF
ba8057e4e0424cbc1521c650fa3a07edba34cbd8e90391f5273ce5c22d55e305FNF
bb264f253989b30cd12094f3d2e34773de2ffb9f77472b7bd12673eb092157ae}NF
bbc7199164da8d3b64fe85a385ca152120db612e702d3318ac67877b9c25e534

ee:V+rF
b40ba100ed5ee8ae86882af45ded185b07a11fcfe03cc9c0e8481bbe5a89278bF
b410c0490c2af4f7e5e57b126535f682c43747b4f65ab0c3b8b86259df169293F
b41a681dfb0b8b82973c7815eeee4cc5e3fc5e27cb13f55d251186c29146a4f3F
b41d7b6dcc5a7a79787391b203c6f01ca8cc2b821d1918b71d1f1e0fd2182b3cF
b436b196f3c2735dddfe5727a948d1a2e443bdebffd7018905aa2558baba56d9F
b438e03eb4776904a5d3eda9f71311951963cace861385cb395c161e85901444F
b444f8f9031836d93018190b4da5a39d69dff36187e399dfc8ea308d2398757ciF
b4483eb8d3d6d68b68ad3e08c79385f43b0a40aa17c3681e16b53bdddfa10befF
b44b031eb36308c5d95e0003f3cb129a5fec117dca9e4bca0e8448da97c03db7F
b465213867e16065d782ed8791eb493ef1e3a0260294e730ea9d4c86e4e7510fF
b46ce984b02b31bec731f80328c745600ec4e07a5c031e77dbb554e88ba7fcbb
F
b471f99ddcb78e386e77a4c7bf4a814b35fce51259b2f34d2daa9be4e09d6e98MF
b47475049748725638cfe057a54b45b2386eb621ed65e7dc441b3f6dff971e60

ee:V+rF
b4a38f14218c431d03e34c26a134c609d688ef2c83f268f6867bfb1003efcf2bF
b4bb4d388af0708a559cf09c5a7fc75ab89a349115729620b72c790f28e7422eiF
b4cbf615b36395073b874a9c133a8bf54fd76e3016b591c08aa9bb4e0bc70679(F
b4ef197940e3c4fa8fa6153875480c974b0ffa36f4534e7c04d901e91440e53cF
b4f318de6ef0eb132e4123f8b5fe5520c45b79417dc124c993f2ae8570bd2ea4tF
b4f762ba7ffb9fcb803ea8da5868bfe7d15e7777c60e6f0f4f2f4a4d3f90cb50F
b4fb6c1de92fa5a737add5cf91cb77255e46b3c6bd53cb56fb0440dba5b32f9dF
b5008882f07f8c6c00a0b544313ead5522d4d71ffce67d2a4c5c59a41e89e091FF
b505b67a44068dde29102d451d6c870990ee335392b3e5328c79d22c00912870F
b508e84aaf73a34f2d109602c78e906df8eb37fed7c853749929b1c52770464fF
b524427963041d0c49036598caa6da026b76085863c14fdbec1466146a3b137aF
b534be5ce2fdd42fba4271d4bfc8275f8788cc729ebeb59920e58209b92fbf2e^F
b53a6924f3594abaaeaa39917b0114b7f6f7dcf8df0ffe03ab3a8957ae3405c4

ff;W,rF
b554c183bd7760a4c29b178039f5b3746c8549c6a6d40686cd8b4f7a5314ba26F
b554df264228a60d69e256e2f70f55d320abe544bb18085a944c35b983f83b21F
b55dbe4208bb3c90683449a91d2a51f9e672cea8adfe70dae659fe5f39549d2fF
b55dfb902c51c301e4075cc32658c8a11145de6ede53d43aeaf2057090a9bdcfTF
b57c33a0b61dc0b3c7c8b1c2fc69d8106f19978caed12eb3547f80ac41328a7aF
b57dcb1aa6d049c9f0206c226dae51fc7047a9bd3a94dd60673d7d58d3e0a2d2OF
b5816382d23e2c39a1010248b904a92618f9140583546a2750585d023b31a97fjF
b58cede57828d0966881342f8638cc0309f8064b70437b0adf9d649bfe1ade45F
b58fd5d0fbbbaf80d3e0405749952cb4e46fea09ad96f495282995d6dc2f0a15F
b5962c01ec97042d7aa371253ae592a53b11214605721063be11027949cd9ee6E
b59dc7ffbf0ef066ff9a1cf076ed8bff6d49817bed656cf03853d4c14c19563fnF
b59e577acfd79936a81667c77131d1327e4ad70bde597f697884a4eaf7e3a7ec
rF
b5a2b6df0e41a71f9cfd396eaf57386bb3c21a06e22de723d7391c558e82402f

ee:V+rF
b5bacd96f28f126743bbc0807bcb665ff0c52ee4b0256b7bcffb9a10f8d18c68F
b5e1f251fa985a796daa60023e6589a2ba38ccb958e5fb09215538f676a01863F
b6052b91db5ed4e063fd850d975d05689cc9b1996c06638c4d251659b128c9acFF
b620f989048c7f2f276ae3cbc4a5217f51cff7aad191e75030d927f8022e7c5aKF
b6282c4c1e703d703b92a52a9f3959b4a6412072b5923853674734d4920eb1eegF
b629a630cf9bcbefa47414156640cb216d8f887d9dae33819d9e0461c4c0119eDF
b62cc8d7fa7e89475ac858e1c622dd266841dcd23fd2841b274d435990854dde4F
b64165d72cf869748c81b8e41581c93b8354747c22d548ae910ab54e118a90a5
F
b649840984828bb702a86f59b74053d9fb62a7d9512eed421f9ac6fd2c5e648aF
b64c66f5d35425a886b1afbcf898922915a06a253e4ec2f2efb169f42dea7125F
b65a283b2abdd24d3efe7491ad9fbe6bab445307ebf30070af80a0fd335b8560F
b66da86b2643b46bd5d193eebb6f236cfdf753506a9c50caf4ed52fc5bce7172F
b6bfd04cfc31afc2ac3f06d27918b98d44851172acf977da0dd12062ad342af4-

ff;W+rF
b6d54a557b4be65879c789367443480c4c3cb12adfbb35c324b6786e2f8ba2a7F
b6db83391c36a0ea8bba99215ea32a1b0cbff013b8b497b6fbef6ecfd3e1d880F
b6e274e05ac34f9451986e5f375b66cef94037ebc8c2b402675b73d23033f6d4F
b6e908a5877e75ecf0c9f0d2e6230660232dc1176edac5fab3ea2fc7d9185753uF
b6ef3e291bb25a5525d4b85ac8b4bad708a7f474d0baeb5ed6d75da8f0ff9c5e
RF
b6fa4027fc4b1885bba1e19874919c93e8cbaa34816975d67e07e866d7a53bf3F
b6ff39e8375e47ff8d8c06f442a8b78add02677aa81e66db47255f6469357012'F
b716a9548efd53a938625df1910ca436cae1cbf92940422987c01ae7cbb040e3E
b73a625e6724b514380e5393dc8ac1ff68137ee32e63057c82c80eb5439701baiF
b7454eacf95c0a09d97a1463029b82bc777116a9ed468c5edd4c0e8ec75006e6F
b750d9875369ddf78843edcdbe9053b4d4a7e6d7bc2ca858b563d14bf5a16e4b:F
b772674f402708d7a9f5c7def69900c57b170e563c2d85cab68cb3c7dd011b4aF
b77480a5bbcbb658aa18aaa138438f5924d6978f45f40b09f5958c6479004c18

ee:V+rF
b7a51c89deecc8235479935646047575b00838c8e74a15aa90fd3f04dbf38d1fF
b7b161ba7512043214d72f44fb3c9276bcc89dc678e4ff85292f3754b4a8eb45F
b7b726f83f6133f92e0037c54e043aa50a4cdcd0b17600cdcd827769833b0ae2F
b7c575cffd422a15f77eaeb8f4a41cc6e965c486511f363df2d62887b7934eb0kF
b7d834f2cc5aa84ce95931ece2e31ba36b1622f5cf8408527a2a75727e975348	F
b7e3524e3d408eca2c519e323f8b8841358c3ee89c7362d30b856ed807a0cad7
F
b7e366f21ddcc468fdf5911183613253aa34811a255f3ce61359b728e281b233F
b808a968c2ce3fd33503aecac4b0f640badeb9c4fc64b22515676fc26677bdbaF
b822a9890f5063ab0234ba6cf91bd64b1adc0c4e2f854176b9b00a76b414ca7e&F
b82ab048b9697892096528f61737d1713449b0dfdae049f4533ac7d1e469ad0eF
b83531fbbb21a612cb6bf9dd29ef1ba3afdeacd82de1d86b9949dac00d9edecbF
b843af350666656b6246dd355d5e90fac356a7c6b609118d69957fefcf9350b3F
b856dd2cc821e1fa2cbc89c6901577691af284f98280ef05cc1a7c3826acae41

ee:V+rF
b87014ec721416e0cf97d51775ad4670f9e657f37f27c2287900efbdf9361423YF
b87fbc79faea13909a981784d127aa69be3a440f342f46eb2f0ac3baa4c8fb1aUF
b880a0b670e4d960e2f45b887ba9131d3fde1d7bb679f52407002490f974445bF
b884e513e4fabc67d102225daf07a6948f3c7aba4eea99292cf5bbaa993d41e7^F
b88c8339f9ad90d0855cda0072a67860549759e8870cc9abc61555e4d4ef4f61F
b8969d6cee16b77e095cb73262e74f3bea7aeaacc386fb96ed8274c2732c2893F
b89dfe0d8f7dd4115a1057dd176a0db69c4c6c947cd62369e8f6701a52c637ffVF
b89f6284503fe622422027e205df72fde54169ba290d768ca1952506a29792cb
F
b8aa34987f1faadf2c76fb58239d11cf1222dba253fc175f21607f57bb0e908cF
b8af2291b240e6adee1241ffbbc596bcb08dc54cfa7eec97883a3840e21871caF
b8b4286c072a6e2914a35c1f9d77c2d2f6fc910361424e0fd362363d7d5d74a7F
b8c980b0d2eaf56affe69fde8c004c91dde7d83277578de4cfc8c06aaa322858	bF
b8d2de93054764674ee23673c18575b0b841cfa8e724e00499ab00ed583c6621

ff;W,rF
b8f63d0b7b046b2e21566cd9b7a99d818dc33c5c9b5f6176fcdeb296a99ad731F
b8f6f54bce094feadbc5ae893e955b1ec40d9dc16c1497c780f7215a7643291b>F
b8fb9ea2d60a9b5cadcc413c18b5359c3c36bee78234865951f0d9441fcd344aF
b909289acabf305cfeb8f77f4351ab4fa67c1a023c392ae4e326c32ba911376byF
b918eb715248bdb46d8f49387310a25030a9f4fe192d5ee0f69fabde9b84d42d	F
b91c19d3211778e075a890f5366a6f8e279f0f8516238accd9f976e88ae5d259F
b922b23c5579da9d7a1a127a1d46f32b941981d9a61ac309ffa1ca688fda5a47
F
b929a42b8d0177a7813b33484e7fc53ee017c678c48081d067dcde010be775d9~F
b9339ad70e81b9edbe99c176f811eaa3f6b5564cff528ff56f4f44d677623c02F
b93825bf103f570b5e1032748e404b0d685f2025279cdfd1efbd0506671dd269E
b957705e340403c636b68ab6ee9c49dd1552eb20220d0175dbbf84f042ac62c4&F
b95af4b262010256013a4265ab61dfb37bf37e1d4ca12de8b007b315ae8a9b1cF
b960b52aab1348559908af3d4bae59cf32f1543cfd052b3e2d9fcd3edcfd2353

ee:V+rF
b970000edfe83918a60d36a58443e70febbc8053c3ced7c67732f55f07d0a976vF
b97a0e1f72d3fb43f706975f8e02ff0c130ef35fc6b4763eb18db88980fcde25F
b97ca8437ca8ddd548433b4e5244b6b95c3c06fabebee6a67b64e0183ff83641KF
b987f0cc8431b286cd14af878fe7d373d1fef790672495746f45a37477544b88GF
b989926a63d032134a604af73945bec5d655b1f56d71ee89b60cdd36ad43db7b]F
b98e50cb5344b27eeecb7c8f6a0bd8ae65ea51bfc626a744f6d64347692558a8F
b9b11e2c45c327237aea9d0fd84d0d41db9d2a4137822d95f71cedd3ae9145c2F
b9b371aa85a094ef9bf89ccec7f948b0f98488eac855ba41f5653f61941610e4	"F
b9b66cac17e884fd31966a5fd2874494926a1a8d4408b6ceb84dd898b05ce3f9F
b9bc38488c309455bbf6f753ef1aaaa244614ec08a027b5ff58a7b234006eac1F
b9c8fac8c6b10a87a024279c0ecef2ddf68ea3c55076d9478ee93b3ba8bfc5c0eF
b9cbd1c4954833f2a8f3d68b1cc92407f3df064e044f0f7f335563bf1983963bF
b9cdab2c69719f6bbf7b533475859fb6f47e37976e9c3f8dc8235fb67f98c995
$

ee:V+rF
b9e13a24be722461646243414da9fe3046ae65baec41a7aad1670103307a6921F
b9e5d765d9cdb4e753cc90c405374ae4f1e90a89b8969164455783fc60720afdRF
b9f7953bb8ad08f44b13f7946b99015a8a305f7022e1575b7243c15e252d3cfd
hF
ba087a07d4834f084f6c1c67dd0871b4faec0852cdda6a66f64c6203f78ef56c@F
ba0ec772d06061df246b8969b37e4815a06dc47d41fc74a28df3a929e7acfd687F
ba22fffa8b12afc9653dd3d202c1f25ea68005dc24e14085ecfbecab982605c8F
ba296a88e1432d771cd920109f74098580b81344ab27e869815dfaf5cd73b1bdF
ba3679dbdaf62ecae1a485bd198e4127a1c7605fffa6492fb32ed97c97eff892=F
ba3bba99a83841a7ef214b159627a5734756196a37510565d94c55e374ab6dc9F
ba5a53ea9bd2aff2765fd9fc38a3f75ecd5d3e617e1c2cb85f6a9a793063506c	F
ba60b418779a0e59ca05c44a8a4e59cf92572aec1f631f59c0e2f6cdc8e7d1faF
ba6f42672b28ba6a322e4daf6a3e3fc791a39cdd7e438b6d6954713e77022fa6	#F
ba701cb5769f4b33298d989a3a2f322062b88774a949cc71f4d59c46e785f253


gg<X-tF
ba86ad50d0caa853696fbf8bb669856b215fcf866bddf9a40a79e2097b6bdac7
F
baa1991d1849681ae5e74f8eeb2d213f69221f0c76cbe0018df32bd8f5ec1cb6F
babc2d4404f1281796b179a84267b81054e32776eea8769de35591c3971fe0feF
bac160608046f1b8a53fee2478c1cf5eacbd98780405257d17db4aa0e88221e9F
bacfb2cae8fa0a136505d13d9ba4f457a70110c92d232123563b0978aace5648F
bad44aa372dd71ae7305ec77706bf7df2edd9e52a618230db1ac76a6fb0f5545F
badc986837eca92a61c46a7beb9bd700e04af6d84681d4ca53417eb37b7eeac4F
badfc32e957614210eda392b71e458da964b3e66c2b8b1d7b457703c93fb8070F
bae6332ef212f5e4fe0b1eada2f87ebde9f8d0ae3bc2bf1231463bddc7837af2	F
baf17e426a993485d612c72f85e502e6494151b0c2a6581a932bb3bddd9a2d65
sF
bb040f65e782eb45f2e750692dccebe3a40db82890f2982e835b5946fb8a3a13E
bb05359bb91eb56f0684f800012c621df3fb69caa61349ed4d20292998b1cb0b`E
bb1ab36dd4c499189f1a463cc83793aa1e996879aa0fc39e43580add7837b7c9!

ee:V+rF
bb3864015d5c6e8d0e5f6d4ad1683af99c0b275dcf2efcaee1e4aebf6d78082dF
bb408fa95bcf415eb2f22a47b9881db4b7939785d83fa16655c8dc2709c0e454sF
bb4a0d5f27950f8712ba44e0d94dac84d24f409c0064a28dd7e64dab38dea9bcF
bb4b4f96791149e67da2521bb1cfaefb082667ce11c33f3fb4daf083fc100c8diF
bb549c96d2986def32a70c8f766e2a23ac2dd2f4c76e72e116fdc699bd0c6eb9eF
bb6c4bb2a43504110b58abd968a896a9cb28e447e17abd926b4366f43bb50835iF
bb6e90b56d4b253121d4d970d8427ccc31a51594a6631e598efd9c3a3c659156F
bb7eaa756f5d42c513cfe946f0f1ba45130c482c2f40200c3e68e01181b80fedF
bb889461e56e1855ace7437bb01465dd50bda036d71e6dc023139aefdb0ee98e1F
bb99b24bb6932637a09babfa34970f02619096864977bef0bf48a0e701ea428aF
bb9d06747ab519acfbcb5813fc1980b1af09ff804dab7cf685cf77230153ea1a	F
bba4318d019ae161e780b129f85d5ab91b299e3b9745f99a659fc52dacdfb221kF
bbc54477e470a694a3032e391624ba33b9753f81d283b60a19dca7c1c52b35c4

ee:V+rF
bbc75e7ebe20ce9f9b3a0c5ed5ebce0ec757c6a71b928408b3219bb857294882eF
bbcc65876a2808fc3b0866365675ccaee30c914a03af4a86bac11a13ac2192e1uF
bbce7868f8e66ee5f69db6702fdb909d81b8c17bb4f7417dbf08a87ef2a26308F
bbd3efd923fc7315be5c5ab97b3a2459859dcca70068d448ba1d7a8aca4b9af0F
bbe6a456297232dde9056eadfd3e0082764eea1606419c384a0779b6951f9ae7F
bbe893457383d81228467a2e58df9d5f1d18cbfd30d4cd35b2c717dc660133b76F
bbf2b7054c85cc8831c0ffba64a4cabdc3eb23c4d32ba5484b962d4c8f22ecdeF
bbfa941de4ca08de5ac2912c49346b26f8b10f79c9dedcc1c73b7593d728b8d94F
bbfb59fb0bbbee9e6941d7531aa54e1719671ed000cfb77426d6cc19506cebe1
/F
bc009c7bfbbc8f4c90f5bb2715b2f88462acdb617db354d01214ce91bf2aab13F
bc124f709e0c7debfdda22b0a98dbce5ebc798a8c16477f0129128e573b3a65c^F
bc12fc1a4e756efa8689dfeed9925dee6bea368e4e5e865c6972641a3d1f894dF
bc1b8404e2707eba59addc78201595f614f7350f97cf87e924e6f6dbac90b3c3

ee:V+rF
bc347437d264c256ccfc842e7dd7fc5bfc2649f300c61c63b59dc2676631e404
gF
bc3ad50d23ee3913b90b02ecb46fe4404d8bee5abbbce1bcd8310b15ba6abf16$F
bc3fa21f1527e3d417bd20356fdc535325869f41a856887ba3fa0883c308713eF
bc42b202db19ddd70b5c8192eb30b148f6a3229d05aa0eaa7757cdfab321184e
VF
bc430ed0cfd4a663b76358074912057f989f4af493a6909136e70731ba2358deF
bc48b6efaada693fbc4334eb4916585c339309ea27b400a73cdea90049477bf7F
bc495afc92d333d543576431a1cfc03dccc3bda5282057211d2065d0032129f1F
bc5370995408c827ead95c7505c7c12bd393b513d4e6dcd996f4149eeda69686F
bc63c8bfc930293da3e922e892186113cc420688e28a4ef936bbae8372240055JF
bc77febf9b5e706cc4d68361638309818761fa19dfe82ca91496f40a23d81bacF
bc8180bbf3602244c3a34b6a576fcd6db7b1b882332f6a22471bbdb479835f92F
bcabaf0d5da539b375bef6f5b408b4c4ec6fb3c207f79f771b9a4349431144f7F
bcaf6c4cc70c53cf9b6f0220af4a968ffc131c6372bbda67e1ad799972341b5do
1N1|]>jNF
bccabcae0cba84cc84cbbe98ef845532c6d35b342a05aa650c421cfcecc269acNF
bd49c65cde81a93d80eed77c33ebfb093577ce199e9c182c9d77e73774072f37NF
bdc9a186d8366629fb8cebd6f2da7e719bafe512cf237e1600cb799720208e34NF
be8404b5ebae76ba968eb3364b0d41d94244b74d0af84bd6045d32cd88c42932NF
beeb913c932963a0d8888e51c12b07a6993454a38f7ef567a5a56da4208e5949rNF
bf742dc3dc34fd5e59a231bfb252573f70d7b5a840803d31e860e52fe35f902ewNF
c00c788573b1f8856547492b5c19c3b90b2452bcbf56003dee2b20426b79dab2NF
c0b12c0fdbe123567a7fdef5ac2588a2251ae9765f4962c97c73d4a897684662NF
c1655691384373ba1d496ebdba513f6a4f1ad2c2e6ffd5b7985a6702890f6d58NF
c1de6a4cb5385396b3e8ffd02b9cdbcb0a79b12b5db809d846de74cd4322d1a3"NF
c29c2680928459b5247e613db52774e62b9696ce64b4b85f878cdfd4775a8f05
ONF
c36162f22f8c779d80318cc08d286cb53edb4aefee5789af29a4838a219d9350<NF
c3df4151777a268106f45f068f7a6e09e974ef1222fd6ccbafd4fd2f7307e011

ff;V+rF
bccc059b870905bea5990608d411cde04cf06ed6d3bfa76015aa73439a38a8b6F
bce31a77615b379250e7eba11be12018aecf44bf33cd3d92aba684b157074907F
bce793675eea8330ee5714f685ee6bf75de56dd9f106dbbe3149d9fa9d144416YF
bcebc5d5ae20b6fbf0a5f35a2831414d8ad7aa1ea1720883560416fbd5db15b7mE
bcf2e159d49fe0cc5b342fc05255f862141272c22ce694e38e0133129e1ca198zF
bcfb391f7881055ca608ff7eb04d4957ec6829b99a6cf0fad156e59165558f0btF
bd09647e7e930afde068aa13eae3a3f7166bcf0d4918c52f525b47c511c7b692nF
bd09bb37e73e22a5b20339a2eafaa7a10698dd1ebf5a8bf4c187d59b68d06a60F
bd0b8c4bd642bf2ddec4f60168cf63044086bf8e861160721a1ffb61a553229aF
bd0d1c4bba8882d3e5bbeb0d58b3e9677c33d9fcf22226207d7f43f0540af0d3F
bd2c5200554793773e752c3edacd8567d9f6db98bf2bc3399bb18086f6b771e8F
bd426d0e03bbd097435638bf127e0f1c2cd5e3fbaa1161378173491fadba6adb
QF
bd48e9a406f3a105ecd028149cc4b8df348dc33f19ec4151daa74115a22b11fe

ee:V+rF
bd4f5d655ba5a25030d453a042ac28a2d723812f5dde3bd8ab1a817e87237f97HF
bd55b6e53bef2770d4702bf6fb6bcd13145e761a809da1a07423a7e1e3898f82F
bd606511a1c296702ecfd01d1fa8f5651c4c51d34d4f242cd3fe75de4b25c299F
bd616a68bac2dba0c3050b8d3da7ce5d016fa05d03d2c3ca41e478309141d6d8]F
bd868619b7086e2a7d7b78b6c2fc753b70a71567880be1bb5c40f85ca1a88875F
bd8a86b08520baae3c12fc08ce56e105878e1607594deb88f00c1675d75ef7d1F
bd8ba984e8b76d404b8422b2aeaf6d8ebee207f7fe92acda66e7ef0e2f94f312bF
bd8c7fed84bd9c96c9070953fff9bc087ea7a8ba8cd56bfd5fc956ef76df0492wF
bd9209ce7471aae3638a5d0464764e35ae7dd88dd1526747997c8bbec7ceb786F
bd945872965d8eeb4accc4fc087400341b7ecfd21918499fa21ff68810cb4194F
bd9b457e03a3e875a7f50a246490891ba2bf62f71e73613950b38d17f84d340dF
bdbf6d455da867729477ffe919b5a9f8f2c11626c5047e6dfe129589a1d1ae99F
bdc8ab95aa96bf3f851a6cd97f2d9c878fe34101ff383e7ab7f2c5eb11a13d78,

ee:V+rF
bddae66326cff2ad3bae20dfe8698be8546b0620b72acfdd23feb708989d5e53F
bdfe37339f1054699a6343f8d578f712a70a609276a9b8ed1eee991f37771614F
be04d6f2b74a87abab03f3e5db7bd69c9c3aba89bf5aeaf5464dfb3e90027fe0fF
be0ce9e4ff4bdfae6a6868243b708bb09deb84a5401d6d59e749b0aa376ff432F
be1124e1f840cb866d332ff93aa0c138c358e7a5c45b54ab72d58a19da6c3a65@F
be203dd4714182fcfeef395bb57d7d5e9f418c603b87d6a5eb1ddb4db5253163	?F
be2825be40e44e47e533b1d6e13b3145e41e073086a22147b77532548436e30d	F
be2cf27ae12e4ffcf8e8d79ef82ec36c4c7d67299d1b3bf9e1ceb0325e08de8bFF
be4849e6f5efd2df57c2054a73f7edaf2b47ce5ce34a2819269e10158ee4d4601F
be4cfd2a6f6ccca83e063fb2eccc0c3e16716ba370638be5de4deda72c80848aF
be582ab129bf0e7739face571fb544ef2d038667883f4d15867fa2c2c302f748F
be758c7001ddef751029603c28bb7e9f4c05b54b45fdf3ce79e59de8ae0d7426
F
be7ce57daa28ef35ce7974665112d6551b70b8c48b1c14c9fb067c8aae658533

ee:V+rF
be995dc375c67dc51acf2c699baca627283b58d86d70153bb13df3b2549662d4F
be9e5f7cee095463cb4d9b9f2109692cc190d7b3dd83fd149316ee244992293fF
bea336c1c8f050927b1a639ba83b0ad350d97d65f1c37c25a38e1418af07f9e4F
bea5901fa1364aca49ab785c08b8debad25fab28cdc3793bf3925cb1cd91f136rF
bea9e14dd6778afded7cb4e5d5a5f3fa3b0fefe9bafbf913cd21dd494fc8a966F
beaba5748ba50e7e5eb175940f2356990aa23d1176560268068ee630c38f3953F
beb197d7c2f90fd69f5bfa094f8d100c9477cf8f5bee05d5d87ab41cff92c6feF
bebf3e1f9a460eb53ffa76825f7941c604da28361997c54fd39f0224ef015391kF
bece87454982682fbdb7722fda453b231999ee186bb714b2151fb7a2f81a9897F
bede1b23de7ac03e2016ec4a2b4e29cd230b29837f427b14a2d8d9c06f385151F
bede65036dfee6105ded35adb1c299002018a1016e9efd4163446d8e6a92bfccF
bee03f8565ac02484c05292876b9c0976e9334dad12bbf643dd9f59526e9eb6d
F
bee904f26bd404d9a8fbf3d71746543eca0b7761bcb562e0158d4282ef1ab8d4

ee:V+rF
beef6f9a15afb17e466001549c5ab96b1b00d12812239114ab0ee733cba615f3cF
bf010b9168523d32bd2cae3bab71cda19cb9e2d00bbb861630c256f5c6b49d70rF
bf08078851ef715022279479446f3e390e30bd92cb15b2aed42318fb677e40a0	F
bf168312334f60bf2d480510b014eddac0d80a449ec219c38682ae29ad20259dF
bf1f40d6279d065b649f886d586e1bc6bb518de89df420459f9ba36c8a3f403aRF
bf1fe8afbf03b29de5f3eba68d356ac251478692658c6449b4cda08c73d4d4f8F
bf23abfbb52f27d2a18450e2bbc48bb65f02cee123b849b8e4fb9c07a0e91259	.F
bf404adf3b74fc2e12fa6437b1abaaa8f327ed847a1b30602af13942c9bb57d7F
bf4623f90ace835b85614e7e022ffcb2427a5b8235c7dedd511d580ac0c878aagF
bf547b98a8486311d474acce3d85c5eab20067359561488db6243baf1f10d389F
bf6158e17a81b9067714e7011f8111f3764aec96494c531e4518423d302b355bSF
bf636c3d1c7371276e6fcf8c17bb54ad4a7b3adb5b7ac282711c4d8559a5996b
F
bf6b711d995c2cfcd7c146204145b34ce97998804eb37c62306f383d81097962

ff;W+rF
bf786f7803813a8167ec504e8216dcf9372e8a7df9b4c38050d1db3b93509cd7F
bf7de5cc417bd99213c10e8ad8c5772cf6317388fcd795f4c584548f0e6b9c7bF
bf7e4ecac92c09b957b31c3b99fe5124cb6807feecce32ee6137fa893ce3daec4F
bf842b8211bed6cacf365fa45198ae4376c511311e8e65daff8a87231424ed8fF
bfa63f078bde4ea375db5cc30abe54fca1f2adb2bd5da3b8160c848844e31770F
bfbaa306ef62a274da0c3a7df6f2c28ed78243d6d6b8fc3c909b90fec19c16baF
bfe191b783a11c70daf05fb86e81e2e36d80b7dec5eb2243fa223700ce330824F
bfebf9b332bfdd37851d0e28304a7388d0da7c5c2ba905903d1294494041b80bE
bff0a6adc60eba913218bcccc836d732221469cd7650eb27d199e3f7780373a7*F
bff2adfbc894a60df24055ab573b81c8128737c5d8b2530955f48d64f1c121b5F
bffa643f42fbf585a2b14d6c8bfb9d7ac804826cf20ad4d14bbdc3c996290615F
bffc06b208a2645d2beeed5ae0505ff7be55cec6055ed415ae076e3e74f9aa2e|F
c0008274bc972c590974f8fd638093aa709f6a43093fe6fba3de63f4d87c0dc9

ee:V+rF
c017fccf387f4e86a1ff26de3d85c015ae1bdfc53bf1e30acf131d4aa4f5011fF
c01bfc1d06b6e8d39a0bb038993a565a42a4f152542fec05d266098c4206140fvF
c03292752990aca90663df6d79d0ced6a2ec2471fe674a726f6cb19f9a3d1044F
c03ba838a367a50725a5bad5793e263d9c1c7d7e962a29cd8e0b093cf5a0056dVF
c03dc4d5e3cc2cadf7460b3f8fd8f02f0716c8e9ab44b6c38b6ac28113d2f65d
F
c041cb0f7c5becd34a9fa8c2693fe7723c0e561a13cee7ae61287bfc4ff2eb4d>F
c053243ee1cb35d96150add59e7a1c0861276f5b2a3a9ca734501801a605c029F
c0676678d1a3bcf8ce6a786607357db6145dd2dff6d685cc3e3b7312511343fcF
c072f12110aa95c982d941e51b30f703d3010b75f805ba9c70e921f74a87e54fF
c0938d8860cf5e93761458738a21c3f5f505e71d1669169693c88f8471d51381	,F
c09c4232be25f378a871198874931161c40b1ce864dffbd95137c1d37205669c
F
c0a3bcd41e5beba5e539861177a8ed67f9626d4b21b11ab1b621770a53bf3137F
c0a963a27f23cc436b7364ce694e6afe9a0e8d26be17bc8dc816b46fc2e0f261

gg<X,rF
c0ba90dceb83ffcdd8192f4e130a324c73ac021f2a9b2ccdc98d58cdf26f727bF
c0c2b524cce50372b06ea8c7a4618f02d379ce6a9cbf9b2a7bbd6e21c4a80dd7yF
c0cdfc6bfb60f09c2c483ee32a2e4b09104018a5e00d8f9d93e0c7532e31f72a
F
c0e72c1dbf2c72f272577dc891736d1403dd928b5e9f236721ea261f99677b61F
c0eafbce155d39e1994ca8d23ba73f0a3e34259c7ce6e24278493c4f837c0075F
c0f34781687d2456cffd35d278bdf12469af28f83cafc51ead4a756ded452bddF
c102608096eb8bfc89f563c1a82e55812f85dc764c578fc98b29fe740b014b88F
c105b1034aff6f1bd9548d1cbb3a57a4f09c0231af2d0d033fcce3129be8f9beE
c10b86b4a5c3b1385c04eab748fa24507011e241349fb530ab4df3fbb719f26e"F
c10cbe426290ea35692c88e6f4393bef89f510b20d8587b123e03a419891e2a3E
c119aff62d5c0644926253cc760d84d4a8fbbb2124668b95f93468f578a85b04WF
c13dc951f499e2d4af158a7e69ac636e75289d333b51e67cf3b6c1c3b573e7df<F
c14a2c1aedcaa3d699f1c72757981d99ea27868828762056492a78d9705d6011

ee:V+rF
c16b5a1bf49c89cb3789f39c8dd6db6309830df4d3274cfa0ea3d38e38f0ebb8
F
c174e242620aa57f9c880faa05975ab8a1b3a70f3d6ea6ec30f58cfd3a0c11f8F
c1769c3e3380140052696701ca6809cb191ea6c245caf1c658a1b8bc580f13baF
c17c899c85f4bf07e0a3d27c864052d979465728527bfb0e23eee049af68e8daF
c18739f0ff30069eb1e908fc713e8ef1e7fa3a75c981a8b45cd1383597e8a1e9F
c19464cde9f5e6924a75e43dc5a5f2a6f67fe7b180bebf78fe28c2a9ea75b38aoF
c1965ea7b6eac21676014e538803935d779938ef7971d74668df9e5d24b9f56dF
c19e37c8595f0a36840e5ffde24ba2022e36425cc814639db070930027e078abF
c1a1ba3ae8f745008a0b7e5c0e4663241db1a386d16bd54eef846e125686ceba F
c1a6b5c7d510c383e4cd61ceed4ca28f3f378bc0b62830d40f4fcb14f147b555
,F
c1b656d07a2265aaad3c80a8e621f30eacc4d7131ecac7e66fade5608ce366e2F
c1cd4eb34426e59fd5e537c63a1cf87b0239c01779661465731ea826a0cbe7d8F
c1d7e786bf4c095d0ce6ba44863e3fa1e5626c2c14307901e7bcd56c8a589876P

ee:V+rF
c1f39d4de68160899478e6a3a13d87ca0cbb510af261d0319a2c3f3690cf263f
F
c1fb45bbf918990aa7c9459fcbcf058bc3b97c0e00ccf709693ef5cf9d26dd1dF
c204a4ffd212c3a27c0afea8e7c43b386fac6da8dfb78049b8fff2cea01ea128F
c205e6c8f267b531e6cb7cdabe53c2b3cda12f1afd4735ece2a55f5c116d0159F
c20dbccc7c4cc73173c89b3632eb2dbf33e22faaaf1b317279ecad8e2b1fe49b	F
c21af136e37b18345d2d844866515fe9c44bedd736b4e98701ea2e6a2210c5a4F
c225d678d3f32eba7cf04174d8cf0eeb9ab41ca91d2b6ab7e323881eb77970d1^F
c2282a789d3df8501b91543727d2c0b76e144991275bca82e8c75c83afbe05d7wF
c24a69689734522bcd79de71a9857bfd1e1606898cc42344ee7b089da3406af0F
c24fe30d66c39a6dc7e1701a8503f46d3e747baaf032761258334310ad79e035\F
c253a31b070bc89bcd355eeb3c549a299fb205b9c6badcc9d3e7254057f26ef3F
c2704f809e155e3001e594ac90307613511c21fe04bb1d9422c1476b935f42faF
c2800a0089be75b093cde6c6c8289a71707f6b56b3e1e3655e237dd5229856efy

ee:V+rF
c2a79994207490930e3a02bf699b03b7c209983a3342dc5e7c7ba2451f5355c7dF
c2b42f750a619815728e53e19957decfbf5dc33eb529eebf3fb6b9ecf562e320F
c2b79101f730ccfa892ffdfdb7ce4d806f9960bc302581dc10991c7321dd4e24XF
c2c9b259e70aede7a57ebe7fa8a93a475866d4cce68f6b903edb0875c829bc6cF
c2cdc7a6e9930a49880578ed60314a159c97e36dd96908f892d53e315b1c0895F
c2dee3fc80a476ec4b0960d8a193508056f424e74141e414c57914a3c8f07e86F
c3063c4a546358bcf8640da753ea13f90ccbb18da78588f7c8a9b3011eccfd55F
c30d6ca286d3a7294da3e5596cf791d5c1314667173d02f21d751e689e05d52bUF
c31f2747e3388b9d79c19442e86c3d4556be28b28509108ed5c494f7278e2a38AF
c328c37ab19654e8c75410894318772e2ded988336a832db854b41d7fdb4f144F
c34ab6928f9fde2419804036a6bf4221cb2f3487c33bd131afad5e5573f289feF
c355bbad46f478fe445b10f024dcf94c2baf4e0c856db5be8d2cb654bc37f559<F
c3571b20ed80af5bcdad26c4ffded5902a413e69a9f36e66ea22eb7f0b7343be
~

ee:V+rF
c3729b12ca4075c75da87d40054a8cd81d3a2be928846fec9b090f2282da0809F
c37c5f2481d02ad5543d7d4d2dbddb16eba4ee2deed077d977114cf608f12247nF
c37e4471ce6ce9e562309ca353e9b1cd0725d1ec5d073e80ad7a9ba3f32732c1F
c382bcbdefe46cc6dfe4495a86577e964b1e6d8d445b5112c6f6224c1177b7ebF
c388ede56e4bc34aa4c415c55b4aacfaecac0e8ac63e3aafb72c8678c87d2b5eF
c38c420b6dbc3c61cd71784ca87f3a88f4a61d461e77b66508742c89d1d7e1fd	F
c39c2b1f50d0ee1b0b3edd4f05c23ffa2f7d0cf847b1f78fc6f36f9f4bb83c8fzF
c39f22a6884386aa2ab755116305a2ebdc6ae0a68f0992d56e87e8772c8dc240F
c3b0298c3bbfa69481b4841885e4c53580433e8d4610ea22939be12d797bd88aDF
c3b133e5f06890f86c2c918c35177dfe1000500cfee3fc5ff248faab874324f1F
c3b34b85ae893b22977e8dfafa61a01dd6b4c787c7b37cab2e89df863cc94330fF
c3bdafdc7b5df1eae10ff90840698573957b8409268bf2a94cf0a31564d3658cLF
c3df19c15f8ddba5346c826fd07ba66f82958ff47801b4b8f2b8842525aec713

ee:V+rF
c3e8755371c95986d3d9b24ce2a85e7158f92f26160148570b73b95ab7cc341c
F
c403db828d16aa325941eddc93e7be599767dc0bb4ec3be436c20c8a9ad14744sF
c40a3a99e0047693ac6789e2c35f28639c6c6c3dafcaa8083ab1f6aec4279cd6F
c40a42601b6e79bc8b02eba97fef14998961f2c034ebf3a2c9cf36acb94a8012F
c425b045fd266e2130faf0b97fe7cadc5218ad8cbb8e87ffbafe1d35b166ff43F
c43c6671ab2d1c670d0abc37f1638ba2ea5bc99bfcf4092458d4f333b9d6e8a0F
c43cc5c86cdd41a4e686f3173df2eca34068dc56d75a5a468786fc13989bd5fdF
c43dc5cc0d5557e10da9f67c4460ea748ef4efdd5608a73b33c14113ebe7dd76
F
c441b3fe43905a4ba494377fd18f7afb8d59b3c95abfb93384cd0577b3568a5cF
c4456d3a9934c3fe90a0750649cc735745508843da43735b39aa5cdcaadb99a4F
c448f7707d3e7d90b0f7376b9e91d551448d8304a6b162d474c8cf243b7f11e57F
c44b275bbc2e3ffe972b69236172d24d3e22046b3060cd4282021355c2777c8d"F
c4697b0258943ed3a070f75ed2b1163ddeb2746108163a6b372318bfc419db74

ee:V+rF
c4776c0f7679c318248d6de58590eabf05cbf410c78eb952a8d259663745c806XF
c480e3a1a9b563578db18be5b147c32561044872ed18447819bf430f2cde21c2&F
c4848c6ee81a224b1eb505bb2bf5a9c8572e930973b92319a6e17e294d14310b	UF
c48a58dcffbae76ac3c3c2d01d36951eb5a8df91ec715371c54637f6cdeb4f19
F
c48cdbee47b50246eeff421099d33fa4c714820624f898dd7b17a6940d7ea5b9F
c4a681b60727112a37ddcabfef6cfcafd36496fa1748cd9e419ad0d579eeb740|F
c4ae76d7c6a23e9345f969ab95acd6dee04900b227f0de925cc539ffeb60c2e7
F
c4bb36e81ea1d28a9b054d4a06f11d8ff53cc6d3f1e8523504685e0998b38dd6F
c4bc426d70f27932111cdba1edd2eb69526aef608fccde2da51a6282a479270c	F
c4c001caa89f5bff6fb1c4dbee4050dbbb93bd7c79c16d2c309103992c0b7987gF
c4cc0146e823c14ccfdfc6e0d5991b3b44a23d81a1bc4c2e84d9dd55bed96730F
c4dd18d9c01ea40a453a4a345bdb13d9ca5f3315e69e78ce7e1f9798972a5d47	F
c50443dc25797f6103ba04c6929511b3b0ddfbc2d0ba5c3b956094079715ca98/
1N1|]>jNF
c515fb742f9fbf6e205c91df3d75b991bc0e87b359f64d944d2e6930b0b37ce8@NF
c57edeef8ad80c1218e8f3c5f03298b8e4c78de794ef89153d213f767d7e76e8NF
c5f291e7ee7a541358f9f6a3957b58ba61670f95010f0fbfb4d6b94d30857d5c
NF
c697cda85543d0498850f1a43781d8a7a9027a93e2d04cb19345ead2d9caab5cNF
c756565e383627d473b483efbba85ad5704019846d85a5578c515082ff9cf44cNF
c7826779aa132803da82be7ea0e99d8799ff4ebc7f93d26dee0731d8c1c9f25fNF
c81589b411d434da5e3ce899b20f0ec5f0d89e805bb98654a0220574a6567a5eNF
c8f7c98bcb2f070e4421790cc39453b0046912b5c8325ad6660342177869da6eNF
c99acfec136e15a54620f53419e266691c0a771c09aa286798ab5aa047dfc846NF
ca36fb0f490cdd14f4ed8b6ecf0440998542eaeed3c3985f7357025964231df6NF
cadd165d38724eb665db004d9c8b750aecb7c5d88cafaecac40cf6bd136bc3b9
NF
cb5931215d156696cbe58219e39202ac72b87128adece13396ffa94ab6dad395NF
cbca2af9e05f80103f7d418c99cb1e8808a0b5b2aeb348a19e6ec009ccfe7972
R

ee:V+rF
c51cb2eba6f030cce0b81686cebf834e0aad1fb747875ef6fc8d06c6930fe18aF
c5210f6bcc42e5949db2d2f133a369159d73a960cf7abe1a47a4248fe1d48491F
c52c2ec344adb35fb699f72d9fab8082e82e08caea1e844a3afc83b4ff564820F
c538ef407bc0967b16f615b25eb59fae617d84051826819aa6837e85e7ff4db9F
c540f6cbef4a78a050fb751882916735d1bd6054d8c177140c200cf31eaf923f	F
c5512bfc8f5d17195d34252e20dd34ef75e390d9bb8a38b30ba8be4e5c0904adAF
c55fbad2b511346ebf2a848c75861a87c98b38738226ac74429144324281ef52	F
c560870127d4c5652e42c74ffbb3cf96a864ca994702fffd84bfe5a6b5275464
uF
c5658a365bac1d6a010849f23983b9904b689b2d9191ee2bb6e12c828ec3855dF
c565a665dee8bff0a1df1f9e228b65e7935723b9a6e91ae26f4b30dc3b90452bF
c567a821a6580c7066f9d12f98b47ff92838fdd821cc89005118e82149703252F
c5741b7e80a2b537f19292e12c2a7fc0a403f25be8a24c117ecec3e7b88a182a
F
c57d7c3a751af63b1ff3aecc767463cb46fcfcea3212e2b6a04d39baa1975083	

ee:V+rF
c5857421c619421bd4cd8ddb51736ad8d819352b2770078910fd43a33461df77F
c58619a42724ddd986279b0da66e4cf0f075d25cfbc11cc80a105c9c47f0cc1c&F
c59613f8305583361be758cf7921fe48cedfaca536f354535c5dca03087c3798F
c59ce9d5e2b28c278b947391fce0c591d912b04727d6141c27262cf98fb99844	F
c59d4299cbd7dc796fc38b8ac3ad9e4a8030d20ee8831940a24af8b28a84cca5F
c59e261df9c78880ac906231fc2cce51d269a2a4bdd58d5cccea75abe0465c0baF
c5b3418463d5359ed0d1cfb6d42a2b588d5ee49a2fcee4755d55489ae9e78860F
c5b8ab0d8d7cb70f48d43af7b11ed34cd4a069ee3f243e0b5c1601adbbf3b7baF
c5c83afc05bf26a4cc57f6113c9a03a1c709f35aca39423aa00a65cde5710234F
c5cb7460760e2885f04cef6e4c190e295bc38c25d8654fc325e8b08c5f835ffd
F
c5debfa2df24c434430b601b89c524d821308d5207f350610e556a17360391b5hF
c5ef38f748c2f2a1c21e14d6274fec8b3391722d8c6c93cdd5f977075f798d88F
c5f0f07eae306ab7f2f7b4798fc0f577aa6584d592fcf290ae03ea28e66a9eba_

ee:V+rF
c5f6d5239e70240eea7d64dfafd3bbd553f7681f7d2bec1a8ab1298d606ef9d2F
c5fc7f37feaeaf11068007f084d0a7046d1674006226de685b890730ee95e3c5DF
c61d2053d483f06c16fe09b040f911571abd663498e0d24266d849b51fdb0479
UF
c62386a6973d93798bd5a17ee72907932c0796c21589648ab5f313805f6ae46cF
c62e34aa51c1c89400b007376b014e42f551c284ffea7d077883fb2cf5673bd8F
c636f7b1ee487e382b84fc78e7079b3cdcbe8a18b64dbec20379bad79eb119ddF
c6531fa5a214fb87e4f247ba04ec04f2330a77311ac144e58229390092eac77cF
c653aaa3759f6c65e6ccf1dafa36096bf4821f315dbf756943730947258100efF
c6578be082e094285bfff45773f10ef576902f4e6d7f9f5a58b810e7e4d8ab9a:F
c6779b89961037e58b7567513d65d8d4840f1a7a23bade7e22a9b02e8b3af7b6F
c67a99f8d73138551a0d40218c32828b28c8df46641ed69f149aa858bfb4476cF
c67c4c4063b74aae72efd079229bf2ca2167a39844fe319e3e726d3df81c4767F
c6835fc2dc5e5741781c97f0dd76cd871e82a83dded531a6ca44d9a58abd9a2a

ee:V+rF
c6b55809244b010e1d1dc344b9add936f4598f2be100373d25749f6d2da8522d	F
c6c5c2f11ff4c5bdd22deb3a88852ae012482664acb196d328e4b290495979edGF
c6d99f5b0af764bb805c8a25d287df1075775cac7560d92681c1956e45be1836F
c6ee2dc7f4859cf7e741172a64ed8a91fa20379d8b50ae273712fdc3b54f8d59F
c6f14dac0ec25c398840115e52a340353f02aaea3834f3a0eba9c59477ed29acF
c6fc833a542f540c1edc0431e34f06b0cd121fc635294ae62ae5d48fab254ddfRF
c72af8695184bcf71c7eb184fbd1f20bd8db5be9ccb44f698e3109b9ac66cb88F
c72baaba3b68e23ad5857f22697380908c1ca9201e4bbe875f13601fc99a9465F
c72c2effb396db8fd12fe1bf50dc5ae0543a4d684cc6990bc2a8f8c1c707bd2aF
c72ec63e342428ba130a7b46db76c98e1bb002c13c208a1768a433c1cb1625f6F
c73295f51e8bcd58ab89943d676e27d4d7473a645904454667ae786d5b948bebyF
c73585577567169544907d481ba9e354f44184d1e11e8bddbfc58e96334f4a21qF
c7423e39173d9fe8056ef70f6214e1c4f4af271fa10cf07b321ec23fa5e89359^

ff;W+rF
c75a27c33e9c743311271dde24228b03ec56642d945c2ce4bec9e63ef71d81a9F
c75b3f328720ad1b052e7621ddbf3ccfea04b35a21209225248e310d623b5644F
c75dd0b94b1e1300b04edfbfa5a3739573a6f83dc0737110d2f8cfedfc5ab7a2F
c7607cfa2a4a5dcba948ec0c8b744a7f05d5113920dcbe14a16acdc6a14166b7:F
c7627b2a018e4b1db2b6131608528eae404bf3c43ab252995b1d5f7196ab97e1F
c763f6d47ed5f33b5810818fd094773ac77ca94070088529b832a5189debe293F
c76608ef79bd1a9fa553bc282e40bd895ee744ac0f6b7a570796bd2bef414ce2E
c7663ee5f2439075ade107aa7f0383f301032506d3673446ac4c84d046337418bF
c76bb943b6a1a6711f5c6301f55730c1b173e983e6b7b095c9d0135c7b6a52f0bF
c76cdef35908893f12eaa11205c3140dbd9f989ea6e01fd9bc00741c05bdb4c5F
c77668ed49c6336ca11d1c0025def5d4583d666b6ee85808328364fc1fdd0a96F
c779ed4a8b7cd8df613f47c214050d61ac25927ab97381ffb59944fb998585ffFF
c77e3e9c9f9cc48a40bb188838bad833e1ea361ee0ba3424abed546f3945d701

ff;W+rF
c791e843e2fbae086343a6654618fae6ea425f37e0816212e9805136c98a236cF
c7963550f0e18a7fdd4139bb7942c93b0a9cffc5bec4e5833552b722e442120fDF
c79764e439db44bf5b1a2d07e42ed27562693784744a529c9d1f300ee54145d2F
c799c7a9b990e36dedf9785fd1b300a75ffe77c3f8e0e9074d4279a3d1d85cd7VF
c7a38de9170db3ea671c715e4f878f1c3731c4a067bcb77c2c9827c8cd02d694pF
c7b50fc58609f6e4057703fe1bb83fe6a7c2c9ca068b534e97ac8c7a78e4c8f4/F
c7b6417b605af3adcca501eb73c1898aa00b4691197c4567e74e721dcb034436E
c7c905b4d230c3305d7223c1efb2e2c29d90ee0fe667ec5973b84522b52f1b7cmF
c7da8cb6d16db2f0182ecd0e22414d98692b3d8ff0b8cdf1e790afd09f8825b3F
c7dec18b5dff68e91dd42275e011d20aecbe60817c948f50fef7adfc8276ec34F
c7df39cc317144af8cab982c0134ec6182c78bfaafe8e47f94f33a0cd4991c97F
c7fd61c26b7aa8ef79e64d61f67cf2643bdfb67b8af8ac5993f3fe4e727d44e6F
c80cdecf0a4d4edc4e52f018171be3aaff999a6abe4579401f05dcf51a2e25866

ee:V+rF
c81f90a03e1572c395b80f30a24efd34def63ec2a53550ae57b48380ded6bcd5F
c82b48182722e9c7204fcb4910d9aa25f350db17be47eea64e52281990462ea1pF
c837dad26046c4672910508d3f90d5dca273c22c3503ded2f75eed49602908afF
c83b382761599c654c4924c45b614f3f44705f0072d35ce4e89a498f643de93cF
c846a72195e654b76f0ca3467ec6a0e034d1907a307e6d797b1e4238ab8e1949%F
c8476e1d935321320f812a72c05a7442201d6f34050996100637f18917d65923*F
c84bd4cd2d437d984953f25e00196fba34b6d1f25cb29da168b9469d4969236eF
c86aee9cf2e2da2f84035f7c561f1365eee34235321b9b4983b359b9f5cd8060F
c86d5aac322f831336236ac7648dc4aad9c1aba665e21ec635d36c1ca14d7092F
c8b6abc5626065638f17e289f7fb74fa496ecaff7832cc8ba0a863022187702fF
c8c0d6d376e5a026cccec4e8a7f10de5f58b0178fb266a8f627d285ea803e25cF
c8da0723eb57ace188d0bd03e37e8827a42913c10542cfa8bd6bd8817a724916F
c8dfb7c69048e40d89f055121f7bf399c85c51f08160824fe50d9434c253a4a3

ee:V+rF
c91dc3bbc7593fb7442fa9ec947f30d95bad094d5b4180e4669380d535253bb7
sF
c92bf980488dff6128c5564f2f75712ccb2a9a0f859f4667af435f967eef4c45F
c9392783583e0597ccdfaf17dae6fee1b00c3d8da0cb91842328276045fb62a5EF
c93c7d0870295039879e0541eba827c632e03b42a8662810fca06462a79987f1F
c942cd6a2b252aa88c37729e5753a20d63376cc0d329bdcbc5265806440a4f46oF
c95477083d786f35fe049b4cf228df007b60410ff81fc37b0e6dd8bd2124cdcc	YF
c9587fe47330c8c9650ddea3de6ed9574b7027a816ed5dc48c5f19783f043700F
c95a549af2d83400b97e70bcf7ebf1fbbb8b58bb768c6f7761edc982d7326504F
c960158be24b783ab7fb4a317899b83f806692c1e48426fe46c6bee909357ee5F
c962e5dd6d3414983350e5da2de55b057477d165e891c9d963cb8eb49a7c6330F
c96966864df3d8f7e446dbab1aaaf13a2bc50887d2c246af4d21658831913c1c3F
c97d7ef5a7b53916750b597fabf99dee5bcb2c1e382ef0e3d179ca285ccaefd7F
c990d11d35716ef252caf3630273bd9502a4f8556105b0ee8005c3164ce118df

ee:V+rF
c9abea6a673cf74708122a7d0f1620be7008d59c4f0a60af39850105cb52adadF
c9bd64813e41abf55c807e7a4e61c62906d1c51817c09e583a7b4306568104a8	vF
c9c2a62c7fb170cc9007afb571d8b9beab632b42aaef2f1461f8ba0a2c5f6d9a	F
c9dc78f6c0e94a26844ea7d1aa7fbde598ea704957ae7b657c4a63c822bd9f21F
c9e8e27be0763433d2342ad0573164a56176f17826d8830f39d0e08518d54127F
c9ec93a5f3a15917b5ceeb7e19b67519e6e4ed8b7b2df39dc7999cf6d9f4c5e5F
c9fd3024d128c4accf8a1b5a9b3207e10e714a336f6fe04b88a1d557e2bc7a24zF
ca0dc93240a019ed96e9975ce1f61dee6b3765eb9bc098678f11bc9e92d8f8bcF
ca1ec435ed2ce96fee64276f36654333806f220fe770817ae10d14688f42be20
F
ca2161cc3876646306f0db5c0e9ef5cbff21e55e209ba8bb3bea3329c4748d0aF
ca22627ed1921f923bf0d6590573bb115ae89ab16f2cd8439ca78680ac859464
F
ca2534fe257e28c069b648a161fddd50d841f1df267a98ca33d8ceea488d83c7}F
ca324724b8cd304f2f0526d1276c77c5ee70b667d98887859d364faeda98e532X

ff;W+rF
ca3865c7f4066896a26c6e00f973c8f6edbfb58dee7538f4795b8c102ec8dbf1LF
ca42c81542be47ee686bcb3662bdb26e91f2fa0041534bf807e0b9294dcae15aGF
ca4ba17177c7df277d3b1d022543b4bad6f9ceff842f9b3d18126d3f7bc73149F
ca59a355697c31c9ad51c2e64ca52833b18efc933c257e7d0dfe4f7509ec425bF
ca5ee1ff2a858d3eaf6bbed3a7c0421519183d99018689b9d2bfb4f8b2bdb122F
ca6596355a07541ba770e0a63ceee3a9117eed3bfcecff0d30b56b32bc0d60160F
ca696a4355291a8491772d196b5e4adac8a368af8fdbace8e9c9f75724d2e4b4!F
ca6edad606ed1ae0aad8a9ae177f501264d15718f85d304957942d0ed5768647/E
ca73e4d1c2e57869c6e300075fa3bdd65118ee30910c0ed450532b3fd0d7976b#F
ca7df206b32aa8f478b9a3751e1c7049c9f5302ca5417f2e0531f4bacadcf5dc
F
ca86ae6d34c40dee72606cee1e52e0dc9ab807fce4ecf71c5fbd47ec447bfbc9
IF
cab18530e297449d292d630ec6e205013f25a4889616836298778283e58c4646F
cad56706d665a1639372b33e26f5e8b2d45d262ba181a414599688a30272bffd0

ff:V+rE
cae6bd3ac4c68910abe44b5f1d6e48b99b76914d3a6223b9511bde08f8a3e1cd?F
caf6cf5af9791e8fd3e3612202b1fe3208956e0f50b7add46fc8761ba8265cc3
F
caf7f0adf042b63657e0610f87dbb3aa3334f9a81292aa836ddc648117954f9d
F
cafdbebcda7664e47d81f647d715249983cbe0bb4b063c1d56ab327a8766e2d0F
cb0dd1d2921d86e3d93f0eded02f6d9dd60ff0961589b65e59561cf10654d493F
cb1bac17d8c7b1c7813cfbc4a050c0bd153b06a08874a369c55a1597e25d5a52
)F
cb1bff3dcdabc1801553de1e4bae164ca1ca0aa473eebe3e7afd8360d53dcad7F
cb1e709d6fc4d17df3ff827f54f59d30c0e4cb11b30652b60e0f1087d387bdd9F
cb236ed8e588d128b8cdc78afdce6379dcd39b817725c547e7f06734476accd8F
cb353d5c74471de09be7e0fd09fe8cc300e96b28268cedc2c0c08e286daf5f95F
cb3a549fe050cd75184479500b542065e37366ce62d90769646352bf2d9798a2F
cb3ea59253d078a2c7a60ff6f6c3f55bf94679248c132be8e27c534245acd6c8dF
cb56c1afbb8da7034985bbc168d9be562e1692239a7ac99ac69557a2743af4cdO

ff;W+rF
cb67d241eba9a27bbdc48cb45a7d59bf2fa393abbdd65778e51bb78396255ac4F
cb86afe6203e0e076f646a698b5f55cc194b2523e731d2af6fad43073fedcf79F
cb86f1399947fbb9131708d22997718ff926c00d9e0cdfa9ce37811fe7e47e4d
YF
cb8ae6ec45ef9ce08ede28575bc163dd1337f4776778e13ebf08457f0470623bXF
cb8ea18480b29a851f5294a367ac6b15344338149139ef7f7230a7888c960c7d
}F
cb8f53283b6ea93d8c0582b7445551d68528dd0bc9eb4f0843b5026088dc7d1bF
cb993c6b41619d0b739c98a53cc2ca52430d470822dc5d7f74a0f2761581971bE
cbb13427dedac5cf271bc5a5113b736a34f96516510eb972cb3320ae396950fbxF
cbb6af40c795f009b496be4951e5998ed66639496f46e7e7cff519014726e16cF
cbb9fd109a25fe1c52b74144b6c1416666fbfd38ad1fd70a31ad0f95e9ded252
F
cbbbf0c961b09325211c498b9b16d75a582a8a2c062653a5a8965090c1ea66acF
cbc27f39937173e8134e59deb6baac91cea3e9497f76d2e139b4eb64bc1aade3F
cbc4ea12d67dbb0aec7f99363fd0094c3b67059cbe632d6140c54b02128a4520z

ee:V+rF
cbdf552514fc3c8f3e787e174fe5b17897007c1d1e76bf0565f3c48969b03d86_F
cbe559a32b73c61ade8a92a3d95bf1f0a39b70082feed6bbf79aaff46a5ddf19F
cc04b6fd7a53d6566cf64cd227d959dc95f522bc3b6e773b8a1346ff987aedd2
\F
cc0d2cbf6bd6a4619b82b4666f297b6d0d894f6e665d587919aeb24e013118a5#F
cc2af8b460ae945f1afdf5f03ea0b48e40aa3372a33d96e0408d1256c8c0294eF
cc45c070a71c4c4e81aafc430379ec90092af6bb68d3db667d3bc265f3e79eceEF
cc499773d5b8e2ef0f1585f8f54cda5bdf26720005e766f1ad4fa13b420b5f7a
F
cc4f393f3dc8376ae20557ef6ef4666627e5e582ff7ecd121164659a24781cfdF
cc89949280e927133ec7bcd3f3d4e2b299ae223f458650d04bc324a015418f95^F
cc9292399132346f75bd097e7ee2df57581d949a9ca4f74d5d800c7565f777ecF
cc95d52dd6acca1790e3c4f0dd8c26d939c93423de333d2066dece7bf767d545F
cc98e7151dca218503a6d908ee58257a7e7958347117c435c93746255a841c89F
cc99796988903240582ca2234451a6b7eaa5f9534e910f4f9838cbd024cc7b0a	

ee:V+rF
cc9eef61c95aebbc7a432d58f5f85fbab25f19ee777834f671bc23fa94964d57GF
cca2c300e4d60c107c6754108edbc965f0f6e66119848ecaa71eff8b4c7e5961F
ccaed81377566681009e212ad6067bf7a462c3a7df25aa078d71854dc61496baIF
ccca4bce0f9734afe3ffbbf8289dcde7d83df145008c78c72d9ab7affdddb8a3F
ccd6b1145000587fc43fbba493221eba1716a9183d64796c8e42beecbbad5afc
@F
cce50d5874faecf4616bbc5ef77e0672efaef940a90870c5d652dbb07846408cF
cce9b9d8e55d003cd7be906f5603d626c0f14b8e422e5123076eb85b9dab7694F
ccec65f2954ca1f6ef27f02d35bd7687f0c4b6e784e48233282a82c2e5f53b7aF
cd00145bb9ec1111aeeef6a3549e8186d773009d553f2c6ed0b608e4fbd9adcf
F
cd0ee0b99212979ff9dd5d920ddf6f8d82ee56bbc646f1e3c3b7e62a102b1186HF
cd15c26fb1146a5e8fc006618f54a1857a651b59524ad0b43e2de55f2ecdf4adF
cd2e66ab8554e43fed6cf3a6fe7067b925de6a4ebe0acd82af46e341ce011229oF
cd38869a69886ec7014b529b0a5e2a8c6f5cb941544d083216de2f68d1db8abf
1N1|]>jNF
cd47da0bf7624d9af2d98aa4723dcdf7e0ce48932c9a21df223ff98c038a0e30NF
cdf297d87f9e31de2e54f1bf4d87339af059f5d4048b6160bee5114397b3fa21vNF
ce5ed6d89d8f493b333f990a74873904d861f5b520c9b0a8be3c6e2b614068f7qNF
cf170bfe59fb4723dcf9f79d8e4e924c16926a7fa50ee45988c38123421bfff3sNF
cfcfe9d9ae37170dc134b041696f09f451bb92f77ec37a8f19b080810bd0f006
NF
d0502f4f4281f85dbdfa765998b7f3281933945c8291d40a49d1ba948c4c59c6NF
d0da9dd8f5ac62ff338820e4c82cef86962fbebc7eac9dcbcddcf8b7b61036baNF
d161a8ffe0e1f9856548b6a48619295b25351949a76f0c3447034360be168304NF
d1d5c6c9105983f9ee30842fcf4a13fb9df2c9ee2104e6df95600984d8d0c9edNF
d2642493abe4c602af8bd00a8d0954219b93cb84fabd9870230cad39d45b9ee7	NF
d2df50179ec4ae53b3b02398bb8ed1d376fddb157a0b2c4996e0c09559793409yNF
d38a715f8c0b25a49a238ed3f75475a44586f7371a1cb8df82caad826f4dad72NF
d41f2ba7244ea561f95aae87e10fc0d097ee72ed2f5cf1cb1e7455374f1add83
c

ee:V+rF
cd5dcd832d5dda7bea32dbdbe45ad8e13ef022b0a9d83e5b78427944aaab8f18F
cd61cf9c12e868cd95161567895609d82e39f45f923f851caab9d599ebecf0a6BF
cd7a7f077489d8e2a9dd46b53fdf41995243a699f3fa2bbb47093c9bfd7d9266WF
cd7ab4d402e24250450215dd316bc8db5cbabc2abdaf16110521f6e623589deaF
cd7d87fbf38e3d491a5a8b262d70dddd01ac00ec722b52c01b44e67f7d8c5a66	F
cd7ecade58c83774da56075ecbc93181d0299693efa4a31b09f39a234ea8c0d8F
cd951b49a8dc85630b344b12bc84af00fff22d713c5869528aabb40dc78fa0c0F
cd9f701311cf726c8b434a5ee4f0f2cb6e0df53b5a843c3ce0633217921b81dbF
cda402fcb291052201381d37c733af954d30e2e6e3f24e5b636ae67715e8c0d0
F
cda41b361d863ac2471e67f30a37dfa1d776eb1ecdfd24b6d620d454ea726cf4F
cdc630a6947d25b54a576be1d51170f8ca7a920b446adaa54aece61b239e798dF
cddc3744f22b625662ab15986f90fc202f14ece03ac5fce4fbde2d656b5f38ddSF
cde329dfeb5e14ef8d11d694202b0c974945910ba3f73f3790e665927fce7c52

ee:V+rF
cdfa438ee0d5eaf9ebf066c879fea0ad0e14ef3381353d9d8a8f249ff220b2afhF
ce07814a85fabc6115195714ab5d8670ba930a5369258eadf917f899881058b0
EF
ce1575869a76eeb5a281f8df3980870380850f3aff9297f84f741f893b7244fd[F
ce1840da43b758b433ff86f3ea7b59008e2d64a9f66fed798463409de17511c46F
ce1ab686b3cc8d98f3fa3f3c27de632d04b3076d3a9573953d36d0cc337b62c3F
ce2818bc990e044731480c4212c5c16d899dd8492d225c3948f138e58c8031c5F
ce2b479d726968ea27bfbfd9dc3bf20a2ef62e6ab1f4d3b4a0e6d4230a9ef0ecXF
ce32d3269966c385c52153f1c95ee8578b768a8b69a1d2937f50ab40dc45e380	F
ce32f7bf96aa04670b34d8d775667ca1ef2afcc5c614f240767eb7ef1968722aF
ce3a408dfe9ac91c4e9fefe4168ef2cbd9d6d18a92f2dfd2e36b2b7af8c8b103F
ce44bc6fbc305c3861c8d26e236f8872ccd1827001528bced75ea5a087db84d4F
ce4f5cfaaa8ee847baeaa1449c9bda07462f87ac1b32027dc3d2b1086d417890F
ce586e3bad67654fe73ef5a5f9ade5281e7611c7839e8ee28c76f1f48753cbfa4

ee:V+rF
ce776b97b4d788033910fe00975ced115a86f293d3c25e4ef91029227b0d3a15F
ce7d925a850e5e2f13538931031755559aff5bd0677306a69a885cc9bdc20822F
ce80d24890bb555cc41eecc7ee95f5ff2de2c648c51eb9f4c10e2d48275a1c45F
ce893faa55582d8281001d9876f4ceaddca9de5adf25f32692196a6e85a1aa48YF
ceb4699a86911fa2a032df43313a18847098f66921adb5fab1298f3791d1b144F
ceba479b3f7e61b1f98d50e4797543b538d563b420b419155fedeead08a06b2erF
cebe503265c9efa9afa036f10cf99ab4d5eeabe4c13950dc76ba50fc4304f4fc&F
cec370a7441899c3ffcd47f783a0437d9d649fd4a1252c6c317561f431e537c4F
cedf74bcc18ccfbbe277b033c31b3a65c6fae8135a0c90fadef65c35b5da0d1cF
cef38591d6d987235d823aca0105ccdf5c702a3c16a3ad8301d64d8cc9b6ef5dF
cef919b47e2ac46501512262000f8aa6f2804d306139f51f0a7eb8a4f8443bdaVF
cefaa998452e2e34b3a59dbbf972dd1e45e2bf1e4bad5a8df4b34529aab350b6F
cf01690bbc873920b5a486d4d4e6b92160ae532f81d1ce1045c632c8c0c68aae

gg;W+rE
cf312b0640aa93a5701862f262416738887b1618922b58eaadfe16d281c1fa7dDF
cf60217ce1218a1776d98ef45492d93967a6f10369810ef6bb833bbbc8bcb9a0F
cf61322c3e87c6c21ad8be1051fa2d235337e2a97a9a894828a70e5cd12a2254
F
cf6e5c1bef9ab5c56100beb91545140ecb2ffc878294ed3cb87ee4d53c82f799F
cf7edef3f54d6a2816515812d2f679ae21bbfb26767bf64e34b73d19a3bce3aeF
cf810cc7447c597839d02d5738646b8afcdb25edddcbd9cfbd3173d5a01cf3a3F
cf83179c708ff22b53ddfb306e537749dfa4ac8e8f7f820be6740d1988c8ffc8F
cf8845ef810f6cf39ce19f2a986496e8ae2fed2fe5d711309d0e91b72b693e29E
cf900656ad664e99d27fd815261164678b178f186d6fbadf440dbc7ab48fbbfe F
cf9c2b5f9dfcab24dece292fa32fbddfd9d7101708606617b5bc07bcc4a15756F
cfa48cdc2568095e4f3d0e92a8d3efdec6838bb0b3f6920c55320674e7a2a3e3F
cfb8fb181e4fcc069e88e40ad4838b6d53339b522603c2c188f4b7719a7547d1F
cfbce8f5d94f01a7ce8c1dc8545168b7c3c1c2a62bae89f00a69ebd439002ffa

ee:V+rF
cfdd7dc1c23cdb3468016785f9f50105c16d23f98222683011322bc94d444700F
cfde4230671763bf6a464de9ec8c191195c9ae864571afd92bc7bea8dfcbb11e	F
cfeadf715a776582bc168121a31f85069becc17f2556be2c3ea11c7d6040209dF
cfeef0c73c66033047dc4cf15b633dace6008e084cb069e2c95d1c60abffd496F
cffd614b0edc8b160d92daa7f3c4c4dffd5e33a66532c35ee32132d1b56e63b7F
d00284a41b68e575da476321841fba290849066dcd50949ee1f46e5984294f6aF
d008be734234764be6a4c1b2f1c97cad53b746ecc9d1086444715833c6eb8450F
d009248700d9e5dfb31d429a3fc4511bf6d988ab6276af506e8279a020138c9bF
d03be814a86828be3841393ebfa51e9a8c3907a53dbae5960d470f20fd79d04c[F
d0428b24d84b75519bce64c115f13b151f065712ac094dcd035dc9b63bbdc664F
d042e5b60af5791405d9b06cced6de982519177eed1cee3e7edb8c9002315ac6	8F
d048e9282e3eab42d5adfd632ef5cd029524100f32b305395da9da9a0371c460F
d04f4f2c802e659ebc50e30c425e08c36096ac47223dc795afdd8d19c31aeed9b

ee:V+rF
d057cb97f19e0b7a6e8769b9407b59d09edac0f8548ba4137a65575461013ea6F
d062a6b1a3c9142376097e0924927205723ac2f41ee8c930c3758a81a1d31221+F
d0654dfa758aa2f563a1f6f4f32f87d271d5f810da3218400fc7edc14c9af188HF
d06a6708c5a849908340ed5c521556ec87aa647c040dfcefe01d9e5ef19ddcba&F
d06dbbf76b8b169c1b023c46e3216cb5da8af23e885d61da4c9547057c30c45cF
d06eef6e09b25151ae88be0acd91ea6c0eebd9c3a619ef2de948701f44307288RF
d06f004563a6bdeb574cc83ae16bbfda190879efa994a9182b24e45eafe5a039uF
d093869ed5878283193de6a764e7847674976671131c829603d9981e56660bfb	F
d09bdd004c3fac87661119d619afb43d9ad9824ef8a2e58fa51c55f0211f12d9
F
d0a250d18f4b89599438cfd448782db11f8012472af6df48eced91d60be23eb0F
d0b3530450134364f48fc2529fb28b6ba4924562e2743be8a4a9531df24ce934nF
d0c3a21a7ae050cc88bb11365edee8ae76ce4656de55be60d371d691353d0a2aF
d0c60cdd0430a434420ef3cbcd3cd9ebd0e4089f8059b3a3b7bc427c158c0505'

ff;V+rF
d0e13c7b2d8069a8e53ad1f052d37d201f037564f4a6b8c6165af57ea91234a3F
d0f3c1d37d812e6fbf2b4e853fb66fd0ffe2a908b0bd0749ea1f99b53198ad71
F
d0f42f7832c466e0318f15b6905f47d9e8977a198c140303463e8baf861f9983tE
d10825f54b07b6022f065b39a4e37c8c89bfdc877a230746fbbc048f9659348aCF
d1092d59f303a24817bad40a23bbaac2dcc1d56beef54c5d1c3d42e225090212F
d1270ff691bc97bc9a737c8556081408a04f2a325ffb0db2fb561a7add15d0e62F
d12d34da150d926afed7f5810b9ebdc562f483d0100cdce78091fd464612301deF
d12ea2121d6e19b9305bc2887e981903b907ef5b7969c1672e397a125e33f070F
d13238ab1217026e026ff8cdb5a027315b909e6962176287bb83b326f33c5f80F
d13a43c2f72be1aac5c18bee475d4bf325e04b8cc511f75df749c29fb616adc1=F
d13e07cfe07df702ed4d93300184aab0f5cef8ffabf3d2182655dfd182050683F
d14497105b68ae6076141f696ba00d9f42a831aa982b7bbacae503f429464e72aF
d1505aaf07075307e949adfd5133dbffded6e90d371bddf5dd1e04c913a8a7b7

ee:V+rF
d16ae7c3c974cef652ff9b87037d3450587a3df6ff7e04c65cade8d7bdebe945
F
d16c70a8d4f77c28cd4ccea87c2c453deab255c95d8267f88c3be5f925f8defb|F
d1779b88b2029c7b3cd102334127e7013a0a71479581fd2f04f0d23bbc8a0463EF
d17c2ab42cfa6667afaac7434e92be20fd0330b7a2cf8ad897daec993049f5e9F
d17d23e9f3e2cd89c98f84ba07345a6c51f1dc3d67f5d52d483e6f2ed2d93751F
d1870d7298e93c62411f7b0b728df981e13f75ca9fdac1fb117b0e2d50d3b71fF
d1937f2c7485f2270affb2fae284834c2bfb13cad80964b9cd2717fed8279cbcsF
d196c69e20dcc6a970af086c699d1d015396019ac8638386994deb8017fcc72b
F
d1a6eb397fc04c57428b2ed1f9e3077ed639a5877ef02b2312725fb99c17c807F
d1af2d4f355246306f9048649c71512ffc060b2884722d14e15d42ae54300524F
d1afd88393ffa5ac982a19f815f212f48fb963ea78add0832a9de497411e2322
F
d1b44c5bcb094399e0bce41de4218e28b8f69fb0c0a79c24411b5561978ec6b5	ZF
d1d53660bffa4c0d03720470eba69755d1fe600ebcd13dc49a736237a10983eb

ee:V+rF
d1faf007d61466191ae5ad07935839a8673f5e51b6c24bd3465e5503da56f20bF
d20149409ae526dab742784b326a5dd70b37681effe645a6221fdfc0adcaf401F
d209fc6a50302b35ffe0a948bce5c2b144f66af599a404ffd4a6771e24896130
F
d219bddd9ca9b61182ef38132b073da37b5c7b6727fe9ef79c35acfe7e1aca0eF
d21a1f7149813805ef3c6537ab7c9dee0567804a8f9983618aef692ed579f292F
d21ecbddef5ee619c1909b27a81f4793db8cbaca93baa944afe265fce0c076c8F
d222b43a6c9a83d63e9c529e8e528b248aa0f77b4b23e5e7256d32c1a64bee44F
d23dd2eb44577c74053a9b0d2df44d8fb4618ffcdc560bc60003b1393107baf1F
d247f05fd2f22a9dc59679f6c668b92c75b8f5beb481c99983a0b6d26d10bb08<F
d24805d0f00f2158a082be3fd450a90be7ca614871fb70850db6aa028a020d87F
d2490b1f0f83f60017971858b0aa1f5aba0285093f3b53cdaa0e5a1dd65b282bF
d24b5e95b20420b1e37b28037c9bd5175c6fbfd17e6a78347fb26b2792a126efrF
d2619ceca8fca7e9ee19cea2143fbd219429e9f9b06409934c366c8d6fb4cefb

ee:V+rF
d264ee805ecda49c30b17382368adfa7d60dde5fe60862b200ff3a5b11b02cfaF
d26cb8a2b0d5538a5634e8042449259bf4e95598e113a4edfad93ec1ac17e831F
d297c29388bc4f582e226fb85070d6108bb21fb17acb88d7d2de900bfcc84423F
d2ad19a42ac73b25413d43fb03cf20d85cde9e294f4a5948192ea0c673669777F
d2bc75a69afc2e940e2a933c55941d7c4f269ade992c161c681b9cd72ff158a4F
d2be459c9fddcb43bea87bad5b80c2656b90fede44f30c5bef1510d68feaef5bF
d2c498e78241cc2d36124d37d4771f877da25de95d6a31c1ad42e1287fdda746F
d2c7c9daa4378bb677e4fa893b6839ebef8009ea1e132569083c4a845ec60a22gF
d2cc1f66c9ca4847924aa950f6bf6e884b94331ad97c0150bd241fccb76ae118F
d2d500ea0189e3f9d7f6ce3102af96d24e0a9a06f89ce42f89346c33e7d48100PF
d2d641c7cc9c03e9ca6482ca35b0c36b1e23ba7b853e1bdc6bec25eb9af46a6ePF
d2d65f2dde15fdba0abf08f0eba0a75c42ca7a41d64da706060132398e03a472
 F
d2db9132b158642ca3acdce95a3018565ff05f4497c6fa76140e7a98a3a959f3q

gg<W+rF
d2e121f5577f678e6c3a8c113a90dec22cf3020128b6c0a00148ff5490889516F
d2ee3c87b0f7cd858c02969d5c617afe7f2d92c540498c4ce94ecaf46e9f8f0dF
d3025de9185bb10743b56de3b1a535e26b438db0b43bb7d1b8859d2681a8a2c4
{E
d309a7bec2af466981338b2729711aca0aac30101fc7b53822baf4eca6bf3bf3lF
d30f35b56aec811e1b348312a8f58d2e793a4c89f8e25ac9155a5e74a0d04b90&F
d315bb2c28ee908b28dcdf583c02c6e2135a1e2a504eab6b1b0b1ea2366cd38cF
d31bb4f7fa204fe5abb6eb2d32b3dbf61485358f507f608be3bec49ef46e3e5e
zF
d31ed1bf33208a48c1659c4aa33c952c4a88624e0ef52fdda4e5cb196354ac40E
d3229cfb18563fc8a24139a13a8b266e417258f43d36a4a4ac3b372af35d59f8F
d351a336b4df1a8014e1c30b9d39d008bb492694a7dd3a345cdad5b169a37692F
d357914edfc5e38eb99a385b00d0fb43d1c581d9af1d12406c5dbae63542e08e*F
d358a86339e24e16bfcc77c61f6f12dea5c1485847a4bd5eee6a6e06c3634ff2F
d382251ecdf030132bcf5b89fcc80c1ec3dfeb1e41cca0d840d735c44e371ed4

ee:V+rF
d38b342552cd6a20a2dfc066035f36eb0359a01a38100cddf5da31c8b7880c92F
d39bb4b8585a8c347658eb0e4b8c573ecb73f3bbb4c1b07af1b30a7d8cacce0c
F
d39ddef78717bb9c60b1a73d0b5bd7070471daf3610288379a07921135392492lF
d39fb02417c772d1ee5c9eb6d9a3981e59719475b6865e25c7e431882fec497b
F
d3aeeaf9aaede46280cce061abf9bec44b4dbe1a3fa01fd5d3ec75cf1be3ff14IF
d3b825ecf0857cf7486c9085c1579cac88394eb38dbc27d654ff8a989aa9f4f2F
d3c2e1e27a400829f10a9833f70edf0886d63ded954c2aca900c1d63fd6cb984@F
d3f83e6ec632331c1a4225feeaaf7c261512e7eb7a079d16b971c7c027fa3c0b
F
d40393b60950d71a26774d9b1e266fd5bb089196ab92a7c1d63bc4e09f86640cF
d407c748075b7355c9958eda5ff21771b816ee274b0d13adadeb34a3d3cb72ed	oF
d413e9756d3b6aece12ea946151d51900d80c7fc73dbaac617ca6d4212d49e38MF
d41b5d8b6192712bf36a8ca2a106db94ce0b4451ac3b212fd91ab7cb0ed75e82	F
d41ecaf1cea900f2c9354fc197197c80a88316766208fa264735e4153be0668e

ff;V+rF
d4212ad62f054bb8defbdd91f8b8be6d7cd36ab2c646d79f0ec7c7e36b8a2409F
d424fac47526dc6b037adfd66b2ff2ba1e1395086399d34a1b862222e961c079F
d434ab93e69642120974f37b28bf06b2fc55a8b51e2bb5b62b339413bcc1b605,F
d43f51759f659c79abdf2a56831458fa8cf1af488cfda2fae914b1dd04bbaba0$F
d4448c84868ba851628434b5cedc79248ebbc6aeda79ecb6339065c844d6d809E
d45776ea070dd01bfa5681b3d5be4cd2fdb7fe2baac5c1720ab216221ef7ddf8XF
d4718c0bcf9365bfcd07e9c307952a12ae32802cbc6bde5707222c30c90cbb85F
d47daec1adb6903ec50993bb856136c6ca6c1d28610a211a0082c8b683162941ZF
d48a4b2fd37317e4545a3515a2c3d39cc3c64505924570c14b14d2c06007e7a6F
d4c752f14b919fcec87f8f21c7401dc7c9b2ceb39af9d43b03be700c06316653MF
d4c9bba0cf86d681a086b4238c954468eb5e278505324118d68938f5918c7a89F
d4ce276deccf36c3cdff38a52ff6f73bd2c271d8df45463c61cc66cdd8dd7e18
tF
d4d33673f61182e94386c936d90db76b50dd75d08ee12591565c25dfe73cc1f7

ee:V+rF
d4f08989f469c8c654a2986c6fe6f0f1f7bb38bec3e1445f93c1df505f92d04a.F
d4f34dceeada317c1daa9f144ef934ddb2e8268f3b1e5ea56ff174ca96919479
[F
d4fd0adcfbd04fb5365175b9d356f5d3f697870607c655b2853cc010c8514ce7EF
d512375bde1aef7ba436074db5e9c21e9baa01feef514ddc544ada6efd20aa7eYF
d512882b1e6a2e0854dd99d20a3bdcbbfa71dd8002a9647e11460a803a49a486F
d51829dbdacb88845a2597570d1a7102fbf961cce1be232b53e652c9e0877c17F
d55b375f8c5f1486c544d95e93bbe9054f39c43705b029fc26b80f33c96e703bF
d561b43042ddb9d02a31ae81d1c4935a05988542719e259b277dfcc2995339cf
F
d5660d632b89221fe127f4475df5c34071486cde5540e458836be4a6b5ab6bcdF
d56ae1d4e0d4b0be63156bddcdb2f72700d55124efafecb654bbb436fd36eca5F
d56af4f540372397f7f6ab93063de3ab226d756872e62f763f65d636a00b901cF
d56f208cb0a3f9404c7aa65a34d04ff637f76d4517d2f68c4c63ec940a0806a5+F
d5777f8c7d443792e6a87299514e3e7da9cb0ffc7ebac5512e40867a84aa7427
1N1|]>jNF
d5b31f13f3b46bf5b0b92ae49a2422fef7d5c0ecefccc27c7b96a0aae7f7ce31NF
d63186e6cef38839b7dec9223b2e71fce4525a6125dbb201cab77ddcd29b6eb3NF
d6af98392b986204b8b504202adcf13ec1eca355c819f9d4a1ee4d8448a14c55NF
d761e44c332a8ff96d411a4c5c1f89e8dd4f879fdc8fcc876f24cd2683aea6aeoNF
d7d58e3708a957c3e2d7c60c347de4ffa8baf7169446426889d9fd0618af02c9NF
d84e36f29bdfc3258ea945056512bc5478db08e97bee521c8debc13bb0e514b1.NF
d8dd9b50628f10da8aacac180c1d67e558c1ea21f01087d813dcd0249e74edbd)NF
d95478aaa9369b4b49b219aa8aa09278b47ea7f04a2b46280915968e638d861bNF
d9df089dfd6da09a0d335f5f7217eb49fb786af4bc6bdc86f8f5780e9588cb54mNF
da3a8c2abd8f7012e5d4bebd1103714f6d567dbd1f5281431b01ffd6d61025fbNF
dac3bbae30e7a82b68413ff66cde2cd6f8ebd5f1c4af294556c60e63c0e4246e%NF
db87f894acc24775904c7b50e997fa12818c4c6368e17139307fd37433372e1e8NF
dc05a54d0cc4b8594a65cf6d4163952f2a15da4e0eb7775e31af36653653ed82

ee:V+rF
d5b8118e51ac12c714bac62344ad5e2f4caebfee78da0c525e284f1a1334bd7d5F
d5ca3273956d3492b8666156d82f9217e75f2dc732b30d638dfba9f17f7cebd1F
d5d036f0277fc2ae76a968b607924ea30394398f7a0e5d8a355d14f7c35960f50F
d5da28b2cc382844aa578c0eb19c23535d011518b699a177d00f377554f5c80aF
d5efe4a3fd7895b05dc1b8b045dc980999601e654844bd49e0d6400295ab6e81F
d5f36384f01382169e35a68adc8feedd5a3f1bb1e38a45244efcf65320e8c633F
d5fa6533d980b7889d1404f6dda42ce2de80411d4079bd78b7ce3257cb36e5desF
d6029c8033366f8fa025ecb16d28c0d7ebe9ff2aa2c4b0f27fd5af20a22fc2d0F
d6069d49f727f500878d2326ae170486edd57be2ead8d6aa3454e528b9d0cad7F
d60af5df8c01a193097c36e1ec5c7d66f470b5c9f4400ee4e1e714397de12e81F
d60ccb9327412f5e9b92a65ce3c4d3ec7c9cef9e0d21433888157b9758c62587F
d60d364eab2fcbe5b73378922674c904aa0843d27145c8b5ab2bc29462a3ddc0YF
d62663db9bfe5188b678168ce54fbc9a25029291dad7f25e911dca2b4745ad8fn

ee:V+rF
d63cfee88470e6abc2c1c016bfb5ec0aa462545cf7fb74bd3fb6432fde840057)F
d64ab36b01ec9723eaab8170d2287e1ce9a08cb7098b0c0912d596f03dfbcbbdF
d64ee0696017c879c9cac304b66dad0523eafec9464a87a647d5b5c2a19e24669F
d6562a8f4c336171a1c63516de07f7e1ff14168c67b6aa0b7065c624836896f7F
d65c68263d6673f69842bd0f97718ea1b27b0cfdef0dd093bccb847c4a9bdc14F
d65cdceba1822f154d19bc4845ed70da24d2b51bcaadb12af03fe2668101a3eaF
d666c7aa2c9af7b68e1d9bb3646d95b078ea804f6833a701a44fd99fac4c9ae2'F
d66f8f50f89a80ba6132ad39773812f3a9b5d598db35a63de6e8465c3c7137d8F
d6778189c30093bfbf953888db850ae1d4f311e8b24b88bced9f2ec61bc84479F
d67f0639fb490343c9abcb00e2620e6b3adbccb1d2fe315924eefec088757c1dF
d67f32510e94c118c64283659db64d073108bebd5993b1c728d0d366e4aad1bdF
d684dd221be8f63b6422400e18992182df125fe9108dd93f3afba9a92561c1ec7F
d69a242a1a58b858cffa727cb8193e2ccaf358421e81076cf5c96b4a5082d5f9

ee:V+rF
d6beb9da905c4b24c2f8e52152046e20369cddd4a1f98e7babf6ac1658ced21b	MF
d6c3d91ad22937af9a211a458f12e6b3d4f7bdc4b0d3241d7559e29615a2e379F
d6ea0ca981efba600c4c9a961ef325d51932a90a277b9769a59c3a585824515dF
d7000378e73195f460b1df7dafb97183eefb63440b39636075973f460f0b141dF
d70d1392ce3021f70e51c4dc35c2fa251da70e2e0b7384fc3ca8003c9c2f59bf2F
d71161880783b5c75a2c86c86ecd65a9b1c075f8f6ae57b1c22186db3a0e482b1F
d7327ee1af7919fb77069b475af28300ad4c73d10e840a156a1105e5099f1885yF
d7438560c82cb351cd0c021c2a6a0dc12a8235905b6ad52fac1aa4dfa0cb347fyF
d7480f6ca0e1f89838274cae938826c82a1a691a1f3fa5dc9b3eda6662d64f7bF
d7513536c9026fa249a909d4498e9e94991fd98da6b1a4b02d60b054ce605018F
d755a7a0945f9ae0c99eaa26a96db5d9fcca41d6a1a533a895cad61a85f4e6d6	F
d756103ebb5cdaa112e97017abdb37c31ccacc831f5042c1c0c423e446ab3b8f(F
d75ace9160c666f8c11b19909fd788117c9134c9ec1c12c636f6a45ee642ed18

ff;W+rF
d76bb9d2f1d62a9fed452572a310fc87fca445e6330ebfd58bbedafcd6dc171bHF
d770a9ddaeae868ed4fb99212c73d0d42e4532aa0842040000775c829f11459fF
d7742b51255b8d94dbac98ddda85c44af8fd3e086a9e97e34eaa931c19309558F
d7798262e71fd5dd605dc0caee6bd51e2af8c6e1d8c23080eb215303d42d2c4fF
d787f263d801d560eb3933a597fbdb2f4eb89a55b5cd49730ab0dc795715c028^F
d78b8165e29e10002bc50adceb4a01bd56deec94d12fc30d4f3479c5ece32e38hF
d7991efb2314af20970eb2c8f5ccbf757b66f3b4443f904f07638d6729d87951F
d79bdff199cc5f9127f01f99ca4906b965b3c5fb198906c1ed16e725d5bbe25f
F
d7aa835b93bc87305149d24877aa4eb93af26e9c534bda18564bb0727392139cTE
d7b21ff17ce56f83ff2000fca6f369f4160b7c039d960862da62ff6aab5c8df3tF
d7bfd9d26185d5c9bbb6d7f10f8dfc69f1ef41dccd5f719b912299bbc532252f
/F
d7d05bd3b99401da823317bb7e6c1a90595816c4f9e5eb8c21d12f8f3f5ebf66F
d7d37b96a50496b4afbe1af4b21e18430fd0714fe31b3d770dbee2da882cb98a

ee:V+rF
d7e9e8eaabb6fc8e9c18b08b483a4a81d3edc3a4d0156c915353f0e5778870bcF
d7f65f5f9fa39de94807feafc132da13d35ac5d5d8864bf8bb7af2099bd8163eF
d80f9a89dac504f4ac37f8ea511d7ea892e9a02e191b8bf374506a66f6ff3395RF
d815a590697b3df0167d56b28753612896111d06c6e033a0694f444261d23d09kF
d81b0c0ebf60fb1b4d6ccb36f93b9d93064cf246ecff7f7c16b2ddbb61c57c91@F
d81c62d59566998fb91a334f86a794e936a86dbd458bf3633b8ab3f2d471e581
0F
d81caf81254734559eabc40be6eb6cddaeb393b4e93b64804cb596861d688776F
d81e6ad3a689839ef620ae3e5c932a9d0f5ef9bcd3f88d2e10f029ceb30a4f23F
d81ef905a985548d803b0e6d1f1537c299d7d342e862ba4651ee9ccacb8b23eaSF
d828d76b49cd8eef2060250c9dc6bd5cb60ff05970adf2e0352cdffb341700ebF
d8331a6dfd4b2d434a4ff55b8287d92617ce478e81f9d0efed00c4b7fea39196F
d837edc3c03b3b3e816e3578cfb0fb39a5018c0d8b79486829a91303a31fba95	SF
d83df69f3f8696e0c3baee4eb2d4a692612706bad980d06d71759195aefe28a4


ff;V+rF
d850176c0a4cdf0424b72ae4e068e7464ebcaba44a41850c646e0e7b0e8b2ac7oF
d85313c82ec7673519a211411e459e2105de52fc4111ca7c8f5993153e516415QF
d858f3c88588d0a0006133a7b6f5d5b77ff58e2705465cf0c43a798850d97b18E
d85c7c7044bb25d459d1d3377a16e6bc25cd16ea3a67985795886527085aca81kF
d8752f8190b36bb9dd01e3568f7822c9a11fbce472408c4206c1a371ea109c53|F
d877319028506f8c2fdc203339535f7dc588bc67e02079adf6bb0e73b4690c97WF
d892760dbed5cfbe821c1f743b05a838bb1a8e646c36fc267a6ce003baac6d8bF
d893452495f6ed739d82236d307ce20f1ee7fb06ea522109fca58008ef041452F
d8993e0975c0634b18618194daf0bdb6dc0edc17cb7ba015d6a03e74436a21b9F
d8997cf26edabd8e589ab76bac92e5421bf78eb3fde42b9e071f81183dcc3b2b0F
d8ad0a7ee2c7b587dabb291d73d00b779874822a850485d9db4e31f1e20bc562]F
d8cc4f7ba48ecdc9de7b819650b043bff67e2a0f66f0100cff7b2021dfdb7019F
d8d9646b9eb2ea7556c1afe53b0eacb8fcacd861d66fc82fd1bcecaf2c47e41a

ee:V+rF
d8e476878a37bbc6056f5f2cfa3f1c9b9406ca06fd0c7ba1bb6e17b09a385ae9F
d8e9e473880f01fe4af7cbd16870f030f0c4d3b35cd00bcd3813a8c472c2eea3QF
d8f18b1da519f3d475ad00269e3908ecb8abedc91f0754a3a8a6aa8b624b04ddF
d8f95fca6716286e91c7ab7b9be9bd359800c870cc0bdb90128bf93397e9352dF
d90d150799643440c4a06c356693a216dd240f7c4b21d95255e233cae0b23fe0
F
d91245d56499e00006afb5caef9f595c26917df6d3112f9952a0e2b928994342JF
d91a5237171093f889f2e37c55c5cbf4f02728ff2fb050c08f0547c1c7cf5f63QF
d91d835f435d138d7db35fab1aba38aaba2d467d57ccdc15593e6e37665d9e9d_F
d9305a12e977c57f2881d0d6b5d0a5c612d311bf062b22798ff09ce88469752c
xF
d9319fe4e9861108bb5cec23bad9875cac3e057b9ed2a069db7213681942b7d1F
d93864058f944550d1b6bcace4755bf6917cc80f773596ac1296ac0c13f00336QF
d9429a549658c0c14acf519f07d00e2c522ae9defd82f2d4466baf627173297a
F
d94b31603d9a0603f9b8587d472ecc87593a0be74e3c99c956b06ed7a156102b@

ff;W+rF
d95a1b973a2d9ba1396f6af5f28e140022664ee433c6719ad7033c59b8007afcjF
d965d09a6d6db58488fc06f0a1f491c8769c8295f4e6dfaec5bf9e496cc72deb
F
d96f6359c8daf94bb109d46c6f4da10422a428e3101b641458380f3246030c16F
d977ef2c9e09f15898d44de8446c4e0984f357c637fa6b2194f05cf87e8abc29}F
d97cce4820b6ef5656963548218f0d4ff9ef7c504f16623dd12d6b73c7cf2e2fWF
d97cd106cf9572dc73237ecabf174c9e7fd63f1831ecd180582edfe2ee993409F
d9821c48f2918944061117f3ab8c87a78a29d2649124aeb7f47f886ec7903dd6E
d98a7567aa18df65a4b612f107387d6f50362fcef232a4c1fe5a246e2d477764>F
d9a010b778f886239f2f727be22f6e054b2c499ecf8ad2846b7837ce3764547b
-F
d9b6c849e3f7bb3fa602d5b17cbfbda40ae131b42cc00f3c522157a30999d010[F
d9c05b12d02951ae6c67f270d0144e1db212577c99d87cbff4e1fbf63e9576cdF
d9c97d1412cfdb3b24b2aca08bec9bed63be4db9461f19ba0eef840ad48dc19eF
d9de662df6b2d06baba19d02a89453bc264c7daa9c6fefb8214e3a084eca6e1b:

ee:V+rF
d9ee541fc64d9aeaa99ba6171d9a8585ba8c37d8e288b3c6b029f4a1aa292beeF
da01a171c185a98e0fc00bd31c919dcde123a4f0d7b42379acae4b7bd481a35aF
da05a8dcff76310419bb1fc12a7598dd9d24206d8f1a6db041a8900ce84de810F
da05fbb9b8450a92e98610e675aa2f6b8d363493edbf91cc645a281adce116ffIF
da0ee7d0ba196b9b234e978896c8b7430980fc8e6df7cab9fabd870d89ab5bf0F
da13c76a95a624d2a68550bf3fcf6a40650e79fef0cb040d51e46aa293093fb8F
da160f160c233fe77d6e2113aad1a189ed766c41fc8254b49f764306d9538dc9F
da19c51c2a6a05fd9cbc856b73aab1fda9c5974c9fd026652be8e555e60410ceF
da19e809bc2749d2727d0bb85172cda681f9f2751137a52646ab7ebe32ebdf66F
da1dc98d83517de259389f28cb15535a0c5b895342f95881d9cdb88529401e7a}F
da23c291f94eaf3fa1751e0812449824e582ca5853fa7e71e730f6f1fb2e0327
bF
da2b0ffc968803d239f38444842e6792e85494901ff8d0075652f6c2d7aa1800F
da38341360f5d41b718df71ed8a4ab57fe1fb09ba331c4f1da5fd6729ab4d567%

ff;V+rF
da4cd5b16857b9f434f773471d103d61dba9fbe99a3264cfce051444c342cf1bpF
da5e7ca2931d95eff55acb5a19e8a5281ca44689ee64bfee2a30b12163c91f83F
da6113b8e3f60613882eeec8c8497c068bd46559042351e5cf030ec9ad382d41	NE
da671c2234ad85d7898dc39cf7cbbe3f81c92f9de8153ed656a948fe022cc14bjF
da833fcbf72323a7a85e0da6ba8c9336419447f7d6dab0d5107ab974425ae951eF
da8588048a3618261c5ce040bd0a4053c3a59f68de23dae234a757305ef02c43	yF
da8db8418933d315b0ed79893d80242ae95d51f00cabe099162d09d07124d15bqF
daad2593294d57ecd2ba590f2b8292ca6c1a15ac312f2ce7da8dbb7128a21db5F
daae913efb6e4874bfa75dfcd0e5d7e7a5608566622349ab0a84cb1fb2583e70GF
dab287aa189bc4e289c79998917467ba4a97037e00fe28be6d93e2537aed7bb7F
dab70d9c3e9d60e9a4331d2ccb0d2d3dacfe1d41e355572961045f2ce2c22a34	F
dab8429bc58eb477c02d8eddb235455fe3be912176fb73b641187fb0ae7dfceeF
dabd6fc3fcccc9d794b28168afdd8fb94f2d78fda10a5751459cee469f8412d4

ff;V+rF
dacb7b788cec2e57fc23d0ff804942ec81a7a415eee8eca5a9a61540c86d896aF
daff96fd89f92832ea99fda83cf1b76e717202ee8aa4dbe27e75350ce028065fF
db00d954c05dbf5ebc5e47f7671980d64911b459229bc83c8dcd6c60c4ce0b90F
db07f94b0ea8f757e8c7e4e9ab64552d472d4baf724499628c1d7447b4ce574bF
db0b608c42aca3d5a6652b87d0c3bce10a8ae188cd758704c3f1f4b70ea42cbdF
db24348500eb9dbf5298596dfe2e37ca3bc54a7bacc1db758d4a433d37f486a4gE
db29a04632a66bb63dd0b015dea1aadce0cd2e22371225ebfeec0ec5dec16c02F
db3908bf5643d267bcfaa924ae478da8414a6179e1b83c3700e7f99f75d8164aF
db4dac1347f0a7c37ce54b990ae4be455c6c016e54d0a315f1e2cbefcefd3073F
db4ef1e0a6b2f44fef3fdb8ad686016dcfa25ae6374a3646a9c898f01668d499F
db61bcfb079f0f252d5ffb4b3f3f8e5ecb7d0963e782c43dc2c33b98250903afF
db707f9fd1fe35154ab4047938dc0ffe4a07327789e176680886a697d796b61eF
db7d1e186c2ae291d66b611f4323aa29b919d87a3e6ea1478b9cb9b642e60f17

ee:V+rF
db914ded5eb6eb9d8b435563ac6f54fc75c81cd4118ec39a25d1562f420c41f8F
db91ac87e5096fe4cf5cd292f4692633d26bdafb9ceefc8288141677f62626caF
dba6657dac2be85cbc8f4e111f952c8a9b31b95116671a599320b57503781a49
F
dba6df762c2a7b4df2011636555ed8910dd7c702ac1a8c2233d5bdc1752907ddF
dbab6f5f1c1f7222d48fde249b8f8b6ab3e0899028dd22c3a51b9c38eea6a20aF
dbbb88d9eb3b101dd3369a46793946b7cefc449cb1c00dab5affc0a3c6adfad7	F
dbbd36394253b7a5eeea86bfcbbe4f0ab7aa133c3e762b34f7a4b0e3d3b138f4~F
dbc118d3ccfcbb7b3059ad8a684e25485e0745d8f682f5b8e2a16c1ab4a3100bF
dbc4de07d0e60afa27428cc96344b4424c8cf8209e8961f014f4989de0ede96dF
dbd4fcb28f8cbfd9fb540e8d37c4b83f661fd5b856fa728606339a61f95f4513VF
dbdc73fdef9098f3a36034a34baac0fea56523a9d5f32161ee961570387e2ab1
qF
dbf4ca6d02e1dc4d99cd9b7dd3a4c943d4209115d0f33ec526d0e4338623bfe3?F
dbfc7031b1cd09899c676d6ca513c824c52747913d402f85f2e22b0b8baac066+

ee:V+rF
dc1039bae026e06f606e2a26e159743f3cf3ed19a75609cb5664372c17b4d90cF
dc1bf06608a791a1bc05682c7a5dd37ff4776553816b5359923260fb02f0c9e22F
dc1cfb04b799c30dca02faae2f75f5cc94d83b63b11cf8e7acb33ed1b252117ffF
dc1ec1c4e74af368428ce982615f87d7121b8baea33bec02313d1f3b501a036eF
dc3a05b48786ae7763cd0966fcd06703e3d056abc82ba14fd98bdd54152fb214F
dc47fdc3f4078f0e108d5906bf66ded4e5642cacf6309ac532e5e06c533878ba|F
dc486f913960456b5d2e5d97371e0ea044e845fd7daad4a9405caee17252a41aF
dc4b5c4bfb6d4b6fd4006830469bd40d093d6938603f2fc413c3ff2d54ceaaacF
dc5b0b3c78dcae2b3bf5f5c9dcbcf24534372b9e13c9464c300a0017948eaf99\F
dc69ec026bc1c217d4ab702f2ab40cc5fe01355f2ba29351877fb7a58751e541'F
dc71096c57fc06718137b2f317d123ac81f3c58557e1d9e42b1d0cceaeb95d38F
dc73b498dea020241c15f040008e6f96731b9a67cfa83b452c60a9d4510edd41F
dc77ee42e3378dfc1bde015704e9af335bd8e6829d547325da2fc62adc0db229


ee:V+rF
dc829add4d45f5884e77bcd5570fa643f0a482815fe304ac97cf74eae7bf891dqF
dc83e35a513a39a6511e6815dff7c318849b1e9ec3399ac8de14115dd8663f84
F
dc90a5cca940b1f478ed520e28cd82492738bbb49889b2cd96a4cff2fbc503bc	F
dc916d8fb8fa71e2b3598fd5f5d1544cc54745b116f27a7ab2ecadf3df918a7f&F
dc97c23964c8ec5ec9543fb0bb7c476a1deca4202929a65f43265b1ae8ccf0ad(F
dca184c57d0913cdde1f9f39c446f2cad1f8daa197d290e0f0ee296dc3b345daNF
dcac6f9cfc56c02c04c7a838dc97614858baaa53286986731947f8d1e57c98ac
9F
dcccb19275e44c98b220ff45b313949c6d1e421f5326c9e3d8f568c1ae986c15@F
dcd5ebbf96fa4b554ad2a5520ab76814b9eae044e649c9408139b2b07795d5f4	AF
dd05b77f960a6b0aed0f034b93449043a31100aec1f59ed4819b5d1ad663b83dF
dd0e9de5630bcc248395482170c7a3b3d61876f1b93a950464ca6a1125b6dd53F
dd1acce44324d0f78c3fefe9d62e4f6b967b6a1f192ce18c8c0336a4c8adabd0	TF
dd26f40a18d45abe032d5e12209ca47ece3291fb0c9b2777688d685549c62407
n
1N1|]>jNF
dd33037be3199f5576c54b56155a6558f0ffc24162964a2a3f1e2dd0be0681c8NF
ddbc53b44a7ec6dd175840df4ba96e8440a167aca06195e38f9ce8e768f82f30NF
de133553b72273258b6a99609593572620371fffa43173a2338c8558bfa99e7eNF
de8317deebc44e01bffee751beab8a8a0e35efa4cccd2d3dd442f02026778754NF
df3f0112c83d6ec1425240197c85476b62397067d6ac0c7e5040adae2a01ff93NF
dfe0da66e34f229040771968adc12e53f3ef8575433da409ecd46a284495677eNF
e04dc4c0f21261a4b8f79045ccd056e8127d18e5487b1cb244df94daebd947ef^NF
e0d5c3c3503d52c16cbaa1ee54130af69d4b939561a49a2a1591e2049fd69279	0NF
e161fe668a338dbcc5fd4207138cf06b234756554c7b000fd5627366c98b5f3a
NF
e1e1b8adc5317dafcd61f9374708c3ef7388ecd2591a47bb2dfdedc0eee9d389|NF
e2a10703222e1811d5a65784d7297dc8909810f2a89b78d6c78a402ba28e7a22uNF
e31ccbd3696503d01bf17eb08d66c852a75d233ea3040b15ee14477f72f2013d%NF
e3d2e4fe4672614c07f199cf8ea78ca12ec2e4c5bfee735cbffb6dca84ba91cd	

ee:V+rF
dd3bfb74354db34116d2bb2b298b233f3d005acdb7709c1ea17dd9dede2e0566F
dd427ef9920f27966d5b507f154c88d80a03bc944b494a89f98eae387f25e950F
dd5402f5bb60ada1db63c1305e3650e8804adcacfb1557affb8623621fd83155F
dd6a74f8a692f2fe556164b50fc2c03bcb46f1e09f4aa5d99bc036cfaf80970fF
dd6b1ad5b433b7d1f74b7dd91b9b5cb0f241de67b3ac6e130a4577c5fcbfb7dbF
dd83fab8ff66edc9c2eb4cce6304324d64c9a9f43b6f394c7886c2bbb9f6c689jF
dd8b1af64f49b071bf8395d452ac0dd4a5272f3de913475a6e1158eba0bcf9a0	{F
dd909825185de2980f63f3adca1ec98161c8737e440d1fdcae489d50885111a0F
dd911d44d893c09a124700634046d5e3c9936eb30f6d85537e2f2aca791b4349/F
dd928d632917d65ac27ed05d45f342a550ac01430159ae99363d9a406701fe04F
dd98390ecb2875b55a18bb8ce2f4fe960e7d8f308cf206decddcbcf25c6638c0F
dda309e14f66aa1f8ced19d835b7e6ff04827b05e42baed38cfbde2ea01b3351F
ddafb1e92f08f922d622d8426b42ea6cd1ddf7090da44abf0678b4cfd67cd2d3&

ee:V+rF
ddc9339c832234c2d2d9c946d96c23c6d1fe5ea3a34710694d2a8bd819d4b8f3)F
ddcaa350e33d1c8dbffab5d04b8b98a223178542f0bbbc0bffdae33e41b18241
F
ddcdf775af5a3b6b701817a264a8052171cb2eeb71ee4ee1901bffcb91e5d74b>F
ddd375eab5397ba731106d9d1a805e9a2c6aa4e504e7487eea4ff54190770885fF
ddd64d000d677447dbb3a66637d5f9d9064439fbdd584fdad1f5aea0b47ef550PF
ddd921add46e38c9947a1be713846fcb866f41a25bf6671f3a81e65cc5ae6906F
dddabe759540f01cb15424d35255ccfac26564331254e9757e3ad94869e2cf05lF
ddf36ad1ce4578114e5a65661c1a8de7696ede0b51d5d3a2d8ac551164a4d7cc9F
ddf90c0ec436cf18228ba0646f73776e9a121426e0c05038fb1f4378646ff646F
ddfdb301a369e390465e7fed07a523d49328f34568875ece4041374ce5341b09F
de01b8c6bef6e8935094026fbbfa516daaf970a7e92df84e3705c559853ece19wF
de0f021707bee4c5aaee236900b154d83bb1e1fb6cf13faf8ff2b8f68fd04dcbF
de11efb648c50dca4022b29c14b4bc06fdcb8f36be5009d20018c917583af9bc6

ee:V+rF
de13d1a20b6a077c828b91d64b7be5abb1b5809f45b27d389afd2811ffa6f9c1}F
de277490ec2359c7396f0b7c4d39dfa4426e563ea8cc9defdaad322dd0c42a48F
de291c1622d5eebba6a97c0060a631087ecd9651815e7294c243b6f31e580508F
de3aeef4443f60aa6795ee64bd6c2d7bf33a2b82ff3b9119c255830faa49f4c4F
de3b8490416a13143355e8684c271fdc9f605d2dbf6ff8553f500f049a96f027=F
de55e1ddb71f75f5b701d57786cf4b70fee1d92f72205d32c353fe0e17602361F
de56cf10dbbabd9a55f388bacf02eb1f5bb04b430bbad9a217d6dc57141aaeb5F
de58dba9cc8af79c110d13626931309529fa1a8782a121fbfc29dd03e58e58b6	F
de628f3727cacb859cd8375cb35493f4ee9c74aeb3751c1ba0c049341d84eb2eF
de6d7edb575cf2c912b54349020bb0c64b19b18869c865f5da30ef088e3cad85F
de7c7cd5bd6465116843083e7515695b436a00a145d6c705355b3e74a55e2b6bF
de7cfbe962bd72bff05eb5b687355c2d1b4e53a0affdf86ce99149c64c2d5d6bF
de7f44e2c7986c23e352486d2894499d26f632330a153b346ea4363cdf0397cb	

ee:V+rF
de913afce451c42b905510d6c1260b853922e572f20edefc2488719a3c92770aF
de9c5a6a93ac35ebe471dd45b8186ff0a1ee0c2c80c9e122c072728aa4e603a7F
de9e4e230ed945c27a0bd1d2400e9562d9cfd0a8d54ca6d1bc09dda52211b3f1F
dea5908065b3f9a0fbb1fdc5cae84e7dd1e61e274eb25e8a1c1bf2881f5cecf1F
deca008ed0c50034daab0bb70b65cd418b3ae2a3bb46f2fb5b5d2c80f9cbe0e5F
decf2a313c4d562a043eed4b9202d10b5c58750490b4d6db6e70c5a2bf2fe794F
dee28e194d7127f17697a1e4475e1ffb525b9887c34d90564152f147605360acF
deefbf7dc62157f10bf35bfcceae5fb497403a6fbf86fef1e8cfd5636f7bad10F
defc20ca4fb42304e9222b189cd76864191e45eb95df7eb3cb3ba3efd335419f;F
deff998718fe21f42d80a710db70d787a484e432b9c7bd0e6a27a4751d9bd70bF
df21a3fb768e603f322d9c16831a48f1a953dcc954f4b9b79e30a3e77107cd77F
df2ac268f02376356b5c4723b8c369c8593c63db05b25c52b9d0d0cfa7b0299bF
df2c03d36edd3da46dc78887ba0c21af48565b9a39893e1157cf83913aa1b361

ee:V+rF
df3f90935ef976e235c93ee9f86af7d2ce39b33df6bbfbd00b0187a2a6055b4fF
df41fca55a3d1bff5343ac8fd47f2dabaf9e5da86bb0851f46af715e74c7cd59F
df51484667e5b744416e438fadb87d6b7f90ebd7deb4e6682c6fb5544b4824d9
F
df6e614866add11969ca0b65851bfa71c6bc9f4844246ad53138cc6918480108XF
df76a933cd54ed2e60e4eacb34639d343d8e273926033d63c3e9f0090215673eEF
df7a357bd7450087019d5bb9f1bb2a2fb80ae9a9ee7a1a2a6117f7d9bbf995e77F
df82dbee56b4fa877e8f7aef9b9d8dbc81c598816135c2ccea24f43af66790f7F
df8d2506c03d24e1a590d6879a32d25fc08c64674c5b3363908407344377e1ddBF
dfa0087b709a643d5c0cd08f474c7f4e2246be49e0ed748ef007f5903a31b544F
dfa6a2ee9076eba358c12de54d5d936a15a282109538f6772bdb75582afd0584F
dfbc0cbaf5fb588c23fcfdacafa9024ed6efd13bfbb1cf69316269cbaee79463F
dfc95bdd8057839d4b45153318acb4e09f4da257afee1c57c07781870a68ecef{F
dfcf30fce1599be0699955042c34db80273d1dc14cc38af5a8f91b02ab70060b

ee:V+rF
dfe2f972771603f046f22e69e38741bf6dc94baeaec867665169bb3e9b9b8eacF
dfe4993ac8d4d097c4e5e97fc006d27039a6a3d4cc79f87f4d56c9e79afd3a86F
dfe598bbcefc64fd6bb542cf6d1966fef6a3995e68fa2b6cc2ed34220ca65ee8F
dfee136c3e1717a2003cc2ab23a101250a304de173d85ce35e611d5481bc08efF
dff37a0add22b38eab5365de428508592ec00dc762e1cb45853495efb7c80c04F
e0016f8f138d66a274153a7698e46c96dcb464b183d398ffed1911d528dbf7bdIF
e00e4e27e76a7ce874a947e6df6282be03c80787552e9101d00197dc467c0182F
e024eb4fe098b64e9e4de794efbaffc32240faa47afbd2335907c1f6f78cb52bF
e027d56a8d05e8044b59f1f1d0ff564fabaec69db38c5a78c6eedad992bd0ca0F
e02972fac05c3f064d850d48bd37730bdc682a15ee48e9df9f51ad3d023e5115F
e033e09baf35ab533a503e8e87c8e01aae28de712da982f5371673bf0567fa4aF
e0386a64a095ddfdf29e498080b5d77f7bb681d49c55cf461188e3263c1ab429F
e03fb473c4111b34ab231b026b46e185aba267a54abad312d1fc4be2fe1a79ba:

ee:V+rF
e063c651b9c19f3ff44c19dafd53594a57c6c58f609c5e0e419a4b724c4b5f87%F
e07580dc20cee29ddae2c26b7d4782a6e7671477d7f4ae210d2cef6cc71555cbF
e07e25a4f64939f2fc2c8dfbcd0358561025cfc19d01318d054b161d02e76a80F
e08149c8f4894437d1cb9d2b60f6771c7922cc3b83c5f92705e75f509b0481154F
e083624285f3f8668aeebe5e4297e96c9e4ea9ed3cece7a3318166272f0fe11aF
e085961e3f16d1265f8327c5a41bf5ca2eea0419c2b09b20092466009a492983lF
e08f5391f6f27a9c77207532b12000e6771dbbab3411de893ea6640343d7c557
F
e0907ae58b30e07ab32bd9786cb264f46806e15e1e41ca13375f1a8601a9e2833F
e09b5f3555e23622b184571a63391c9f149a33111cf6ec9a07616cecca01c1c3F
e0a4a368252a2466ddc2b35c58646282829e8b14ff12d3237645aab8609ca5c2*F
e0a695f230a608e0bfdeba85a6146080546349b0d23836b272a5c44012b9fa09
F
e0a86a5b4129921e13dc76157dee997faa829d4d9a825ace7a0a53f87b4846d9-F
e0b87fa8a61f451d3299d6569707241d3342eab4af1de892fd6bf8e03d5551d8

ee:V+rF
e0d62271ecc1d123dd2dfe6e63131923215ed05f9f87bb42cbe1c713b4cfec5dF
e0e135c635d6d7b7cc130fbb412e09c42992d3447f2a5ee0356a07ef5d6489a9F
e0fb73f01affcb06ca29acf2c378ce6d3035f42a90552ed157bd34ccf137226fF
e107c061dd44f2966524c0a39c675a112e3f712a7f1b891c19bc27ddadc6d91b
`F
e10f54c5d580e560b5d4611357d17fabf744c685d0597c57f65096c26149632cF
e1163c5b5240558b24ddea7085492d62d63dd722ce6b4775724583c2ebcffdf2F
e1197686e2dde2402bf2c97fffaafc2a53e90a49b640a6fa6272c09b15d1bcb7F
e12fcfca359b3c38140cf59ead8a267ef1c024a4ed16d4250b7d14c94300a665F
e14abc4dfd161e931b9099dce439db26a29175c166b124a14167a664a0d5a600F
e14e58cd6c0a61d873c99c10de7e5a36ec844b84147e4656a784e33c1b0715b4F
e1558062e338ec19488115a645f60559e370f1ddbf06a4b6e522b9803ac21304 F
e1558a4ef78a248b5c220ba56ed44d6ebb4fc90cf62cd3efcf72e602bc088eb0	F
e15ae7c19afb196a228163866e632f1a6dcc877a8490009959707d354bf833c5

ee:V+rF
e17a8027f3820da82d6b20358ef0d2e8fb3c334ec7632d5262a93004b4cf2fbf-F
e185e29258de4ab6f27caaedc2002626f5e10ca9ec0c4c0d9b98007fb617fa6fF
e18ea59775bba4c1bd311fdb9225cf287d5862c29e8b3199c4ad3bf57a00b83ekF
e19244daf20ce87cf283cadda5ea9d45bb6c17bfdb674dfeef35d29825c62af2F
e1931c2c08f74962ec1d742c785c518f1942b86d552b9e27d9cb776d4c555f8aYF
e19a3d190b4be2dfd6bf0e58eb5017d6235b6dc0bc5b12d4b5d07c5dfdf34eecF
e1b83152038966e7b6a720ab0871b052fb0dc4df9c843243ac9f34f68ff8a58fF
e1c638e35cb4c885aeeee8317465b9424dc26e85b3d95b1a84601727366a7bafF
e1d065bfaef705d407c6134352d1afc64ecf26a5970a0e5282f6dda745483db8F
e1d60b061557e368c20da15e4517376a49df65648636bd09fa3baa81f162391d	F
e1da241785b81fa88a78902772f84fe8352a55fdf1c3e24e75f1489f0ed6c85eEF
e1db7a00d2204d116b7e75f87e236094c6578a2ebf4a48a7af11edd3618ebce3F
e1dd38dc66a44126b420260a1c8cbd7fc5a5e66fca9097fbacb6645b53215ec9M

ee:V+rF
e1e650013a118dcd257d99f632eaaa7d97ca8ff95832c08b76f5f19daaa2c8300F
e1f96091d25298a2ba6942bf99057752361acd85a35af09192241146d47a7a08	:F
e204c387125736b5126202b4d99222db286a7d676c022fc50ccfe99a1a8ed302F
e2176587ba77f1d2a38ee9ec89781028cc33042f069dc103523ebee850d6b68fF
e23ad6387e0d97dd5a8214f1c20a8112b68c12124bedabc0dd60ef5e8397681aF
e248caabcf1382b1871901dc2504fe1b16e85e748d76553c646487a5ac907f1fF
e251fe0d7ffbb8b51c6644310756c5ea0a0ea8d5282cb0ecda819c8ff161dfecOF
e256274cc5f1a6f7f97af45288258ffc553c2f425401d35928622845d32c4465F
e26a698ca51f4049464d83df1c17062a826cf136c188c2d3994ed01f90974ab6F
e27571469712e3c2e9c26aebde7261eee92c600cc19e6d3f6b1bc172f0234ab4F
e28f306d4893ec7a68589345b053be93e9d807543f263f0bbfd81eacefbc4c10F
e291f44f4466940d2b21380d3d68e50016685dad9868bd9563a304233da7eca0F
e29dd1c6d36379f2cd4d51b34af58306f6334f7eef664b48361f0e5833bb90a7

ee:V+rF
e2a3860deceb4f2f2ddc8390def1eb021196fee5ef075702ec1588374818efa60F
e2b80fc90e80e10166a785ab1c718ed12380055d955ab295c5363ad6405fe815	F
e2c51db626a29271a596a4998c57628cb1a37278b0c06566729c4f36ebe12ebfF
e2c654e3afba7eae27baf8ba94d32ce0d7b64ee9e4d712f07c55fe5511ac0e78F
e2d9e1fc46982332f4c50e35b6e51f62edc6bd78156642b63e2553d404909efa	
F
e2dd0c67f3d88a9506f72fcc21ec0af786a377befabac8e1670d3e012d844b06F
e2dd1e90386216ad54e0f6e9509f96a4314819f96abc9b8ea88ffbb03f05dd03F
e2e263c938ce2c5090d810688c04ec6cd001741c076f39d1466a32d13305f123vF
e2f69cb9ce06dc6e440ee55d4de796bbf6daa032c04f11a93e33ceae0d79eb9cF
e2febf7854a5223cbd8ac5101e3cb5cc8a2a9ac22a6ed7712ad25b139199fee2<F
e3048df9af89b5496455f0ad788ff0b492712c8c06683cf6f908894638139c9fF
e311decc49b7ee2360283ef4b0704bc4c8dc2c2628d70e47cfff25b1e8583f72/F
e319773b66bb4f0227b1608807845710d392639797e4f0e6714024b71cb7b1f7

ee:V+rF
e329f4af5a2d9e0b4ba62a957f0696c7fa7fd5a4fb911f99a4f9f7fc965b46b8F
e32d8d85dca546b68def9a0c2f007a2e17b1c0a6759ec1917fbd3848b1afdaf0F
e33353c1f5c8cd09778ece298733e91964fae61ddc04af20b7b6eec95035236cF
e34c0ad20744217c96add514c92d0cbc2a8b8784c76ab519306475684082bc7bF
e357af06726c5602fad5542ef0502f94391737c732c9fbf6706f80fb6757f197	F
e35ecb4beea182f7288644cabd57114e698301a9bc0577e0b71c41956b316426
F
e36b9d803bc4c2cac122e737759eaaf8944848895c016d80232d05a405a97587LF
e377bae670c12638d474197ef518748c1e088342df7e30d7b48305b688397f86
F
e3787987f77c2d6216bcd7f8b59f521fa32928443f39660b17f98be3f0a684a0[F
e3969bb97655724f00a321057ffa1c3761259a7544eb9024a813c22c09309f89F
e3a12de0d6fa0c1cb65f6e6311428c947041d9751905ca6825693129f0d1e5a5F
e3a24b7d3f533aea4ed0f3d9388b2f7d72febbb435d58e7be4020cdbc47107e6,F
e3c6ac455f3f655e70629ab69610a70ab4f4e55490536ec08dc32ec06031f28b

ff;V+rF
e3d2e5a0802cde0d09552d1bd3102383e1851a9aecf88fd83a5fb81baae6d53c	F
e3d6fe10b5be6ef1037244968642c245659e0a8f0dce997e92167e26158779cfF
e3da9cf446dbbd5a2b65cf4a7f59080bf53067a5b3c1c938582a6c2e7874a819bF
e3e0d812a13816d47ae085d4f88c2d0f4d8affad6568434ab0f720442981017bAE
e3f5a839e2e8acc1d26bf39b94c2d5f01d99b4c9f59926532da730dd0cc33feaF
e3fe1238b3aefa061d1f4c2e420e93639cafe3a21ce171d5f4a80fbe6aa7e5558F
e40e9974b84165100cfd49afdff81253e38049ca2ba3d57dcdf352538fe84014F
e41dee63d125e890be93881d99ae457aaebbcaa795e8a90597fa3babf9dd5a67
F
e43708faf11f54060a6b8d9ee565f6c43fdf9b7c1d5537257443dcfe58320462F
e438b29905ef5550f7c5d07e807e9f7f882272fce7c62fc02d8dd31abdf3e759F
e4434d6372a44237428f390b21eaa263d38ebe585fcde7c9b6d093bd6a53f942F
e446b1822c2b1f232e747d463041aa38f581221d371740705042a6966578d818F
e450e9d5bc1c7f5f5f4f8b5d7ce575e0a5756a4bab5ed98be38ec59c1ffb0276

ee:V+rF
e4950b148639895cb3ed78b8a00c0708abe4685bd380e0003ebeb947ea1edc42F
e4982c6de18a9fd5a9baa26a2ae8d32a5e2474516998095e06a900fc16cecb18F
e49bddae5537553d4d5a78524aa8b60eccbdcb546e79e3e046c946ef9da09ef0F
e4b6df13c59f0686bb12ef575deeaeb4ba581e4d0dd1d2595bf0d7ed9ad2e65f F
e4bb7031f520b296dbe56b80bca148b9f8409329cef2007dd5a06e4548e780d3\F
e4d444d844a4cafb1f7e4fa1a67562e38078b7cbb3816a7216492e9a2d40c822F
e4d4ae004f1e33c3542d967b6301d6307f9a848be51a7008ff5726259a3e5a5dF
e4d97a37a80e7bde04e338c95d54a5872ecd63949d6cf626c567ad3c7a83b5b66F
e4e12b73d5732eaf8ad672f5c847ce8d4099eb0f3f222ea7785a84bbb5c28f75F
e51d2de57b856312d8eb1bbf6ee6b7ac8f910ebf5d7e0b516012d5d9c31c7853F
e528ea9bec7db57fa568791758764da431303a54e6189e0449c7b1f92756f230F
e53316518deaff6343f609e95cac017e8bde5012d97256307e5dfb033e102c0fUF
e55f24cd7b3be8300c44b260f1159a66b99a1775ff2fe6134024d8c234f14559
1N1|]>jNF
e55f9021fa118e217df9db527f05fb35638c68975d0977584ac974b8c6a6bddfNF
e5bed7d18f1cb03d90274c85c7eb780577a158e85aa2ac2af3e174486ae52f9dNF
e638dd51d9159ae8157653edb26aaf106eb560ae53f15fb80efa319e41e729b6NF
e68322c77301aa109da2791f2c544f5933ba77ca4eb36116ea02fcc3d83c6209oNF
e72e7e5054cec7dd0b5f52acc7183ddfcb107875c50ad6ef52f07a3785689966WNF
e7be65394477619c3bc276a472efa4a7f642dce66c5dee203826d0391223391aKNF
e84cbc56cc8d3cad5fbc8fdb06739cfdecf9f15a7df56f7d2af53fbc4308d0c3
NF
e8c8f15154fb4dc69d8a6ed87e54bf5e6b084aa0153827e82cd2471889908402NF
e9972fdb7ca4cc3ff44e4f3ed37bfc724bfa5d7006592b775660808adeaacd37NF
ea4070c75f7c99de5202445cbf44e188a168785685b3ee3a524f47abd2e476b2	uNF
eac7d9685870a65836a4ca60f270d56cb0278fbdcef6be718d7aae558eeab78dNF
eb48815ca014d65a115c0ac9dba6f0c28dc765fbc161fc9ac11d3573786c6b4a'NF
ebd82b5546583e76abeafb233879f04f1488a96c1f1823eac177889b8218328d
OjNF
ec526953368001477a55a50c3cc2a5d51c651ebf782ccc4a61d9c0cd7dd37eda
NF
f4b81bba6d36049eb10ff5bb2d20310de20be1048a6d3e39a65a860939563c6fGNF
fbdd5b5415f56af9b9ab84c65d8ccf11fa14c3f554904f46a117fa7e039d2a92

ff;V+rF
e55fe3806bd7c427b2a99d06f4cd6144b05e9c389c33efc7071369f9a633b952F
e5654c00b989b0595c553eaf073114c219aec1d06fb9571ebdcebbdfef5a90d5JF
e5677937bcb75d7acb7f08f429bf9a0f982b23101f1c089b063117be1a84ccb1F
e568d73cd1ea3df0a67fb17bceeae36b33a91af90d651ab33c4ae492f208ff32E
e56a5b95dac0bbc46dff9f5743926a4f4bf4883bf7b515cdcd6310771c36a4a8ZF
e56d1ffa341be20d595bbecff5b341080ab023c5d8420ce4a03813df47621344F
e58be69903032ce19789e8066ac18b837e6cf4b67db9460c5dbac4897f678352;F
e58d4578833550c574d220588395dd2ff7fdabaa1bd5e48a04c31911a6caca8aF
e59f39966b86233054daea322ee01721e6f8f1148e751fbc8fe36aa7381a0c3aF
e5a0b645a5f31d68cab7845d9767b0fa6efa5b4d5b70698b58c9ce1f62421820,F
e5b4fe58bfeb115113e7edd7fb472941f60801137b90d42e57b06b22865ac47dF
e5b7423528cbf9cc19e9723b53e3944ec1bccf375eed6cd5d975ed01325ecce3F
e5bbff1b2c6d054cc79f530eb0647fb1a04ec02c79c456548c0d9082b4d41037y

gg;W+rF
e5bf29d89efc9dcdf73e8e8b84b8aa41793d043e3bf944a0c3659d666a13bb4b	E
e5c8dac0c01ec10e911180046ed350bf3dafcb9bd06121d746055d20b4d55586F
e5da7feab326c7d54715dd536bcd5dfd2fb186f7fb2c524d033599095a696f93F
e5f363f81639b222cd478b35c882cd06eecb2b8e8876f3e80dd3d85c8a6198a2F
e5f5632841ed822338ddb9d3ea6e1bf7785e6b1ba1d354993db1a5a47209507eF
e5f76a4c5b41b3334ed3da7aa9bf17480ddf89e174661aaa2d61a1fe4efc7ad4
F
e5f77930d5fc1f574da19410b3b247527067731d9fcb73c1449994d5079c56cbUF
e601bbdfd361d5089be7cec55d69d6cc4b85d1c52963c2f8d004de14bd0ccde1	IE
e614cee98b3c2a67c0a489a233ca9a7a574ea6bc8dd166f835f26bca8d3d5f7cTF
e61584e7d9905cb45027e741b94c7b54f6b883091b652d2e13a682d244a0d9c9F
e6273ad14c1f319502c24fe2004a6765421589ad83742d12e87a81b3c84c6d08F
e6275a113df1d4b0f258355e75adebd1cc562e086cb9229721d17bdf2efe7547F
e63709673c8670886d3e9e2205785adba63f0186853bcf74298fcce168c18f0d

ee:V+rF
e648ee67624dc2ef09455b433a6f9e43ed3a673d6a32275422c2cd824c5d2e025F
e649737e5bf6a5d2b0bb6c20cbdfd046ba295e9f79765fec2800f61f3d408ac0F
e651cd64c12f15c06125f138481787d6ec5290b1c58e9c8b7898b52c10c8441aWF
e653897f2dd6f84ab92a95f869a1a8b62ee9ab93e65633bab0f315f3b744c72a:F
e6594c28667d65623967ed4dcb33fb0e473593cd3c65b2b17b0828490986f908	F
e65c76e2da0feca843e2f481d8447767d71a1f723ceeca4f9720896b896a6e7e:F
e65e62f1a74d176259823a76ae7741ded81383eefe67562563e90a903f05c86cIF
e65eedfb0130d1f3e59f5a4547b25b0e1994042c06fb9833816fdb384c062165F
e668a6070cd6a22b4de750baa84e146e8e064e1a05849a958600f9b2d6b51c0d
F
e6771230fa6e197c3187538f6fa13d73b7350fb996824194127c1ad59a8fee30\F
e6780d4f50b1f42151e1c147e42bdba85660cca20eb7f459aa271886818f9058"F
e67c1938cd59583e0619d2d7e8c5830ae4585c3509d473ef7f73fac3a559c82fF
e67d6b84ad7acb2955ee72b7ee68979e8e001bb2a5d5cd54e752f6d78ee327d9

ee:V+rF
e69d6d87e87eca926adc10baf1eeb4125ba0103b79977c638b305b870f7d2110F
e6abdcee27c8de20b83368d087e14b888bef04262eb07ab80e58e528334e1a1cF
e6b35740952d21b92b5fd63b78ed0f5a4649c9aeb22cf9cb5af2d6c5c8a86dc3F
e6b656e21f27f47b357f21b2071ae59b0a85a6c23d1e221ddaa30e32116bf9e2IF
e6bb8a9138e3246eedff3c7522b5bdd6a006e9d47913ff4c10817c6036530510
<F
e6bd9014923fd5db4edcfc633f2800d2d9eda0bd0b416f22bfe615c9c8abf000F
e6d47a4c88646ebb1f6ff54dd92d1dda1c8abb10bc8530e1cfe498c70ff1db87F
e6e6ba69197bfc243b1960a9622d4e657bb927c0f6bd1e8cc8ee4f1cbc2162e3F
e6f4e61f30e26ae0718f9ae0753c408d47f937201175fa1753774f9139b55f1cF
e6ffa74bab49f49dde242d6ce151c85a071ed9f55bbfe61e19f182d53a82496cF
e70fc2d0e61c7e1f8c65da239c406fae5141f1efae29ff4e2ded90e4f2271ac7
F
e71a307c1ef8b62e83a97e331815cedb4e6c75a9c53468d64a42013fc4038c08F
e7250202a7c16893d5954675d11df0fab80808b7c4c5c285328f1c4315027ceem

ee:V+rF
e73e80ff6eb4ad13c6cbb061fbc0b000631cf8e49449db648db76556adee995e
F
e73f1115eaf8a0021df6047f5efc221b536a0cd13fdd292d1f38a1f658589414_F
e73fb6987d2e8000602d878eae68fcb1f8b4dce3a67fe1e988767ef5a8c5677cF
e75e5f7dc4aac557d9b274de60d58b81f3549dd86073ed6505512e434de72884
`F
e769db0a6566751d86087f44601cb2aedbda527c4a514beaa8e8a1f4a9d2d02enF
e76b18f34fbbf2a1e7810ed95efd446420bc4ee561f16434445b97b5a0d466c4	F
e783291d5ab16df4900451958335994c05de05b904aa33cf87682f106e2baf20uF
e786b3b03097afeace07b7db363528e3c435b3fe280d06c8e864a93b15a8448faF
e78824bc6d2ccd3f5942b851ce6c3323367ca0cfa615dc8c95158aee19c123feF
e7909f526d0702267a79ed10cb3c92dbaf4f95ac7cfc1fed8313c4c13a955925F
e79f036d785295613332bcd3cf90576996a5ccf4caf4279ccd2519d51ec04845EF
e7aab445dd74ec3ddd4f7504b5e00f8b2f7024c95448fb6ee6de759e0517cac4F
e7ad03734c0fc0d4d420d177cc82478f12f8c7fcb1b49294d3f686e186915e9bP

ee:V+rF
e7c1b560ac8edc237347234d58d014ac60737500c37066f24b7f254871ccb2cdF
e7dd086b27d2e2fb6eeac4d5032cfb52149916c6c88f31b59a12c5bc48c71672F
e7dfe1246a7bc34d021885e09adac136307a97c7a0acc867665ed6f71b091d48
F
e7e24cc31f3c532de3376ea95f7fa6356ead993a563d11fdc5f66f22f5c565ffGF
e7e90b3e6ae85deb749d4071a5467a5a718a12808213ecd6657a9d70d12129ce	F
e7f2bf03392856717c1588ee1a77010b1537d1a678ed7dd1dad5ad7391cd4147	nF
e813e31fc27015fa715af1d13ab9191ba9af31d93085ac2e76e58359305bc66aF
e818d4e04d72d3014d26343beb92384fad7a4c394dde4f7dc2a541d0416f569fDF
e81e2d49de42c4084b831416da43610e82111f1e2bf57b09c2cfecdedc32e6d9~F
e826d4748706ca4acec7f8adad39873fcd390f7a0086ace767fbf32cfc28d3b0F
e841a2a32725b0c2d0447c0dda8ba50326219acf4722bc6f864e23dd416cd272^F
e8468f3515b06d1ca7bf5b19ef2db35762b8397bb1d841f2a9e8409ad97af8faF
e84733a2c4b6d0f60e70451f27a7c82164f2fa899abad53af1c69553175d5411k

ee:V+rF
e85016af12ca079ec7dcd10cfe41ca3eb0ae74f337e7db981ea8289ce132cc0bF
e855f087b1b23b7efc6503e87350c4cca1ef6881dc97c31f1512bcda747a478b
F
e861c291ad02f4c05f77bcae1e8fdba63ab7eff4dbc48957941c33985baa04e1F
e86b714d0c1f2ae4a38a0244f16cb28ce588dd6802d4a4341ea79e52e3cd5799F
e87677e240924426b72cfef3f1ea5a1e88a7a4f5e9fd2f778a2cc3fa1a10069aF
e87be7552176482fd5e981021e62d2dab6c7950108f44af47af3d68b9fa442a8F
e8843e39d98b4c77a9cab62b23793b825c2c78175ae84da344250acedf05778eF
e888a6e4abc3928d95ec0b18f8a42febb63ba70ba0371c23615b8823209d9317	F
e88c137e89be1334bc4b12c371f5d7a2513ff468e6b5530a069c0f42a2d803eaF
e899e4be36103040ff23d743f3f3ec0eaf8bddfc2604aee19b9ab12e587d87e8,F
e8b67a41970fcee6a5eee5fa362a4648b27e47a04ae221fba0de5f5bc2c64e37F
e8c196f4e751026825afd99f7aaf6ab5d3234a2fba46b51b585338b80c837da0
TF
e8c1f68569cc209cc9fa2df02ad4b7b0845192e6e74e5167c8cf3400acdc4c2b
7

ee:V+rF
e8d290b951820742ddb84f040482ef781da092f44db1523ea7d4b25d3674bd2baF
e8fcf04ec6289d6ed5e26623877c40ac8ff5d22653e6acfb45465877e4ff0dc5F
e9036e2b707bcda2cefdab377479ae65cfc1d4f0da25dc54312d9786b65eb947F
e90d3b7f1beb833473709255affdf6f47d5b2f24def150c5ba2db2d65edf7dae(F
e912503786155640b2280491e5de73ce270fcfcaf9fc882663359bec6597f790F
e91975b3209890c97303eaf69e0732753a849373370d3f3db3d54eaa5d7a540dF
e931e9fe49a9a7c21e0cc3baa18262e5603d94fb11d0284564ceefad2eac5d87zF
e9370bcf27554400437736d6d3c4091baa10166592baf0f0a1912084c024255dF
e940311272fea2057047e571496ef2c682d234a1b3e10e8c505258a1cc20ae6b	WF
e95162c5ce19bdda8897921e19c340bcc15ab18c2627b6d8915c79b8754c1505	JF
e95f299b4e1d9a775808bed9298856196169c363ce0d077bfc1bda79e4c4d4f4VF
e964887b330c27510a0b5b1eb8c31a8c5eda05bde74e42a145bea54bb240d3354F
e96f88c3dd68cba08085ab79ac4207e040e7c65ade70b55699f2e7ff5fa8e7bf
d

ee:V+rF
e9c3f41aecb56447424691a9aedff1c7449cb17f5a1e759c6f7c7c089b2d1adf0F
e9c57b29838349dee4d11ec1d130cd0d7b3fb5df669721f178440fd42a507752F
e9ccc19a3fa831005a0f5568fdabe7c13acd32de915df5fe49983a0214fb34d3NF
e9cf08af12886825c6d69d18bf973a365efea2397256411d55daa08c561f2b04F
e9db6345b34c115b15bd297bcda0f0680ee1a37cf51adeb1477e16e232d6f289F
e9ee7e077912afbee46d9de1440f905a3150a783ca98d2999145e7f0d4946b00F
e9f64d411062686481236a557581f3593d4706cf5f1fd5f942dc86a107e85be4F
e9fa16cde65d0d202fe417fb0585d64a534cd25d39e715a1fb32a75e6620e475F
ea09355eb6ee209c2b42e898475fc5462249ee3f27b0dd881ee2fd0db8245464F
ea213c63260f95219614321b7530531b4a081af5c6ae3749a8ed600ba0507ddbLF
ea320050b773b3095645df0c61516e8030958f578d9daf62822c281104949a7cNF
ea32b047fba7fd327bf943da2a18413a1ed3e245cc1b077f34d1c8f6048d9813F
ea3f0bb12ce7b5c386ca301b0f16f7dddafa4ed5f63b2ab2cd2fe297d066f387@

ee:V+rF
ea41aafc4258682847158cad9b72b66d86e801649ba22dfbbb766d88ea1addafF
ea43fb93ee5477ce7a096f94c4c69775bd338911a252668b833ecc7ffe9f4452F
ea48b9fb3553584f758b7a3b5b3689740e4d04e82eb6d0359b8fecbde72b9b23
F
ea590d364a03624b219bdbcff4119983ab7a1bd31a6a7146afb0d4e684761056	F
ea5bee404d5fc3e07b6c6c946b4663fdc9b4befd89d89e5fd0c57da7b27800ecF
ea62e68511b809f9becc99bd815384ecd8f52c7abded5c1a0a143ce0c6f07f1evF
ea6f1a1a7c98ce44e3489a64d9fcac1d1df66d5e27e509bf3c0413c0d2f01be2
F
ea73cbefe91a8c86fea9a227d19b9f36d68daa5f9e640d6d6acf7a6ad65c4297	F
ea9c2c4f4cd124e0cdbfbb60888f7eea8cf1e397c7c5596b9b262f491182efda_F
ea9dcf09763ae93b161230c20f7c1a05f3a8854c5c164594f7bcfbeefb4c4ffdF
eaa6538f84c57debe1e4e618a3bc6f27c19d7cf0cec59ad717f487b978c10409F
eabc52b09196e354f58fd80ffdc7a2ac038da61c3a8d783f6064cc3031bc9fcc&F
eabf42cd353ef8d1bad1431cc770d9f360563c64237198926aaa475aab327c3d

ee:V+rF
eacae6ba8f4fa9d2b666e28bad819c383c5eb197aa1aa5f5979c415530cf3376
F
eace35203de4fbc64ea081a27197877a56615d25b23b30e79f559209ff736310F
ead119fe47b9382012e61124387aa69dfe644f344ccdfad3b91a64e1ab35f467F
eade03c2757a3c0b0151aabbf535e1647f2a3c18eae55a5a975327c4c8027a4cF
eae7a2d2bc9f6058c113c27e6bdea6677a865df0f7924ed51165a2653c2d2175F
eaffff0c99bd293104ff77f035145a5872da50599d8f1b26609f145f305e2df4XF
eb01e604d2abe850e31d2092b9db3c5b0df3ee2c53ee80d31ea248c0962ea297F
eb03c3bd51b0bec375b458b8d72953391f35f59d1ffa7969433da6b1fecf8867
vF
eb1886e298af82bc97e979491381fe23e271aabb79f09bef435b84c876817fbdsF
eb18e0e118e44349b3d8917b223e6ca7e2331d41d2e49ec2e8a65f091985bfb7F
eb29338fad95f41a0a8ae1941a0bf623792e7b35ba434c87283f68788f25817dF
eb2b61c0a574c0e3c540083c4f4f8009c0832616ae48554fa6f402b145b77bb0aF
eb2e226e824b06855d4cf867531fb5f3409412d883d6e56543603660748ecfbb

ee:V+rF
eb5d1459a1ed3b55d3a45f58f61633509ffca8700fc3dc3f1935cde74eb204c0F
eb5ebcc220cbcdd1df7a8fd9b4c1dcc27b611af10741997070d522208153e79beF
eb68b066fac31ef1d13db384711879546250d149147a9bfbe0a62bd5f62d0bca9F
eb68e76343740b950f6fb531ed5af6afc884e16c3ca61bdb35b1d2115d73f0c4F
eb7bebdbd517434195d041324099366ce234dfd58929430224320ff59b866c8eGF
eb89964d5fd40ec94ee8db97a5a14cc8dd6329b83d82ab29ee1a595653ce5223F
eb952f256def8d9b5c0ecaab67593927376bd7ec33819298399c3542e974f47b
F
eb9adb9f6d4141d4d82fd9f2740d41d0ed32fde5148d9e4a3d952f1aedb10a52F
eba7c5a667e7db88684d709d6c7106aa972e55a41d27a79736afb8d0eec1de6dkF
ebbfadfcdd945e3b5ae40adb51fb4d444facc09bdd9f9cc989542bfed2cdee60F
ebc3f9be0c742cb29c3852f630ce1ed5605f07849ea71b3f6dcad16424055700F
ebce0b46fb13981f4746adf603b6f96c83356c88ae4ed0053fdb5b506fbb97b1sF
ebcf9402d4327c9a14ef951bf3262aefce60b172528292bf1c628e54a7055235

ee:V+rF
ebe9101eafa195e97d5191257396d826d54a03212851b56130c2502068cb8f4c
F
ebf604edce00a3a3778207eeaac06a3de226dbf62bfb987ed00584aa8d736ea1F
ebf6108e3363c7e97a710010b034bcd8756cb06bdb7dcad7f1cfd7b5d5b94925F
ebf8758838f5dc246c98cc6f76706eafa07a5083df17f4fbfa2489df5db984586F
ebfa2d89f68f1f01852d54bde30581583c8843675d4c7bd6d2d5474a0d29fc5a
F
ec1b22bbbd65cf0d8ac4abc748b4d4e1721149c816440d123ce3d707e25059a8F
ec1f41bbc53f78290aa486eef749003264f457b41442f93d5ea5e629c64bbe1fPF
ec2503de79ebe13134bfc568d71d9a2c99d9f6d109eb2f80a8198fb2e331bb9fF
ec25d05d782c32b42db9e24ba4c9449d7fc9c689e3d0fa711ce8f94c261ce6b7F
ec3383b51ed106826513f9c2945df6ff25b528b122a9b848b069c9e8d6cb5e46F
ec41eab909a34c37394e1bd1e2d8c1f86ed4342eb3aec006e4dce9be59094696F
ec4cb2d5a569d854ac525bd458045223e598500765770d860e5bf0b84a41767bF
ec4e31145b2bd5c37f07b12786ef3f1a7f747d2b7545a8f2deb7ca4a1dee6692	G

ee:V+rF
ec5c24d5377fe314137f22aa6ce809acee1e0231e7772cd10fcb69dfd3c4bb00XF
ec5ec6e21071682dfbc3c256617c810c886af178cfc7f21a96104cf10ee6cb25F
ec694ed3c68742fc4ff18e183f1eb03790bcac0cf47880b2b25ad5ac15c207f6~F
ec7d4d6f34f218c71ac4c95b8ae162cfa554d6f3285e389a230c52898b5df662;F
ec825c7e726b4f918e38b5d16c4713c4f73534bac35c94b116810482f92134c3iF
ecac7aae69f045e6bb94ecf2521d78d9f8f856a67352b6d877799477a31afa6bfF
ecb37964581de31750352b4a0c77e2efd6f71b55d33d488cc7d2460a0a00d744F
ecb4654a5f2ad2d8e3539f0b0076eee523a54eda425ef270ec5cb0394fa1ea8cF
ecb7f8d19fb659a35a4a25d22a891cfd89fd55cc12d791df222c33eba1c9dbdbF
ecbcdfc04b53ea64ad8edb3e42271b75385cb3a6087173d58c0d0e9ac5074c56-F
ecbe95651dc59d12d773005ad0f00df91c1b689c1ad0402467603a9ab799c2fbF
ecd28bfd8a7f97d111587dec88746bdc8143ed9ea22a73f2c05141e5361dc7c2uF
ece1ae02259706cdcec7364ec892760537f5ace9a72c3942a8fe38bc4c185099
1N1|]>jNF
ecf00639a05e5928c699eb7451b91c04ef62ea4e3ada1c96ee6c9ba35c065f28\NF
edcb7daa302df852d996cca8fd843525c686219264ba83f606c7566c191682c4=NF
ee580eaecadcceeb9560a23a48c376d9c012f5fee8623d0f10419c273b744065NF
ef07f2b266e0d616931d672568f5c39d7789f51adb7332df77df77b19e7882a4NF
ef84b3d3c085de9b3168fe830f5afbe609ea6253e83c2174f7a07ed4efa94889NF
eff160acd2825b382858cba77f4f60a433755fd1621b6510f0a8a57dae54a512NF
f062b9d33e6eee164c17233ffc747844edad4fb3865de2b1c409d81837aff544TNF
f136bc0eecf5d5320db54998eac1c4599ab87a312d5ce7a2cefc841ab054b1ea
NF
f19ae45fcb7a758368a349bdd8244b1029ea8e22cd16b83c2fd74bcfa32253b6ENF
f24dce379d6c501f95ff094a43c786cc4932cecf9af4ed5ad162b4159d5a2007>NF
f2cbc4c0d7d808554f9689174450c43f80db727c186bd3a1980494886a25212aNF
f37f01eec61a287a1271577470666ad9b985aa271aa8eec00beb21627c77dd76#NF
f41e3da0ff09a0dfcee4669524a544896ae845227cd61f6da9cf4fac362b2c63

ee:V+rF
ecf0213aa5f1df68903633d6e37f83ba74657dcdfef00998680e1d13d4107e9bF
ecf6cae26af65369af3f9a5e154c7224e8c19a7f2b087e7e89cde5eec6f6000dF
ecfb16cf527793f6ec8118a181cf88df17babbdd3805563e4cd5e75bfa4846d1F
ed293f56a8fa1ff864e007c158a2833d672efa0618a2cd57b24f8ee570b7df80F
ed2d48ef1a3e3a6e64fd20780277157eee5875df3e41cf640f9569e3437be284kF
ed34b500e7e1951b8208f45e26b323c12c4fe5f89a8823445ddeeb1f28d5e93e7F
ed4172e7f07f89851711d81ae9ac691552500f1359efcfa1a0312b3c42b1e171F
ed62288ee271d53bb3c81742a33a6fe77f2edda3206814cfbd782ea0e9a2983bF
ed6e07b307de61a56b4041aaba7661b6fcdeb599402390671b3db4d8c0b4cdfcIF
ed85063f79df4dd6522878618ebc5308ad2d764ce401220c527ff0cca6d5f7d0F
eda7c72438a02feaa87b0471bad982e64322ca96392f353cea98f6fac51c34ceF
edc0594488f23ae7a46857065d3cd4d74e61a711b96dd5b99713419b033816a4
F
edc739d70b417881fba0df26ea94231e859c67a681a92b7a79ac1c97f5bba817

ee:V+rF
ede6fc896f82acb407c88ed425d1c7fa8420645aae77c5aaea694f1c692cbc45F
edf5824c7caaf50e97ae8b83f252bc9a7263368eef75626da3749913eb217eda~F
edfa799d5c426dea0808d52912a4ed39b1534c8e7a5d3dc0a96937be66990f1cF
ee029bb52291786cac00074d77fa338a3cdf2968607a5e85ffd05a69b46ebcdd
BF
ee0b6ee143ba37c13abc5858fef0725d5b30992afdcaff90babcd5af1ac812c8F
ee16939ba598d58caca0f792ce6324cd0251c779d1d37874af442d8cba4c2f23F
ee179dac3f97636a2f35955ae764b090dd0723607221b2ff12cbd42907440344F
ee225d31e25d3fd9c6524bed27748c75c0944037288a89578e3005fb2eedea8fYF
ee2c790a3cd22b1261a5cde580d44da4c93c567104a3688cf2369009abb5d332F
ee52c09ab7dca8a8e11fe87c0855b1ce38df1fdaef899e8ce50d80b72009b62bF
ee53408fcafec1e4615b6bf7b7991d0eacea72066fe43c1f01e49800d46bebceF
ee54ecaecccdbbb8de156e19a27d770e04d61778a19ef2dc30478b7fcfe65865xF
ee561a3f0dd8945edec3478e8426cc324bdf6fc5fe6a31d762cfae60d3e14830

ff;W,rF
ee6eb3ef29eea0165c0b0ffc82aba7958b58d0abbb0174433821699be8a41789F
ee75c5b0a2710a2f96753bcdc8e8b106f33c7eb00f1997b39950eff703900bf2F
ee831a9a421c3f86e21ee19ee0a9cf5254cfb534d32e86d6e52c61dba58a55f3F
ee8a7377ed0c955a55eec8ea39cbb91e5c2b99a4b050e0f4136075e5c7c87796F
eeb0a2f82f3dc57694d35b3eaf181212193a3ecdcce63837ee1d869a138901d0dF
eeb0ed8d5fd30d98e3bef225ead945fafb2e3dbd8cea8e4b45565671473073d7	F
eecc80d13fe486baa625924789eb5a656a1d00ebf4d3802de276c8d8c56dcb47F
eed9c32dd42309910cb6b2852ea885380fc1241a6f30a2cfe2b358fb417a433aF
eee4cb71588d025d63ac9b8c966fe2a49c4d9ab89f23553fcb7e360eb7ef2343~F
eeec2b53758cdbb0b3f3402b7117dddcf34c40e99612fc0ec69bb799b2a7b6beE
eef2f7ac436c0d23750d0d428880ec5d58260342fcb7de2587122eea70893429-F
eeff2dd2126e05da5903de0991d891313049be87f35dda8f67c383779761163fF
ef051c1a4e1bb137134383ae56882cf3cd061c02e00abb7c467c618029133545

ee:V+rF
ef0aa34944c10f3dbe1446cc6ead8acf304187b1c4cc41baa0b1780ae54410188F
ef23d81c590cbf657f32525eaf60a72a65cac4272b7cfa37677546ee5204deb1sF
ef26f87d833891a36ec1eeac1cbd5de9be6729295a8243544f11a26a7e28373a F
ef279f239f0fe62929c62165d00a4076c51667ba82c640a3790df88dfa67ffa1cF
ef2da07e17ad85947c0e573c1504b7566d8f242eb7bd44c2113d1acbb0e78a607F
ef3258341d0c757014a17a4cc94207f623282b6190b470f1517c29d8bb42218f	F
ef450f18a4cbb4b3e2590e06da308d71a68963d41ea453f5a033f04eeb3d6af2F
ef4964d104e49faae860fc6c639d7d643ba1785fc33508588d20d8486431c33fF
ef535692955e3b9dc14a633b487f86ba36720866a39c354e86275b7f23d6adba(F
ef66a09a84348d5622f0a06d5b40c4c3a826cd62cc050713646da3398248d3bcF
ef6b1d6ee31b3645952263c7292d83ff8479a7e1fa07238da2994be9d38f266bF
ef7f2a44b28fe81a03c9c1d9ff9899b216bc95ee9f93b7647a5a07a655a990c2tF
ef82a93c26a7db64bb635cb373e0bf00ab1038b8e42c02b37a970cc41e97ef34Y

ff;V+rF
ef867ce0d361ef3e0350fa0128a70e322998b6b6c0ed8efaf0a06ff011e132c8uF
ef8ede3695ebb9829a9403065f243ab8acef8f14316aabcc9b26c4255ee93bbe
+F
ef91b432545f513294a7b3949519656a6cd8b9d3ee0fc8217364537cfefde363NE
ef9ae19900dd432de99370f4bb886c82cc0f4b68367dc2be63113d3f3cbd48d1BF
efa06b2642e8d158f0e16bbaaa5d8d454be1db364722a3321c4cf61727e988d8F
efa403ad1b6d2564bce0ec54cef3ee401c15f4282733a928d75bb703119161b5iF
efa7cbf450462d4d95389173c50afbb6786eb202258fbc8ba90ef57e2459561aF
efd5c472cec8f06ea30eaa8cef287b401fcdf4b0a30e6b2531888ea03f1f9549F
efd9d7f9ca4a7ab583fb075ecf7b7abda7fa92b4657a5d14c6e3ea7f67c30608F
efe004dfc7fcd0160427a7f637f2cab140b7a315eee7143e1894e834e4a70487	F
efe7ae6b25e582508f3ba41e0017ca4b0ffbec80692919abd79c1b54bbb43465F
efe92dccaf584ac534e20c985a62a2b2030dbbc1cac6586eb9de81ac5dcc7acdF
efeaab4045eee3dabd94e6ae1b90d46bc4bc41180b4e0b8ceec3e018edace11d

ee:V+rF
f009c9c18a2c60a9c998051c6c0a08500ac08b6f4d0b3e130aec02f0bac6afe5F
f00c1a71ef838f6972f7559129c30772cf908879baef300c1d4d8fe9b449c0a9?F
f01aa14c280b18ae6d80cc559938fa75c648eb1537499db7841129684e2be5d9DF
f01ff7e1c5e53cb4a291d2d25285e11895191ae658824d9c05669907941f4c34F
f020458306c1798b97bbe293da7347160996bd9a1e89d548f4012bde28cc4a52F
f023965895ca396ee7837ef741c80807f3fcd4e941fe9b021ef6476083832b31F
f0254a038a74be08cf548424dccbe986696e47e0e50cd52cf8f1ecdf5cf432b0F
f0264bd6f2bbb5db07d005243d60a13920c116e9e1b122e88fab4886f3ff1bc8+F
f0308f6cab8d1b2a831f455e5c9950062be00908841b0a04d0555377c61e49ca	F
f03348b00055f767dc054a8e674751bceb513c92df57c9bdfdd52dbc987da25aF
f035504bb52e167428211e66d8d1e6057ea84e13f5eb03edf9c7d58b26a52b99qF
f037f86f203b3b15569c8b08388aeeeba9eda00ceac6945410b851d91563d688xF
f057ce5463bca14d6bab2c699782e32341b1b37571dc5466905db2fca2c1b392}

ee:V+rF
f066c4d77c32004d1843615beab2f59dce9664e5e79aaf6f5453d44d0d9e02fe	F
f07e21fd43e16c0797d167891e1f8dd87c7bcf4ac4177307aec21e25a55ece03dF
f086e1ae057782a612a9146ab15a673cb1fc1c351507f164527a1561fe1017e1EF
f08e9ea6985102fff682040f9282a64d08ae60b52a53ac25a2ae2d14b381049e
F
f09a628b0ae728f1bafc53c158926f284c0273e95363412bc951888d30e73e36F
f0af2e9f5541fb785da048e6b6711cfb336457efd4dbe07344c3ed34aaacbea7F
f0b50f270ec1c14903fbb91ed28d0134d984399e67c5cab7709b5de27479c361oF
f0c0b3f210497c3d560f42df97307f09afe0cd687c2e08ebc1cb7b03e28b8319F
f0c9b7b923d47df8b92aa0c427d4754da9c2d22e9eb87e436c06305406998a3c[F
f1014b0e635f3231b9775aea6acf589330dd8192d714a231b5392dff24ffc861F
f10fadd67898b87e6a2cff2133bfc00f51855894a26aec2b6bbd530aec018cc2F
f111af81b1171cde02cdf42152cd2cf0b250c9a755cff39952df38908f7a55f8:F
f12b43b7660d30cf43f854e59aded17e8167850a81e00bc36ff1f71c6366769e

ee:V+rF
f138db80a257cdee37382222b7317f2f922c13efffd8d47716c4daff0fb11d68$F
f13bbe4b18a80136adc1b2b02ef61c69686b5b4b0437ee77f9ae29ee64542d8cF
f13d571f41792afa9d08465580b23f08ff7dd564e51f40e42a9b9f3a0ff77b62^F
f13d76a0cbcea5bf7f05f28bbb2ad0ca59d71e977f1c3f3c544f403d4f947794RF
f1402f59f4309e9a2ad497a9699c098b61381170de7f600a6a7636db589400d5mF
f1543bd7c42d040f29b768234c950b37aba8c48f0e6347079bc3d83cd152f2b5F
f154f7fbe4285c64fd5d8032253657798d0717ac258ce5a8ece9b6e798df388cF
f175256e0db000797ef4332af954004e00e6e2e00f33db843eee3edb4eddc61e]F
f17b58dd383483f1592c8c3c0bf814ed80d208d19a254620ec541a14c9f5f144F
f17e881111b5bdf792e8c6c4ebf56c864fe82ead7236e9d1714054bb3577b4c1F
f181f4bc3868b84eb350197aee4e79d0466d5aaac0e0a70a37eb58aa7533e228	gF
f1844144d5a3c42025f3ef1788373858de7187d6dd96e9bcddac4b3fd027e5c9	F
f1896e8ffe63eff76d82b6ef313c62631fce45258dee3c4ac0e2ffe4b8e841e6

ee:V+rF
f19ef75ad99fd28a32063032985acd16eed69a49de7940fe80fe25a45d7b20d5RF
f1aac8f28d7b09a95684a3721602f0d75b800ec4446164425cbe36568cb5d9e6F
f1ba2741b87027c8c0f29b9262bb396c142986c3ad3c68f88e90f34cb028b6deF
f1f8e68da43d3543c537c23e696bea84b8c7e225d2a8e638f1d3e6b4c768f286F
f1fbcc04902985414df518ea977cb39390df37dc9fc617aeab23437cf6fe80e5
SF
f204489e33ce1fbb9eeba9986ed191914338380781d4fef1e6cb0b7256570389lF
f2136014ff193c8527ea2351651b413e5c8cb5eeb1687c98dd2e6d544c6813bdF
f21d363926810e31889a7fa98205382c0b8de58aa4f45928c27d9e67046b9482
.F
f2241666af94fe720a9238c276f97db47b1cb8737b678465e84924e2d3a8d6e1vF
f22ced6e5193aa0b22495fa95e9de588c04f9afa2d6070faf801306fc7e68363zF
f2365b1ca47b98315778026ca1ce13fb99b6db32a6919f3686b8ecf3a457b96e{F
f23ad28777ef3020a0b4c72141bc0d367c9a60a8eca144eafcef471df349d126.F
f23cd99f65fe05afff0761b481a6ae707428f006a7f8e5dc7c8c2f1c8a92a6e7

ff;V+rF
f24ecb14a77ec32e37ced96fada59ef24d4cd88eb3684963738eff6c0f73f73cOF
f24fba7955a7d873bfbd39bae28a5c850f2c27928e1cd98d54264fe51a7d4befPF
f251e57808a6960518cf05f98f4bed5c0b006b5a01550a68ebb9141c79f0a2dd	 F
f261f44a0301705f4e2b2a56556cdb340ae2487517c8ca12013301b3a983bd58F
f26c9b240bf171505aca04c2bee6244c21da11124c5c4e9424507df05251fc9dF
f26eeb8cccc9c113330f61096bc1da10e3aa2798e3da03526928f761d77785ecE
f27e3d167e8d7cfb2c448d400f034b7443c2e076e94b38a67fddd951a9bf745eaF
f281eb4ce184ac0156ea4bb4999c5ac0071da44c1cb72f33d1fa6cfd57c1b932F
f292ac03827b0d517e0873201d36bd5f7899da820fe99fba7955de328d3e2773:F
f2a450757e610e9d7a49050e04cab12edad074ddca95fd92a67972bd61fcbabafF
f2a56e1e7ae1606a974d68a45c31824b05cfcb8ff28d94b4d090080e6e76c3a7F
f2bf2828a9c0dfda573e370c7710e37259fb9041de3d51ef97b7cd65188789a9!F
f2c9f87c9483b4181bdafd6a1753e97a9f5dcfc18ea6c72e9295ea06d7048933

ee:V+rF
f2dc09932d5afec99bdc35c39f858385a06e600f3b989133d348ed00959ba429F
f2e6529205d5d5cda9ea3d5996514f86afdf1ddacc087c47d9f80362b885b94d=F
f2ec86971a1091e0bfe181b4363faea8e87a9b3e3559bb53f97966d8f02e97d2	F
f2ef03a6ec5037c50e7f13a6a7c2465e14b247e48ec9b158e91bbf86094e3dd1yF
f2fa340f24195c35a86b3ed5c2f4ca5405ba1e6482aab26dd1e8d7ce339a73fbF
f30bed050378d0ff2aec7c2fe523d1b6505bc116cce61a59687efe5e1d2a0014F
f313883838c79487308bec6209cc25ea688f77759c6bbdb331c4237999334033dF
f317e5b0fc8e8e40046f6893b5e1dc36e8b5cf17a92069152dccb27c1ff6c45dF
f31fd03961b259ff05fa33eb46e64b8dfb29cd1193b459d1721e424ea9616d10F
f3232baca2103d254d79671daddcba0c012aa020484304adc85d7cceaa00fab4F
f3480d9490430ccdec35a8db1fdcd4f48fc92476fd17dea7b616fd9995372e88uF
f34c8bb09dee906565117017407530b10c48ef7eb3ccb89860689de03b8e4118F
f359b38fcffcd9d7ae7daab258f4fd7abea1c839790269254b9b1fbebcb55ba1

ee:V+rF
f3a22e24901cdfdb4cde6e3e1d5b92db9632edc9ae10810d0634340ae334a5fdhF
f3a76eebff774f1e84066ca2ae1e4c12833ebcff375ee7d2d50547214c4f9d1bMF
f3aa08ddf57c680c2b4642a22c261e11569a25f83c746d38afc1173fef7580f0
F
f3aaf1422d162735cb3147c5876e2d569c5ab751c3e355d4f973d16250916a4cYF
f3c1504a0f9e8be3e261212092e89009d8b01f3fe0f1804ed10e767846e87d26F
f3cd33690b0532fcbb6ef97043d3026fa11e0d5e3583d070659675619ccd31b3PF
f3cd69f130263e2bd4ccca5ef76054432d3c23432298df1d0aeed37eda7db3f4/F
f3d62a8cb0a97c76e6a8d6432f16d9b3f9040d5289f63d709f50a3776efaa8b4\F
f3dc3c542749f94c4e3a601842a9a8d6311fb735a5d6ee8d3845ce5b137c43ee!F
f3e24a8285c55480cfef6e63c976be0f143c1010b3511cdb0c8f2bc86dd82ef4"F
f3ebae8493971694208c96d6d6286e660e797bed742700585d403ce9fd145072F
f3f69f58e04b244b740beae57319f782363f8a8bfaacea37bca6ed2cb7d1cd2eAF
f3feee0430c1446d861e17d9a043a72cc0690f3c3618ae27a60610bfc197c499

ee:V+rF
f424072382650daa052fcb9ac01eb3fc0209eb1d8f2bc0d18f3bf1bebd42dc39
F
f42f1e28a26e049582540bf27d99e95a1b241c2fc2e9faf3b2165ac8dbdd35e8F
f43e7c1792d357cd5fb1ac5a13e744a5ba50e7309444d7ab7d0149227755b575F
f44cd6beef0e0285e87ceddb589f3ce6b36f4340a280ed674cc37aa7141b8397ZF
f455772710a92ccc156759199ca532b9536d567cda99884613c0d4ec6f35ed4cF
f45ad8b56aec3746c319fed77321ec80808dbcf5aba0a01712c29bf922951edbF
f465238db8cffd5b22112d022c74977b69d65ca1b414ece5ec29ff7b1f1c209aF
f46d473dfbe5a0b5d02b3be921a86e5638354a09914341da2a7329751ea9632aF
f47163cfd1c460c07d781e489622d1befb7dde8116948f80289c8bc685eef102~F
f48caf62db65a846a2e5bf134e7e6a5aa0bcc81a67c9995255a33f3f18ab9f65F
f48ce4d917bdd2d6d5ec5a6aa18216b99e980b86d7308d6e535eafb38aa0fbfcSF
f48d75115ac638576d608849a173ace6a70c2430a2e0226487652befdf004b27F
f4a5bde79d6cee985d2f0ff8727b2428ec15fbdd03adaa9733b09f7b173c01c7

ee:V+rF
f4c0956c54c55adea5769904bb460f6ab64b017d31e9a73f0a047345be6dd6afF
f4deeab3c5a75216ce3af70b11f8d415b9ca7db8bbbabd522ec02ba360b945c4F
f4df6c727e6e445ddca7fe286fc32ec9aed6c8a3fddf42faf905580926d1117a+F
f5037b5658870caf9db57fef7e511d690b1959170ab11cfda5aa83f814633ba2DF
f51bb9d1fa63c5bb467fc5024de79c68a580bffb93e0ee00dad4ffd1edfb0dc6
F
f530a65c0efca53f618f63e02801129283b12266fbf21ac221e35617a45b0d4b
F
f5394565fcf1a20382bcdd1f64e77e587e222a4e135860c31a6a2b4f012e4691	F
f53aa25a58a78740dad5a5777ccec426834c3455b4a323c3cd264c877f39e567F
f53cc1052d30f24f16353f3b8289baea8f6b5784241e361ca528cc3a0eaa3777
mF
f53d0c4b2718fb2cccc1cce0666cef6323bd6fdb7b789f34a3fa3a744c3892ecF
f53f33bb25947de42ac961faa1b3edbf1207b3e8028e8c283c139b943b66ed73F
f5431ddb3fa8ee6d51952c046b560ee5619c84a6216a417156f99dd392045d24F
f544bc64d6a690d2e5853b042cb5a8c7eb50879dacd1acf3c3eca69966d25370	
1O1|]>jNF
f547d5c45db4604dbe0d39eae1befa3f083f7d65e124d7458ba4032e3ab8a287
NF
f5e02cd3cf204b648c7dd511674fd8b54070efe7521303ff43080cfcb8b074a3NF
f65aabbd9e294d13896f966d93142b9e462abc508dc124cbced08758d3d9247ayNF
f6c5c1dd3e31927fa431f3f886053e4f234ec506a168fc28c7d537f9e6f5e4c9_NF
f72c4452b5c2bc0bf8146118cc495dcd56c62624ab38dedb3ae6ba2a0abd7a9cNF
f7db305710a65de9955170c92aeba72e62fb979802464b4239b0b607d6adc2a07NF
f83a9cc23d159877dba95b62d685edf3a6968d8d968732049c688fe7d49777d42NF
f86fdc6c605d339bf653d5faa2de82748934dd460074eeb49f6832f2870c1190QNF
f8d95a99893e9265f3f6125f684c56c23afa3834653a04d0e9dbe9360a6aaf5dNF
f97dd6a530e0dc37dde8d1e71e04e877196e4f36ac6754904cd6a5e8e0e4990fUNF
fa07de67ceb878410ad9f1e78b5368935921fefc6de60e009128f1c94f70de52OF
facd76c3134bc61acc238804781421a124627264ef3476cf551ab5fdf5edf584#OF
fb3f399c2cd3a00d11861039ba16df58c2d041ebce64824acdef0563df4d8ed8

ee:V+rF
f563d696d882905f6633fed7a3fe77d0876a29170b14175715b53e21a84887b1F
f566582c4354cf859dbaad8604aeac5c8344f7e81c02de69fe4124ea1537501cF
f5670dae0add00bdfd492611247f9503be7281552df1cc745f5b359269462efdF
f57d7074e8e50a23c9a10a230c6edbd1f48bc3130046704525be72e10c371656F
f583bf56ffb7c05d556141a0b44a90d47787543323e3780b29177cbad9e84c99+F
f595ada1902e66bf4b5ae1c8ad3bf1f1092dee59bd392f2519b518dd24fc8e33
	F
f59ceed71d088a420b5ecc67bc4a13df798f7d3d12556a27285fb4dfd594850eF
f59dc733e2e61cc262d571504ef9b62561aab27935f5cc432e2109e165936dacF
f5a544c1c54d159d63ecf02b66555411db8230d7164937c969ee12412a7b3426F
f5c53c037a56c4f01f26c5e6d1a0011da7c9f759cf87074bf864708e6ce19828F
f5d02c79227db8a83ef923f005bb223131cc21a7d230cd462aa73916b2da8a5aYF
f5d06a0438f7a24578bc611af20cbc9e52844b6cfbb52579826da412b7050eafF
f5d9885773ed21397aa08232737d51af6803c1358395a2168b6820ce496d927f

ff;V+rF
f5e54963c8d3735251b4501639c3af99731c36ad7de1884a62f8086d7546d5b1F
f5e6524f1f2a9dcc72ebf9399a52dc24da1e60c30002c88d69c630e49623aac1F
f5ed6de364527262c7c94c0a93639ae14e4a1137b79f84385dfd331a2a78b7f4lF
f5ee3ffceb6d3dc9e61ef0f7f67a18dcd1934d4331e74fa1ae157538a284020d.F
f6017656fae735dfc5831c4b635cb2dda2cae8615a1d0a4b66898f7a6b9f168bE
f613394ac503882a78ac261fc0ddce0cd6b033530342f31d88f080b4b99f51b0UF
f61c338504f42e88dbef95a448e0e1aa1c04a89586134610472f384c31966981VF
f6274f5c3cd73beb54d94229fd5b93b99b525f50921dae06b852ca0ada18b5b9F
f63528cfd40b5a5fb0d1e92cd4b91403bab6d49b9bd38ad0aef9e293a98a4b2aF
f636e55dd0ac87d64782eab7493353a4a5210c1b1178a67593b356a1a82b9180F
f63a8f468eb357e3dd612d59f718c35eb2605df94684b551b1a984c732862fbeF
f646388701bda1badf96a2fb3864cff8cec8c983277a87af8b050a51147a03af5F
f659cc4a3ded31fe85ee2123860696b26f1983182f66c76b6a76d0e5dc5f3d2fi

ff;V+rF
f6645c7cbc24d07e153f2c8892cf815d6c7edf416985b8afe81d4a7af9562adcGF
f66887fb1f33b96e1102061d623623d7d06c2f8b951e00a16b5c6b4d260f7a75	rF
f676e5412e87446863b10f16b82807f5a4324279353554edb7aeb3cfa9143061DF
f689ef5286607afcfe9eb7c26a9d7f07776b7313883081a2f3da3e14867271b4F
f69f263757a6c7fcfc52b278211fe2c2f78f053dfb157200b4e1e1a874b400c2 E
f6a237d150654379162b6b0cb9396c65ec4227bf24e4b01d1dbb5180dc3b28beMF
f6a468589dc2d68540fefdc5fe28df4e741f1d5c46a396376cd5787d8170a88aF
f6a7307b2019d7d0e915192006d8ef7f56bbd11efafed60f9a5cb5f67f74db72F
f6b017a1e5d505f7794845950a247b12ba961e8bd6ea366098a0ca5e83e7acec
*F
f6b2698566260a93a03d412c81d071599637c1e75b05da8cabdcc3de0e4591eaF
f6b64e5a20d4a11fbbe440a1ef9cc7566bba9bb10dcf6852b1d53148fdcf01b6F
f6b96a84dad57397afdccb0873c1927936c50a3c80b0b8e632763ea46c6bd495
F
f6c41df4e2079f35e9de7d6585897bf99e364b1eb18aa9ec79d9e20b9766f5e4a

ee:V+rF
f6c854fef6008f3f063c3ed1c4f6a2e51821b5fe057282702dfcd15b7783bd41F
f6c9684def9cd5c7f66fcd886ee8773d2b2f5ae9bdb6dfb6f71d2377b140d30d
F
f6d493768ae9d25baa9e023ca6cee4fb1666c5cbd53f8c18631342dc3e38f221
F
f6db1b3fb1c1f752662a489c152e531a9bb3841011827eb8aa03225e7521e058F
f6e16caafd938158d5d693a73fc21601fae109452acfff7e3b9ed72d940a89b7F
f6eec5c1e694fd7e8232482c537de9cd0baf38de7afc7c99fee2ddf4b248488d
F
f6f4af57d47fdebdd0de45acce2777a89181f31063e8511ded23c672de57fe992F
f6fbb6525d675cb023750b0e38502f6e9d30cb7ce70f98d75a7bc6a76d175598F
f707cfc509f1fd8d7d482b5937245f4dbfc078d16c4defb7fef772d41daac079F
f7211e59a025b27356cfb06417188c0dd5e275b865c332da16611d69cbc3addb
F
f725b54a5b7f5170fe4100a72816877759353b4ed7786387970c66d43de05d9drF
f7291bdf6020187d7cf5369c95f16faeef861f866ffc8c46c03116ea2adf9092
F
f72a7e95336d9380f37c46d2de0b736c876a15b4c1e7dbb4c351ca2552bbc411

ee:V+rF
f74a68159214f1426d96de0733bdacb896eb4589d3e21a7f2e703f6256d709bcF
f74b0b973f9171904ea286136bf82b4154a2d8121fb7508c2e3a8285485f2f48OF
f74f11e10a148e5f0fa3445db786553e080cb5d020e255c3b688dfd528ab6f2cEF
f7501b0cdc7eb8f83b56ce263d1a1408914f103af339c893bd31a587ad345cd3F
f759508ca587ecc4ba720b9a7958780468e4b3259069514d52bbb9963d29f17e2F
f7789c32ac34827df4b6c180e845361bb70aa1fcbc165a6c2a533559f2bc3f76F
f7945628e8e698e802ec8e5135e5523626b0540472b6dbc6921ff39095ca55d1F
f7adf614ea3e894e205363b2127216f22ee9c39ca71d8e74850d8e335e75be47F
f7bd069d04d994e785e1883f97be7c9af76091600cb13d99b634f878bb79c5e0
MF
f7c28e4b2e40bd7978b5bd740987494914a4fb3430ca45bea2cc9a5f94c01b50F
f7c83637d8468e19213b90ac92d161c309fd5941a55567c16d8598b7ff66e882F
f7d0605e20c9b7a067014b7687865aa1141217958d73b9b8d83a71b4da504dafF
f7db225b7e95f311ff6f6b1334882841ae105198666b212f6c134f496b5c2ea76

ee:V+rF
f7e3acc601ed8b9698fbc58cf297b2ad5a49ead168e515f329e2d95f3cd8083dF
f7f083c13947185b5768e1f009aec9585e1938f2f714b6fe2248b509babb5dbdF
f7f4d9e5559f8b130d55ce0048a0976d08ca48b1e818df7319c89d168e26c14e
!F
f7f969b6625cce5d7207b8a291d03841700e7b868361f6f98ce61bb3cc624622F
f7faa6dc9e93209b28d0cf6a0ef6f0697ece6387cbb402f2554016b1db3192a5F
f807177c77f5b66e10ff872d87a5651796c519c8d3b788ad034ec80c6c71e89fxF
f80cd4881b32dd129ece7202403ba656b6cabbaebccce97cfcacaf448e2d221fF
f818d743b3ac159c87610d03230aad3b70743afe5fc38d30a3aac4ab50db977eF
f81e7c1a0f24f7ca56cedc1938c0e1bba78c74ad082589529118fe1d795d6748TF
f82689a8168490ea030790e836a9ce025ac23d19836b5ef4eb2d441b7d99d8a0F
f8276a4628fde1b9537d7805763e64371f666ae7c100b439e3e89016471525d9
F
f82ec6b5a321f21916898763958f2f66aa27af989f717611ee77da7475cd01dbF
f8321c847bc9b5ba2834eb175db280c4c1ab904ea8bbe5ce080e0e4a7f8e9536
e

ee:V+rF
f83ec3658d72831d5deeee66d0ec75ae458c847847184396c345cb664bbe8d43F
f83ef096b0d758bfec621ecd1c7467134e6ea814c4941955dcba2bb7e59529a7GF
f84205da14142e8d12abc39e3d5796ac7bb70e93f90df0226c6de1e7ee119da1&F
f84f146908408a42a5ca58fda595d715329febfea19773c4ce12227022c0a0fe/F
f854a25eb972d3b371b5576e432a9a20947bb7be07e83253e98bd2b39025d16aF
f857d70721c9f191d7cebc1993d75fc3dbb29bc7c08b3b8e0044ba4d2205446aMF
f85bf7e8f01a89ac772fea257536fa49cc0e71b925cccbf45c5bac62a6c37058F
f85c959b9b36039c3d4707a5c1e73243be76f1191f9b467bae50a18a9612af31PF
f85fb2606d67d58d19d4784aa765bd6d383b85945372625ef606ddc20559702dF
f8613e068693df3d5e08f956697ae0b595071f7b8c8bbed307faf9dbadef2a8a	lF
f864e79dfe36d75d7556fb743ec1038d71b3a2297a830d51c78853475c425d76hF
f868ce40374cc82b06433374fe4cf3bba215a30f1d27cc97037f1c1d746e0c33
F
f86c6c90299668354041eda67783846766ed3c5050562845c55de4a2ebe33c85

ff;W+rF
f878599f24a0292058a13dbc96e35533360c55c1e4616d4db0cce5da1e4ed0e3F
f878ae8eff1fab58c570c743d050866a386253258cd06a481221516b31ab7bc9F
f87c2dd925c9d1309b2c16ad21f5c84cb1b2789d322aefb90bd02179185c3c04F
f87dbce0436b2de45c2927d892e89fb44340ab9ee675d27c648fbe5c6ae4fdebF
f87df491c22e76385180845739c13ba05724afcded006f1e0f2114ff956460e9HF
f88c4bed9b2d9000b18a7505809eaf38777fe41fd6aeed9b928493c204e4783fF
f89d39e2f15a5f9de6ac154edd1ca68886b384c0e12ef5657eb722c92e9c0788
F
f89e78370bd25ce90933cc003b71d1a2bcb2d53f73c8919389825731abc978072E
f8c005d77b5c2074f8f5ecf019407c406d423acd0fddbce4ac8b4efa1be0f808F
f8c57e980b49a9dd5b43aabb9b590741efe9dc8ac4e8fe1955f4ffa5f0bb2399@F
f8d118dd0c38e6be586da71c24bb8639d30d388d9b57e276ec52b9ac2f649eadF
f8d5011b3c0674720d0b3957a9b73860210ff186379452e0225431f7619a349f
F
f8d72ec48ec0e1f77e42f4f2a5c6dbeabe6e13e680771e35008c6865faee59f6B

ee:V+rF
f901d903838a840af4b07b7405171f08944a919391efff75f782b9d2c5a6a8a7
F
f9112352a12b79f2772b0d357f993f93cfbadb96eb79b1c1b7ea2072dad1e32a,F
f9138cc0c8bd84737691daa9f6f8f6914ee52bef60ec7862c2921c8d8743faa70F
f9157874165a2f0bfd45d4225d6b6665f3447d99d8b0b7c31b884b462c45218eF
f91b2363933aa9f88629048ee0d497b9541689ada66a07709b03177f3d709470CF
f926be88eca8a48d3a20210809bb3b3034814e0660e27737f39f9db9589b332dF
f92fde3f97c0034135796baa7cd55f87c0550a88ac79adbdcc9c7f64c595614bF
f93d558436474dcf26feea265313045cb98abbe57849c1f0f07a622d83612eb1F
f94a030f57e0305ea48372f1b189a3297e92fb634475062f758ad5de5eec967e
F
f94ef4ce18a021edb2b5a72fc87092d88e8c7b4aac3c605213fea20cdeefb002F
f95f722b442bc9d91784e68a17b61860bc39197eaa93b49c63ee4572dd5a1007{F
f9676ddcb0d16744e15c0dea1da0d19db48f65f8b002b815347953e2a4f2bed8F
f97d96977b7b2e8e4ab1dfcae63bf6275503575c3a994ebfdf713ecee262b899Q

ff;V+rF
f97f8b49e1c67b65e3bc3821a5542f91cff1d9241f858a36d041fae368a1f2fc2F
f985f476bdedc2f9a31dcd4fddfea63520d50b7d0201272e1df3ec06366409a3{F
f9905c0c94b3cb7db5412f3ffcce1c6b2b13d3d3d679ba948bd55a6d413c8944F
f9934db5cc1113b572f8e7b163ba8385a71464f8594e0a39efcdf885afab2e39YF
f9a5378694573063ecf61c516d27731ba3a515cc1b91bfced9a7057634a8d54cE
f9a690e8aa496786b4e27818af37b20bb17b3805bd626de662a2647c04ea6bb1(F
f9a6ea022ebc4cdade8272e421cc47f8c54d66a2ad1efefff8e7486fa6802399F
f9b5b8e607b0475317be118a94288240012fe680504fba887596246d7173029fF
f9c8ee59079e1a20cac32e3fe1b20f6f94b271c132efb4de7f5f0ebad73c632dF
f9d23d9aa39fc06d77ca52634c5687043798a77e8d556e2e1acc0ec503af693dF
f9e0e769bfa29d7f3fba358e5524c7245c425336886a47e1697aaa57c199fd16F
f9e741d7af4fbcb102cf759697c858701bf8839ced08a5f62c9415ac5de9dda3cF
f9eddb4d96fec5e873cef47d5028d8ef2534235e25948f0010a17f3da79f7835

ee:V+rF
fa096ffba3dc527395eaeb5d48dee9df05e4ddb693f382a610b5b0527eb217d4F
fa1ad496790644bccab3140b7f585dd72d55f3d0b242ec69cf7c2939b91b468bmF
fa23e5ba8d9b56049a550f17e94cd3178b35786e85c7098ea8f409f9cd1bd8c2F
fa313558117870b2ad9b85826be67b6ecce53baa6ddcbf99024428840d38fba7!F
fa3eac9fbdec92e915947210c7b62dd3bc17f62bd80edc537b07d378a58418d5TF
fa40075494cdb791de80bb9dd16a60c61c5e4200559523fc4cb22ded671eda5a]F
fa6421de2c15921a2e6fedbf4185a77ea6ccb46658a05d2002f389b7e2a8b60eyF
fa679cc7ff7900d485618ebb16638390e1b2e4a43f1278263dc8722680e307abF
fa80c361dec771feb54951286af7bb8032aef89cd8ded021b942b091ad431e5dF
fa816cfd764e59f3d6af36d6fe658eaf2ad7d0af0472a9bef2ab112995965b1fF
faa6d60940c2b7406116f4f0516e03526f4e692a662e39080ecd2196b0b55f9bF
faacc67629472caf8377dc9a0bf33c24bb238dbcb391edf62435e70baf591d97yF
fabce6473ab9dd2d36533444066b3b09b7055e6949844f6b7b52531e3d42f914

ff;W+rF
fad06e13ad887025495d47068294bf443e6c6209bbb16324fa1b3eb9ef5a885epF
fad6c8c1ae7000eeba2040a8163e5cc4920ac0d48ff08d1634dbe24df69b112dF
fae889b06ab0ce312053475d9327bbc3ab774b5205f23a802574f40fb6dd1621F
faea0d6adefaa474577c184f31a44469d13846a44412ea382dafc9f9ea6a3a77F
faf0e74d26792022e70a474776f33b0d995899e1d6150d742af9199b9cce5376
F
faf10a9ee4a6a84d4d3e47e83fc9b5e9820bc013e514a117737d79a517e0386a	tF
faf21678af2663e54fcc8f5016f8bcab54c797e4a2817cccba232b0e673d3370>E
fb00ca97e06f7da066e8d05cafb17b9f9680e39f50979090e489d8a1720bb4d4QF
fb019a858ec470c37fb4514a9c501552516bfe09f3c57ab59409c560d2a46ca9F
fb054f7e2c4002421c1a192b728bcaf7b397d066ecfefa67cb8fef0e35bc581cF
fb0edda86631e065ab929a5645c3c5c9573ef194bf8813617457f152c46177e3F
fb317c790c7775a8cd2becc6286e6028a33743078585cef6e150d0614e34aa17yF
fb38f857551fb354a5eed747d7a1167588232589a2bfc88abc3f695d37b7e705

ee:V+rF
fb53f898a944ec236a811663325ceef801af9d4d3e2c11522ee1bd7a77d9da79	F
fb54396129c15361020a0307c4dd42f46da87f1c0a0841e0d0ee3ee404ce59bdtF
fb633afcbec86339bf68947e27f45d0baba732bf9a5f35de6dd47472c02091a8
F
fb649db85a7fa03afc98ca05e61011b3c7d2d0ddfa11c9e025af979339542a81
F
fba2b7f38bb5d3e71e06753d36856e49f231e20be3c06505b414184bd656d595cF
fbae91cfe9ae73876a8eeb3b715dacaef2f15103aae6c0a6040a7aec6578cc0dF
fbb00aafe5d8bd8b4ce85814f2d529e893f31e915c6393c651859d9dd4be56ab F
fbc2fabe0f2dd520e1af93518f0669fbb0c91b469d7508a7402404cbbea73b6d
F
fbc75db0004b4f2ffa063eb646e4714cfa1fa34ce927f4cdac02ed19920adcc8
F
fbc77f001aab9462525aa44d833841b0d3687718322240a9c0df2ea113689697F
fbcc3e564c6dca446a39edd03f346e88b9881d9d18050e89024d0ff48b46240adF
fbd39d1a8897fa30ac649d4e1c6652bada403accff15f98abb244507a91a8494[F
fbdc480b9ba57d0d9e0972e4e60bb2e1de36296f91b120ddcc7d7abcbd955f94

ee:V+rF
fbdf0d211089d0219b49949e4bac45457c7c0de563ac494e01584ec1c65eb69d(F
fbfc27e8e45f88c94b069c77e301bd007e2e4c2d7e71b268fcaa0c9bee8f84a6F
fc069c671947a77de565e36b545682f1a73f32c53725d79715125c1c12e518d07F
fc095d80f336de3930ba83232f8684e5f27e20a6a90348f9746f9d4c65940aa4F
fc0d3c5609c739acc6d67bf0bff0c3ce7d1a05383836701bcb21e55aea34acef6F
fc23786485123d8fc0e167c65ecee809b1c1047c61cea465e243cf4b64b2a78eF
fc2d6ed7481cb42c62b4bd75126fc4237093c74ba7e87908a90815f672bdf45dF
fc3bab612213d15e8f3305d921a6c746a042fa8d06b3e8b75aa25f4eeced3daeF
fc45ecc53eafb78138b2291907fb4463e871868f19476b0d29e6c42b9e2f42a3F
fc48a72a9a0a8898553b10f1e151b5cb865e23d1ae5200c58cf22572c71ff6acF
fc626afc893b85c55f51d292c8bb06d0f31d54e62391e473e9fd5d070392c64cF
fc6296617d74745ac75f51e708264f5e77144e1a594d2ddfaadc84e9d9d9624dHF
fc6444986c7f47167fd58aa8888952344750766901c89c5c31b69ed13631e92d?O
 k?O	F
ff7e64392cb0525eb93067fe372af5efaf9fe58c81b8b7441f540801c817f214OF
fee2103b6ba68f134bc8d706313e6d873b9ef2d803cbcb27234da184bd579eb1OF
fc6cceaef55bd37f4fcdef13e567e0f496246d1ef59bd1803f1d77af60ef774a{OF
fd5c2fb9ea8fe33dda81b2c13693c8901313964b621a4845172a14c12df1439a"OF
fdbe2525e655b8cf975f2027191bcc9231946f75aa3196dd6bc68d144b98da20
OE
fe57c2235944b61957f96287d962dc8a6f63af33aa9a45b6bff9fc30a34862f53

ff;W+rF
fc7476815d3e884a39b6216376b5758e79de7e6fa1e0d85ad7c4923a963f6e0dF
fc779dd3d8c318abfbcddbc7accbbfc6b6690b7989ac005f12a76ade071b6d13bF
fc8271b385663f8ee5b7718d56371ca3af96ca4df7b25c4f38ff59ce2e327270F
fc8c80035602313a7b83027140e8b3e5895c85d6fbce04b2d73a53976a616e73MF
fc910dd4afd1311d8be1bdce2147613448f4162c19797bb345c5b725efff1d08
F
fc93fa73ee589349b26030b1fd56173975859786d624ddeaf826606e99c8b4f3JF
fce2a6c0ec49c42d5100944108bbb85b8a3e2685de9b583b1b4627e6f66b330eE
fce742e752f83c91c4d9e2dc4fad5ff1b7affb7363270b752a793df36c00754f=F
fcfcf89049ecf9f09cbf47f552ddb936bf74e4cd3537825f1c463ce4d4d50c66F
fd17cae7a3075f2ad58ed62ad9a2bb016b9d0ecbda3ed31b464e395e00f4dcb9~F
fd2db008a8253afbc54436a251251bbe5b6346f3c7a12892e6fe0b2aeb947358NF
fd358c591bdefefe4f8f4b730734f8e570c3f50680413739ef8785c99d73fddd	F
fd4d10950f499e8ff12b7354df494a29bc6c5c88db808bb7245d05a900fc6dbf)

ee:V+rF
fd5d1ca9a11a3575a3c34f7dbcd30cc924d2b41a0a004c3a793506098be60bcaoF
fd61faa3534a72b2293194c7decb752ff356a8de561e126459a7e8d55d0c96eb2F
fd640f5804c8bb45a16b7f00fef1ce4a1ec58f5ce9fb6650e9d98fa6c316fcd7pF
fd72ad4e19f26b5ab55c6b53a5824234f78c29cf3c20aca13156acea64a3346c
oF
fd7b7df51401985176a27907f57d0a616ead620f53c6855fee58b0ca86fe83945F
fd7c147bd421d47e6afa077b39fee3edde95b7c1ad7a4371b4271f0aaea8ca13F
fd8b80ddbac39b51ec642889d4f7007835aa7e1d353569778d00ad7dfdb85326F
fd8e59feae40f80e38ab4a8de84b96325cd6b29832ce967fca67cb83405b1342	F
fd9eac77800954e912c795b1baa2897a1255e8c44f1dcbe7f154da4bbb690fcd0F
fdad65275349657bbcdf47559eea430b65c4e7b72549cbc6960987457bc53c5bF
fdb3d033e3ca54175fbc3432d0eaabe73a06e7062247eadf1c8f79411c315081F
fdb600cfe62d10fb9b78089a4daae03dd3010232a321c952510faa95723d5a60F
fdb87f18d9c02219b23bb7f3233d128374d7e17e958892065ed687a59f5aad38

ee:V+rF
fdbf4bfe28188e74649c64f6a210cdce1aec37dafe82324cc4a7403e012e4c4fF
fdc3d5723bc3c1ed88713853d0c264f40ff05adf61533cdf99fc13598c015d19F
fdcabd5524523efc4fa2f438cdb2f40de42b6606b73bbff9e8f65e21ea81f437VF
fdd43196e4073342f9366aaa990c71e1f5ed36c633b8c6bc935da0a5d6fd8dd6F
fde70f28b5a0ce727403a12e9a6a39a8f953d1975000b7be4be8c5434c4d3556F
fdec48655b5d576de07b5788ee9206ab7b71c6fb8374b3e7fa47f3b65bfea9f3F
fdff2f1a1756e0f2d41cfa80f3b32907c40bd0172a470e140d1cb91e3b1dbecaF
fe01de01f7bcb863a54f276394f9ab097a0d29db56661a42eb33d27e4bef27f8	F
fe20198b1c59cd2bd81f50412b770ffdbe657e59f816450e2235e0863704f4d5F
fe31962a7aaae275d7dcbf9efe7364a94ada762b968513d3d783f9e763f8441bNF
fe35603b7abe8e1540b93b5c81f16503aa0704fb2bffed7d863b738cf0cf67b4	F
fe463cbf93e98cd763c89bf55103a9c84e8d48e998eb06542fe3e3fb72a10dd9F
fe536bc26d329494e0702e1ea45051bf8d51d2c5bd6f3d8f4810b32b738f7d54

ff;V+rF
fe59e0e08fdd30fac03b78e5e5afd3169677c15d89d0797bddd5d5e796f2e43aF
fe5bfef21df5d0e8252e7ac8804794d70a0db68230a14972077289f7d05e21e8	F
fe63730a873042e3f6763ad2922d8d1c714e93fe81d223bc2ae7454b4803f1fdE
fe65f8c1104a49b25deba3a5dd771fe3ef37e4b8efeb398644007101e18a44734F
fe81316791b5a33fb6e458bc981914e5a5c7d16da0e818f6b455b94fd257fbd8F
fe9ddea76d491834446326906a81c67139192d20db46b613104c60028b90693bF
feaa19dbb1f49048b7c247b0f07eca95e4c1ec3e3553221a73e356227d399654
F
feb6b437532dab8f5310701ed22fb3134f9e87f87fd7786802bcadba0cdeb3d6F
fec7ec65b7db46bf359cb0e984f68dfa1d760320e274306052a510c5d288ed1a2F
fed1a25dff437173e5198969384d287e1c91872362d72445cda5bf8bc78201f5	F
fed7b567e393c86119acb36d69b38b769bcb51e24ddcf415141d81230fdc54a8IF
fede7faa428def30a78d440b2dfd020e0a972bca7601dbd552274dc2f98434c9WF
fee0270ebb6d96079cd62a8292ee140622ec167fe229396b49b1691c2d2d6e74

ee:V+rF
fee8dc3a19870d83d686d8f123acfabb5dcca85f4ee2450ffe3dbd5f3b132a54F
feeaaecf67702b0e5815ef109a94fbdbbce95e0e6228db0f8c286f9f61a845ddF
fefe08dca680fa571c295cf0d51d266aa3aa3a357dc1bdb87dd804e1fe5179fd F
ff0af5a6e3acbbdec8607cb8aa6f258edbb87c22d9e2e162b476d366c16a6372
F
ff13cc6851b7555532b91dc5f8a9c7b73fb8f47f0f39be06ad101f6250c679c5OF
ff32b3ca928a0d84d11d5efe9433ba05d661f2a1df648fe6eee586eb09c24ac6F
ff3b468571e583e09e30108bb68b5b52e5aa7c6c634076708aa4dbbf6d6a6c7eOF
ff451f91104128c99b259625e000b9cbae52cee36db749f5b2e5291742d7ecc29F
ff4671dfa3a8f95a13b8ba51b2a558742445e61b30cbb1cf07788364ca2bb076F
ff496670decb17b290f032a8854f0420ac2848d6b92e9e0df99491a13901a396F
ff6ddec249d0b0ae7fe315e3626507ee4cbcf1c98b1ef5a0b571846cfa67ac37F
ff72d842591430311c483b93233f526b1dd34e953a34c084885d68d786f0aebaBF
ff7bd67ed63db8e85a6f69944e947f3a58d239a5e418b671d1eea3c8271d0777

ee:V+rF
ff8272f92c772a5d757bacb85570f4468e0c2c40956746d49494f1daa5041086F
ff9511b80fc18b09e37c9c11c984d322a95ec84172a9fafabc4b068d7d854bc4F
ffa04ef798ab2e5815f659306b1ff16a316bf5e5501788e7e0bdda2800e8afd0\F
ffa522d1a8d77788b084a92a321a67dd3087522b4c665f5b59ff0576763efcd2F
ffb599a2b9c5f8a8a237f321581e0fdbab30bb4d57604ff0a504dd1222938ebfF
ffbadd5995846ef0be55a84dee1a668513bc703e46ee467cb84a4e847415cbe4
F
ffc1d3cbc957771182427d3972e83824283b43b4272f105619d32ec0195171ceF
ffcf7016d990141a16d89aca74ebc89f797e93581bb8c97a08c83f5bf4ae47e4F
ffd9abc7bf1c18a5121be12799691f3e50e09ec00e67de327db03a1cf7a29d6cF
ffdb0e908ca8cc9013d59da38b6a5d9d04ea15e6af25a38508bc92e04af68500F
ffe6c8fe6239af5ba9b802d1110485c57c37832e367d2ff85fa1252c920e1193F
fffcdd496e8017e9a7bb4fdc0e4a0d7e1b98c54d5f9dabf43b01870bbb14d79eF
fffeb3e36d81e735ea56a95e6ac78d23c78c3ac7e4afb27bcdf91a835d7cb3b6
Back to Directory File Manager